Data Processing Agreement
This Data Processing Agreement ("DPA") forms an inseparable annex to the Organizer Terms of Service ("Organizer Terms") between Amahi s.r.o. (the operator of the Lapvio service) and the Organizer that has accepted those Terms.
This DPA sets out the terms on which Amahi s.r.o., as processor, processes personal data on behalf of the Organizer, as controller, in connection with the Organizer's use of Lapvio Pro. It is concluded under Article 28 of Regulation (EU) 2016/679 (the "GDPR") and corresponding Czech law (Act No. 110/2019 Coll. on the processing of personal data).
By accepting the Organizer Terms, the Organizer accepts this DPA. Both documents are part of one contract.
In this DPA:
- "Amahi", "we", "us", "our", and "Processor" refer to Amahi s.r.o.
- "Organizer", "you", "your", and "Controller" refer to the Organizer party to the Organizer Terms
- "Lapvio" and "Lapvio Pro" have the meanings given in the Organizer Terms
- "Driver Data" has the meaning given in the Organizer Terms: personal data of drivers and other end users that flows through Lapvio Pro in connection with the Organizer's events
- Capitalized terms not otherwise defined here have the meanings given in the GDPR
1. Subject matter and roles
1.1 Roles of the parties
For Driver Data processed in Lapvio Pro on behalf of the Organizer, the Organizer is the Controller and Amahi is the Processor.
For Amahi's own platform-level data (admin user accounts, billing data, platform usage analytics, marketing communications to admins), Amahi is the controller, and that processing is governed by the Lapvio Privacy Policy, not by this DPA.
1.2 Subject matter
The subject matter of this DPA is the processing of Driver Data that Amahi performs on behalf of the Organizer in the course of providing Lapvio Pro under the Organizer Terms.
1.3 No joint controllership
The parties do not act as joint controllers under GDPR Article 26. Each party determines independently the purposes and means of processing for which it is the controller.
2. Duration
This DPA takes effect when the Organizer accepts the Organizer Terms and continues for as long as Amahi processes Driver Data on the Organizer's behalf. Termination is governed by Section 17.
3. Nature and purpose of the processing
Amahi processes Driver Data for the sole purpose of providing Lapvio Pro to the Organizer in accordance with the Organizer Terms and the Organizer's documented instructions.
This includes:
- Storing driver registration data submitted through event portals
- Sending transactional emails to drivers on the Organizer's behalf (registration confirmations, magic links, briefing invitations, waiver requests, post-event communications, broadcast messages the Organizer initiates)
- Delivering push notifications to drivers' devices in connection with the Organizer's events (for example, event chat messages and event notifications), where the driver has installed the Lapvio app and enabled notifications
- Generating and validating magic-link tokens for driver authentication
- Coordinating waiver signing through DocuSeal (where the Organizer chooses to use it)
- Synchronising orders from WooCommerce or other connected sources where the Organizer has configured this
- Routing payments through Stripe Connect where the Organizer has enabled it (Stripe acts as a processor of payment data directly to the Organizer; Amahi does not see card data)
- Generating QR codes for check-in
- Producing platform-level features the Organizer has activated (CRM tools, photo set publishing, event reporting, etc.)
- Storing logs and backups for the operation, security, and continuity of the service
Amahi does not process Driver Data for its own purposes. The platform-level analytics described in the Privacy Policy use only de-identified, aggregated data that does not identify individual drivers or organizers.
4. Categories of data and data subjects
4.1 Data subjects
The Driver Data Amahi processes on the Organizer's behalf relates to:
- Drivers who register for the Organizer's events
- Booking owners who purchase multiple slots and assign them
- Other end users to whom the Organizer grants access (e.g. instructors, staff, guests)
4.2 Categories of personal data
The categories of personal data processed depend on what the Organizer collects through Lapvio Pro. Typically this includes:
- Identity: first name, last name, display name
- Contact: email address, phone number, language preference
- Vehicle: car make/model, licence plate, car type
- Event participation: slot type, registration status, briefing completion, waiver status, signed waiver PDF, check-in status, day-of operational notes (slot/pit assignment, transponder, group)
- Organizer-generated: notes, tags, flags (incident, payment-due, behavioral, no-show), ban status and reason
- Photos and media: photographs of drivers' cars or of the driver, where the Organizer publishes photo sets
- Communications metadata: delivery and engagement metadata for emails sent on the Organizer's behalf
- Payment data (limited): where Stripe Connect is enabled, transaction amount, currency, status, and reference. Card data and full bank details are processed by Stripe directly and are not visible to Amahi.
