Data Processing Agreement
Last updated: September 3, 2026
Version 1.0 | Effective September 3, 2026
The short version
When you use RushHour, the personal data in your account is yours. You decide what goes into it and what happens to it. We hold and process it to run the service for you, on your instructions, and for nothing else. This document is the contract that says so. It is written to meet Article 28 of the EU and UK GDPR, which is the strictest standard we are asked to meet, and the same commitments apply under Israeli and US state privacy law.
This Data Processing Agreement ("DPA") forms part of the RushHour Terms of Service and of any order form you have signed with us (together, the "Agreement"). It applies automatically: you do not need to sign anything for it to take effect, and it takes effect the moment you accept the Terms.
If your legal team needs a countersigned copy, or a copy of the Standard Contractual Clauses with the annexes completed for your entity, write to privacy@rushhourapp.com. The last section says exactly what to include.
This DPA is published in English. Any translation is provided for convenience only; if there is a difference, the English version applies.
The parties, and when this DPA applies
This DPA is between you - the company named on your order form or on your RushHour account ("you", "your", the "Customer") - and:
Rush Hour Logistics System Inc
A business corporation incorporated in the State of New York, USA, on 8 March 2017
New York Department of State ID: 5098884
Registered office: 1272 54th Street, Brooklyn, NY 11219, USA
Privacy contact: privacy@rushhourapp.com
In this DPA, "RushHour", "we" and "us" mean that company.
Definitions
"Data Protection Laws" means every privacy and data protection law that applies to the processing under the Agreement, including the EU General Data Protection Regulation 2016/679, the UK GDPR and the UK Data Protection Act 2018, the Israeli Protection of Privacy Law 5741-1981 and the regulations made under it, and US federal and state privacy laws.
"Customer Personal Data" means personal data that we process on your behalf under the Agreement. "Controller", "processor", "data subject", "processing" and "personal data breach" have the meanings given to them in the GDPR, and the equivalent terms in other Data Protection Laws are read the same way. Under the Israeli Protection of Privacy Law you are the owner of the database and we are a holder of it.
Where we offer the service
RushHour is sold to business customers in the United States and Israel. The product is offered in English and priced in US dollars. Under Recital 23 of the GDPR, the mere accessibility of a website or an app in the Union does not by itself amount to offering services there, and we do not currently target the EEA or the UK market.
We say that plainly rather than quietly, because it explains the next sentence. We are not established in the EEA or the UK, and we have not appointed an Article 27 representative in either. Before we offer the service to customers established in the EEA or the UK, we will appoint an Article 27 representative in the EEA and one in the UK, and we will name them here.
None of that limits this DPA. Where EU or UK data protection law applies to your use of the service, the commitments in this document apply to us in full, including the Standard Contractual Clauses set out below.
Who decides what: our roles
You are the controller
For everything in your RushHour account - your drivers, your staff, your customers, your orders, your documents - you are the controller. You decide what personal data goes into the platform, why, who may see it, and how long it stays. Where you are yourself a processor, because your own customer decides those things, you are the processor and we are your sub-processor. This DPA works either way.
We are the processor
We process Customer Personal Data only to provide, secure and support the service for you, and only as this DPA and your instructions allow.
Where we are a controller for our own account
A narrow band of data is ours to decide about. This DPA does not govern it - our Privacy Policy does:
- the account and contact details of the people at your company who sign up, sign in, administer the account or contact support;
- billing records - the invoices we issue to you, the payments you make, and the tax records we are required to keep;
- security, fraud-prevention and abuse records, and the logs we keep in order to run the platform safely;
- our correspondence with you, and enquiries submitted through our website.
We are the controller of that data and we handle it as described in our Privacy Policy. We do not use Customer Personal Data for our own purposes.
