MarketCheck
API Docs MCP Pricing

Legal

Data Processing Agreement

v1.2 · Last updated Sep 08, 2026

1. DEFINITIONS AND INTERPRETATION

1.1 In this DPA, the following terms have the meanings set out below:

(a)      “Controller” means the natural or legal person that determines the purposes and means of the Processing of Personal Data; for the purposes of this DPA, the Customer.

(b)      “Customer” means the entity that has agreed to the Terms of Service and that acts as the Controller (as defined in Section 1.1(a)) for the purposes of this DPA.

(c)      “Data Protection Laws” means the UK GDPR, the Data Protection Act 2018, Part 5 of the Data (Use and Access) Act 2025, and any other applicable legislation relating to the protection of Personal Data, in each case as amended, updated, or replaced from time to time.

(d)      “Data Subject” means an identified or identifiable natural person to whom Personal Data relates.

(e)      “DPA” means this Data Processing Agreement.

(f)      “MarketCheck” means Market Check Cars, Inc., a Nevada corporation.

(g)      “Personal Data” means any information relating to a Data Subject that is Processed by MarketCheck solely as a Processor on behalf of the Customer in connection with the Service, and expressly excludes any Personal Data that MarketCheck Processes as a Controller for its own business purposes.

(h)      “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.

(i)      “Processing” (and “Process”) means any operation performed on Personal Data, as defined in the UK GDPR.

(j)      “Service” means the MarketCheck Developer Platform and associated APIs as described in the Terms of Service.

(k)      “Sub-Processor” means any third party engaged by MarketCheck to Process Personal Data on behalf of the Customer.

(l)      “Supervisory Authority” means the Information Commissioner’s Office (or its successor body, the Information Commission, established under the Data (Use and Access) Act of 2025) or any other competent data protection authority.

(m)      “Terms of Service” means the MarketCheck Developer Platform API Terms of Service at developers.marketcheck.com.

(n)      “UK GDPR” means the United Kingdom General Data Protection Regulation as defined in the Data Protection Act 2018.

1.2 Terms not defined in this DPA have the meanings given to them in the Terms of Service or, where applicable, in Data Protection Laws. References to “Articles” are to articles of the UK GDPR unless stated otherwise. Words in the singular include the plural and vice versa.

2. SCOPE AND RELATIONSHIP OF THE PARTIES

2.1 This DPA applies to the extent that MarketCheck Processes Personal Data on behalf of the Customer in connection with the Service. Where no Personal Data is processed, this DPA imposes no obligations on either party.

2.2 The Customer is the Controller and MarketCheck is the Processor with respect to Personal Data processed under this DPA. Each party shall comply with its respective obligations under Data Protection Laws in that capacity. As Controller, the Customer is solely responsible for determining the purposes and means of the Processing and for discharging all Controller obligations under Data Protection Laws. The Customer represents and warrants that it has, and will maintain throughout the term, a valid lawful basis for the Processing, and that it has provided all privacy notices and obtained all consents, permissions, and authorizations necessary for MarketCheck lawfully to Process the Personal Data in accordance with this DPA and the Customer’s documented instructions.

2.3 The subject matter, duration, nature and purpose of Processing, the types of Personal Data processed, and the categories of Data Subjects are described in Annex 1 (Details of Processing).

2.4 Nothing in this DPA prevents MarketCheck from processing Personal Data for which MarketCheck is itself a Controller (including for example, account registration data, usage, telemetry, and log data, and other data Processed for MarketCheck’s own legitimate business purposes, such as billing and account management, service operation and analytics, security, fraud prevention and abuse detection, and product development and improvement). MarketCheck may further compile, generate, and use aggregated, de-identified, or anonymised data derived from the Service for any lawful business purpose, provided that such data does not directly identify the Customer or any Data Subject. Any such Processing is carried out by MarketCheck as an independent Controller, is governed by MarketCheck’s own privacy policy and not by this DPA, and shall comply with Data Protection Laws.

