Data Processing Agreement (DPA)
Last updated: January 2026
1. Introduction
This Data Processing Agreement ("DPA") forms part of the contractual relationship between TRAVEL NINJAS PTE. LTD., a private company limited by shares incorporated in Singapore (UEN: 202534928K), having its registered office at 160 Robinson Road, #14-04, Singapore Business Federation Center, Singapore 068914 ("Processor") and the customer entity using the Tour Ninja services ("Client" or "Controller").
This DPA applies where personal data is processed by the Processor on behalf of the Controller in connection with the use of the Tour Ninja platform and Services, as defined in the Terms of Service.
2. Definitions
For the purposes of this DPA:
- Applicable Data Protection Lawsmeans all data protection and privacy laws applicable to the processing of personal data, including the Singapore Personal Data Protection Act (PDPA) and, where applicable, the EU General Data Protection Regulation (GDPR).
- Personal Datameans any information relating to an identified or identifiable natural person processed under this DPA.
- Processinghas the meaning given under applicable data protection laws.
3. Roles of the Parties
- The Client acts as the Data Controllerand determines the purposes and means of the Processing of Personal Data.
- TRAVEL NINJAS PTE. LTD. acts as the Data Processorand processes Personal Data solely on documented instructions from the Client.
- The Processor shall not process Personal Data for its own purposes.
- Such instructions may be provided through the normal use of the Services, configuration options, or written communications.
4. Scope and Purpose of Processing
The Processor processes Personal Data solely for the purpose of providing, operating, maintaining, and supporting the Tour Ninja services.
Categories of data subjects may include:
- End users of the Client
- Travelers and customers of the Client
Categories of Personal Data may include:
- Identification and contact details
- Travel-related information
- Dates of travel, preferences, booking details
- Payment information (processed via secure third-party providers)
5. Security Measures
The Processor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data in transit and at rest
- Access controls and authentication mechanisms
- Regular security assessments and updates
- Employee training on data protection
- Incident response procedures
6. Sub-processors
The Client authorizes the Processor to engage sub-processors for the provision of Services. The Processor shall:
- Maintain an up-to-date list of sub-processors
- Ensure sub-processors are bound by equivalent data protection obligations
- Notify the Client of any intended changes to sub-processors
- Remain liable for the acts and omissions of its sub-processors
7. Data Subject Rights
The Processor shall assist the Controller in responding to requests from data subjects exercising their rights under applicable data protection laws, including rights of access, rectification, erasure, and data portability.
8. Data Breach Notification
The Processor shall notify the Controller without undue delay upon becoming aware of a personal data breach affecting data processed under this DPA. Such notification shall include all information reasonably required for the Controller to comply with its obligations under applicable data protection laws.
9. International Data Transfers
Where Personal Data is transferred outside of Singapore or the European Economic Area, the Processor shall ensure appropriate safeguards are in place, such as Standard Contractual Clauses or equivalent mechanisms approved under applicable data protection laws.
10. Duration and Termination
This DPA shall remain in effect for the duration of the processing of Personal Data by the Processor on behalf of the Controller.
Upon termination of the Services, the Processor shall, at the Controller's choice, delete or return all Personal Data and delete existing copies, unless retention is required by applicable law.
11. Audit Rights
The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, subject to reasonable notice and confidentiality obligations.
12. Governing Law
This DPA is governed by the laws of the Republic of Singapore. Any dispute arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the courts of Singapore.
13. Contact
For any questions regarding this Data Processing Agreement, please contact us at: contact@tourninja.io
TRAVEL NINJAS PTE. LTD. - Singapore