This Data Processing Agreement (“Partner DPA”) is incorporated by reference into the commercial agreement, partnership agreement, alliance agreement, or other commercial terms (the “Main Agreement”) between Almosafer Company for Travel and Tourism (“Almosafer”) and any commercial partner, affiliate, or corporate entity (“Partner”). By executing the Main Agreement, exchanging data, integrating systems, or engaging in joint business operations with Almosafer, the Partner automatically agrees to these terms.
Almosafer: Almosafer Company for Travel and Tourism, Imam Saud Bin Abdulaziz Bin Mohammed Rd, 3730, Al Taawun, Riyadh, Saudi Arabia.
Partner: Any third-party business, affiliate, corporate client, or commercial entity executing the Main Agreement.
Relationship: Independent Data Controllers. Each party independently determines the purposes and legal means of processing the shared personal data for its own operational, commercial, and regulatory compliance needs.
Term: Coterminous with the Main Agreement. This Partner DPA remains active as long as personal data is processed, exchanged, or handled between the parties.
Main Agreement: The underlying commercial contract, alliance terms, or service agreement executed between Almosafer and the Partner.
Governing Law and Jurisdiction: As defined in the Main Agreement. If the Main Agreement is silent, this Partner DPA shall be governed by the laws of the Kingdom of Saudi Arabia.
Data Protection Laws: All laws and regulations which apply to the processing of personal data, including the Personal Data Protection Law (PDPL) in the Kingdom of Saudi Arabia and applicable international frameworks (such as the GDPR), as amended from time to time.
Data Subjects: Customers, users, travelers, employees, or business contacts whose data is processed between the parties.
Types of Personal Data Processed: Customer identity details, contact information, transactional metadata, interaction histories, or financial details necessary to fulfill the commercial purpose of the Main Agreement.
Purpose Limitation: The parties process and exchange personal data exclusively to facilitate, execute, or improve the services and commercial objectives agreed upon in the Main Agreement.
Independent Ownership: Neither party processes data on behalf of the other as a processor. Once personal data is legitimately transmitted from one party to the other, that data becomes part of the receiving party's independent records. The receiving party is solely responsible for its safe handling under its own privacy policy and legal obligations.
Each party warrants and represents that it will:
Maintain its own valid lawful basis (such as contract fulfillment, legitimate interest, or explicit consent) for processing the shared personal data under applicable Data Protection Laws.
Maintain a transparent, public-facing privacy policy that accurately informs data subjects about how their data is collected, used, and shared.
Manage its own operational overhead regarding data management, retention, and localized regulatory reporting.
Direct Handling: Because both parties operate as independent controllers, each party is individually responsible for addressing, validating, and responding to requests from data subjects exercising their privacy rights (such as access, rectification, or erasure).
Reasonable Cooperation: If a data subject exercises a right with one party that impacts data held by the other party, the parties agree to cooperate in good faith to communicate the request and facilitate compliance to the extent permitted by applicable local laws and record-retention requirements.
Security Standards: Both parties warrant that they have implemented industry-standard technical and organizational safeguards (including encryption in transit and at rest) to protect the processed data, as detailed in Annex 1.
Breach Notification: If either party suffers a data security incident or unauthorized access that impacts the shared personal data, that party will notify the other within 72 hours of confirmation. Both parties will cooperate in good faith to mitigate downstream risks to the affected individuals.
International Routing: The parties acknowledge that modern business operations and cloud infrastructures may require international data transfers to fulfill commercial terms.
Legal Safeguards: Where personal data is transferred across borders to a destination country that does not hold an official adequacy status under KSA PDPL or global frameworks, the data importer warrants that it utilizes recognized legal transfer mechanisms (such as Standard Contractual Clauses or equivalent frameworks) to ensure an equivalent level of protection.
Precedence: If a conflict arises between this Partner DPA and the Main Agreement regarding data protection clauses, this Partner DPA takes priority.
Amendments: Almosafer reserves the right to periodically update this framework to maintain compliance with evolving statutory requirements. Continued data processing or business interaction following a posted update constitutes acceptance of the modified terms.
Severability: If any provision of this Partner DPA is found to be invalid or unenforceable, the remaining provisions will continue in full force and effect.
All Partners processing data in connection with Almosafer are required to align with the following baseline security protocols:
1. Transmission & Integration Integrity
Transport Encryption: All programmatic data exchanges, file transfers, or API connections must be forced over secure cryptographic layers (such as TLS 1.2 or higher).
