Executed copy
This executed copy of the JourneyFuse Data Processing Agreement is entered into on the date of signing below between JourneyFuse LLC, 5950 Yellowtail St, Timnath, CO 80547, United States ("JourneyFuse"), and [Customer], [Address], [Country] ("Customer"). It consists of the Data Processing Agreement published at journeyfuse.com/dpa (last updated September 8, 2026), reproduced in Part A, and the International Transfer Schedule in Part B, which the parties agree completes the transfer mechanism referred to in Section 6 of the DPA.
JourneyFuse has signed this document in advance. It takes effect when the Customer signs it, and neither party needs to take any further step.
Part A. Data Processing Agreement
Overview
This Data Processing Agreement ("DPA") supplements the JourneyFuse Terms of Service and forms part of the contract between JourneyFuse LLC ("Processor") and the Customer ("Controller") for processing of personal data on the JourneyFuse platform ("the Service").
This DPA applies whenever JourneyFuse processes personal data on behalf of a Customer, including personal data subject to the EU General Data Protection Regulation (GDPR), the UK GDPR, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act (CCPA/CPRA), and equivalent laws in other jurisdictions.
1. Roles
For data the Customer uploads to the Service about their clients, travelers, suppliers, and contacts, the Customer is the Controller and JourneyFuse is the Processor. For account-level data about the Customer's own users (workspace owners, admins, agents), JourneyFuse is an independent Controller as described in the Privacy Policy.
2. Subject Matter and Duration
JourneyFuse processes personal data only to provide and support the Service, for the duration of the Customer's subscription, plus a defined retention period for backups and legal compliance after termination.
3. Categories of Data and Data Subjects
Data subjects: the Customer's clients and travelers, the Customer's suppliers and contacts, and the Customer's own staff (workspace users).
Categories of personal data: contact details, traveler profile data, passport details, trip preferences and itineraries, communications, financial records (commissions, invoices), and tokenized payment references. Card numbers themselves are never processed by JourneyFuse, they are tokenized in-browser by Evervault before reaching JourneyFuse servers.
4. Processor Obligations
- Process personal data only on documented instructions from the Controller (the Service itself constitutes those instructions)
- Ensure personnel authorized to process personal data are bound by confidentiality
- Implement appropriate technical and organizational measures (described in Section 7)
- Assist the Controller with data subject requests and with notifications to supervisory authorities
- Delete or return personal data at the end of the engagement, subject to legal retention obligations
- Make available information necessary to demonstrate compliance and allow for audits as described in Section 9
5. Sub-processors
The Controller authorizes JourneyFuse to engage the sub-processors listed at /sub-processors. JourneyFuse remains responsible for sub-processor compliance.
JourneyFuse will provide advance notice via the sub-processors page and to account contacts before adding or replacing a sub-processor. The Controller may object on reasonable data-protection grounds; if a resolution cannot be reached, the Controller may terminate the affected portion of the Service.
6. International Data Transfers
JourneyFuse processes data on infrastructure located in the United States. Customers who require formal international data transfer mechanisms (including Standard Contractual Clauses for transfers from the EEA, UK, or Switzerland) can request them by emailing privacy@journeyfuse.com. We will work with the Customer to put the appropriate mechanism in place before any covered transfer begins.
7. Technical and Organizational Measures
- Encryption in transit: TLS 1.2+ on every connection
- Encryption at rest: AES-256 via Supabase; payment card data tokenized in-browser by Evervault and never stored by JourneyFuse
- Tenant isolation: Postgres Row-Level Security enforced at the database layer, keyed to the Customer's workspace, so that application-level defects alone do not permit cross-workspace access. Policies are version-controlled and covered by an automated test suite that exercises them against the live database
- Authentication: Supabase Auth with password hashing; TOTP-based two-factor authentication available and enforceable per workspace
- Access controls: production access is restricted to JourneyFuse's founder and explicitly authorized engineers
- Monitoring: Sentry for application errors with PII scrubbed; rate limiting via Upstash
- Backup and recovery: encrypted backups via Supabase
- Incident response: notification to affected Customers without undue delay, and in any case within 72 hours of confirmed personal data breach
JourneyFuse designs, tests, and monitors these measures as an ongoing practice and reviews them periodically. No software system can be guaranteed free of defects, and nothing in this Section is a warranty that a security control can never fail. The limitations of liability in the Terms of Service apply to this DPA.
8. Data Subject Requests
JourneyFuse provides self-serve access, correction, export, and deletion tools inside the Service. Where additional assistance is required to respond to a data subject request (access, rectification, erasure, restriction, portability, or objection under GDPR; access, deletion, correction, opt-out under CCPA), JourneyFuse will assist the Controller without undue delay. Requests can also be sent to privacy@journeyfuse.com.
9. Audits
JourneyFuse will make available to the Controller, on reasonable notice and no more than once per twelve-month period, the information necessary to demonstrate compliance with this DPA, including current sub-processor information, security documentation, and (where available) third-party audit reports from infrastructure providers.
10. Return or Deletion of Data
On termination of the Service, the Customer may export their data using built-in CSV export tools or by request. JourneyFuse will delete or anonymize personal data within 30 days of account closure, subject to legitimate legal retention obligations (financial records, fraud prevention, dispute resolution).
