Last updated: 2026-05-10 · v1

Supplier Data Processing Agreement

Effective Date: 2026-05-11 Last Updated: 2026-05-11 Version: 1.0

This Supplier Data Processing Agreement ("Supplier DPA") supplements the Supplier Agreement where personal data is transferred between GRANDROUTES GLOBAL PTE. LTD. ("Gvoya") and the operating Supplier in connection with bookings made through the Gvoya Service. Both Gvoya and Supplier act as independent controllers of end-consumer Personal Data within their respective spheres; this Supplier DPA establishes the controller-to-controller protections required by GDPR Article 26 (joint controllership where applicable), Article 28 (where Supplier acts as processor for ancillary services), Article 44-49 (international transfers), and analogous provisions of UK GDPR, China PIPL, Singapore PDPA, CCPA/CPRA, LGPD, PIPEDA, and APPI.

1. Roles

1.1 Independent controllers (default)

For the carriage and operational fulfillment of the booking:

Personal DataController
Account data, AI Concierge logs, payment metadataGvoya (Section §3 Privacy Policy)
Passenger manifest, passport, dietary, medical, accessibilitySupplier (operational responsibility)

Once Supplier receives the data necessary for the voyage (after Gvoya transmits the booking), Supplier is an independent controller of that data under its own privacy policy. Supplier shall not "process for Gvoya"; Supplier processes for Supplier's own legitimate operational purposes (carriage, safety, regulatory reporting).

1.2 Joint controllership (limited)

For specific scenarios where both parties jointly determine purposes and means:

  • Customer-feedback collection where Gvoya solicits ratings on behalf of the Supplier
  • Co-marketing campaigns
  • Joint loyalty programs (where applicable)

In each case, the parties shall execute a specific Article 26 GDPR arrangement defining responsibilities for transparency, data-subject rights, and retention.

1.3 Processor (limited)

Where Supplier provides ancillary services that Gvoya purchases on the consumer's behalf and Gvoya remains the controller (e.g., specialty dining package add-on resold by Gvoya), Supplier acts as Gvoya's processor for that data. The full Gvoya DPA applies as a sub-clause to such limited engagements.

2. Categories of Personal Data Transferred

CategoryPurposeSensitivity
Passenger names, DOB, nationalityBooking manifest, age verificationStandard
Passport numbers, expiry, countryManifest, visa preparationHigh (encrypted by Gvoya at rest; Supplier must protect equivalently)
Contact email, phoneBooking confirmation, pre-departure opsStandard
Dietary restrictions, accessibility needsOperational accommodationSpecial category if medical
Voluntary disclosed medical conditionsSafety, fitness assessmentArticle 9 GDPR — explicit consent only
Emergency contactSafetyStandard
Payment confirmation referenceReconciliationPseudonymized

Gvoya never shares: full credit-card numbers (PCI scope), Gvoya account password hash, AI Concierge raw conversation logs (only the recommendations the consumer accepted), or other Gvoya-internal identifiers.

3. Cross-Border Transfers

Suppliers operate globally; Gvoya end consumers reside in 199 countries. Transfers are governed by the following framework:

3.1 EU/EEA → Supplier outside EU/EEA

  • Standard Contractual Clauses (Commission Decision 2021/914) Module One (controller-to-controller) incorporated by reference into this Supplier DPA. The four annexes are completed via the booking metadata and the Supplier-onboarding form.
  • Where the Supplier's jurisdiction has an adequacy decision (Switzerland, UK, Japan, Republic of Korea, Argentina, Israel, etc.), reliance on adequacy.
  • Supplementary measures: encryption in transit (TLS 1.2+), encryption at rest (where Supplier holds passport data).
  • Transfer Impact Assessment per Schrems II for high-volume or sensitive transfers.

3.2 UK → Supplier outside UK

  • UK International Data Transfer Addendum 2022 to the EU SCCs, executed by reference.

3.3 China → Supplier outside China

  • Separate consent obtained from the consumer at booking under PIPL Article 39 for each receiving Supplier.
  • Standard Contract for Cross-Border Transfer of Personal Information (CAC) executed where the volume threshold applies.
  • Cybersecurity Review where the volume threshold or critical-information-infrastructure threshold applies.

3.4 California → Supplier outside California / US

  • Service Provider terms under CCPA §1798.140(d) where applicable; otherwise controller-to-controller transfer with the consumer's notice at collection (privacy policy section 5).

