Data Processing Agreement
Version 1.0 · Last updated: 9 August 2026
1. Purpose
This Data Processing Agreement (the "DPA") governs the processing of Personal Data carried out by Bike Booking Engine, S.L. ("Bike Booking Engine", "BBE" or the "Data Processor") on behalf of the Customer in connection with the provision of the Services.
The purpose of this DPA is to establish the terms applicable to such processing and the obligations of the Parties in accordance with applicable Personal Data protection laws, including, where applicable, Regulation (EU) 2016/679, the General Data Protection Regulation ("GDPR").
This DPA forms part of the contractual agreement between Bike Booking Engine and the Customer governing the use of the Platform and the Services.
2. Identification of the Parties
For the purposes of this DPA:
Data Processor:
BIKE BOOKING ENGINE, S.L.
Tax Identification Number (NIF): B44711695
Avinguda Bartomeu Riutort, 57, Ground Floor
07610 Palma
Balearic Islands
Spain
Hereinafter, "Bike Booking Engine", "BBE" or the "Processor".
Data Controller:
The natural or legal person that contracts Bike Booking Engine's Services and determines the purposes and essential means of the processing of Personal Data managed through the Platform.
Hereinafter, the "Customer" or the "Controller".
Bike Booking Engine and the Customer may be referred to collectively as the "Parties".
3. Scope
This DPA shall apply where Bike Booking Engine processes Personal Data on behalf of the Customer as a result of the use of the Platform or the Services.
This may include, among others, data relating to:
- End customers;
- Individuals making bookings;
- Users of rental services;
- The Customer's employees and collaborators;
- Authorized Users;
- Contacts;
- Suppliers;
- Individuals associated with bookings, deliveries, collections, repairs or other operations managed through the Platform; and
- Other individuals whose data is entered into or processed through the Services by the Customer.
Details regarding the categories of Data Subjects, categories of Personal Data, nature, purpose and duration of the processing shall be set out in the Annexes to this DPA.
4. Roles of the Parties
As a general rule, with respect to Personal Data entered, collected or managed by the Customer through the Platform:
a) The Customer shall act as the Data Controller, determining the purposes for which Personal Data is collected and used.
b) Bike Booking Engine shall act as the Data Processor, processing Personal Data on behalf of the Customer and in accordance with its documented instructions.
The Customer shall be responsible for determining that the processing carried out through the Platform has an appropriate legal basis and complies with the obligations applicable to it as Data Controller.
Bike Booking Engine shall not determine on behalf of the Customer the legal basis that legitimizes the Customer's processing activities.
5. Processing Carried Out by Bike Booking Engine as Controller
The Processor status established under this DPA shall not prevent Bike Booking Engine from acting as a Data Controller in relation to certain processing activities carried out for its own legitimate and independent purposes.
This may include, where applicable, processing strictly necessary to:
- Manage the contractual relationship with the Customer;
- Administer accounts and business contacts;
- Invoice the Services;
- Comply with its own legal obligations;
- Protect its rights and legitimate interests;
- Prevent fraud or abuse; and
- Maintain the security of its own systems.
Such processing shall not be governed by this DPA to the extent that Bike Booking Engine acts as an independent Controller and shall instead be subject to applicable law and the relevant privacy documentation.
6. Documented Instructions from the Customer
Bike Booking Engine shall process Personal Data only in accordance with the Customer's documented instructions, unless applicable law requires Bike Booking Engine to process such data otherwise.
For these purposes, the following may constitute documented instructions from the Customer:
- This DPA;
- The Terms of Service;
- Configurations made by the Customer within the Platform;
- The Customer's use of enabled functionalities;
- Requests submitted through authorized support channels;
- Additional instructions agreed in writing between the Parties; and
- Any other action by the Customer that reasonably constitutes an instruction regarding processing within the scope of the contracted Services.
Where applicable law requires Bike Booking Engine to process Personal Data in a manner different from the Customer's instructions, Bike Booking Engine shall inform the Customer before carrying out such processing, unless applicable law prohibits such notification on important grounds of public interest.
7. Instructions Contrary to Applicable Law
If Bike Booking Engine reasonably considers that an instruction from the Customer infringes the GDPR or other applicable data protection law, Bike Booking Engine shall inform the Customer accordingly.
Bike Booking Engine may suspend the execution of the affected instruction while the Parties assess its compliance with applicable law.
This provision does not imply that Bike Booking Engine assumes general responsibility for verifying the lawfulness of all processing activities carried out by the Customer through the Platform.
8. Purpose of Processing
Bike Booking Engine shall process Personal Data on behalf of the Customer only to the extent necessary to:
- Provide the Platform and the contracted Services;
- Manage bookings and related operations;
- Provide functionalities configured or enabled by the Customer;
- Store and process information;
- Provide support and maintenance;
- Protect the security and integrity of the Platform;
- Perform backup and recovery operations;
- Facilitate authorized integrations;
- Execute the Customer's lawful instructions; and
- Perform other operations necessary to provide the Services in accordance with the contractual agreement.
The specific purposes and processing operations shall be detailed in the relevant Annexes.
9. Duration of Processing
Bike Booking Engine shall process Personal Data for the duration of the contractual relationship with the Customer and thereafter for the applicable retention periods.
As a general rule, following termination of the subscription, Customer Data may be retained for a period of 90 days, in accordance with the Backup & Retention Policy, in order to allow, where applicable, account reactivation, recovery or export of information, and the management of outstanding obligations.
Once this period has expired, the data shall be deleted from active systems unless:
- A specific retention period applies;
- A legal obligation requires its retention;
- Certain information must be retained for the establishment, exercise or defense of legal claims; or
- Another legitimate circumstance provided for in the contractual documentation or applicable law applies.
Information contained in backups may remain temporarily until the relevant backups reach the end of their ordinary rotation cycles.
10. Optional Functionalities and Customer Decision
Certain Platform functionalities may involve the processing of additional categories of Personal Data.
Where the Customer chooses to enable, configure or voluntarily use a functionality, such action shall constitute an instruction to Bike Booking Engine to carry out the processing technically necessary to provide that functionality.
The Customer shall be responsible for assessing whether it has an appropriate legal basis and whether the use of the functionality is necessary and proportionate for the purposes pursued.
This shall apply in particular to functionalities involving the collection of additional information from end users, including, where available and enabled by the Customer, the upload of identification documentation during the online check-in process.
The specific conditions applicable to such documentation, including its purpose and retention period, shall be expressly set out in the Annexes to this DPA.
11. Processing in Accordance with the Customer's Instructions
Bike Booking Engine shall process Personal Data only in accordance with the Customer's documented instructions and within the scope necessary to provide the contracted Services.
Bike Booking Engine shall not use Personal Data processed on behalf of the Customer for its own purposes that are incompatible with such instructions, unless the processing is required by applicable law.
Technical access to the data by Bike Booking Engine shall not constitute authorization to use such data for purposes other than those necessary for the provision, maintenance, security and support of the Services.
12. Confidentiality
Bike Booking Engine shall ensure that persons authorized to process Personal Data on behalf of the Customer are subject to appropriate confidentiality obligations.
Such obligations may arise from:
- Employment agreements;
- Service agreements;
- Non-disclosure agreements;
- Professional obligations; or
- Other appropriate legal instruments.
Confidentiality obligations shall continue to apply for the period required according to their nature and applicable law.
13. Restricted Access to Personal Data
Bike Booking Engine shall restrict access to Personal Data to authorized personnel and collaborators who require such access to perform functions related to the Services.
Access may be necessary, among other circumstances, to:
- Provide support;
- Perform maintenance;
- Investigate incidents;
- Resolve technical issues;
- Protect the security of the Platform;
- Perform recovery operations;
- Comply with the Customer's lawful instructions; or
- Comply with applicable legal obligations.
Bike Booking Engine shall apply the principle of least privilege, seeking to ensure that each individual has only the access reasonably necessary to perform their responsibilities.
14. Security of Processing
Bike Booking Engine shall implement appropriate technical and organizational measures designed to protect Personal Data processed on behalf of the Customer, taking into account the nature of the processing, the associated risks and the applicable circumstances.
Such measures shall be designed, as appropriate, to protect Personal Data against:
- Accidental or unlawful destruction;
- Loss;
- Alteration;
- Unauthorized disclosure;
- Unauthorized access; and
- Other forms of unlawful processing.
The applicable security measures shall be described in greater detail in the relevant Annex to this DPA and shall be interpreted together with Bike Booking Engine's Security Policy.
15. Maintenance and Evolution of Security Measures
Bike Booking Engine may modify or update the technical and organizational measures used to protect Personal Data as the following evolve:
- The Platform;
- Infrastructure;
- Available technologies;
- Identified risks;
- Security threats; and
- Applicable legal obligations.
Such changes may involve the replacement of technologies, providers, tools, architectures or procedures.
Bike Booking Engine shall seek to ensure that such modifications do not materially reduce the overall level of protection applicable to Personal Data processed on behalf of the Customer.
