v1.516 July 2026

Data Processing Agreement

This Data Processing Agreement ("DPA") forms an inseparable annex to the Organizer Terms of Service ("Organizer Terms") between Amahi s.r.o. (the operator of the Lapvio service) and the Organizer that has accepted those Terms.

This DPA sets out the terms on which Amahi s.r.o., as processor, processes personal data on behalf of the Organizer, as controller, in connection with the Organizer's use of Lapvio Pro. It is concluded under Article 28 of Regulation (EU) 2016/679 (the "GDPR") and corresponding Czech law (Act No. 110/2019 Coll. on the processing of personal data).

By accepting the Organizer Terms, the Organizer accepts this DPA. Both documents are part of one contract.

In this DPA:

  • "Amahi", "we", "us", "our", and "Processor" refer to Amahi s.r.o.
  • "Organizer", "you", "your", and "Controller" refer to the Organizer party to the Organizer Terms
  • "Lapvio" and "Lapvio Pro" have the meanings given in the Organizer Terms
  • "Driver Data" has the meaning given in the Organizer Terms: personal data of drivers and other end users that flows through Lapvio Pro in connection with the Organizer's events
  • Capitalized terms not otherwise defined here have the meanings given in the GDPR

1. Subject matter and roles

1.1 Roles of the parties

For Driver Data processed in Lapvio Pro on behalf of the Organizer, the Organizer is the Controller and Amahi is the Processor.

For Amahi's own platform-level data (admin user accounts, billing data, platform usage analytics, marketing communications to admins), Amahi is the controller, and that processing is governed by the Lapvio Privacy Policy, not by this DPA.

1.2 Subject matter

The subject matter of this DPA is the processing of Driver Data that Amahi performs on behalf of the Organizer in the course of providing Lapvio Pro under the Organizer Terms.

1.3 No joint controllership

The parties do not act as joint controllers under GDPR Article 26. Each party determines independently the purposes and means of processing for which it is the controller.

2. Duration

This DPA takes effect when the Organizer accepts the Organizer Terms and continues for as long as Amahi processes Driver Data on the Organizer's behalf. Termination is governed by Section 17.

3. Nature and purpose of the processing

Amahi processes Driver Data for the sole purpose of providing Lapvio Pro to the Organizer in accordance with the Organizer Terms and the Organizer's documented instructions.

This includes:

  • Storing driver registration data submitted through event portals
  • Sending transactional emails to drivers on the Organizer's behalf (registration confirmations, magic links, briefing invitations, waiver requests, post-event communications, broadcast messages the Organizer initiates)
  • Delivering push notifications to drivers' devices in connection with the Organizer's events (for example, event chat messages and event notifications), where the driver has installed the Lapvio app and enabled notifications
  • Generating and validating magic-link tokens for driver authentication
  • Coordinating waiver signing through DocuSeal (where the Organizer chooses to use it)
  • Synchronising orders from WooCommerce or other connected sources where the Organizer has configured this
  • Routing payments through Stripe Connect where the Organizer has enabled it (Stripe acts as a processor of payment data directly to the Organizer; Amahi does not see card data)
  • Generating QR codes for check-in
  • Producing platform-level features the Organizer has activated (CRM tools, photo set publishing, event reporting, etc.)
  • Storing logs and backups for the operation, security, and continuity of the service

Amahi does not process Driver Data for its own purposes. The platform-level analytics described in the Privacy Policy use only de-identified, aggregated data that does not identify individual drivers or organizers.

