Data processing agreement

How GateRoam processes personal data on behalf of travel agencies, under Article 28 of the GDPR.
Effective Tine Dolenc, s.p.[email protected]
Early access, for testing
GateRoam is a spin-off project of Current Code. It is in early access, offered for testing purposes, and has no legal structure of its own yet. Use it at your own risk.

This Data Processing Agreement (DPA) is part of the Terms of service. It applies when an agency (the controller) uses GateRoam and GateRoam processes personal data on the agency's behalf. The agency accepts it together with the Terms when its owner creates the agency.

1. Parties

  • Controller: the travel agency that uses GateRoam, represented by its owner.
  • Processor: Tine Dolenc, s.p., Slovenia, operator of GateRoam. GateRoam is a spin-off project built with Current Code; it has no legal structure of its own yet and is offered for testing purposes only. Contact: [email protected].

2. What is processed

ItemDetails
Subject matterRunning the GateRoam Service for the agency: AI connections, supplier searches and pricing, client offers
DurationAs long as the agency uses the Service, plus the deletion period in section 9
Nature and purposeStoring, organising, retrieving, displaying, sending to the agency's AI app and suppliers, publishing offers by link, deleting
Data subjectsThe agency's members; the agency's clients and travellers; other people the agency mentions in offers
Personal dataNames and email addresses of members; client names and anything the agency writes or puts into offers; when an offer link was opened; search details the AI sends (routes, dates, passenger counts, and any names it includes); logs of AI and supplier calls
Special categoriesNone intended. The agency must not put special categories of data (for example health data) into the Service.

3. Instructions

We process personal data only on the agency's documented instructions. Using the Service, its settings and its AI tools, and these Terms, are the agency's instructions. We will tell the agency if we think an instruction breaks data protection law. We may process data without instructions only where EU or Slovenian law requires it, and we will tell the agency unless that law forbids it.

The agency is responsible for having a legal basis for the personal data it puts into the Service and for informing its clients.

4. Confidentiality

Everyone we allow to process the data is bound by confidentiality.

5. Security

We take appropriate technical and organisational measures (GDPR Art. 32), including:

  • encryption in transit (TLS);
  • supplier keys encrypted with a key kept apart from the database; tokens stored only as hashes;
  • separation between agencies by database row-level security, and access by role within an agency;
  • access to production systems limited to the operator, with key-based server access;
  • backups at our hosting and database providers.

GateRoam is in early access and these measures may change, without lowering the overall level of protection.

6. Sub-processors

The agency gives general authorisation for us to use sub-processors. The current ones:

Sub-processorPurposeLocation
SupabaseDatabase, authentication, file storageEU (Ireland)
Hetzner OnlineApplication serverEU (Helsinki, Finland)
CloudflareDNS, network protection, content delivery, spam checkGlobal network
ResendSending emailsSee Resend's privacy policy

We bind each sub-processor to data protection terms that are at least as protective as this DPA, and we remain responsible for them. We will update this list before adding or replacing a sub-processor. If the agency objects, it may stop using the Service and close its agency.

The agency's travel suppliers (such as Amadeus) and its AI app (such as Claude or ChatGPT) are not our sub-processors. The agency chooses them and sends data to them under its own contracts.

7. Transfers outside the EU/EEA

Where a sub-processor processes data outside the EU/EEA, the transfer relies on an adequacy decision (including the EU-US Data Privacy Framework) or the European Commission's Standard Contractual Clauses.

8. Help for the agency

Taking into account what the Service does and the information we have, we help the agency:

  • answer requests from data subjects (access, correction, deletion and others). Requests we receive directly about agency data are passed to the agency;
  • meet its duties on security, breach notification, data protection impact assessments and prior consultation (GDPR Art. 32 to 36).

9. Personal data breaches

We tell the agency without undue delay after we become aware of a personal data breach affecting its data, with the information we have at that time, and update it as we learn more.

10. End of processing

When the agency is closed, we delete its personal data within 90 days, unless the law requires us to keep it. Before closing, the agency can copy what it needs from the app (for example its offers) or ask us for an export.

11. Proof and audits

On request, we give the agency the information it needs to show that this DPA is followed. Audits beyond that are done in writing (questionnaire), with reasonable notice, at most once a year unless a breach or an authority requires otherwise.

12. Liability and precedence

Liability under this DPA follows the limits in the Terms of service, to the extent the law allows. If this DPA and the Terms disagree on personal data processing, this DPA applies.

13. Contact

Tine Dolenc, s.p., operator of GateRoam: [email protected].