GDPR Policy for Tourdash

1. Introduction

Tourdash is committed to protecting the privacy and personal data of our customers and their clients. This GDPR policy outlines how we collect, process, and safeguard personal data in compliance with the General Data Protection Regulation (GDPR).

2. Data Controller

Tourdash acts as a data processor for the personal data provided by our customers (who act as data controllers) through our Tour Dashboard.

3. Types of Personal Data We Process

We may process booking relevant data contained in mails or technical interfaces (API's).

4. Purpose of Data Processing

We process personal data for the following purposes:

  • To provide our Tour Dashboard services
  • To visualize booking information for our customers
  • To respond to customer inquiries and support requests

5. Legal Basis for Processing

We process personal data based on the following legal grounds:

  • Performance of a contract with our customers
  • Legitimate interests in providing and improving our services
  • Consent, where applicable

6. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable laws and regulations.

7. Data Subject Rights

We respect the rights of data subjects and will assist our customers in fulfilling data subject requests, including:

  • Right to access
  • Right to rectification
  • Right to erasure
  • Right to restrict processing
  • Right to data portability
  • Right to object

8. Data Security

We implement appropriate technical and organizational measures to ensure the security of personal data, including:

  • Encryption of data in transit
  • Regular security assessments and audits
  • Access controls and authentication mechanisms
  • Employee training on data protection and security

9. International Data Transfers

If we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions.

10. Data Breach Notification

In the event of a data breach, we will notify the affected customers (data controllers) without undue delay and within 72 hours of becoming aware of the breach.

11. Subprocessors

We may use subprocessors to assist in providing our services. We maintain a list of subprocessors and ensure they comply with GDPR requirements.

12. Data Protection Officer

Our Data Protection Officer can be contacted at:

GDPR@tourdash.app

13. Changes to This Policy

We may update this policy from time to time. We will notify our customers of any significant changes.

14. Contact Us

If you have any questions about this GDPR policy or our data protection practices, please contact us at:

GDPR@tourdash.app

Last updated: 2024-09-10