Privacy & Data
GDPR Compliance
How Tripistic meets EU and UK GDPR obligations — lawful bases, data subject rights, transfer safeguards, subprocessors, and breach notification.
Template notice. Confirm your representative details, supervisory authority, and subprocessor list with counsel before publishing.
Tripistic is built for operators selling travel across the European Economic Area, the United Kingdom, and Switzerland. This page sets out how we support compliance with the General Data Protection Regulation and UK GDPR.
Controller and processor roles
| Scenario | Controller | Processor |
|---|---|---|
| Your Tripistic account, billing, support | Tripistic | Our vendors |
| Traveller, booking, participant, and CRM records in your workspace | You, the operator | Tripistic |
| Website analytics on tripistic.com | Tripistic | Analytics vendors |
When we act as processor, the Data Processing Agreement governs the engagement and is incorporated into your subscription automatically — no signature required.
Lawful bases
We rely on performance of a contract for delivering the platform; legitimate interests for security, fraud prevention, and product analytics; consent for marketing cookies and advertising measurement; and legal obligation for tax, accounting, and audit records. Our balancing tests for legitimate-interest processing are documented and available to enterprise customers on request.
Data subject rights
Travellers and operator staff can exercise the following rights:
| Right | GDPR article | How we support it |
|---|---|---|
| Access | Art. 15 | Workspace data export, plus manual fulfilment within 30 days |
| Rectification | Art. 16 | Direct editing of customer, participant, and booking records |
| Erasure | Art. 17 | Record-level deletion and full workspace purge within 30 days |
| Restriction | Art. 18 | Record flagging that suspends automated messaging |
| Portability | Art. 20 | Structured export of workspace data |
| Objection | Art. 21 | Marketing opt-out and objection handling |
| Automated decisions | Art. 22 | No solely automated decisions with legal effect; AI output is advisory and human-reviewed |
If a traveller contacts us directly about data held in an operator's workspace, we acknowledge the request and route it to that operator as controller, then support fulfilment.
Records of processing
We maintain an Article 30 record of processing activities covering purposes, categories of data subjects and data, recipients, transfers, retention, and security measures. Enterprise customers can request an extract under NDA.
International transfers
For transfers out of the EEA, UK, or Switzerland we rely on:
- European Commission Standard Contractual Clauses (2021/914), modules two and three as applicable.
- The UK International Data Transfer Addendum.
- Transfer impact assessments covering the destination legal regime.
- Supplementary measures: TLS in transit, encryption at rest, tenant isolation, least-privilege access, and audit logging.
Where a customer requires EU-only data residency, this is available on enterprise plans — contact sales@tripistic.com.
Subprocessors
The current subprocessor list is published in the Privacy Policy. We notify account administrators at least 30 days before adding a subprocessor that processes personal data, and you may object on reasonable data-protection grounds.
Security measures
Technical and organisational measures are described in the Security Policy and Annex II of the DPA: encryption, access control, tenant isolation enforced on every query path, signed webhooks, audit logging, backup and restore testing, secure development practices, and vendor due diligence.
Personal data breach
We maintain an incident response process with defined severity levels, on-call escalation, and forensic logging. Where we act as processor we notify affected controllers without undue delay and within 72 hours of becoming aware of a personal data breach, with the information required by Article 33(3) as it becomes available. Where we act as controller we notify the competent supervisory authority and, where required, affected individuals.
Data protection impact assessments
We support customer DPIAs with architecture documentation, data-flow descriptions, retention schedules, and security control summaries. Contact privacy@tripistic.com.
Children and vulnerable travellers
Operators running educational, youth, or accessibility-sensitive programs must obtain the consents their jurisdiction requires before uploading participant or guardian data. Tripistic provides waiver, document, and participant records to support that, but the lawful basis remains the operator's responsibility.
Contact
- Data protection enquiries: privacy@tripistic.com
- EU and UK representative details: available on request via the contact form
- You also have the right to lodge a complaint with your local supervisory authority.
Questions about this document?
Email legal@tripistic.com or use the contact form. Enterprise teams can request countersigned copies and completed security questionnaires.