FastLane Ops

Data Processing Addendum

The terms governing FastLane Ops processing of Customer Personal Data.

Effective Date: 09/21/2026Last Updated: 09/21/2026

This Data Processing Addendum ("DPA") is incorporated into, and forms part of, the FastLane Ops Terms & Conditions between Kira & Company ("FastLane Ops," "we," "us") and the Customer that has accepted those Terms ("Customer," "you"). This DPA applies whenever FastLane Ops processes Personal Data on Customer's behalf in the course of providing the Service. Capitalized terms not defined here have the meaning given in the Terms.

1. Definitions

“Personal Data” means information relating to an identified or identifiable individual that Customer submits to, or collects through, the Service — for example, a shop's customer's name, contact information, or vehicle and service history.

“Processing” means any operation performed on Personal Data, such as collection, storage, use, or deletion.

“CCPA” means the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and its implementing regulations.

“GDPR” means the General Data Protection Regulation (EU) 2016/679, and, where applicable, the UK GDPR.

“Subprocessor” means a third party FastLane Ops engages to process Personal Data in providing the Service.

“Security Incident” means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.

2. Roles of the Parties

As between the parties, Customer is the “business” (or, where applicable, “controller”) with respect to Personal Data it submits to the Service, and determines the purposes and means of processing that Personal Data through its use of the Service. FastLane Ops is Customer's “service provider” or “contractor” under the CCPA, and, to the extent GDPR applies, a “processor” acting only on Customer's documented instructions as set out in this DPA and the Terms.

3. Scope & Details of Processing

Subject matter: FastLane Ops's hosting and processing of Personal Data to provide the Service.

Duration: for the term of the Terms, plus any post-termination access and retention period described there.

Nature and purpose: providing, securing, supporting, and improving the FastLane Ops service-lane management platform.

Categories of data subjects: Customer's own customers (e.g., vehicle owners), and Customer's authorized users (employees or contractors).

Types of Personal Data: names, contact details (phone, email, address), vehicle and service/repair records, appointment and communication history, and billing information Customer chooses to store in the Service.

4. Customer Instructions

FastLane Ops will process Personal Data only to provide the Service in accordance with the Terms, this DPA, and Customer's documented instructions given through use of the Service's ordinary features and configuration. FastLane Ops will notify Customer if it believes an instruction violates applicable data protection law, and may decline to follow an instruction it reasonably believes is unlawful.

5. Confidentiality of Personnel

FastLane Ops will ensure that personnel authorized to process Personal Data are subject to a duty of confidentiality, whether contractual or statutory.

6. Security Measures

FastLane Ops maintains reasonable administrative, technical, and physical safeguards appropriate to the nature of the Personal Data and the risks of its processing, designed to protect against unauthorized access, disclosure, alteration, or destruction. Where GDPR applies, these measures are intended to satisfy the risk-based security obligations of Article 32.

7. Subprocessors

Customer authorizes FastLane Ops to engage the Subprocessors listed in Exhibit A to process Personal Data in connection with the Service. FastLane Ops will impose data protection obligations on each Subprocessor that are substantially similar to those in this DPA, and will remain responsible for each Subprocessor's performance. If FastLane Ops adds or replaces a Subprocessor with access to Personal Data, it will provide reasonable advance notice (for example, by email), and Customer may object on reasonable data-protection grounds by contacting FastLane Ops within a reasonable time after notice; the parties will work in good faith to resolve the objection.

8. Assistance with Data Subject & Consumer Requests

Taking into account the nature of the processing, FastLane Ops will provide Customer with reasonable assistance — through Service functionality or otherwise — to help Customer respond to requests from individuals to exercise their rights under applicable data protection law, such as requests to access, correct, or delete Personal Data. If FastLane Ops receives such a request directly, it will not respond directly (except to confirm receipt) and will promptly forward the request to Customer.

9. CCPA-Specific Terms

With respect to Personal Data subject to the CCPA, FastLane Ops will: (a) not sell or share Personal Data; (b) not retain, use, or disclose Personal Data for any purpose other than the business purposes specified in the Terms and this DPA, or as otherwise permitted by the CCPA; (c) not retain, use, or disclose Personal Data outside the direct business relationship between FastLane Ops and Customer; (d) not combine Personal Data with personal information FastLane Ops receives from other sources, except as permitted by the CCPA; and (e) notify Customer if FastLane Ops determines it can no longer meet its obligations as a service provider or contractor under the CCPA.

10. GDPR-Specific Terms (Where Applicable)

To the extent GDPR applies to the processing of Personal Data under the Terms, FastLane Ops will: process Personal Data only on Customer's documented instructions, including regarding international transfers, unless required to do otherwise by law; ensure personnel are bound by confidentiality; implement Article 32 security measures; engage Subprocessors as described in Section 7; assist Customer with data subject rights requests and, taking into account the information available to FastLane Ops, with Customer's obligations under GDPR Articles 32–36; make available information reasonably necessary to demonstrate compliance with this Section and allow for audits as described in Section 12; and, at Customer's choice, delete or return Personal Data at the end of the provision of the Service, subject to Section 11 of the Terms and any legal retention requirements. Where Personal Data is transferred outside the European Economic Area or United Kingdom, the parties will implement an appropriate transfer mechanism recognized under GDPR (such as Standard Contractual Clauses) if required.

11. Security Incident Notification

FastLane Ops will notify Customer without undue delay after becoming aware of a Security Incident affecting Personal Data, consistent with Section 14 of the Terms, and will provide information reasonably available to it about the incident's nature, scope, and any remediation steps taken. Notifying affected individuals, regulators, or other third parties remains Customer's responsibility as the business/controller, except where FastLane Ops is independently required by law to provide such notice; FastLane Ops will reasonably cooperate with Customer's response.

12. Audits & Compliance Information

FastLane Ops will make available information reasonably necessary to demonstrate compliance with this DPA. If Customer reasonably requires an audit to verify compliance — including to satisfy a regulator or an applicable legal requirement — the parties will discuss a mutually agreeable approach, which may include a summary of FastLane Ops's security practices, a third-party audit report if available, or a mutually scheduled review, conducted in a manner that avoids unnecessary disruption to FastLane Ops's business and other customers' data.

13. Deletion or Return of Data

Deletion, export, and retention of Personal Data following termination are governed by Section 11 of the Terms (locked, read-only export access, followed by deletion from active systems, subject to legally required retention and routine backup handling as described there).

14. Liability

Each party's liability arising out of or relating to this DPA is subject to the limitations and exclusions in the Terms, including Section 21 (Limitation of Liability), as if fully set out here.

15. Term; Order of Precedence

This DPA remains in effect for as long as FastLane Ops processes Personal Data on Customer's behalf under the Terms. If there is a conflict between this DPA and the Terms regarding the processing of Personal Data, this DPA controls, consistent with Section 28 of the Terms.