Data Processing Agreement (DPA)
The processor terms between the subscribing tour operator (controller) and TravelBookingWidgets (processor), incorporated into the Terms of Service. Structured around UK GDPR Article 28 and the Kenya Data Protection Act 2019 processor duties.
1. Roles, subject matter and scope
This DPA applies where TravelBookingWidgets ([COMPANY LEGAL NAME], "Processor") processes personal data on behalf of the subscribing tour operator ("Controller") to provide the platform. The Controller determines the purposes and means of that processing; the Processor acts only on the Controller's documented instructions.
The details of the processing — subject matter, duration, nature and purpose, data categories and data-subject categories — are set out in Annex A. The security measures are set out in Annex B.
2. Documented instructions
The Terms of Service, the Controller's workspace configuration, and any written instructions agreed between the parties constitute the Controller's documented instructions. The Processor will inform the Controller if an instruction appears to infringe data protection law, and will notify the Controller if it cannot comply with an instruction.
3. Confidentiality
The Processor ensures that personnel authorised to process personal data are bound by confidentiality obligations and access personal data only on a need-to-know basis.
4. Security
Taking into account the state of the art, costs of implementation and the nature of the data, the Processor maintains the technical and organisational measures in Annex B, including encryption in transit and at rest, multi-factor-capable authentication, tenant isolation via row-level security, encrypted storage of mailbox credentials, attachment scanning and rate limiting. The Processor may update these measures without reducing the overall level of protection.
5. Subprocessors
The Controller gives general written authorisation to the Processor's subprocessors listed at /legal/subprocessors. The Processor will give at least [30] days' advance notice of any new or replacement subprocessor by updating that page and emailing workspace owners, during which the Controller may object on reasonable data-protection grounds. If the parties cannot resolve an objection, the Controller may suspend the affected processing or terminate the affected service, with a pro-rata refund of prepaid unused fees.
The Processor imposes data-protection obligations equivalent to this DPA on each subprocessor and remains fully liable to the Controller for subprocessors' performance.
6. Data-subject rights
Taking into account the nature of the processing, the Processor assists the Controller in fulfilling its obligations to respond to data-subject requests (access, rectification, erasure, restriction, portability, objection). Today this assistance is provided via a request to privacy@travelbookingwidgets.com — self-service export tooling is in development.
7. Personal-data breach
The Processor notifies the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller's data, providing the nature of the breach, the categories and approximate numbers concerned, likely consequences and measures taken or proposed. Regulatory notification duties sit with the Controller as controller (for example, 72 hours to the UK ICO, and notification to Kenya's ODPC where required); the Processor assists with information for those notifications and maintains its own breach records.
8. Impact assessments and consultation
The Processor provides reasonable assistance with data protection impact assessments and prior consultation with regulators, taking into account the information available to the Processor.
9. International transfers
Where processing involves a transfer of personal data out of the UK that is restricted under UK GDPR, the Processor makes the transfer under the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, with transfer risk assessments where required. For data of data subjects located in Kenya, the Processor applies safeguards consistent with the Kenya Data Protection Act 2019 and ODPC cross-border guidance. Processing locations for each subprocessor are listed at /legal/subprocessors.
10. Return and deletion
On termination of the services, the Processor, at the Controller's choice, deletes or returns the personal data. Practically: the Controller has a [30]-day post-termination export window (exports are provided on request while self-service tooling is in development), after which the Processor deletes or de-identifies remaining personal data within [60] days, except where law requires retention.
11. Audit, records and accountability
The Processor maintains records of processing under UK GDPR Article 30(2) (and Kenya DPA 2019 equivalents), makes available to the Controller the information necessary to demonstrate compliance with this DPA, and allows for and contributes to audits — via compliance summaries on an annual request cycle, and, only where reasonably required and on [30] days' notice, an inspection that does not jeopardise other tenants' data or confidentiality.
12. Liability and precedence
Liability under this DPA is subject to the limitations in the Terms of Service. This DPA forms part of the Terms of Service; if there is a conflict about personal-data processing, this DPA prevails.
Annex A — Details of processing
| Item | Description |
|---|---|
| Controller | The subscribing tour operator |
| Processor | [COMPANY LEGAL NAME] trading as TravelBookingWidgets |
| Subject matter | Management of the Controller's traveller, booking and correspondence data in the platform |
| Duration | The subscription term plus the post-termination exit window |
| Nature and purpose | Capture, storage, quoting and document generation, communications (email/WhatsApp), payment-request initiation and payment metadata — solely to operate the Controller's travel business on the platform |
| Categories of data subjects | Controller's staff; travellers and guests; the Controller's supplier contacts |
| Categories of personal data | Identity and contact details (names, emails, phone numbers, addresses); trip and booking details; documents; communications content; payment metadata (amount, currency, status, tracking references — never card data) |
| Special-category data | The platform is not designed for special-category data; the Controller must not submit it |
| Processing locations | Per the subprocessor list at /legal/subprocessors [hosting regions being recorded and to be published] |
Annex B — Technical and organisational measures
- Encryption of personal data in transit and at rest.
- Two-step verification for operator accounts; optional multi-factor authentication.
- Tenant isolation enforced by database row-level security.
- Mailbox and integration credentials stored encrypted; secrets vaulting.
- Attachment scanning; rate limiting; session and audit logging.
- Access control on a need-to-know basis; personnel confidentiality obligations.
- Backups and documented restore capability.