3.5 Other jurisdictions

  • LGPD: transfer impact analysis under ANPD guidance; SCCs.
  • PIPEDA: Privacy Commissioner-aligned safeguards.
  • APPI: separate consent and adequacy where Japan recognized; SCCs otherwise.

4. Supplier Obligations as Independent Controller

When acting as an independent controller, Supplier shall:

a. Have its own privacy policy meeting the requirements of GDPR Articles 13-14 / equivalent local law and provide it to consumers operationally (in the boarding pack, on the ship, etc.); b. Process Personal Data only for the operational purposes of the booking and any ancillary purpose for which the consumer separately consented through Supplier's channel; c. Implement security measures appropriate to the risk under GDPR Article 32 / PIPL Article 51 (encryption in transit and at rest, access control, audit logging); d. Maintain a record of processing under GDPR Article 30 to the extent applicable; e. Respond to data-subject requests directed to Supplier, and forward to Gvoya any request that relates to Gvoya-controlled data; f. Notify Gvoya of any personal-data breach affecting the data Gvoya transmitted, without undue delay and no later than seventy-two (72) hours after becoming aware; g. Not retain the data beyond the operational and statutory retention need (typically seven (7) years for booking records under tax and audit law); h. Not use the data for marketing without Supplier's own independently-obtained consent.

5. Sub-processors (When Supplier Acts as Processor)

When Supplier acts as Gvoya's processor (limited cases — see §1.3), Supplier shall:

a. Engage sub-processors only with Gvoya's prior written authorization or via a notice-and-objection regime; b. Bind sub-processors to terms substantially equivalent to this Supplier DPA; c. Remain fully liable for sub-processor performance.

6. Audit Rights

Once per calendar year (more often only on reasonable suspicion of breach), Gvoya may audit Supplier's compliance with this Supplier DPA, with thirty (30) days' notice and reasonable confidentiality undertakings. Supplier may satisfy by providing independent third-party audit reports (SOC 2, ISO 27001) covering the relevant scope.

7. Breach Notification

Supplier shall notify Gvoya in writing (dpo@gvoya.com) of any personal-data breach affecting Gvoya-transmitted data without undue delay and no later than seventy-two (72) hours after becoming aware. The notification shall include nature, categories, approximate number of records, likely consequences, and remedial measures.

8. Data Subject Rights

Each party shall handle data-subject requests directed to it within statutory deadlines (30 days GDPR, 45 days CCPA, 15 days LGPD). Where a request necessitates action by both parties (e.g., a global erasure request), the parties shall cooperate in good faith. Gvoya's Privacy Policy §8 explains the process to consumers.

9. Retention and Deletion

Supplier shall retain Personal Data only as long as needed for operational and legal purposes, after which it shall delete or anonymize. Common periods:

DataRetention
Booking and manifest7 years (tax, audit)
Passport numbers (post-voyage)Up to 12 months for booking lookup; then deleted unless retained under legal hold
Medical declarationsUntil voyage completion + insurance claim period (typically 2 years)
Marketing data (where separately consented)Until consent withdrawn

Upon termination of the Supplier Agreement, Supplier shall, within ninety (90) days, return or delete all Gvoya-transmitted Personal Data save where required by law, and certify to Gvoya in writing.

10. Cooperation with Authorities

If a regulator (e.g., EU Data Protection Authority, UK ICO, PRC CAC, Singapore PDPC) issues a binding direction concerning data covered by this Supplier DPA, the parties shall cooperate in good faith and notify each other (where lawful) before responding.

11. Liability

Liability for breach of this Supplier DPA is governed by Supplier Agreement §13, except as required by GDPR Article 82's joint-and-several liability regime, which cannot be contractually limited. Statutory liability for personal-data breaches under PIPL, GDPR, CCPA, etc. is preserved.

12. Term and Order of Precedence

Effective for the term of the Supplier Agreement and any data retention thereafter. In conflict between this Supplier DPA and the Supplier Agreement on matters of personal data, this Supplier DPA prevails. In conflict with the EU SCCs (where they apply), the EU SCCs prevail.

13. Contact

Gvoya Data Protection Officer: dpo@gvoya.com Gvoya Privacy team: privacy@gvoya.com Supplier success: suppliers@gvoya.com

GRANDROUTES GLOBAL PTE. LTD. (operating Gvoya), Singapore.