Under US state privacy laws
We act as a service provider or processor, as those laws define the terms. We do not sell personal information and we do not share it for cross-context behavioural advertising. We do not retain, use or disclose Customer Personal Data for any purpose other than performing the service for you, or as the law otherwise permits, and we do not combine it with personal information from other sources except where a service provider is permitted to.
What we process, and for whom
This section is the description of the processing that Article 28(3) requires, and it is Annex I(B) of the Standard Contractual Clauses.
- Subject matter. Our provision of the RushHour platform to you - the company portal, the customer portal, the driver mobile app and the API - as described in the Agreement.
- Duration. For as long as the Agreement is in force, plus the periods in "Returning and deleting your data" below.
- Nature of the processing. Collection, recording, organisation, structuring, storage, retrieval, use, display, transmission to the recipients you choose, restriction, erasure and destruction, by automated means.
- Purpose. Running dispatch and delivery operations for you: creating and pricing orders, planning and optimising routes, assigning drivers, collecting driver location while a route is active, capturing proof of delivery, recording vehicle inspections and hours of service, messaging between your dispatchers, drivers and customers, storing documents and photos, invoicing and taking payment, reporting, and the AI assistant and document features where they are used in your account.
- Frequency. Continuous, for the term of the Agreement.
Categories of data subject, and the personal data involved
| Data subjects | Personal data |
|---|---|
| Your staff - dispatchers, administrators and accounting users | Name, work email address, phone number, job role and permissions, profile photo, sign-in and presence records, and entries in the activity and audit logs showing what they changed and when. |
| Drivers you engage - employees and contractors | Name, email address, phone numbers, date of birth, national identification number (a US Social Security number) where you choose to enter one, home address, driving licence number, type, expiry, country and state, images of the driving licence, the vehicle registration and the vehicle insurance card, profile photo, vehicle plate and description, GPS location points (latitude, longitude, altitude, accuracy, heading, speed and time) collected while a route is active, duty status and hours-of-service records, vehicle inspection reports including photos and a signature image, issues they report, violations recorded against them, pay and payout records, device push tokens, and a Telegram user id where you switch Telegram messaging on. |
| Your customers, their contacts, and the people who receive deliveries | Company name, contact name, email address, phone number, pickup and delivery addresses and any access instructions, order and stop details, delivery photos, recipient names and signatures, notes, support tickets, invoices, payment card tokens with the card brand and last four digits, and messages and email exchanged inside the platform. |
| People you invite into your Customer Portal | Name, email address, sign-in and invitation records, and whatever they submit - orders, quote requests, payments, support tickets and messages. |
Special categories of personal data
The platform is not designed to process special categories of personal data under Article 9 of the GDPR, or the equivalent categories under Israeli and US state law, and you must not use it to. If you need to process such data, tell us first so that we can agree in writing what additional measures apply.
Three things are worth stating plainly, because a reader could otherwise assume the opposite:
- The insurance card upload is for vehicle insurance. The field labelled "Insurance Card" in the driver app and in the company portal sits alongside the driving licence and the vehicle registration, and it exists to hold the vehicle insurance card. It is an image field and we do not inspect what is uploaded into it. Please tell your drivers not to upload health, medical or other unrelated documents.
- We do not collect health data about drivers. There is no medical card, medical examiner certificate, fitness-for-duty record, drug or alcohol testing result, injury report or sickness field anywhere in the platform. The expenses module can record that your company paid for a driver's DOT physical, motor vehicle record pull or drug test, together with any receipt you attach to that expense - but no result, certificate, expiry date or medical finding is stored.
- One operational field mentions fatigue. When a route is handed from one driver to another, your people select a reason code. Fatigue is one of the four options, alongside shift end, team driving and other. It is an operational reason entered by your own staff, not a health assessment by us.
A driver's national identification number is treated as sensitive personal information under several US state privacy laws. That field is optional, and you decide whether to fill it in.