3. PROCESSING INSTRUCTIONS AND RESTRICTIONS

3.1 MarketCheck shall process Personal Data only on the Customer’s documented instructions, unless required to do so by applicable law. The Terms of Service, this DPA, and Annex 1 constitute the Customer’s initial documented instructions. The Customer may issue additional written instructions consistent with the terms of this DPA. MarketCheck may charge the Customer its reasonable costs from implementing any instruction that requires configuration, development, or effort beyond the standard configuration of the Service, provided that MarketCheck notifies the Customer of such costs in advance. MarketCheck shall not be liable for any loss, cost, or consequence arising from Processing carried out in accordance with the Customer’s documented instructions.

3.2 MarketCheck shall not process Personal Data for any purpose other than as necessary to provide the Service in accordance with the Customer’s documented instructions.

3.3 If MarketCheck is required by applicable law to process Personal Data other than on the Customer’s instructions, MarketCheck shall inform the Customer of that legal requirement before carrying out the relevant Processing, unless the applicable law prohibits such notification on important grounds of public interest.

3.4 MarketCheck shall immediately inform the Customer if, in MarketCheck’s reasonable opinion, an instruction from the Customer infringes Data Protection Laws or is inconsistent with, or conflicts with, the ordinary operation or technical configuration of the Service. MarketCheck shall not be required to carry out any such instruction until the Customer has confirmed or modified it in writing. MarketCheck shall not be liable for any delay in Processing resulting from compliance with this Section 3.4. MarketCheck shall have no liability to the Customer arising from acting on, or declining to act on, any instruction that conflicts with the ordinary operation or technical configuration of the Service, and any resulting degradation, interruption, or non-availability of the Service shall not constitute a breach of this DPA or the Terms of Service by MarketCheck.

4. CONFIDENTIALITY

4.1 MarketCheck shall ensure that any person it authorizes to process Personal Data under this DPA is subject to an appropriate obligation of confidentiality, whether by contract or by operation of law.

4.2 MarketCheck shall ensure that access to Personal Data is limited to those persons who require such access for the performance of the Service and who have been informed of the confidential nature of the Personal Data.

4.3 The obligations set out in this Section 4 shall survive the termination or expiry of this DPA and the Terms of Service for so long as MarketCheck or any of its personnel retains Personal Data.

5. SECURITY MEASURES

5.1 MarketCheck shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk of Processing, taking into account the state of the art, the costs of implementation, and the factors set out in Section 5.2, and in accordance with Article 32 of the UK GDPR. Such measures represent a reasonable, risk-based standard appropriate to the risk and shall not be construed as a guarantee that Personal Data will be secure against all Personal Data Breaches. Such measures are described in Annex 2 to this DPA.

5.2 In assessing the appropriate level of security, MarketCheck shall take into account:

(a) the state of the art of available security technologies;

(b) the costs of implementation;

(c) the nature, scope, context, and purposes of Processing; and

(d) the risk of varying likelihood and severity for the rights and freedoms of Data Subjects, including the risks of accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.

5.3 MarketCheck shall regularly test, assess, and evaluate the effectiveness of its technical and organizational measures to ensure the ongoing security of Processing.

5.4 MarketCheck may, from time to time and at its discretion, update or modify the measures described in Annex 2 without the Customer’s prior consent, provided that any such update or modification does not materially reduce the overall level of protection afforded to Personal Data. MarketCheck shall notify the Customer promptly of any material change to such measures.

5.5 The Customer is responsible for the security of Personal Data within its own systems, applications, networks, and API integrations, including the secure configuration and use of the Service, the safeguarding of its API keys and access credentials, and the security of any Personal Data once it has been transmitted to or received by the Customer. MarketCheck shall not be responsible for any Personal Data Breach to the extent arising from the Customer’s systems, integrations, or failure to implement appropriate security measures within its own environment.

6. SUB-PROCESSORS

6.1 General Authorization. The Customer provides a general written authorization for MarketCheck to engage Sub-Processors to process Personal Data on the Customer’s behalf in connection with the Service.

6.2 Sub-Processor List. MarketCheck shall maintain a current list of Sub-Processors at developers.marketcheck.com/sub-processors, specifying each Sub-Processor’s name, location, and description of processing activities.

6.3 Notification of Changes. MarketCheck shall notify the Customer at least 30 days before engaging any new Sub-Processor or replacing an existing Sub-Processor. Notification shall be provided by email to the address associated with the Customer’s account or by posting an update to the Sub-Processor list.

