Last Updated: September 29, 2026
This Data Processing Addendum (“DPA”) forms part of the Sojern Terms and Conditions or other written agreement by and between Sojern and Customer for the provision of the Sojern Services (“Agreement”). All capitalized terms not defined in this DPA will have the meanings set forth in the Agreement.
1. Scope
- Customer Data Processing Agreement (Soern as a Processor). With respect to Service Data that constitutes Personal Data (“Service Personal Data”), (a) Customer is the “controller” and “business” (as such terms are defined under applicable Data Protection Law), (b) Sojern is the “processor” and “service provider” (as such terms are defined under applicable Data Protection Law), and (c) Section A of this DPA applies. “Personal Data” means “personal data,” “personal information,” “personally identifiable information,” or any analogous term under applicable Data Protection Law.
- Data Processing Agreement (Sojern as Controller). To the extent agreed upon between the parties, Sojern and its Affiliates may process Service Personal Data for the following business purposes: (a) for accounting, tax, billing, audit and compliance purposes, (b) to provide, improve, develop, optimize and maintain the Sojern Services, (c) to investigate fraud, spam, wrongful or unlawful use of the Sojern Services, (iv) to create analytics, reports and audiences, as permitted under the Agreement; and (d) as otherwise permitted or required by applicable law. In these scenarios, Sojern and Customers are independent controllers, and Section B of this DPA applies.
- Compliance. Each party will comply with its respective obligations under applicable privacy and data protection law (“Data Protection Law”) in connection with the Sojern Services and Service Personal Data.
- Conflicts in Interpretation. If there is any inconsistency or conflict between terms of this DPA and the other terms of the Agreement, the terms of this DPA will control to the extent of such inconsistency or conflict.
SECTION A – Customer Data Processing Agreement (Sojern as Processor)
1. Scope
- Scope of Processing. The subject matter, nature and purpose of Sojern’s processing of Service Personal Data, the types of Service Personal Data processed by Sojern, and categories of applicable data subjects are set out in Schedule I-A.
2. Service Personal Data
- Service Personal Data Processing. Sojern will only process Service Personal Data to provide the Sojern Services and in accordance with Customer’s documented instructions as set forth in this DPA, the Agreement, or otherwise provided by Customer to Sojern in writing (“Documented Instructions”). Customer may issue additional instructions to Sojern as necessary to comply with applicable Data Protection Law. Unless prohibited by applicable law, Sojern will inform Customer if Sojern is subject to a legal obligation that requires Sojern to process Service Personal Data in contravention of Customer’s Documented Instructions.
- Sojern Responsibilities. Sojern will not (a) “sell” or “share” (as such terms are defined in the California Consumer Privacy Act) Service Personal Data, (b) retain, use, or disclose Service Personal Data for any purpose other than in accordance with the Documented Instructions, (c) retain, use, or disclose Service Personal Data outside of the direct business relationship between Sojern and Customer, nor (d) except as otherwise permitted under applicable Data Protection Law, combine Service Personal Data with personal data that Sojern receives from or on behalf of any third party.
- Personnel. Sojern will ensure that all personnel and Subprocessors that process Service Personal Data are subject to a contractual or statutory obligation of confidentiality. Sojern will regularly train personnel regarding Sojern’s obligations under this DPA and applicable Data Protection Law.
3. Subprocessors
- Authorization. Customer hereby authorizes Sojern to engage the subprocessors as set forth at www.sojern.com/legal/partner-list/ (“Subprocessors”). Sojern will (a) enter into a contractual agreement with each Subprocessor that imposes obligations that are as protective as Sojern’s obligations under this DPA and (b) remain responsible for the acts and omissions of the Subprocessors’ processing of Service Personal Data under this DPA. consistent with the limitation of liability provided in the Agreement.