16. Logging and Traceability
Bike Booking Engine may maintain technical, access, security and audit logs relating to the use and operation of the Platform.
Such logs may be used to:
- Ensure security;
- Provide traceability;
- Investigate incidents;
- Detect anomalous activity;
- Prevent fraud or abuse;
- Resolve technical issues; and
- Comply with legal obligations.
Access to such logs shall be restricted according to the relevant roles and operational requirements.
17. Assistance to the Data Controller
Taking into account the nature of the processing and the information available to Bike Booking Engine, the Processor shall provide the Customer with reasonable assistance to facilitate compliance with the obligations applicable to the Customer under relevant data protection laws.
Such assistance may include, where applicable:
- Handling Data Subject rights requests;
- Security of processing;
- Management of Personal Data breaches;
- Data Protection Impact Assessments; and
- Prior consultations with supervisory authorities.
The scope of such assistance shall depend on the nature of the Services, the information available to Bike Booking Engine and the obligations legally applicable to each Party.
18. Data Protection Impact Assessments and Prior Consultations
Where the Customer is required to carry out a Data Protection Impact Assessment (DPIA) in relation to processing performed through the Platform, Bike Booking Engine shall, taking into account the nature of the processing and the information available to it, provide reasonable assistance regarding those aspects that are under its control.
Likewise, where prior consultation with a supervisory authority is legally required, Bike Booking Engine shall provide reasonable assistance regarding information relating to the Services that is necessary for such consultation.
Bike Booking Engine shall not be responsible for determining on behalf of the Customer whether a DPIA or prior consultation is legally required.
19. Information Necessary to Demonstrate Compliance
Bike Booking Engine shall make available to the Customer the information reasonably necessary to demonstrate compliance with the obligations applicable to the Data Processor under applicable data protection laws.
Such information may be provided through:
- Contractual documentation;
- Security policies;
- Technical documentation;
- Security questionnaires;
- Information regarding technical and organizational measures;
- Documentation relating to Sub-processors; or
- Other reasonable means.
Bike Booking Engine may restrict the information provided where its disclosure could compromise the security of the Platform, reveal trade secrets, affect other Customers or expose confidential information.
20. Audits and Inspections
Bike Booking Engine shall allow for and contribute to audits or inspections that are reasonably necessary to verify compliance with the obligations applicable to the Data Processor.
Audits shall:
- Relate to the processing covered by this DPA;
- Be conducted with reasonable prior notice, unless a legal or security-related reason justifies urgent action;
- Be carried out in a manner that minimizes disruption to Bike Booking Engine's operations;
- Comply with applicable confidentiality and security obligations; and
- Not compromise information relating to other Customers or the security of the Platform.
Where reasonable, Bike Booking Engine may satisfy an audit request by providing documentation, questionnaires, reports or equivalent evidence that enables compliance to be assessed without requiring direct physical or technical access to its systems.
21. Costs Arising from Extraordinary Requests
Ordinary assistance reasonably necessary for compliance with the Data Processor's legal obligations shall be included within the provision of the Services.
Where a Customer request involves extraordinary, repetitive or disproportionate activities that reasonably exceed the ordinary obligations arising under this DPA, the Parties may agree in advance on the applicable conditions and, where appropriate, the reasonable costs associated with such assistance.
The foregoing shall not limit any obligations that Bike Booking Engine is legally required to fulfill under applicable law.
22. Cooperation with Authorities
Bike Booking Engine shall cooperate, where legally required, with data protection authorities or other competent authorities in relation to processing carried out in its capacity as Data Processor.
Where an authority directly requests information from Bike Booking Engine relating to data processed on behalf of the Customer, Bike Booking Engine may inform the Customer of such request where permitted by applicable law.
Bike Booking Engine shall not be required to notify the Customer where such notification is prohibited by law.
23. Use of Sub-processors
The Customer grants Bike Booking Engine general authorization to engage third-party providers acting as Sub-processors where necessary for the provision, maintenance, security, support or evolution of the Services.
Bike Booking Engine may engage Sub-processors to provide, among other things:
- Cloud infrastructure services;
- Hosting and storage;
- Databases;
- Backups;
- Content delivery;
- Communications and email services;
- Monitoring and security;
- Payment processing, where acting as processors or Sub-processors;
- Artificial intelligence services, where applicable;
- Technical support; and
- Other technological services necessary for the operation of the Platform.
The use of an external provider does not necessarily mean that such provider has access to all Personal Data processed through the Platform.
24. Obligations of Sub-processors
Where Bike Booking Engine engages a Sub-processor to carry out specific processing activities on behalf of the Customer, Bike Booking Engine shall impose data protection obligations on such Sub-processor that provide appropriate safeguards with respect to the processing performed.
In particular, Bike Booking Engine shall seek to ensure that the relevant agreement establishes data protection obligations substantially equivalent to those applicable to Bike Booking Engine under this DPA, to the extent relevant to the services provided by such Sub-processor.
Bike Booking Engine shall remain responsible to the Customer for the performance of the Sub-processor's obligations to the extent required by applicable law.
25. Selection of Sub-processors
Bike Booking Engine shall seek to select providers that offer sufficient guarantees regarding the implementation of appropriate technical and organizational measures to protect Personal Data.
The assessment may take into account, where appropriate:
- The nature of the services provided;
- The categories of data potentially processed;
- Available security measures;
- The location of processing;
- Contractual safeguards;
- Available certifications or assessments;
- The provider's track record and reputation; and
- Other reasonably relevant factors.
The use of a provider does not imply that Bike Booking Engine guarantees the absolute absence of incidents or failures relating to such provider.
26. List of Sub-processors
Bike Booking Engine shall maintain information regarding the Sub-processors used to process Personal Data on behalf of Customers.
An up-to-date list of, or information regarding, Sub-processors may be made available to Customers through:
- The Platform;
- Legal documentation;
- A website;
- The help center;
- Upon request; or
- Any other reasonable means.
Such information may include, where appropriate, the identity of the provider, the general nature of the services provided and the relevant location or geographical scope of the processing.
27. Addition or Replacement of Sub-processors
The Customer grants Bike Booking Engine general authorization to appoint new Sub-processors or replace existing ones.
Where a change involves the addition or replacement of a Sub-processor that processes Personal Data on behalf of the Customer, Bike Booking Engine shall provide information regarding such change with reasonable prior notice where required under applicable law.
Such notification may be provided through:
- Email;
- Notification within the Platform;
- An update to the Sub-processor list;
- Publication in the relevant documentation; or
- Any other reasonable means.
28. Customer's Right to Object
Where applicable, the Customer may submit a reasoned objection to the appointment of a new Sub-processor on legitimate grounds relating to the protection of Personal Data.
The objection must be submitted within the reasonable period specified in the relevant notification and must explain the specific data protection grounds on which the objection is based.
The Parties shall seek in good faith to find a reasonable solution.
Where it is not reasonably possible to provide the Services without using the relevant Sub-processor, Bike Booking Engine may, depending on the circumstances:
- Propose an alternative technical solution;
- Restrict the affected functionality;
- Agree on other reasonable measures with the Customer; or
- Where no reasonably viable alternative exists, allow termination of the affected Services in accordance with the applicable contractual terms.
An objection to a Sub-processor shall not grant the Customer a general right to determine the technology providers used by Bike Booking Engine.
29. Urgent Replacements
Where it is necessary to replace or appoint a Sub-processor urgently for reasons of security, Service continuity, regulatory compliance, provider unavailability or another circumstance that reasonably prevents prior notification, Bike Booking Engine may implement the change before notifying the Customer.
In such case, Bike Booking Engine shall seek to inform the Customer of the change as soon as reasonably practicable.
30. Restricted Access by Sub-processors
Sub-processors shall process only the Personal Data necessary to provide the services entrusted to them.
Bike Booking Engine shall seek to contractually restrict processing by Sub-processors to the purposes necessary to provide the relevant services.
The mere engagement of a Sub-processor shall not authorize that Sub-processor to use the Customer's Personal Data for its own purposes incompatible with the applicable instructions.
31. Providers Acting as Independent Controllers
Not all third parties involved in the provision of the Services will necessarily act as Sub-processors.
Certain providers may act as independent Data Controllers in relation to particular processing activities where they determine their own purposes and means of processing in accordance with applicable law.
Where applicable, the relationship between the Customer and such providers may be directly subject to their own terms and privacy policies.
The classification of a provider as a Sub-processor or independent Controller shall depend on the actual nature of the processing performed and not solely on its technical integration with the Platform.
32. Payment Service Providers
Where the Platform integrates payment processing services, the processing of associated data may be subject to the terms and responsibilities of the relevant payment service provider.
Depending on the nature of the transaction, such provider may act as a Processor, Sub-processor, independent Controller or in another capacity recognized under applicable law.
Bike Booking Engine shall not automatically consider all data processed by a payment service provider to be processed by that provider in its capacity as a Sub-processor.
