Data Processing Agreement
Last updated: 9 September 2026 Effective: 9 September 2026
This Data Processing Agreement (“DPA”) forms part of, and is incorporated by reference into, the Terms and Conditions between you (“Customer”, “Controller”) and Hell’s Highway (eenmanszaak), KvK 73442372, Geerbosch 10a, 5461 XJ Veghel, the Netherlands (“we”, “us”, “Processor”), governing the G3 Operations service (the “Service”).
It applies where we process personal data on your behalf — that is, the personal data contained in the tour content you enter into the Service. It does not apply to the account and billing data described in Section 3.1 of our Privacy Policy, for which we are the controller in our own right.
No signature is required: by using the Service you accept this DPA. Business and institutional customers who need a countersigned copy may request one at privacy@g3ops.com.
1. Definitions
Terms used but not defined here — including personal data, processing, controller, processor, sub-processor, data subject, personal data breach, and supervisory authority — have the meanings given in the GDPR (Regulation (EU) 2016/679). “Customer Personal Data” means personal data within your tour content that we process on your behalf. “Applicable Data Protection Law” means the GDPR and the Dutch Uitvoeringswet AVG.
2. Roles of the parties
You are the controller of Customer Personal Data and we are your processor. You determine the purposes and means of processing that data; we process it only to provide the Service.
You are responsible for the lawfulness of the data you enter: for having a valid legal basis, for providing the required transparency information to the people concerned (tour managers, drivers, clients, participants, and any other third parties you name), and for the accuracy of the data. We have no direct relationship with those people and, other than as set out here, no visibility into why you hold their data.
Where we act as controller — account, authentication, and billing data — our Privacy Policy applies instead of this DPA.
3. Processing on documented instructions
We process Customer Personal Data only on your documented instructions, including as to international transfers, unless required otherwise by EU or Member State law — in which case we will inform you of that requirement before processing, unless the law prohibits it on important grounds of public interest.
Your instructions consist of: this DPA, the Terms, the Privacy Policy, and your use of the features of the Service. Annex I describes the processing.
We will inform you if, in our opinion, an instruction infringes Applicable Data Protection Law. We do not sell Customer Personal Data, do not use it for advertising, and do not use it to train machine-learning models.
4. Confidentiality
We ensure that any person authorised to process Customer Personal Data is bound by an appropriate obligation of confidentiality, whether contractual or statutory, and that access is limited to those who need it to provide, secure, or support the Service.
5. Security
We implement appropriate technical and organisational measures under Article 32 GDPR, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to data subjects. The measures in force are described in Annex II.
We may update those measures over time; we will not make changes that materially reduce the overall level of protection.
6. Sub-processors
You give us general authorisation to engage sub-processors for the provision of the Service. The sub-processors engaged as at the effective date are listed in Annex III.
We impose on each sub-processor, by written contract, data-protection obligations that are no less protective than those in this DPA, and we remain fully liable to you for their performance.
We will notify you of any intended addition or replacement of a sub-processor at least 30 days in advance, by email to your account address or by an update to Annex III announced through the Service. You may object on reasonable data-protection grounds within that period. If we cannot resolve your objection, you may terminate the affected subscription and receive a pro-rata refund of prepaid fees for the unused remainder of the term — your exclusive remedy in that case.
7. Assistance with data subject rights
The Service gives you direct control over your tour content: you can view, correct, export, and delete it yourself at any time, which will in most cases be the fastest route to satisfying a request.
Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests to exercise data-subject rights under Chapter III GDPR. If a data subject contacts us directly about data that is your tour content, we will not respond substantively; we will refer them to you and inform you promptly.
8. Personal data breach
We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.
We will provide reasonable assistance to you in meeting your own obligations under Articles 33 and 34 GDPR. Our notification is not an acknowledgement of fault or liability.
9. Data protection impact assessments
Taking into account the nature of processing and the information available to us, we will provide reasonable assistance with your data protection impact assessments and any prior consultation with a supervisory authority under Articles 35 and 36 GDPR.
10. International transfers
Customer Personal Data in the core application — the database that holds your tours — is stored in the European Union. Certain sub-processors listed in Annex III are established outside the EEA or may access data from outside it. Where personal data is transferred outside the EEA, the transfer is made on the basis of an EU adequacy decision (including the EU-US Data Privacy Framework where the recipient is certified) and/or the European Commission’s Standard Contractual Clauses, together with any supplementary measures required.
11. Return and deletion
On termination or expiry of your subscription, and in any event on deletion of your account, we will delete Customer Personal Data in accordance with our Privacy Policy: access is withdrawn immediately, and the data is irreversibly erased after a 30-day recovery window, save to the extent that EU or Member State law requires storage — in which case we continue to protect it and process it only for that purpose.
You may export your tour data yourself, at any time and without a request to us, using the export feature of the Service. Please do so before deleting your account: after the recovery window the erasure is permanent and we cannot restore your data.
Residual copies within backups are erased on the backup cycle described in Annex II, within a maximum of 30 days.
12. Audits and information
We will make available to you all information reasonably necessary to demonstrate compliance with Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
In the first instance we will satisfy such requests through written information and by making available the relevant certifications and audit reports of our sub-processors. Where that is genuinely insufficient to demonstrate compliance, an on-site or remote inspection may be conducted, on reasonable prior notice of at least 30 days, no more than once in any 12-month period (unless required by a supervisory authority or following a personal data breach), during normal business hours, without unreasonably disrupting our operations, and subject to confidentiality. You bear your own costs and, beyond the first audit in any 12-month period, our reasonable costs.