Access Authorization: Digital connections between parties must be safeguarded via secure authorization mechanisms (such as OAuth tokens or secure VPN tunnels).
2. Storage & Records Protection
At-Rest Encryption: Databases, file systems, or cloud storage environments archiving processed personal data must use robust encryption algorithms (such as AES-256).
Data Minimization: Partners shall only store and retain the exact data fields strictly necessary to execute the commercial purpose of the partnership.
3. Operational Hygiene
Access Control: Internal access to the systems hosting the processed data must follow the principle of least privilege, ensuring only authorized personnel with a business need can view the data.
Authentication: Multi-factor authentication (MFA) must be enforced for administrative and remote access to environments containing shared personal records.
This Data Processing Agreement (“DPA”) is incorporated by reference into the Master Services Agreement, Terms of Service, or other commercial agreement (the “Main Agreement”) between Almosafer Company for Travel and Tourism (“Almosafer” or “Controller”) and the service provider (“Processor”). By providing services to Almosafer that involve the processing of personal data, the Processor automatically agrees to the terms of this DPA.
Controller: Almosafer Company for Travel and Tourism, Imam Saud Bin Abdulaziz Bin Mohammed Rd, 3730, Al Taawun, Riyadh, Saudi Arabia.
Processor: The vendor, service provider, or partner supplying services to Almosafer under the Main Agreement.
Relationship: Controller to Processor.
Term: This DPA is coterminous with the Main Agreement and will continue in effect until the Main Agreement is terminated or expires, and all personal data has been returned or deleted.
Main Agreement: The commercial contract, terms of service, or insertion order executed between Almosafer and the Processor.
Governing Law and Jurisdiction: As defined in the Main Agreement. If the Main Agreement is silent, this DPA shall be governed by the laws of the Kingdom of Saudi Arabia.
Data Protection Laws: All laws and regulations which apply to the processing of personal data, including the Personal Data Protection Law (PDPL) in the Kingdom of Saudi Arabia and the GDPR, as amended from time to time.
Nature, Purpose, and Duration of Processing: The Processor will process personal data strictly to the extent necessary to provide the services outlined in the Main Agreement and only for the duration of the Main Agreement.
Types of Personal Data and Data Subjects: The personal data processed includes the information provided by Almosafer to facilitate the services (which may include customer, employee, or partner identity data, contact details, and booking information).
Breach Notification Period: 72 hours.
Sub-processor Notification Period: A reasonable timeframe before the new sub-processor takes effect.
Purpose: The parties are entering into this DPA for the purpose of processing personal data in compliance with applicable Data Protection Laws.
Definitions: Adequate country, Controller, data subject, personal data, process/processing, Processor, Sub-processor, and supervisory authority have the same meanings as defined in the applicable Data Protection Laws.
Controller obligations: Controller is responsible for obtaining all consents, licences, and legal bases required to allow Processor to process personal data in accordance with this DPA and applicable Data Protection Laws.
Processor obligations:
Only process personal data in accordance with this DPA and Controller's documented instructions (unless legally required to do otherwise).
Not sell, retain, or use any personal data for any purpose other than as permitted by this DPA and the Main Agreement.
Inform Controller immediately if (in its opinion) any instructions infringe Data Protection Laws.
Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk involved as set out in Annex 1.
Notify Controller of a personal data breach within the Breach Notification Period (72 hours).
Ensure that anyone authorised to process personal data is committed to confidentiality obligations.
Provide Controller with reasonable assistance in responding to a personal data breach and comply with breach notification obligations.
Without undue delay, provide Controller with reasonable assistance with:
Data protection impact assessments.
Responses to data subjects' requests to exercise their rights under Data Protection Laws.
Engagement with supervisory authorities.
If requested, provide Controller with information necessary to demonstrate its compliance with obligations under Data Protection Laws and this DPA.
Allow for audits at Controller's reasonable request, provided that audits are limited to once a year and during business hours except in the event of a security incident.
After termination of this DPA, delete or return personal data upon Controller's written request unless retention is required to meet legal or regulatory obligations.
Warranties: The parties warrant that they and any staff and/or subcontractors will comply with their respective obligations under Data Protection Laws for the Term.
Use of sub-processors: Controller generally consents to Processor using sub-processors when processing personal data, subject to the conditions of this DPA.
Sub-processor obligations:
Require its sub-processors to comply with equivalent terms as Processor's obligations in this DPA.