Your instructions, and what we will not do
We process Customer Personal Data only on your documented instructions. Your documented instructions are the Agreement, this DPA, the settings and integrations you configure in the product, the actions your authorised users take in it, and any further written instruction you give us that we agree to. There is nothing else.
- We will not process Customer Personal Data for any other purpose. We do not sell it, we do not use it for advertising, and we do not use it to build products for anyone else.
- We do not train any RushHour model on your data. Where the AI features are used in your account, the records the assistant needs to answer a question, and text extracted from documents you upload, are sent to the AI provider configured for that account. Those providers are named on the sub-processor page. If you supply your own provider key, that provider processes on your instruction and under the terms you have with it.
- If US law requires us to process Customer Personal Data other than on your instructions, we will tell you before we do, unless that law forbids us from telling you on important grounds of public interest.
- If we think an instruction you give us breaches Data Protection Laws, we will tell you. We may pause that instruction until it is resolved, and we will not be in breach of the Agreement for doing so.
What you are responsible for
- Having a lawful basis for everything you put into the platform, and giving the people concerned the privacy notice their law entitles them to. We have no relationship with your drivers, your staff or your customers. You do.
- Telling your drivers that their location is collected while they have an active route, and running any consultation, works-council or employee-notification process your law requires before you monitor them.
- Keeping the account accurate, including deactivating people who leave.
- Configuring the permissions in the platform so that your own people see only what their role requires.
- Assessing any integration you switch on. Where you connect an accounting system, a telematics provider, a messaging channel or your own AI provider key, you are instructing us to send data there, and the terms that third party has with you govern what it does with the data once it arrives.
Confidentiality of our people
- Everyone we allow to process Customer Personal Data is under a written duty of confidentiality, in their employment or engagement contract, that survives the end of their engagement.
- Access to production systems is limited to the small number of our people whose work requires it. Access is individually credentialled and logged, and it is removed when someone changes role or leaves.
- Our people are told what this DPA commits us to, and what they may and may not do with your data.
Security measures
We implement appropriate technical and organisational measures under Article 32, taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing, as well as the risk to people. The measures we maintain are set out in the security section of our Privacy Policy, which is incorporated into this DPA as Annex II of the Standard Contractual Clauses. In summary:
- Traffic between our apps, portals and browsers and our servers is encrypted in transit with TLS, and our API sends HTTP Strict Transport Security.
- Access is role-based. Every record is scoped to the company that owns it, and each person - our staff and your colleagues alike - sees only what their role permits.
- Access to production is limited, individually credentialled and logged.
- We keep audit and activity logs of administrative actions, of changes to business records, and of what the AI assistant and the document features did, so that changes can be traced.
- Card numbers are entered directly into our payment processor's own hosted fields and never reach our servers. We hold only a token, the card brand and the last four digits.
- Stored AI-provider credentials are encrypted at the application layer.
- We maintain a documented incident-response process.
We may change these measures as the platform develops. We will not make a change that materially reduces the overall level of security during the term of the Agreement.
We only claim what we can show you
Every measure listed above is one we can demonstrate on request. We have deliberately not listed controls we do not yet have, because a security claim we cannot evidence is the easiest statement in this document to disprove. If a specific control matters to your assessment, ask us before you sign and we will answer straight.
Sub-processors
You give us a general written authorisation to engage sub-processors. The sub-processors we use today, what each one does, what data it receives and where it processes, are published at rushhourapp.com/subprocessors. That page is part of this DPA and is Annex III of the Standard Contractual Clauses.
- Notice of changes. We will update that page before a new or replacement sub-processor starts processing Customer Personal Data, and before an existing one starts handling a materially different category of Customer Personal Data. Updating the page is how we inform you of an intended change for the purposes of Article 28(2) GDPR, and you agree to that method of notice. There is no minimum waiting period between the page being updated and the sub-processor being engaged. If you would also like an email, write to privacy@rushhourapp.com and we will add you to the notification list; subscribers are emailed each time the page changes.
