Processing on behalf of the Customer pursuant to Art. 28 GDPR. Effective 14 April 2026.
This Data Processing Agreement (the “ DPA ”) forms an integral part of, and is incorporated by reference into, the Terms of Service (the “ Main Agreement ”) concluded between (1) the customer identified in the Main Agreement (the “ Controller ”, “ Customer ”, “ you ”); and (2) Ananas GDS UG (haftungsbeschränkt) , Nutzweg 30, 97424 Schweinfurt, Germany, registered in the Commercial Register of the Amtsgericht Schweinfurt under HRB 10075, represented by its Managing Director Mohammad Metwally (the “ Processor ”, “ Ananas GDS ”). In the event of any conflict between this DPA and the Main Agreement with respect to the processing of personal data, this DPA prevails.
Capitalised terms not defined here have the meaning given in Regulation (EU) 2016/679 (“ GDPR ”). “ Customer Personal Data ” means any Personal Data processed by Ananas GDS on behalf of the Customer in connection with the Platform. “ SCCs ” means the Standard Contractual Clauses adopted by the European Commission in Decision (EU) 2021/914 of 4 June 2021.
2.1 Subject-matter. The Processor processes Customer Personal Data strictly to provide the Platform as described in the Main Agreement and this DPA.
2.2 Duration. The processing lasts for the term of the Main Agreement and any period thereafter during which the Processor is required to retain Customer Personal Data to comply with instructions, legal obligations, or return/deletion at the end of the service.
2.3 Nature and purpose. Collection, recording, organisation, structuring, storage, retrieval, consultation, use, disclosure by transmission (to authorised partners of the Customer), restriction, erasure and destruction, carried out to provide a B2B Global Distribution System for non-bookable tourism data and to support ancillary features (notifications, analytics, support).
2.4 Categories of Data Subjects: employees and representatives of the Customer; sub-users authorised by the Customer; individual contacts at connected business partners; natural persons identifiable in fact sheets, contracts, surveys, or media uploaded by the Customer.
2.5 Categories of Personal Data: identification and contact data; authentication data (hashed credentials, API tokens, session identifiers); usage and technical data (IP address, timestamps, device/browser metadata); business content uploaded by the Customer that incidentally contains Personal Data. The Processor does not knowingly process special categories (Art. 9 GDPR) or criminal-offence data (Art. 10 GDPR); the Customer undertakes not to upload such data.
3.1 Instructions (Art. 28(3)(a)). Process Customer Personal Data only on documented instructions from the Customer, including regarding third-country transfers, unless required by Union or Member State law (in which case the Processor informs the Customer beforehand unless legally prohibited). The Customer’s instructions are set out in the Main Agreement, this DPA, and further written instructions via Platform settings, admin panels, API, or email to privacy@ananas-gds.com. The Processor shall immediately inform the Customer if an instruction appears to infringe data-protection law.
3.2 Confidentiality (Art. 28(3)(b), 29, 32(4)). Ensure authorised persons are committed to confidentiality and process data only on the Controller’s instructions.
3.3 Security (Art. 28(3)(c), 32). Implement appropriate technical and organisational measures appropriate to the risk — see Annex II .
3.4 Sub-processors (Art. 28(2),(4)). Engage Sub-processors only in accordance with clause 4.
3.5 Data Subject rights (Art. 28(3)(e)). Assist the Customer by appropriate measures in responding to Data Subject requests under Chapter III GDPR; forward any requests received directly from Data Subjects to the Customer without undue delay.
3.6 Assistance with Arts 32–36 (Art. 28(3)(f)). Assist with security, breach notification, data protection impact assessments and prior consultation, taking into account the nature of processing and information available.
3.7 Return or deletion (Art. 28(3)(g)). At the Customer’s choice, delete or return all Customer Personal Data after the end of services and delete existing copies unless storage is legally required.
3.8 Audits (Art. 28(3)(h)). Make available all information necessary to demonstrate compliance and allow for and contribute to audits in accordance with clause 8.
3.9 Records (Art. 30(2)). Maintain a written record of all categories of processing carried out on behalf of the Customer.
4.1 General authorisation. The Customer grants the Processor a general written authorisation to engage Sub-processors for the provision of the Platform, subject to the safeguards in this clause.
4.2 Current Sub-processors. A current list is set out in Annex III and kept up to date (name, location, purpose).
4.3 Changes. The Processor shall inform the Customer of any intended addition or replacement of Sub-processors at least fourteen (14) days in advance, giving the Customer the opportunity to object on legitimate data-protection grounds; if no commercially reasonable solution is found, the Customer may terminate the affected services with immediate effect.
4.4 Flow-down. The Processor imposes the same data-protection obligations on Sub-processors by written contract and remains fully liable to the Customer for their performance (Art. 28(4)).
The Processor shall not transfer Customer Personal Data outside the EEA unless: (a) to a country with a valid adequacy decision (Art. 45); (b) appropriate safeguards under Art. 46 are in place, in particular the SCCs (Module 2 Controller-to-Processor; Module 3 Processor-to-Processor as applicable), supplemented by a transfer impact assessment and additional technical measures where necessary; or (c) another Art. 49 derogation applies and has been communicated to the Customer. Where a Sub-processor is outside the EEA and no adequacy decision applies, the Customer authorises the Processor to conclude the SCCs with that Sub-processor on the Customer’s behalf and update Annex III.