4. Categories of data and data subjects

4.1 Data subjects

The Driver Data Amahi processes on the Organizer's behalf relates to:

  • Drivers who register for the Organizer's events
  • Booking owners who purchase multiple slots and assign them
  • Other end users to whom the Organizer grants access (e.g. instructors, staff, guests)

4.2 Categories of personal data

The categories of personal data processed depend on what the Organizer collects through Lapvio Pro. Typically this includes:

  • Identity: first name, last name, display name
  • Contact: email address, phone number, language preference
  • Vehicle: car make/model, licence plate, car type
  • Event participation: slot type, registration status, briefing completion, waiver status, signed waiver PDF, check-in status, day-of operational notes (slot/pit assignment, transponder, group)
  • Organizer-generated: notes, tags, flags (incident, payment-due, behavioral, no-show), ban status and reason
  • Photos and media: photographs of drivers' cars or of the driver, where the Organizer publishes photo sets
  • Communications metadata: delivery and engagement metadata for emails sent on the Organizer's behalf
  • Payment data (limited): where Stripe Connect is enabled, transaction amount, currency, status, and reference. Card data and full bank details are processed by Stripe directly and are not visible to Amahi.

4.3 Special categories of data

Lapvio Pro is not designed to process special categories of personal data under GDPR Article 9 (data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, or data concerning a person's sex life or sexual orientation).

The Organizer agrees not to use Lapvio Pro to process special categories of data without first consulting Amahi. If the Organizer intends to record health-related information about drivers (for example, a medical declaration on the waiver), the Organizer is responsible for ensuring an appropriate lawful basis under Article 9, and Amahi may require additional safeguards or refuse the use case.

4.4 Data of children

Lapvio Pro is intended only for adult drivers. The Organizer agrees not to register drivers under 18 in the system without prior written agreement with Amahi.

5. Controller's instructions and obligations

5.1 Documented instructions

Amahi processes Driver Data only on the Organizer's documented instructions. The Organizer's instructions are:

  • The act of using Lapvio Pro in its normal way (each interaction with the platform is an instruction to process the corresponding data accordingly)
  • The configuration choices the Organizer makes in the admin interface
  • Specific written instructions sent by an authorized person to privacy@lapvio.com, where they are reasonable, lawful, and consistent with this DPA

If an instruction would, in Amahi's reasonable view, breach the GDPR or other applicable law, Amahi will inform the Organizer without undue delay and may decline to act on the instruction until clarified.

5.2 Controller's responsibility

The Organizer is responsible for:

  • Establishing a lawful basis under GDPR Article 6 (and Article 9 where applicable) for each processing activity
  • Providing drivers with the privacy notice required by Articles 13 and 14, covering the processing the Organizer carries out as controller
  • Maintaining its own record of processing activities under Article 30 where required
  • Responding to data subject requests where the Organizer is the controller (Section 10 covers Amahi's assistance)
  • Notifying the relevant supervisory authority and, where required, data subjects of any personal data breach affecting Driver Data, regardless of where the breach originated (Section 11 covers Amahi's role)
  • Carrying out a Data Protection Impact Assessment under Article 35 where required (Section 12 covers Amahi's assistance)
  • Ensuring that the Organizer's transfers of personal data to Lapvio Pro comply with applicable law

5.3 Lawfulness warranty

The Organizer warrants that:

  • It has a valid lawful basis for each category of Driver Data it loads into or generates within Lapvio Pro
  • It has obtained any consents required from drivers
  • The processing the Organizer instructs Amahi to carry out is lawful

If a driver, a supervisory authority, or a court determines that the Organizer lacked a lawful basis for a specific processing activity, the consequences of that determination are the Organizer's responsibility, subject to the indemnity in Section 10.4 of the Organizer Terms.

6. Processor's obligations

Amahi commits to the obligations set out in GDPR Article 28(3). Specifically:

  • Processing only on instructions: Amahi processes Driver Data only on the Organizer's documented instructions, including with regard to transfers to third countries, except where required by EU or EU member state law (in which case Amahi will notify the Organizer of that requirement before processing, unless the law prohibits notification on important public-interest grounds)
  • Confidentiality of personnel: Amahi ensures that anyone who processes Driver Data is bound by confidentiality obligations or is under an appropriate statutory duty of confidentiality (Section 7)
  • Security: Amahi takes the technical and organizational measures described in Annex B (Section 8)
  • Sub-processors: Amahi engages sub-processors only on the conditions in Section 9
  • Data subject rights: Amahi assists the Organizer in responding to data subject requests, by appropriate technical and organizational measures, in so far as this is possible (Section 10)
  • Compliance assistance: Amahi assists the Organizer in fulfilling its obligations under GDPR Articles 32 to 36, taking into account the nature of the processing and the information available to Amahi (Sections 11 and 12)
  • Return or deletion: At the Organizer's choice, Amahi returns or deletes Driver Data at the end of the engagement (Section 13)
  • Audit cooperation: Amahi makes available to the Organizer the information necessary to demonstrate compliance with this DPA, and allows for and contributes to audits (Section 14)

