top of page

Data Processing Addendum (DPA)

Effective Date: September 2026

Last Updated: September 2026

If you have any questions regarding this Data Processing Addendum (DPA)  please contact:

The FlyTribe Ltd

Email:privacy@theflytribe.world

Website: www.theflytribe.world

Protecting Personal Data with Confidence

The FlyTribe is committed to processing personal data securely, responsibly and in accordance with applicable data protection laws.

This Data Processing Addendum explains the responsibilities of The FlyTribe and our customers when personal data is processed through our platform, helping ensure transparency, security and regulatory compliance for every organisation we support.

This Data Processing Addendum ("DPA") forms part of the agreement between The FlyTribe Ltd ("Processor", "The FlyTribe", "we", "our" or "us") and the Employer identified in the applicable Order Form ("Controller", "Employer", "you" or "your").

This DPA applies whenever The FlyTribe processes Personal Data on behalf of the Employer in connection with the Services.

1. Purpose

The purpose of this DPA is to ensure that the processing of Personal Data complies with:

  • UK General Data Protection Regulation (UK GDPR);

  • Data Protection Act 2018;

  • where applicable, EU General Data Protection Regulation (EU GDPR);

  • other applicable data protection legislation.

Where there is any conflict between this DPA and the Employer Terms & Conditions in relation to data protection, this DPA shall prevail.

 

2. Definitions

Unless otherwise defined in this DPA, capitalised terms have the meanings given in the Employer Terms & Conditions.

For the purposes of this DPA:

Controller means the organisation determining the purposes and means of processing Personal Data.

Processor means The FlyTribe Ltd.

Data Subject means an identified or identifiable natural person.

Personal Data means any information relating to an identified or identifiable individual.

Processing has the meaning given under applicable data protection legislation.

Sub-Processor means any third party engaged by The FlyTribe to process Personal Data on its behalf.

Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.

 

3. Scope

This DPA applies whenever The FlyTribe processes Personal Data on behalf of the Employer through:

  • Membership administration;

  • Organisation Hub;

  • communication tools;

  • AI productivity services;

  • Meeting Assistant;

  • customer support;

  • technical support;

  • Platform administration;

  • any related Services.

 

4. Roles of the Parties

The Employer acts as the Controller of Personal Data provided to The FlyTribe.

The FlyTribe acts as the Processor of such Personal Data except where The FlyTribe determines the purposes and means of processing in its own capacity, in which case it acts as an independent Controller.

Each party shall comply with its respective obligations under applicable data protection legislation.

 

5. Processing Instructions

The FlyTribe shall process Personal Data only:

  • on documented instructions from the Employer;

  • as necessary to provide the Services;

  • where required by applicable law.

If The FlyTribe believes an instruction infringes applicable data protection legislation, it shall inform the Employer unless prohibited by law.

 

6. Confidentiality

The FlyTribe shall ensure that persons authorised to process Personal Data:

  • are bound by confidentiality obligations; or

  • are subject to an appropriate statutory duty of confidentiality.

Access to Personal Data shall be limited to personnel with a legitimate business need.

 

7. Security Measures

The FlyTribe shall implement appropriate technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

These measures may include:

  • encryption in transit and at rest where appropriate;

  • role-based access controls;

  • multi-factor authentication;

  • logging and monitoring;

  • secure cloud infrastructure;

  • vulnerability management;

  • regular security reviews;

  • secure backup procedures;

  • staff security training.

The measures implemented shall take account of the state of the art, implementation costs, the nature of the processing and the risks to Data Subjects.

 

8. Sub-Processors

The Employer authorises The FlyTribe to engage Sub-Processors where reasonably necessary to provide the Services.

The FlyTribe shall:

  • undertake appropriate due diligence before appointing a Sub-Processor;

  • ensure that Sub-Processors are subject to written contractual obligations substantially equivalent to those contained in this DPA;

  • remain responsible for the performance of its Sub-Processors to the extent required by applicable law.

The FlyTribe will maintain an up-to-date list of Sub-Processors and make it available upon reasonable request.

 

9. International Transfers

Where Personal Data is transferred outside the United Kingdom or European Economic Area, The FlyTribe shall ensure that an appropriate transfer mechanism is in place, including where applicable:

  • UK International Data Transfer Agreement (IDTA);

  • UK Addendum to the EU Standard Contractual Clauses;

  • adequacy regulations;

  • another lawful transfer mechanism recognised under applicable law.

 

10. Assistance to the Controller

Taking into account the nature of the processing, The FlyTribe shall provide reasonable assistance to the Employer in fulfilling its obligations relating to:

  • Data Subject rights requests;

  • security obligations;

  • Personal Data Breach notifications;

  • Data Protection Impact Assessments (DPIAs);

  • consultations with supervisory authorities where required.

11. Data Subject Rights

Taking into account the nature of the processing, The FlyTribe shall provide reasonable assistance to the Employer in responding to requests from Data Subjects exercising their rights under applicable data protection legislation.

These rights may include:

  • right of access;

  • right to rectification;

  • right to erasure;

  • right to restriction of processing;

  • right to data portability;

  • right to object;

  • rights relating to automated decision-making where applicable.

Where The FlyTribe receives a request directly from a Data Subject relating to Personal Data processed on behalf of the Employer, The FlyTribe shall, unless prohibited by law:

  • promptly notify the Employer;

  • not respond directly except on the documented instructions of the Employer or where legally required.

