Data Processing Agreement

This Data Processing Agreement (“DPA”) forms part of the agreement between the Customer and Musafir for the provision of travel services. Musafir connects Customers with travel partners (e.g., hotels, airlines) to book accommodation, flights, visas, holiday packages, and other services, ensuring the highest level of privacy throughout the booking process. This DPA complies with applicable data protection laws, including the General Data Protection Regulation (GDPR) and UAE Personal Data Protection Law (PDPL), to foster a partnership built on trust and transparency.

1. Details of Processing

1.1 Purpose of Processing

Musafir processes personal data to:

  • Create, maintain, and update customer accounts.
  • Manage travel bookings, including flights, hotels, visas, and holiday packages.
  • Provide customer service and send notices (e.g., flight delays).
  • Provide travel confirmations and updates.
  • Measure interest and improve services.
  • Notify about special offers and customize user experiences.
  • Resolve disputes and store emergency contacts.

Musafir will not use personal data for unrelated purposes or sell personal data.

1.2 Processing Roles

  • Customer: Controller of personal data of individuals using the customer account.
  • Musafir: Processor, facilitating connections between the Customer and travel partners.

1.3 Nature of Processing

  • Collection, recording, storage, use, structuring, and transmission of personal data.

1.4 Affected Data Subjects

  • Individuals invited to the Musafir platform by the Customer (e.g., employees, contractors, job candidates) and their emergency contacts.
  • Customers booking reservations through the website or customer service agents.
  • Passengers whose travel arrangements are made by the user.

1.5 Affected Personal Data

  • User information (e.g., name, contact details including telephone number, postal and email addresses, job information, identification documents).
  • Travel history (e.g., hotel stays, flights, car rentals, visas, holiday packages).
  • Customer service interactions.
  • Travel affiliation information (e.g., frequent flyer numbers, meal requests, seat selection, ticketing options).

Payments are processed by third-party processors compliant with standards like PCI DSS. Musafir does not store sensitive payment information (e.g., full credit/debit card numbers, cardholder name, expiry date) but may store non-sensitive details to facilitate user profiles. Data transmissions use high-grade encryption (256-bit TLS 1.2 or higher).

Musafir does not require special categories of personal data and will delete such data unless necessary to follow user instructions (e.g., special meal requests).

1.6 Duration of Processing

  • Musafir will process personal data for the duration of travel service provision and applicable statutory retention periods (typically 7 years).
  • Deletion or anonymization cannot occur before termination of the relationship, except for individual data subject requests.
  • Individual travelers can be archived or deleted by admins at any time.
  • Musafir will issue written confirmation of deletion or anonymization upon request.
  • This DPA remains in force until Musafir deletes or anonymizes personal data within 30 days after termination or expiration of statutory periods, whichever is later.

2. Terms of Processing

2.1 Applicable Laws

  • All relevant laws and rulings, including GDPR, UK GDPR, CCPA/CPRA, FADP (Switzerland), and UAE data protection regulations.

2.2 Customer Obligations

  • As controller, the Customer ensures a lawful basis for processing and meets transparency obligations, including obtaining consent for sharing passenger information where required.

2.3 Instructions for Musafir

  • Musafir will process personal data only on the Customer’s documented instructions, as outlined in this DPA.
  • New instructions require an amendment to this DPA.
  • Musafir will immediately notify the Customer if instructions infringe applicable laws.

2.4 Confidentiality

  • Musafir staff are bound by contractual and/or statutory confidentiality obligations.

2.5 Security Measures

  • Musafir implements technical and organizational measures appropriate to the risk level, including administrative, technical, and physical procedures, firewalls, intrusion detection systems, and encryption for sensitive transmissions.
  • Details are available in Musafir’s Privacy Policy at https://www.Musafir.travel/privacy/default.aspx and will be updated as needed.

2.6 Personal Data Breaches

  • Musafir will notify the Customer of any personal data breach within 24 hours of awareness, free of charge, and provide ongoing information.
  • Musafir will assist with investigation, containment, and remediation at no cost.
  • Musafir will not disclose breach information to third parties without consent, unless legally required.

2.7 Assistance

  • Musafir will forward data subject or authority requests within 5 days, free of charge.
  • For authority disclosure requests, Musafir will notify the Customer, challenge the request (where permitted), and disclose the minimum required data.
  • Musafir will assist with relevant assessments at no cost.
  • Users may access and correct their personal information upon request.

2.8 Sub-processors

  • The Customer accepts Musafir’s current sub-processors, including third-party vendors for credit card processing, business analytics, customer service, tourism boards, fraud prevention, and suppliers (e.g., hotels, airlines). A list is available at dpo@musafir.com
  • Selecting specific sub-processors is not possible.
  • Musafir will notify the Customer 30 days before engaging a new sub-processor, allowing objections. If objected, parties will seek an amicable solution within 30 days; otherwise, the Customer may terminate the relationship with 30 days’ notice per the travel service agreement.
  • New sub-processors will be bound by equivalent processing terms via written contracts.
  • Musafir is liable for sub-processors’ acts, errors, or omissions.

2.9 International (Restricted) Transfers

  • Musafir primarily processes personal data in the UAE.
  • Sub-processors may process data in third countries, with compliance ensured (e.g., via standard contractual clauses).

2.10 Audit Rights

  • Musafir allows audits at the Customer’s reasonable request, free of charge, during business hours, except in case of a data breach.
  • Musafir will bear audit costs if responsible for a breach.
  • Musafir will provide information to demonstrate compliance, free of charge.

2.11 Liability and Indemnity

  • Musafir shall indemnify the Customer against any direct losses, damages, or expenses incurred due to Musafir’s failure to comply with this DPA or applicable data protection laws, provided such failure is attributable to Musafir’s negligence or willful misconduct.
  • The Customer shall indemnify Musafir against any claims arising from the Customer’s instructions that infringe applicable laws or from the Customer’s failure to fulfill its obligations as a controller.
  • Liability under this DPA is subject to the limitations and exclusions set forth in the travel service agreement, except where prohibited by applicable law.

3. Other

  • Terms (e.g., “personal data”) have meanings as defined in applicable laws.
  • Amendments to this DPA must be agreed in writing.
  • This DPA constitutes the entire agreement regarding the processing of personal data for travel services.