7. Confidentiality of personnel

Amahi ensures that all personnel and contractors with access to Driver Data:

  • Are subject to a written contractual or statutory duty of confidentiality
  • Receive appropriate guidance on the protection of personal data
  • Have access only to the Driver Data they need for their assigned task

This duty of confidentiality continues to apply after the end of the relevant employment or engagement.

8. Security

8.1 Article 32 measures

Amahi takes appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk to the rights and freedoms of natural persons.

The current technical and organizational measures are set out in Annex B. Amahi may update Annex B from time to time as the security landscape evolves; any update will maintain at least the same level of protection.

8.2 No reduction of standards

Amahi will not reduce the security standards described in Annex B without the Organizer's prior written agreement.

9. Sub-processors

9.1 General authorization

The Organizer gives Amahi a general authorization to engage sub-processors to process Driver Data, subject to the conditions in this Section 9.

9.2 Sub-processor obligations

Amahi imposes on each sub-processor, by written contract, data protection obligations equivalent to those in this DPA, in particular, sufficient guarantees to implement appropriate technical and organizational measures so that processing meets the requirements of the GDPR. Amahi remains liable to the Organizer for the performance of each sub-processor's obligations.

9.3 Current list of sub-processors

The current list of sub-processors is in Annex A. The same list is published at lapvio.com/legal/sub-processors and is updated when sub-processors change.

9.4 Notification of changes

Amahi notifies the Organizer of intended additions to or replacements of sub-processors at least 30 days in advance by:

  • Updating the list at lapvio.com/legal/sub-processors
  • Sending an email notice to the Organizer's super-admin email address

9.5 Right to object

Within 14 days of an Amahi sub-processor change notice, the Organizer may object in writing to privacy@lapvio.com if it reasonably believes that the proposed change creates a meaningful new risk to Driver Data.

If the parties cannot resolve the objection within 30 days, the Organizer may terminate the Organizer Terms (and this DPA) by written notice without penalty, with effect from the date the objected-to sub-processor would otherwise become active. The Organizer remains liable for fees accrued before termination.

If the Organizer does not object within the 14-day period, the change is deemed approved.

10. Data subject rights assistance

10.1 Direct requests to Amahi

If a driver contacts Amahi directly with a request relating to Driver Data (for example, a request for access, rectification, erasure, restriction, portability, or objection) Amahi will:

  • Acknowledge receipt and inform the driver that the relevant controller is the Organizer
  • Forward the request to the Organizer without undue delay
  • Not respond substantively to the driver about the controller-level processing, except to direct them to the Organizer

10.2 Assistance to the Organizer

Amahi assists the Organizer, by appropriate technical and organizational measures and in so far as this is possible, in fulfilling the Organizer's obligations to respond to data subject requests. This includes:

  • Providing tools in the Lapvio Pro admin interface that allow the Organizer to find, view, edit, export, or delete a driver's data without involving Amahi support
  • Where Amahi support is needed, responding to reasonable requests from privacy@lapvio.com within five business days

10.3 Costs

Amahi provides reasonable assistance at no additional charge as part of the subscription. For unusually frequent or burdensome requests, Amahi may charge for additional support work at then-current rates, with prior notice and the Organizer's agreement.

11. Personal data breach notification

11.1 Notification timing

Amahi notifies the Organizer of a personal data breach affecting Driver Data without undue delay after becoming aware of it, and in any event within 48 hours of becoming aware.

11.2 Information provided

Where the relevant information is available, the notification includes:

  • A description of the nature of the breach including, where possible, the categories and approximate number of data subjects and records concerned
  • The likely consequences of the breach
  • The measures Amahi has taken or proposes to take to address the breach and to mitigate its possible adverse effects
  • The name and contact details of the Amahi point of contact for further information

If not all information is available within 48 hours, Amahi provides what is available and follows up as the investigation progresses.