 

12. Personal Data Breaches

The FlyTribe shall maintain appropriate procedures for identifying, managing and responding to Personal Data Breaches.

Where The FlyTribe becomes aware of a Personal Data Breach affecting Personal Data processed on behalf of the Employer, it shall:

  • notify the Employer without undue delay after becoming aware of the breach;

  • provide available information regarding the nature of the breach;

  • describe the categories and approximate number of affected Data Subjects where known;

  • identify the likely consequences of the breach where reasonably possible;

  • describe the measures taken or proposed to address the breach and mitigate its effects.

The Employer acknowledges that information may become available progressively during the investigation, and The FlyTribe may provide updates as further facts are established.

 

13. Audit Rights

Upon reasonable written request, and no more than once in any twelve (12) month period (unless required by law or following a confirmed Personal Data Breach), The FlyTribe shall make available information reasonably necessary to demonstrate compliance with this DPA.

Where an audit is requested:

  • reasonable notice shall be provided;

  • audits shall be conducted during normal business hours;

  • audits must not unreasonably interfere with The FlyTribe's business operations;

  • the Employer shall bear its own audit costs unless otherwise agreed.

Where appropriate, independent third-party audit reports, certifications or security documentation may be provided in place of an on-site audit.

 

14. Return or Deletion of Personal Data

Upon termination or expiry of the Services, and subject to applicable law, The FlyTribe shall, at the Employer's written request:

  • return the Personal Data; or

  • securely delete the Personal Data.

The FlyTribe may retain Personal Data where required:

  • by applicable law;

  • for regulatory compliance;

  • for the establishment, exercise or defence of legal claims;

  • within securely maintained backup systems until deletion occurs through normal retention cycles.

Any retained Personal Data shall remain subject to the confidentiality and security obligations contained in this DPA.

 

15. Liability

Each party remains responsible for its own compliance with applicable data protection legislation.

Nothing in this DPA limits or excludes liability where such limitation or exclusion would be unlawful.

The liability provisions contained within the Employer Terms & Conditions shall apply to this DPA unless expressly stated otherwise.

 

16. Changes in Law

If applicable data protection legislation changes during the Term of the Agreement, the parties shall cooperate in good faith to make any amendments reasonably necessary to maintain compliance.

The FlyTribe may update this DPA where required by:

  • legislative changes;

  • regulatory guidance;

  • supervisory authority decisions;

  • developments in recognised industry standards.

Where changes materially affect the Employer, reasonable notice will be provided.

 

17. Governing Law

This DPA shall be governed by and interpreted in accordance with the laws of England and Wales.

 

18. Jurisdiction

The courts of England and Wales shall have exclusive jurisdiction to determine any dispute arising out of or in connection with this DPA, unless applicable data protection legislation requires otherwise.

 

SCHEDULE 1 — Details of Processing

Controller

The Employer purchasing The FlyTribe Memberships.

Processor

The FlyTribe Ltd.

Subject Matter

Provision of The FlyTribe Platform and related Services.

Duration

For the duration of the Agreement and for any lawful retention period thereafter.

Nature of Processing

Processing activities may include:

  • collection;

  • recording;

  • organisation;

  • storage;

  • consultation;

  • use;

  • transmission;

  • retrieval;

  • deletion;

  • secure disposal.

Purpose of Processing

To provide:

  • Membership administration;

  • user authentication;

  • Organisation Hub functionality;

  • communication features;

  • travel safety services;

  • productivity tools;

  • customer support;

  • technical support;

  • service improvement;

  • security monitoring.

 

SCHEDULE 2 — Categories of Data Subjects

Personal Data may relate to:

  • employees;

  • contractors;

  • consultants;

  • authorised users;

  • administrators;

  • customer contacts;

  • Partner contacts;

  • support contacts.

 

SCHEDULE 3 — Categories of Personal Data

Depending upon the Services used, Personal Data may include:

  • name;

  • business email address;

  • business telephone number;

  • employer;

  • job title;

  • account identifiers;

  • authentication credentials (encrypted where applicable);

  • travel-related information submitted by users;

  • communications within the Platform;

  • support requests;

  • technical usage data;

  • device identifiers;

  • IP addresses;

  • audit logs.

The FlyTribe does not intentionally require Employers to provide special category personal data unless specifically agreed and supported by an appropriate lawful basis.

 

SCHEDULE 4 — Technical and Organisational Security Measures

The FlyTribe maintains security measures appropriate to the risks associated with the Services, which may include:

  • encryption in transit using industry-standard protocols;

  • encryption of stored data where appropriate;

  • role-based access controls;

  • least-privilege access principles;

  • multi-factor authentication for administrative access where implemented;

  • network and endpoint security controls;

  • logging and security monitoring;

  • vulnerability assessment and patch management;

  • secure backup and recovery procedures;

  • staff confidentiality obligations and security awareness training;

  • incident response procedures;

  • business continuity and disaster recovery planning.

The FlyTribe may update these measures over time provided that the overall level of protection is not materially reduced.

woman_scrolling_phone_in_airport_lounge.jpg
the flytribe black full

The Advantage Behind Every Successful Business Journey

Designed for organisations that want more from business travel.

Ready to unlock more value from every business journey?

@2026 The FlyTribe Ltd. All rights reserved

man_scrolling_phone_in_airport_lounge.jpg

Every journey leaves an impact.

 

We're helping make it a positive one.

​​​​​​£2 from every membership supports Sustainable Travel International.

sustainable travel international logo
Image by Apostolos Vamvouras
bottom of page