Data Processing Addendum
Last updated: March 2026 · TUTU VIEW Ltd
This Data Processing Addendum ("Addendum" or "DPA") forms part of, and is incorporated into, the agreement between TUTU VIEW Ltd and the counterparty identified in the relevant agreement (the "Agreement").
This Addendum applies only to the extent that TUTU VIEW Ltd acts as a Data Processor or Sub-Processor on behalf of the other party under the Agreement.
1. Definitions and Interpretation
1.1 Capitalised terms not otherwise defined in this Addendum shall have the meanings given to them in the Agreement or under applicable Data Protection Laws.
1.2 "Data Protection Laws" means all applicable data protection and privacy laws, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the EU GDPR (where applicable), and any implementing or supplementary legislation.
1.3 For the purposes of this Addendum:
- "Controller", "Processor", "Sub-Processor", "Personal Data", "Processing" and "Special Category Data" shall have the meanings given under applicable Data Protection Laws.
- "PTS" means Protected Trust Services, the financial protection scheme of which TUTU VIEW Ltd is a member (membership number [PTS MEMBERSHIP NUMBER]), and whose trust account administration may require the processing of limited personal data in accordance with PTS membership obligations.
2. Scope and Roles of the Parties
2.1 The parties acknowledge that, depending on the nature of the services provided under the Agreement:
- (a) the Client may act as a Controller and TUTU VIEW Ltd may act as a Processor; or
- (b) the Client may act as a Processor and TUTU VIEW Ltd may act as a Sub-Processor.
2.2 Where TUTU VIEW Ltd acts as a Processor or Sub-Processor, it shall process Personal Data solely on behalf of, and in accordance with the documented instructions of, the Client, unless required to do otherwise by applicable law.
3. Compliance with Data Protection Laws
3.1 Each party shall comply with its respective obligations under applicable Data Protection Laws.
3.2 TUTU VIEW Ltd shall:
- (a) process Personal Data only on documented instructions from the Client;
- (b) ensure that persons authorised to process Personal Data are subject to appropriate confidentiality obligations;
- (c) not use Personal Data for its own purposes.
4. Technical and Organisational Measures
4.1 TUTU VIEW Ltd shall implement appropriate technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data.
4.2 Such measures are further described in Appendix 1 (Security Measures).
5. Sub-Processing
5.1 The Client grants TUTU VIEW Ltd a general authorisation to engage Sub-Processors for the performance of the services.
5.2 TUTU VIEW Ltd shall:
- (a) provide prior written notice of any intended changes concerning the addition or replacement of Sub-Processors; and
- (b) allow the Client a reasonable opportunity to object on reasonable data protection grounds.
5.3 TUTU VIEW Ltd shall ensure that any Sub-Processor is subject to data protection obligations no less protective than those set out in this Addendum.
5.4 The Client acknowledges that TUTU VIEW Ltd is required, as a condition of its PTS membership (membership number [PTS MEMBERSHIP NUMBER]), to share limited booking and payment data with PTS for the purpose of operating the Protected Trust Account. Such sharing constitutes a legal and contractual obligation on TUTU VIEW Ltd and shall not require separate Client consent under this Addendum.
6. International Data Transfers
6.1 Where Personal Data is transferred outside the United Kingdom or the European Economic Area, including to service suppliers located in the People's Republic of China, such transfers shall be made in accordance with applicable Data Protection Laws.
6.2 The parties agree that such transfers shall be governed by:
- (a) the UK International Data Transfer Addendum to the EU Standard Contractual Clauses; or
- (b) the EU Standard Contractual Clauses, as applicable.
7. Assistance to the Client
7.1 TUTU VIEW Ltd shall provide reasonable assistance to the Client in responding to data subject rights requests, data protection impact assessments, and regulatory inquiries, to the extent required by applicable law.
8. Personal Data Breaches
8.1 TUTU VIEW Ltd shall notify the Client without undue delay upon becoming aware of a Personal Data Breach affecting Personal Data processed under this Addendum.
9. Audits and Information
9.1 TUTU VIEW Ltd shall make available to the Client information reasonably necessary to demonstrate compliance with this Addendum.
9.2 Audits shall be limited in scope and frequency and subject to reasonable confidentiality and security requirements.
10. Return or Deletion of Personal Data
10.1 Upon termination or expiry of the services, TUTU VIEW Ltd shall, at the Client's choice, return or delete Personal Data, unless retention is required by applicable law.
11. Liability
11.1 Liability arising from this Addendum shall be subject to the limitations and exclusions of liability set out in the Agreement.
12. Governing Law and Jurisdiction
12.1 This Addendum shall be governed by and construed in accordance with the laws of England and Wales.
12.2 The courts of England and Wales shall have exclusive jurisdiction.
Appendix 1 – Security Measures
TUTU VIEW Ltd maintains internal technical and organisational security measures, including:
- access controls and role-based access restrictions;
- secure communication channels;
- internal data protection and IT security policies;
- staff confidentiality obligations;
- reasonable measures to prevent unauthorised access or disclosure.
Appendix 2 – Details of Processing
Data Subjects: Customers / Guests; system users.
Categories of Personal Data:
- Identification and contact information;
- Travel and booking information;
- Special category data including dietary requirements, health or medical information, and religious beliefs, where strictly necessary for travel arrangements;
- Booking and payment reference data shared with Protected Trust Services (PTS) for the administration of the Protected Trust Account, in accordance with TUTU VIEW Ltd's PTS membership obligations.
Purpose of Processing: Provision and coordination of travel-related services and itinerary design.
Retention:
- Enquiry data: up to 24 months;
- Unsuccessful enquiries: 12–24 months;
- Booking records: up to 7 years;
- Marketing data: until consent is withdrawn;
- Legal claims: for the duration of the claim and applicable limitation periods.
International Transfers: United Kingdom to service suppliers located in China, subject to appropriate safeguards.
Signed for and on behalf of TUTU VIEW Ltd (trading as Nihaoserica)