11.3 Cooperation

Amahi cooperates with the Organizer in investigating, mitigating, and remediating any personal data breach. The Organizer remains responsible, as controller, for any notifications required to a supervisory authority under Article 33 or to data subjects under Article 34.

11.4 Direct breaches at Amahi level

For breaches of Amahi's own infrastructure that may also affect Driver Data of multiple Organizers, Amahi may provide notifications collectively where appropriate, while still meeting the timing and content requirements above.

12. DPIA and prior consultation assistance

Amahi provides reasonable assistance to the Organizer with:

  • Data Protection Impact Assessments under GDPR Article 35
  • Prior consultations with supervisory authorities under GDPR Article 36

This assistance includes providing information about the Lapvio Pro platform, its sub-processors, and its security measures, and is provided at no additional charge for reasonable requests.

13. Return or deletion of Driver Data

13.1 Choice on termination

At the end of the provision of services relating to processing under this DPA, Amahi will, at the Organizer's choice expressed at termination:

  • Return the Driver Data to the Organizer in a structured, commonly-used, machine-readable format (typically JSON or CSV); or
  • Delete the Driver Data

If the Organizer does not communicate a choice within 30 days of termination, Amahi defaults to making the data export available for download by the Organizer for a further 30-day period, after which deletion proceeds.

13.2 Deletion process

Deletion involves:

  • Removing Driver Data from active systems (database, file storage, search indexes)
  • Confirming deletion in writing to the Organizer at the super-admin email
  • Allowing backup copies to age out under the standard backup rotation (currently up to 35 days), after which they are unrecoverable

13.3 Records that must be retained

Amahi retains data after the termination date only:

  • Where required by Czech or EU law (for example, financial records under Czech VAT law)
  • For the limitation period of legal claims that are pending or reasonably foreseeable
  • In aggregated, anonymized form that no longer identifies individual drivers or the Organizer

Any retained data continues to be protected by the security measures in Annex B.

13.4 Driver-side personal profiles

Where drivers have claimed Lapvio profiles and verified event history has flowed to those profiles, the historical fact that a driver attended an event run by the Organizer remains visible on the driver's own Lapvio profile, attributed to the historical organizer name. This is the driver's own data on their own profile, not Driver Data the Organizer controls. The Organizer does not have a right to demand erasure of this driver-side history, and Amahi does not delete it as part of the Organizer's termination.

14. Audits and inspections

14.1 Right to audit

The Organizer has the right to verify Amahi's compliance with this DPA through:

  • Information requests: written requests sent to privacy@lapvio.com to which Amahi will respond within 30 days with reasonable detail about its data-processing practices, security measures, and sub-processors
  • Standard documentation: Amahi makes available certifications, audit reports, and security documentation it holds (for example, sub-processor SOC 2 reports it can lawfully share)
  • On-site or remote audit: once per calendar year, the Organizer may conduct a more detailed audit, subject to the conditions below

14.2 Audit conditions

On-site or remote audits are subject to:

  • At least 30 days' written notice
  • Conducted during normal business hours
  • Conducted by the Organizer's qualified personnel or by an independent third-party auditor reasonably acceptable to Amahi (and not a competitor of Amahi)
  • The auditor signing an appropriate confidentiality agreement
  • Not unreasonably interfering with Amahi's operations or other organizers' use of the platform
  • Limited to information relevant to the Organizer's Driver Data and the obligations under this DPA

14.3 Costs

Each party bears its own audit costs, except where the audit identifies material non-compliance by Amahi, in which case Amahi reimburses the Organizer's reasonable audit costs.

14.4 Coordination

For multi-organizer audits relating to common platform infrastructure, Amahi may coordinate audit responses to minimize burden on all parties involved. The Organizer accepts that Amahi may share its individual audit findings with other affected organizers in suitably anonymized form.