33. Artificial Intelligence Services
Where the Customer enables an optional functionality requiring the involvement of an external artificial intelligence provider and such provider processes Personal Data on behalf of Bike Booking Engine, the relevant provider shall be treated as a Sub-processor where this follows from the nature of the processing.
Bike Booking Engine shall seek to limit the information transmitted to such providers to that which is reasonably necessary to provide the relevant functionality.
The use of optional artificial intelligence functionalities may be subject to additional terms, specific configurations or additional information provided to the Customer.
Bike Booking Engine's core functionalities do not, by default, require sensitive Customer Data to be transmitted to external artificial intelligence providers.
34. Changes to Technology Providers
Bike Booking Engine may modify its infrastructure and replace technology providers as its technical, commercial, operational or security requirements evolve.
This DPA shall not be interpreted as a commitment to permanently use any particular provider.
Where such change affects a provider acting as a Sub-processor, the obligations established in this Chapter shall apply.
35. General Principle
Bike Booking Engine shall seek to ensure that Personal Data processed on behalf of the Customer remains within the European Economic Area (EEA) where compatible with the architecture and Services used.
However, certain Sub-processors or technology providers may process Personal Data from countries located outside the EEA where necessary to provide certain functionalities or services.
Where such processing constitutes an international data transfer under applicable law, Bike Booking Engine shall ensure that the transfer is carried out using a legally recognized transfer mechanism.
36. Transfer Mechanisms
Where Personal Data is transferred to a country outside the EEA that has not been recognized by the European Commission as providing an adequate level of protection, Bike Booking Engine shall use, as appropriate, one or more transfer mechanisms permitted under applicable law.
Such mechanisms may include:
- The European Commission's Standard Contractual Clauses (SCCs);
- Binding Corporate Rules, where applicable;
- Certification mechanisms or legally recognized frameworks;
- Derogations expressly permitted under applicable law; or
- Any other valid transfer mechanism recognized under applicable law.
37. Adequacy Decisions
Where the European Commission has determined that a country, territory, specified sector or mechanism provides an adequate level of protection for Personal Data, transfers may be carried out on the basis of such adequacy decision for as long as it remains in force.
Bike Booking Engine may rely on adequacy decisions in effect from time to time without implementing additional safeguards where permitted under applicable law.
38. Standard Contractual Clauses
Where it is necessary to use Standard Contractual Clauses approved by the European Commission, Bike Booking Engine shall seek to ensure that such clauses are incorporated into the relevant contractual relationship with the recipient of the data.
The appropriate SCC module shall be used according to the respective roles of the parties involved in the transfer.
Where a Sub-processor carries out an onward transfer of Personal Data, it shall implement the safeguards required under applicable law.
39. Assessment of Transfers
Where required under applicable law, Bike Booking Engine may assess the relevant circumstances of an international transfer and the available safeguards in order to determine whether Personal Data receives a level of protection essentially equivalent to that required under European data protection law.
Such assessment may take into account, among other factors:
- The destination country;
- The nature of the data;
- The purpose of the processing;
- The provider involved;
- Existing contractual safeguards;
- Applicable technical and organizational measures; and
- The relevant legal framework.
40. Supplementary Measures
Where necessary, Bike Booking Engine may implement or require supplementary measures designed to strengthen the protection of Personal Data subject to an international transfer.
Such measures may be:
- Technical;
- Contractual; or
- Organizational.
The specific measures shall depend on the circumstances of the transfer and the risks reasonably identified.
41. Transfers Carried Out by Sub-processors
Bike Booking Engine shall require its Sub-processors to ensure that any international transfer of Personal Data carried out in connection with the Services complies with applicable data protection requirements.
A provider's primary location within the EEA does not necessarily mean that all processing activities or ancillary services are performed exclusively within the EEA.
Where applicable, safeguards relating to onward transfers shall form part of the contractual obligations applicable to the relevant Sub-processor.
42. Information to the Customer
Bike Booking Engine shall make available to the Customer reasonable information regarding relevant international transfers carried out in connection with Personal Data processed on behalf of the Customer.
Such information may be provided through:
- The Sub-processor list;
- This DPA;
- Privacy documentation;
- Contractual documentation;
- The Platform; or
- Upon reasonable request by the Customer.
Bike Booking Engine may restrict the information provided where necessary to protect confidential information, trade secrets or the security of its systems.
43. Changes to Transfer Mechanisms
The legal mechanisms applicable to international data transfers may change as a result of:
- Legislative amendments;
- Court decisions;
- Decisions by data protection authorities;
- New adequacy decisions;
- Amendment or replacement of the SCCs; or
- The introduction of new legally recognized mechanisms.
Bike Booking Engine may replace or adapt the mechanisms used where necessary to maintain the compliance of international transfers with applicable law.
44. Customer Cooperation
Where reasonably necessary to implement a valid international transfer mechanism, the Customer shall provide the information and cooperation required within its area of responsibility.
Where a transfer results directly from a specific integration, configuration or instruction of the Customer, the Customer shall be responsible for assessing the obligations applicable to it as Data Controller, without prejudice to Bike Booking Engine's own obligations as Data Processor.
45. Transfers Requested by the Customer
Where the Customer expressly instructs Bike Booking Engine to transmit Personal Data to a third party or system located outside the EEA, such instruction must comply with applicable law.
Bike Booking Engine may request additional information where reasonably necessary to determine how to execute the instruction in a manner compatible with its obligations as Data Processor.
Bike Booking Engine may refuse to execute an instruction where it reasonably considers that doing so would result in a breach of applicable data protection law.
46. Customer Responsibility
The Customer, in its capacity as Data Controller, shall be responsible for handling requests submitted by Data Subjects in connection with the exercise of their rights under applicable data protection law.
This may include, where applicable, the rights to:
- Access;
- Rectification;
- Erasure;
- Restriction of processing;
- Data portability;
- Objection; and
- Rights relating to automated individual decision-making, where applicable.
The Customer shall be responsible for determining whether a request is valid, verifying the identity of the requester where necessary, and deciding the response to be provided in accordance with applicable law.
47. Assistance by Bike Booking Engine
Taking into account the nature of the processing, Bike Booking Engine shall reasonably assist the Customer through appropriate technical and organizational measures, insofar as possible, to enable the Customer to respond to requests from Data Subjects exercising their rights.
Such assistance may include, where appropriate:
- Facilitating access to information stored within the Platform;
- Enabling the rectification of data;
- Facilitating the deletion of information;
- Providing data export functionalities;
- Locating relevant information;
- Carrying out the Customer's lawful instructions; or
- Providing other technically reasonable assistance.
The availability and specific form of such assistance shall depend on the nature of the data, the available functionalities and the technical characteristics of the Platform.
48. Requests Received Directly by Bike Booking Engine
Where Bike Booking Engine directly receives a request from a Data Subject relating to Personal Data processed on behalf of a Customer, Bike Booking Engine shall not substantively respond to such request on behalf of the Customer unless:
- Expressly authorized by the Customer;
- Necessary under this DPA; or
- Required by applicable law.
Where reasonably possible, Bike Booking Engine shall forward the request to the relevant Customer or inform the Data Subject that they should contact the relevant Data Controller.
49. Identification of the Relevant Customer
Where a request received directly by Bike Booking Engine relates to data managed by one of its Customers, it may be necessary to identify which Customer acts as the Data Controller with respect to such data.
Bike Booking Engine may request from the Data Subject the information reasonably necessary to identify:
- The company with which the Data Subject had a relationship;
- The relevant booking or transaction;
- The service used; or
- Any other information necessary to identify the relevant Controller.
Bike Booking Engine shall avoid requesting additional information that is not reasonably necessary to handle the request.
50. Access and Retrieval of Information
Where the Customer is required to respond to an access request, Bike Booking Engine shall, to the extent reasonably possible and in accordance with the available functionalities, provide the means necessary to access or retrieve the Personal Data processed through the Platform that is relevant to the request.
The determination of what information must be provided to the Data Subject and how the request should be answered shall remain the responsibility of the Customer as Data Controller.
51. Rectification
Where a Data Subject requests the correction of inaccurate or incomplete Personal Data, the Customer may use the functionalities available within the Platform to modify such information where possible.
Where rectification cannot be performed directly through the Platform and intervention by Bike Booking Engine is necessary, the Processor shall provide reasonable assistance in accordance with the Customer's lawful instructions.
52. Erasure
Where the Customer determines that Personal Data must be deleted in response to the exercise of the right to erasure, Bike Booking Engine shall facilitate or carry out the relevant deletion to the extent technically possible and in accordance with the Customer's lawful instructions.
Deletion of data from active systems does not necessarily result in its immediate deletion from backups.
Data contained within backups shall be removed in accordance with the ordinary rotation cycles established in the Backup & Retention Policy, unless applicable law requires otherwise.
53. Restriction of Processing
Where the Customer determines that certain Personal Data must be subject to a restriction of processing, Bike Booking Engine shall provide reasonable assistance to implement such restriction where technically possible within the Platform.
