Data Processing Agreement (Art. 28 GDPR)
Version of 29 September 2026 — English translation for convenience; the German version is binding.
between the agency using Navklar (the "Controller") and Donau Ventures Private Limited, [Anschrift der Donau Ventures Private Limited / address — placeholder] (the "Processor"). Representative in the European Union: Manigrama [Rechtsform und Anschrift / legal form and address — placeholder].
1. Subject and duration
- The Processor runs the platform Navklar for the Controller and processes personal data on the Controller's behalf.
- This agreement applies for as long as the Controller uses the Platform.
2. Nature, purpose and scope
- Purpose: providing the customer website, the assistant, flight search and booking, request handling, invoicing and email for the Controller.
- Data subjects: the Controller's customers and prospects, fellow travellers, the Controller's staff.
- Categories of data: name, phone number, email address, travel wishes and searches, messages to the assistant and to the agency, for bookings the travellers' names, dates of birth and gender, booking and invoice data, billing address; for staff, account and log data.
3. Instructions
The Processor processes the data only on documented instructions from the Controller — including the settings the Controller makes in the Platform — unless required to do so by law. If it considers an instruction unlawful, it tells the Controller.
4. Obligations of the Processor
- People with access to the data are bound to confidentiality.
- It takes the technical and organisational measures in Annex 1 (Art. 32 GDPR) and keeps them up to date without lowering the level of protection.
- It helps the Controller with data subjects' requests (Art. 12–22 GDPR), with notifying personal data breaches (Art. 33, 34 GDPR) and with data protection impact assessments.
- It notifies the Controller of a personal data breach without undue delay after becoming aware of it.
- At the end of the agreement it returns the data on request and then deletes it, unless the law requires it to be kept.
- It provides the information needed to demonstrate compliance with these obligations and allows audits by arrangement.
5. Sub-processors
- The Controller agrees to the sub-processors in Annex 2.
- The Processor informs the Controller of intended changes in advance in text form; the Controller may object for an important data protection reason within 14 days.
- The Processor binds sub-processors to the same data protection obligations by contract.
- Transfers to countries outside the EU / EEA take place only under Art. 44 et seq. GDPR.
6. Obligations of the Controller
The Controller is responsible for the lawfulness of the processing and for informing data subjects, in particular through a privacy notice on its customer website. The Platform provides a template for it.
Annex 1 — Technical and organisational measures
- Separation: each agency's data is held in its own database; access is limited to that agency.
- Access: personal accounts for all staff, passwords stored only as hashes, roles and permissions, a log of important actions, limits on sign-in attempts.
- Transmission: encrypted transmission (TLS). Credentials for the agency's email accounts are stored encrypted.
- Availability: regular backups of the databases.
- Data minimisation: travellers' dates of birth and gender are sent to the flight supplier at booking but not stored.
Annex 2 — Sub-processors
| Sub-processor | Service | Location |
|---|---|---|
| Hostinger International Ltd (Lithuania, EU), data centre in Frankfurt am Main, Germany | Hosting the Platform | Germany (EU) |
| OpenAI | Digital assistant on the customer website (customers' messages) | USA — standard contractual clauses (Art. 46 GDPR) |
| Jinko | Flight search and booking (for bookings: traveller data) | [location, safeguards — placeholder] |
| The agency's email service | Sending emails to customers — chosen by the agency itself | — |