Skip to content
viaondo
viaondo

Data processing agreement

The terms on which Viaondo, as processor, handles the personal data of each agency's clients and travelers on behalf of the agency, as controller.

This text is a translation. If there is any discrepancy, the Spanish version prevails. Read the Spanish version

This agreement governs the processing of personal data that Viaondo carries out on behalf of each customer agency when providing the service, in accordance with article 28 of Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 of 5 December on the Protection of Personal Data and the Guarantee of Digital Rights. It forms part of the terms of service, and the Customer accepts it together with them when creating its account. If the Customer needs a signed copy, it can request one at [[OWNER: email de contacto]].

1. Parties

  • Controller: the agency that subscribes to the Service (the “Customer”).
  • Processor: [[OWNER: razón social]], with tax ID (NIF) [[OWNER: NIF/CIF]] and registered office at [[OWNER: domicilio social]] (“Viaondo”). Data protection contact: [[OWNER: email de contacto]]. Data protection officer: [[OWNER: delegado de protección de datos, si existe]].

Terms defined in the GDPR, such as “personal data”, “processing” or “personal data breach”, have the same meaning in this agreement. “Service” has the meaning given to it in the terms of service.

2. Subject matter, nature and purpose

Viaondo will process the personal data that the Customer enters in or uploads to the Service, or that is generated through its use, for the sole purpose of providing the Service to the Customer. Specifically, to:

  • host and organize the Customer’s trips, clients, travelers, bookings and documents;
  • show each traveler their trip in the traveler app, through private links, and allow them to save it offline;
  • send travelers, when the Customer turns this on, email notices about changes to their trip;
  • extract booking data from the documents the Customer uploads to AI import, so that the Customer can review it;
  • record travelers’ interaction with the app and their ratings, and show them to the Customer;
  • provide technical support when the Customer requests it.

The processing is automated and includes the collection, recording, organization, storage, consultation, extraction, adaptation, disclosure to travelers through the links, erasure and destruction of the data.

3. Duration

This agreement lasts for as long as the contract for the Service is in force. When it ends, clause 12 applies. Confidentiality obligations continue after termination.

4. Data subjects and categories of data

Categories of data subjects:

  • the Customer’s clients and travelers, including their companions and, where applicable, minors;
  • agency users, as regards the data the Customer processes about them in the Service, such as who made each change; Viaondo processes the data of their sign-in accounts as controller, under the privacy policy;
  • other people whose data the Customer includes in a trip, such as guides or supplier contacts.

Categories of data:

  • identification: first name and surname;
  • contact: email and phone number;
  • trip data: itinerary, dates, destinations, bookings, seats, booking references, accommodation and activities;
  • travel documents: boarding passes, vouchers, insurance policies and other documents uploaded by the Customer, which may include identity card or passport numbers;
  • the Customer’s internal notes, which are never published;
  • interaction with the traveler app: trip opened, saved offline, documents viewed, updates applied, additions to the calendar, pre-trip checklist completed and install guide shown, without location or device data, and the ratings travelers send.

Special categories of data. The Service is not designed to process special categories of data (article 9 GDPR), such as health data, or data relating to criminal convictions and offenses. Viaondo expressly recommends that the Customer does not include them. If the Customer decides to do so, for example by uploading a medical certificate, it does so under its own responsibility, only where strictly necessary for the trip and with a valid legal basis; Viaondo will process them with the same security measures as the rest of the data.

5. Customer’s obligations

The Customer undertakes to:

  • have a valid legal basis for each processing operation and give data subjects the information required by articles 13 and 14 GDPR;
  • give Viaondo instructions that comply with data protection law;
  • include only the data that is necessary and keep it accurate and up to date;
  • manage its team’s access and revoke or replace trip links that should no longer work;
  • oversee the processing, including by carrying out the audits provided for in clause 13.

6. Viaondo’s obligations

Viaondo undertakes to:

  • Instructions. Process the data only on the Customer’s documented instructions: those arising from this agreement and the terms of service, those that follow from the Customer’s configuration and use of the Service’s features, and those it gives in writing. If Viaondo considers that an instruction infringes data protection law, it will inform the Customer immediately. If European Union or Member State law requires it to process the data otherwise, it will inform the Customer beforehand, unless that law prohibits it.
  • Purpose. Not use the data for its own purposes or disclose it to third parties, except to authorized sub-processors or where required by law.
  • Confidentiality. Ensure that the persons authorized to process the data have committed themselves to confidentiality or are under a statutory obligation of confidentiality, and that they only access the data when needed to provide the Service or the support the Customer requests.
  • Security. Apply the measures in clause 8, in accordance with article 32 GDPR.
  • Sub-processors. Comply with the conditions in clause 7.
  • Assistance. Assist the Customer, taking into account the nature of the processing and the information available to it, in responding to data subject requests (clause 9) and in meeting its obligations regarding security, notification of personal data breaches, data protection impact assessments and prior consultation (articles 32 to 36 GDPR).
  • Records. Keep a record of the processing activities it carries out on the Customer’s behalf (article 30.2 GDPR).
  • Deletion or return. Delete or return the data when the Service ends, as set out in clause 12.
  • Information. Make available to the Customer the information needed to demonstrate compliance with this agreement and allow audits, as set out in clause 13.