The specific manner in which the restriction is implemented may depend on:
- The nature of the data;
- The system in which it is stored;
- The available functionalities; and
- The nature of the request.
54. Data Portability
Where the right to data portability applies, Bike Booking Engine shall provide the Customer with reasonable assistance to obtain the relevant Personal Data in an available and technically appropriate format.
Bike Booking Engine shall not be responsible for determining whether the right to data portability applies to a particular request.
The Customer shall be responsible for assessing such circumstances and providing the appropriate response to the Data Subject.
55. Objection to Processing
Where a Data Subject exercises the right to object in relation to processing carried out under the Customer's responsibility, the Customer shall be responsible for determining the legal consequences of such request.
Bike Booking Engine shall carry out the lawful instructions received from the Customer where necessary to modify or cease specific processing activities performed on the Customer's behalf.
56. Automated Decision-Making
Where a Platform functionality enables the Customer to carry out processing that may involve automated decision-making concerning natural persons, the Customer shall be responsible for determining whether the rules governing such decisions under applicable data protection law apply.
Bike Booking Engine shall provide reasonably available information regarding the operation of functionalities under its control where necessary to enable the Customer to assess its obligations.
The mere automation of operational processes within the Platform shall not necessarily constitute automated individual decision-making within the meaning of applicable data protection law.
57. Response Timeframes
The Customer shall be responsible for ensuring that requests relating to the exercise of Data Subject rights are handled within the time limits established by applicable law.
Where Bike Booking Engine's assistance is required, the Customer shall submit the request with reasonably sufficient time to allow it to be processed.
Bike Booking Engine shall seek to provide the necessary assistance without undue delay, taking into account the nature and complexity of the request.
58. Manifestly Unfounded or Excessive Requests
The Customer shall be responsible for determining whether a Data Subject request is manifestly unfounded, excessive or subject to any exception provided for under applicable law.
Bike Booking Engine shall not be required to make a legal determination regarding the applicability of a Data Subject right on behalf of the Customer.
Where a request submitted by the Customer to Bike Booking Engine involves extraordinary, repetitive or technically complex activities, the provisions regarding extraordinary assistance set out in this DPA may apply.
59. Definition
For the purposes of this DPA, a Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss or alteration of Personal Data processed on behalf of the Customer, or to the unauthorized disclosure of or access to such data.
Not every technical or security incident shall necessarily constitute a Personal Data Breach.
60. Incident Management Procedure
Bike Booking Engine maintains internal procedures for managing security incidents that may affect the Platform or Personal Data processed through it.
Where a relevant incident is detected, Bike Booking Engine may take such measures as are reasonably necessary to:
- Identify the incident;
- Contain it;
- Analyze its nature and scope;
- Mitigate its potential effects;
- Resolve it;
- Recover affected systems where necessary; and
- Document and monitor the incident through to closure.
The specific measures taken shall depend on the nature, severity and characteristics of each incident.
61. Notification to the Customer
Where Bike Booking Engine becomes aware of a Personal Data Breach affecting data processed on behalf of the Customer, Bike Booking Engine shall notify the affected Customer without undue delay.
Notification shall be made using the contact details available for the Customer or through any other reasonably appropriate channel.
Bike Booking Engine may provide information progressively where it is not possible to provide all details of the incident at the time of the initial notification.
62. Content of the Notification
To the extent that the information is reasonably available to Bike Booking Engine, the notification may include:
- The nature of the Personal Data Breach;
- The categories of affected Data Subjects;
- The categories of Personal Data affected;
- An estimate of the number of affected Data Subjects, where possible;
- An estimate of the number of affected records, where possible;
- The potential consequences of the breach;
- The measures taken or proposed to contain, mitigate or resolve the incident; and
- A point of contact for obtaining additional information.
Where certain information is not initially available, Bike Booking Engine may provide it subsequently without undue delay as the investigation progresses.
63. Investigation and Containment
Bike Booking Engine shall investigate Personal Data Breaches affecting information processed on behalf of the Customer and shall take reasonable measures designed to contain and mitigate their effects.
The investigation may include, where appropriate:
- Reviewing technical logs;
- Analyzing access records;
- Identifying affected systems;
- Assessing potentially compromised data;
- Revoking or modifying access permissions;
- Implementing corrective measures; and
- Recovering or restoring systems.
The scope of such actions shall depend on the specific circumstances of the incident.
64. Cooperation with the Customer
Bike Booking Engine shall provide the Customer with reasonable assistance to enable it to assess the Personal Data Breach and comply with its obligations as Data Controller.
Such cooperation may include reasonably available information regarding:
- The scope of the incident;
- The data affected;
- The measures taken;
- The reasonably identified consequences; and
- The mitigation measures implemented.
Bike Booking Engine may provide additional updates where materially relevant information becomes available during the investigation.
65. Notification to Supervisory Authorities
The Customer, in its capacity as Data Controller, shall be responsible for determining whether a Personal Data Breach must be notified to the competent supervisory authority in accordance with applicable law.
Bike Booking Engine shall provide the Customer with such reasonable assistance as may be necessary to enable it to make that assessment.
Unless otherwise required by applicable law, Bike Booking Engine shall not make the notification required of the Data Controller on the Customer's behalf without the Customer's instructions or authorization.
66. Communication to Data Subjects
The Customer shall also be responsible for determining whether a Personal Data Breach requires communication to the affected Data Subjects.
Bike Booking Engine shall provide reasonable assistance to the Customer where such communication is necessary and the assistance relates to information or systems under Bike Booking Engine's control.
Bike Booking Engine shall not directly contact affected Data Subjects on behalf of the Customer unless:
- Requested or authorized by the Customer;
- Necessary to comply with this DPA; or
- Required by applicable law.
67. Regulatory Timeframes
Where the GDPR applies, the Customer shall take into account the timeframes established under the GDPR for notifying Personal Data Breaches to the competent supervisory authority.
Bike Booking Engine's obligation shall be to notify the Customer of a Personal Data Breach without undue delay after becoming aware of it, so that the Customer can assess and comply with its own regulatory obligations.
This DPA does not establish a specific contractual notification period shorter than that required under applicable law for notification by the Processor to the Controller.
68. Documentation of Incidents
Bike Booking Engine shall maintain reasonable documentation regarding Personal Data Breaches affecting data processed on behalf of its Customers, as necessary to comply with its legal, operational and security obligations.
Such documentation may include information relating to:
- The nature of the incident;
- The systems affected;
- Its effects;
- Containment measures;
- Corrective measures; and
- The closure and follow-up of the incident.
Access to such documentation shall be restricted to authorized personnel and to persons or authorities legally entitled to access it.
69. Incidents Involving Sub-processors
Where Bike Booking Engine becomes aware of a Personal Data Breach originating from a Sub-processor and affecting data processed on behalf of the Customer, the notification and cooperation obligations established in this Chapter shall apply.
Bike Booking Engine may rely on information provided by the Sub-processor to investigate the incident, assess its scope and provide information to the Customer.
70. Post-Incident Measures
Following a Personal Data Breach, Bike Booking Engine may implement reasonable measures designed to reduce the risk of similar incidents occurring in the future.
Such measures may include, where appropriate:
- Technical modifications;
- Configuration changes;
- Access reviews;
- Procedure updates;
- Dependency updates;
- Additional monitoring measures;
- Provider reviews; or
- Improvements to security controls.
The measures implemented shall depend on the causes and circumstances of the incident.
71. No Admission of Liability
Notification by Bike Booking Engine of an incident or Personal Data Breach shall not, by itself, constitute an admission of liability, breach of contract, negligence or violation of applicable law.
The liability of the Parties shall be determined in accordance with the circumstances of the incident, applicable law and the relevant contractual provisions.
72. General Principle
Bike Booking Engine shall retain Personal Data processed on behalf of the Customer only for as long as necessary to provide the Services and for any additional retention periods applicable under this DPA, the contractual documentation and applicable law.
Upon termination of the Services, Bike Booking Engine shall proceed with the return or deletion of Personal Data in accordance with the provisions of this Chapter and the Backup & Retention Policy.
73. Retention Following Termination
Following termination or cancellation of the subscription, Customer Data shall not be deleted immediately.
As a general rule, Bike Booking Engine shall retain such data for a period of 90 days from the effective date of termination of the Service.
During this period, the data may be retained for the purpose of allowing, where applicable:
- Account reactivation;
- Recovery of information;
- Data export;
- Resolution of outstanding incidents;
- Compliance with the Customer's lawful instructions; and
- Management of obligations arising from the contractual relationship.
The Customer's access to the Platform during this period may be restricted or disabled in accordance with the terms applicable to termination.
74. Return and Export of Data
During the post-termination retention period, the Customer may request, where applicable and technically feasible, the export of Personal Data processed on its behalf.
Bike Booking Engine shall provide the data through the functionalities or export procedures reasonably available.
