Data Processing Addendum
Last updated: 2026-04-22
This Data Processing Addendum ("DPA") applies between the Customer identified in an Order Form or Twendie account (the "Controller") and Neonworks Consulting Limited (the "Processor" or "Twendie"). It is incorporated into and governed by the Terms of Service.
Where a Customer requires a signed version of this DPA, countersign below and email a copy to legal@twendie.com. We will return a countersigned copy.
1. Definitions
Terms used but not defined in this DPA have the meanings given in the Terms of Service or applicable data protection laws ("Data Protection Laws"), including the EU and UK General Data Protection Regulation, the Kenya Data Protection Act, 2019, and the California Consumer Privacy Act (as amended). "Personal Data," "Process," "Controller, " and "Processor" have the meanings given in those laws.
2. Scope and roles
This DPA applies to Twendie's Processing of Customer Personal Data that constitutes personal data under Data Protection Laws. The Controller is the controller of such personal data, and Twendie is the processor. Details of processing (subject matter, duration, nature, purpose, categories of data and data subjects) are set out in Schedule 1.
3. Processing on instructions
Twendie will Process Customer Personal Data only on the Controller's documented instructions, including as set out in the Terms of Service, this DPA, and the Controller's configuration of the Service, unless required to do otherwise by applicable law. Twendie will inform the Controller of any such legal requirement before Processing, unless the law prohibits such notice on important grounds of public interest.
4. Confidentiality
Twendie ensures that personnel authorised to Process Customer Personal Data are bound by written confidentiality obligations and have received appropriate training on data protection.
5. Security measures
Twendie implements and maintains the technical and organisational measures set out in Schedule 2 to ensure a level of security appropriate to the risk.
6. Sub-processors
The Controller authorises Twendie to engage the sub-processors listed at /sub-processors. Twendie will:
- impose data protection obligations on each sub-processor that are no less protective than those in this DPA;
- remain liable for each sub-processor's performance;
- give the Controller at least 30 days' notice of any addition or replacement of sub-processors (by updating the sub-processor page and, for Customers subscribed to update notifications, by email);
- give the Controller a reasonable opportunity to object on reasonable grounds related to data protection. If the objection cannot be resolved, the Controller may terminate the affected part of the Service for convenience and receive a pro-rata refund of pre-paid unused fees.
7. Assistance to the Controller
Taking into account the nature of the Processing and information available to it, Twendie will assist the Controller (at the Controller's cost where reasonable) in:
- responding to data subject requests (access, rectification, erasure, restriction, portability, objection);
- meeting obligations under Articles 32–36 of the GDPR or equivalent provisions of other Data Protection Laws (security, breach notification, impact assessments, prior consultation).
8. Personal data breach notification
Twendie will notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will include, to the extent known, the nature of the breach, categories and approximate number of affected data subjects and records, likely consequences, and measures taken or proposed.
9. Return or deletion
On termination or expiry of the Service, Twendie will, at the Controller's choice, return or delete Customer Personal Data within the periods stated in the Terms of Service and Privacy Policy, except to the extent applicable law requires continued storage.
10. Audit
Twendie will make available to the Controller the information reasonably necessary to demonstrate compliance with this DPA, including a summary of its most recent third-party security audit where available. Audits beyond written information are limited to once per 12 months, on reasonable notice, during business hours, by an independent auditor bound by confidentiality, and not disruptive to the Service. The Controller bears its own costs; additional Twendie costs are payable by the Controller at reasonable rates.
11. International transfers
Where Twendie transfers Customer Personal Data out of the EEA, the UK, or another jurisdiction requiring a transfer mechanism, the parties agree that:
- the EU Standard Contractual Clauses (Module 2: Controller to Processor) and, as applicable, the UK International Data Transfer Addendum are incorporated into this DPA by reference, with Twendie as data importer and the Controller as data exporter;
- the optional docking clause, third-party beneficiary rights, and governing-law selections are as set out in the Terms of Service (Kenya) to the extent permitted; otherwise the laws of Ireland apply to the EU SCCs;
- for transfers subject to the Kenya Data Protection Act 2019, the parties rely on contractual safeguards and, where required, authorisation from the Office of the Data Protection Commissioner.
12. California (CCPA/CPRA)
To the extent the CCPA applies, Twendie acts as a " service provider" and will not (a) sell or share Personal Information, (b) retain, use, or disclose Personal Information outside the direct business relationship or for any purpose other than the business purposes specified in the Terms of Service, or (c) combine Personal Information received from the Controller with personal information received from other sources, except as permitted by the CCPA.
13. Liability
The liability of each party under or in connection with this DPA is subject to the limitations and exclusions of liability in the Terms of Service.
14. Order of precedence
If there is any conflict between this DPA and the Terms of Service, this DPA prevails to the extent of the conflict, except that the Standard Contractual Clauses prevail over this DPA to the extent of any conflict relating to international transfers.
Schedule 1 - Details of processing
Subject matter
The provision of the Twendie Service to the Controller under the Terms of Service.
Duration
For the duration of the Service, plus the retention periods set out in the Privacy Policy and Terms of Service.
Nature and purpose
Hosting, storing, transmitting, organising, retrieving, and otherwise processing Customer Personal Data to provide the Service, including AI-assisted features.
Categories of data subjects
- the Controller's personnel and authorised users;
- the Controller's clients, prospects, and travellers (End Users);
- third parties referenced by the Controller or End Users in itineraries, messages, or documents.
Categories of personal data
- identification and contact data (name, email, phone);
- profile and preference data (travel preferences, dietary requirements, accessibility needs);
- itinerary and booking-related data;
- communications (messages, emails, attachments) exchanged through the Service;
- technical and usage data (IP address, device, logs) collected when End Users interact with share links or forms;
- billing identifiers limited to what is needed to manage Customer's own billing (full payment card numbers are handled by payment processors and not stored by Twendie).
Special categories
The Service is not intended for special-category data. The Controller must not enter special-category data (for example, health, racial or ethnic origin, biometric or genetic data, political opinions) beyond what is strictly necessary for travel planning and permitted under applicable law.
Schedule 2 - Security measures
- Access control: role-based access, unique accounts, mandatory MFA for production access, periodic access review.
- Authentication: passwords stored only as salted hashes; SSO and MFA supported in the application.
- Encryption: TLS 1.2+ in transit; encryption at rest for primary data stores.
- Network security: segmented production network, restricted ingress, web application firewall, DDoS protection at the cloud provider layer.
- Logging and monitoring: centralised logs, automated alerting for anomalous activity.
- Vulnerability management: automated dependency scanning, periodic third-party security testing, patching cadence aligned to severity.
- Backup and recovery: regular encrypted backups with defined retention and tested recovery procedures.
- Secure SDLC: code review, separation of environments, least-privilege CI/CD credentials.
- Incident response: documented playbooks and 72-hour breach notification commitment.
- Personnel: background checks where permitted, confidentiality obligations, security and privacy training.
- Vendor management: due diligence and contractual commitments with sub-processors (see Schedule 3).
- Physical security: production data is hosted by cloud providers whose data centres are physically secured to recognised industry standards.
Schedule 3 - Sub-processors
The current list of authorised sub-processors is maintained at /sub-processors and is incorporated into this DPA by reference.