Legal

Data Processing Agreement

Last updated: July 15, 2026

Maintained by Tripa. This DPA supplements the Terms of Service and applies where Tripa processes personal data on behalf of a Customer (typically a company workspace). It is offered as a template — signed counterparts are available on request.

This document uses bracketed placeholders such as [Company legal name] where the operator must supply specifics. Have qualified counsel review before relying on this text in production.

1. Parties & roles

“Customer” means the company subscribing to Tripa and acts as the Controller. “Tripa” ([Company legal name]) acts as the Processor. Where GDPR applies, Article 28 terms are incorporated.

2. Scope of processing

  • Subject matter: providing the Tripa service to Customer.
  • Duration: the term of the subscription plus deletion windows.
  • Categories of data: account, trip, itinerary, calendar, location, expense, and communication metadata.
  • Data subjects: Customer’s employees, contractors, and travellers.

3. Processing instructions

Tripa processes personal data only on Customer’s documented instructions, which include use of the service as configured in the workspace, unless required by law.

4. Confidentiality

Personnel with access to personal data are bound by confidentiality obligations.

5. Security measures

  • Encryption in transit (TLS) and at rest for the managed database.
  • Role-based access control and per-request row-level security policies.
  • Rate limiting, bot protection, and audit logging on privileged operations.
  • Strict security headers (HSTS, CSP, X-Frame-Options) on all responses.
  • Principle of least privilege for internal access.

6. Subprocessors

Tripa uses the following subprocessors. Customer is deemed to authorise them; new subprocessors are notified with a reasonable objection window.

  • Lovable Cloud — hosting, database, authentication, storage.
  • Google Maps Platform — places, photos, routing.
  • Lovable AI Gateway — AI model inference.
  • Email delivery provider — transactional email from notify.ontripa.com.

7. Data subject requests

Tripa provides Customer with tools to fulfil access, correction, export, and deletion requests. Tripa will assist Customer where reasonable technical means are required.

8. Breach notification

Tripa will notify Customer without undue delay, and where feasible within 72 hours, after becoming aware of a personal data breach, with the information required by applicable law.

9. Audit rights

Tripa will make available information necessary to demonstrate compliance. Audits are satisfied via written responses to reasonable questionnaires; on-site audits may be arranged for material concerns under confidentiality.

10. International transfers

Where personal data is transferred outside the EEA/UK, the parties rely on Standard Contractual Clauses or another approved transfer mechanism.

11. Return & deletion

On termination, Tripa will delete or return personal data within [30] days, subject to legal retention obligations.

12. Contact

Data protection contact: privacy@ontripa.com.

Questions? Contact legal@ontripa.com.