B2B · Data Processing Agreement
Data Processing Agreement (DPA)
How personal data of Partner's customers is handled when SkyLux-Global manages bookings on Partner's behalf, in line with Art. 28 GDPR and the CCPA.
Ultimo aggiornamento: 25 settembre 2026
Bozza in fase di revisione legale: il testo non è ancora definitivo e può cambiare prima del lancio.
1. Roles
| Party | Role | Scope |
|---|---|---|
| Partner | Data Controller | Its customers' personal data and the purposes of processing |
| SkyLux-Global Inc. | Data Processor (CCPA: service provider) | Processing needed to search, book, ticket and service bookings for Partner |
| Airlines, properties and other suppliers | Independent controllers | Data needed to perform the travel service |
2. Instructions
- SkyLux-Global processes personal data only on Partner's documented instructions, which are the agreement and Partner's API requests.
- Partner instructs and authorises SkyLux-Global to anonymise personal data and to use the resulting anonymised data as described in the Intellectual Property, AI & Data terms. Anonymised data is no longer personal data.
- SkyLux-Global will inform Partner if it believes an instruction infringes data protection law.
3. Security measures
- Encryption in transit (TLS 1.2+) and at rest.
- Role-based access control, least privilege and audit logging.
- Confidentiality obligations for all staff and contractors with access to personal data.
- Regular backups, vulnerability management and incident response procedures.
4. Sub-processors
Partner authorises the use of sub-processors (e.g. cloud hosting, payment processing, email delivery, AI services). SkyLux-Global keeps an up-to-date list, gives [30] days' notice of new sub-processors so Partner can object, and imposes equivalent data protection obligations on each of them.
5. Assistance, breaches and audits
- SkyLux-Global assists Partner in responding to data subject requests and with data protection impact assessments.
- Personal data breaches are notified to Partner without undue delay and in any case within [48] hours of discovery.
- Partner may audit compliance once a year with 30 days' notice, or rely on SkyLux-Global's independent audit reports.
6. International transfers
Transfers of EEA personal data outside the EEA are covered by the European Commission's Standard Contractual Clauses (or the EU-US Data Privacy Framework where applicable), incorporated by reference into the DPA.
7. PCI DSS
- SkyLux-Global processes card payments through PCI DSS Level 1 certified payment providers and does not store full card numbers. SkyLux-Global's own PCI DSS compliance status: [SAQ type / level to be confirmed].
- When Partner transmits card data to SkyLux-Global, it must be PCI DSS compliant, use tokenisation or encrypted channels, and never send full card numbers by email, chat or unencrypted files.
8. Deletion at the end of the agreement
At the end of the agreement, SkyLux-Global deletes or returns Partner's personal data, at Partner's choice, except where retention is required by law (e.g. tax records) or needed to service bookings not yet travelled.
Documenti per i partner
Non trovi quello che cerchi? Centro assistenza
