Data Processing Agreement
Last updated June 15, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between Envoy (“Processor”) and the customer (“Controller”) for use of the EnvoyEngage platform and its apps, including VendorApp (the “Service”). It governs the processing of personal data that the Processor carries out on the Controller’s behalf.
1. Roles
For Customer Data processed through the Service, the Controller is the controller and Envoy is the processor. Where the Controller is itself processing on behalf of its own customers (e.g. airlines or vendors), Envoy acts as a sub-processor and the Controller remains responsible for its instructions and lawful basis.
2. Subject matter and duration
The subject matter is the provision of the Service; processing continues for the term of the agreement and the limited period needed for deletion or return of data afterwards.
3. Nature, purpose, data, and data subjects
- Purpose: hosting and operating branded support portals and administration on top of the Controller’s Zendesk.
- Data types: identifiers (names, email addresses), support ticket content, organization and user records, and usage/log data.
- Data subjects: the Controller’s personnel and the end users of the Controller’s customers (e.g. vendor and airline staff) who interact with the portals.
4. Processor obligations
- Process personal data only on the Controller’s documented instructions, including for transfers, unless required by law.
- Ensure personnel authorized to process are bound by confidentiality.
- Implement appropriate technical and organizational security measures (see Security & Trust).
- Engage sub-processors only as permitted below and impose equivalent obligations on them.
- Assist the Controller, taking into account the nature of processing, with data subject requests and with security, breach notification, and impact assessments.
- Notify the Controller without undue delay after becoming aware of a personal data breach.
- At the Controller’s choice, delete or return Customer Data at the end of the services, except where retention is required by law.
5. Sub-processors
The Controller authorizes Envoy to engage the sub-processors listed in our Sub-processors. We will inform the Controller of intended changes and give the Controller the opportunity to object.
6. International transfers
Where personal data is transferred across borders, the parties will rely on a valid transfer mechanism, such as the Standard Contractual Clauses, which are incorporated by reference where applicable.
7. Audits
Envoy will make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, subject to reasonable confidentiality and security limits.
8. Execution
To put a signed copy in place for your organization, contact jakub@goenvoy.co. This page is a template and does not by itself constitute a signed agreement.