This Data Processing Agreement ("DPA") is entered into between the business that holds an account on the Tosiu platform (the "Operator" or "Controller") and I/E TOSIU, Individual Entrepreneur registered in Georgia (identification number 304829112), Nikoloz Baratashvili street N12 / Sanapiro street N2, Tbilisi 0105, Georgia ("Tosiu" or "Processor"). It forms part of the Terms of Service and applies automatically to every Operator from the moment the Terms are accepted; no separate signature is needed. A countersigned PDF copy can be requested at contact@tosiu.com. Terms defined in the Terms of Service have the same meaning here. Capitalised data-protection terms have the meaning given in Regulation (EU) 2016/679 ("GDPR").
1. Roles and scope
- The Operator is the Controller of the personal data of its Customers, of the visitors of its Site, of its drivers, staff and partner companies, and of any other natural person whose data it enters into or collects through the Platform ("Operator Data").
- Tosiu is the Processor of Operator Data. Tosiu processes it only on the documented instructions of the Operator, which are: the Terms of Service, this DPA, and the configuration the Operator applies in the Platform (features switched on, integrations connected, webhooks and endpoints chosen, users invited).
- For data about the Operator itself (account, billing, support) Tosiu is an independent Controller; that processing is described in the Privacy Policy, not here.
- Where two Operators exchange a Booking through the Marketplace, each is an independent Controller for its own purposes and Tosiu is the Processor of each.
2. Details of the processing (Annex I)
- Subject matter: the provision of the Platform: booking website, booking engine, quotes, back office, customer and driver Portal, emails and documents, integrations, API.
- Duration: the term of the Operator's account, plus the deletion and backup periods in section 9.
- Nature and purpose: hosting, storage, display, transmission, generation of documents and emails, automated notifications, statistics for the Operator, technical support, backup and restore, and the AI features the Operator uses (translation, drafting of texts and quotes, automatic replies).
- Categories of data subjects: Customers and passengers (including people travelling under a Booking made by someone else), visitors of the Site, people who send a contact or quote request, drivers, staff, partner companies and their contacts, Portal users.
- Categories of personal data: identification and contact data (name, e-mail, phone), Booking data (pickup and drop-off addresses, dates and times, passengers, luggage, flight, train or ship numbers, pickup sign, notes), payment status and references (never card numbers), quote and message texts, documents the Operator uploads for drivers or partners (licences, insurance, vehicle papers), account credentials (hashed), technical data (IP address, browser, device, language, pages visited, consent choices), communication logs.
- Special categories: none are required by the Platform. Free-text fields (notes, assistance requests, messages) may incidentally contain health or mobility information entered by the data subject; the Operator instructs Tosiu to store such text as entered and to do nothing else with it.
- Frequency: continuous, for as long as the Platform is used.
3. Tosiu's obligations as Processor
- Instructions. Tosiu processes Operator Data only on the instructions in section 1, including for transfers to third countries, unless required to do otherwise by law applicable to Tosiu; in that case Tosiu informs the Operator before processing, unless the law prohibits it. Tosiu informs the Operator without delay if, in its opinion, an instruction infringes the GDPR.
- Confidentiality. Only the persons who need access to run and support the Platform have it, and they are bound by confidentiality. Today Tosiu is a sole-trader business; the owner is the only person with administrative access.
- Security. Tosiu implements the technical and organisational measures in section 10 (Annex II) and keeps them under review.
- Sub-processors. See section 5.
- Assistance with data-subject rights. The Platform gives the Operator the tools to answer access, rectification, erasure and portability requests itself (booking and customer views, exports, the Backup and Wipe tool, Portal account management). Where a request needs Tosiu's help, Tosiu assists within 10 working days at no charge for ordinary requests. Requests sent to Tosiu directly by a data subject of the Operator are forwarded to the Operator without answering on the merits.
- Assistance with Articles 32 to 36. Tosiu provides the information reasonably needed for the Operator's security assessments, data-protection impact assessments and consultations with a supervisory authority, taking into account the nature of the processing and the information available to Tosiu.
- Personal data breach. Tosiu notifies the Operator by e-mail without undue delay, and in any case within 48 hours, after becoming aware of a breach affecting Operator Data, with the information available at that time (nature, categories and approximate number of data subjects and records, likely consequences, measures taken), and completes it as more becomes known.
- Deletion and return. Section 9.
- Audits. Tosiu makes available the information necessary to demonstrate compliance with Article 28 GDPR: this DPA, the security measures, the sub-processor list, and answers to a reasonable written questionnaire once per year. An audit or inspection by the Operator or an independent auditor bound by confidentiality may take place once per year, on 30 days' written notice, during business hours, without disrupting the service, at the Operator's cost, and limited to the systems that process Operator Data.
- Records. Tosiu keeps the record of processing activities required by Article 30(2) GDPR.
