Data Processing Addendum
Last updated: 11 July 2026
Data Processing Addendum
Last updated: 28 June 2026
This Data Processing Addendum (" DPA") forms part of the Terms of Service between Red Friend Co., Ltd., trading as Movialy (" Processor", " we", " us"), and the customer (" Controller", " you"). It governs our processing of personal data on your behalf when you use the Movialy service (" Service").
It applies to the extent that you act as a data controller (or processor on behalf of another controller) and we process personal data as your data processor — in particular, the personal data of your own clients (renters) and your Authorized Users that you enter into the Service.
In case of conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA prevails.
1. Definitions
Terms such as "personal data", "processing", "data subject", "controller", "processor", and "personal data breach" have the meanings given in the GDPR and/or the Thai PDPA, as applicable. "Applicable Data Protection Law" means all laws relating to data protection and privacy that apply to the processing under this DPA.
2. Roles of the Parties
2.1 You are the Controller of the personal data you submit to or process through the Service about your renters and Authorized Users. You determine the purposes and means of that processing.
2.2 We act as your Processor with respect to that personal data and process it only on your documented instructions, including as set out in the Terms of Service, this DPA, and your use of the Service's configuration options.
2.3 We are an independent Controller for the limited data described in our Privacy Policy (e.g. account administration, billing, security). That processing is governed by our Privacy Policy, not this DPA.
3. Your Instructions and Responsibilities
3.1 You instruct us to process personal data only (a) to provide and maintain the Service, (b) as further specified in the Terms of Service and this DPA, and (c) as configured by you within the Service.
3.2 You are responsible for ensuring that you have a valid legal basis and any required consents to collect and process the personal data you enter into the Service, including identity documents (such as driver's licences, passports, and ID cards) and photographs, and for providing required notices to data subjects.
3.3 You will not use the Service to process personal data in violation of Applicable Data Protection Law, and your instructions will not require us to do so.
4. Subject Matter and Details of Processing
Subject matter: provision of the Movialy fleet and booking management Service. Duration: for the term of your Account, plus the retention periods described in the Terms of Service and Privacy Policy. Nature and purpose: hosting, storage, transmission, display, and processing of Customer Data to deliver the Service's features (bookings, check-in/check-out, finance, maintenance, reporting, optional AI features). Categories of data subjects: your renters (clients), your Authorized Users, and other individuals whose data you choose to enter. Categories of personal data: identity and contact details; identity documents (driver's licence, passport, ID card); photographs; booking, financial, and ledger records; notes and ratings; and related metadata. Special-category / sensitive data: the Service is not intended for the processing of special-category data beyond identity documents necessary for vehicle rental. You must not enter sensitive data unless you have ensured a lawful basis for doing so.
5. Confidentiality
We ensure that personnel authorized to process the personal data are bound by appropriate confidentiality obligations and that access is limited to those who need it to provide the Service. Privileged super-administrator access is restricted and logged.
6. Security Measures
We implement appropriate technical and organizational measures, including those described in our Privacy Policy: encryption in transit (HTTPS/TLS), tenant isolation via Row Level Security (company_id), role-based access control re-verified server-side, signed time-limited URLs for stored files, change logging, and restricted, logged privileged access. A summary of measures is set out in Annex 2.
7. Sub-Processors
7.1 You authorize us to engage sub-processors to provide the Service. Current sub-processors are listed in Annex 1 and on our Privacy Policy / sub-processor page.
7.2 We impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance.
7.3 We will notify you of any intended addition or replacement of a sub-processor at least thirty (30) days in advance, giving you the opportunity to object on reasonable data-protection grounds within that period. If you raise a reasonable, well-founded objection that we cannot resolve, you may, as your sole remedy, terminate the affected part of the Service by written notice.
8. Assistance to the Controller
8.1 Taking into account the nature of the processing, we will assist you by appropriate technical and organizational measures, insofar as possible, to fulfil your obligation to respond to data-subject requests (access, rectification, erasure, restriction, portability, objection). The Service also provides export (CSV) and deletion functionality you can use directly.
8.2 We will assist you, where relevant and at your reasonable request, with data-protection impact assessments and prior consultations with supervisory authorities, taking into account the information available to us.
9. Personal Data Breach
We will notify you without undue delay after becoming aware of a personal data breach affecting personal data processed on your behalf, and will provide information reasonably available to us to help you meet your own notification obligations.
10. International Transfers
Where the provision of the Service involves transferring personal data across borders, we will ensure an appropriate transfer mechanism is in place as required by Applicable Data Protection Law (such as Standard Contractual Clauses under the GDPR, or applicable PDPA mechanisms). See Annex 1 for sub-processor locations.
11. Return and Deletion of Data
Upon termination of the Service, and at your choice, we will return or delete the personal data processed on your behalf, except to the extent we are required to retain it by law. We will make Customer Data available for export for thirty (30) days after termination, after which it may be deleted, except where retention is required by law.
12. Audit
We will make available to you information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor mandated by you, subject to reasonable notice, confidentiality, and frequency limits, and during normal business hours. Audits are limited to once per calendar year, unless a higher frequency is required by a supervisory authority.
13. Liability
The liability of each party under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.
14. Governing Law
This DPA is governed by the law specified in the Terms of Service ( Thailand), without prejudice to the mandatory provisions of Applicable Data Protection Law.
Annex 1 — Sub-Processors
| Provider | Purpose | Location | |---|---|---| | Supabase, Inc. (via Lovable Cloud) | Database, authentication, object storage, server functions | United States / EU (per project configuration) | | Cloudflare, Inc. | CDN, edge workers, PWA delivery, caching | United States; global edge network | | Lovable AI Gateway | OCR, vehicle suggestions, document classification, translation, thumbnails | United States / EU | | ClickUp | Support tickets and bug reports | United States | | Omise / Opn Payments | Payment processing (local) | Thailand / Singapore | | Paddle | Payment processing (international) | United Kingdom / EU | | Third-party GPS tracking services (feature under development) | Optional GPS connection; credentials supplied by Controller, not stored by default | Feature under development | | Nager.Date | Public-holiday data by country | European Union | | FlagCDN | Flag icons for the language selector | Global CDN |
Annex 2 — Technical and Organizational Measures (Summary)
- Encryption of personal data in transit (HTTPS/TLS).
- Logical tenant isolation enforced by Row Level Security on
company_id. - Role-based access control (roles + per-feature permissions), re-verified server-side for sensitive actions.
- Signed, time-limited URLs for access to stored photos and documents.
- Audit logging of changes to bookings, clients, vehicles, and financial records.
- Restricted and logged super-administrator access.
- Session management with expiry and password reset.
- Daily reset and isolation of demonstration data.