4.3 Special categories of data
Lapvio Pro is not designed to process special categories of personal data under GDPR Article 9 (data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, or data concerning a person's sex life or sexual orientation).
The Organizer agrees not to use Lapvio Pro to process special categories of data without first consulting Amahi. If the Organizer intends to record health-related information about drivers (for example, a medical declaration on the waiver), the Organizer is responsible for ensuring an appropriate lawful basis under Article 9, and Amahi may require additional safeguards or refuse the use case.
4.4 Data of children
Lapvio Pro is intended only for adult drivers. The Organizer agrees not to register drivers under 18 in the system without prior written agreement with Amahi.
5. Controller's instructions and obligations
5.1 Documented instructions
Amahi processes Driver Data only on the Organizer's documented instructions. The Organizer's instructions are:
- The act of using Lapvio Pro in its normal way (each interaction with the platform is an instruction to process the corresponding data accordingly)
- The configuration choices the Organizer makes in the admin interface
- Specific written instructions sent by an authorized person to privacy@lapvio.com, where they are reasonable, lawful, and consistent with this DPA
If an instruction would, in Amahi's reasonable view, breach the GDPR or other applicable law, Amahi will inform the Organizer without undue delay and may decline to act on the instruction until clarified.
5.2 Controller's responsibility
The Organizer is responsible for:
- Establishing a lawful basis under GDPR Article 6 (and Article 9 where applicable) for each processing activity
- Providing drivers with the privacy notice required by Articles 13 and 14, covering the processing the Organizer carries out as controller
- Maintaining its own record of processing activities under Article 30 where required
- Responding to data subject requests where the Organizer is the controller (Section 10 covers Amahi's assistance)
- Notifying the relevant supervisory authority and, where required, data subjects of any personal data breach affecting Driver Data, regardless of where the breach originated (Section 11 covers Amahi's role)
- Carrying out a Data Protection Impact Assessment under Article 35 where required (Section 12 covers Amahi's assistance)
- Ensuring that the Organizer's transfers of personal data to Lapvio Pro comply with applicable law
5.3 Lawfulness warranty
The Organizer warrants that:
- It has a valid lawful basis for each category of Driver Data it loads into or generates within Lapvio Pro
- It has obtained any consents required from drivers
- The processing the Organizer instructs Amahi to carry out is lawful
If a driver, a supervisory authority, or a court determines that the Organizer lacked a lawful basis for a specific processing activity, the consequences of that determination are the Organizer's responsibility, subject to the indemnity in Section 10.4 of the Organizer Terms.
6. Processor's obligations
Amahi commits to the obligations set out in GDPR Article 28(3). Specifically:
- Processing only on instructions: Amahi processes Driver Data only on the Organizer's documented instructions, including with regard to transfers to third countries, except where required by EU or EU member state law (in which case Amahi will notify the Organizer of that requirement before processing, unless the law prohibits notification on important public-interest grounds)
- Confidentiality of personnel: Amahi ensures that anyone who processes Driver Data is bound by confidentiality obligations or is under an appropriate statutory duty of confidentiality (Section 7)
- Security: Amahi takes the technical and organizational measures described in Annex B (Section 8)
- Sub-processors: Amahi engages sub-processors only on the conditions in Section 9
- Data subject rights: Amahi assists the Organizer in responding to data subject requests, by appropriate technical and organizational measures, in so far as this is possible (Section 10)
- Compliance assistance: Amahi assists the Organizer in fulfilling its obligations under GDPR Articles 32 to 36, taking into account the nature of the processing and the information available to Amahi (Sections 11 and 12)
- Return or deletion: At the Organizer's choice, Amahi returns or deletes Driver Data at the end of the engagement (Section 13)
- Audit cooperation: Amahi makes available to the Organizer the information necessary to demonstrate compliance with this DPA, and allows for and contributes to audits (Section 14)
7. Confidentiality of personnel
Amahi ensures that all personnel and contractors with access to Driver Data:
- Are subject to a written contractual or statutory duty of confidentiality
- Receive appropriate guidance on the protection of personal data
- Have access only to the Driver Data they need for their assigned task
This duty of confidentiality continues to apply after the end of the relevant employment or engagement.