4. Operator's obligations as Controller
- The Operator warrants that it has a lawful basis for every processing it configures, that it gives its data subjects the information required by Articles 13 and 14 GDPR (privacy notice on its Site, cookie information and consent where required, consent texts on its forms), and that its instructions comply with the law.
- The Operator decides which third-party tags, integrations and providers to connect (advertising tags, payment processors, electronic-invoicing provider, management software, SMS provider, storage destinations, webhook endpoints). Those providers are recipients chosen by the Operator, not sub-processors of Tosiu, and the Operator contracts with them directly.
- The Operator uses the Marketplace, the Portal and the API in a way that keeps Customer data limited to what the recipient needs for the trip or task.
- The Operator removes access of users (drivers, staff, partners, Portal accounts) who should no longer have it.
5. Sub-processors (Annex III)
The Operator gives a general written authorisation for the sub-processors below. Tosiu informs Operators of any intended addition or replacement at least 30 days before it takes effect, by e-mail to the account address or by a notice in the Platform, and updates this page. An Operator may object on reasonable data-protection grounds within that period; if no solution is found, the Operator may close its account under section 23 of the Terms. Tosiu imposes on each sub-processor data-protection obligations equivalent to this DPA and remains fully liable to the Operator for the sub-processor's performance.
| Sub-processor | Function | Location of processing | Transfer safeguard |
|---|---|---|---|
| Namecheap, Inc. | Hosting of the Platform (the server that runs the Platform and its database, all Operator Data) | United States | Namecheap Data Processing Addendum with the EU Standard Contractual Clauses |
| BunnyWay d.o.o. (bunny.net) | Content delivery network and storage of media files (photos, logos, documents, videos), encrypted backups | Slovenia (EU); edge servers worldwide serve public files only | EU company |
| Amazon Web Services EMEA SARL | Encrypted backup storage | Germany (eu-central-1) | EU processing; AWS DPA with SCCs for support access |
| SMTP2GO Ltd | E-mail delivery relay for every transactional e-mail (confirmations, notifications, Portal messages) | New Zealand (company), servers in the EU and the United States | EU adequacy decision for New Zealand; SMTP2GO DPA with SCCs |
| Anthropic, PBC | AI text generation and translation (site texts, replies, quote drafts) for the AI features the Operator uses | United States | EU-US Data Privacy Framework; Anthropic commercial terms (no training on API data) |
| OpenRouter, Inc. | Routing of some AI requests (translation of contact requests, quote drafts, planning and market texts) to model providers such as Anthropic and Google | United States | EU Standard Contractual Clauses (OpenRouter DPA) |
| Google Ireland Ltd / Google LLC | Google Maps Platform (addresses typed by Customers and Operators are geocoded and routed), sign-in with Google for Operators, Google Ads API for the Ads tools (aggregate campaign data) | EU / United States | EU-US Data Privacy Framework; Google Cloud data-processing terms with SCCs |
| Cloudflare, Inc. | Turnstile bot protection on booking, contact, Portal and login forms (IP address and browser signals) | United States / global edge | EU-US Data Privacy Framework; Cloudflare DPA with SCCs |
| Telegram FZ-LLC | Internal operational alerts to Tosiu (new booking, contact request, partner application, support ticket) limited to the booking reference, the Site, the route, the amount and the Customer's first name; no e-mail address, phone number, notes or documents | United Arab Emirates (data centres in the EU for European users) | Data minimised to non-sensitive operational data; no contract available from the provider |
| API.market (AeroDataBox) | Flight status lookup | United States | No personal data: only the flight number and date are sent |
| MaxMind, Inc. | GeoLite2 country database | Not applicable: the database runs on Tosiu's server, no data is sent to MaxMind | Not a transfer |
Not sub-processors (recipients chosen and contracted by the Operator): payment processors (Stripe, PayPal, SumUp, Nexi, Revolut, myPOS, Satispay, Mollie, Axerve, Zettle), the electronic-invoicing provider (for example Aruba), management software (for example NCCGEST), SMS providers (Skebby, Twilio), backup destinations (the Operator's own Bunny, pCloud or MEGA account), advertising and analytics tags the Operator enters (Google Analytics, Google Ads, Meta Pixel, Hotjar, Tawk.to, LiveChat), webhook endpoints, and other Operators in the Marketplace.
6. International transfers
- Tosiu is established in Georgia and hosts the Platform in the United States. Neither country benefits from an adequacy decision of the European Commission. The Operator's transfer of Operator Data to Tosiu is therefore made under the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), which are incorporated in this DPA by reference and prevail over it in case of conflict ("SCCs").
