Legal
Partner data processing addendum
Last updated 15 September 2026. This page is a template for solicitor review and is not legal advice.
Execute this addendum before we issue live API keys.
Parties: Courier Drivers (“us”) and the partner business (“you”).
Roles
When you look up a passport, you are an independent controller of the status you receive. We are controller of the underlying driver records. This DPA covers any processing we do on your instructions (for example delivering webhooks to your endpoint).
Subject matter
Passport number, overall status, issue/expiry dates, and a required-check summary (type, status, dates, evidence strength, DBS result band). No identity images, no DVLA payloads, no DBS files.
Instructions
We will only send lookup results and webhooks to endpoints you configure. You will not request, and we will not provide, prohibited document dumps.
Security
TLS in transit; API keys hashed at rest; rate limits; audit of lookups; encrypted document store for driver uploads. You must store API keys in a secrets manager, not in client-side apps.
Sub-processors
Hosting, identity provider, DVLA commercial enquiry, DBS umbrella, occupational-health provider (if used). We will give notice of material changes.
International transfers
UK adequacy or UK IDTA / EU SCCs plus UK addendum.
Breach
Notify without undue delay, and within 72 hours of becoming aware of a personal-data breach affecting partner lookups.
Deletion
On termination, revoke API keys. Historical lookup audit retained as in our privacy notice. You delete cached status.
Cookies
Partner dashboards use the same strictly necessary session storage described in our cookie policy. We do not set advertising cookies on lookups.
Governing law
England and Wales.