- Your right to object. You may object within 30 days of the change appearing on that page, on reasonable grounds relating to data protection, by writing to the same address and telling us what the concern is. We will work with you in good faith to address it - by explaining the safeguards, by offering an alternative, or by changing the configuration of your account.
- If we cannot resolve it. You may terminate the part of the service that requires the sub-processor, or, where it cannot be separated, the Agreement, on written notice and without penalty. We will refund fees you have prepaid for the period after termination.
- Same obligations, and our liability. We put each sub-processor under a written contract with data protection obligations no less protective than those in this DPA, and, where the sub-processor is outside the EEA or the UK, on the transfer terms below. We remain fully liable to you for a sub-processor's performance of those obligations.
- Optional integrations are different. Some providers on that page are used only where you switch an integration on. If you do, you are instructing us to send data there. We still contract with the ones we engage on your behalf - but where the account is yours, such as your own accounting, telematics or AI provider account, the relationship with that provider is yours too.
Helping you answer people's requests
Requests from data subjects - access, correction, erasure, restriction, portability, objection - are yours to answer, because you are the controller. We help in two ways.
The product does most of it
- Your administrators can find, view, correct and export the records held about a driver, a staff member, a customer or a contact directly in the company portal, without needing us.
- You can delete a driver from the portal: Drivers, then the row's actions menu, then Delete. There is a bulk option for several at once.
- A driver can delete their own account from the mobile app: Dashboard, then Settings, then Privacy, then Delete Account. Deletion is refused while they have an active route or an outstanding balance, and their access ends immediately.
- Where a request needs something the product cannot do on its own, we will do it for you.
If a request comes to us
- If a data subject contacts us directly about data held in your account, we will not answer it on the merits. We will tell them to contact you, and we will pass the request on to you promptly - unless the law requires us to respond, in which case we will tell you first where we are permitted to.
- We assist you with appropriate technical and organisational measures, so far as this is possible, taking into account the nature of the processing.
- This assistance is included in your subscription for a reasonable volume of requests. If requests become excessive or repetitive because of how your account is being used, we will tell you before doing the work and agree a written estimate with you first.
Security incidents, impact assessments and prior consultation
If there is a personal data breach
- We will notify you without undue delay, and in any event no later than 48 hours after we confirm a personal data breach affecting Customer Personal Data. That is deliberately inside your own 72-hour deadline.
- The notification will describe the nature of the breach, the categories and approximate number of data subjects and records involved so far as we know them, the likely consequences, the measures we have taken or propose to take, and a contact point. Where we do not have everything at once, we will send it in phases as we learn more, rather than waiting.
- We will take reasonable steps to contain the incident and reduce its effects, and we will keep you updated while we do.
- We will not notify a supervisory authority or the data subjects on your behalf unless the law requires us to, or you ask us to and we agree in writing. We will not name you in a public statement about an incident without your consent unless the law requires it.
- Under the Israeli Protection of Privacy (Data Security) Regulations 5777-2017, we will give you what you need to meet your own obligation to report a severe security incident to the Privacy Protection Authority, and we will follow any instruction it gives about notifying the people affected.
Report a suspected vulnerability or incident to security@rushhourapp.com. We will acknowledge it and tell you what we are doing about it.
Impact assessments and prior consultation
Taking into account the nature of the processing and the information available to us, we will give you reasonable assistance with a data protection impact assessment under Article 35, and with any prior consultation with a supervisory authority under Article 36, where the processing relates to your use of RushHour. In practice that means providing the description of the processing in this DPA, a description of our security measures, the current sub-processor list, the retention periods we apply, and written answers to reasonable questions from you or from your regulator.
Returning and deleting your data
During the term
You can export your data from the product at any time while the Agreement is in force. If you need something the export tools do not cover, ask us and we will provide a copy in a structured, commonly used, machine-readable format.
When the Agreement ends
- You have 30 days from the end of the Agreement to export your data. Tell us during that window if you would rather we returned it to you, and we will.