15. International transfers

15.1 Transfers to third countries

Some of Amahi's sub-processors are located in countries outside the European Economic Area, including the United States. The current sub-processors and their locations are in Annex A.

15.2 Transfer mechanisms

For each transfer of Driver Data to a third country, Amahi relies on one or more of the following mechanisms (in order of preference):

  • A European Commission adequacy decision for the recipient country (currently in force for the United States via the EU–US Data Privacy Framework, for sub-processors that are certified under it)
  • Standard Contractual Clauses (the European Commission's 2021 SCCs, Implementing Decision 2021/914) signed with the sub-processor
  • Other appropriate safeguards under GDPR Chapter V where applicable

Amahi takes the supplementary measures necessary to address any risks identified, including encryption in transit and at rest.

15.3 If a transfer mechanism is invalidated

If a transfer mechanism Amahi relies on is invalidated by a court or supervisory authority decision, Amahi will:

  • Promptly notify the Organizer
  • Switch to an alternative valid mechanism, or
  • Migrate the affected processing to a sub-processor in an adequate jurisdiction
  • If neither is feasible without material change to the service, work with the Organizer on a solution that may include termination

15.4 Organizer's role

The Organizer remains responsible, as controller, for ensuring that its overall use of the service complies with the international transfer rules of any country whose residents' data the Organizer processes through Lapvio Pro.

16. Liability and indemnity

The liability of the parties under this DPA is governed by Section 10 of the Organizer Terms (Liability and Indemnity), as if it were stated in this DPA.

For the avoidance of doubt: damages and regulatory fines arising from a breach of this DPA (by either party) count toward the liability cap in the Organizer Terms, except in the cases where the cap does not apply (intentional or grossly negligent breach, breach causing material harm to data subjects, and other liability that cannot be limited under Czech law).

The Organizer's indemnity to Amahi in Section 10.4 of the Organizer Terms covers third-party claims arising from the Organizer's own breach of data-protection law in its role as controller.

17. Term and termination

This DPA takes effect alongside the Organizer Terms and continues for the duration of those Terms.

This DPA terminates automatically when the Organizer Terms terminate. Sections that should reasonably survive termination (confidentiality, return or deletion of data, audit rights for the limitation period, retention of records required by law, and dispute resolution) continue to apply.

Termination of this DPA without termination of the Organizer Terms is not possible. Amahi cannot continue to provide Lapvio Pro without the underlying processor relationship, so the two stand or fall together.


Annex A: Sub-processors

The following sub-processors process Driver Data on behalf of Amahi as of the effective date of this DPA. The current list is published at lapvio.com/legal/sub-processors.

Sub-processorService providedCategories of data processedCountryTransfer mechanism
Supabase Inc.Database, file storage, authentication infrastructureAll Driver Data stored in the platform database and storageIreland (database in Frankfurt, eu-central-1)Within EEA: no transfer mechanism required
Vercel Inc.Application hosting, server logsPage requests, IP addresses, application execution logsUnited States (with EU edge presence)EU–US Data Privacy Framework + SCCs as backup
Postmark / ActiveCampaign LLCTransactional email deliveryRecipient email, name, message content, delivery metadataUnited StatesEU–US Data Privacy Framework + SCCs as backup
DocuSealWaiver signing platformDriver name, email, waiver content, signed document, audit trailEU (DocuSeal EU servers)Within EEA: no transfer mechanism required
Stripe, Inc. and Stripe Payments Europe LtdPayment processing via Stripe Connect (where the Organizer enables it)Payment amount, currency, name and email for receipt; card data processed by Stripe directly under their own controller-level relationship with the driverIreland and United StatesEU–US Data Privacy Framework + SCCs as backup
Google Ireland Limited / Google LLCOAuth authentication for organizer admin sign-inAdmin user email, name, profile picture, OAuth token metadataIreland and United StatesEU–US Data Privacy Framework + SCCs as backup
QuickChartServer-side QR code image generation for check-inDriver name, event ID, encoded into the generated QR codeUnited StatesSCCs
Expo (Expo, Inc.)Push notification delivery serviceDevice push token, notification content of push notifications delivered to drivers' devices (for example, event chat messages and event notifications sent in connection with the Organizer's events), delivery metadataUnited StatesSCCs
Google LLC (Firebase Cloud Messaging)Transport layer for push notifications to Android devicesDevice push token, notification payload in transitUnited States and EUEU-US Data Privacy Framework + SCCs as backup

Sub-processors used only for Amahi's own controller-level processing (for example, Google Analytics, Meta Pixel for marketing on lapvio.com) are not listed here, as they do not process Driver Data on behalf of the Organizer. They are listed in the Lapvio Privacy Policy.


