Legal
Data Processing Addendum
Last updated: July 3, 2026
1. Roles
When a workspace stores personal data about its clients in TripOS (names, contact details, preferences, trip notes), the workspace is the controller and TripOS is the processor, acting only on the workspace’s documented instructions: providing, securing, and supporting the Service. For account data of TripOS users themselves, TripOS is the controller as described in the Privacy Policy.
2. Processing details
- Subject matter & duration: client and traveler data processed for as long as the workspace stores it.
- Nature & purpose: hosting, itinerary generation, delivery of client-facing documents, email on the workspace’s behalf.
- Categories of data: contact details, travel preferences, itinerary contents, notes entered by the workspace.
- Data subjects: the workspace’s clients and travelers.
3. Our commitments
- Process client data only to provide the Service.
- Keep tenancy isolation enforced in the data layer, with role-based access and audit logging in every workspace.
- Bind everyone with access to confidentiality obligations.
- Use the subprocessors listed in the Privacy Policy under equivalent terms, and post material changes before they take effect.
- Notify workspace owners without undue delay of any personal data breach affecting their data.
- Delete or return workspace data on deletion of the workspace, subject to backup rotation (up to 30 days).
- Assist with data-subject requests and, to the extent reasonable, with impact assessments.
4. Executing a signed DPA
A countersigned DPA incorporating EU Standard Contractual Clauses is available for workspaces on the Agency and Enterprise plans. Email legal@tripos.dev from an owner’s address with your workspace name and we’ll send the execution copy. This page summarizes the addendum; the signed document prevails for workspaces that execute it.