Part B. International Transfer Schedule
B1. EU Standard Contractual Clauses
For any transfer of personal data from the European Economic Area to JourneyFuse, and for any transfer to which B2 or B3 applies, the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (the "EU SCCs") are incorporated into this DPA by reference and form part of it. Module Two (controller to processor) applies where the Customer acts as controller, and Module Three (processor to processor) applies where the Customer acts as processor on behalf of another controller. The Customer is the data exporter and JourneyFuse is the data importer.
The parties make the following selections: Clause 7 (docking clause) applies. Clause 9(a), Option 2 (general written authorisation) applies, with notice of intended changes given as described in Section 5 of the DPA. The optional wording in Clause 11(a) does not apply. Clause 13: the supervisory authority is determined in accordance with Clause 13(a). Clause 17, Option 1: the EU SCCs are governed by the law of Ireland. Clause 18(b): disputes are resolved before the courts of Ireland.
Annex I of the EU SCCs is completed by Part B4 below, Annex II by Section 7 of the DPA, and Annex III by Part B5 below.
B2. UK International Data Transfer Addendum
For any transfer of personal data subject to the UK GDPR, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018 (version B1.0, in force 21 March 2022), including its Part 2 Mandatory Clauses as revised under its Section 18 (the "UK Addendum"), is incorporated into this DPA by reference and forms part of it.
Table 1 (Parties): the exporter is the Customer and the importer is JourneyFuse, with the details in Part B4. Table 2 (Selected SCCs, Modules and Selected Clauses): the Approved EU SCCs as incorporated and completed in B1, including the modules and selections stated there. Table 3 (Appendix Information): Annex 1A and 1B are Part B4, Annex II is Section 7 of the DPA, and Annex III is Part B5. Table 4 (Ending this Addendum when the Approved Addendum changes): neither party may end the UK Addendum under its Section 19.
B3. Switzerland
For any transfer of personal data subject to the Swiss Federal Act on Data Protection, the EU SCCs apply as incorporated in B1, with references to the GDPR read as references to the Swiss Federal Act on Data Protection, the Swiss Federal Data Protection and Information Commissioner as the competent supervisory authority for those transfers, and the term "member state" not interpreted so as to exclude data subjects in Switzerland from bringing a claim in their place of habitual residence.
B4. Description of the transfer (Annex I)
- Data exporter: [Customer], [Address], [Country]. Contact: [Name], [Email]. Role: controller (or processor, where Module Three applies). Activities: use of the JourneyFuse Service to run a travel business.
- Data importer: JourneyFuse LLC, 5950 Yellowtail St, Timnath, CO 80547, United States. Contact: Tim Peterson, Owner, privacy@journeyfuse.com. Role: processor. Activities: providing the JourneyFuse Service.
- Categories of data subjects, and categories of personal data: as set out in Section 3 of the DPA.
- Sensitive data: passport details, and any dietary, accessibility or health information the Customer chooses to record about travelers. Protected by the measures in Section 7 of the DPA.
- Frequency of the transfer: continuous, for as long as the Customer uses the Service.
- Nature and purpose of the processing: hosting, storing and processing personal data to provide and support the Service, as set out in Sections 2 and 4 of the DPA.
- Retention: for the duration of the Customer’s subscription, then deleted or anonymized as set out in Section 10 of the DPA.
- Transfers to sub-processors: to the sub-processors in Part B5, for the purposes and data stated there, for the duration of the Service.
- Competent supervisory authority: as determined under Clause 13 of the EU SCCs. For transfers under B2, the UK Information Commissioner.
B5. Sub-processors (Annex III)
The Customer authorizes the following sub-processors, as listed at journeyfuse.com/sub-processors on the date of signing below. Changes follow Section 5 of the DPA.
- Supabase: Primary database (Postgres), authentication, file storage. Data: Workspace data, client records, trip data, account credentials, uploaded files. Location: United States (AWS).
- Vercel: Web application hosting and edge delivery. Data: Application traffic, request logs. Location: United States and global edge.
- Evervault: PCI DSS Level 1 card tokenization for client payment authorizations. Data: Credit card numbers, CVV (tokenized in-browser, never on JourneyFuse servers). Location: United States and EU.
- Stripe: JourneyFuse subscription billing and planning fee collection. Data: Billing contact, payment method tokens. Location: United States.
- Resend: Transactional and outbound email delivery. Data: Email addresses, message contents sent through the Service. Location: United States.
- Sentry: Application error monitoring (PII scrubbed before transmission). Data: Error stack traces, anonymized request metadata. Location: United States.
- Upstash: Rate limiting and ephemeral cache. Data: Request fingerprints, short-lived session tokens. Location: United States and EU.
- Mapbox: Map tiles and geocoding for itinerary maps. Data: Location queries, IP address. Location: United States.
- OpenAI: AI features under no-training terms: proposal and itinerary generation, email drafting, passport photo OCR, commission-statement extraction. Data: Only the specific text or image submitted for that request; not retained for model training. Location: United States.
- Google (Places API): Address autocomplete, place lookups, and place photos for itinerary planning. Data: Search queries and place identifiers, no personally identifiable customer data sent. Location: United States.
B6. Order of precedence
If there is any conflict between the EU SCCs or the UK Addendum and the rest of this DPA or the Terms of Service, the EU SCCs or the UK Addendum prevail. Nothing in the DPA or the Terms of Service limits either party’s liability to data subjects under the EU SCCs or the UK Addendum where those instruments do not permit it to be limited.
The signed PDF is emailed to you and to JourneyFuse LLC. Your IP address and the time of signing are recorded with the signature.