8. Security
8.1 Article 32 measures
Amahi takes appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk to the rights and freedoms of natural persons.
The current technical and organizational measures are set out in Annex B. Amahi may update Annex B from time to time as the security landscape evolves; any update will maintain at least the same level of protection.
8.2 No reduction of standards
Amahi will not reduce the security standards described in Annex B without the Organizer's prior written agreement.
9. Sub-processors
9.1 General authorization
The Organizer gives Amahi a general authorization to engage sub-processors to process Driver Data, subject to the conditions in this Section 9.
9.2 Sub-processor obligations
Amahi imposes on each sub-processor, by written contract, data protection obligations equivalent to those in this DPA, in particular, sufficient guarantees to implement appropriate technical and organizational measures so that processing meets the requirements of the GDPR. Amahi remains liable to the Organizer for the performance of each sub-processor's obligations.
9.3 Current list of sub-processors
The current list of sub-processors is in Annex A. The same list is published at lapvio.com/legal/sub-processors and is updated when sub-processors change.
9.4 Notification of changes
Amahi notifies the Organizer of intended additions to or replacements of sub-processors at least 30 days in advance by:
- Updating the list at lapvio.com/legal/sub-processors
- Sending an email notice to the Organizer's super-admin email address
9.5 Right to object
Within 14 days of an Amahi sub-processor change notice, the Organizer may object in writing to privacy@lapvio.com if it reasonably believes that the proposed change creates a meaningful new risk to Driver Data.
If the parties cannot resolve the objection within 30 days, the Organizer may terminate the Organizer Terms (and this DPA) by written notice without penalty, with effect from the date the objected-to sub-processor would otherwise become active. The Organizer remains liable for fees accrued before termination.
If the Organizer does not object within the 14-day period, the change is deemed approved.
10. Data subject rights assistance
10.1 Direct requests to Amahi
If a driver contacts Amahi directly with a request relating to Driver Data (for example, a request for access, rectification, erasure, restriction, portability, or objection) Amahi will:
- Acknowledge receipt and inform the driver that the relevant controller is the Organizer
- Forward the request to the Organizer without undue delay
- Not respond substantively to the driver about the controller-level processing, except to direct them to the Organizer
10.2 Assistance to the Organizer
Amahi assists the Organizer, by appropriate technical and organizational measures and in so far as this is possible, in fulfilling the Organizer's obligations to respond to data subject requests. This includes:
- Providing tools in the Lapvio Pro admin interface that allow the Organizer to find, view, edit, export, or delete a driver's data without involving Amahi support
- Where Amahi support is needed, responding to reasonable requests from privacy@lapvio.com within five business days
10.3 Costs
Amahi provides reasonable assistance at no additional charge as part of the subscription. For unusually frequent or burdensome requests, Amahi may charge for additional support work at then-current rates, with prior notice and the Organizer's agreement.
11. Personal data breach notification
11.1 Notification timing
Amahi notifies the Organizer of a personal data breach affecting Driver Data without undue delay after becoming aware of it, and in any event within 48 hours of becoming aware.
11.2 Information provided
Where the relevant information is available, the notification includes:
- A description of the nature of the breach including, where possible, the categories and approximate number of data subjects and records concerned
- The likely consequences of the breach
- The measures Amahi has taken or proposes to take to address the breach and to mitigate its possible adverse effects
- The name and contact details of the Amahi point of contact for further information
If not all information is available within 48 hours, Amahi provides what is available and follows up as the investigation progresses.
