Last Updated: September 6, 2026
This agreement governs our processing of personal data on your behalf when you use TourSyncer. It applies automatically if you are subject to the GDPR, UK GDPR or Swiss FADP — no signature is required.
This Data Processing Agreement (“DPA”) forms part of the agreement under which Tripsyncer Inc.(“TourSyncer”, “we”, “Processor”) provides the TourSyncer platform to you (“Customer”, “Controller”) (the “Principal Agreement”).
Tripsyncer Inc.2116 Sumard DrLittle Elm, TX 75068United StatesPrivacy Officer: Belle Maya — [email protected]It applies where the Customer is subject to the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, or a comparable data protection law, in respect of Customer Personal Data processed through the platform.
Acceptance.This DPA is incorporated into the Principal Agreement by reference and takes effect on the earlier of the Customer’s acceptance of the Principal Agreement or first use of the platform. No signature is required for it to bind both parties. A countersigned copy is available on request to [email protected].
Order of precedence. In the event of a conflict, this DPA prevails over the Principal Agreement in respect of the processing of Customer Personal Data. Where the Standard Contractual Clauses incorporated in Section 8 apply, they prevail over this DPA.
Terms not defined here have the meaning given in the GDPR.
For Customer Personal Data — including personal data about the Customer’s own travellers, guests, staff and contacts entered into or generated by the platform — the Customer is the controller and TourSyncer is the processor. The Customer determines the purposes and means of that processing.
Separately, we act as an independent controllerfor a limited set of data we determine the purposes of ourselves: the Customer’s own account and billing records, platform security and fraud-prevention logs, and aggregated product usage statistics. That processing is governed by our Privacy Policy, not by this DPA.
Each party is responsible for its own compliance with Data Protection Law in respect of the processing it controls.
We will process Customer Personal Data only on the Customer’s documented instructions, including with regard to transfers to a third country, unless required to do otherwise by Union or Member State law to which we are subject. Where such a legal requirement applies, we will inform the Customer before processing unless that law prohibits it on important grounds of public interest.
The Principal Agreement, this DPA, and the Customer’s use and configuration of the platform constitute the Customer’s complete documented instructions. Additional instructions must be agreed in writing and may be subject to reasonable charges where they go beyond the platform’s standard functionality.
We will immediately inform the Customer if, in our opinion, an instruction infringes Data Protection Law, and may suspend performance of that instruction until it is withdrawn, amended or confirmed.
Customer responsibilities. The Customer warrants that it has a lawful basis for the processing it instructs, has provided the transparency information its data subjects require, has obtained any necessary consents, and that its instructions comply with Data Protection Law. The Customer is responsible for the accuracy and lawfulness of the Customer Personal Data it submits.
We ensure that persons authorised to process Customer Personal Data are bound by an appropriate obligation of confidentiality, whether contractual or statutory, that survives the end of their engagement. We limit access to Customer Personal Data to personnel who require it to provide, support or secure the platform.
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk to data subjects, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 GDPR. Those measures are described in Annex II.
We may update the measures over time provided the update does not materially reduce the overall level of security.
General authorisation. The Customer grants a general authorisation for us to engage sub-processors to process Customer Personal Data. Those engaged as at the date of this DPA are listed in Annex III.
Changes. We will give the Customer at least thirty (30) days’ notice before adding or replacing a sub-processor. Customers may subscribe to notifications by writing to [email protected].
Objection. The Customer may object on reasonable data-protection grounds within that notice period. We will work in good faith to make a reasonable alternative available. If we cannot, the Customer may terminate the affected part of the service without penalty and receive a pro-rata refund of prepaid fees for the unused term.
Flow-down and liability. We impose on each sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and we remain fully liable to the Customer for the performance of each sub-processor’s obligations.
Tripsyncer Inc. is established in the United States, and Customer Personal Data is stored and processed in the United States by the sub-processors listed in Annex III.
Where the transfer of Customer Personal Data from the European Economic Area, the United Kingdom or Switzerland to us is subject to Data Protection Law, the SCCs (Module Two) are incorporated into this DPA by reference and apply, completed as follows:
United Kingdom. Transfers subject to the UK GDPR are made under the SCCs as amended by the UK International Data Transfer Addendum issued by the Information Commissioner, with Tables 1 to 3 completed from this DPA and its Annexes, and Table 4 specifying that neither party may terminate under Section 19 of the Addendum.
Switzerland.Transfers subject to the Swiss FADP are made under the SCCs with references to the GDPR read as references to the FADP, the Swiss Federal Data Protection and Information Commissioner as competent authority, and “Member State” read so as not to prevent data subjects in Switzerland from enforcing their rights in their place of habitual residence.
The platform provides the Customer with the ability to access, correct, export and delete Customer Personal Data directly, which in most cases is sufficient for the Customer to respond to a data subject request without our involvement.
Taking into account the nature of the processing, we will assist the Customer by appropriate technical and organisational measures, insofar as this is possible, to fulfil the Customer’s obligation to respond to requests to exercise rights under Chapter III GDPR.