- Notice of New Subprocessors. Customer can subscribe to the RSS feed at www.sojern.com/legal/partner-list/ to receive notification about changes to Sojern’s Subprocessors list. Customer may object to the appointment of such new Subprocessor within 30 days of the date of such notice by providing Sojern written notice of its objection at sojernprivacy@sojern.com with subject line “Sub-processor Objection,” along with a contact’s name, company’s name, name of the Sojern product or service, name of the sub-processor, and a justifiable ground for objection. If Customer objects to Sojern’s appointment of a new Subprocessor, Customer and Sojern will work together in good faith to address any such objection.
4. Assistance
- Data Subject and Consumer Rights. Sojern will (a) promptly forward to Customer any request it receives from “data subjects” or “consumers” (as such terms are defined under applicable Data Protection Law) to exercise their rights under applicable Data Protection Law relating to Service Personal Data, (b) advise such data subjects and consumers to submit such requests directly to Customer, and (c) provide Customer with reasonable assistance as necessary for Customer to fulfil its obligations under applicable Data Protection Law to respond to such requests.
- Cooperation. Taking into account the nature of the processing, Sojern shall assist Customer, including by implementing appropriate technical and organizational measures, with the fulfilment of its obligations under applicable Data Protection Law, including (a) replying to investigations and inquiries from regulatory authorities and conducting data protection impact assessments, (b) notifying personal data breaches, and (c) ensuring that personal data is accurate, by informing Customer if Sojern becomes aware that personal data is inaccurate or has become outdated. Unless prohibited by applicable law, Sojern must obtain Customer’s written authorization before responding to, or complying with any requests, orders, or legal obligations referred to in Section 4.
5. Security
- Security Measures. Sojern has implemented and will maintain reasonable and appropriate technical and organizational security measures designed to protect the security of Service Personal Data as described in Schedule I-A of this DPA (“Security Measures”). The parties acknowledge that the Security Measures provide an appropriate level of security for the risks of the processing of Service Personal Data under the Agreement. Sojern may update or modify the Security Measures provided that such updates and modifications do not materially decrease the overall security of the Sojern Services.
- Audit Reports and Certifications. Sojern is audited annually against known, established industry standards performed by external auditors. Upon Customer’s written request, Sojern will provide Customer with Sojern’s audit reports or certifications applicable to the Sojern Services (e.g., SOC 2 Tye 2, ISO, NIST or other similar audit report), or other information reasonably necessary to demonstrate compliance with this DPA.
- Audits. Upon Customer’s written request, no more than once every 12 months, Sojern will permit Customer to audit Sojern’s controls applicable to its processing of Service Personal Data and compliance with this DPA (“Audit”), provided that such Audit is (a) conducted by Customer or a third-party auditor designated by Customer that has executed an appropriate confidentiality agreement with Sojern, (b) conducted at Customer’s sole cost, (c) during normal business hours, (d) in a manner that causes minimal disruption, and (e) in accordance with mutually agreed upon scope and terms, including the start date, scope and duration of, and security and confidentiality controls applicable to, such audit. Customer may use the results of an Audit only for the purposes of meeting Customer’s regulatory audit requirements and/or confirming compliance with the requirements of this DPA.
6. International Data Transfers
- Data Transfers. Customer authorizes Sojern to conduct transfers of Service Personal Data to countries deemed to have an adequate level of data protection by the European Commission or the applicable competent regulatory authority on the basis of adequate safeguards in accordance with applicable privacy and data protection laws or pursuant to (a) the contractual clauses annexed to the European Commission’s Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of Personal Data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, as amended, superseded, or replaced from time to time (“EU SCCs”), or (b) the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner, Version B1.0, in force 21 March 2022, as amended, superseded or replaced from time to time (“UK Addendum”).