11.3 Cooperation
Amahi cooperates with the Organizer in investigating, mitigating, and remediating any personal data breach. The Organizer remains responsible, as controller, for any notifications required to a supervisory authority under Article 33 or to data subjects under Article 34.
11.4 Direct breaches at Amahi level
For breaches of Amahi's own infrastructure that may also affect Driver Data of multiple Organizers, Amahi may provide notifications collectively where appropriate, while still meeting the timing and content requirements above.
12. DPIA and prior consultation assistance
Amahi provides reasonable assistance to the Organizer with:
- Data Protection Impact Assessments under GDPR Article 35
- Prior consultations with supervisory authorities under GDPR Article 36
This assistance includes providing information about the Lapvio Pro platform, its sub-processors, and its security measures, and is provided at no additional charge for reasonable requests.
13. Return or deletion of Driver Data
13.1 Choice on termination
At the end of the provision of services relating to processing under this DPA, Amahi will, at the Organizer's choice expressed at termination:
- Return the Driver Data to the Organizer in a structured, commonly-used, machine-readable format (typically JSON or CSV); or
- Delete the Driver Data
If the Organizer does not communicate a choice within 30 days of termination, Amahi defaults to making the data export available for download by the Organizer for a further 30-day period, after which deletion proceeds.
13.2 Deletion process
Deletion involves:
- Removing Driver Data from active systems (database, file storage, search indexes)
- Confirming deletion in writing to the Organizer at the super-admin email
- Allowing backup copies to age out under the standard backup rotation (currently up to 35 days), after which they are unrecoverable
13.3 Records that must be retained
Amahi retains data after the termination date only:
- Where required by Czech or EU law (for example, financial records under Czech VAT law)
- For the limitation period of legal claims that are pending or reasonably foreseeable
- In aggregated, anonymized form that no longer identifies individual drivers or the Organizer
Any retained data continues to be protected by the security measures in Annex B.
13.4 Driver-side personal profiles
Where drivers have claimed Lapvio profiles and verified event history has flowed to those profiles, the historical fact that a driver attended an event run by the Organizer remains visible on the driver's own Lapvio profile, attributed to the historical organizer name. This is the driver's own data on their own profile, not Driver Data the Organizer controls. The Organizer does not have a right to demand erasure of this driver-side history, and Amahi does not delete it as part of the Organizer's termination.
14. Audits and inspections
14.1 Right to audit
The Organizer has the right to verify Amahi's compliance with this DPA through:
- Information requests: written requests sent to privacy@lapvio.com to which Amahi will respond within 30 days with reasonable detail about its data-processing practices, security measures, and sub-processors
- Standard documentation: Amahi makes available certifications, audit reports, and security documentation it holds (for example, sub-processor SOC 2 reports it can lawfully share)
- On-site or remote audit: once per calendar year, the Organizer may conduct a more detailed audit, subject to the conditions below
14.2 Audit conditions
On-site or remote audits are subject to:
- At least 30 days' written notice
- Conducted during normal business hours
- Conducted by the Organizer's qualified personnel or by an independent third-party auditor reasonably acceptable to Amahi (and not a competitor of Amahi)
- The auditor signing an appropriate confidentiality agreement
- Not unreasonably interfering with Amahi's operations or other organizers' use of the platform
- Limited to information relevant to the Organizer's Driver Data and the obligations under this DPA
14.3 Costs
Each party bears its own audit costs, except where the audit identifies material non-compliance by Amahi, in which case Amahi reimburses the Organizer's reasonable audit costs.
14.4 Coordination
For multi-organizer audits relating to common platform infrastructure, Amahi may coordinate audit responses to minimize burden on all parties involved. The Organizer accepts that Amahi may share its individual audit findings with other affected organizers in suitably anonymized form.
15. International transfers
15.1 Transfers to third countries
Some of Amahi's sub-processors are located in countries outside the European Economic Area, including the United States. The current sub-processors and their locations are in Annex A.
