AIRSHIP SERVICES LIMITED — DATA PROCESSING AGREEMENT — SCHEDULE 2 TO THE AIRSHIP & TOGGLE STANDARD TERMS AND CONDITIONS
This Data Processing Agreement ("DPA") forms Schedule 2 to the Agreement between Airship Services Limited ("Airship") and the Client identified in the Order Form (Schedule 1). It sets out the terms on which Airship processes Personal Data on behalf of the Client in connection with the provision of the Services. In the event of any conflict between this DPA and the main body of the Agreement, this DPA shall prevail in respect of data protection matters.
1. DEFINITIONS
In this DPA, the following terms have the meanings set out below. Capitalised terms not defined here have the meaning given in the Agreement.
| Appropriate Safeguards | Legally enforceable mechanisms for international transfers of Personal Data permitted under Data Protection Legislation from time to time (including UK Standard Contractual Clauses or adequacy decisions). |
| Controller | Has the meaning given in Data Protection Legislation. |
| Data Protection Legislation | All applicable data protection and privacy legislation in force in the UK from time to time, including: (a) the UK GDPR; (b) the Data Protection Act 2018; (c) the Privacy and Electronic Communications Regulations 2003 (as amended); and (d) any laws implementing or supplementing the foregoing. |
| Data Protection Losses | All liabilities including costs (including legal costs), claims, demands, actions, settlements, charges, fines, penalties and sanctions imposed by a Supervisory Authority, and compensation ordered to be paid to a Data Subject. |
| Data Subject | Has the meaning given in Data Protection Legislation. |
| Data Subject Request | A request made by a Data Subject to exercise any right under Data Protection Legislation. |
| Personal Data | Personal data (as defined in Data Protection Legislation) included in the Client's data and processed by Airship in connection with the Services. |
| Personal Data Breach | Any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data. |
| Processing / Process / Processed | Has the meaning given in Data Protection Legislation. |
| Processor | Has the meaning given in Data Protection Legislation. |
| Sub-Processor | Any third-party Processor engaged by Airship to process Personal Data on the Client's behalf. |
| Supervisory Authority | The Information Commissioner's Office (ICO) or any other relevant regulatory body responsible for administering Data Protection Legislation. |
| UK GDPR | Regulation (EU) 2016/679 as it forms part of UK domestic law by virtue of the European Union (Withdrawal) Act 2018, as amended. |
2. PROCESSOR AND CONTROLLER
2.1 The parties agree that, for the purposes of this DPA and Data Protection Legislation, the Client is the Controller and Airship is the Processor in respect of Personal Data processed in connection with the Services.
2.2 Nothing in this DPA relieves the Client of its own obligations or liabilities as Controller under Data Protection Legislation.
2.3 Airship shall process Personal Data only in accordance with this DPA and the Agreement and shall comply with Data Protection Legislation in its capacity as Processor.
2.4 The Client warrants, represents and undertakes that at all times: (a) it shall comply with Data Protection Legislation in its collection, storage and processing of Personal Data; (b) it has provided all necessary fair processing notices and, where required, obtained all necessary consents from Data Subjects in connection with the processing activities Airship performs on its behalf; and (c) all instructions it gives to Airship in respect of Personal Data shall at all times be in accordance with Data Protection Legislation.
3. PROCESSING INSTRUCTIONS
3.1 Airship shall (and shall take steps to ensure each person acting under its authority shall) process Personal Data only on and in accordance with the Client's documented instructions, which shall consist of: (a) the Agreement and this DPA; and (b) any further instructions the Client provides in writing from time to time that are consistent with the Agreement.
3.2 If Airship is required by applicable law to process Personal Data other than in accordance with the Client's instructions, Airship shall notify the Client before carrying out such processing (unless prohibited by law on grounds of public interest).
3.3 Airship shall promptly inform the Client if, in its reasonable opinion, an instruction infringes Data Protection Legislation, without obligation to take any action on that instruction until the Client has confirmed or amended it.
3.4 The Client acknowledges that any command to process (including deletion of) Personal Data executed through the Services by an Authorised User constitutes a processing instruction from the Client. The Client is responsible for ensuring Authorised Users are authorised to issue such instructions.
4. SECURITY AND TECHNICAL & ORGANISATIONAL MEASURES
4.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Airship shall implement and maintain appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful processing and accidental loss, destruction or damage.
4.2 Such measures include, at minimum:
4.3 Airship may update or amend its technical and organisational measures from time to time, provided that any such amendments do not result in a material reduction in the level of protection afforded to Personal Data.
4.4 Further details of Airship's security measures are available on written request, subject to confidentiality obligations.
5. SUB-PROCESSORS
5.1 The Client hereby grants Airship a general authorisation to appoint Sub-Processors, subject to the requirements of this clause 5.
5.2 Airship shall maintain an up-to-date list of its Sub-Processors, accessible at its legal documentation pages (or available on written request). Airship shall provide the Client with at least 14 days' prior written notice of any intended addition or replacement of a Sub-Processor.
