DPA

Data Processing Addendum

This Data Processing Addendum (DPA) forms part of the Terms of Service between Ruty and the customer that operates a workspace. It applies whenever Ruty processes personal data on the customer's behalf.

Last updated: June 22, 2026

Roles

The customer is the data controller (or, where applicable, the responsable del tratamiento under Mexican law, or the controlling organization under PIPEDA). Ruty is the data processor and acts only on the documented instructions of the customer, which include using the Ruty application as designed.

Scope of processing

Ruty processes personal data about the customer's end users (dispatch staff, drivers, freight customers, and their contacts) for the duration of the subscription. Processing activities include storage, retrieval, transmission of tracking notifications, generation of ETAs, and generation of customer-facing replies through the AI gateway. Categories of data are described in the Privacy Policy.

Sub-processing

The customer authorizes Ruty to engage the sub-processors listed at /subprocessors. Ruty will give reasonable notice of new sub-processors and remains responsible for their performance.

Security

Ruty implements administrative, physical, and technical safeguards designed to protect personal data against unauthorized access, disclosure, alteration, or destruction, including encryption in transit, row-level security in the database, scoped access tokens, audit logging of privileged operations, and least-privilege service credentials.

Data subject requests

Ruty will assist the customer in responding to verified data-subject requests (access, correction, deletion, portability, objection) by providing the tools and information reasonably necessary to fulfill those requests. The customer is primarily responsible for responding to its own end users.

Incident notification

If Ruty becomes aware of a personal-data breach affecting the customer's workspace, Ruty will notify the customer without undue delay and provide the information reasonably needed to meet the customer's notification obligations under applicable law.

International transfers

Personal data is processed in the United States. Where transfers from Canada or Mexico require contractual safeguards, the parties rely on the protections in this DPA, the customer's consent collected at signup, and the contractual protections Ruty has in place with its sub-processors.

Return or deletion

On termination of the subscription, Ruty will, on written request, delete or return the customer's personal data within a commercially reasonable period, subject to backup-retention windows and legal-retention requirements.

Acceptance

This DPA is accepted automatically when an authorized representative of the customer creates or administers a Ruty workspace. A counter-signed copy is available on request for enterprise customers.

This page is app-owned editable content provided for transparency. It is not legal advice. For binding legal questions, consult qualified counsel in your jurisdiction.