What this is. This Data Processing Addendum ("DPA") is incorporated into the Terms of Service and any Subscription Agreement between Nice Technologies, Inc. ("Processor", "we") and the customer organization ("Controller", "you"). It sets out how we process personal information on your behalf. You do not need to sign a separate copy for it to apply, though we will sign your own form on request.
1. Roles and scope
For personal information contained in Customer Data, you are the controller and we are the processor (a "service provider" under California law). You determine the purposes and means; we act only on your documented instructions.
Your instructions are: the Terms of Service, this DPA, your Subscription Agreement, the configuration choices your administrator makes in the Platform, and any further written instruction we accept. We will tell you if we believe an instruction breaches applicable data protection law.
2. Details of processing
| Subject matter | Provision of the Nice fleet management platform and related support |
| Duration | The term of the agreement, plus the export window in section 9 |
| Nature and purpose | Hosting, storage, transmission, display, backup, security monitoring and support, in order to operate fleet routing, dispatch, maintenance, compliance and rider communication |
| Categories of data subject | Your personnel and administrators; drivers and aides; riders and students; parents, guardians and caregivers |
| Categories of personal data | Identifiers and contact details; employment and qualification records; vehicle assignment and operational records; vehicle location during service; rider stop assignment and accessibility requirements |
| Sensitive data | Not requested and not required. You should not submit it. Where an accessibility requirement is recorded, it is limited to what is operationally necessary. |
| Children's data | Where you operate student transportation. See Student Data Privacy. |
3. Our undertakings
We will:
- process personal information only on your documented instructions, and not for our own purposes;
- not sell or share personal information, and not retain, use or disclose it outside the direct business relationship or for any purpose other than performing the services;
- not combine it with information from other sources, except as permitted by law for a service provider;
- ensure personnel with access are subject to binding confidentiality obligations and receive appropriate training;
- limit access to those who need it to perform their role;
- implement and maintain the security measures in section 6; and
- make available the information reasonably necessary to demonstrate compliance with this DPA.
4. Sub-processors
You give general authorisation for us to engage sub-processors. Our current list is published at Sub-processors, which you may subscribe to for change notices.
We will give at least 30 days' notice before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, we will work with you to find an alternative; if we cannot, you may terminate the affected service without penalty and receive a pro-rata refund of prepaid fees.
We impose data protection obligations on each sub-processor no less protective than those in this DPA, and remain fully liable to you for their performance.
5. Assistance to you
Taking into account the nature of the processing, we will:
- provide the tools for you to access, correct, export and delete personal information yourself, so that you can answer data subject requests without our involvement;
- promptly forward any request we receive directly from a data subject, without responding to it substantively other than to direct them to you;
- assist you with data protection impact assessments and consultations with regulators, so far as they relate to our processing; and
- assist you in meeting your security and breach notification obligations.
6. Security measures
We maintain appropriate technical and organizational measures, including:
- Encryption of personal data in transit (TLS) and at rest, including backups.
- Tenant isolation enforced at the data layer, so that cross-customer access is not a permission that can be expressed.
- Least privilege by default: new accounts start at the narrowest role and are widened deliberately.
- Access control for our own personnel, with individual accounts and multi-factor authentication.
- Support access to a customer tenant that is time-limited, reason-tagged, approved by the customer, and recorded in an audit log the customer can see.
- Audit logging of who changed what, when and from where.
- Backup and recovery testing, and documented restoration procedures.
- Vulnerability management, dependency patching and secure development practices.
7. Personal data breach
We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting your data. Our notice will describe, so far as known: the nature of the breach, the categories and approximate number of records and data subjects affected, the likely consequences, and the measures taken or proposed.
Where we cannot provide all of that at once, we will provide it in phases without undue further delay. We will not make any public statement identifying you without your prior consent unless legally compelled.
8. Audits
On reasonable written notice, not more than once in any twelve months (unless required by a regulator or following a breach affecting your data), we will:
- respond to a reasonable security questionnaire; and
- make available any then-current third-party audit reports or certifications we hold.
Where those are not sufficient to demonstrate compliance, we will allow an audit by you or an independent auditor bound by confidentiality, during business hours, without unreasonable disruption, and at your cost unless the audit reveals material non-compliance.
9. Return and deletion
You may export Customer Data at any time during the term. On termination we will retain it for 30 days to allow export, then delete it. On your written request we will delete it sooner, and confirm deletion in writing.
Backups containing deleted data age out on their ordinary 35-day cycle and are not restored to live systems. We may retain personal information where legally required, for as long as required and for no other purpose.
10. International transfers
Personal information is processed and stored in the United States. We do not transfer it outside the United States, and will not begin to do so without updating this DPA and putting an appropriate transfer mechanism in place.
11. Liability and precedence
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service and any Subscription Agreement. If this DPA conflicts with those documents on the processing of personal information, this DPA controls.
If you require your own DPA, a state-standard student data privacy agreement, or a National Data Privacy Agreement (NDPA) exhibit, send it to info@nicetechnologiesinc.com and we will review and sign where we can meet its terms.
12. Changes
We may update this DPA where required by law or to reflect a change in our processing. We will give at least 30 days' notice of material changes to the account administrator, and no change will reduce the protections that apply to your data.