Legal

Data Processing Addendum

Data Processing Addendum

1. Introduction and Scope

This Data Processing Addendum ("DPA") forms part of the Terms of Service between you ("Data Controller" or "Customer") and Hastings Dynamics Ltd ("Data Processor" or "Processor") for the processing of Personal Data in connection with the Rivileo platform.

This DPA applies where and to the extent that we process Personal Data on your behalf in the course of providing our services, in accordance with the UK GDPR, EU GDPR, and other applicable data protection laws.

In the event of any conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to data protection matters.

2. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person as defined by applicable data protection laws.
  • "Processing" has the meaning given in applicable data protection laws and includes any operation performed on Personal Data.
  • "Data Subject" means the individual to whom Personal Data relates.
  • "Sub-processor" means any third party appointed by the Processor to process Personal Data.
  • "Supervisory Authority" means the Information Commissioner's Office (ICO) in the UK or other relevant data protection authority.

3. Data Processing Details

3.1 Nature and Purpose of Processing

We process Personal Data for the purpose of providing the Rivileo platform services, including:

  • Account management and authentication
  • Social features and user-generated content hosting
  • Trip planning and itinerary management
  • Booking facilitation (commission-based)
  • Customer support and communications
  • Platform analytics and improvement

3.2 Categories of Data Subjects

  • Platform users (travelers)
  • Business partners (accommodation providers, tour operators)
  • Customer support contacts

3.3 Types of Personal Data

  • Identity data (name, username, profile photo)
  • Contact data (email address, phone number)
  • Account data (password, preferences, settings)
  • Usage data (browsing history, search queries, interactions)
  • Technical data (IP address, device information, cookies)
  • Location data (approximate or precise, with consent)
  • User-generated content (posts, reviews, photos, itineraries)
  • Transaction data (booking details, payment information processed by third parties)

3.4 Duration of Processing

We will process Personal Data for the duration of the service agreement and as required by law or our data retention policies thereafter.

4. Processor Obligations (GDPR Article 28)

4.1 Processing Instructions

We shall process Personal Data only on documented instructions from you, unless required to do so by applicable law. If we believe an instruction violates applicable data protection laws, we will inform you immediately.

4.2 Confidentiality

We ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

4.3 Security Measures

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of Personal Data in transit (TLS/SSL) and at rest (AES-256)
  • Regular security testing and vulnerability assessments
  • Access controls and authentication mechanisms (multi-factor authentication)
  • Logging and monitoring of access to Personal Data
  • Employee training on data protection and security
  • Incident response and business continuity plans
  • Regular backups and disaster recovery procedures

4.4 Sub-processors

You authorize us to engage the following categories of sub-processors:

  • Cloud infrastructure providers (Microsoft Azure)
  • Payment processors (Stripe)
  • Email service providers
  • Analytics providers (Google Analytics)
  • Customer support tools

We will inform you of any intended changes concerning the addition or replacement of sub-processors, giving you the opportunity to object to such changes within 30 days.

We ensure that sub-processors are bound by data protection obligations equivalent to those in this DPA.

4.5 Data Subject Rights

We will assist you in responding to requests from Data Subjects to exercise their rights under applicable data protection laws, including:

  • Right of access
  • Right to rectification
  • Right to erasure ("right to be forgotten")
  • Right to restriction of processing
  • Right to data portability
  • Right to object

We will respond to such requests within a reasonable timeframe, taking into account the nature of the request.

4.6 Data Breach Notification

We will notify you without undue delay (and in any event within 72 hours) upon becoming aware of a Personal Data breach affecting your data. The notification will include:

  • Description of the nature of the breach
  • Categories and approximate number of Data Subjects and Personal Data records affected
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach and mitigate its effects

4.7 Data Protection Impact Assessments

We will provide reasonable assistance to you in conducting Data Protection Impact Assessments (DPIAs) where required by applicable data protection laws.

4.8 Audits and Inspections

We will make available to you all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by you or an auditor mandated by you, subject to reasonable notice and confidentiality obligations.

5. International Data Transfers

Personal Data may be transferred to and processed in countries outside the UK and EEA. For such transfers, we ensure adequate protection through:

  • Standard Contractual Clauses (SCCs) approved by the UK ICO and EU Commission
  • Adequacy decisions recognizing equivalent data protection standards
  • Binding Corporate Rules or other approved transfer mechanisms

Upon request, we will provide you with copies of the relevant transfer mechanisms.

6. Data Deletion and Return

Upon termination of services or at your request, we will:

  • Delete or return all Personal Data to you, at your choice
  • Delete existing copies unless storage is required by applicable law
  • Provide certification of deletion upon request

We may retain Personal Data to the extent required by law or for legitimate business purposes (e.g., tax, accounting, legal compliance) for up to 7 years.

7. Liability and Indemnification

Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service, except where prohibited by applicable data protection laws.

We will indemnify you against fines and penalties imposed by Supervisory Authorities resulting from our breach of this DPA, to the extent caused by our acts or omissions.

8. Term and Termination

This DPA will remain in effect for as long as we process Personal Data on your behalf. Upon termination, the data deletion and return provisions in Section 6 will apply.

9. Governing Law and Jurisdiction

This DPA is governed by the laws of England and Wales. Any disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales.

10. Contact Information

For questions about this DPA or data processing matters:

Email: hello@support.rivileo.com

Post: Hastings Dynamics Ltd, 124 City Road, London, England, EC1V 2NX