Courier Passport

Legal

Partner data processing addendum

Last updated 15 September 2026. This page is a template for solicitor review and is not legal advice.

Execute this addendum before we issue live API keys.

Parties: Courier Drivers (“us”) and the partner business (“you”).

Roles

When you look up a passport, you are an independent controller of the status you receive. We are controller of the underlying driver records. This DPA covers any processing we do on your instructions (for example delivering webhooks to your endpoint).

Subject matter

Passport number, overall status, issue/expiry dates, and a required-check summary (type, status, dates, evidence strength, DBS result band). No identity images, no DVLA payloads, no DBS files.

Instructions

We will only send lookup results and webhooks to endpoints you configure. You will not request, and we will not provide, prohibited document dumps.

Security

TLS in transit; API keys hashed at rest; rate limits; audit of lookups; encrypted document store for driver uploads. You must store API keys in a secrets manager, not in client-side apps.

Sub-processors

Hosting, identity provider, DVLA commercial enquiry, DBS umbrella, occupational-health provider (if used). We will give notice of material changes.

International transfers

UK adequacy or UK IDTA / EU SCCs plus UK addendum.

Breach

Notify without undue delay, and within 72 hours of becoming aware of a personal-data breach affecting partner lookups.

Deletion

On termination, revoke API keys. Historical lookup audit retained as in our privacy notice. You delete cached status.

Cookies

Partner dashboards use the same strictly necessary session storage described in our cookie policy. We do not set advertising cookies on lookups.

Governing law

England and Wales.