Data Processing Addendum
Effective date: April 17, 2026 · Version: 1.0.0
1. Parties and Role Allocation
This Data Processing Addendum ("DPA") governs the processing of End-Client Data by TripBuilt("TripBuilt") on behalf of Operators. It forms part of the Terms of Service.
- Operator is the Data Fiduciary (as defined under the DPDP Act, 2023) — the entity that determines the purposes and means of processing End-Client Data.
- TripBuilt is the Data Processor — processing End-Client Data solely on the Operator's instructions within the Platform.
TripBuilt acts as a separate Data Fiduciary for Personal Data of Operators' authorized users processed for its own account management purposes, which is governed by the Privacy Policy.
2. Subject-Matter and Duration
TripBuilt shall process End-Client Data to provide the Platform services described in the Terms and Documentation. Processing continues for the duration of the Operator's active Subscription plus the 30-day data export window following termination, after which TripBuilt deletes or anonymizes the data per the Privacy Policy retention schedule, unless Applicable Law requires longer retention.
3. Nature and Purpose of Processing
TripBuilt processes End-Client Data to:
- Store and display End-Client profiles, booking details, and travel documents;
- Enable the Operator to generate proposals, itineraries, and GST invoices;
- Facilitate WhatsApp and email communications between Operator and End-Clients;
- Enable payment tracking and reconciliation;
- Provide AI-assisted features where the Operator has activated them;
- Maintain audit logs and ensure Platform security; and
- Comply with Applicable Law and lawful regulatory requests.
TripBuilt shall not process End-Client Data for its own marketing, product development, or commercial purposes.
4. Types of Personal Data and Categories
End-Client Data processed through the Platform may include: names, email addresses, phone numbers, passport and travel document numbers, travel itineraries, payment references, preferences and special requirements, and any other data the Operator chooses to enter.
Sensitive Personal Data: Passport numbers and government-issued identifiers are Sensitive Personal Data under the SPDI Rules. Operators are responsible for ensuring they have a required lawful basis before entering such data.
5. Operator Obligations
The Operator represents, warrants, and covenants that:
- It has a lawful basis under the DPDP Act for processing each category of End-Client Data;
- It has provided End-Clients with all required privacy notices and obtained all required consents;
- It is solely responsible for the accuracy and completeness of End-Client Data;
- It will respond to rights requests from End-Clients and relay to TripBuilt any rights requests requiring TripBuilt's assistance;
- It will not instruct TripBuilt to process End-Client Data in violation of Applicable Law; and
- It will promptly notify TripBuilt of any breach or unauthorized access to End-Client Data.
6. TripBuilt's Obligations as Data Processor
- Processing per Instructions: Process End-Client Data only on documented Operator instructions.
- Confidentiality: Ensure all personnel authorized to process End-Client Data are bound by confidentiality obligations.
- Security: Maintain the security measures described in Section 9 and the Privacy Policy.
- Breach Notification: Notify the Operator within 48 hours of becoming aware of a Personal Data breach affecting End-Client Data.
- Rights Request Assistance: Provide reasonable assistance for Operator compliance with End-Client rights requests.
- Sub-Processors: Provide at least 30 days' written notice before engaging a new Sub-Processor or making material changes.
- Return and Deletion: On Subscription expiry, make End-Client Data available for download or delete it and certify deletion in writing.
7. Sub-Processors
| Sub-Processor | Purpose | Country |
|---|---|---|
| Supabase Inc. | Database hosting, authentication, storage | Singapore |
| Vercel Inc. | Platform hosting, CDN, serverless functions | United States |
| Razorpay Software Pvt Ltd | Payment processing, GST invoicing | India |
| Meta Platforms, Inc. | WhatsApp Cloud API — message delivery | United States |
| Google LLC | Gmail API integration | United States |
| OpenAI LLC | AI-assisted content generation | United States |
| Upstash Inc. | Rate limiting, caching (Redis) | United States / EU |
8. International Data Transfers
End-Client Data is processed by some Sub-Processors outside India. Where the destination country is notified as adequate under Section 16 of the DPDP Act, the transfer proceeds on that basis. Otherwise, TripBuilt ensures contractual safeguards requiring equivalent data protection standards. All transfers comply with FEMA, 1999 to the extent applicable.
9. Security Measures
- Encryption in Transit: TLS 1.2 or higher on all data transmissions.
- Encryption at Rest: AES-256 via Supabase's storage layer.
- Access Controls: Role-based access controls (RBAC) with multi-factor authentication for production systems.
- Audit Logging: All access to End-Client Data logged and retained for 12 months.
- Vulnerability Management: Regular dependency audits (Dependabot, npm audit) and code reviews.
- Incident Response: Written incident response procedure with priority triage.
- Sub-Processor Due Diligence: Sub-Processors required to maintain industry-standard security certifications.
- Network Security: Firewall controls, rate limiting (Upstash), and DDoS mitigation (Vercel edge network).
10. Audit Rights
No more than once per 12-month period (unless TripBuilt has suffered a material security incident), the Operator may request an audit of TripBuilt's data processing activities. At least 30 days' written notice is required. Audits occur during business hours at the Operator's expense without unreasonably disrupting TripBuilt's operations. TripBuilt may satisfy the audit right by providing a current third-party audit report (e.g., SOC 2 Type II) covering the relevant controls.
11. Governing Law
This DPA is governed by the laws of India. Disputes arising under this DPA are resolved per the dispute resolution provisions in the Terms of Service, with courts of Hyderabad, Telangana having jurisdiction for non-arbitrated matters.
Questions? Contact: support@tripbuilt.com · TripBuilt · https://tripbuilt.com