Skip to main content
Attention Keeper Logo

Data Processing Agreement

Last Updated: August 14, 2026

DPA Overview

This Data Processing Agreement (DPA) forms part of Attention Keeper's Terms of Service and applies to the processing of personal data by Attention Keeper on behalf of its customers. It governs how we handle data that our customers entrust to us through the use of our platform, ensuring compliance with GDPR, CCPA/CPRA, and other applicable data protection regulations.

1. Definitions

For the purposes of this DPA, the following terms shall have the meanings set out below:

  • "Controller" refers to you, the customer, who determines the purposes and means of the processing of personal data through your use of the Service.
  • "Processor" refers to Attention Keeper, which processes personal data on behalf of the Controller.
  • "Personal Data" means any information relating to an identified or identifiable natural person processed by the Processor on behalf of the Controller through the Service.
  • "Sub-Processor" means any third party appointed by the Processor to process Personal Data on behalf of the Controller.
  • "Data Subject" means the identified or identifiable natural person to whom the Personal Data relates.
  • "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.

2. Scope & Purpose

This DPA applies to all Personal Data that the Processor processes on behalf of the Controller in connection with the provision of the Attention Keeper platform and services.

The nature and purpose of processing includes: storing customer contact records, travel booking data, client communications, itineraries, documents, and other data entered by the Controller into the Service. The duration of processing is the term of the Controller's subscription agreement with Attention Keeper.

Categories of data subjects include: the Controller's clients, employees, travel agents, leads, and contacts. Categories of personal data include: names, email addresses, phone numbers, physical addresses, passport details, travel preferences, booking history, payment references, and other data entered by the Controller.

3. Processor Obligations

Attention Keeper as Processor shall:

  • Process Personal Data only on documented instructions from the Controller, unless required by applicable law
  • Ensure that persons authorized to process Personal Data have committed to confidentiality
  • Implement appropriate technical and organizational security measures as described in this DPA
  • Respect the conditions for engaging Sub-Processors as outlined in this DPA
  • Assist the Controller in responding to requests from Data Subjects exercising their rights
  • Assist the Controller in ensuring compliance with security, breach notification, and data protection impact assessment obligations
  • At the Controller's choice, delete or return all Personal Data after the end of the provision of services, and delete existing copies unless required by law to retain them
  • Make available to the Controller all information necessary to demonstrate compliance with these obligations

4. Controller Obligations

The Controller shall:

  • Ensure that the processing of Personal Data through the Service has a lawful basis under applicable data protection laws
  • Provide all necessary notices and obtain all necessary consents from Data Subjects for the processing of their Personal Data
  • Ensure that documented instructions to the Processor comply with applicable data protection laws
  • Be responsible for the accuracy, quality, and legality of Personal Data provided to the Processor

5. Sub-Processors

The Controller authorizes the Processor to engage Sub-Processors to assist in providing the Service. Current Sub-Processors include:

  • Convex (database and backend services), United States
  • Stripe (payment processing), United States
  • Amadeus (GDS, connected by Controller's own account)
  • Duffel.com (travel booking API), United Kingdom
  • Tawk.to (live chat), United States
  • Microsoft Clarity (analytics, when enabled by cookie consent), United States

The Processor shall notify the Controller of any intended changes to Sub-Processors, giving the Controller the opportunity to object. If the Controller reasonably objects and the Processor cannot accommodate the objection, the Controller may terminate the affected services.

6. International Data Transfers

Personal Data may be transferred to and processed in the United States (US East, N. Virginia) where our servers are located. For transfers from the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses (SCCs) adopted by the European Commission.

We implement supplementary measures as needed based on the destination country's data protection framework, including encryption in transit and at rest, access controls, and contractual commitments from Sub-Processors.

7. Security Measures

The Processor implements and maintains appropriate technical and organizational measures to protect Personal Data, including:

  • Encryption of data in transit (TLS 1.2/1.3) and at rest
  • Role-based access controls and authentication requirements
  • Regular security assessments and vulnerability testing
  • Rate limiting and DDoS protection at the infrastructure level
  • Input validation and sanitization (DOMPurify, Zod validation)
  • Content Security Policy (CSP), HSTS, and security headers
  • Automated logging with sensitive data redaction

8. Data Breach Notification

The Processor shall notify the Controller without undue delay after becoming aware of a Personal Data breach. The notification shall include the nature of the breach, categories of data affected, approximate number of data subjects affected, likely consequences, and measures taken to mitigate the breach.

The Processor shall cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the breach.

9. Data Subject Rights

The Processor shall assist the Controller in fulfilling its obligations to respond to Data Subject requests, including rights of access, rectification, erasure, restriction, portability, and objection. The Processor shall promptly notify the Controller if it receives a request from a Data Subject directly.

10. Data Retention & Deletion

The Processor shall process and retain Personal Data only for the duration of the Controller's subscription. Upon termination or expiration of the subscription, the Processor shall delete all Personal Data within 30 days, unless retention is required by applicable law. The Controller may request a copy of their data in a portable format prior to deletion.

11. Audit Rights

The Controller has the right to conduct audits, including inspections, to verify the Processor's compliance with this DPA. The Processor shall make available all reasonably necessary information and shall allow for and contribute to audits conducted by the Controller or a third-party auditor mandated by the Controller.

Audits shall be conducted with reasonable advance notice (at least 30 days), during normal business hours, and shall not unreasonably interfere with the Processor's business operations.

12. Liability

Each party's liability under this DPA is subject to the limitations of liability set forth in the Terms of Service. Nothing in this DPA limits either party's liability for breaches of data protection laws where such limitation is not permitted by applicable law.

13. Term & Termination

This DPA shall remain in effect for the duration of the Controller's subscription to the Service. The DPA shall automatically terminate when the Processor no longer processes Personal Data on behalf of the Controller, subject to the data deletion obligations described above.

14. Contact

For questions regarding this DPA or to exercise your rights, please contact our Data Protection team.

Email: privacy@attentionkeeper.com

We use cookies

This website uses cookies to improve your experience. By continuing to use this site, you agree to our use of cookies. See our Cookie Policy to learn more.

If you click Decline, only Necessary Cookies will always be enabled.