1. Roles of the parties
In respect of any Customer Data that constitutes personal data under the GDPR, the UK GDPR, or equivalent laws:
- The Customer (agency or user of the Service) is the Controller.
- Travelboost Inc. is the Processor, processing personal data only on the Controller’s instructions.
The subject matter, duration, nature, purpose, categories of data, and categories of data subjects are described in Annex A.
2. Scope of processing
We process personal data only:
- To provide the Service in accordance with the Terms of Service;
- On documented instructions from the Controller (including via the product configuration itself);
- As required by applicable law, in which case we will notify the Controller unless prohibited from doing so.
3. Confidentiality
We ensure that any personnel authorised to process personal data are bound by contractual or statutory confidentiality obligations. Access is granted on a strict need-to-know basis and is regularly reviewed.
4. Security measures
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. These include, at minimum, the measures described in Annex B and in our Security Policy. We regularly review and, where appropriate, update these measures.
5. Sub-processors
The Controller authorises Travelboost Inc. to engage the sub-processors listed in Annex C and to engage additional sub-processors with prior general written authorisation. We will notify the Controller at least 30 days before any change to the sub-processor list. The Controller may object on reasonable grounds; if the objection cannot be resolved, either party may terminate the Service.
Each sub-processor is subject to a written agreement that imposes obligations at least equivalent to those in this DPA.
6. Data subject rights
Where a data subject exercises any of their rights under GDPR (access, rectification, erasure, restriction, portability, objection), we will:
- Notify the Controller without undue delay if the request is made directly to us;
- Provide reasonable assistance, using appropriate technical and organisational measures, to help the Controller respond;
- Not respond to data-subject requests ourselves except as directed by the Controller.
7. Personal data breach notification
In the event of a personal data breach affecting Customer Data, we will notify the Controller without undue delay and no later than 48 hours after becoming aware. The notification will include:
- Nature of the breach;
- Categories and approximate number of data subjects and records concerned;
- Likely consequences;
- Measures taken or proposed to address the breach and mitigate its effects.
8. Data protection impact assessments (DPIAs)
We provide the Controller with reasonable assistance in conducting DPIAs and prior consultations with supervisory authorities, at the Controller’s cost for any non-trivial requests.
9. International transfers
Personal data may be transferred to and processed in the United States and in other countries where our sub-processors operate. For transfers of EEA, UK, or Swiss personal data to a country not deemed to provide adequate protection, the parties incorporate by reference the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914), Module Two (Controller-to-Processor), and — where applicable — the UK International Data Transfer Addendum (2022) and Swiss addendum. Details in Annex D.
10. Return or deletion of personal data
At the end of the provision of Services, the Controller may export all Customer Data in a standard machine- readable format for up to 30 days. Thereafter, Travelboost Inc. will delete all Customer Data from active systems; backups purge within 90 days. On request, we will provide written certification of deletion.
11. Audits
Travelboost Inc. makes available to the Controller all information necessary to demonstrate compliance with GDPR Article 28, including annually-updated summary security documentation and, where applicable, SOC 2 Type II attestations. Where the Controller requires an on-site audit, the parties will agree the scope, timing, and reasonable cost in advance.
12. Liability
The liability of each party under this DPA is subject to the limitations in the Terms of Service, except that neither party may limit its statutory liability towards a data subject.
13. Term and termination
This DPA remains in force for the duration of the Terms of Service and for any period during which we process Customer Data. On termination, the deletion obligations in Section 10 apply.
Annex A — Details of processing
- Subject matter: processing of Customer Data by Travelboost Inc. to provide the TravelBoost Service.
- Duration: for the term of the Terms of Service, plus retention periods described therein.
- Nature and purpose: hosting, storage, computation, analytics, and communication features of the platform.
- Categories of data subjects: Controller’s customers, prospects, leads, suppliers, employees, sub-agents, pilgrims, travellers.
- Categories of personal data: identification data (name, email, phone), contact and address data, passport / visa / vaccination details (where uploaded), financial data (payment history, invoices), communications (email, WhatsApp threads), location data (for transport module), device / usage data.
- Special categories: only where the Controller uploads them (e.g. religious information via Hajj/Umrah records, health information via medical fitness fields). The Controller is responsible for the legal basis for uploading such data.
Annex B — Technical and organisational security measures
- Encryption: TLS 1.3 in transit; AES-256 at rest for databases and file storage.
- Access control: role-based access, least privilege, mandatory MFA on all production systems.
- Isolation: multi-tenant architecture with row-level tenant isolation on every query.
- Monitoring: 24/7 log aggregation, anomaly detection, security alerting.
- Backups: continuous point-in-time backups; monthly restore drills.
- Personnel: confidentiality obligations, security training on hire and annually.
- Physical security: hosting in ISO 27001 / SOC 2 certified data centres.
- Incident response: documented playbooks; 48-hour breach-notification commitment.
Annex C — Approved sub-processors
Current list, updated periodically. Notice of changes is given at least 30 days in advance.
| Sub-processor | Purpose | Location |
|---|---|---|
| DigitalOcean, LLC | Hosting, database, storage | US / EU regions |
| Amazon Web Services, Inc. | Backup storage, media delivery | US / EU regions |
| SendGrid (Twilio Inc.) | Transactional email | US |
| Twilio Inc. | SMS and WhatsApp Business API | US / EU |
| Stripe, Inc. | Payment processing | US / EU / UK |
| Cloudflare, Inc. | Network security, WAF, CDN | Global |
Annex D — International transfers
For transfers of personal data from the EEA / UK / Switzerland to the United States or another country not recognised as providing adequate protection, the parties incorporate by reference the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914), Module Two (Controller-to-Processor), including:
- Docking clause (Clause 7): not applied.
- Sub-processor authorisation (Clause 9): Option 2 (general written authorisation), 30-day notice.
- Complaints (Clause 11): Option not selected (no independent dispute resolution).
- Governing law and jurisdiction (Clauses 17 & 18): laws and courts of the country in which the data exporter is established, or if not in EU, of Ireland.
For UK transfers, the parties adopt the UK International Data Transfer Addendum issued by the Information Commissioner’s Office (version B1.0, 21 March 2022) with Tables 1 and 2 populated by reference to this DPA.
14. Signature
This DPA is effective automatically for all Customers as of the effective date at the top of this page. If your organisation requires a signed copy for its records, email [email protected] and we will provide a countersigned PDF within 5 business days.