The Customer shall be responsible for requesting and retaining any information required to comply with its own legal, tax, accounting, administrative or operational obligations.
75. Deletion Following Termination
Once the general 90-day retention period has expired, Bike Booking Engine shall proceed to delete the Customer's Personal Data from active systems, unless:
- A legal obligation requires its retention;
- A specific retention period applies;
- Certain information must be retained for the establishment, exercise or defense of legal claims;
- An incident, dispute or proceeding legitimately justifies its retention; or
- Applicable law permits or requires additional retention.
Where reasonably possible, any additional retention shall be limited to the data necessary for the relevant purpose.
76. Identification Documentation During Online Check-In
Where the Customer enables the relevant functionality, end users may upload a copy of their identity document, passport or other accepted identification document during the online check-in process.
Bike Booking Engine shall process such documentation on behalf of the Customer and in accordance with its instructions, for the purpose of enabling the Customer to carry out the necessary checks relating to the booking and to facilitate faster and more efficient preparation and delivery of the booked goods or services.
The Customer, in its capacity as Data Controller, shall be responsible for determining the applicable legal basis for the collection and use of such documentation and for providing Data Subjects with the information required under applicable law.
77. Retention Period for Identification Documentation
Identification documentation uploaded through the online check-in process shall be subject to a specific retention period separate from that applicable to the remaining data associated with the booking.
As a general rule, Bike Booking Engine shall retain such documentation only for the period necessary to manage the booking and shall automatically delete it from active systems within 72 hours following the completion of the booking.
This specific retention period shall prevail over the general retention period applicable to other booking or Customer Data.
Deletion of identification documentation shall not result in the deletion of the booking itself or other associated data subject to different retention periods.
78. Exceptional Retention of Identification Documentation
Exceptionally, identification documentation may be retained for an additional period where a circumstance legitimately justifies such retention, including:
- An incident relating to the booking;
- A claim or dispute;
- Judicial or administrative proceedings;
- A fraud-related investigation;
- The need to establish, exercise or defend legal claims; or
- An applicable legal obligation.
Where Bike Booking Engine acts as Data Processor, such additional retention shall be carried out in accordance with the Customer's lawful instructions, unless a legal obligation directly applicable to Bike Booking Engine requires otherwise.
The documentation shall be retained only for as long as reasonably necessary to address the circumstance justifying such retention.
79. Backups
Deletion of Personal Data from active systems does not necessarily result in its immediate deletion from all existing backups.
As a general rule, Bike Booking Engine maintains:
- Daily backups, retained for 30 days; and
- Weekly backups, retained for 6 months.
Data deleted from active systems may temporarily remain within such backups until they reach the end of their ordinary retention cycles and are deleted in accordance with the rotation process.
80. Deleted Data Contained in Backups
Personal Data that temporarily remains within backups after having been deleted from active systems shall not be used for the ordinary operation of the Platform.
Bike Booking Engine shall not use backups as a mechanism to deliberately extend the retention of data that should have been deleted.
When a backup containing such data reaches the end of its retention period, it shall be deleted in accordance with the ordinary rotation cycle.
81. Restoration of Backups
Where it becomes necessary to restore a backup for Service recovery or continuity purposes, such backup may contain data that had previously been deleted from active systems.
In such circumstances, Bike Booking Engine shall seek to implement reasonable measures to preserve the previously applicable deletion decisions and retention periods.
The technical restoration of a backup shall not, by itself, initiate a new retention period for data that was already required to be deleted.
82. Deletion at the Customer's Request
During the term of the Services, the Customer may request the deletion of certain Personal Data processed on its behalf where such deletion is necessary to comply with its obligations as Data Controller.
Bike Booking Engine shall carry out the Customer's lawful instructions to the extent technically possible and in accordance with this DPA and applicable law.
Deletion from active systems shall not necessarily result in the immediate deletion of data contained within backups that remain subject to their ordinary rotation cycles.
83. Legal Exceptions
Bike Booking Engine may retain certain information where a legal obligation directly applicable to it requires such retention.
Where applicable law prevents the immediate deletion of certain information, Bike Booking Engine shall restrict its processing, where appropriate, to the purposes justifying its retention.
Where legally permitted, Bike Booking Engine shall inform the Customer of any obligation preventing the execution of a deletion instruction.
84. Anonymized Data
The deletion obligations established in this Chapter shall not apply to information that has been transformed in such a way that it no longer constitutes Personal Data through an irreversible anonymization process in accordance with applicable law.
Bike Booking Engine may retain and use properly anonymized information for legitimate purposes such as:
- Statistical analysis;
- Improvement of the Services;
- Performance analysis;
- Capacity planning; and
- Development and evolution of the Platform.
Pseudonymization shall not, by itself, be considered irreversible anonymization.
85. Precedence of the DPA
In the event of any conflict between the Backup & Retention Policy and this DPA regarding the processing of Personal Data carried out by Bike Booking Engine on behalf of the Customer, the provisions of this DPA shall prevail to the extent necessary to comply with applicable data protection law.
86. General Security Principle
Bike Booking Engine shall implement and maintain appropriate technical and organizational measures designed to protect Personal Data processed on behalf of the Customer.
Such measures shall be established taking into account, where appropriate:
- The nature, scope, context and purposes of the processing;
- The risks to the rights and freedoms of natural persons;
- The technical characteristics of the Platform;
- The state of the art; and
- The reasonable security and operational requirements of the Services.
The measures described in this Chapter represent the general security framework applied by Bike Booking Engine and may evolve as the Platform, infrastructure and identified risks change.
87. Infrastructure
The Platform is hosted using professional cloud infrastructure.
Bike Booking Engine may use managed infrastructure services, including, where appropriate:
- Cloud servers;
- Managed databases;
- Storage systems;
- Backup services;
- Content delivery networks; and
- Other components necessary for the operation of the Platform.
The physical security of the data centers used to host the infrastructure is the responsibility of the relevant infrastructure providers.
Bike Booking Engine shall select providers that offer security measures appropriate to the nature of the services used.
88. Communications Security
Communications with the Platform are protected using HTTPS and standard TLS technologies.
The Services use digital certificates issued by recognized certificate authorities.
These measures are designed to protect information during transmission against unauthorized access or interception.
89. Protection of Credentials
User passwords are not stored in plain text.
Bike Booking Engine uses hashing mechanisms to protect stored passwords.
Mechanisms are also implemented to reduce the risks arising from repeated or abusive authentication attempts, including:
- Attempt rate limiting;
- Temporary lockouts; and
- Automated mechanisms for detecting suspicious activity.
90. Administrative Authentication
Administrative access to production systems is restricted to authorized technical personnel.
Multi-factor authentication (MFA) is mandatory for accounts with administrative access.
Bike Booking Engine shall restrict such access to the number of individuals reasonably necessary for the administration, maintenance and security of the Platform.
91. Access Control and Least Privilege
Bike Booking Engine applies role-based access controls and the principle of least privilege.
Access to production systems and Personal Data shall be restricted to authorized personnel who require such access to perform their duties.
Where an individual no longer maintains an employment or contractual relationship justifying such access, their permissions shall be revoked in accordance with applicable internal procedures.
92. Logical Separation Between Customers
Bike Booking Engine implements mechanisms designed to maintain the logical separation of each Customer's data within the Platform.
Each company has a logical environment that enables its information to be isolated from that of other Customers.
A Customer is not authorized to access another Customer's data.
The Platform's authorization mechanisms are designed to prevent such unauthorized access.
93. Customer Roles and Permissions
The Platform provides role and permission mechanisms that enable access by Authorized Users to specific functionalities and information to be restricted.
The Customer shall be responsible for properly configuring and managing the permissions of its own Authorized Users within the available functionalities.
Bike Booking Engine shall maintain the technical mechanisms necessary to enforce the permission configurations supported by the Platform.
94. Session Management
User sessions are subject to expiration mechanisms.
Sessions may automatically expire after a configurable period of inactivity.
Bike Booking Engine may implement additional session controls where necessary to protect the security of the Platform.
95. Development and Pre-production Environments
Bike Booking Engine maintains development environments separate from the production environment.
Bike Booking Engine also maintains a staging or pre-production environment designed to validate changes before they are deployed to production.
The separation of environments is intended to reduce the risks associated with the development, testing and deployment of new functionalities or modifications to the Platform.
96. Change Review and Deployment
Changes to the Platform are subject to version control, code review and functional testing processes before deployment to production.
New versions are deployed through automated processes supervised by authorized personnel.
Bike Booking Engine may modify its development and deployment procedures as its tools and architecture evolve, provided that a reasonable level of control over changes introduced into production is maintained.
97. Dependency and Vulnerability Management
Dependencies used by the Platform are periodically reviewed and updated as part of preventive maintenance activities.
Bike Booking Engine uses dependency analysis mechanisms and periodic reviews designed to identify known vulnerabilities.
Where a relevant vulnerability is identified, Bike Booking Engine may implement such technical measures as are reasonably necessary, taking into account its nature, severity and risk.
