Skip to content
R Renaro
ProductSolutionsComparePricingDocsResources
Book a 20-min walkthrough
ProductSolutionsComparePricingDocsResources Book a 20-min walkthrough
  1. Home
  2. Legal
  3. Data Processing Addendum

Legal

Data Processing Addendum

This addendum governs how Renaro processes personal data on behalf of operators - the instructions Renaro follows, the security it maintains, the subprocessors it may use, and what happens to data when service ends. It is part of the Terms of Service for every operator.

Effective 2026-07-18 · last updated 2026-07-18

Scope and incorporation

This Data Processing Addendum (the "DPA") forms part of the agreement between Renaro and each operator with an account - the Terms of Service, or a signed order form or pilot agreement where one exists (together, the "Agreement"). It applies whenever Renaro processes personal data on the operator's behalf in providing the platform ("Operator Personal Data"): passenger, driver, vehicle, booking, communication, and trip-payment records, as cataloged in the Privacy Policy.

For that data, the operator is the controller (or a processor acting for its own client) and Renaro is the processor. Data Renaro controls for its own purposes - operator staff accounts, billing, security logs, product analytics, and support records - sits outside this DPA and is covered by the Privacy Policy. "Data Protection Laws" means the laws that apply to the processing under the Agreement, including the UK GDPR and Data Protection Act 2018, the EU GDPR, and applicable US state privacy laws.

Operators who require a countersigned copy of this DPA for their records can request one at support@renaroapp.com; the published version applies to all operators either way.

Details of the processing

Subject matter and duration: provision of the Renaro dispatch operations platform for the term of the Agreement, plus the wind-down period described under Deletion. Nature and purpose: hosting, storage, transmission, and display of records; dispatch and routing computation; messaging delivery; payment orchestration; reporting; and the related support the operator requests. Renaro processes Operator Personal Data only to provide these services - never for advertising, never for sale, and never to train models that identify people.

  • Data subjects: passengers and customers, drivers, operator staff, corporate account contacts, and other people whose details appear in booking records (for example emergency contacts and hotel guests).
  • Categories of data: identity and contact details; booking, trip, and location data (including driver location during shifts); communication content and metadata; tokenized payment references and financial records; uploaded documents and signatures; service-history measures; and free-text notes the operator records.
  • Sensitive categories: the operator controls what it records - driver compliance identifiers (for example licence numbers or national insurance numbers), background-check status, or accessibility needs on bookings can appear where the operator's workflows require them.

Renaro's obligations as processor

  • Process Operator Personal Data only on the operator's documented instructions - the Agreement, the operator's configuration of the platform, and its use of platform features are those instructions - unless law requires otherwise, in which case Renaro informs the operator unless legally barred.
  • Tell the operator promptly if, in Renaro's view, an instruction infringes Data Protection Laws.
  • Ensure everyone Renaro authorizes to process the data is bound by confidentiality obligations.
  • Maintain the technical and organizational measures described below, and not degrade them materially during the term.
  • Assist the operator, taking into account the nature of the processing, with data-subject requests, security, breach notification, impact assessments, and consultations with supervisory authorities.
  • Make available the information reasonably necessary to demonstrate compliance with this DPA, and allow audits as described below.
  • Delete or return Operator Personal Data at the end of the service as described under Deletion.

Security measures

Renaro maintains, at minimum, the following measures - described in operational terms because they are how the platform is actually built:

  • Tenant isolation enforced at the data layer: every tenant-scoped query is organization-bound, with database row-level security as defense in depth.
  • Encryption in transit for all connections; authenticated encryption at rest for stored integration credentials; API keys and session tokens stored only as cryptographic hashes.
  • Private object storage for files with short-lived signed links, malware scanning, and quarantine on upload.
  • Role-based access control with operator-managed roles, IP allowlists, and access schedules; multi-factor authentication available through the platform's identity provider, with step-up verification on sensitive administrative writes.
  • Comprehensive audit logging of writes and sensitive access, including the acting user; log redaction covering sensitive field paths; session replay disabled in analytics and error tooling.
  • Documented deletion and anonymization pipelines with per-step completion evidence; retention schedules per data category as published in the Privacy Policy.
  • Production monitoring, dependency and audit gates in the deployment pipeline, and incident response with operator notification.

Subprocessors

The operator gives general written authorization for Renaro to engage the subprocessors listed on the Subprocessors page, and future replacements or additions under this clause. Renaro imposes data-protection obligations on each subprocessor at least as protective as this DPA and remains fully responsible to the operator for their performance.

