1. Parties and acceptance
This Addendum is between the customer ("Controller") and Drive Dash AI, Shield Driving Center LLC d/b/a Driver Ed Consultants, a Pennsylvania limited liability company ("Processor"). It forms part of the Terms of Service and takes effect automatically when the Controller accepts those Terms — no separate signature is required. If your procurement process needs a countersigned copy, email brad@driveredconsultants.com and we will execute this same text.
Where this Addendum conflicts with the Terms of Service on the processing of personal data, this Addendum prevails.
2. Subject matter, duration, nature, and purpose
- Subject matter: provision of the Drive Dash AI marketing and measurement platform for driving schools.
- Duration: for as long as the Controller's account is active, plus the retention windows described in the Privacy Policy and section 9 below.
- Nature of processing: collection, storage, organization, retrieval, analysis, transmission to the subprocessors listed, generation of drafts, and deletion.
- Purpose: to operate the platform for the Controller, including scheduled and on-demand analysis runs, publishing content the Controller approves, and support.
- Processing is carried out only on the Controller's documented instructions, which comprise the Terms of Service, this Addendum, and the Controller's configuration and use of the platform.
3. Categories of data subjects and personal data (Annex I)
| Categories of data subjects | Categories of personal data |
|---|---|
| The Controller's staff and authorized users (owners, managers, administrators). | Name, work email, role, authentication data, activity and audit logs, billing contact details. |
| The Controller's instructors and staff named in business listings. | Name and business role where the Controller enters it. |
| Authors of public reviews of the Controller's locations. | Display name and review content as published on the review platform, plus replies the Controller approves. |
| Individuals who contact the Controller's business publicly (e.g. public social comments). | Display name and public comment content, where a connected platform returns it. |
No special categories of personal data are processed. The platform is not designed for and must not be used to process student or minors' personal data; the Controller must not upload such data.
4. Processor obligations (GDPR Art. 28)
- Process personal data only on the Controller's documented instructions, and inform the Controller if an instruction appears to infringe applicable law.
- Not use personal data for our own purposes, and not sell it, share it for advertising, or use it to train AI models.
- Ensure our personnel are bound by confidentiality obligations and are trained on their duties, with access limited to those who need it.
- Implement the technical and organizational measures in Annex II below.
- Engage subprocessors only under the terms of section 6, imposing data protection obligations no less protective than these.
- Assist the Controller in responding to data subject requests (section 7) and, taking account of the nature of processing, in meeting its obligations under Arts. 32–36, including security, breach notification, and impact assessments.
- Notify the Controller of a personal data breach without undue delay (section 8).
- Delete or return personal data on termination (section 9).
- Make available the information necessary to demonstrate compliance and allow audits (section 10).
5. Security measures (Annex II)
- Encryption of personal data in transit using TLS.
- Provider-managed encryption at rest for the database and stored files, applied by our managed infrastructure provider.
- Application-layer encryption of OAuth access and refresh tokens: values are encrypted in our application code, before they are written to the database, using AES-256-GCM authenticated encryption with a unique initialization vector per value. The key is held as a server-side secret and never stored in the database; decryption occurs only in server-side code. For Google, no access token is stored — only a refresh token is retained, and short-lived access tokens are requested as needed and held only in memory.
- Row-level security enforced on every application table and scoped to the Controller's organization, providing tenant isolation at the database layer.
- Privileged-role-only access to credential tables: no end-user role holds any privilege on the tables containing token ciphertext, which are reachable solely by the privileged server-side role.
- Least-privilege service access, role-based access control within the application (owner, member, internal staff) with separate gating for internal support access, reviewed migrations, and automated scanning of schema, grants, and policies.
- Deletion of tokens on disconnect: disconnecting an integration deletes the stored token, and for Google the token is revoked with Google first.
- Secrets held in a managed secret store, read only inside server-side handlers, never exposed to browsers.
- Server-side validation of inputs, protection against server-side request forgery on any URL fetched on a customer's behalf, and per-organization rate limits and provider quotas.
- Logging of runs, credit movements, and errors to support accountability and incident investigation.
- Managed infrastructure with provider-operated backups, patching, and physical security; no personal data on employee devices.
These measures may be updated over time as the platform and the threat landscape change. We will not reduce the overall level of protection, and we will notify the Controller of material changes.
6. Subprocessors
The Controller gives general authorization for us to engage the subprocessors published on our Subprocessors page, which forms part of this Addendum. Providers that only receive data once the Controller connects an account or supplies a key are marked as such on that page.
We will give at least 30 days' notice, by email to account owners and by updating that page, before adding or replacing a subprocessor that processes personal data. The Controller may object on reasonable data protection grounds within that period by emailing brad@driveredconsultants.com; if we cannot offer a workaround, the Controller may terminate the affected service without penalty for the unused portion of prepaid fees.
We remain liable for our subprocessors' performance of these obligations.
7. Data subject requests
The platform lets the Controller access, export, correct, and delete the personal data in its workspace directly. Where the Controller needs more, we will provide reasonable assistance to respond to access, rectification, erasure, restriction, portability, and objection requests within the statutory deadline. If a data subject contacts us directly about data we process for the Controller, we will not respond substantively and will refer them to the Controller, informing the Controller promptly.
8. Personal data breach notification
We will notify the Controller without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting personal data we process for them. The notice will describe the nature of the breach, the categories and approximate number of records and data subjects affected so far as known, the likely consequences, the measures taken or proposed, and a contact point. We will provide updates as the investigation progresses and cooperate with the Controller's own notification duties.
9. Deletion and return on termination
On termination, the Controller may export its data from the platform. On the Controller's written request, or in any event within 90 days of account closure, we will delete personal data from live systems, with backups expiring on their normal rotation. We may retain data where required by law — for example billing and tax records — and such retained data remains subject to this Addendum.
10. Audit and information rights
On reasonable written request, no more than once a year unless a breach or regulator requires otherwise, we will provide the information reasonably necessary to demonstrate compliance with this Addendum, including a description of our measures and any available provider certifications or reports. Where a Controller requires an on-site or bespoke audit, the parties will agree scope, timing, and confidentiality in advance and the Controller bears its own and our reasonable costs.
11. International transfers
Processing takes place in the United States and on a global edge network. For transfers of personal data from the EEA, UK, or Switzerland, the parties incorporate the European Commission's Standard Contractual Clauses (Decision 2021/914): Module Two (controller to processor) where the Controller is a controller, and Module Three (processor to processor) where the Controller acts as a processor for its own customers, together with the UK International Data Transfer Addendum and the Swiss adaptations where applicable.
- Clause 7 (docking clause) applies.
- Clause 9: Option 2 (general written authorization) with the 30-day notice period in section 6.
- Clause 11: the optional independent dispute resolution body is not selected.
- Clauses 17 and 18: the governing law and forum are those of Ireland, unless the Controller is established in a jurisdiction whose supervisory law requires otherwise.
- Annex I is section 3 of this Addendum together with the Subprocessors page; Annex II is section 5.
12. Liability and order of precedence
Each party's liability under this Addendum is subject to the limitations in the Terms of Service, except where applicable data protection law provides otherwise, including under the Standard Contractual Clauses. If the SCCs conflict with this Addendum, the SCCs prevail.
Contact for all matters under this Addendum: brad@driveredconsultants.com, 6047 Allentown Blvd, Suite B-118, Harrisburg, PA 17112.