Skip to content
← All legal documents

Data Processing Addendum

GDPR / UK GDPR terms governing our processing of personal data on behalf of business customers.

Draft dated: July 1, 2026 · v1.0 (Draft)

Draft — pending legal review. This document is a proposal for review, not an executed agreement or evidence of legal approval. Publication does not amend an existing contract, activate a service, or establish that a listed safeguard or vendor arrangement has been verified. Your applicable law and any existing agreement still apply. It does not constitute legal advice. Questions or help reaching the appropriate legal, privacy, or security contact: johnny@tourist-sos.com.

This Data Processing Addendum is offered to business customers who need contractual GDPR / UK GDPR terms governing how Tourist SOS LLC, a Delaware limited liability company processes personal data on their behalf. It is designed to be read alongside our Terms of Service, Privacy Policy, Trust & Security page, and Subprocessors list. An approved customer version and completed schedules are required before this draft can govern processing. Contact us using the details below to establish the appropriate documents for your service.

1. Introduction & scope

This draft Data Processing Addendum (“DPA”) proposes terms for a written customer agreement (the “Agreement”) between Tourist SOS LLC, a Delaware limited liability company (“Tourist SOS,” “we,” “us”) and the business customer that has agreed to the Agreement (the “Controller” or “Customer”).

This published draft is not binding and is not automatically incorporated into the public Terms. An approved version applies only after the parties expressly incorporate it into, or execute it with, their Agreement and complete the required schedules. The proposed obligations below describe that approved arrangement, not a representation that every measure or agreement is already in place.

Its scope is Personal Data Tourist SOS processes on the Customer's behalf for the documented Services, where Applicable Data Protection Law applies. The parties must identify their actual controller, processor, or subprocessor roles for each activity. Those labels do not, by themselves, establish a California service-provider relationship or a HIPAA Business Associate arrangement; any required additional terms and safeguards must be addressed separately.

In an adopted agreement, this DPA takes priority over conflicting general terms concerning processing, but mandatory law and any applicable executed transfer clauses take priority over this DPA. Capitalized terms not defined here have the meaning given in the Agreement. Publication alone does not execute Standard Contractual Clauses or a UK transfer instrument.

2. Definitions

  • “Applicable Data Protection Law” means all data protection and privacy laws applicable to the processing of Personal Data under this DPA, including, as applicable, the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and the UK Data Protection Act 2018, and other comparable state, federal, or national data protection laws.
  • “Controller” means the entity that determines the purposes and means of the processing of Personal Data (sometimes referred to as a “Business” under comparable laws).
  • “Processor” means the entity that processes Personal Data on behalf of, and on the documented instructions of, a Controller (sometimes referred to as a “Service Provider”).
  • “Personal Data” means any information relating to an identified or identifiable natural person that is processed by Tourist SOS on behalf of the Customer under the Agreement.
  • “Processing” means any operation performed on Personal Data, whether or not by automated means, including collection, storage, use, disclosure, and deletion.
  • “Data Subject” means the identified or identifiable natural person to whom Personal Data relates.
  • “Personal Data breach” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data processed under the Agreement.
  • “Subprocessor” means any third party engaged by Tourist SOS to process Personal Data on behalf of the Customer in connection with the services.

3. Roles & instructions

The parties acknowledge and agree that with regard to the processing of Personal Data, the Customer is the Controller and Tourist SOS is the Processor, except where the Customer acts as a processor on behalf of a third party, in which case Tourist SOS is a subprocessor.

Tourist SOS will process Personal Data only on the documented instructions of the Customer, including with regard to transfers of Personal Data to a third country, unless required to do so by law to which Tourist SOS is subject. In that case, Tourist SOS will inform the Customer of that legal requirement before processing, unless the law prohibits this on important grounds of public interest. The Agreement (including this DPA) constitutes the Customer's documented instructions as of the effective date.

Tourist SOS will promptly notify the Customer if, in its opinion, an instruction from the Customer infringes Applicable Data Protection Law. The parties will address the affected instruction before the relevant processing proceeds, subject to any overriding legal requirement.

The Customer is responsible for its lawful basis, required notices and permissions, the accuracy and necessity of data supplied, and the authority of people giving instructions. Tourist SOS remains responsible for its own applicable obligations. Independent processing, such as company account administration or a provider's clinical care, must be separately identified; this DPA does not turn every participant in a case into the Customer's processor.

This DPA is not an instruction to use Customer Personal Data for unrelated marketing or general-purpose AI training. Any different purpose requires its own lawful assessment and appropriate documentation, not an implied permission from use of an AI-enabled feature.