- The SCCs are completed as follows: Clause 7 (docking): not used. Clause 9: Option 2, general written authorisation, 30 days' notice (section 5). Clause 11: the optional independent dispute resolution body is not used. Clause 13: the supervisory authority of the EU member state where the Operator is established. Clause 17: Option 1, the law of Italy. Clause 18: the courts of Italy. Annex I = sections 1 and 2 of this DPA and the parties' details in the Terms and the Operator's account; Annex II = section 10; Annex III = section 5.
- For Operators established in the United Kingdom, the UK International Data Transfer Addendum to the SCCs (version B1.0) applies in the same way, with the Information Commissioner as supervisory authority and the law and courts of England and Wales for the Addendum.
- For Operators established in Switzerland, the SCCs apply with the adaptations required by the Federal Data Protection and Information Commissioner.
- Onward transfers from Tosiu to the sub-processors in section 5 rely on the safeguards listed there. Tosiu has assessed that, given the nature of the data (booking and contact data of passengers, no special categories by design), the encryption in transit and at rest, and the absence of any request from a public authority to date, the SCCs provide an adequate level of protection; Tosiu will inform the Operator if it becomes unable to comply with them.
7. Tosiu's own operational processing
To run the Platform, Tosiu processes limited Operator Data for its own monitoring, always as part of the service and never for marketing or profiling: internal alerts for new Bookings, requests and tickets (section 5, Telegram, minimised); a copy of transactional e-mails kept in an internal mailbox to verify delivery and to help with support, deleted on a rolling schedule; server and application logs kept for security and debugging (365 days at most); aggregated, non-identifying statistics about the Platform as a whole. The Operator instructs Tosiu to carry out this processing.
8. Liability
Each party is liable towards the other as set out in the Terms of Service (section 21). Nothing in this DPA limits the rights of data subjects under the SCCs or the liability of either party towards data subjects and supervisory authorities under Article 82 GDPR.
9. Deletion and return of data
- During the term, the Operator deletes Operator Data itself through the Platform (bookings, customers, documents, Portal accounts, the Backup and Wipe tool).
- On closure of the account, Tosiu returns the Operator Data as described in section 23 of the Terms (a copy by e-mail within 48 hours of the request, in machine-readable formats) and then deletes or anonymises it, except for data Tosiu must keep under a legal obligation (for example invoicing records about the Operator, which contain no Customer data).
- Deleted data may persist in encrypted backups for up to 365 days, after which the backups age out. Backups are not restored except to recover from an incident, in which case the deletion is applied again.
- Tosiu confirms deletion in writing on request.
10. Technical and organisational measures (Annex II)
- Encryption: TLS 1.2 or higher on every connection; passwords stored as one-way hashes; payment-processor credentials and API secrets encrypted at rest; backups encrypted before leaving the server.
- Access control: one administrator (the owner); role-based access for Operators and their users (staff, drivers, partners, Portal accounts) enforced server-side and scoped per Site; session cookies Secure, HttpOnly, SameSite; login throttling and lockout; bot protection (Cloudflare Turnstile, honeypots, rate limits) on public forms; a permanent list of the owner's own network addresses excluded from Operator analytics.
- Data separation: every record is scoped to a Site and an account; cross-tenant access is refused at the query level; the Marketplace exposes passenger identity to the accepting Operator only after assignment.
- Minimisation: first-party analytics store a truncated IP address and no user-agent string; internal alerts carry no contact details; logs are pruned automatically (visitor logs 365 days, sessions 90 days, tokens 30 days after expiry).
- Availability and backup: full encrypted database backups every 4 hours to two independent providers (Bunny, AWS Frankfurt) with up to 365 days of retention; restore procedure tested; monitoring of the server, of e-mail delivery and of the booking funnel with alerts.
- Secure development: parameterised queries throughout, CSRF tokens on every state-changing request, output escaping, input validation, security headers (HSTS, frame denial, content sniffing protection), an automated test harness run before changes, change logs on booking data.
- Incident management: error and security logs reviewed daily; breach notification process in section 3; sub-processors' breach notifications flow to the same process.
- Organisation: written internal rules for testing (never on client data), for destructive operations (dump first, scoped queries) and for retention; the owner is the only person with access to production credentials; contractors, if any, sign confidentiality terms before any access.
11. Term, precedence, and changes
- This DPA lasts as long as Tosiu processes Operator Data. Sections 3 (deletion, confidentiality), 6, 8 and 9 survive.
- In case of conflict: the SCCs prevail over this DPA; this DPA prevails over the Terms of Service for the processing of Operator Data.
- Tosiu may update this DPA to reflect changes in the law, in the Platform, or in the sub-processor list, under section 27 of the Terms; the sub-processor notice rule in section 5 applies in any case.
12. Contact
Data-protection matters: contact@tosiu.com, subject "DPA".
I/E TOSIU, Nikoloz Baratashvili street N12 / Sanapiro street N2, Tbilisi 0105, Georgia (ID: 304829112).