Last updated: 2 October 2026
Data processing agreement
Courtesy translation. If there is any discrepancy, the Portuguese version prevails.
This agreement, under Article 28 of the General Data Protection Regulation (GDPR), forms part of the terms of service. The customer (the transfer company) is the controller; RIGOTTOUR – TRANSFER ALGARVE, UNIPESSOAL, LDA ("processor") processes data on the customer’s behalf to provide Paxtio.
1. Subject and duration
The processor processes personal data only to provide the contracted service, for the duration of the subscription and for the export and deletion period set out below.
2. Data and data subjects
- Data subjects: the customer’s passengers and clients, drivers, staff and suppliers.
- Data: name, contact details (email, phone), trip details (addresses, dates, flights, number of passengers), notes, amounts and payment status, users’ login data and, for drivers and vehicles, documents and expiry dates.
- The service is not intended for special categories of data (Article 9 GDPR). The customer must not enter such data.
3. Processor obligations
- Process the data only on the customer’s documented instructions, given through use of the system and these terms.
- Ensure that anyone with access to the data is bound by confidentiality.
- Apply appropriate technical and organisational measures: separation of each customer’s data in the database with access rules by company and role, encrypted connections, backups, access logging and internal access limited to what is necessary.
- Help the customer respond to data subject requests (access, rectification, erasure, portability), in particular through the system’s features and exports.
- Notify the customer without undue delay, and where possible within 48 hours, after becoming aware of a personal data breach affecting it.
- Help the customer with impact assessments and consultations with the supervisory authority, where necessary.
- At the end of the contract, allow the data to be exported for 30 days and then delete it, unless the law requires it to be kept.
- Make available the information needed to demonstrate compliance with this agreement and allow reasonable audits, with prior notice.
4. Sub-processors
The customer authorises the use of the following sub-processors, bound by equivalent data protection obligations:
| Sub-processor | Activity | Location |
|---|---|---|
| Supabase Inc. | Database and authentication | European Union (Paris, France) |
| Vercel Inc. | Hosting of the website and the system | European Union and USA (standard contractual clauses) |
| Resend Inc. | Sending emails (vouchers, notices, invitations) | USA (standard contractual clauses) |
| Stripe Payments Europe Ltd. | Subscription payments and card payments for bookings | European Union (Ireland) |
| Google Ireland Ltd. | Maps and address search | European Union (Ireland) |
We give the customer 30 days’ notice before adding or replacing a sub-processor; the customer may object and, in that case, cancel at no cost.
5. International transfers
The database is in the European Union. When a sub-processor processes data outside the European Economic Area, the transfer is based on an adequacy decision or on the European Commission’s standard contractual clauses.
6. Customer obligations
- Ensure a legal basis for the data it enters and inform data subjects (for example, in its privacy policy and booking conditions).
- Manage its users’ access and remove access for anyone who stops working with it.
7. Contact
Data protection questions: support@paxtio.com.