Data Processing Addendum
v1.0.0
Effective September 15, 2026
Parties. This Data Processing Addendum (“DPA”) is between Farel, Inc., 2261 Market Street, Suite 85854, San Francisco, CA 94114, United States (“Farel”) and the customer identified in the applicable service agreement (“Customer”). It applies where Farel processes personal data on the Customer’s behalf under that agreement, including reservation, passenger service, communications and notification services. Farel acts as processor and the Customer as controller; where the Customer is itself a processor, Farel acts as sub-processor.
1. Subject Matter, Duration, Nature and Purpose
Farel processes personal data to provide the Services for the term of the service agreement. The processing consists of hosting, storage, transmission, display, notification delivery and support, for the purpose of operating the Customer’s reservations, passenger services and communications as instructed.
2. Personal Data and Data Subjects
Categories of data: passenger and contact identifiers; booking and flight information; contact details; communication content and delivery status; and, where the Customer supplies them for a service purpose, assistance or special-service information. Data subjects: the Customer’s passengers, contacts and staff.
3. Instructions
Farel processes personal data only on the Customer’s documented instructions: the service agreement, this DPA, any communications instructions annex, and written instructions from the Customer’s authorized contact. Farel informs the Customer if it considers an instruction to infringe applicable data protection law. Farel does not use Customer personal data for its own sales, advertising, product-improvement or artificial-intelligence purposes.
4. Confidentiality
Farel ensures that persons authorized to process the personal data are bound by confidentiality obligations and act only on instructions.
5. Security
Farel implements technical and organizational measures appropriate to the risk, including encryption in transit and at rest, access control based on least privilege with multi-factor authentication for administrative access, logging and monitoring, vulnerability management, backups and incident response. A description of current measures is available on request.
6. Sub-processors
The Customer authorizes the sub-processors listed at https://farel.io/legal/subprocessors/. Farel gives at least 30 days’ notice before adding a sub-processor; the Customer may object on reasonable data-protection grounds, and the parties will work in good faith to resolve the objection. Farel imposes data-protection obligations on its sub-processors equivalent to this DPA and remains responsible for their performance.
7. Assistance
Taking into account the nature of the processing, Farel assists the Customer in responding to data-subject requests (forwarding requests it receives within five business days), in meeting security and breach-notification obligations, and in data protection impact assessments and prior consultations. Farel may charge reasonable costs for extensive assistance.
8. Personal Data Breaches
Farel notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data, provides the information reasonably available, and updates it as the investigation proceeds.
9. Deletion and Return
On termination of the Services, Farel returns or deletes the Customer’s personal data within 90 days, at the Customer’s choice, unless retention is required by law, and deletes remaining copies thereafter, subject to backup rotation during which the data is isolated from ordinary processing. Communication copies are kept for the periods stated in the communications instructions annex or, absent instructions, the defaults published in Farel’s data-handling schedule.
10. Audits
Farel makes available the information necessary to demonstrate compliance with this DPA and allows for and contributes to audits, including inspections, by the Customer or an auditor mandated by the Customer, on reasonable notice, not more than once a year unless required by a supervisory authority or following a personal data breach, subject to confidentiality.
11. International Transfers
Farel processes data in the United States and the European Union (Germany), with staff access from the United States, Serbia and Spain. For personal data transferred from the EEA, the parties incorporate the EU Standard Contractual Clauses (Commission Decision 2021/914), Module Two (controller to processor) or Module Three (processor to processor) as applicable, with the Customer as data exporter and Farel as data importer, and the following options: Clause 7 included; Clause 9 option 2 with 30 days’ notice; Clause 11 optional language not included; Clause 13 supervisory authority of the exporter’s Member State; Clause 17 law of Ireland; Clause 18 courts of Ireland; Annexes I to III completed by this DPA, the service agreement and the sub-processor list. For personal data transferred from the United Kingdom, the UK International Data Transfer Addendum to those Clauses applies; for Switzerland, the adaptations required by the Swiss data protection authority apply.
12. Representatives
Farel’s Article 27 representatives are Prighter EU Rep GmbH (Schellinggasse 3, 1010 Vienna, Austria) for the European Union and Prighter Ltd (20 Mortlake High Street, London, SW14 8JN, United Kingdom) for the United Kingdom, appointed through Prighter GmbH (Austria) and named in Farel’s privacy policy. When a data subject submits a rights request through the representative’s Privacy Rights Manager, Prighter GmbH acts as processor for that request data, using Hetzner Online GmbH (Germany) as sub-processor, and forwards the request to Farel.
13. Liability and Precedence
Liability is governed by the service agreement. This DPA prevails over the Terms of Service and the service agreement for the processing it covers, and the Standard Contractual Clauses prevail over this DPA where they conflict.
14. Term and Changes
This DPA applies for as long as Farel processes Customer personal data. Farel may update it to reflect changes in law or in the Services with notice to the Customer; material changes take effect only with the Customer’s acceptance.
Governing law of this DPA: as the service agreement, without prejudice to the governing law of the Standard Contractual Clauses.
Ready to take back control?
See the full platform live - tailored to your airline's operations.