6.4 Right to Object. The Customer may object to a new or replacement Sub-Processor by notifying MarketCheck in writing within 30 days of receiving notice. If the Customer raises a reasonable objection, MarketCheck shall use commercially reasonable efforts to make available an alternative arrangement. If no resolution is reached within 30 days of the objection, the Customer’s sole and exclusive remedy shall be to terminate the affected portion of the Service, and the Customer shall have no right to claim damages or any other remedy against MarketCheck in connection with such objection.

6.5 Flow-Down Obligations. MarketCheck shall impose on each Sub-Processor, by way of a written contract, data protection obligations no less protective than those set out in this DPA.

6.6 Liability. MarketCheck shall be liable to the Customer for the performance of each Sub-Processor’s obligations under this Section 6 only to the same extent that MarketCheck would be liable for its own acts or omissions under this DPA, and in no event shall MarketCheck’s liability for any Sub-Processor exceed its own direct liability. Any such liability shall in all cases be subject to the limitations and exclusions of liability set out in the Terms of Service.

7. DATA SUBJECT RIGHTS

7.1 MarketCheck shall, taking into account the nature of the Processing, assist the Customer by appropriate technical and organizational measures, insofar as this is technically possible and reasonable given the nature of the Processing, in fulfilling the Customer’s obligations to respond to requests from Data Subjects exercising their rights under Data Protection Laws (including rights of access, rectification, erasure, restriction, portability, and objection).

7.2 MarketCheck shall promptly notify the Customer if it receives a request from a Data Subject in respect of Personal Data processed under this DPA. MarketCheck shall not respond to any such request directly, and shall not be obligated to do so, unless expressly authorized in writing by the Customer or required to do so by applicable law. The Customer shall remain solely responsible for assessing, determining, and providing the substantive response to any such request.

7.3 Where MarketCheck is required by applicable law to respond to a Data Subject request, MarketCheck shall inform the Customer of that legal requirement before responding, unless prohibited by law from doing so.

7.4 The Customer shall reimburse MarketCheck for all reasonable costs and expenses (including staff time at MarketCheck’s then-current rates) incurred in providing any assistance under this Section 7, save only to the extent such assistance forms part of MarketCheck’s ordinary operation of the Service.

8. BREACH NOTIFICATION

8.1 MarketCheck shall notify the Customer without undue delay after confirming a reportable Personal Data Breach affecting Personal Data processed on behalf of the Customer. MarketCheck’s initial notification is provided for the Customer’s information and shall not constitute an acknowledgment or admission by MarketCheck of any fault, liability, or wrongdoing.

8.2 The notification shall include, to the extent then reasonably available to MarketCheck at the time of notification:

(a)      a description of the nature of the Personal Data Breach, including (where possible) the categories and approximate number of Data Subjects and Personal Data records concerned;

(b)      the name and contact details of MarketCheck’s point of contact from whom further information may be obtained;

(c)      a description of the likely consequences of the Breach; and

(d)      a description of the measures taken or proposed to address the Breach, including measures to mitigate its possible adverse effects.

8.3 Where it is not possible to provide all information at the time of the initial notification, MarketCheck shall provide the remaining information in phases without undue delay as it becomes available.

8.4 MarketCheck shall cooperate with the Customer and take reasonable steps as directed by the Customer to assist in the investigation, mitigation, and remediation of the Breach and in meeting the Customer’s obligations under Data Protection Laws, including any notification obligations to Supervisory Authorities or Data Subjects. The Customer shall reimburse MarketCheck for any reasonable costs incurred in providing assistance under this Section 8.4 to the extent such assistance is extensive or requires effort beyond what is necessary for MarketCheck’s ordinary operation of the Service.

9. DATA PROTECTION IMPACT ASSESSMENTS AND PRIOR CONSULTATION

9.1 To the extent that the Customer’s Processing of Personal Data under or in connection with the Service requires a data protection impact assessment (as described in Article 35 of the UK GDPR) or prior consultation with a Supervisory Authority (as described in Article 36 of the UK GDPR), MarketCheck shall provide the Customer with reasonable assistance in conducting such assessment or consultation.