Renaro gives at least 30 days' notice before adding or materially changing a subprocessor, by updating the Subprocessors page and notifying operators through the platform or by email, except for emergency replacements needed for security or availability, where notice follows as soon as reasonably possible. An operator may object within the notice period on reasonable, documented data-protection grounds; the parties will work in good faith on a solution, and if none is reasonably available, the operator may terminate the affected service and receive a pro-rata refund of prepaid fees for the unused period.

Services the operator itself connects - accounting ledgers, calendar sync, its own webhook endpoints, its own messaging providers, and partner operators it farms bookings to - are the operator's own recipients, engaged on the operator's instructions, and are not Renaro subprocessors.

International transfers

The operator authorizes processing in the United States and the other locations shown on the Subprocessors page. Where Data Protection Laws require a transfer mechanism, the parties rely on the UK International Data Transfer Addendum and the EU Standard Contractual Clauses (processor-to-processor or controller-to-processor modules as appropriate), which are incorporated into Renaro's vendor agreements and, to the extent required, into this DPA between the operator and Renaro. Renaro maintains transfer documentation and makes it available on request.

Data subject requests

Renaro's platform gives operators the tools to answer most requests themselves: record correction in the dashboard, organization data export, and the confirmed deletion flow. If a data subject contacts Renaro directly about Operator Personal Data, Renaro passes the request to the operator without undue delay and does not respond substantively except as the operator instructs or law requires. Renaro provides reasonable further assistance where the tools alone cannot fulfil a request.

Personal data breach

Renaro notifies the operator without undue delay after becoming aware of a personal data breach affecting Operator Personal Data, and in any event within the time needed for the operator to meet its own 72-hour obligations. The notice describes, to the extent known, the nature of the breach, the categories and approximate volumes affected, likely consequences, measures taken or proposed, and a contact point - supplemented as investigation continues. Renaro's notification is not an admission of fault.

Audits

Renaro makes available documentation demonstrating compliance - this DPA, the Subprocessors page, security descriptions, and summaries of relevant third-party attestations held by its infrastructure vendors. Where Data Protection Laws give the operator an audit right that this documentation does not satisfy, the operator may audit once in any 12-month period (more often after a breach affecting its data, or where a supervisory authority requires it) on at least 30 days' notice, during business hours, under confidentiality, without access to other operators' data, and at the operator's cost. Renaro may satisfy the audit through a qualified independent third party's report.

Deletion and return at end of service

During the term, operators can export their data at any time. On termination or expiry, the operator can trigger the deletion flow described in the Privacy Policy: a confirmed request starts a 30-day grace period, after which Renaro revokes access, deletes or anonymizes Operator Personal Data, removes private files and cached entries, and deletes provider identities where lawful. Renaro may retain what law requires it to retain - financial, tax, audit, and evidence records - with personal fields minimized, and legal holds pause erasure until resolved. Absent a request, data is retained per the published retention schedule and remains exportable for a reasonable wind-down period.

US state privacy law terms

Where a US state privacy law applies, Renaro acts as the operator's service provider or processor: it processes Operator Personal Data only for the business purposes in the Agreement; it does not sell or share the data, retain, use, or disclose it outside the direct business relationship, or combine it with data from other sources except as the law permits for service providers; it certifies that it understands these restrictions; and it notifies the operator if it can no longer meet them, at which point the operator may take reasonable steps to stop unauthorized use.

Precedence and liability

If this DPA conflicts with the rest of the Agreement on data-protection matters, this DPA controls. Where incorporated transfer clauses conflict with this DPA, the transfer clauses control for the transfers they govern. Liability under this DPA is subject to the exclusions and cap in the Agreement, to the extent Data Protection Laws allow, and nothing in this DPA limits either party's liability where the law does not permit it to be limited.

Related documents

  • Privacy Policy
  • Subprocessors
  • Terms of Service

On this page

  • Scope and incorporation
  • Details of the processing
  • Renaro's obligations as processor
  • Security measures
  • Subprocessors
  • International transfers
  • Data subject requests
  • Personal data breach
  • Audits
  • Deletion and return at end of service
  • US state privacy law terms
  • Precedence and liability
R Renaro

Transparent dispatch software for taxi, limo, and private hire operators.

Product

  • Live dispatch
  • Booking management
  • Payments and ledger
  • Analytics

Solutions

  • Taxi fleets
  • Limo operators
  • Airport transfers
  • Corporate transport

Docs

  • Platform overview
  • Dispatch scoring
  • Payments and ledger
  • API and webhooks

Explore

  • Compare software
  • Integration guides
  • Market pages
  • Buying guides

Company

  • About
  • Security
  • Book demo
  • Contact

Legal

  • Terms of service
  • Privacy policy
  • Acceptable use
  • All legal documents
© 2026 Renaro Terms Privacy Cookies Dispatch, accounted for.