5.3 The Client may object in writing to any proposed new or replacement Sub-Processor within 14 days of receiving notice. Where the Client objects and Airship is unable to accommodate the objection, either party may terminate the Agreement on written notice, without prejudice to any accrued rights or obligations.
5.4 Airship shall ensure that each Sub-Processor is appointed under a written contract that imposes materially equivalent data protection obligations as those set out in this DPA, and Airship shall remain fully liable to the Client for the acts and omissions of its Sub-Processors as if they were its own.
5.5 Airship's current principal Sub-Processors are listed in Annex 2 to this DPA. Airship will update Annex 2 to reflect any additions or changes made in accordance with this clause 5.
5.6 Airship shall ensure that all persons authorised by it (or by any Sub-Processor) to process Personal Data are subject to written confidentiality obligations.
6. ASSISTANCE WITH DATA SUBJECT RIGHTS AND COMPLIANCE
6.1 Airship shall refer any Data Subject Request it receives directly to the Client without undue delay and shall not respond to a Data Subject Request on the Client's behalf without the Client's prior written authorisation.
6.2 Taking into account the nature of processing and the information available to Airship, Airship shall provide such reasonable technical and organisational assistance as the Client requires to fulfil its obligations under Data Protection Legislation with respect to:
6.3 Airship may charge the Client at its standard time and materials rates for assistance provided under clause 6.2 that goes beyond what is reasonably incidental to Airship's obligations as Processor.
7. INTERNATIONAL DATA TRANSFERS
7.1 Airship shall not transfer Personal Data outside the UK or European Economic Area (EEA) unless:
7.2 Where Airship relies on an approved framework or standard contractual clauses for an international transfer, it shall ensure such mechanisms are and remain valid and enforceable.
7.3 Airship's current international transfers and the applicable safeguards are set out in Annex 2.
8. RECORDS, INFORMATION AND AUDIT
8.1 Airship shall maintain written records of all categories of processing activities carried out on behalf of the Client, in accordance with Article 30 of the UK GDPR.
8.2 Airship shall, on reasonable written request, make available to the Client such information as is reasonably necessary to demonstrate Airship’s compliance with this DPA and Article 28 of the UK GDPR. This may include: Aikido vulnerability scan reports; CrowdStrike Falcon deployment confirmation; penetration test summary reports; PCI DSS Attestation of Compliance (for the Toggle platform); annual security risk assessment summaries; and details of Airship’s sub-processors, a current list of which is publicly available at academy.airship.co.uk.
8.3 Where the Client reasonably requires further assurance beyond the documentation provided under clause 8.2, it may submit a written request for additional information. Airship shall respond by providing, at its discretion, one or more of the following: penetration test summary reports; internal security policy summaries; or other relevant compliance documentation. The Client agrees to review such materials in good faith and in full before making any further request.
8.4 Only where the documentation provided under clauses 8.2 and 8.3 is demonstrably insufficient to satisfy the Client’s obligations under Data Protection Legislation, and subject to Airship’s prior written consent (not to be unreasonably withheld), may the Client request a further audit by an independent third-party auditor. Any such audit shall be subject to all of the following conditions:
9. PERSONAL DATA BREACH NOTIFICATION
9.1 Airship shall notify the Client without undue delay upon becoming aware of a Personal Data Breach involving Personal Data processed under this DPA. Such notification shall, to the extent known at the time, include:
9.2 Where full details are not available at the time of initial notification, Airship may provide information in phases, without undue delay.
9.3 Airship shall cooperate with the Client and take such reasonable steps as the Client may direct to assist with the investigation, mitigation and remediation of any Personal Data Breach.
9.4 Airship shall not make any public communication or disclosure in relation to a Personal Data Breach involving the Client's Personal Data without the Client's prior written consent, unless required to do so by law.
10. DELETION AND RETURN OF PERSONAL DATA
10.1 On termination or expiry of the Agreement for any reason, Airship shall, at the Client's election and subject to clause 13.3.3 of the Airship Standard Terms:
10.2 The Client must make any election under clause 10.1 in writing within 15 days of the termination or expiry date. Airship shall use reasonable commercial efforts to complete the return or deletion within 30 days of receiving the Client's written request, subject to the Client having paid all outstanding charges.
10.3 Airship may retain Personal Data to the extent required by applicable law, for the minimum period required and subject to the protections of this DPA.
10.4 On completion of deletion, Airship shall, on written request, provide the Client with written confirmation that deletion has been carried out.
11. LIABILITY
11.1 Airship's liability under this DPA is subject to the limitations and exclusions of liability set out in clause 12 of the Airship Standard Terms. Nothing in this DPA increases Airship's total aggregate liability beyond those limits.
11.2 Airship shall be liable for Data Protection Losses only to the extent such losses are caused by Airship's direct breach of this DPA.
11.3 If either party receives a compensation claim from a Data Subject or third party in connection with the processing of Personal Data under the Agreement, it shall promptly notify the other party in writing. Neither party shall make any admission of liability or agree any settlement in respect of such a claim without the prior written consent of the other party (not to be unreasonably withheld or delayed).