98. Monitoring
Bike Booking Engine maintains infrastructure and application monitoring mechanisms designed to detect:
- Incidents;
- Errors;
- Service degradation; and
- Other circumstances relevant to the operation and security of the Platform.
The specific monitoring mechanisms and tools may evolve as the infrastructure and operational requirements change.
99. Error and Access Logging
Bike Booking Engine maintains logs of relevant system errors to facilitate their analysis and resolution.
Access to the Platform is also logged for security and audit purposes.
Access to such logs shall be restricted to authorized personnel according to their responsibilities.
100. Logging of Critical Actions
Certain relevant actions performed within the Platform are recorded through audit mechanisms.
Such records may be used to:
- Provide traceability;
- Investigate incidents;
- Analyze actions performed within the Platform;
- Detect anomalous activity; and
- Contribute to the security of the Services.
101. Backups
Bike Booking Engine maintains periodic backup mechanisms designed to facilitate the recovery of information and systems.
As a general rule:
- A full daily backup is performed and retained for 30 days; and
- A weekly backup for longer-term retention is maintained and retained for 6 months.
Backups are maintained separately from the relevant primary server.
Bike Booking Engine performs periodic restoration tests designed to verify backup integrity and recovery capabilities in the event of an incident.
102. Incident Management
Bike Booking Engine maintains a procedure for managing critical incidents that includes, where appropriate:
- Identification;
- Containment;
- Analysis;
- Resolution;
- Documentation; and
- Monitoring through to closure.
Where an incident constitutes a Personal Data Breach, the provisions of Chapter VI of this DPA shall also apply.
103. Personnel Confidentiality
Personnel with access to confidential information shall be subject to confidentiality obligations.
Access to Customer Data is not generally granted to all Bike Booking Engine employees or collaborators.
Such access shall be restricted to authorized personnel and only where necessary to provide support, perform maintenance, administer infrastructure, manage incidents or carry out other legitimate functions related to the Services.
104. Access Reviews
Bike Booking Engine shall review and manage access to its systems in accordance with operational and security requirements.
Access rights shall be revoked when they are no longer necessary, including upon termination of the relevant individual's employment or contractual relationship.
105. Physical Security
The infrastructure used to provide the Services is hosted in data centers managed by specialized providers.
The physical protection of such data centers, including the physical controls applicable to their facilities, is the responsibility of the relevant infrastructure providers.
Bike Booking Engine does not maintain ordinary physical access to the servers hosted in such data centers.
106. Review and Evolution of Measures
The technical and organizational measures described in this Chapter may be reviewed and modified as the following evolve:
- Technology;
- The architecture of the Platform;
- The providers used;
- Security risks;
- Identified threats;
- Service functionalities; and
- Regulatory obligations.
The replacement of a specific technology, tool or provider shall not, by itself, require an amendment to this DPA, provided that Bike Booking Engine maintains a level of protection appropriate to the risks of the processing.
107. General Responsibility of the Customer
The Customer, in its capacity as Data Controller, shall be responsible for ensuring that Personal Data processed through the Platform is collected and used in accordance with applicable data protection law.
In particular, the Customer shall be responsible for determining:
- The purposes of the processing;
- The categories of Personal Data that need to be processed;
- The categories of Data Subjects concerned;
- The applicable legal basis;
- The applicable retention periods within its area of responsibility; and
- The persons who should be authorized to access such data.
Bike Booking Engine shall not assume obligations that legally correspond to the Customer in its capacity as Data Controller.
108. Lawfulness of Processing
The Customer shall ensure that it has a valid legal basis for collecting, entering, storing, using and processing through the Platform the Personal Data in respect of which Bike Booking Engine acts as Data Processor.
Where it is necessary to obtain the Data Subject's consent, the Customer shall be responsible for determining:
- When such consent is required;
- How it must be obtained;
- What information must be provided to the Data Subject; and
- How such consent must be documented or managed.
The Customer's use of the Platform shall not, by itself, constitute a determination by Bike Booking Engine that the processing carried out by the Customer is lawful.
109. Information Provided to Data Subjects
The Customer shall be responsible for providing Data Subjects with the information required under applicable law regarding the processing of their Personal Data.
Such information shall include, where applicable:
- The identity of the Data Controller;
- The purposes of the processing;
- The applicable legal basis;
- The recipients or categories of recipients;
- The applicable retention periods or criteria;
- Information regarding international transfers, where applicable;
- The rights of Data Subjects; and
- Any other information required under applicable law.
Bike Booking Engine may provide functionalities or technical mechanisms to assist the Customer in complying with these obligations, without thereby assuming the Customer's corresponding legal responsibility.
110. Accuracy and Quality of Data
The Customer shall be responsible for taking reasonable measures to ensure that Personal Data entered into or managed through the Platform is adequate, relevant and, where necessary, accurate and up to date.
Bike Booking Engine shall not be responsible for generally verifying the accuracy of information entered by the Customer, its Authorized Users or end users.
Where the Platform allows information to be modified or updated, the Customer shall be responsible for using such functionalities where necessary.
111. Data Minimization
The Customer shall seek to limit the collection and processing of Personal Data through the Platform to data that is adequate, relevant and necessary for the purposes pursued.
The Customer shall not use the Platform to collect Personal Data that is manifestly unnecessary for the provision of its services or for the relevant legitimate purposes.
The technical availability of a field, functionality or information upload mechanism does not imply that its use is necessary or legally appropriate in all circumstances.
112. Special Categories of Personal Data
Unless a functionality is expressly designed for such purpose or a specific agreement has been entered into with Bike Booking Engine, the Customer shall not use the Platform to store or process special categories of Personal Data in a manner that is not necessary for the Services.
Where the Customer processes special categories of Personal Data through a permitted functionality, the Customer shall be responsible for ensuring that it has an appropriate legal basis and complies with any additional requirements established under applicable law.
113. Identification Documentation
Where the Customer enables the functionality that allows end users to upload identification documentation during the online check-in process, the Customer shall be responsible for determining that such collection is lawful, necessary and proportionate.
The Customer shall be responsible for:
- Determining the applicable legal basis;
- Properly informing the end user;
- Limiting the use of the document to the relevant legitimate purposes;
- Avoiding unnecessary additional copies or uses; and
- Complying with any additional obligations applicable to such documentation.
Bike Booking Engine shall process such documentation in accordance with the conditions established in this DPA, including its automatic deletion from active systems within 72 hours following the completion of the booking, unless a legitimate exception applies.
114. Authorized Users
The Customer shall be responsible for determining which individuals may access its account and the Personal Data managed through the Platform.
The Customer shall:
- Create accounts only for authorized individuals;
- Assign appropriate roles and permissions;
- Review access rights where necessary;
- Revoke access when it is no longer justified;
- Adequately protect its credentials; and
- Seek to ensure that its Authorized Users use the Platform in accordance with the applicable contractual documentation.
Bike Booking Engine shall not be responsible for access carried out using valid credentials where such access results from improper management of users or credentials by the Customer, without prejudice to Bike Booking Engine's own security obligations.
115. Security Under the Customer's Control
The Customer shall take reasonable measures to protect those aspects of security that are under its control.
This may include:
- Protecting access credentials;
- Not sharing personal accounts between users where individual accounts are available;
- Properly configuring roles and permissions;
- Keeping account contact details up to date;
- Protecting the devices used to access the Platform; and
- Notifying Bike Booking Engine of any suspicious access or relevant incident of which it becomes aware.
116. Instructions to Bike Booking Engine
The Customer shall ensure that instructions provided to Bike Booking Engine regarding the processing of Personal Data are lawful and compatible with applicable law.
Bike Booking Engine shall not be required to carry out instructions that it reasonably considers to be:
- Contrary to applicable law;
- Incompatible with this DPA;
- Technically impossible; or
- Likely to unjustifiably compromise the security or integrity of the Platform.
In such cases, the provisions of this DPA relating to instructions contrary to applicable law shall apply.
117. Integrations and Third Parties Selected by the Customer
Where the Customer connects the Platform to third-party applications, systems, APIs or services selected or configured by the Customer, the Customer shall be responsible for assessing the data protection implications arising from such integration.
The Customer shall be responsible for determining:
- Which data should be transmitted;
- The lawfulness of such transmission;
- The necessary authorizations;
- The legal relationship with the third party; and
- The applicable information obligations.
Bike Booking Engine shall be responsible only for processing activities carried out within the scope of its own obligations under this DPA.
118. Data Subject Requests
The Customer shall be responsible for handling requests relating to the exercise of Data Subject rights in accordance with Chapter V.
Where assistance from Bike Booking Engine is required, the Customer shall provide the information reasonably necessary to identify the affected data and the actions requested.
119. Security Breaches Under the Customer's Control
Where the Customer becomes aware of a security incident relating to:
- Its Authorized Users;
- Its credentials;
- Its devices;
- Its systems;
- An integration managed by the Customer; or
- Any other element under its control that may affect data processed through the Platform,
the Customer shall take the measures applicable to it and, where relevant to the security of the Platform or the data processed by Bike Booking Engine, notify Bike Booking Engine without undue delay.