If a data subject contacts us directly about Customer Personal Data, we will not respond substantively except to confirm the request should be directed to the Customer, and we will forward the request to the Customer without undue delay.
We will notify the Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data, and in any event in sufficient time to allow the Customer to meet its own obligation to notify its supervisory authority within 72 hours where that applies.
The notification will describe:
Where we cannot provide all of that information at once, we will provide it in phases without undue further delay. We maintain a record of Security Incidents including the facts, effects and remedial action taken.
Our notification is not an acknowledgement of fault or liability. It is the Customer’s responsibility, as controller, to notify its supervisory authority and affected data subjects where required.
Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance to the Customer with data protection impact assessments and prior consultations under Articles 35 and 36 GDPR.
On termination or expiry of the Principal Agreement, and at the Customer’s choice, we will delete or return all Customer Personal Data and delete existing copies, unless Union or Member State law requires continued storage.
The Customer may export its data through the platform at any time during the term. Unless the Customer requests deletion earlier, Customer Personal Data is deleted within thirty (30) days of termination, after which it is no longer recoverable.
Two categories are retained beyond those periods because the law requires it. They are isolated from active processing and used only for the purpose that requires their retention:
These retention periods are also stated in our Privacy Policy, and the two documents are kept consistent.
We will make available to the Customer all information necessary to demonstrate compliance with the obligations in Article 28 GDPR and this DPA, and allow for and contribute to audits, including inspections, conducted by the Customer or another auditor it mandates.
In the first instance we will satisfy this obligation by providing documentation about our security measures, sub-processors and relevant third-party certifications or reports we hold. Where that is insufficient for the Customer to demonstrate compliance, the Customer may conduct an audit subject to reasonable conditions: not more than once in any twelve-month period unless required by a supervisory authority or following a Security Incident, on at least thirty (30) days’ written notice, during business hours, without unreasonably disrupting our operations, subject to confidentiality, and not extending to the data or systems of our other customers.
This DPA takes effect as set out in Section 1 and continues until all Customer Personal Data has been deleted or returned in accordance with Section 11. Obligations that by their nature should survive termination do so.
Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Principal Agreement, except where Data Protection Law does not permit those limitations to apply. Nothing in this DPA limits a data subject’s rights under Data Protection Law or under the SCCs.
Except where the SCCs specify otherwise, this DPA is governed by the law stated in the Principal Agreement.
Data exporter: the Customer, acting as controller. Contact details and signature are those in the Principal Agreement. Activities relevant to the transfer: use of the TourSyncer platform to manage its tour and travel operations.
Data importer: Tripsyncer Inc., acting as processor, at the address in Section 1. Contact: Belle Maya, Privacy Officer — [email protected]. Activities relevant to the transfer: provision of the TourSyncer platform.
Categories of data subjects:the Customer’s travellers and guests; the Customer’s staff and authorised users; the Customer’s business contacts, suppliers and agents.
Categories of personal data:identification and contact data (name, email address, telephone number, postal address); booking data (tour, dates, party composition, traveller ages or age bands where the Customer records them, special requests, notes); transaction data (invoices, amounts, currency, payment and refund status); account data for the Customer’s users (name, email, role, permissions); and technical data (IP address, device and browser information, access timestamps).
Sensitive data: the platform is not designed for, and the Customer is instructed not to submit, special categories of personal data as defined in Article 9 GDPR. Where a Customer records dietary, accessibility or medical information in a free-text field, it does so as controller and remains responsible for the additional safeguards Article 9 requires.
Frequency of the transfer: continuous, for the duration of the Principal Agreement.
Nature and purpose of processing: hosting, storage, retrieval, organisation, display, transmission and deletion of Customer Personal Data, for the purpose of providing the TourSyncer platform and its support, security and backup functions.
Duration: for the term of the Principal Agreement plus the deletion periods in Section 11.
The supervisory authority of the EEA Member State in which the Customer is established; or where the Customer is not established in the EEA, the supervisory authority of the Member State in which its Article 27 representative is established.
The measures below are those we implement to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR.
Sub-processors are required to maintain measures no less protective than those above.
We engage sub-processors in the following categories. All process Customer Personal Data in the United States.
| Category of sub-processor | Processing activity | Location of processing |
|---|---|---|
| Cloud infrastructure provider | Application hosting, database, authentication and file storage | United States |
| Content delivery network | Content delivery, DNS and denial-of-service protection | United States and a global edge network |
| Payment processor | Subscription billing for your account. Payments from your own guests are handled by the processor you connect, under your own account. | United States |
| Product analytics provider | Usage analytics for the signed-in operator console, so we can understand which features are used. Served through a subdomain of ours that routes to the provider, who processes the data. | United States |
| Advertising and tag management provider | Advertising measurement on our marketing and signup pages, loaded only where you have accepted cookies | United States |
The named list. The identity of each current sub-processor — its legal name, location and role — forms the agreed list referred to in Clause 9 of the Standard Contractual Clauses. We will provide it to any Customer on request to [email protected], so that the right to object under Section 7 can be exercised meaningfully. It is not published here, but it is not withheld from Customers.
To receive notice of changes to this list, or to request a countersigned copy of this DPA, write to [email protected].