Data Processing Agreement

AIRSHIP SERVICES LIMITED — DATA PROCESSING AGREEMENT — SCHEDULE 2 TO THE AIRSHIP & TOGGLE STANDARD TERMS AND CONDITIONS

This Data Processing Agreement ("DPA") forms Schedule 2 to the Agreement between Airship Services Limited ("Airship") and the Client identified in the Order Form (Schedule 1). It sets out the terms on which Airship processes Personal Data on behalf of the Client in connection with the provision of the Services. In the event of any conflict between this DPA and the main body of the Agreement, this DPA shall prevail in respect of data protection matters.

1. DEFINITIONS

In this DPA, the following terms have the meanings set out below. Capitalised terms not defined here have the meaning given in the Agreement.

Appropriate SafeguardsLegally enforceable mechanisms for international transfers of Personal Data permitted under Data Protection Legislation from time to time (including UK Standard Contractual Clauses or adequacy decisions).
ControllerHas the meaning given in Data Protection Legislation.
Data Protection LegislationAll applicable data protection and privacy legislation in force in the UK from time to time, including: (a) the UK GDPR; (b) the Data Protection Act 2018; (c) the Privacy and Electronic Communications Regulations 2003 (as amended); and (d) any laws implementing or supplementing the foregoing.
Data Protection LossesAll liabilities including costs (including legal costs), claims, demands, actions, settlements, charges, fines, penalties and sanctions imposed by a Supervisory Authority, and compensation ordered to be paid to a Data Subject.
Data SubjectHas the meaning given in Data Protection Legislation.
Data Subject RequestA request made by a Data Subject to exercise any right under Data Protection Legislation.
Personal DataPersonal data (as defined in Data Protection Legislation) included in the Client's data and processed by Airship in connection with the Services.
Personal Data BreachAny breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
Processing / Process / ProcessedHas the meaning given in Data Protection Legislation.
ProcessorHas the meaning given in Data Protection Legislation.
Sub-ProcessorAny third-party Processor engaged by Airship to process Personal Data on the Client's behalf.
Supervisory AuthorityThe Information Commissioner's Office (ICO) or any other relevant regulatory body responsible for administering Data Protection Legislation.
UK GDPRRegulation (EU) 2016/679 as it forms part of UK domestic law by virtue of the European Union (Withdrawal) Act 2018, as amended.

2. PROCESSOR AND CONTROLLER

2.1 The parties agree that, for the purposes of this DPA and Data Protection Legislation, the Client is the Controller and Airship is the Processor in respect of Personal Data processed in connection with the Services.

2.2 Nothing in this DPA relieves the Client of its own obligations or liabilities as Controller under Data Protection Legislation.

2.3 Airship shall process Personal Data only in accordance with this DPA and the Agreement and shall comply with Data Protection Legislation in its capacity as Processor.

2.4 The Client warrants, represents and undertakes that at all times: (a) it shall comply with Data Protection Legislation in its collection, storage and processing of Personal Data; (b) it has provided all necessary fair processing notices and, where required, obtained all necessary consents from Data Subjects in connection with the processing activities Airship performs on its behalf; and (c) all instructions it gives to Airship in respect of Personal Data shall at all times be in accordance with Data Protection Legislation.

3. PROCESSING INSTRUCTIONS

3.1 Airship shall (and shall take steps to ensure each person acting under its authority shall) process Personal Data only on and in accordance with the Client's documented instructions, which shall consist of: (a) the Agreement and this DPA; and (b) any further instructions the Client provides in writing from time to time that are consistent with the Agreement.

3.2 If Airship is required by applicable law to process Personal Data other than in accordance with the Client's instructions, Airship shall notify the Client before carrying out such processing (unless prohibited by law on grounds of public interest).

3.3 Airship shall promptly inform the Client if, in its reasonable opinion, an instruction infringes Data Protection Legislation, without obligation to take any action on that instruction until the Client has confirmed or amended it.

3.4 The Client acknowledges that any command to process (including deletion of) Personal Data executed through the Services by an Authorised User constitutes a processing instruction from the Client. The Client is responsible for ensuring Authorised Users are authorised to issue such instructions.

4. SECURITY AND TECHNICAL & ORGANISATIONAL MEASURES

4.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Airship shall implement and maintain appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful processing and accidental loss, destruction or damage.