Ensure appropriate safeguards are in place before internationally transferring personal data to its sub-processor.
Remain fully liable for any acts, errors, or omissions of its sub-processors under this DPA.
Approvals: Processor may appoint new sub-processors provided they notify Controller in writing (or via an agreed-upon subscription update mechanism) within the Sub-processor Notification Period.
Objections: Controller may reasonably object in writing to any future sub-processor. If the parties cannot agree on a solution within a reasonable time, either party may terminate this DPA.
4.1 Instructions: Processor will transfer personal data outside the KSA, the EEA, or an adequate country only on documented instructions from Controller, unless otherwise required by law.
4.2 Transfer mechanism: Where a party processes personal data outside the KSA, the EEA, or an adequate country:
(a) That party will act as the data importer.
(b) The other party is the data exporter.
(c) A suitable legal Transfer Mechanism will apply.
4.3 Additional measures: If the Transfer Mechanism is insufficient to safeguard the transfer, the data importer will promptly implement additional or replacement measures as necessary to ensure personal data is protected to the same standard as under Data Protection Laws.
4.4 Disclosures: If the data importer receives a request from a public authority to access personal data, it will (if legally possible):
(a) Challenge the request and promptly notify the data exporter about receiving it.
(b) If it is necessary to disclose personal data, only disclose the minimum amount required to the public authority and keep a record of the disclosure.
Survival: Any term of this DPA which is intended to survive termination will remain in full force.
Order of precedence: In case of a conflict between this DPA and other relevant terms, they will take priority in this order: DPA, then the Main Agreement.
Notices: Formal notices under this DPA must be in writing and sent to the primary business contacts established under the Main Agreement.
Third parties: Except for affiliates, no one other than a party to this DPA has the right to enforce any of its terms.
Entire agreement: This DPA supersedes all prior discussions and agreements and constitutes the entire agreement between the parties with respect to its subject matter, and neither party has relied on any statement or representation of any person in entering into this DPA.
Amendments: Any amendments to this DPA must be agreed in writing.
Assignment: Neither party can assign this DPA to anyone else without the other party's consent.
Waiver: If a party fails to enforce a right under this DPA, that is not a waiver of that right at any time.
The Processor must implement and maintain the following technical and organisational measures to ensure an appropriate level of security in relation to the risks presented by data processing. The Processor must regularly review and update these security measures to address new threats and ensure ongoing compliance.
1. Data in Transit
Encryption: All data transmitted over public networks must be encrypted using strong encryption protocols such as TLS to prevent unauthorized access during transfer.
Integrity Checks: Implement mechanisms to ensure the integrity of data during transit, such as checksums or hash functions.
Secure Channels: Use secure communication channels, such as VPNs or secure file transfer protocols (e.g., SFTP, HTTPS).
2. Data at Rest
Encryption: Data at rest must be encrypted using strong encryption algorithms (e.g., AES-256).
Access Controls: Implement strict access controls to ensure only authorized personnel can access data storage systems.
Regular Audits: Conduct regular security audits and vulnerability assessments to identify and mitigate risks.
3. Data Protection
Encryption Controls: Ensure that personal data is encrypted both in transit and at rest.
Data Minimization: Apply data minimization principles to limit the amount of personal data processed and stored.
Anonymization/Pseudonymization: Where possible, apply anonymization or pseudonymization techniques.
4. Data Access
Access Controls: Implement role-based access controls (RBAC) to restrict access based on the principle of least privilege.
Authentication: Use strong authentication mechanisms, such as multi-factor authentication (MFA).
Audit Logs: Maintain detailed audit logs of data access and usage to detect unauthorized access.
5. Endpoint Security
Antivirus/Antimalware: Install and regularly update antivirus/antimalware software on endpoints processing personal data.
Patch Management: Implement a process to ensure all systems are up-to-date with the latest security patches.
Endpoint Monitoring: Continuously monitor endpoints for security breaches.
6. HR Security
Background Checks: Conduct thorough background checks on all employees/contractors with access to personal data.
Security Training: Provide regular security training and awareness programs.
Confidentiality: Ensure all relevant personnel sign confidentiality agreements.
The Processor shall maintain an up-to-date list of its current Sub-processors utilized in the delivery of the services. This list shall be made available to the Controller upon request, or securely hosted on the Processor's official website or trust center, and shall be updated in accordance with the Sub-processor notification terms outlined in this DPA.