Data Processing Agreement

Last Updated: September 6, 2026

This agreement governs our processing of personal data on your behalf when you use TourSyncer. It applies automatically if you are subject to the GDPR, UK GDPR or Swiss FADP — no signature is required.

1Parties, Scope and Acceptance

This Data Processing Agreement (“DPA”) forms part of the agreement under which Tripsyncer Inc.(“TourSyncer”, “we”, “Processor”) provides the TourSyncer platform to you (“Customer”, “Controller”) (the “Principal Agreement”).

Tripsyncer Inc.2116 Sumard DrLittle Elm, TX 75068United StatesPrivacy Officer: Belle Maya[email protected]

It applies where the Customer is subject to the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, or a comparable data protection law, in respect of Customer Personal Data processed through the platform.

Acceptance.This DPA is incorporated into the Principal Agreement by reference and takes effect on the earlier of the Customer’s acceptance of the Principal Agreement or first use of the platform. No signature is required for it to bind both parties. A countersigned copy is available on request to [email protected].

Order of precedence. In the event of a conflict, this DPA prevails over the Principal Agreement in respect of the processing of Customer Personal Data. Where the Standard Contractual Clauses incorporated in Section 8 apply, they prevail over this DPA.

2Definitions

Terms not defined here have the meaning given in the GDPR.

  • Customer Personal Data— personal data contained in Customer Data that we process on the Customer’s behalf, as described in Annex I.
  • Customer Data — all data the Customer or its authorised users submit to, or generate within, the platform.
  • Data Protection Law — all laws applicable to the processing of Customer Personal Data under this DPA, including the GDPR, UK GDPR and Swiss FADP.
  • SCCs — the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor).
  • Sub-processor — a third party engaged by us to process Customer Personal Data.
  • Security Incident — a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.

3Roles of the Parties

For Customer Personal Data — including personal data about the Customer’s own travellers, guests, staff and contacts entered into or generated by the platform — the Customer is the controller and TourSyncer is the processor. The Customer determines the purposes and means of that processing.

Separately, we act as an independent controllerfor a limited set of data we determine the purposes of ourselves: the Customer’s own account and billing records, platform security and fraud-prevention logs, and aggregated product usage statistics. That processing is governed by our Privacy Policy, not by this DPA.

Each party is responsible for its own compliance with Data Protection Law in respect of the processing it controls.

4Processing on Documented Instructions

We will process Customer Personal Data only on the Customer’s documented instructions, including with regard to transfers to a third country, unless required to do otherwise by Union or Member State law to which we are subject. Where such a legal requirement applies, we will inform the Customer before processing unless that law prohibits it on important grounds of public interest.

The Principal Agreement, this DPA, and the Customer’s use and configuration of the platform constitute the Customer’s complete documented instructions. Additional instructions must be agreed in writing and may be subject to reasonable charges where they go beyond the platform’s standard functionality.

We will immediately inform the Customer if, in our opinion, an instruction infringes Data Protection Law, and may suspend performance of that instruction until it is withdrawn, amended or confirmed.

Customer responsibilities. The Customer warrants that it has a lawful basis for the processing it instructs, has provided the transparency information its data subjects require, has obtained any necessary consents, and that its instructions comply with Data Protection Law. The Customer is responsible for the accuracy and lawfulness of the Customer Personal Data it submits.

5Confidentiality of Personnel

We ensure that persons authorised to process Customer Personal Data are bound by an appropriate obligation of confidentiality, whether contractual or statutory, that survives the end of their engagement. We limit access to Customer Personal Data to personnel who require it to provide, support or secure the platform.

6Security of Processing

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk to data subjects, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 GDPR. Those measures are described in Annex II.

We may update the measures over time provided the update does not materially reduce the overall level of security.

7Sub-processors

General authorisation. The Customer grants a general authorisation for us to engage sub-processors to process Customer Personal Data. Those engaged as at the date of this DPA are listed in Annex III.

Changes. We will give the Customer at least thirty (30) days’ notice before adding or replacing a sub-processor. Customers may subscribe to notifications by writing to [email protected].

Objection. The Customer may object on reasonable data-protection grounds within that notice period. We will work in good faith to make a reasonable alternative available. If we cannot, the Customer may terminate the affected part of the service without penalty and receive a pro-rata refund of prepaid fees for the unused term.

Flow-down and liability. We impose on each sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and we remain fully liable to the Customer for the performance of each sub-processor’s obligations.

8International Transfers

Tripsyncer Inc. is established in the United States, and Customer Personal Data is stored and processed in the United States by the sub-processors listed in Annex III.