Annex B: Technical and organizational security measures

Amahi takes the following technical and organizational measures to protect Driver Data, in accordance with GDPR Article 32.

Access control and authentication

  • Authentication for organizer admins via Google OAuth with MFA encouraged at the Google account level
  • Authentication for drivers via email OTP (no passwords stored)
  • Magic-link tokens stored only as SHA-256 hashes in the database; raw tokens are never stored or logged on Amahi servers
  • Role-based access control within Lapvio Pro (super_admin, admin, operator) limiting access by least privilege
  • Production database access limited to a small number of authorized Amahi personnel, all using MFA-protected accounts
  • All admin actions logged and retained for audit

Data protection in transit and at rest

  • All data in transit encrypted with TLS 1.2 or higher
  • Database encryption at rest in Supabase
  • Storage bucket encryption at rest in Supabase
  • Backups encrypted at rest

Network and infrastructure security

  • Hosting infrastructure provided by certified providers (Supabase: SOC 2 Type II; Vercel: SOC 2; Stripe: PCI DSS Level 1)
  • Secrets and API keys stored in encrypted secret-management infrastructure, not in source code
  • Production and development environments separated
  • Application-level rate limiting and abuse detection

Software development practices

  • Code changes reviewed before deployment to production
  • Dependency vulnerability scanning enabled
  • Security advisories from sub-processors and dependencies monitored

Backups and disaster recovery

  • Automatic database backups
  • Backups retained for up to 35 days
  • Restoration capability tested as part of operational practice

Incident response

  • Documented incident response procedure
  • Personal data breach notification within 48 hours of awareness (Section 11)
  • Post-incident review and remediation tracked

Personnel

  • All personnel with access to Driver Data bound by written confidentiality obligations
  • Access removed promptly when an engagement ends
  • Privacy and security guidance shared with personnel

Sub-processor management

  • Each sub-processor bound by a written DPA equivalent to this one
  • Sub-processor list maintained at lapvio.com/legal/sub-processors and updated with at least 30 days notice for changes (Section 9)

Amahi may update this Annex B from time to time as the platform evolves and as the security landscape changes. Updates will maintain at least the same level of protection as these measures.


Annex C: International transfer mechanisms

Sub-processorLocationMechanismStatus
SupabaseIreland (HQ); database in FrankfurtEEA: no mechanism required for storage locationActive
VercelUnited States with EU edgeEU–US Data Privacy FrameworkActive (Vercel certified under DPF)
PostmarkUnited StatesEU–US Data Privacy Framework + SCCsActive
DocuSealEU serversEEA: no mechanism requiredActive
StripeIreland (Europe entity); United States (US entity)EU–US Data Privacy Framework + SCCsActive
Google (OAuth)Ireland and United StatesEU–US Data Privacy FrameworkActive (Google certified under DPF)
QuickChartUnited StatesSCCsActive
ExpoUnited StatesSCCsActive
Google (Firebase Cloud Messaging)United States and EUEU-US Data Privacy FrameworkActive (Google certified under DPF)

For any sub-processor that is not certified under the EU–US Data Privacy Framework, Amahi has executed Standard Contractual Clauses (Implementing Decision (EU) 2021/914) and supplements them with the technical and organizational measures in Annex B.

If the EU–US Data Privacy Framework is invalidated, Amahi falls back to SCCs alone where they are already in place, and notifies the Organizer of any material change in protection.


End of Data Processing Agreement.

For questions about this DPA, contact privacy@lapvio.com.