Skip to main content

How Mobaro complies with GDPR

Mobaro's role as your GDPR data processor: the Data Processing Agreement, where your data is hosted, and how sub-processors are managed.

Written by Logan Bowlby

Overview

The EU General Data Protection Regulation (GDPR) sets rules for handling personal data of people in the EU. When your organization uses Mobaro, you are the data controller for the personal data in your Mobaro account, and Mobaro A/S is your data processor: Mobaro processes that data to provide the service, on your instructions.

This article covers Mobaro's side as your processor: the Data Processing Agreement, where data is hosted, and sub-processors. For finding, exporting, correcting and deleting personal data in your account, see EU Data Protection/GDPR.

At a glance

Who can do this

Your organization, as a Mobaro Subscriber, can request the DPA

Where

Works on

All Mobaro services: Backend (web), Mobile app, RideOps and Public API

Availability

All organizations


Data Processing Agreement

Mobaro's Data Processing Agreement (DPA) sets out the terms under which Mobaro processes personal data for you as your processor. To enter into Mobaro's DPA, email [email protected].

For questions about the DPA's terms, such as international transfers, contact [email protected] or your Customer Success Manager. This Help Center doesn't replace the DPA or your agreement with Mobaro.


Where your data is hosted

Mobaro's production systems are located in Europe, on Microsoft Azure. Mobaro controls access to the infrastructure that hosts your data.

Some features use service-specific sub-processors that access your data, and some of them store it outside Europe — for example, email delivery for notifications and reports is stored in the US. The current list, with each provider's purpose and storage location, is in Sub Processors and Sub Contractors.

ℹ️ Note: There's no setting in Mobaro to choose a hosting region. If your organization has specific data-residency requirements, talk to your Customer Success Manager before you go live.


Sub-processors

Mobaro uses sub-processors — third parties, and members of the Mobaro Group, that may access or process your data — to provide the service. Mobaro requires them to meet obligations equivalent to Mobaro's own under the DPA.

Sub Processors and Sub Contractors is the up-to-date list and explains how Mobaro announces new sub-processors. Customers who have signed the DPA can object to a new sub-processor in writing, with their reasons, within 30 days of the list being updated.


Your part as controller

As controller, your organization decides which personal data goes into Mobaro — user profiles, who completed each Checklist, photos and free text. When someone asks your organization about their personal data, EU Data Protection/GDPR shows how to find, export, correct and remove it in your account, and what each action leaves in place.


Frequently asked questions

Where is my data stored?

In Europe, with some exceptions. Mobaro's production systems run on Microsoft Azure in Europe. Some service-specific sub-processors, such as email delivery, store data in the US; each one's storage location is listed in Sub Processors and Sub Contractors.

Who runs your servers?

Microsoft Azure provides the infrastructure; Mobaro runs the service on it and controls access to it. Azure is listed as Mobaro's infrastructure sub-processor in Sub Processors and Sub Contractors.

Can I choose which region my data is stored in?

No. There's no region setting in Mobaro, and Mobaro's production systems are in Europe. If you have data-residency requirements, discuss them with your Customer Success Manager.

Did this answer your question?