- After that window we delete Customer Personal Data from our live systems. Deletion is completed within 60 days of the end of the Agreement.
- Deleted data ages out of our encrypted backups on the normal rotation cycle. We never restore a deleted account from backup.
- We will confirm the deletion to you in writing if you ask.
Deleting one person
- When a driver account is deleted - by the driver in the app, or by your administrator in the portal - access ends immediately, and a 30-day period begins during which the deletion can be reversed by restoring the driver to active.
- After that period the record is erased, and erasure completes within 30 days of the period ending.
- Erasure empties the record of the person. Name, email address, national identification number, date of birth, phone numbers, home address and licence details are removed, along with the licence, registration, insurance card and profile images, the login and its password, device tokens, and any outstanding invitation. Location points are deleted outright.
- Records that must be kept are retained without the person's identity attached to them. Those are the records your own law obliges you to hold: hours-of-service and duty records, roadside inspection and violation records, vehicle inspection results, delivery records, pay records and invoices. They stay attached to a record that no longer names or identifies the individual.
Where we keep something longer
We keep driver GPS location points for 90 days and then delete them. We keep invoices, payment records, tax records and payroll-related records for 7 years, because US federal and New York State record-keeping rules require it, and delivery documentation for up to 7 years where it evidences a shipment and may be needed for a freight claim. Server error reports are kept for 90 days. Activity, audit and AI-usage logs are kept for the periods set out in the Privacy Policy. Anything we retain after the Agreement ends stays subject to this DPA, and we process it only for the purpose that required us to keep it.
Audit and information rights
Article 28(3)(h) gives you the right to satisfy yourself that we are doing what this DPA says. Here is how that works in practice, in the order we expect it to happen.
1. Documentation first
- We make available the information necessary to demonstrate compliance with this DPA: this document, the sub-processor list, the security section of the Privacy Policy, our retention periods, and our incident-response process.
- Once in any 12-month period we will complete a reasonable security and privacy questionnaire from you, in writing and at no charge. We will answer within 30 days of receiving it.
- Where a sub-processor publishes independent audit reports or certifications, we will point you to them, or pass them on where we are permitted to.
2. An audit, if documentation is not enough
- If the documentation does not answer your question, you may audit us, or appoint an independent auditor to do so - once in any 12-month period, on at least 30 days' written notice, during our normal business hours, and for no longer than is reasonably necessary.
- You may audit more often where a supervisory authority requires it, or following a confirmed personal data breach affecting your data.
- An auditor you appoint must not be a competitor of ours and must sign a confidentiality agreement with us before the audit begins. Everything learned in an audit is confidential.
- An audit may not cover another customer's data, and it may not require us to disclose information whose disclosure would breach a confidentiality obligation we owe someone else or would itself create a security risk. We will find another way to give you the assurance in that case.
- An audit must not unreasonably disrupt the service or our business. We will agree the scope, timing and method with you in advance.
- You bear your own costs and, where the audit is not triggered by a breach or by a regulator, our reasonable costs of supporting it.
- Our data centres belong to our hosting provider, so on-site inspection of them is not ours to grant. We will provide that provider's own published assurance material instead.
Where the Standard Contractual Clauses apply, this section is how Clause 8.9 is performed.
International transfers
Everything we run is in the United States
Our application servers, the operational database, the search index, the cache and the image store run in Amazon Web Services in US East (Ohio). Uploaded company documents are stored in AWS in US West (Oregon). Our portals and website are hosted on Vercel. We do not operate a hosting region in the EEA, the UK or Israel. So if you are in the EEA, the UK or Israel, every transfer of personal data to us is a transfer to the United States - not an edge case, the normal case.
Most of our sub-processors are in the United States as well. A few process elsewhere, and the sub-processor page says which, and where.
