Support Desk: Found a bug or facing any issue? Please contact the Travflex Support Team immediately. Your feedback helps us improve the system and resolve issues quickly.
Travflex CRM is now 100% Free Create Free Account →
Legal

Data Processing Agreement

How we process personal data on behalf of your agency.

Last updated: August 1, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between travflex Technologies ("Processor," "we," "us," or "our") and the travel agency using the travflex platform ("Controller," "you," or "your").

This DPA supplements the Terms of Service and Privacy Policy and applies when travflex processes personal data on your behalf.

1. Scope & Purpose

This DPA applies when you use the travflex CRM to process personal data of your clients, travellers, and business contacts. As the Controller, you determine the purposes and means of processing. travflex, as the Processor, processes personal data only on your documented instructions and in accordance with this DPA.

2. Definitions

  • Personal Data: Any information relating to an identified or identifiable individual processed through the Service, including traveller names, passport details, contact information, and booking records.
  • Processing: Any operation performed on personal data, including collection, storage, use, transmission, and deletion.
  • Sub-processor: A third-party service provider engaged by travflex to assist in processing personal data.
  • Data Subject: The individual whose personal data is being processed (e.g., your clients and travellers).

3. Data Processing Obligations

travflex shall:

  • Process personal data only on documented instructions from the Controller.
  • Ensure that personnel authorised to process personal data have committed themselves to confidentiality.
  • Implement appropriate technical and organisational security measures (see Section 6).
  • Not engage another sub-processor without prior written authorisation from the Controller.
  • Assist the Controller in responding to Data Subject rights requests.
  • Delete or return all personal data upon termination of the Service, at the Controller's choice.
  • Make available all information necessary to demonstrate compliance and allow for audits.

4. Controller Responsibilities

The Controller shall:

  • Ensure it has a lawful basis for processing personal data through the Service.
  • Provide clear instructions to travflex regarding the processing of personal data.
  • Notify travflex promptly of any data subject complaints or regulatory inquiries related to the processed data.
  • Conduct its own data protection impact assessments where required by applicable law.

5. Sub-processors

travflex uses the following categories of sub-processors to provide the Service:

  • Cloud hosting providers — for data storage and infrastructure
  • Email service providers — for transactional and notification emails
  • Analytics providers — for anonymised usage analytics
  • Payment processors — for billing and subscription management

travflex will notify the Controller of any changes to its sub-processors at least 30 days in advance. The Controller may object to a new sub-processor within 14 days of notification.

6. Security Measures

travflex implements the following technical and organisational measures:

  • AES-256 encryption at rest for all stored personal data
  • TLS 1.3 encryption for all data in transit
  • Role-based access controls with principle of least privilege
  • Multi-factor authentication for administrative access
  • Regular penetration testing and vulnerability assessments
  • Automated threat detection and incident response procedures
  • Regular backups with tested recovery procedures

7. Data Subject Rights

travflex will assist the Controller in responding to Data Subject requests (access, rectification, erasure, portability) within a reasonable timeframe. The Controller is responsible for managing Data Subject requests directly where possible, using the tools available within the travflex platform.

8. Data Breach Notification

In the event of a personal data breach, travflex shall:

  • Notify the Controller without undue delay, and no later than 48 hours after becoming aware of the breach.
  • Provide details of the breach, including the nature of data affected, the number of records, and the measures taken to address it.
  • Cooperate with the Controller to mitigate the impact and comply with regulatory notification obligations.

9. International Data Transfers

Where personal data is transferred outside the country of collection, travflex ensures appropriate safeguards are in place, including standard contractual clauses, adequacy decisions, or other legally recognised transfer mechanisms as required by applicable data protection laws.

10. Term & Termination

This DPA remains in effect for as long as travflex processes personal data on behalf of the Controller. Upon termination of the Service, travflex will, at the Controller's choice, delete or return all personal data within 30 days, except where retention is required by applicable law.

11. Governing Law

This DPA is governed by the laws of India, consistent with the Information Technology Act 2000 and the Digital Personal Data Protection Act 2023 (DPDP Act), and any applicable data protection regulations.

12. Contact Us

For questions about this DPA or our data processing practices:

travflex Technologies

Data Protection Officer: [email protected]

General: [email protected]

Enterprise data protection

travflex is built with enterprise-grade security. Start your free trial today.