4.2 Such measures include, at minimum:

  • Encryption of Personal Data at rest and in transit using industry-standard protocols; all stored passwords hashed and salted; backup data encrypted;
  • Access controls based on the principle of least privilege; multi-factor authentication enforced for all systems; no shared credentials; quarterly access reviews; access revoked promptly on staff departure;
  • Continuous automated vulnerability scanning and endpoint protection across all systems and devices; critical security patches applied within 28 days of release;
  • Network security controls including firewalls, VPN-protected administrative access, network segmentation, and intrusion detection;
  • Security event logging and monitoring across all systems; logs retained for a minimum of 5 years;
  • Separate development, staging and production environments; live Personal Data not used for testing; all code peer-reviewed prior to deployment; secure coding standards applied throughout the development lifecycle;
  • Regular data backups with tested restoration procedures; documented disaster recovery plan tested annually; high-availability infrastructure for the Toggle platform;
  • Documented incident response and business continuity plans; annual security risk assessments; annual review of all security policies;
  • Regular security awareness training for all staff, including phishing simulations; background checks on new employees; security obligations embedded in employment contracts;
  • PCI DSS compliance maintained for the Toggle platform in its capacity as a service provider, including annual external audit by an accredited QSA. Airship does not store payment card data on either platform.

4.3 Airship may update or amend its technical and organisational measures from time to time, provided that any such amendments do not result in a material reduction in the level of protection afforded to Personal Data.

4.4 Further details of Airship's security measures are available on written request, subject to confidentiality obligations.

5. SUB-PROCESSORS

5.1 The Client hereby grants Airship a general authorisation to appoint Sub-Processors, subject to the requirements of this clause 5.

5.2 Airship shall maintain an up-to-date list of its Sub-Processors, accessible at its legal documentation pages (or available on written request). Airship shall provide the Client with at least 14 days' prior written notice of any intended addition or replacement of a Sub-Processor.

5.3 The Client may object in writing to any proposed new or replacement Sub-Processor within 14 days of receiving notice. Where the Client objects and Airship is unable to accommodate the objection, either party may terminate the Agreement on written notice, without prejudice to any accrued rights or obligations.

5.4 Airship shall ensure that each Sub-Processor is appointed under a written contract that imposes materially equivalent data protection obligations as those set out in this DPA, and Airship shall remain fully liable to the Client for the acts and omissions of its Sub-Processors as if they were its own.

5.5 Airship's current principal Sub-Processors are listed in Annex 2 to this DPA. Airship will update Annex 2 to reflect any additions or changes made in accordance with this clause 5.

5.6 Airship shall ensure that all persons authorised by it (or by any Sub-Processor) to process Personal Data are subject to written confidentiality obligations.

6. ASSISTANCE WITH DATA SUBJECT RIGHTS AND COMPLIANCE

6.1 Airship shall refer any Data Subject Request it receives directly to the Client without undue delay and shall not respond to a Data Subject Request on the Client's behalf without the Client's prior written authorisation.

6.2 Taking into account the nature of processing and the information available to Airship, Airship shall provide such reasonable technical and organisational assistance as the Client requires to fulfil its obligations under Data Protection Legislation with respect to:

  • Responding to Data Subject Requests;
  • Security of processing;
  • Data protection impact assessments;
  • Prior consultation with the Supervisory Authority regarding high-risk processing; and
  • Notifications to the Supervisory Authority and communications to Data Subjects in response to a Personal Data Breach.

6.3 Airship may charge the Client at its standard time and materials rates for assistance provided under clause 6.2 that goes beyond what is reasonably incidental to Airship's obligations as Processor.

7. INTERNATIONAL DATA TRANSFERS

7.1 Airship shall not transfer Personal Data outside the UK or European Economic Area (EEA) unless:

  • The transfer is solely for the purposes described in Annex 1;
  • The transfer is covered by an adequacy regulation or decision (including any approved framework such as the UK Extension to the EU-US Data Privacy Framework); or
  • Appropriate Safeguards have been put in place and Data Subjects have enforceable rights and effective legal remedies.

7.2 Where Airship relies on an approved framework or standard contractual clauses for an international transfer, it shall ensure such mechanisms are and remain valid and enforceable.

7.3 Airship's current international transfers and the applicable safeguards are set out in Annex 2.

8. RECORDS, INFORMATION AND AUDIT

8.1 Airship shall maintain written records of all categories of processing activities carried out on behalf of the Client, in accordance with Article 30 of the UK GDPR.