EU Standard Contractual Clauses
Where Customer Personal Data is transferred from the EEA to us, the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 are incorporated into this DPA by reference and form part of it. They are completed as follows.
| Clause or annex | How it is completed |
|---|---|
| Module | Module Two (controller to processor) where you are a controller. Module Three (processor to processor) where you are yourself a processor acting for another controller. |
| Parties | Data exporter: you, the Customer. Data importer: Rush Hour Logistics System Inc. |
| Clause 7 (docking clause) | Applies. |
| Clause 9(a) (sub-processors) | Option 2, general written authorisation. Changes are notified by publication on the sub-processor page, as set out in the sub-processor section above. |
| Clause 11(a) (independent dispute resolution) | The optional body is not used. |
| Clause 17 (governing law) | Option 1. The law of Ireland. |
| Clause 18(b) (forum) | The courts of Ireland. |
| Annex I.A (parties) | You, as identified on your order form, and Rush Hour Logistics System Inc, 1272 54th Street, Brooklyn, NY 11219, USA. Data protection contact: your account administrator for you, and privacy@rushhourapp.com for us. |
| Annex I.B (description of the transfer) | The subject matter, duration, nature, purpose, data subjects, personal data and frequency set out under 'What we process, and for whom' above. Transfers are continuous for the term of the Agreement. |
| Annex I.C (competent supervisory authority) | The supervisory authority of the EEA member state in which you are established. Where you are not established in the EEA, the authority determined under Clause 13. |
| Annex II (technical and organisational measures) | The measures described in the security section above and in the security section of the Privacy Policy. |
| Annex III (sub-processors) | The list published at rushhourapp.com/subprocessors. |
By entering into the Agreement, each party is treated as having signed the Clauses and their annexes on the date the Agreement takes effect. If anything in this DPA conflicts with the Clauses, the Clauses win.
United Kingdom
For transfers from the United Kingdom, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0, issued by the Information Commissioner and laid before Parliament on 2 February 2022, is incorporated by reference and completed as follows: Table 1 is the parties named in Annex I.A above; Table 2 is the Approved EU SCCs, Module Two or Module Three as applicable, completed as in the table above; Table 3 is the annexes described in that table; and in Table 4, neither party may end the Addendum when the Approved Addendum changes. Where the Addendum requires it, the Clauses are read as the Addendum directs.
Switzerland
Where the Swiss Federal Act on Data Protection applies, the Clauses apply with the amendments published by the Federal Data Protection and Information Commissioner: references to the GDPR are read as references to the FADP, the Commissioner is the competent authority, and the Clauses also protect the data of legal entities until Swiss law provides otherwise.
Israel
For transfers from Israel we rely on Regulation 2(4) of the Protection of Privacy (Transfer of Data to Databases Abroad) Regulations 5761-2001, and this DPA is the written undertaking that regulation requires. We undertake to you, as the owner of the database, to hold and use the data on the conditions that apply to a database held in Israel under the Protection of Privacy Law 5741-1981 and the Data Security Regulations 5777-2017, so far as those conditions can apply to a holder outside Israel, and not to transfer the data onward to anyone except on those same terms. Every sub-processor we engage is bound to equivalent terms, so the onward-transfer condition holds down the chain. Protection of Privacy Law matters go to privacy@rushhourapp.com.
Government access requests
- If a public authority asks us for Customer Personal Data, we will tell you as soon as possible so that you can respond, unless we are legally prohibited from telling you. Where we are prohibited, we will use reasonable efforts to obtain a waiver, and to have the prohibition lifted as soon as possible.
- We will challenge a request that we consider unlawful under the law of the requesting authority, or that conflicts with the obligations in the Standard Contractual Clauses, including by seeking interim measures where there are grounds to.
- Where we must disclose, we will disclose only the minimum amount permissible on a reasonable interpretation of the request.
- We will keep a record of these requests and make it available to you on request, so far as the law allows.
- We will not give any authority direct, unsupervised access to Customer Personal Data.
