Перейти к основному содержанию

Data Processing Agreement

This Data Processing Agreement (the “DPA”) supplements the Commercial Agreement, the Reseller Agreement or any other agreement in force between LIVA DOT COM (ASIA) CO., LTD. (“LIVA.COM”) and the operator or partner accepting it (the “Counterparty”) (together, the “Principal Agreement”).

It applies whenever one party processes personal data on behalf of the other in connection with the Principal Agreement. Where this DPA conflicts with the Principal Agreement on a matter of data protection, this DPA prevails.

1. Definitions

“Applicable Data Protection Law” means the Personal Data Protection Act B.E. 2562 (2019) of Thailand (“PDPA”), Regulation (EU) 2016/679 (“GDPR”) where it applies, and any other data protection law applicable to a party’s processing under the Principal Agreement.
“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing” and “Personal Data Breach” have the meanings given in the GDPR, and the equivalent meanings under the PDPA.
“Data Controller” under the PDPA is treated as equivalent to Controller, and “Data Processor” as equivalent to Processor.
“Sub-processor” means a third party engaged by a Processor to carry out processing on the Controller’s behalf.

2. Roles of the parties

The parties record that, in the ordinary operation of the Principal Agreement, each party acts as an independent Controller in respect of the Personal Data it holds for its own purposes. LIVA.COM is a Controller for the booking transaction and its own customer relationship; the Counterparty is a Controller for the performance of its own services and its own legal obligations.

Neither party is the other’s Processor by default. A processing relationship arises only where the parties have agreed in writing that one party processes specified Personal Data on the other’s behalf and on that party’s instructions. Where that is the case, clauses 3 to 12 apply, with the instructing party as Controller and the other as Processor.

The transfer of Personal Data between two independent Controllers is not a disclosure to a Processor. Each party is responsible for its own lawful basis, its own transparency notice and its own retention.

3. Subject matter and details of processing

Where a processing relationship arises, its subject matter, duration, nature and purpose are those set out in the Principal Agreement and in the written instruction that creates it.

Unless the parties record otherwise in writing, the details are:

  • Categories of Data Subject: passengers and travellers; the Counterparty’s and LIVA.COM’s staff and contact persons.
  • Types of Personal Data: name; contact details; booking, journey and itinerary details; passenger manifest details required by the carrier or by law; payment reference and status; correspondence relating to a booking; and any identification or travel-document data that law requires for the journey.
  • Duration: the term of the Principal Agreement and any period for which retention is required by law.
  • Special category data: not processed under this DPA, unless a party is required by law to process accessibility, medical-assistance or similar information in order to carry a passenger safely, in which case it does so as an independent Controller under its own lawful basis.

4. Processor obligations

Where acting as Processor, a party shall:

  • process the Personal Data only on the Controller’s documented instructions, including as to international transfers, unless required to do otherwise by law — in which case it shall inform the Controller before processing, unless that law prohibits it;
  • immediately inform the Controller if, in its opinion, an instruction infringes Applicable Data Protection Law;
  • ensure that persons authorised to process the Personal Data are bound by an appropriate obligation of confidentiality;
  • not sell the Personal Data, and not use it for its own purposes, including its own marketing or the training of any model, at any time.

5. Security

Each party shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking account of the state of the art, the costs of implementation and the nature, scope, context and purposes of processing.

Those measures shall include, as appropriate: pseudonymisation and encryption; encryption of Personal Data in transit over public networks; access control on a least-privilege basis with individual accounts and no shared credentials; logging of access to Personal Data; the ability to restore availability after an incident; and a process for regularly testing and evaluating the effectiveness of the measures.

6. Sub-processors

A Processor shall not engage a Sub-processor without the Controller’s prior written authorisation, which may be general. Where authorisation is general, the Processor shall inform the Controller of any intended addition or replacement, giving the Controller a reasonable opportunity to object before the change takes effect.

The Processor shall impose on each Sub-processor, by contract, data protection obligations no less protective than those in this DPA, and remains fully liable to the Controller for the Sub-processor’s performance.

7. Data Subject rights

Each party shall handle requests from Data Subjects in respect of the Personal Data it holds as Controller.

Where acting as Processor, a party shall, taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller’s obligation to respond to requests to exercise rights of access, rectification, erasure, restriction, portability and objection.

A party that receives a request relating to Personal Data for which the other is Controller shall forward it to that party without undue delay and shall not respond to it substantively itself, unless legally required to do so.

8. Personal Data Breach

A party shall notify the other without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Personal Data processed under the Principal Agreement.

The notification shall describe, so far as known: the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Information that is not available at the time may be provided in phases without undue further delay.

Neither party shall make a public statement identifying the other in connection with a breach without first consulting that party, except where required by law or by a supervisory authority.

9. Assistance

Where acting as Processor, a party shall provide the Controller with reasonable assistance in carrying out data protection impact assessments and any prior consultation with a supervisory authority, taking into account the nature of the processing and the information available to it.

10. Deletion and return

On termination of the Principal Agreement, or when the processing purpose ends, a Processor shall at the Controller’s choice delete or return the Personal Data and delete existing copies, unless law requires it to retain the data — in which case it shall retain it only for the period and purpose that law requires, and shall continue to protect it under this DPA.

Each party as Controller shall apply its own retention schedule to the Personal Data it holds for its own purposes.

11. Audit and information

Where acting as Processor, a party shall make available to the Controller the information necessary to demonstrate compliance with this clause and with Applicable Data Protection Law, and shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates.

Audits shall be on reasonable prior written notice of not less than thirty (30) days, no more than once in any twelve-month period unless a Personal Data Breach or a supervisory authority requires otherwise, during business hours, and subject to confidentiality. The auditing party shall bear its own costs and shall not unreasonably disrupt the audited party’s operations.

12. International transfers

Neither party shall transfer Personal Data processed under the Principal Agreement outside the country in which it was collected unless a lawful transfer mechanism is in place.

Where the GDPR applies, that means an adequacy decision, Standard Contractual Clauses, or another mechanism permitted under Chapter V of the GDPR. Where the PDPA applies, that means a mechanism permitted under sections 28 and 29 of the PDPA. Each party shall provide the other, on request, with evidence of the mechanism it relies on.

The parties acknowledge that performing a journey inherently requires the Counterparty to receive passenger details in the country of travel, and that this is a transfer for the performance of a contract with the Data Subject.

13. Liability

Each party is responsible for its own compliance with Applicable Data Protection Law and for any administrative fine or claim arising from its own act or omission.

Liability under this DPA is subject to the limitations and exclusions in the Principal Agreement, save that nothing limits a liability that cannot lawfully be limited, including liability to a Data Subject or to a supervisory authority.

14. Term and changes

This DPA takes effect when accepted and continues for as long as either party processes Personal Data in connection with the Principal Agreement.

LIVA.COM may publish a new version to reflect a change in Applicable Data Protection Law or in the processing. The portal will show the new version as requiring acceptance and will record which version was accepted, when and by whom.

15. Language, law and precedence

This DPA is drawn up in English; any translation is for convenience and the English version prevails.

It is governed by the law stated in the Principal Agreement. It does not vary the Principal Agreement other than on matters of data protection, where it prevails.

If any provision is held invalid or unenforceable, the remainder continues in force.