4. Schedule 1 — proposed processing description

The following describes the categories that may be needed for agreed business services. Before adoption, the parties must select the applicable products, workflows, data categories, recipients, and locations; inclusion here is not authorization to collect every category.

  • Subject matter and purpose. Hosting and administering the selected service; organizing authorized intake and case records; care-navigation and provider communications; document and consent workflows; insurance-document, eligibility, billing, or claims support where separately agreed; and securing and supporting those functions.
  • Operations. Collection, structuring, storage, retrieval, authorized sharing, translation or AI-assisted preparation where selected, access logging, export, correction, restriction, and deletion. AI providers and the information sent to them must be identified in the completed service and subprocessor schedules.
  • People concerned. Customer personnel and authorized users; travelers or patients whose cases the Customer lawfully administers; their authorized representatives and emergency contacts; and provider, hospitality, transport, or payer contacts involved in the agreed workflow.
  • Ordinary Personal Data. Names and contact details; account roles and organization information; relevant travel or location details; case references and communications; identity or insurance identifiers where necessary; signatures and authorization records; billing, transaction, and claims references; and service-access or security logs.
  • Sensitive information. Health history, symptoms, allergies, medication, treatment or disability information may be relevant to an authorized case. The parties must document the applicable special-category condition, safeguards, and access limits. Data about children or dependent adults requires an appropriate lawful basis and verified representative authority where required. This is not blanket permission for unrestricted medical-record uploads.
  • Frequency and duration. Processing may occur when authorized users interact with the selected service and while records are maintained for it. The agreed schedule must specify the service term, retention by record category, return or deletion arrangements, backup lifecycle, and any identified legal retention requirement. Expiry of a subscription is not permission for indefinite retention.

Completion required before execution: identify both legal parties and authorized signers, relevant products and purposes, instructions and incident contacts, data subjects and categories, retention periods, processing and support-access locations, approved subprocessors, and any required transfer annexes. These facts are customer-specific and have not been filled in by this website draft.

5. Confidentiality

Tourist SOS ensures that personnel authorized to process Personal Data are subject to appropriate confidentiality obligations, whether contractual or statutory, and receive appropriate training on the handling of Personal Data in accordance with this DPA.

6. Security measures

Tourist SOS implements appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing.

The adopted security schedule must specify the measures applying to the service, including encryption in transit and at rest where appropriate, least-privilege access, and relevant activity logging. Measures must be appropriate to risks to individuals, including the sensitivity of health information. Our public security overview is maintained at tourist-sos.com/trust, which is provided for informational purposes and does not itself form part of this DPA.

7. Schedule 2 — security measures to document

This is a completion checklist for the contractual security schedule, not an attestation that each control is deployed in every product. The approved schedule must describe actual measures and supporting evidence, responsible owners, and any agreed exceptions:

  • Access provisioning and removal, role and tenant boundaries, privileged accounts, authentication safeguards, and access review.
  • Encryption coverage and key responsibility for databases, files, transmissions, exports, and backups; any limitations must be explicit.
  • Data minimization, authorized disclosure paths, and restrictions on exposing identifiers or health data in AI requests, logs, email, analytics, or support channels.
  • Event logging, access to logs, evidence preservation, and the scope and limits of any tamper-resistance measures.
  • Backup and restoration arrangements, availability and recovery planning, testing of safeguards, vulnerability management, and secure change management.
  • Personnel confidentiality and training, supplier review, physical safeguards allocated to infrastructure providers, and an incident response and notification process.

Service levels, audit reports, certifications, data residency, and recovery objectives require express, supported commitments. A vendor's advertised capability or a link to our Trust page is not a substitute for the completed schedule.

8. Subprocessors

Under an adopted DPA, the Customer may grant general written authorization for the Subprocessors identified in its completed schedule. Tourist SOS must bind each authorized Subprocessor to applicable data-protection obligations, including appropriate safeguards, consistent with this DPA before entrusting Customer Personal Data to it.

Tourist SOS remains liable to the Customer for the performance of each Subprocessor's obligations. The public inventory at tourist-sos.com/subprocessors is a confirmation-required draft, not the Customer's completed authorization list. The adopted Agreement must specify a working notice channel and advance notice process for additions or replacements, giving the Customer a meaningful opportunity to object on data-protection grounds before processing begins.

The parties will assess a reasonable alternative if an objection cannot be resolved, and document any affected-service restriction or termination right in their Agreement. A public page update alone is not a substitute for required notification or authorization. The completed Agreement must state the notice periods and any affected-service remedies.