9.2 Such assistance shall include, where applicable, providing the Customer with information regarding MarketCheck’s Processing activities, technical and organizational measures, and Sub-Processor arrangements, to the extent reasonably necessary for the Customer to complete the relevant assessment or consultation.

9.3 The Customer shall submit any request for assistance under this Section 9 in writing with reasonable advance notice. MarketCheck may charge the Customer its reasonable costs incurred in providing assistance under this Section 9, provided that MarketCheck notifies the Customer of such costs in advance. MarketCheck shall not be obligated to commence any assistance under this Section 9 until the Customer has confirmed in writing its agreement to bear MarketCheck’s estimated reasonable costs.

10. COMPLAINTS HANDLING

10.1 The Customer acknowledges that, to the extent required by the Data (Use and Access) Act 2025 (Part 5) or other applicable Data Protection Laws, it is responsible for facilitating and resolving complaints from Data Subjects regarding the Processing of their Personal Data.

10.2 The Customer shall, in respect of any Data Subject complaint received:

(a)      acknowledge receipt of the complaint to the Data Subject within 30 days of receipt;

(b)      take all reasonable steps to resolve the complaint without undue delay; and

(c)      inform the Data Subject of the progress and outcome of the complaint.

10.3 MarketCheck shall, taking into account the nature of the Processing, provide reasonable assistance to the Customer in fulfilling the obligations set out in Section 10.2. Such assistance may include promptly providing relevant information held by MarketCheck, cooperating with the Customer’s investigation of the complaint, and implementing any remedial measures agreed between the parties. The Customer shall reimburse MarketCheck for any reasonable costs incurred in providing assistance under this Section 10, to the extent that such assistance requires efforts beyond MarketCheck’s ordinary operation of the Service, provided that MarketCheck notifies the Customer of such costs in advance.

10.4 MarketCheck shall promptly notify the Customer if it receives a complaint directly from a Data Subject relating to the Processing of Personal Data under this DPA, and shall not respond to such complaint except as instructed by the Customer or as required by applicable law. For the avoidance of doubt, MarketCheck’s obligation under this Section 10.4 is limited to forwarding the complaint and notifying the Customer, and MarketCheck shall have no obligation to substantively respond to, investigate, or resolve any such complaint.

11. INTERNATIONAL DATA TRANSFERS

11.1 MarketCheck shall not transfer Personal Data from the United Kingdom to any country that does not benefit from an adequacy decision under Data Protection Laws unless an approved transfer mechanism is in place.

11.2 To the extent MarketCheck transfers Personal Data from the United Kingdom to the United States in connection with the Service, the parties shall rely on one of the following transfer safeguards, as applicable:

(a) the UK International Data Transfer Agreement (IDTA) issued by the Information Commissioner under section 119A of the Data Protection Act 2018; or

(b) the UK Addendum to the EU Standard Contractual Clauses, as approved by the Information Commissioner.

11.3 The applicable transfer safeguard identified in Section 11.2 is incorporated into this DPA by reference. Where required, the parties shall execute the relevant instrument separately.

11.4 Before relying on any transfer safeguard under Section 11.2, MarketCheck shall complete, and make available to the Customer on the Customer’s reasonable written request, a Transfer Risk Assessment evaluating the laws and practices of the destination country to confirm that the transfer safeguard provides appropriate protection for the Personal Data; provided that MarketCheck shall not be required to disclose any confidential, proprietary, or commercially sensitive information (including detailed descriptions of its security architecture or measures), and may satisfy this obligation by providing a summary of the relevant findings.

11.5 If a change in applicable law or regulatory guidance renders the transfer safeguard relied upon under Section 11.2 invalid or insufficient, the parties shall cooperate in good faith to implement an alternative lawful transfer mechanism without undue delay. Any such change in applicable law or regulatory guidance that is beyond MarketCheck’s reasonable control shall not constitute a breach of this DPA by MarketCheck, and shall not by itself give the Customer the right to terminate this DPA or the Service, provided that MarketCheck continues to cooperate in good faith as set out in this Section 11.5.

12. AUDITS AND COMPLIANCE

12.1 MarketCheck shall make available to the Customer all information reasonably necessary to demonstrate compliance with the obligations set out in Article 28 of the UK GDPR and this DPA.

