Privacy & Data

GDPR Compliance

How Tripistic meets EU and UK GDPR obligations — lawful bases, data subject rights, transfer safeguards, subprocessors, and breach notification.

Last updated July 1, 2026·Effective July 1, 2026·3 min read

Template notice. Confirm your representative details, supervisory authority, and subprocessor list with counsel before publishing.

Tripistic is built for operators selling travel across the European Economic Area, the United Kingdom, and Switzerland. This page sets out how we support compliance with the General Data Protection Regulation and UK GDPR.

Controller and processor roles

ScenarioControllerProcessor
Your Tripistic account, billing, supportTripisticOur vendors
Traveller, booking, participant, and CRM records in your workspaceYou, the operatorTripistic
Website analytics on tripistic.comTripisticAnalytics vendors

When we act as processor, the Data Processing Agreement governs the engagement and is incorporated into your subscription automatically — no signature required.

Lawful bases

We rely on performance of a contract for delivering the platform; legitimate interests for security, fraud prevention, and product analytics; consent for marketing cookies and advertising measurement; and legal obligation for tax, accounting, and audit records. Our balancing tests for legitimate-interest processing are documented and available to enterprise customers on request.

Data subject rights

Travellers and operator staff can exercise the following rights:

RightGDPR articleHow we support it
AccessArt. 15Workspace data export, plus manual fulfilment within 30 days
RectificationArt. 16Direct editing of customer, participant, and booking records
ErasureArt. 17Record-level deletion and full workspace purge within 30 days
RestrictionArt. 18Record flagging that suspends automated messaging
PortabilityArt. 20Structured export of workspace data
ObjectionArt. 21Marketing opt-out and objection handling
Automated decisionsArt. 22No solely automated decisions with legal effect; AI output is advisory and human-reviewed

If a traveller contacts us directly about data held in an operator's workspace, we acknowledge the request and route it to that operator as controller, then support fulfilment.

Records of processing

We maintain an Article 30 record of processing activities covering purposes, categories of data subjects and data, recipients, transfers, retention, and security measures. Enterprise customers can request an extract under NDA.

International transfers

For transfers out of the EEA, UK, or Switzerland we rely on:

  • European Commission Standard Contractual Clauses (2021/914), modules two and three as applicable.
  • The UK International Data Transfer Addendum.
  • Transfer impact assessments covering the destination legal regime.
  • Supplementary measures: TLS in transit, encryption at rest, tenant isolation, least-privilege access, and audit logging.

Where a customer requires EU-only data residency, this is available on enterprise plans — contact sales@tripistic.com.

Subprocessors

The current subprocessor list is published in the Privacy Policy. We notify account administrators at least 30 days before adding a subprocessor that processes personal data, and you may object on reasonable data-protection grounds.

Security measures

Technical and organisational measures are described in the Security Policy and Annex II of the DPA: encryption, access control, tenant isolation enforced on every query path, signed webhooks, audit logging, backup and restore testing, secure development practices, and vendor due diligence.

Personal data breach

We maintain an incident response process with defined severity levels, on-call escalation, and forensic logging. Where we act as processor we notify affected controllers without undue delay and within 72 hours of becoming aware of a personal data breach, with the information required by Article 33(3) as it becomes available. Where we act as controller we notify the competent supervisory authority and, where required, affected individuals.

Data protection impact assessments

We support customer DPIAs with architecture documentation, data-flow descriptions, retention schedules, and security control summaries. Contact privacy@tripistic.com.

Children and vulnerable travellers

Operators running educational, youth, or accessibility-sensitive programs must obtain the consents their jurisdiction requires before uploading participant or guardian data. Tripistic provides waiver, document, and participant records to support that, but the lawful basis remains the operator's responsibility.

Contact

  • Data protection enquiries: privacy@tripistic.com
  • EU and UK representative details: available on request via the contact form
  • You also have the right to lodge a complaint with your local supervisory authority.

Questions about this document?

Email legal@tripistic.com or use the contact form. Enterprise teams can request countersigned copies and completed security questionnaires.