Data processing agreement
This Data Processing Agreement (DPA) is part of the Terms of service. It applies when an agency (the controller) uses GateRoam and GateRoam processes personal data on the agency's behalf. The agency accepts it together with the Terms when its owner creates the agency.
1. Parties
- Controller: the travel agency that uses GateRoam, represented by its owner.
- Processor: Tine Dolenc, s.p., Slovenia, operator of GateRoam. GateRoam is a spin-off project built with Current Code; it has no legal structure of its own yet and is offered for testing purposes only. Contact: [email protected].
2. What is processed
| Item | Details |
|---|---|
| Subject matter | Running the GateRoam Service for the agency: AI connections, supplier searches and pricing, client offers |
| Duration | As long as the agency uses the Service, plus the deletion period in section 9 |
| Nature and purpose | Storing, organising, retrieving, displaying, sending to the agency's AI app and suppliers, publishing offers by link, deleting |
| Data subjects | The agency's members; the agency's clients and travellers; other people the agency mentions in offers |
| Personal data | Names and email addresses of members; client names and anything the agency writes or puts into offers; when an offer link was opened; search details the AI sends (routes, dates, passenger counts, and any names it includes); logs of AI and supplier calls |
| Special categories | None intended. The agency must not put special categories of data (for example health data) into the Service. |
3. Instructions
We process personal data only on the agency's documented instructions. Using the Service, its settings and its AI tools, and these Terms, are the agency's instructions. We will tell the agency if we think an instruction breaks data protection law. We may process data without instructions only where EU or Slovenian law requires it, and we will tell the agency unless that law forbids it.
The agency is responsible for having a legal basis for the personal data it puts into the Service and for informing its clients.
4. Confidentiality
Everyone we allow to process the data is bound by confidentiality.
5. Security
We take appropriate technical and organisational measures (GDPR Art. 32), including:
- encryption in transit (TLS);
- supplier keys encrypted with a key kept apart from the database; tokens stored only as hashes;
- separation between agencies by database row-level security, and access by role within an agency;
- access to production systems limited to the operator, with key-based server access;
- backups at our hosting and database providers.
GateRoam is in early access and these measures may change, without lowering the overall level of protection.
6. Sub-processors
The agency gives general authorisation for us to use sub-processors. The current ones:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | EU (Ireland) |
| Hetzner Online | Application server | EU (Helsinki, Finland) |
| Cloudflare | DNS, network protection, content delivery, spam check | Global network |
| Resend | Sending emails | See Resend's privacy policy |
We bind each sub-processor to data protection terms that are at least as protective as this DPA, and we remain responsible for them. We will update this list before adding or replacing a sub-processor. If the agency objects, it may stop using the Service and close its agency.
The agency's travel suppliers (such as Amadeus) and its AI app (such as Claude or ChatGPT) are not our sub-processors. The agency chooses them and sends data to them under its own contracts.
7. Transfers outside the EU/EEA
Where a sub-processor processes data outside the EU/EEA, the transfer relies on an adequacy decision (including the EU-US Data Privacy Framework) or the European Commission's Standard Contractual Clauses.
8. Help for the agency
Taking into account what the Service does and the information we have, we help the agency:
- answer requests from data subjects (access, correction, deletion and others). Requests we receive directly about agency data are passed to the agency;
- meet its duties on security, breach notification, data protection impact assessments and prior consultation (GDPR Art. 32 to 36).
9. Personal data breaches
We tell the agency without undue delay after we become aware of a personal data breach affecting its data, with the information we have at that time, and update it as we learn more.
10. End of processing
When the agency is closed, we delete its personal data within 90 days, unless the law requires us to keep it. Before closing, the agency can copy what it needs from the app (for example its offers) or ask us for an export.
11. Proof and audits
On request, we give the agency the information it needs to show that this DPA is followed. Audits beyond that are done in writing (questionnaire), with reasonable notice, at most once a year unless a breach or an authority requires otherwise.
12. Liability and precedence
Liability under this DPA follows the limits in the Terms of service, to the extent the law allows. If this DPA and the Terms disagree on personal data processing, this DPA applies.
13. Contact
Tine Dolenc, s.p., operator of GateRoam: [email protected].