- EU Data Transfers. For transfers of Service Personal Data from the European Union, Customer and Sojern conclude Module 2 (controller to processor) and/or Module 3 (processor to subprocessor) of the EU SCCs, which are incorporated herein and completed as follows: (a) the “data exporter” is Customer, (b) the “data importer” is Sojern, (c) the optional docking clause in Clause 7 is implemented, (d) option 2 of Clause 9(a) is implemented and the time period therein is specified in Section 3.2, (e) the optional redress clause in Clause 11(a) is struck; (f) option 1 in Clause 17 is implemented, (g) the governing law is the law of Ireland and the courts in Clause 18(b) are the Courts of Dublin, Ireland, and (h) Annex I to module 4 of the EU SCCs is Schedule I-A to this DPA. For transfers of Service Personal Data from Switzerland, any dispute arising from these EU SCCs relating to Swiss data protection laws will be resolved by the courts of Switzerland and data subjects who have their habitual residence in Switzerland may bring claims under the EU SCCs before the courts of Switzerland.
- UK Data Transfers. For transfers of Service Personal Data from the United Kingdom, Customer and Sojern conclude the UK Addendum, which is incorporated herein and completed as follows: (a) in Table 1, the “Exporter” is Customer and the “Importer” is Sojern, their details are set forth in this DPA and the Agreement, (b) in Table 2, the first option is selected and the “Approved EU SCCs” are the EU SCCs referred to in Section 6.2, (c) in Table 3, Annexes 1 (A and B) and II to the “Approved EU SCCs” are Schedule I-A, and (d) in Table 4, both the “Importer” and the “Exporter” can terminate the UK Addendum.
SECTION B – Data Processing Agreement (Sojern as Controller)
1. Scope
- Roles of Parties. With respect to Personal Data, each party is a separate “controller” and “business” (as such terms are defined under applicable Data Protection Law). For the avoidance of doubt, the DPA does not establish or confirm a joint-controller or a controller-processor relationship between the parties.
- Scope of Processing. The subject matter, nature and purpose of Sojern’s processing of Personal Data, the types of Personal Data processed by Sojern, and categories of applicable data subjects are set out in Schedule I-B.
- Conflicts in Interpretation. If there is any inconsistency or conflict between terms of this DPA and the other terms of the Agreement, the terms of this DPA will control to the extent of such inconsistency or conflict.
2. Obligation of the Parties
- Compliance with law. Each party shall comply with its respective obligations under applicable Data Protection Law.
- Records and Cooperation for Compliance. Each party will reasonably cooperate with the other party in complying with applicable Data Protection Law to (a) maintain a records of processing of Personal Data to the extent required by applicable Data Protection Law, (b) conduct data protection impact assessments; (c) handle requests or consultations with data protection authorities, and (d) conduct audits in accordance with the Agreement.
- Notice. The parties acknowledge that Sojern does not maintain a direct relationship with the data subjects whose Personal Data is provided to Sojern. As such, where required by applicable Data Protection Law, Customer will make available the Sojern Privacy Policy available at https://www.sojern.com/privacy/privacy-policy/ to these data subjects.
- Consent and Opt-Out. Customer shall provide notice to, and obtain consents from, individuals as required by applicable Data Protection Law regarding Customer’s collection, use, and disclosure of Personal Data. If applicable Data Protection Law requires mechanisms by which individuals may exercise rights, including but not limited to opt-out rights, Customer (or such other party who is responsible for the collection of Personal Data on behalf of Customer), shall provide such mechanism to individuals. Customer will be presumed to have provided appropriate notices and have obtained appropriate consents, if required, from any individuals whose Personal Data is provided to Sojern. Customer shall promptly provide, upon request and at any time by Sojern, proof that appropriate consents have been obtained by Customer from relevant individuals.
3. Assistance
- Data Subject and Consumer Rights. Each party will reasonably cooperate with the other party in response to any requests or complaints from individuals relating to the processing of Personal Data under the Agreement and pertaining to privacy rights under applicable Data Protection Law. If Sojern receives a request from an individual, Sojern will promptly: (a) forward the request to Customer to manage the request and (b) where Sojern is a data processor, implement Customer’s decision with respect to how the request will be managed.
4. Security
- Parties Obligations. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the parties shall implement appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk.