Representatives, and who to contact about privacy
- Article 27 representatives. We are not established in the EEA or the UK and we have not appointed representatives there, because we do not currently offer the service to customers established in those territories. Before we do, we will appoint an EEA representative and a UK representative and publish their details here.
- Data protection officer. We have not appointed one. Article 37 does not require it here: our core activities are not large-scale, regular and systematic monitoring of data subjects on our own account, and they are not large-scale processing of special categories - we process on behalf of our business customers, as their processor. We operate a named privacy contact instead, which reaches the people who can actually act on a request.
- Israel. The same privacy contact handles Protection of Privacy Law matters, including requests from data subjects that reach us and correspondence with the Privacy Protection Authority.
The privacy contact is privacy@rushhourapp.com. Security matters go to security@rushhourapp.com, and legal notices to legal@rushhourapp.com.
Liability
- Each party's liability under this DPA is subject to the exclusions and limitations of liability in the Terms of Service and in your order form.
- Those limits are aggregate. Claims under this DPA and claims under the rest of the Agreement count together against the same cap; this DPA does not create a second one.
- Nothing in this DPA or in the Terms limits liability that cannot be limited by law. That includes a data subject's rights under Article 82 of the GDPR and under Clause 12 of the Standard Contractual Clauses, and liability for death or personal injury caused by negligence, or for fraud.
- Where the Standard Contractual Clauses apply and their liability terms conflict with this section, the Clauses prevail between the parties for the transfers they govern.
Governing law and dispute resolution for this DPA follow the Terms of Service, except that the Standard Contractual Clauses are governed by the law and the courts named in the table above for the matters they cover, and except where mandatory local law in your country provides otherwise.
Term, precedence and changes
- Term. This DPA takes effect when you accept the Terms of Service or sign an order form, and it continues for as long as we process Customer Personal Data for you. The sections on confidentiality, deletion, liability and transfers survive it.
- Precedence. On the processing of personal data, this DPA prevails over the Terms of Service and over the Privacy Policy. Where the Standard Contractual Clauses apply, they prevail over this DPA. A data processing agreement we have separately negotiated and signed with you prevails over this one.
- Changes. We may update this DPA - when the law changes, or when we improve a commitment. We will update the version number and the dates at the top of this page. For a material change to this DPA we will give you at least 30 days' notice by email to the address on your account, and we will not make a change that reduces your protection during your current term without your agreement. A change to the sub-processor list is not a change to this DPA: it is notified through the sub-processor page as described above, and no notice period applies to it.
- Previous versions. Superseded versions are listed in our legal archive, and you can request a copy of any of them from legal@rushhourapp.com.
- Severability. If a provision of this DPA is held unenforceable, it is modified to the minimum extent needed to make it enforceable, or severed if it cannot be, and the rest remains in force.
How to get a signed copy
This DPA binds us without a signature. If your procurement or legal process needs a countersigned document, email privacy@rushhourapp.com with:
- your full legal entity name, registered address and company or registration number;
- the name, title and email address of the person who will sign for you;
- whether you act as a controller, or as a processor for someone else, so that we complete the right Standard Contractual Clauses module;
- the countries your data subjects are in, so that we complete Annex I.C correctly;
- the RushHour account or order form the copy relates to.
We will return a countersigned PDF, with the Standard Contractual Clauses and the annexes completed for your entity, within 10 business days. If you would rather we reviewed your own DPA or transfer paperwork, send it to the same address and we will come back to you with comments.
Rush Hour Logistics System Inc
1272 54th Street, Brooklyn, NY 11219, USA
New York Department of State ID: 5098884
Privacy and data protection: privacy@rushhourapp.com
Security: security@rushhourapp.com
Legal notices: legal@rushhourapp.com, or by post to the address above, marked "Legal"
Related documents: the Terms of Service, the Privacy Policy, the sub-processor list and the legal archive.