12. SURVIVAL
This DPA shall survive termination or expiry of the Agreement and remain in force until no Personal Data remains in the possession or control of Airship or any Sub-Processor. Clauses 10 and 11 shall continue indefinitely.
13. GENERAL
13.1 This DPA constitutes the entire agreement between the parties in relation to data protection matters and supersedes any previous data processing terms or policies, including the previous Appendix 1 to the Agreement.
13.2 This DPA is governed by the laws of England and Wales. The parties submit to the exclusive jurisdiction of the courts of England and Wales in respect of any dispute arising under it.
13.3 If any provision of this DPA is held to be invalid, illegal or unenforceable, it shall be severed and the remaining provisions shall continue in full force.
13.4 Airship may amend this DPA from time to time to reflect: (a) changes in Data Protection Legislation; (b) changes in Airship's operational or sub-processor arrangements; or (c) guidance from the ICO or other competent authority. Airship shall provide the Client with reasonable written notice of any material amendments.
ANNEX 1 – PROCESSING DETAILS
The table below sets out the details of processing carried out by Airship on behalf of the Client under this DPA.
| Processor | Airship Services Limited, 115a Innovation Drive, Milton Park, Abingdon, Oxfordshire OX14 4RZ. support@airship.co.uk | 0114 299 6477 |
| Data Protection Contact | Oskar Smith, CTO – contact via support@airship.co.uk |
| Controller | The Client as identified in the Order Form (Schedule 1). |
| Subject-matter of Processing | Provision of email marketing, CRM, customer data management, automated journey and communication services, and related analytics via the Airship platform. |
| Duration of Processing | For the duration of the Agreement, and for such further period as may be required for the return or deletion of Personal Data following termination. |
| Nature and Purpose of Processing | Processing necessary to: (a) provide the Services under the Agreement; (b) store and manage Contact Data and Customer Data; (c) send email and SMS communications on the Client's behalf; (d) enable segmentation, profiling and behaviour analysis of Contacts (where consent has been obtained); (e) generate reporting and analytics; (f) facilitate integrations with Third Party Providers; and (g) detect and prevent fraudulent or unauthorised activity. |
| Types of Personal Data | Personal information (gender, title, first/last name, date of birth); contact information (email address, mobile, home and work numbers); postal address; IP addresses and device identifiers (including MAC address); loyalty and gift card data (card reference, balance, points, active status, expiry, programme association — note: no payment card data is stored); booking and reservation data (booking type, party size, dates, deposit and spend); Wi-Fi interaction data (hotspot name, device type, interaction timestamps); feedback and post-visit data (ratings, text feedback, campaign and form references); purchase and transaction history (line description, SKU, quantity, value, date/time, location); hotel stay data (room type, rate, check-in/out dates, guest numbers, financials, booking source); preference and consent records; behavioural and engagement data (email opens, clicks, journey interactions); and any further personal data uploaded by the Client to the platform. Note: Airship does not store payment card information or medical information. |
| Categories of Data Subjects | Customers, prospects and loyalty members of the Client; and (where applicable) employees or representatives of the Client who are Authorised Users of the platform. |
| Location of Processing | Primarily within the UK and EU. Where processing occurs outside the UK/EEA, Airship shall ensure appropriate safeguards are in place as described in clause 7 and Annex 2. |
ANNEX 2 – SUB-PROCESSORS AND INTERNATIONAL TRANSFERS
The following Sub-Processors are currently authorised by Airship to process Personal Data in connection with the Services. Airship will update this list in accordance with clause 5.
| Sub-Processor | Processing Activity | Location | Transfer Safeguard |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure, hosting, storage and data processing | EU / UK (primary) | AWS GDPR DPA; UK SCCs where applicable |
| Bird.com (SparkPost) | Email delivery and transactional messaging | USA / EU | Bird DPA; UK SCCs / adequacy framework |
| SingleStore (formerly MemSQL) | Database and analytics processing | USA / EU | SingleStore DPA; UK SCCs where applicable |
| Google (Workspace / Cloud) | Internal tooling, support communications | USA / EU | Google Cloud DPA; UK adequacy / SCCs |
| CDN77 (DataCamp Ltd) | Content delivery network (Toggle platform) | UK | UK GDPR / DPA 2018 (no transfer) |
| Sinch | SMS messaging delivery | USA / EU | Sinch DPA; UK SCCs where applicable |
| Twilio | SMS messaging delivery | USA | Twilio DPA; UK SCCs where applicable |
| Esendex (Commify UK Ltd) | SMS messaging delivery | UK / EU | Esendex DPA; UK GDPR compliant |
| Unlayer Inc. | Email template editor (platform component) | USA | Unlayer privacy policy; UK SCCs where applicable |
| Better Stack | Uptime monitoring and incident management | EU | Better Stack DPA; EU adequacy |
| Airbrake (Functional Software Inc.) | Application error monitoring and alerting | USA | Airbrake privacy policy; UK SCCs where applicable |
Note: This list will be updated by Airship from time to time in accordance with clause 5 of this DPA. The most current version is available on written request.






