Data Processing Agreement

Last updated: 7 September 2026

This agreement sets out how METIMO processes employee personal data on behalf of a company customer under UK GDPR. It applies to company reporting features, where the company is the data controller and METIMO is the processor.

1. Parties and scope

This Data Processing Agreement ("DPA") forms part of the agreement between the company customer ("Controller") and Calculate My Product Carbon Footprint Ltd, trading as METIMO ("Processor"), for the company's use of the METIMO Employee Commute service (the "Service"). It applies where the Processor processes personal data on the Controller's behalf and takes precedence over any conflicting terms in relation to such processing.

"UK GDPR" means the retained EU General Data Protection Regulation as it forms part of the law of England and Wales, together with the Data Protection Act 2018. Terms such as "controller", "processor", "data subject", "personal data", and "processing" have the meanings given to them in that legislation.

2. Roles of the parties

For the company reporting features (where employees are linked to an employer and their commute data is aggregated for the employer's Scope 3 reporting), the company is the Controller and Metimo is the Processor. Where an individual uses the free single-user app on their own account, Metimo is the Controller for that use and this DPA does not apply.

3. Processor obligations

  • Process personal data only on the Controller's documented instructions, including this DPA and the Controller's use of the Service, unless required by law (in which case we will inform the Controller unless legally prohibited).
  • Ensure that people authorised to process the personal data are bound by confidentiality.
  • Implement appropriate technical and organisational security measures (see section 6).
  • Not engage another processor (sub-processor) except as set out in section 5.
  • Taking into account the nature of processing, assist the Controller by appropriate measures to respond to data subject rights requests.
  • Assist the Controller with security, breach notification, data protection impact assessments, and prior consultation with the ICO, taking into account the information available to us.
  • At the Controller's choice, delete or return the personal data at the end of the provision of services, and delete existing copies unless law requires storage (see section 8).
  • Make available information necessary to demonstrate compliance with Article 28 UK GDPR and allow for and contribute to audits as set out in section 7.

4. Controller obligations

  • Ensure it has a lawful basis to collect and share the employee personal data processed through the Service, and that appropriate privacy information has been given to its employees.
  • Issue instructions to the Processor that are lawful and within the scope of the Service.
  • Be responsible for the accuracy, quality, and legality of the personal data it provides.

5. Sub-processors

The Controller provides general authorisation for the Processor to engage the sub-processors listed below to deliver the Service. Each sub-processor is bound by written terms providing an equivalent level of data protection. We will inform the Controller of any intended change to sub-processors, giving a reasonable opportunity to object on reasonable data protection grounds.

  • Vercel — Application hosting and content delivery (USA / EU).
  • Neon — Database hosting (account and commute data) (EU).
  • Stripe — Payment processing for carbon offsets (USA / EU).
  • Resend — Transactional email delivery (USA / EU).
  • AWIN — Affiliate links for low-carbon products (EU / UK).

6. Security measures

  • Encryption of data in transit over TLS, and of data at rest at the hosting and database layer.
  • Access controls and authentication, with access to production data limited to authorised personnel on a need-to-know basis.
  • Logical separation of each company's data, with company reporting scoped to the relevant employer.
  • Regular patching of dependencies and use of reputable, security-certified infrastructure providers.
  • Backups and the ability to restore availability of personal data in a timely manner after an incident.

7. Audits

The Processor will make available information reasonably necessary to demonstrate compliance with its obligations and will allow for audits, including inspections, conducted by the Controller or an auditor it mandates. Audits will be on reasonable prior notice, no more than once per year (unless required by a supervisory authority or following a personal data breach), during business hours, and subject to confidentiality, so as not to disrupt the Processor's operations.

8. International transfers

Personal data is primarily processed within the UK and EEA. Where a sub-processor processes personal data outside the UK, the Processor ensures an appropriate transfer mechanism is in place (such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses) so that the data receives an essentially equivalent level of protection.

9. Personal data breach

The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's personal data, and will provide the information the Controller reasonably needs to meet its own breach notification obligations to the ICO and affected data subjects.

10. Return and deletion

On termination of the Service, or on the Controller's written request, the Processor will delete or return the Controller's personal data within a reasonable period, and delete existing copies unless retention is required by law. Employees may also manage or delete their own data at any time through their account.

11. Details of processing

  • Subject matter: provision of the Employee Commute reporting service.
  • Duration: for the term of the company's plan, plus any legally required retention period.
  • Nature and purpose: capturing and calculating commuting carbon emissions and aggregating them for the employer's Scope 3 Category 7 reporting.
  • Types of personal data: employee name, work email, employer, home-to-work distance or postcode-derived distance, commute mode and working pattern. The Service does not track live location.
  • Categories of data subject: the Controller's employees who use the Service.
  • No special category data is intentionally processed.

12. Governing law

This DPA is governed by the laws of England and Wales, consistent with the main agreement between the parties.

13. Requesting a signed copy

This page sets out our standard DPA terms. Company customers who need a countersigned copy for their procurement or records can request one from privacy@metimo.io, and we will arrange signature.