Where the transfer of Customer Personal Data from the European Economic Area, the United Kingdom or Switzerland to us is subject to Data Protection Law, the SCCs (Module Two) are incorporated into this DPA by reference and apply, completed as follows:

  • Clause 7 (docking clause) applies.
  • Clause 9: Option 2, general written authorisation, with a thirty (30) day notice period as set out in Section 7.
  • Clause 11: the optional independent dispute resolution mechanism does not apply.
  • Clause 17: the SCCs are governed by the law of Ireland.
  • Clause 18(b): disputes are resolved before the courts of Ireland.
  • Annexes I, II and III to the SCCs are the Annexes to this DPA.

United Kingdom. Transfers subject to the UK GDPR are made under the SCCs as amended by the UK International Data Transfer Addendum issued by the Information Commissioner, with Tables 1 to 3 completed from this DPA and its Annexes, and Table 4 specifying that neither party may terminate under Section 19 of the Addendum.

Switzerland.Transfers subject to the Swiss FADP are made under the SCCs with references to the GDPR read as references to the FADP, the Swiss Federal Data Protection and Information Commissioner as competent authority, and “Member State” read so as not to prevent data subjects in Switzerland from enforcing their rights in their place of habitual residence.

9Assistance with Data Subject Rights

The platform provides the Customer with the ability to access, correct, export and delete Customer Personal Data directly, which in most cases is sufficient for the Customer to respond to a data subject request without our involvement.

Taking into account the nature of the processing, we will assist the Customer by appropriate technical and organisational measures, insofar as this is possible, to fulfil the Customer’s obligation to respond to requests to exercise rights under Chapter III GDPR.

If a data subject contacts us directly about Customer Personal Data, we will not respond substantively except to confirm the request should be directed to the Customer, and we will forward the request to the Customer without undue delay.

10Security Incidents and Assistance with Articles 32 to 36

We will notify the Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data, and in any event in sufficient time to allow the Customer to meet its own obligation to notify its supervisory authority within 72 hours where that applies.

The notification will describe:

  • the nature of the incident, including where possible the categories and approximate number of data subjects and records concerned;
  • the likely consequences of the incident;
  • the measures taken or proposed to address it and mitigate its effects; and
  • a contact point for further information.

Where we cannot provide all of that information at once, we will provide it in phases without undue further delay. We maintain a record of Security Incidents including the facts, effects and remedial action taken.

Our notification is not an acknowledgement of fault or liability. It is the Customer’s responsibility, as controller, to notify its supervisory authority and affected data subjects where required.

Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance to the Customer with data protection impact assessments and prior consultations under Articles 35 and 36 GDPR.

11Deletion and Return of Data

On termination or expiry of the Principal Agreement, and at the Customer’s choice, we will delete or return all Customer Personal Data and delete existing copies, unless Union or Member State law requires continued storage.

The Customer may export its data through the platform at any time during the term. Unless the Customer requests deletion earlier, Customer Personal Data is deleted within thirty (30) days of termination, after which it is no longer recoverable.

Two categories are retained beyond those periods because the law requires it. They are isolated from active processing and used only for the purpose that requires their retention:

  • Invoices and payment records— retained for seven (7) years from the date of the transaction, for tax and accounting purposes. These relate to the Customer’s own billing, for which we act as controller rather than processor.
  • Security incident records — retained for a minimum of twenty-four (24) months from the date an incident is determined to have occurred, as required by Canadian federal law and the Quebec incident register. These record the fact and handling of an incident, not the Customer Personal Data affected by it.

These retention periods are also stated in our Privacy Policy, and the two documents are kept consistent.

12Audits and Information

We will make available to the Customer all information necessary to demonstrate compliance with the obligations in Article 28 GDPR and this DPA, and allow for and contribute to audits, including inspections, conducted by the Customer or another auditor it mandates.

In the first instance we will satisfy this obligation by providing documentation about our security measures, sub-processors and relevant third-party certifications or reports we hold. Where that is insufficient for the Customer to demonstrate compliance, the Customer may conduct an audit subject to reasonable conditions: not more than once in any twelve-month period unless required by a supervisory authority or following a Security Incident, on at least thirty (30) days’ written notice, during business hours, without unreasonably disrupting our operations, subject to confidentiality, and not extending to the data or systems of our other customers.

13Term, Liability and Governing Law

This DPA takes effect as set out in Section 1 and continues until all Customer Personal Data has been deleted or returned in accordance with Section 11. Obligations that by their nature should survive termination do so.

Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Principal Agreement, except where Data Protection Law does not permit those limitations to apply. Nothing in this DPA limits a data subject’s rights under Data Protection Law or under the SCCs.

Except where the SCCs specify otherwise, this DPA is governed by the law stated in the Principal Agreement.

14Annex I — Description of the Processing

A. List of parties

Data exporter: the Customer, acting as controller. Contact details and signature are those in the Principal Agreement. Activities relevant to the transfer: use of the TourSyncer platform to manage its tour and travel operations.

Data importer: Tripsyncer Inc., acting as processor, at the address in Section 1. Contact: Belle Maya, Privacy Officer[email protected]. Activities relevant to the transfer: provision of the TourSyncer platform.

B. Description of the transfer

Categories of data subjects:the Customer’s travellers and guests; the Customer’s staff and authorised users; the Customer’s business contacts, suppliers and agents.

Categories of personal data:identification and contact data (name, email address, telephone number, postal address); booking data (tour, dates, party composition, traveller ages or age bands where the Customer records them, special requests, notes); transaction data (invoices, amounts, currency, payment and refund status); account data for the Customer’s users (name, email, role, permissions); and technical data (IP address, device and browser information, access timestamps).

Sensitive data: the platform is not designed for, and the Customer is instructed not to submit, special categories of personal data as defined in Article 9 GDPR. Where a Customer records dietary, accessibility or medical information in a free-text field, it does so as controller and remains responsible for the additional safeguards Article 9 requires.

Frequency of the transfer: continuous, for the duration of the Principal Agreement.

Nature and purpose of processing: hosting, storage, retrieval, organisation, display, transmission and deletion of Customer Personal Data, for the purpose of providing the TourSyncer platform and its support, security and backup functions.

Duration: for the term of the Principal Agreement plus the deletion periods in Section 11.

C. Competent supervisory authority

The supervisory authority of the EEA Member State in which the Customer is established; or where the Customer is not established in the EEA, the supervisory authority of the Member State in which its Article 27 representative is established.

15Annex II — Technical and Organisational Measures

The measures below are those we implement to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR.

Encryption and pseudonymisation

  • All data in transit is encrypted using TLS.
  • Data at rest is encrypted by our infrastructure providers.
  • Payment card details are collected and processed directly by our PCI DSS compliant payment processor and are never stored on our systems.

Access control and tenant isolation

  • Authentication is managed by a dedicated identity provider, with email verification and support for one-time codes.
  • Role-based access control governs what each user may see and do, enforced server-side on every request rather than only in the interface.
  • Every data access is scoped to the organisation that owns it, so one Customer's users cannot reach another Customer's data.
  • Sensitive operations require step-up re-authentication.
  • Administrative access to production systems is restricted to personnel who require it and is individually attributed.

Integrity, availability and resilience

  • The platform runs on managed cloud infrastructure that replicates data automatically across multiple availability zones, protecting against hardware and zone failure.
  • Traffic is served through a content delivery network providing denial-of-service protection.
  • A Content Security Policy with per-request nonces is applied to defend against script injection.
  • Outbound mail server configurations are validated and pinned before use.

Logging, testing and governance

  • Security-relevant events and administrative actions are logged to a tenant audit trail.
  • Changes are reviewed and pass automated type, test and security checks before release.
  • A documented breach response procedure is maintained, including risk assessment, notification paths and a retained incident register.
  • A designated Privacy Officer is accountable for data protection compliance.

Sub-processors are required to maintain measures no less protective than those above.

16Annex III — Authorised Sub-processors

We engage sub-processors in the following categories. All process Customer Personal Data in the United States.

Category of sub-processorProcessing activityLocation of processing
Cloud infrastructure providerApplication hosting, database, authentication and file storageUnited States
Content delivery networkContent delivery, DNS and denial-of-service protectionUnited States and a global edge network
Payment processorSubscription billing for your account. Payments from your own guests are handled by the processor you connect, under your own account.United States
Product analytics providerUsage analytics for the signed-in operator console, so we can understand which features are used. Served through a subdomain of ours that routes to the provider, who processes the data.United States
Advertising and tag management providerAdvertising measurement on our marketing and signup pages, loaded only where you have accepted cookiesUnited States

The named list. The identity of each current sub-processor — its legal name, location and role — forms the agreed list referred to in Clause 9 of the Standard Contractual Clauses. We will provide it to any Customer on request to [email protected], so that the right to object under Section 7 can be exercised meaningfully. It is not published here, but it is not withheld from Customers.

To receive notice of changes to this list, or to request a countersigned copy of this DPA, write to [email protected].