8.2 Airship shall, on reasonable written request, make available to the Client such information as is reasonably necessary to demonstrate Airship’s compliance with this DPA and Article 28 of the UK GDPR. This may include: Aikido vulnerability scan reports; CrowdStrike Falcon deployment confirmation; penetration test summary reports; PCI DSS Attestation of Compliance (for the Toggle platform); annual security risk assessment summaries; and details of Airship’s sub-processors, a current list of which is publicly available at academy.airship.co.uk.

8.3 Where the Client reasonably requires further assurance beyond the documentation provided under clause 8.2, it may submit a written request for additional information. Airship shall respond by providing, at its discretion, one or more of the following: penetration test summary reports; internal security policy summaries; or other relevant compliance documentation. The Client agrees to review such materials in good faith and in full before making any further request.

8.4 Only where the documentation provided under clauses 8.2 and 8.3 is demonstrably insufficient to satisfy the Client’s obligations under Data Protection Legislation, and subject to Airship’s prior written consent (not to be unreasonably withheld), may the Client request a further audit by an independent third-party auditor. Any such audit shall be subject to all of the following conditions:

  • Reasonable prior written notice of no less than 30 days (except where a Supervisory Authority requires otherwise);
  • No more than once in any 12-month period, unless ordered by a Supervisory Authority;
  • The Client bears all costs, including Airship’s reasonable internal costs of facilitating the audit;
  • Timing, scope, duration and confidentiality obligations are agreed in writing between the parties in advance;
  • The auditor is subject to binding confidentiality obligations and may not be a competitor of Airship; and
  • The audit is conducted during normal business hours with minimal disruption to Airship’s operations and other customers.

9. PERSONAL DATA BREACH NOTIFICATION

9.1 Airship shall notify the Client without undue delay upon becoming aware of a Personal Data Breach involving Personal Data processed under this DPA. Such notification shall, to the extent known at the time, include:

  • A description of the nature of the Personal Data Breach, including the categories and approximate number of Data Subjects and Personal Data records affected;
  • The name and contact details of Airship's Data Protection contact;
  • A description of the likely consequences of the Personal Data Breach; and
  • A description of measures taken or proposed to address the breach, including steps to mitigate its possible adverse effects.

9.2 Where full details are not available at the time of initial notification, Airship may provide information in phases, without undue delay.

9.3 Airship shall cooperate with the Client and take such reasonable steps as the Client may direct to assist with the investigation, mitigation and remediation of any Personal Data Breach.

9.4 Airship shall not make any public communication or disclosure in relation to a Personal Data Breach involving the Client's Personal Data without the Client's prior written consent, unless required to do so by law.

10. DELETION AND RETURN OF PERSONAL DATA

10.1 On termination or expiry of the Agreement for any reason, Airship shall, at the Client's election and subject to clause 13.3.3 of the Airship Standard Terms:

  • Return a copy of all Personal Data to the Client in a commonly used machine-readable format; and/or
  • Securely delete or destroy all Personal Data (and any copies) in Airship's possession or control, including data held by Sub-Processors.

10.2 The Client must make any election under clause 10.1 in writing within 15 days of the termination or expiry date. Airship shall use reasonable commercial efforts to complete the return or deletion within 30 days of receiving the Client's written request, subject to the Client having paid all outstanding charges.

10.3 Airship may retain Personal Data to the extent required by applicable law, for the minimum period required and subject to the protections of this DPA.

10.4 On completion of deletion, Airship shall, on written request, provide the Client with written confirmation that deletion has been carried out.

11. LIABILITY

11.1 Airship's liability under this DPA is subject to the limitations and exclusions of liability set out in clause 12 of the Airship Standard Terms. Nothing in this DPA increases Airship's total aggregate liability beyond those limits.

11.2 Airship shall be liable for Data Protection Losses only to the extent such losses are caused by Airship's direct breach of this DPA.

11.3 If either party receives a compensation claim from a Data Subject or third party in connection with the processing of Personal Data under the Agreement, it shall promptly notify the other party in writing. Neither party shall make any admission of liability or agree any settlement in respect of such a claim without the prior written consent of the other party (not to be unreasonably withheld or delayed).

12. SURVIVAL

This DPA shall survive termination or expiry of the Agreement and remain in force until no Personal Data remains in the possession or control of Airship or any Sub-Processor. Clauses 10 and 11 shall continue indefinitely.

13. GENERAL

13.1 This DPA constitutes the entire agreement between the parties in relation to data protection matters and supersedes any previous data processing terms or policies, including the previous Appendix 1 to the Agreement.

13.2 This DPA is governed by the laws of England and Wales. The parties submit to the exclusive jurisdiction of the courts of England and Wales in respect of any dispute arising under it.

