Data Processing Agreement (DPA)

Last Updated: June 2026

1. Introduction and Scope

This Data Processing Agreement ("DPA") forms part of the Terms of Service between GuideUp Technologies Private Limited ("GuideUp") and the tour operator or travel business ("Customer") that uses the GuideUp platform. This DPA applies where GuideUp processes personal data on behalf of the Customer in the course of providing the platform services.

This DPA is intended to comply with the requirements of Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and reflects the parties' agreement on the processing of personal data.

2. Definitions

In this DPA:

  • "Controller" means the Customer, who determines the purposes and means of processing personal data through the GuideUp platform.
  • "Processor" means GuideUp Technologies Private Limited, which processes personal data on behalf of the Controller.
  • "Data Subject" means an identified or identifiable natural person whose personal data is processed — primarily passengers, tour participants, and related individuals.
  • "Personal Data" has the meaning given in GDPR Article 4(1).
  • "Processing" has the meaning given in GDPR Article 4(2).
  • "Sub-processor" means a third-party processor engaged by GuideUp to assist in processing personal data under this DPA.
  • "Security Incident" means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
3. Roles of the Parties

The Customer acts as the Data Controller in relation to personal data entered into the GuideUp platform. The Customer determines the categories of data subjects and personal data to be processed, and the purposes for which it is processed.

GuideUp acts as the Data Processor and processes personal data only on the documented instructions of the Customer, as set out in this DPA and the Terms of Service, or as required by applicable law.

4. Categories of Personal Data Processed

GuideUp processes the following categories of personal data on behalf of the Customer:

  • Passenger manifest data: full names, nationality, date of birth (where provided), passport or ID numbers (where provided)
  • Contact information: email addresses, phone numbers, postal addresses
  • Booking and reservation data: booking reference numbers, tour and activity selections, travel dates, special requirements or accessibility needs
  • Payment status information: payment confirmation references (payment card data is handled exclusively by Stripe and is not stored by GuideUp)
  • Communication records: emails or messages sent to passengers through the platform
  • Health and dietary information: where voluntarily provided by passengers and entered by the Customer (special categories of data — processed only where the Customer has obtained valid consent from the data subject or has another lawful basis)

The categories of data subjects are primarily tour participants (passengers), their emergency contacts (where entered by the Customer), and Customer staff members who use the platform.

5. Purposes of Processing

GuideUp processes personal data solely for the purpose of providing the platform services to the Customer, which includes:

  • Storing and displaying passenger and booking data within the platform
  • Generating manifests, itineraries, and operational documents
  • Facilitating payment processing via integrated payment providers
  • Sending transactional communications (booking confirmations, reminders) on the Customer's instruction
  • Maintaining platform functionality, backups, and disaster recovery
  • Complying with applicable legal obligations

GuideUp will not process personal data for any purpose other than those set out in this DPA or as otherwise instructed in writing by the Customer, except where required by EU or member state law, in which case GuideUp will inform the Customer of that legal requirement before processing unless prohibited from doing so by law.

6. Legal Basis for Processing

The Customer, as Controller, is responsible for ensuring there is a valid legal basis for processing personal data under GDPR Article 6. Typical legal bases relied upon by tour operators include:

  • Contract performance (Article 6(1)(b)): processing passenger data necessary to perform a tour booking contract.
  • Legal obligation (Article 6(1)(c)): maintaining records required by applicable travel, consumer, or financial regulations.
  • Consent (Article 6(1)(a)): for marketing communications or optional data collection (e.g., dietary preferences).
  • Legitimate interests (Article 6(1)(f)): operational and safety-related processing where not overridden by the data subject's rights.

For special category data (e.g., health information), an additional legal basis under Article 9 GDPR is required. The Customer must ensure this basis exists before entering such data into the platform.

7. GuideUp's Obligations as Processor

GuideUp shall, in its capacity as data processor:

  • Process personal data only on documented instructions from the Customer, unless otherwise required by applicable law.
  • Ensure that all personnel who process personal data are bound by appropriate confidentiality obligations.
  • Implement and maintain technical and organisational measures as described in Section 9 of this DPA.
  • Assist the Customer in responding to data subject rights requests as described in Section 10.
  • Assist the Customer in meeting obligations under GDPR Articles 32–36 (security, breach notification, DPIAs, and prior consultation), taking into account the nature of processing and information available to GuideUp.
  • Delete or return all personal data to the Customer upon termination of the services, as described in Section 13, and delete existing copies unless EU or member state law requires retention.
  • Make available to the Customer all information necessary to demonstrate compliance with obligations in this DPA and allow for and contribute to audits or inspections conducted by the Customer or a mandated auditor (with reasonable notice and at the Customer's cost).
8. Sub-processors

The Customer grants GuideUp general authorisation to engage sub-processors to assist in delivering the platform services. GuideUp's current sub-processors are listed at guideup.co/sub-processors.