12.2 MarketCheck shall permit and contribute to audits and inspections conducted by the Customer or a qualified third-party auditor mandated by the Customer, subject to the following conditions:

(a) the Customer shall provide MarketCheck with at least thirty (30) days’ prior written notice of any proposed audit;

(b) audits may be conducted no more than once in any twelve (12) month period, unless required by a Supervisory Authority or triggered by a Personal Data Breach;

(c) the Customer shall bear the costs of any audit; provided that MarketCheck’s obligation to cooperate with and support any single audit shall be subject to a cap of GBP £25,000 in accordance with Section 14 of the Terms of Service;

(d) audits shall be conducted during normal business hours and in a manner that minimizes disruption to MarketCheck’s operations; and

(e) any third-party auditor shall be bound by written confidentiality obligations no less protective than those set out in this DPA.

12.3 Where MarketCheck engages an independent third-party auditor to conduct a relevant certification audit or security assessment, MarketCheck may satisfy an audit request under Section 12.2 by providing the Customer with a copy of the resulting audit report or certification, provided that such report or certification is no more than twelve (12) months old and addresses the matters relevant to the Customer’s request.

13. DATA RETENTION AND DELETION

13.1 Upon termination or expiry of the Terms of Service, MarketCheck shall, at the Customer’s written election, either: (a) return all Personal Data to the Customer in a commonly used, machine-readable format; or (b) delete all Personal Data in MarketCheck’s possession or control, including all existing copies. The Customer shall communicate its election in writing within thirty (30) days following termination or expiry. If the Customer does not provide instructions within that period, MarketCheck shall delete all Personal Data.

13.2 MarketCheck shall complete the return or deletion of Personal Data within sixty (60) days of receiving the Customer’s instruction (or, where no instruction is received, within sixty (60) days of the expiry of the period specified in Section 13.1).

13.3 MarketCheck may retain Personal Data (i) to the extent, and for the period, required by applicable law; (ii) in backups and archives generated in the ordinary course of business, until such copies are overwritten or deleted in accordance with MarketCheck’s standard backup and retention cycles; and (iii) in aggregated, de-identified, or anonymised form that does not identify the Customer or any Data Subject. Where such retention is required, MarketCheck shall: (a) notify the Customer of the legal requirement; (b) limit Processing to the purposes mandated by that law; and (c) continue to apply the security measures set out in Section 5 and Annex 2 to any retained Personal Data.

13.4 This Section 13 is consistent with, and supplements, Section 9.3 of the Terms of Service. MarketCheck shall provide written certification of deletion upon the Customer’s reasonable written request.

14. TERM, LIABILITY, AND GENERAL PROVISIONS

14.1 Term. This DPA shall commence on the date the Customer accepts the Terms of Service and shall remain in effect for so long as the Terms of Service remain in force. Upon expiry or termination of the Terms of Service, this DPA shall automatically terminate, subject to Section 13 (Data Retention and Deletion) and any provisions that by their nature survive termination.

14.2 Liability. Each party’s liability arising out of or in connection with this DPA (including its Annexes) shall be subject to the limitations and exclusions of liability set out in the Terms of Service. For the avoidance of doubt, this DPA (including its Annexes) does not create, and shall not be construed to create, any liability for MarketCheck greater than, or in addition to, MarketCheck’s liability under the Terms of Service, and all liability arising out of or in connection with this DPA shall count toward, and in no event exceed, the aggregate limitations of liability set out in the Terms of Service. Nothing in this Section 14.2 shall limit either party’s liability for breaches of Data Protection Laws to the extent such limitation is prohibited by applicable law.

14.3 Conflict. In the event of any conflict or inconsistency between this DPA and the Terms of Service with respect to the Processing of Personal Data, this DPA shall prevail.

14.4 Order of Precedence, Governing Law, and Jurisdiction.

(a) Order of Precedence: In the event of any conflict, ambiguity, or inconsistency between the terms of the main Terms of Service and this DPA, the provisions of this DPA shall prevail solely with respect to the processing of Personal Data.