13.3 If any provision of this DPA is held to be invalid, illegal or unenforceable, it shall be severed and the remaining provisions shall continue in full force.

13.4 Airship may amend this DPA from time to time to reflect: (a) changes in Data Protection Legislation; (b) changes in Airship's operational or sub-processor arrangements; or (c) guidance from the ICO or other competent authority. Airship shall provide the Client with reasonable written notice of any material amendments.

ANNEX 1 – PROCESSING DETAILS

The table below sets out the details of processing carried out by Airship on behalf of the Client under this DPA.

ProcessorAirship Services Limited, 115a Innovation Drive, Milton Park, Abingdon, Oxfordshire OX14 4RZ.
support@airship.co.uk | 0114 299 6477
Data Protection ContactOskar Smith, CTO – contact via support@airship.co.uk
ControllerThe Client as identified in the Order Form (Schedule 1).
Subject-matter of ProcessingProvision of email marketing, CRM, customer data management, automated journey and communication services, and related analytics via the Airship platform.
Duration of ProcessingFor the duration of the Agreement, and for such further period as may be required for the return or deletion of Personal Data following termination.
Nature and Purpose of ProcessingProcessing necessary to: (a) provide the Services under the Agreement; (b) store and manage Contact Data and Customer Data; (c) send email and SMS communications on the Client's behalf; (d) enable segmentation, profiling and behaviour analysis of Contacts (where consent has been obtained); (e) generate reporting and analytics; (f) facilitate integrations with Third Party Providers; and (g) detect and prevent fraudulent or unauthorised activity.
Types of Personal DataPersonal information (gender, title, first/last name, date of birth); contact information (email address, mobile, home and work numbers); postal address; IP addresses and device identifiers (including MAC address); loyalty and gift card data (card reference, balance, points, active status, expiry, programme association — note: no payment card data is stored); booking and reservation data (booking type, party size, dates, deposit and spend); Wi-Fi interaction data (hotspot name, device type, interaction timestamps); feedback and post-visit data (ratings, text feedback, campaign and form references); purchase and transaction history (line description, SKU, quantity, value, date/time, location); hotel stay data (room type, rate, check-in/out dates, guest numbers, financials, booking source); preference and consent records; behavioural and engagement data (email opens, clicks, journey interactions); and any further personal data uploaded by the Client to the platform. Note: Airship does not store payment card information or medical information.
Categories of Data SubjectsCustomers, prospects and loyalty members of the Client; and (where applicable) employees or representatives of the Client who are Authorised Users of the platform.
Location of ProcessingPrimarily within the UK and EU. Where processing occurs outside the UK/EEA, Airship shall ensure appropriate safeguards are in place as described in clause 7 and Annex 2.

ANNEX 2 – SUB-PROCESSORS AND INTERNATIONAL TRANSFERS

The following Sub-Processors are currently authorised by Airship to process Personal Data in connection with the Services. Airship will update this list in accordance with clause 5.

Sub-ProcessorProcessing ActivityLocationTransfer Safeguard
Amazon Web Services (AWS)Cloud infrastructure, hosting, storage and data processingEU / UK (primary)AWS GDPR DPA; UK SCCs where applicable
Bird.com (SparkPost)Email delivery and transactional messagingUSA / EUBird DPA; UK SCCs / adequacy framework
SingleStore (formerly MemSQL)Database and analytics processingUSA / EUSingleStore DPA; UK SCCs where applicable
Google (Workspace / Cloud)Internal tooling, support communicationsUSA / EUGoogle Cloud DPA; UK adequacy / SCCs
CDN77 (DataCamp Ltd)Content delivery network (Toggle platform)UKUK GDPR / DPA 2018 (no transfer)
SinchSMS messaging deliveryUSA / EUSinch DPA; UK SCCs where applicable
TwilioSMS messaging deliveryUSATwilio DPA; UK SCCs where applicable
Esendex (Commify UK Ltd)SMS messaging deliveryUK / EUEsendex DPA; UK GDPR compliant
Unlayer Inc.Email template editor (platform component)USAUnlayer privacy policy; UK SCCs where applicable
Better StackUptime monitoring and incident managementEUBetter Stack DPA; EU adequacy
Airbrake (Functional Software Inc.)Application error monitoring and alertingUSAAirbrake privacy policy; UK SCCs where applicable

Note: This list will be updated by Airship from time to time in accordance with clause 5 of this DPA. The most current version is available on written request.