15.2 Transfer mechanisms
For each transfer of Driver Data to a third country, Amahi relies on one or more of the following mechanisms (in order of preference):
- A European Commission adequacy decision for the recipient country (currently in force for the United States via the EU–US Data Privacy Framework, for sub-processors that are certified under it)
- Standard Contractual Clauses (the European Commission's 2021 SCCs, Implementing Decision 2021/914) signed with the sub-processor
- Other appropriate safeguards under GDPR Chapter V where applicable
Amahi takes the supplementary measures necessary to address any risks identified, including encryption in transit and at rest.
15.3 If a transfer mechanism is invalidated
If a transfer mechanism Amahi relies on is invalidated by a court or supervisory authority decision, Amahi will:
- Promptly notify the Organizer
- Switch to an alternative valid mechanism, or
- Migrate the affected processing to a sub-processor in an adequate jurisdiction
- If neither is feasible without material change to the service, work with the Organizer on a solution that may include termination
15.4 Organizer's role
The Organizer remains responsible, as controller, for ensuring that its overall use of the service complies with the international transfer rules of any country whose residents' data the Organizer processes through Lapvio Pro.
16. Liability and indemnity
The liability of the parties under this DPA is governed by Section 10 of the Organizer Terms (Liability and Indemnity), as if it were stated in this DPA.
For the avoidance of doubt: damages and regulatory fines arising from a breach of this DPA (by either party) count toward the liability cap in the Organizer Terms, except in the cases where the cap does not apply (intentional or grossly negligent breach, breach causing material harm to data subjects, and other liability that cannot be limited under Czech law).
The Organizer's indemnity to Amahi in Section 10.4 of the Organizer Terms covers third-party claims arising from the Organizer's own breach of data-protection law in its role as controller.
17. Term and termination
This DPA takes effect alongside the Organizer Terms and continues for the duration of those Terms.
This DPA terminates automatically when the Organizer Terms terminate. Sections that should reasonably survive termination (confidentiality, return or deletion of data, audit rights for the limitation period, retention of records required by law, and dispute resolution) continue to apply.
Termination of this DPA without termination of the Organizer Terms is not possible. Amahi cannot continue to provide Lapvio Pro without the underlying processor relationship, so the two stand or fall together.
Annex A: Sub-processors
The following sub-processors process Driver Data on behalf of Amahi as of the effective date of this DPA. The current list is published at lapvio.com/legal/sub-processors.
| Sub-processor | Service provided | Categories of data processed | Country | Transfer mechanism |
|---|---|---|---|---|
| Supabase Inc. | Database, file storage, authentication infrastructure | All Driver Data stored in the platform database and storage | Ireland (database in Frankfurt, eu-central-1) | Within EEA: no transfer mechanism required |
| Vercel Inc. | Application hosting, server logs | Page requests, IP addresses, application execution logs | United States (with EU edge presence) | EU–US Data Privacy Framework + SCCs as backup |
| Postmark / ActiveCampaign LLC | Transactional email delivery | Recipient email, name, message content, delivery metadata | United States | EU–US Data Privacy Framework + SCCs as backup |
| DocuSeal | Waiver signing platform | Driver name, email, waiver content, signed document, audit trail | EU (DocuSeal EU servers) | Within EEA: no transfer mechanism required |
| Stripe, Inc. and Stripe Payments Europe Ltd | Payment processing via Stripe Connect (where the Organizer enables it) | Payment amount, currency, name and email for receipt; card data processed by Stripe directly under their own controller-level relationship with the driver | Ireland and United States | EU–US Data Privacy Framework + SCCs as backup |
| Google Ireland Limited / Google LLC | OAuth authentication for organizer admin sign-in | Admin user email, name, profile picture, OAuth token metadata | Ireland and United States | EU–US Data Privacy Framework + SCCs as backup |
| QuickChart | Server-side QR code image generation for check-in | Driver name, event ID, encoded into the generated QR code | United States | SCCs |
| Expo (Expo, Inc.) | Push notification delivery service | Device push token, notification content of push notifications delivered to drivers' devices (for example, event chat messages and event notifications sent in connection with the Organizer's events), delivery metadata | United States | SCCs |
| Google LLC (Firebase Cloud Messaging) | Transport layer for push notifications to Android devices | Device push token, notification payload in transit | United States and EU | EU-US Data Privacy Framework + SCCs as backup |
Sub-processors used only for Amahi's own controller-level processing (for example, Google Analytics, Meta Pixel for marketing on lapvio.com) are not listed here, as they do not process Driver Data on behalf of the Organizer. They are listed in the Lapvio Privacy Policy.
