Skip to main content
Odybook.

Data Processing Agreement

Version dated September 7, 2026

Subject, duration, purpose and roles

This DPA applies when SYNSETIO processes personal data for a professional Client in Odybook. The Client is controller for its bookings and traveller relationships; SYNSETIO is processor on documented instructions.

Duration: the Odybook contract and required exit, return, deletion, backup and legal archive operations. Purpose: provide, secure, maintain and support the service. Nature: hosting, storage, display, search, sending, synchronization, payment, support, security, export and maintenance.

Data subjects and data categories

  • Data subjects: Client users, travellers, participants, contacts, voucher beneficiaries, representatives and support contacts.
  • Data: identity, contact details, organization, role, booking, payment reference, messages, shared preferences, technical logs, settings and content uploaded by the Client.
  • Sensitive data: it must be processed only if the Client has a valid basis, gives suitable instructions and applicable supplier contracts allow it.

Instructions, confidentiality and security

SYNSETIO processes data only on documented Client instructions, including for transfers, unless contrary law requires otherwise. SYNSETIO informs the Client if an instruction appears clearly unlawful.

People authorized by SYNSETIO are bound by confidentiality. SYNSETIO maintains suitable measures: encryption in transit, access control, logical separation by organization, backups, useful logging, abuse monitoring and support procedures.

Subprocessors

The Client authorizes subprocessors listed on the Odybook Subprocessors page. SYNSETIO contractually imposes the same obligations on them as this DPA, to the extent applicable to the entrusted services.

SYNSETIO remains liable to the Client for performance of its subprocessors' data-protection obligations. SYNSETIO gives at least 30 days' notice of changes where possible; the Client has 15 days to make a reasoned objection. The parties then seek a reasonable remedy, which may include alternative configuration or termination of the affected service.

Assistance, breaches and audits

SYNSETIO reasonably assists the Client with rights requests, impact assessments, prior consultations, security of processing and duties under GDPR articles 33 to 36.

SYNSETIO informs the Client without undue delay after becoming aware of a breach concerning data processed for it. SYNSETIO provides available information useful for assessment, notification and remediation.

The Client may audit DPA compliance through questionnaire, documentation, relevant reports or supervised inspection with reasonable notice. Inspections must preserve security, secrets, other clients' data and service continuity.

International transfers

SYNSETIO transfers data outside the EEA on Client instruction or to provide the service only where a valid mechanism exists: adequacy decision, standard contractual clauses, available supplementary measures or another lawful basis.

Actual regions and safeguards depend on active suppliers and settings. The Client may request information needed for its assessment.

End of service and Data Act

At the Client's choice, SYNSETIO returns or deletes data processed for it at service end, except where law requires retention. Backups follow their protected technical cycle until expiry.

Where Data Act chapter VI applies, the parties cooperate on switching and portability with authority checks, available formats, secret protection, security, continuity and third-party limits.