- Sojern. Sojern has implemented and will maintain reasonable and appropriate technical and organizational security measures designed to protect the security of Service Personal Data as described in Schedule I-B of this DPA (“Security Measures”). Sojern may update or modify the Security Measures provided that such updates and modifications do not materially decrease the overall protection of Personal Data.
- Personal Data Breach. The parties will notify each other without undue delay after becoming aware of a personal data breach (as defined under applicable Data Protection Law) affecting Personal Data processed in the context of the DPA or the Agreement.
5. International Data Transfers
- Data Transfers. The parties agree that Sojern may conduct transfers of Personal Data to countries deemed to have an adequate level of data protection by the European Commission or the applicable competent regulatory authority on the basis of adequate safeguards in accordance with applicable Data Protection Law or pursuant to (a) the contractual clauses annexed to the European Commission’s Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of Personal Data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, as amended, superseded, or replaced from time to time (“EU SCCs”) or (b) the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner, Version B1.0, in force 21 March 2022, as amended, superseded or replaced from time to time (“UK Addendum”).
- EU Data Transfers. For transfers of Personal Data from the European Union, Customer and Sojern conclude Module 1 (controller to controller) of the EU SCCs, which are incorporated herein and completed as follows: (a) the “data exporter” is Customer, (b) the “data importer” is Sojern, (c) the optional docking clause in Clause 7 is implemented, (d) option 2 of Clause 9(a) is implemented and the time period therein is specified in Section 3.2, (e) the optional redress clause in Clause 11(a) is struck, (f) option 1 in Clause 17 is implemented, (g) the governing law is the law of Ireland and the courts in Clause 18(b) are the Courts of Dublin, Ireland, and (h) Annex I to module 4 of the EU SCCs is Schedule I-B to this DA. For transfers of Personal Data from Switzerland, any dispute arising from these EU SCCs relating to Swiss data protection laws will be resolved by the courts of Switzerland and data subjects who have their habitual residence in Switzerland may bring claims under the EU SCCs before the courts of Switzerland.
- UK Data Transfers. For transfers of Personal Data from the United Kingdom, Customer and Sojern conclude the UK Addendum, which is incorporated herein and completed as follows: (a) in Table 1, the “Exporter” is Customer and the “Importer” is Sojern, their details are set forth in this DPA and the Agreement, (b) in Table 2, the first option is selected and the “Approved EU SCCs” are the EU SCCs referred to in Section 6.2, (c) in Table 3, Annexes 1 (A and B) and II to the “Approved EU SCCs” are Schedule I-B, and (d) in Table 4, both the “Importer” and the “Exporter” can terminate the UK Addendum.
Schedule I - A
Description of Processing
1. List of Parties
Data exporter:
Name: Customer
Activities relevant to the data transferred under these Clauses: As described in the Agreement
Role (controller/processor): Controller or Processor
Data importer:
Name: Sojern
Activities relevant to the data transferred under these Clauses: As described in the Agreement
Role (controller/processor): Processor or Subprocessor
2. Categories of Data Subjects
- Marketing prospects
- Customer’s own guests, customers, website visitors, or mobile app visitors
- End-users and other users of Customer’s products and services
3. Categories of Personal Data Transferred
Service Personal Data, the content of which is determined and controlled by Customer, including:
- Contact information (e.g., name, home and/or business address, email address, telephone details and other contact information)
- Booking and stay information (end users’ booking details and dates, stay preferences, and user ratings and reviews)
- Messaging information (e.g., the contents of messages between Customer and end users, contained in email, SMS, or other messaging channels)
4. Sensitive Data Transferred (If Applicable)
Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures: N/A.
5. Frequency of the Transfer
The frequency of the transfer (e.g. whether the Service Personal Data is transferred on a one-off or continuous basis): On a continuous basis.
6. Nature of the Processing
The Service Personal Data will be processed and transferred as described in the Agreement and DPA.