GuideUp will notify the Customer of any intended changes to the list of sub-processors (additions or replacements) by email or via a notice in the platform at least 14 days before the change takes effect. The Customer may object to a new sub-processor on reasonable data protection grounds by notifying GuideUp within 14 days. If the parties cannot resolve the objection, either party may terminate the relevant services with 30 days' written notice.

GuideUp imposes data protection obligations on each sub-processor that are equivalent to those set out in this DPA and remains fully liable to the Customer for the performance of sub-processors' obligations.

9. Security Measures

GuideUp implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing. These measures include:

  • Encryption in transit: all data transmitted between users and the platform is encrypted using TLS 1.2 or higher.
  • Encryption at rest: all personal data stored in the database is encrypted at rest using AES-256.
  • Access controls: role-based access controls (RBAC) limit access to personal data to authorised personnel on a need-to-know basis. Administrative access requires multi-factor authentication (MFA).
  • Data segregation: each Customer's data is logically isolated from other customers' data within the platform.
  • Regular backups: automated daily backups with tested restoration procedures.
  • Vulnerability management: regular security testing, dependency updates, and code review processes.
  • Incident response: a documented security incident response procedure, including breach assessment and notification workflows.
  • Staff training: all GuideUp personnel with access to personal data receive data protection training.

GuideUp reviews and updates these measures on a regular basis and will implement enhancements as the threat landscape or applicable standards evolve.

10. Data Subject Rights

GuideUp will promptly notify the Customer if a data subject makes a request directly to GuideUp in connection with personal data processed on the Customer's behalf. GuideUp will not respond to such requests directly but will provide the Customer with reasonable technical assistance to enable the Customer to fulfil its obligations to data subjects, including:

  • Right of access (Article 15)
  • Right to rectification (Article 16)
  • Right to erasure (Article 17)
  • Right to restriction of processing (Article 18)
  • Right to data portability (Article 20)
  • Right to object (Article 21)

The Customer retains responsibility for ensuring data subject requests are handled within the statutory timeframe (generally 30 days under GDPR).

11. Personal Data Breach Notification

GuideUp shall notify the Customer without undue delay, and in any event within 72 hoursof becoming aware, of a confirmed Security Incident affecting personal data processed under this DPA. Notification will be sent to the Customer's registered account email address and will include, to the extent known at the time:

  • A description of the nature of the Security Incident, including the categories and approximate number of data subjects and personal data records affected
  • The name and contact details of GuideUp's point of contact for breach-related inquiries
  • The likely consequences of the Security Incident
  • The measures taken or proposed to address the incident and mitigate its effects

Where the full details are not available at the time of the initial notification, GuideUp will provide further information in phases as it becomes available. GuideUp's notification does not constitute an admission of fault or liability.

The Customer is responsible for determining whether the Security Incident requires notification to supervisory authorities and/or data subjects under GDPR Articles 33 and 34, and for making any required notifications within the applicable timeframes.

12. International Transfers

Personal data processed under this DPA may be transferred to and stored on servers located outside the EEA (including India and the United States) in connection with GuideUp's sub-processors. GuideUp ensures that all such transfers are subject to appropriate safeguards in accordance with Chapter V of GDPR, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission where applicable
  • Adequacy decisions where the receiving country benefits from one
  • Binding corporate rules or other approved mechanisms where applicable

Details of the transfer mechanisms applicable to each sub-processor are available in the sub-processor list at guideup.co/sub-processors.

13. Data Retention and Deletion on Contract End

Upon termination or expiry of the Customer's subscription, GuideUp will retain Customer data for a period of 90 days to allow the Customer to export any data they require. After this retention period, GuideUp will securely delete or anonymise all personal data processed under this DPA, unless retention is required by applicable law.

Customers may request earlier deletion by contacting legal@guideup.co. GuideUp will provide written confirmation of deletion upon request.

Backup copies of data may persist for up to 30 days after deletion from live systems due to backup rotation cycles; such backup data is subject to the same security and confidentiality obligations.

14. GDPR Article 28 Compliance

This DPA is intended to satisfy the requirements of GDPR Article 28(3), which requires that processing by a processor shall be governed by a contract setting out the subject matter, duration, nature, purpose, type of personal data, categories of data subjects, and obligations and rights of the Controller.

The parties agree that this DPA, together with the Terms of Service, constitutes the processing agreement required under Article 28(3) GDPR.

15. Contact and Execution

This DPA is entered into automatically upon acceptance of GuideUp's Terms of Service and does not require a separate signature. For enterprise customers requiring a countersigned copy of this DPA, please contact us at legal@guideup.co.

GuideUp Technologies Private Limited
Email: legal@guideup.co