13. Liability, term, and precedence
This DPA takes effect when you begin using the Service and continues for as long as we process Customer Personal Data on your behalf.
Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms. Nothing in this DPA limits any liability that cannot be limited under Applicable Data Protection Law, including liability towards data subjects under Article 82 GDPR.
In case of conflict, this DPA prevails over the Terms on data-processing matters; where the Standard Contractual Clauses apply to a transfer, they prevail over this DPA in respect of that transfer.
14. Governing law
This DPA is governed by the laws of the Netherlands, and disputes are subject to the jurisdiction agreed in the Terms.
Annex I — Details of the processing
Subject matter. Provision of the G3 Operations tour-planning and tour-execution service to the Customer.
Duration. For the term of the Customer’s use of the Service, followed by the deletion described in Section 11.
Nature and purpose. Hosting, storage, structuring, retrieval, display, transmission to users the Customer authorises (tour managers and drivers), export at the Customer’s request, backup, and erasure — all solely to provide, secure, and support the Service. Where the Customer uses the automatic drive-time feature, the location codes of the relevant stops are transmitted to the routing provider named in Annex III in order to calculate travel times.
Categories of data subjects. Tour managers invited by the Customer; drivers given a shared link; and any clients, tour participants, suppliers, contacts, or other individuals whom the Customer chooses to name in tour content.
Types of personal data. Names; email addresses (tour managers, and any addresses the Customer enters); telephone numbers and other contact details where entered; role and assignment information; itinerary and location information associated with an individual; and any further personal data the Customer chooses to enter in free-text fields such as notes.
Special categories of personal data. None are required by the Service, and the Service is not designed or assessed for them. The Customer must not enter special categories of personal data (Article 9 GDPR) or personal data relating to criminal convictions and offences (Article 10 GDPR) into tour content — including, for example, dietary, health, accessibility, or religious details about participants.
Frequency of processing. Continuous, for the duration of the Service.
Annex II — Technical and organisational measures
Encryption. All data in transit is encrypted with TLS. Data at rest in the database, in file storage, and in backups is encrypted by our infrastructure provider using industry-standard encryption.
Authentication. The Service holds no passwords. Guides sign in with Google; tour managers are authenticated by a single-use invitation code exchanged for a scoped session. Sessions can be revoked centrally.
Access control and tenant isolation. Every account’s data sits in its own tenant. Isolation and role-based access are enforced server-side by database security rules, not merely in the user interface, so a user cannot read or write another tenant’s data by manipulating the client.
Driver links. A shared driver link grants read-only access to a single tour. Access is gated server-side by a PIN verified by a rate-limited backend function, which issues a short-lived credential scoped to that one tour; the link alone does not grant access. Links expire after the tour and can be revoked by the account owner at any time, which terminates any live driver session.
Least privilege in the backend. Privileged operations — account provisioning, invitations, deletion, billing, administration — run only in server-side functions with verified identity and role claims. Client applications hold no administrative credentials.
Logging and monitoring. Operational logs (used for security, abuse prevention, and reliability) are retained for 30 days. A limited subset of infrastructure audit logs is retained by the infrastructure provider for up to 400 days and cannot be shortened. Personal data in logs is minimised: email addresses are masked, and request bodies, authentication tokens, PINs, and invitation codes are never logged.
Backup and restore. Managed database backups are retained for 30 days (daily) and 25 days (weekly), with point-in-time recovery for 7 days. An additional independent daily export is retained for 30 days on a lifecycle rule, with soft-delete disabled so that deletion is not silently extended.
Deletion. Account deletion is self-service and runs as a server-side cascade: access is withdrawn immediately, the subscription is cancelled, share links and PINs are destroyed, and the account and its content are irreversibly erased after the 30-day recovery window. A minimal proof-of-erasure record — an internal identifier and a date, containing no name, email, tour, or billing data — is retained as evidence that the erasure took place.
Infrastructure security. Hosting, database, and authentication are provided by Google (Firebase / Google Cloud), whose certifications include ISO/IEC 27001, 27017, 27018, and SOC 2/3. Public access to storage buckets is blocked at the bucket level. Access to production infrastructure is limited to authorised personnel.
Breach response. Suspected breaches are investigated on discovery, the cause contained, and affected customers notified within the period stated in Section 8.
Organisational. Personnel with access are bound by confidentiality. The number of people with production access is deliberately minimal, reflecting the size of the organisation.
Annex III — Sub-processors
| Sub-processor | Role | Processing location | Transfer safeguard |
|---|---|---|---|
| Google Ireland Ltd / Google LLC (Firebase, Google Cloud) | Database, authentication, file storage, application hosting, logging, backups | EU (europe-west1, Belgium); support and administration may be from outside the EEA | Adequacy / EU-US Data Privacy Framework and SCCs |
| Stripe Payments Europe Ltd / Stripe, Inc. | Subscription billing and payment processing (controller data; listed for completeness) | EU / US | EU-US Data Privacy Framework and SCCs |
| Sendinblue SAS (Brevo) | Transactional and invitation email | France (EU) | Within the EEA |
| Cloudflare, Inc. | Website and edge delivery for g3ops.com | EU / US | EU-US Data Privacy Framework and SCCs |
| Geoapify GmbH | Route and travel-time calculation from stop location codes, when the Customer uses the automatic drive-time feature | Germany (EU) | Within the EEA |
Questions about this DPA, or a request for a countersigned copy: privacy@g3ops.com.