9. Data-subject requests

Taking into account the nature of the processing, Tourist SOS will provide reasonable assistance to the Customer, insofar as this is possible, to help the Customer respond to requests from Data Subjects seeking to exercise their rights under Applicable Data Protection Law (including rights of access, rectification, erasure, restriction, portability, and objection). If Tourist SOS receives such a request directly from a Data Subject regarding Personal Data it processes on the Customer's behalf, it will not respond directly except to direct the Data Subject to the Customer, unless legally required to do otherwise, and will promptly notify the Customer of the request.

10. Security, impact assessments & regulator assistance

Taking account of the processing and information available to it, Tourist SOS will assist the Customer with applicable security obligations, personal-data breach assessment and notifications, data protection impact assessments, and prior consultation with supervisory authorities. This includes relevant information about service data flows, safeguards, subprocessors, and material processing changes. Assistance arrangements and contacts must be documented without preventing either party from meeting a statutory deadline or a regulator's lawful request.

11. Personal-data breach

Tourist SOS will notify the Customer without undue delay after becoming aware of a Personal Data breach affecting data processed on the Customer's behalf. Notification will not await completion of an investigation merely because every detail is not yet known.

Information will be supplied as it becomes available, including the nature and scope of the breach, affected categories and approximate numbers where known, likely consequences, mitigation or containment, and a contact for follow-up. Tourist SOS will cooperate with the Customer's assessment and legally required notices, preserve relevant evidence where appropriate, and explain material updates. The Agreement must identify functioning incident contacts; it must not defer required notice to a routine support queue.

12. International transfers

Before a restricted transfer, including relevant overseas remote access, the parties must identify the exporter, importer, locations, legal roles, onward transfers, and an applicable lawful transfer mechanism. Adequacy, where applicable to the recipient and activity, differs from contractual safeguards. Neither a US hosting description nor this draft establishes an approved transfer.

  • EEA transfers. Where eligible and appropriate, the European Commission's 2021 Standard Contractual Clauses require the module matching the actual roles: for example, Module 2 for controller-to-processor or Module 3 for processor-to-processor transfers. The parties must complete the required annexes, selections, contacts, and technical and organizational measures.
  • UK transfers. The UK International Data Transfer Addendum supplements the EU SCCs. The UK International Data Transfer Agreement (“IDTA”) is a separate instrument, not another name for that Addendum. The appropriate instrument must be selected and completed for the relevant UK transfer.
  • Other transfer laws. Swiss or other applicable requirements need their own assessment and any required adaptations or safeguards. The parties must also assess destination-country risk and any necessary supplementary measures.

Transfer instruments become part of the relationship only through an approved, expressly incorporated or executed agreement with completed annexes. They are not deemed signed by visiting this page. Required safeguards must be in place before the affected transfer; if they cannot be satisfied, that transfer must not proceed under this draft.

13. Deletion or return

At the end of the processing services, Tourist SOS will, at the Customer's choice, delete or return Personal Data processed on its behalf and delete existing copies unless applicable law requires storage. The completed schedule must define the election process, export format, operational deletion and backup arrangements, and any confirmation of completion. Legally retained data must remain protected and restricted to the required purpose; the relevant basis and retention scope must be identified rather than treating all case records as permanently exempt.

14. Audits

Tourist SOS will make available to the Customer information reasonably necessary to demonstrate compliance with the obligations in this DPA, and will allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor mandated by the Customer, subject to reasonable advance notice and confidentiality protections. The parties may use appropriate documentation or remote review first where this adequately demonstrates compliance. Scope, timing, and any reasonable cost arrangements will be agreed without obstructing necessary verification, an investigation of a material concern, or a supervisory authority's powers. No routine frequency limit overrides mandatory audit rights or the applicable transfer clauses.

15. Liability & term

Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions in the adopted Agreement only to the extent permitted by law and any applicable transfer clauses. Nothing restricts non-waivable Data Subject rights or a regulator's powers. The data-protection obligations continue for as long as Tourist SOS retains or processes Customer Personal Data, including after the Services end where deletion, return, confidentiality, or required retention remains outstanding.

16. Contact

Questions about this DPA, or requests to execute a countersigned copy, Standard Contractual Clauses, a UK Addendum, or a UK IDTA, may be sent to our privacy contact at privacy@tourist-sos.com or our legal team at legal@tourist-sos.com. Privacy and data-subject requests may be sent to privacy@tourist-sos.com. Our mailing address is 401 Ryland Street, Ste 200A, Reno, NV 89502, USA.

This DPA is a proposed version dated July 1, 2026, prepared for owner and qualified legal review. Where a customer agreement requires different or additional terms (for example, a customer-supplied DPA or specific Standard Contractual Clauses module), the terms agreed in writing between the parties will control.