Data Processing Agreement

Addendum to the TaxiDesk Terms of Service

Last updated: 1 March 2026

1. Introduction

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Moova Mobilise Limited (trading as "TaxiDesk", the "Processor") and the Operator (the "Controller").

This DPA applies where TaxiDesk processes personal data on behalf of the Operator in connection with the Platform services, as required by Article 28 of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

By using the Platform and accepting the Terms of Service, the Operator agrees to this DPA.

2. Definitions

Terms defined in the Terms of Service have the same meaning in this DPA. Additionally:

  • "Controller" means the Operator, who determines the purposes and means of processing Customer personal data.
  • "Processor" means TaxiDesk, who processes Customer personal data on behalf of the Controller.
  • "Sub-processor" means a third party engaged by TaxiDesk to process personal data on behalf of the Controller.
  • "Data Subject" means the Customer (passenger) whose personal data is processed.
  • "Personal Data", "Processing", "Personal Data Breach" have the meanings given in UK GDPR.

3. Scope of Processing

3.1 Subject Matter and Duration

TaxiDesk processes Customer personal data for the purpose of providing the Platform services to the Operator, including booking facilitation, quote generation, booking dispatch, and payment collection. Processing continues for the duration of the Operator's use of the Platform and for the retention periods specified in Section 8.

3.2 Nature and Purpose of Processing

  • Receiving and storing booking requests from Customers.
  • Transmitting booking data to the Operator's dispatch system.
  • Processing card payments via Stripe Connect on behalf of the Operator.
  • Displaying booking status and confirmations to Customers.
  • Generating analytics and reporting for the Operator.

3.3 Types of Personal Data

  • Customer name (where provided).
  • Customer phone number (where provided for SMS notifications).
  • Pickup and drop-off locations.
  • Vehicle type selection and quoted fare.
  • Booking reference and status.
  • Payment reference (Stripe payment intent ID — full card details are not stored).

3.4 Categories of Data Subjects

Customers (passengers) who make bookings through the Operator's Kiosks and Widgets on the Platform.

4. Processor Obligations

TaxiDesk shall:

  • Process personal data only on the Controller's documented instructions, unless required to do so by UK law (in which case, TaxiDesk will inform the Controller before processing unless prohibited by law).
  • Ensure that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  • Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including encryption in transit and at rest, access controls, and regular security reviews.
  • Not engage another processor (sub-processor) without the Controller's prior general written authorisation, subject to Section 6.
  • Assist the Controller in responding to requests from Data Subjects to exercise their rights under UK GDPR, taking into account the nature of the processing.
  • Assist the Controller in ensuring compliance with the obligations under Articles 32 to 36 of UK GDPR (security, breach notification, data protection impact assessments, prior consultation).
  • At the Controller's choice, delete or return all personal data to the Controller after the end of the provision of services, and delete existing copies unless UK law requires storage.
  • Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 of UK GDPR and allow for and contribute to audits and inspections conducted by the Controller or a mandated auditor.

5. Controller Obligations

The Operator (Controller) shall:

  • Ensure there is a lawful basis for the processing of Customer personal data.
  • Provide appropriate privacy notices to Customers before or at the point of data collection.
  • Be responsible for responding to Data Subject requests (with TaxiDesk's reasonable assistance).
  • Comply with all applicable data protection laws.
  • Not instruct TaxiDesk to process data in a manner that would violate UK GDPR.

6. Sub-processors

The Controller provides general written authorisation for TaxiDesk to engage the sub-processors listed below. TaxiDesk will notify the Controller by email at least 30 days before adding or replacing a sub-processor, giving the Controller the opportunity to object.

6.1 Current Sub-processors

Sub-processor Purpose Location
Stripe, Inc. Payment processing (Stripe Connect) United States (with UK/EEA safeguards)
iCabbi (Mobilize Financial Services) Booking dispatch and quote generation Ireland / United Kingdom
DigitalOcean, LLC Cloud infrastructure and hosting United Kingdom / EEA
Laravel Forge (Joyent Technologies Pty Ltd) Server provisioning and deployment United States (with UK/EEA safeguards)

6.2 Objection to Sub-processors

If the Controller objects to a new or replacement sub-processor on reasonable data protection grounds, TaxiDesk will make reasonable efforts to provide an alternative. If no alternative is available, either party may terminate the agreement with 30 days' notice.

TaxiDesk will impose data protection obligations on each sub-processor that are no less onerous than those set out in this DPA.

7. Personal Data Breach

TaxiDesk will notify the Controller without undue delay (and in any event within 48 hours) upon becoming aware of a Personal Data Breach affecting Customer data. The notification will include:

  • A description of the nature of the breach, including the categories and approximate number of Data Subjects and personal data records affected.
  • The name and contact details of the TaxiDesk contact point for further information.
  • A description of the likely consequences of the breach.
  • A description of the measures taken or proposed to address the breach, including measures to mitigate its adverse effects.

The Controller is responsible for notifying the ICO (where required) and affected Data Subjects. TaxiDesk will provide reasonable assistance with such notifications.

8. Data Retention and Deletion

Customer booking data is retained for 6 years from the date of the booking to comply with tax and legal record-keeping requirements.

Upon termination of the Operator's account, TaxiDesk will:

  • Make booking data available for export by the Controller for 30 days following termination.
  • Securely delete or anonymise Customer personal data after the retention period, unless retention is required by UK law.
  • Provide written confirmation of deletion upon request.

9. International Transfers

TaxiDesk will not transfer personal data outside the United Kingdom without appropriate safeguards in accordance with Chapter V of UK GDPR, including:

  • UK International Data Transfer Agreements (IDTAs).
  • Standard Contractual Clauses (SCCs) with the UK addendum.
  • Adequacy decisions by the UK Secretary of State.

Where sub-processors are located outside the UK (see Section 6), appropriate transfer mechanisms are in place.

10. Audit Rights

TaxiDesk will make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA.

The Controller may conduct an audit (or appoint a third-party auditor, subject to reasonable confidentiality obligations) upon 30 days' written notice, no more than once per year, during normal business hours, and in a manner that does not unreasonably disrupt TaxiDesk's operations.

The Controller shall bear the costs of any audit unless the audit reveals material non-compliance by TaxiDesk.

11. Liability

The liability of each party under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.

12. Term

This DPA takes effect when the Operator accepts the Terms of Service and continues until the termination of the Operator's account, plus any retention period required under Section 8.

13. Contact

For questions about this Data Processing Agreement:

Data Protection Contact: privacy@taxidesk.co.uk

Moova Mobilise Limited

Block H, Eastpoint Business Park, Alfie Byrne Road, Dublin 3, Ireland