Effective Date: 01 August 2026
This Data Processing Addendum (“DPA”) forms part of the Terms & Conditions between BYO Travelcations Private Limited, operating the TRAVNEXUS platform (“Processor”, “TRAVNEXUS”, “we”, “our”) and the registered travel agency, travel consultant, DMC, tour operator, or business entity using the platform (“Controller”, “Customer”, “you”).
This DPA governs the processing of Personal Data by TRAVNEXUS on behalf of the Customer in connection with the services provided through the platform.
1. Purpose
The purpose of this DPA is to define the responsibilities of both parties regarding the collection, processing, storage, security, and protection of Personal Data processed through TRAVNEXUS.
2. Scope
This DPA applies whenever the Customer uses TRAVNEXUS to:
- Create travel itineraries
- Manage customer enquiries
- Process hotel bookings
- Submit group flight requests
- Manage fixed departures
- Generate quotations
- Issue invoices
- Store traveller information
- Use CRM features
- Access travel management services
3. Definitions
Personal Data
Any information relating to an identified or identifiable individual, including but not limited to traveller names, contact details, booking information, passport details (where required), and other booking-related information.
Controller
The registered travel agency or business using TRAVNEXUS that determines the purpose and means of processing Personal Data.
Processor
BYO Travelcations Private Limited operating TRAVNEXUS, processing Personal Data solely on behalf of the Controller.
4. Roles and Responsibilities
Customer (Controller)
The Customer is responsible for:
- Collecting Personal Data lawfully.
- Obtaining necessary customer consent where required.
- Ensuring submitted data is accurate.
- Complying with applicable privacy laws.
TRAVNEXUS (Processor)
TRAVNEXUS shall:
- Process Personal Data only to provide the requested services.
- Follow the Customer’s documented instructions.
- Protect Personal Data using appropriate technical and organisational measures.
- Not sell or rent Personal Data.
- Not use Personal Data for unrelated purposes.
5. Categories of Personal Data
Depending on the services used, TRAVNEXUS may process:
- Traveller Names
- Email Addresses
- Phone Numbers
- Company Information
- Booking Details
- Travel Dates
- Hotel Reservations
- Flight Requests
- Passport Information (where required)
- Invoice Information
- Payment References
- Communication History
TRAVNEXUS does not intentionally collect sensitive personal data unless required for a travel booking or legal obligation.
6. Purpose of Processing
Personal Data is processed solely for:
- Managing travel enquiries
- Creating itineraries
- Booking travel services
- Customer relationship management
- Supplier communication
- Booking confirmations
- Invoice generation
- Fraud prevention
- Platform security
- Customer support
7. Confidentiality
TRAVNEXUS ensures that employees, contractors, and authorised personnel with access to Personal Data are bound by appropriate confidentiality obligations.
8. Security Measures
TRAVNEXUS implements appropriate technical and organisational safeguards, including:
- SSL/TLS encryption
- Secure authentication
- Encrypted passwords
- Role-based access control
- Secure cloud infrastructure
- Regular backups
- Security monitoring
- Firewall protection
- Periodic software updates
While no system can guarantee absolute security, TRAVNEXUS continuously works to maintain a high level of data protection.
9. Sub-processors
TRAVNEXUS may engage trusted third-party service providers to support platform operations, including:
- Cloud hosting providers
- Payment gateways
- Email delivery services
- SMS providers
- WhatsApp messaging services
- Analytics platforms
- Hotel suppliers
- Flight suppliers
- Other travel technology partners
All sub-processors are required to implement appropriate security measures consistent with applicable data protection laws.
10. International Data Transfers
Where Personal Data is transferred outside India, TRAVNEXUS will take reasonable contractual and technical measures to protect such data in accordance with applicable laws and recognised industry practices.
11. Data Retention
TRAVNEXUS retains Personal Data only for as long as necessary to:
- Provide services
- Meet legal obligations
- Resolve disputes
- Prevent fraud
- Maintain business records
Upon expiration of the applicable retention period, Personal Data will be securely deleted or anonymised where appropriate.
12. Data Subject Requests
Where TRAVNEXUS receives a request from an individual regarding their Personal Data, TRAVNEXUS will, where appropriate, assist the Customer in responding to such requests, subject to applicable laws and technical feasibility.
13. Data Breach Notification
If TRAVNEXUS becomes aware of a confirmed Personal Data breach affecting Customer data, we will notify the Customer without undue delay after becoming aware of the incident.
Such notification will include, where reasonably available:
- Nature of the breach
- Categories of affected data
- Likely impact
- Containment measures taken
- Recommended actions (if applicable)
14. Audit Rights
Where reasonably required and subject to confidentiality obligations, the Customer may request information demonstrating TRAVNEXUS’s compliance with this DPA.
Any audit or inspection must be mutually agreed upon in advance and conducted without disrupting normal platform operations.
15. Termination
Upon termination of the Customer’s account, TRAVNEXUS will retain or delete Personal Data in accordance with applicable legal requirements, contractual obligations, and its Privacy Policy.
16. Liability
Each party shall remain responsible for its own compliance with applicable data protection laws.
TRAVNEXUS shall not be responsible for:
- Inaccurate information submitted by the Customer.
- Unauthorised disclosures made by the Customer.
- Customer misuse of Personal Data.
- Third-party supplier processing performed outside the control of TRAVNEXUS.
17. Governing Law
This Data Processing Addendum shall be governed by the laws of India.
Any disputes arising under this DPA shall be subject to the exclusive jurisdiction of the courts located in Amritsar, Punjab, India.
18. Contact
For questions regarding this Data Processing Addendum, please contact:
TRAVNEXUS
Operated by BYO Travelcations Private Limited
📞 +91-9878730549
📍 Amritsar, Punjab, India