6.1 Notification. The Processor shall notify the Customer without undue delay, and in any event within 72 hours , after becoming aware of a Personal Data Breach affecting Customer Personal Data, to the primary administrative email on file.
6.2 Content. The notification shall contain, as far as available, the nature of the breach (categories and approximate numbers of Data Subjects and records), the likely consequences, and the measures taken or proposed to address and mitigate it.
6.3 Cooperation. The Processor shall provide reasonable assistance with the Customer’s obligations to notify the Supervisory Authority (Art. 33) and, where applicable, affected Data Subjects (Art. 34).
At the end of services, the Processor shall, at the Customer’s choice, delete or return all Customer Personal Data and delete existing copies, unless storage is legally required. Unless the Customer instructs otherwise within 30 calendar days of termination, the Processor deletes Customer Personal Data in accordance with the retention schedule in the Privacy Policy and Main Agreement. Deletion from back-ups occurs within the normal back-up rotation cycle.
The Customer may, no more than once per calendar year and after at least 30 days’ prior written notice, audit the Processor’s compliance: (a) by requesting written information, certifications (e.g. ISO 27001), third-party audit reports, or questionnaires; or (b) where strictly necessary and justified, by an on-site inspection during business hours, conducted without unreasonable disruption and subject to confidentiality undertakings (the auditor must not be a competitor of the Processor). Audits triggered by a substantiated suspicion of a material breach or by a Supervisory Authority are not subject to the annual frequency limit. Each Party bears its own costs unless the audit reveals a material breach by the Processor, in which case the Processor reimburses the Customer’s reasonable audit costs.
Liability under this DPA is governed by the liability provisions of the Main Agreement, subject to the mandatory provisions of Art. 82 GDPR, which remain unaffected.
This DPA enters into force on the effective date of the Main Agreement and remains in force for as long as the Processor processes Customer Personal Data on behalf of the Customer. Termination of the Main Agreement automatically terminates this DPA, without prejudice to obligations that by their nature survive (confidentiality, return/deletion, liability for past breaches).
11.1 Conflict. This DPA prevails over the Main Agreement regarding the processing of Customer Personal Data; the SCCs prevail over this DPA.
11.2 Governing law and jurisdiction. German law applies, excluding conflict-of-law rules; exclusive jurisdiction is Schweinfurt, Germany, subject to clause 19 of the Main Agreement. For the SCCs, their own governing-law and jurisdiction clauses apply.
11.3 Severability. Invalid provisions are replaced by valid provisions closest to their economic intent; the remainder stays in force.
11.4 Written form. Amendments must be in text form (§ 126b BGB).
Categories of Data Subjects and Personal Data: as set out in clauses 2.4 and 2.5. Special categories: none processed intentionally. Frequency: continuous, 24/7, throughout the Main Agreement. Nature: as in clause 2.3. Purpose: provision of the Ananas GDS Platform (B2B distribution of non-bookable tourism data — fact sheets, stop sales, allotments, photos, surveys, partner contracts — plus authentication, notifications, analytics, billing, support). Duration: the term of the Main Agreement and the retention periods in the Privacy Policy. Competent Supervisory Authority for the Processor: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany.
Confidentiality (Art. 32(1)(b)): hosting in data centres with 24/7 physical security, access logging and video monitoring; individual accounts, strong password requirements, hashed and salted passwords, role-based access control, least privilege, session timeouts; per-user/per-role/per-property permission enforcement, database-level tenant separation, API token scopes; separation of development, test and production; TLS/HTTPS in transit, encryption at rest for credentials, pseudonymised analytics where feasible.
Integrity (Art. 32(1)(b)): TLS-protected transfers; tokens transmitted only over secured channels; logging of security-relevant events (failed logins, permission changes, administrative actions) and API analytics (endpoint, token, success/failure, timestamps).
Availability and resilience (Art. 32(1)(b),(c)): regular back-ups; monitoring and alerting; rate limiting against DDoS and brute-force; disaster recovery; timely restoration of access after an incident.
Regular testing and evaluation (Art. 32(1)(d)): internal data-protection policies and personnel training; documented incident response with 72-hour breach handling; privacy by design and default with data minimisation; vendor management based on documented security posture.
Order control (Art. 28): written DPAs with all Sub-processors; documented Customer instructions; records of processing activities.
The following Sub-processors are engaged as of the effective date. An up-to-date list is available on request to privacy@ananas-gds.com.
| Sub-processor | Location | Purpose | Transfer mechanism |
|---|---|---|---|
| Mochahost (shared hosting) | United States | Platform hosting and database (cPanel / LiteSpeed / MariaDB) | SCCs (Module 3) + supplementary measures; under review for EEA migration |
| Stripe Payments Europe, Ltd. | Ireland (EU) | Payment processing, invoicing, subscription management | Within EEA; onward transfers to Stripe, Inc. (US) under SCCs and EU-US DPF |
| Fyrst Bank (Deutsche Bank AG) | Germany | Receipt of payments (where applicable) | Within EEA |
| Transactional email provider (to be confirmed) | EEA (preferred) | Delivery of transactional emails (verification, notifications, invoices) | Within EEA or SCCs if outside |
The Customer consents to the Sub-processors listed above. Additions or replacements will be notified at least 14 days in advance in accordance with clause 4.3.
This Data Processing Agreement is concluded between the Parties upon acceptance of the Main Agreement and is complemented by the Terms of Service , Privacy Policy , and Imprint . Effective 14 April 2026.