Annex B: Technical and organizational security measures
Amahi takes the following technical and organizational measures to protect Driver Data, in accordance with GDPR Article 32.
Access control and authentication
- Authentication for organizer admins via Google OAuth with MFA encouraged at the Google account level
- Authentication for drivers via email OTP (no passwords stored)
- Magic-link tokens stored only as SHA-256 hashes in the database; raw tokens are never stored or logged on Amahi servers
- Role-based access control within Lapvio Pro (super_admin, admin, operator) limiting access by least privilege
- Production database access limited to a small number of authorized Amahi personnel, all using MFA-protected accounts
- All admin actions logged and retained for audit
Data protection in transit and at rest
- All data in transit encrypted with TLS 1.2 or higher
- Database encryption at rest in Supabase
- Storage bucket encryption at rest in Supabase
- Backups encrypted at rest
Network and infrastructure security
- Hosting infrastructure provided by certified providers (Supabase: SOC 2 Type II; Vercel: SOC 2; Stripe: PCI DSS Level 1)
- Secrets and API keys stored in encrypted secret-management infrastructure, not in source code
- Production and development environments separated
- Application-level rate limiting and abuse detection
Software development practices
- Code changes reviewed before deployment to production
- Dependency vulnerability scanning enabled
- Security advisories from sub-processors and dependencies monitored
Backups and disaster recovery
- Automatic database backups
- Backups retained for up to 35 days
- Restoration capability tested as part of operational practice
Incident response
- Documented incident response procedure
- Personal data breach notification within 48 hours of awareness (Section 11)
- Post-incident review and remediation tracked
Personnel
- All personnel with access to Driver Data bound by written confidentiality obligations
- Access removed promptly when an engagement ends
- Privacy and security guidance shared with personnel
Sub-processor management
- Each sub-processor bound by a written DPA equivalent to this one
- Sub-processor list maintained at lapvio.com/legal/sub-processors and updated with at least 30 days notice for changes (Section 9)
Amahi may update this Annex B from time to time as the platform evolves and as the security landscape changes. Updates will maintain at least the same level of protection as these measures.
Annex C: International transfer mechanisms
| Sub-processor | Location | Mechanism | Status |
|---|---|---|---|
| Supabase | Ireland (HQ); database in Frankfurt | EEA: no mechanism required for storage location | Active |
| Vercel | United States with EU edge | EU–US Data Privacy Framework | Active (Vercel certified under DPF) |
| Postmark | United States | EU–US Data Privacy Framework + SCCs | Active |
| DocuSeal | EU servers | EEA: no mechanism required | Active |
| Stripe | Ireland (Europe entity); United States (US entity) | EU–US Data Privacy Framework + SCCs | Active |
| Google (OAuth) | Ireland and United States | EU–US Data Privacy Framework | Active (Google certified under DPF) |
| QuickChart | United States | SCCs | Active |
| Expo | United States | SCCs | Active |
| Google (Firebase Cloud Messaging) | United States and EU | EU-US Data Privacy Framework | Active (Google certified under DPF) |
For any sub-processor that is not certified under the EU–US Data Privacy Framework, Amahi has executed Standard Contractual Clauses (Implementing Decision (EU) 2021/914) and supplements them with the technical and organizational measures in Annex B.
If the EU–US Data Privacy Framework is invalidated, Amahi falls back to SCCs alone where they are already in place, and notifies the Organizer of any material change in protection.
End of Data Processing Agreement.
For questions about this DPA, contact privacy@lapvio.com.