Bike Booking Engine may provide reasonable assistance regarding those aspects of the incident that are under its control.
120. Compliance with the Customer's Own Obligations
The Customer shall be responsible for complying with the obligations applicable to it as Data Controller under applicable law.
This may include, where applicable:
- Maintaining records of processing activities;
- Carrying out Data Protection Impact Assessments;
- Managing prior consultations;
- Responding to Data Subjects;
- Notifying Personal Data Breaches;
- Responding to requests from authorities;
- Establishing retention periods; and
- Implementing any other measures necessary within its area of responsibility.
The use of Bike Booking Engine as Data Processor shall not exempt the Customer from such obligations.
121. Cooperation Between the Parties
The Parties shall cooperate in good faith to facilitate compliance with their respective data protection obligations.
Each Party shall be responsible for the obligations applicable to it according to its actual role in the processing and applicable law.
The cooperation provided for in this Section shall not alter the allocation of responsibilities between the Data Controller and the Data Processor established under this DPA.
122. Entry into Force and Duration
This DPA shall enter into force on the date on which the Customer accepts, executes or otherwise becomes bound by the contractual agreement governing the use of Bike Booking Engine's Services.
The DPA shall remain in force for as long as Bike Booking Engine processes Personal Data on behalf of the Customer.
Termination of the subscription or the main agreement shall not immediately terminate those provisions of this DPA that must continue to apply for as long as Bike Booking Engine retains or processes Personal Data on behalf of the Customer.
123. Relationship with the Main Agreement
This DPA forms an integral part of the contractual agreement between Bike Booking Engine and the Customer.
Unless expressly stated otherwise, terms defined in the Terms of Service or other applicable contractual documentation shall have the same meaning when used in this DPA.
In the event of any conflict between this DPA and other contractual provisions regarding the processing of Personal Data by Bike Booking Engine in its capacity as Data Processor, this DPA shall prevail to the extent necessary to resolve such conflict.
124. Relationship with Other Policies
This DPA may be supplemented by other Bike Booking Engine policies and documents, including, where applicable:
- The Privacy Policy;
- The Security Policy;
- The Backup & Retention Policy;
- The Sub-processor list;
- The Terms of Service; and
- Other documentation applicable to the Services.
Such documents shall be interpreted together where they govern matters relating to the processing or protection of Personal Data.
In the event of any conflict regarding Bike Booking Engine's obligations as Data Processor, this DPA shall prevail to the extent necessary to comply with applicable data protection law.
125. Liability of the Parties
Each Party shall be responsible for complying with the obligations applicable to it according to its role in the processing of Personal Data and applicable law.
The Customer shall be responsible for the decisions and obligations applicable to it in its capacity as Data Controller.
Bike Booking Engine shall be responsible for the obligations applicable to it in its capacity as Data Processor.
The existence of this DPA shall not alter the allocation of responsibilities established under applicable law.
126. Contractual Limitations of Liability
To the extent permitted by applicable law, the limitations and exclusions of liability established in the main agreement or the Terms of Service shall also apply to this DPA.
Nothing in this DPA shall exclude or limit any liability where such exclusion or limitation is not permitted under applicable law.
The provisions of this Section shall be without prejudice to any rights available to Data Subjects or supervisory authorities under applicable law.
127. Indemnification and Claims
Liability arising from claims, damages, penalties or costs relating to the processing of Personal Data shall be determined in accordance with:
- The respective roles of the Parties;
- The obligations established under this DPA;
- The main contractual agreement;
- The acts or omissions of each Party; and
- Applicable law.
Nothing in this DPA shall imply that either Party automatically assumes liability for acts or omissions attributable to the other Party.
128. Amendments to the DPA
Bike Booking Engine may update this DPA where reasonably necessary to:
- Adapt it to legislative or regulatory changes;
- Incorporate new contractual clauses or legally recognized mechanisms;
- Reflect changes to the Services;
- Improve or clarify its provisions;
- Adapt the document to changes in infrastructure or processing activities; or
- Maintain compliance with applicable law.
Where an amendment materially affects the Customer's data protection rights or obligations, Bike Booking Engine shall provide information regarding the change through a reasonable means.
129. Changes Required by Law
Where an amendment to this DPA is necessary to comply with a new legal obligation, court ruling, decision of a supervisory authority or regulatory requirement, Bike Booking Engine may make the changes necessary to maintain the compliance of the Services.
The Parties shall reasonably cooperate where necessary to adapt the contractual relationship to new legal obligations applicable to the processing.
130. Severability
If any provision of this DPA is held to be invalid, illegal or unenforceable, such circumstance shall not affect the validity of the remaining provisions.
Where possible, the affected provision shall be interpreted or replaced in a manner that preserves its original purpose to the greatest extent permitted by applicable law.
131. No Waiver
Failure or delay in exercising any right arising under this DPA shall not constitute a waiver of such right.
The partial exercise of any right shall not prevent its subsequent exercise or the exercise of any other rights available under this DPA or applicable law.
132. Survival of Obligations
Obligations which by their nature are intended to continue after termination of the Services shall remain in force for the applicable period.
This shall include, where applicable, obligations relating to:
- Confidentiality;
- Security;
- Retention and deletion;
- Cooperation regarding incidents occurring during the term of the Services;
- Liability; and
- Any other obligation that must continue by its nature or as required by law.
133. Governing Law
This DPA shall be governed by the law applicable to the main contractual agreement, without prejudice to the mandatory application of Regulation (EU) 2016/679 (GDPR) and any other applicable data protection legislation.
Where the Customer is subject to additional data protection legislation, the Parties shall comply with the obligations respectively applicable to them within the scope of the Services.
134. Jurisdiction
Contractual matters relating to this DPA shall be subject to the jurisdiction established in the main contractual agreement, unless mandatory law provides otherwise.
The foregoing shall be without prejudice to the powers granted to data protection supervisory authorities and competent courts under applicable law.
135. Entire DPA
This DPA, together with its Annexes and any contractual provisions expressly incorporated by reference, constitutes the agreement between the Parties regarding the processing of Personal Data carried out by Bike Booking Engine on behalf of the Customer.
The Annexes form an integral part of this DPA and shall have the same contractual force as the remainder of its provisions.
This Annex describes the main characteristics of the processing of Personal Data carried out by Bike Booking Engine on behalf of the Customer in connection with the provision of the Services.
1. Subject Matter of the Processing
Bike Booking Engine shall process Personal Data on behalf of the Customer for the purpose of providing, maintaining, protecting and supporting the Platform and the functionalities contracted or enabled by the Customer.
Processing shall be limited to the operations necessary to provide the Services and carry out the Customer's documented instructions.
2. Duration of the Processing
Processing shall take place for the duration of the contractual relationship between Bike Booking Engine and the Customer.
Following termination of the Services, the data shall be subject to the retention and deletion periods established in this DPA and the Backup & Retention Policy.
As a general rule, Customer Data may be retained for 90 days following termination of the Service, without prejudice to specific periods applicable to certain categories of information and legally permitted exceptions.
3. Nature of the Processing Operations
Depending on the functionalities used by the Customer, the operations carried out by Bike Booking Engine may include:
- Collection;
- Receipt;
- Recording;
- Organization;
- Structuring;
- Storage;
- Consultation;
- Retrieval;
- Modification;
- Use;
- Transmission;
- Making available;
- Export;
- Restriction;
- Retention;
- Backup;
- Recovery;
- Anonymization; and
- Deletion.
4. Purposes of the Processing
Processing may be carried out to enable the Customer to use the functionalities of the Platform, including, where applicable:
- Customer management;
- Booking management;
- Rental management;
- Product and equipment management;
- Delivery and collection management;
- Workshop and repair management;
- User and employee management;
- Communications related to the Services;
- Online check-in;
- Document signing;
- Payment management and associated information;
- Technical support;
- Security and auditing;
- Integrations enabled by the Customer; and
- Other functionalities available within the contracted Services.
5. Categories of Data Subjects
Personal Data processed may relate, among others, to:
- The Customer's end customers;
- Individuals making bookings;
- Users or beneficiaries included in a booking;
- Individuals using rented goods or services;
- Customers of workshops or repair services;
- Business contacts;
- The Customer's employees;
- The Customer's collaborators and contractors;
- Authorized Users;
- Suppliers or contacts entered by the Customer; and
- Other individuals whose data is lawfully managed by the Customer through the Platform.
6. Categories of Personal Data
Depending on the functionalities used, the following categories of Personal Data may be processed:
Identification Data:
- First name;
- Last name;
- Internal identifiers;
- Nationality; and
- Other identification data necessary for the provision of the service.
Contact Data:
- Email address;
- Telephone number;
- Postal address; and
- Other contact information provided.