(b) Governing Law and Jurisdiction: This DPA and any non-contractual obligations arising out of or in connection with it shall be governed by, and construed in accordance with, the laws of England and Wales. The parties irrevocably submit to the exclusive jurisdiction of the courts of England and Wales to resolve any dispute or claim arising out of or in connection with this DPA, notwithstanding any conflicting choice of law or jurisdiction specified in the Terms of Service, and without prejudice to any mandatory provisions of applicable Data Protection Laws.

14.5 Amendments. MarketCheck may update this DPA from time to time to reflect changes in Data Protection Laws or Processing activities. The current version will be posted at developers.marketcheck.com/dpa. Material changes will be notified to the Customer in accordance with the notice provisions of the Terms of Service.

14.6 Version and Effective Date. This DPA is version v1.2, last updated September 8, 2026.

ANNEX 1: DETAILS OF PROCESSING

This Annex 1 forms part of the DPA and describes the Processing carried out by MarketCheck as Processor on behalf of the Customer as Controller.

ElementDescription
Subject matter of ProcessingProcessing of Personal Data in connection with MarketCheck’s provision of the Service under the Terms of Service.
Duration of ProcessingThe term of the Terms of Service, unless otherwise required by applicable law.
Nature and purpose of ProcessingProviding automotive data via REST API and related delivery mechanisms; processing API requests containing or returning Personal Data; maintaining Customer accounts on the Developer Platform; generating usage analytics.
Types of Personal DataDealer contact details (names, email addresses, phone numbers); end-user identifiers transmitted via API calls; account holder and authorized user information; IP addresses and usage metadata.
Categories of Data SubjectsDealership personnel whose contact information is included in MarketCheck Data; end users of Customer’s applications whose identifiers are transmitted through API calls; Customer’s account holders and authorized users.
Controller’s obligationsThe Customer, as Controller, is solely responsible for: (a) establishing and maintaining a lawful basis for the Processing of Personal Data; (b) providing all appropriate privacy notices and any required transparency information to Data Subjects; and (c) responding to and resolving Data Subject rights requests and complaints, in each case in accordance with Data Protection Laws.

ANNEX 2: TECHNICAL AND ORGANIZATIONAL MEASURES

This Annex 2 describes the technical and organizational security measures that MarketCheck implements when Processing Personal Data under this DPA, in accordance with Article 32 of the UK GDPR. MarketCheck implements appropriate technical and organizational measures, which currently include the following categories:

CategoryDescription of Measures
Access Controls and AuthenticationRole-based access controls, multi-factor authentication for administrative access, unique user credentials, and least-privilege principles for all systems Processing Personal Data.
EncryptionEncryption of Personal Data in transit (TLS 1.2 or higher) and at rest using industry-standard encryption algorithms.
Network Security and MonitoringFirewalls, intrusion detection and prevention systems, logging of access events, and periodic review of security logs.
Incident ResponseDocumented incident response plan covering identification, containment, eradication, recovery, and post-incident review of security events.
Employee Training and ConfidentialityRegular data protection and security awareness training for all personnel with access to Personal Data; binding confidentiality obligations as set out in Section 4 of this DPA.
Business Continuity and Disaster RecoveryDocumented business continuity and disaster recovery procedures, including regular backups and tested restoration processes.
Security TestingRegular vulnerability assessments and penetration testing, with timely remediation of identified issues.

MarketCheck may update these measures from time to time, provided that any update does not materially reduce the overall level of protection afforded to Personal Data.

ANNEX 3: SUB-PROCESSOR LIST

1. The current list of Sub-Processors authorized by MarketCheck to process Personal Data on behalf of the Customer is maintained at developers.marketcheck.com/sub-processors (the “Sub-Processor List”).

2. MarketCheck shall keep the Sub-Processor List up to date and shall update it before any new Sub-Processor begins Processing Personal Data, in accordance with Section 6 of this DPA.

3. The Customer may subscribe to notifications of changes to the Sub-Processor List by following the instructions at developers.marketcheck.com/sub-processors. MarketCheck shall also notify the Customer of proposed changes in accordance with Section 6.3 of this DPA.

Market Check Cars, Inc. · 169 Madison Ave STE 57434, New York, NY 10016

Product

MCP API Docs Pricing Get Started

Resources

Docs MCP AI Desk Reference Apps AskAuto Claude Plugins
© 2026 Market Check Cars, Inc. All rights reserved. ·Terms·Privacy·