7. Sub-processors

The Customer gives Viaondo general authorization to engage the sub-processors listed on the sub-processors page, which forms part of this agreement.

Viaondo will notify the Customer by email, at least 30 days in advance, of the addition or replacement of any sub-processor. During that period, the Customer may object on reasonable grounds relating to data protection. If the parties cannot find a solution, the Customer may terminate the contract without penalty before the change takes effect.

Viaondo will impose on each sub-processor, by contract, the same data protection obligations as those set out in this agreement, and will remain liable to the Customer for their performance (article 28.4 GDPR).

The street map in the traveler app loads directly from OpenStreetMap’s tile servers, which receive the IP address of the traveler’s device. OpenStreetMap is not a sub-processor, because it does not process data on Viaondo’s behalf; this is disclosed on the sub-processors page and in the privacy policy so that the Customer can inform its travelers.

8. Security measures

Viaondo applies at least the following technical and organizational measures, and reviews them regularly:

  • encryption in transit (TLS) on connections between browsers, the application and the storage services;
  • private file storage: documents have no public addresses and are only delivered after access permission is checked;
  • trip links with 256 random bits, of which only a hash is stored; the Customer can replace or revoke them at any time;
  • access control per agency: every request checks that the user belongs to the agency that owns the data;
  • passwords handled by the authentication library and stored only as hashes, never in plain text;
  • technical logs without trip content, email addresses or links;
  • immutable published versions: each publication creates a version that is never modified afterwards, and the history is kept;
  • concurrency control, which prevents one edit from silently overwriting another;
  • a Content-Security-Policy and a no-referrer policy, which prevents trip links from reaching other sites;
  • verification of the offline copy on the traveler’s device (size and SHA-256 checksum) before it is reported as ready;
  • no advertising and no third-party trackers in the traveler app;
  • access by Viaondo staff to the data limited to what is needed to provide the Service and support.

9. Data subject rights

If a data subject contacts Viaondo to exercise their rights of access, rectification, erasure, objection, restriction or portability regarding data that Viaondo processes on the Customer’s behalf, Viaondo will forward the request to the Customer without undue delay and will not answer it directly unless the Customer asks it to.

The Service lets the Customer view, correct and delete the data of its clients, travelers and trips. Where those features are not enough, Viaondo will give the Customer the reasonable assistance needed to respond within the legal deadlines.

10. Personal data breaches

Viaondo will notify the Customer of any personal data breach affecting data processed on its behalf without undue delay and, where feasible, no later than 72 hours after becoming aware of it. The notification will be sent to the email address of the owner of the Customer’s account.

The notification will include, to the extent available, the information listed in article 33.3 GDPR: the nature of the breach, the categories and approximate number of data subjects and records concerned, its likely consequences, the measures taken or proposed, and a contact point. Where it is not possible to provide all the information at once, it will be provided in phases.

Viaondo will immediately take reasonable measures to contain the breach and mitigate its effects, and will help the Customer notify the supervisory authority and, where appropriate, the data subjects. As controller, the Customer decides on and makes those notifications.

11. International transfers

Viaondo does not intend to transfer the data outside the European Economic Area. The database and files are hosted on Cloudflare with European Union jurisdiction, and emails are sent from Resend’s EU region (Ireland). The location of the other sub-processors is shown in their list. If a transfer became necessary, Viaondo would only make it with the safeguards in Chapter V of the GDPR, such as an adequacy decision or standard contractual clauses, and would inform the Customer beforehand.

12. Return and deletion of data

While the contract is in force, the agency owner can archive trips, reversibly and with their links disabled, or delete them permanently.

When the Service ends, Viaondo will keep the data for [[OWNER: plazo de conservación tras la baja]] so that the Customer can request its return in a structured, commonly used format. After that period, Viaondo will delete the personal data processed on the Customer’s behalf and any copies, unless European Union or Member State law requires it to be kept; in that case, Viaondo will keep it blocked and process it only to meet that obligation. Recovery copies kept by infrastructure providers are deleted when their retention cycle ends. Viaondo will confirm the deletion in writing if the Customer requests it.

Viaondo cannot remotely delete offline copies already saved on travelers’ devices. The app deletes them the next time it is opened with a connection and detects that the link is no longer valid, and travelers can delete them at any time from the app.

13. Information and audits

Viaondo will make available to the Customer the information reasonably needed to demonstrate compliance with this agreement, such as a description of the security measures and the list of sub-processors.

The Customer may carry out audits, including inspections, itself or through an independent auditor bound by confidentiality, with at least 30 days’ notice and no more than once a year, unless there are well-founded indications of non-compliance or a supervisory authority requires it. Audits must not disrupt the Service or give access to other customers’ data, and each party will bear its own costs.

14. Liability and precedence

Each party is liable for the performance of its obligations in accordance with article 82 GDPR. Otherwise, the limitation of liability clause in the terms of service applies, except where the law does not allow liability to be limited.

In the event of any conflict between this agreement and the terms of service on data protection matters, this agreement prevails.