Booking and Service-Related Data:
- Dates and times;
- Products or services booked;
- Rental information;
- Deliveries and collections;
- Accessories;
- Incidents;
- Repairs;
- Comments;
- Preferences; and
- Other information necessary to manage the relevant operation.
Payment-Related Data:
- Payment status information;
- Amounts;
- Transactions;
- Refunds; and
- References provided by payment service providers.
Bike Booking Engine does not need to store full payment card details where such details are processed directly by the relevant payment service provider.
Technical and Usage Data:
- Access information;
- Activity logs;
- Relevant actions performed within the Platform;
- Technical information;
- Error logs; and
- Other data necessary for the security, auditing and operation of the Services.
Identification Documentation:
Where the Customer enables the relevant functionality, copies of identity documents, passports or other accepted identification documents uploaded during the online check-in process may be processed.
Such documentation shall be subject to the specific regime established in this DPA and shall be automatically deleted from active systems within 72 hours following the completion of the booking, unless a legitimate exception applies.
7. Special Categories of Personal Data
As a general rule, the Platform is not designed for the systematic processing of special categories of Personal Data.
The Customer shall avoid entering such categories of data unless a functionality expressly permits such processing and an appropriate legal basis exists.
This Annex describes the main processing activities that may be carried out through Bike Booking Engine.
The specific availability of each activity shall depend on the functionalities contracted, enabled or used by the Customer.
1. Customer Management
The Platform may allow the recording and management of information relating to end customers for the purpose of managing the Customer's commercial and operational relationship with such individuals.
2. Booking and Rental Management
Bike Booking Engine may process information necessary to:
- Create bookings;
- Modify bookings;
- Manage availability;
- Assign products or equipment;
- Manage rental periods;
- Manage accessories and additional services;
- Manage deliveries and returns;
- Record incidents; and
- Maintain the relevant operational history.
3. Online Bookings
Where the Customer uses online booking functionalities, Bike Booking Engine may collect and process, on behalf of the Customer, the data entered by the end user that is necessary to process and manage the booking.
4. Online Check-In
The Platform may allow the Customer to request certain information before the start of a booking for the purpose of streamlining verification, preparation and delivery processes.
The Customer shall determine which check-in functionalities to enable from among the available options.
5. Identification Documentation
Where enabled by the Customer, the end user may upload a copy of their identity document, passport or other accepted identification document.
Bike Booking Engine shall store such documentation on behalf of the Customer only for the period established in this DPA.
As a general rule, the documentation shall be automatically deleted from active systems within 72 hours following the completion of the booking, unless an incident, claim, proceeding or other legitimate circumstance justifies additional retention in accordance with the DPA.
6. Signatures and Documentation
The Platform may allow the signing or acceptance of:
- Contracts;
- Terms and conditions;
- Policies;
- Booking-related documents;
- Delivery documents;
- Return documents; and
- Other operational documentation.
Bike Booking Engine may store information necessary to evidence such actions in accordance with the functionalities used and the applicable retention periods.
7. Deliveries and Collections
Where the Customer uses delivery functionalities, data necessary to organize deliveries or collections may be processed, including contact information, location or delivery address and data associated with the booking.
8. Workshop and Repairs
Where the Customer uses workshop functionalities, Bike Booking Engine may process data relating to:
- Customers;
- Repair orders;
- Goods or products being repaired;
- Services performed;
- Incidents;
- Communications;
- Quotations;
- Documentation; and
- Other information necessary to manage the service.
9. Communications
The Platform may use contact information to enable communications relating to operations managed through the Services.
This may include, depending on the functionalities used:
- Confirmations;
- Booking information;
- Check-in communications;
- Modifications;
- Reminders;
- Operational communications;
- Service completion communications; and
- Review or satisfaction requests.
The Customer shall be responsible for determining the appropriate legal basis for the communications it configures or carries out.
10. Payments
Where integrated payment functionalities are used, Bike Booking Engine may transmit or receive information necessary to facilitate the transaction with the relevant payment service provider.
Full payment card details may be collected and processed directly by such provider without Bike Booking Engine needing to store them within its systems.
The roles and responsibilities of each party shall depend on the specific nature of the payment service used.
11. Users, Employees and Permissions
Bike Booking Engine may process information relating to Authorized Users, employees or collaborators of the Customer in order to:
- Create and manage accounts;
- Authenticate users;
- Assign roles and permissions;
- Record certain actions;
- Protect the security of the Platform; and
- Provide the relevant functionalities.
12. Support and Maintenance
Where the Customer requests assistance, Bike Booking Engine may access information reasonably necessary to:
- Investigate the request;
- Reproduce issues;
- Resolve incidents;
- Provide support; and
- Maintain the proper operation of the Platform.
Access shall be restricted to authorized personnel in accordance with the measures established in the DPA.
13. Security, Logging and Auditing
Bike Booking Engine may generate and retain technical and audit logs in order to:
- Protect the Platform;
- Detect anomalous activity;
- Investigate incidents;
- Provide traceability;
- Prevent fraud or abuse; and
- Maintain the security and stability of the Services.
14. Backups and Recovery
Data may be included in backups performed to ensure the continuity, integrity and recovery of the Services.
Backups shall be subject to the retention periods and procedures established in the DPA and the Backup & Retention Policy.
15. Integrations
Where the Customer enables integrations with external systems or services, Bike Booking Engine may transmit or receive the data necessary to operate such integration in accordance with the Customer's instructions.
1. Applicable Measures
Bike Booking Engine implements technical and organizational measures designed to provide a level of security appropriate to the risks associated with the processing of Personal Data.
The applicable measures are primarily described in Chapter VIII – Technical and Organizational Measures of this DPA and are supplemented by Bike Booking Engine's Security Policy.
These measures include, among others:
- Professional cloud infrastructure;
- HTTPS and TLS;
- Password hashing;
- Protection against repeated authentication attempts;
- Multi-factor authentication for administrative access;
- Role-based access controls;
- The principle of least privilege;
- Logical separation of Customer Data;
- Session management;
- Separation between development and production environments;
- A pre-production environment;
- Version control;
- Code review;
- Functional testing;
- Dependency and vulnerability management;
- Infrastructure and application monitoring;
- Error logging;
- Access logging;
- Logging of critical actions;
- Backups;
- Periodic restoration testing;
- Incident management procedures;
- Confidentiality obligations; and
- Access revocation procedures.
2. Evolution of the Measures
Bike Booking Engine may modify the technologies, tools, providers or procedures used to implement these measures.
Such changes shall not require an amendment to this Annex, provided that an appropriate level of protection is maintained taking into account the risks of the processing.
3. Additional Information
Where reasonably necessary to assess compliance with the obligations applicable to the Data Processor, Bike Booking Engine may provide additional information regarding its technical and organizational measures in accordance with the provisions of this DPA.
The information provided may be restricted where its disclosure could compromise the security of the Platform, reveal confidential information or affect other Customers.
1. General Authorization
In accordance with Chapter III of this DPA, the Customer grants Bike Booking Engine general authorization to engage Sub-processors where necessary for the provision of the Services.
2. Categories of Services
Bike Booking Engine may engage Sub-processors to provide, among other things:
- Cloud infrastructure;
- Hosting;
- Storage;
- Databases;
- Backups;
- Content delivery;
- Email and communications;
- Monitoring;
- Security;
- Payment processing, where the provider acts in such capacity;
- Artificial intelligence services, where used and where the provider acts as a Sub-processor;
- Technical support; and
- Other technology services necessary to provide the Services.
3. Updated List of Sub-processors
Bike Booking Engine shall maintain an up-to-date list of Sub-processors that process Personal Data on behalf of Customers.
Such list may be made available through:
- Bike Booking Engine's legal documentation;
- The Platform;
- The website;
- The help center; or
- Upon request by the Customer.
The list may include, where applicable:
- The identity of the Sub-processor;
- The service provided;
- The general nature of the processing; and
- The relevant country or region from which the processing is carried out.
4. Addition and Replacement
Bike Booking Engine may appoint new Sub-processors or replace existing Sub-processors in accordance with the general authorization framework established in the DPA.
Where required, Bike Booking Engine shall provide information regarding the appointment or replacement with reasonable prior notice to allow the Customer to exercise the right to object provided for in Chapter III.
5. Contractual Obligations
Bike Booking Engine shall impose appropriate data protection obligations on Sub-processors that process Personal Data on behalf of the Customer, taking into account the nature of the services provided.
Bike Booking Engine shall remain responsible to the Customer for the performance of its Sub-processors' obligations to the extent required by applicable law.
6. International Transfers
Where the use of a Sub-processor involves an international transfer of Personal Data, the safeguards and mechanisms established in Chapter IV – International Data Transfers shall apply.
7. Providers Not Acting as Sub-processors
The inclusion of a technology or provider within the Bike Booking Engine ecosystem does not necessarily mean that such provider acts as a Sub-processor.
Providers acting as independent Data Controllers or having another legal role in relation to particular processing operations shall be subject to the appropriate regime according to the actual nature of the processing.