7. Purpose(s) of the transfer and further processing
The Service Personal Data will be transferred and further processed for the provision of the Sojern Services as described in the Agreement and DPA.
8. Duration of Processing
Service Personal Data will be retained for as long as necessary taking into account the purpose of the processing, and in compliance with applicable laws, including laws on the statute of limitations and applicable Data Protection Law.
9. Sub-Processor Transfers
For international data transfer to (Sub)processors, also specify subject matter, nature and duration of the processing: For the subject matter and nature of the processing, reference is made to the Agreement and DPA. The processing will take place for the duration of the Agreement.
10. Competent Supervisory Authority
The competent authority for the processing of Service Personal Data relating to data subjects located in the EEA is the regulatory authority of Ireland.
The competent authority for the processing of Service Personal Data relating to data subjects located in the UK is the UK Information Commissioner.
The competent authority for the processing of Service Personal Data relating to data subjects located in Switzerland is the Swiss Federal Data Protection and Information Commissioner.
11. Technical and Organizational Measures
Sojern implements the following security measures:
- General. Sojern will establish, implement, and maintain appropriate administrative, technical and organizational measures that are designed to protect against unauthorized or unlawful processing of Service Personal Data and against accidental loss or destruction of, or damage to, Service Personal Data. These measures will be adequate to comply with applicable Data Protection Law and Sojern will comply at all times with its information security policies and information security program.
- Information Security Policies and Standards. Sojern will maintain information security policies, standards, and procedures. These policies, standards, and procedures shall be kept up to date, and revised whenever relevant changes are made to the information systems that use or store Service Personal Data.
- Vulnerability Management. Sojern will maintain a vulnerability management program for all systems that process Service Personal Data that includes without limitation internal and external vulnerability scanning with risk rating findings and formal remediation plans to address any identified vulnerabilities.
- Risk Assessment. Sojern will conduct periodic risk assessments to identify and assess reasonably foreseeable risks to the security, confidentiality, and integrity of records containing Service Personal Data and evaluate and improve, where necessary, the effectiveness of its safeguards for limiting those risks.
- Data Classification. Sojern will maintain policies and procedures to classify sensitive information assets, clarify security responsibilities, and promote awareness for all employees.
- Encryption. Sojern will implement industry standard encryption mechanisms and strong cipher suites (AES 256- bit is recommended) for storage and transmission. Sojern will accept connections over encrypted channels (TLS is recommended).
- Network Security. Sojern will secure its network by employing a defense-in-depth approach that utilizes commercially available equipment and industry standard techniques, including without limitation firewalls, intrusion detection systems, access control lists, and routing protocols.
- Virus and Malware Controls. Sojern will protect Service Personal Data from malicious code and will install and maintain anti-virus and malware protection software on any system that handles Service Personal Data.
- Access Control. Sojern will practice the principle of least privilege where access to Service Personal Data is only granted to those within the organization who have a business need for such access and permissions will be limited to the minimum amount required to perform the specific job function.
- Processing Location. Service Personal Data will be processed by Sojern in the United States, subject to applicable Data Protection Law that may require otherwise.
- Incident Response. Sojern will maintain a data security incident response program and will document all suspected data security incidents. Sojern will investigate any data security incidents and take all necessary steps to eliminate or contain the data security incident.
- Personnel. Sojern will maintain an information security awareness and training program and will train critical Sojern personnel on data protection measures and general cybersecurity protections.
- Vendor. Sojern will maintain a vendor management program that will assess all vendors with whom Sojern exchanges Service Personal Data. Such vendors will be held to data security standards no less restrictive than those set forth herein.
12. Subprocessors.
Subprocessors are listed at www.sojern.com/legal/partner-list/.
Schedule I - B
Description of Processing
1. List of Parties
Data exporter:
Name: Customer
Activities relevant to the data transferred under these Clauses: As described in the Agreement.
Role (controller/processor): Controller
Data importer:
Name: Sojern
Activities relevant to the data transferred under these Clauses: As described in the Agreement
Role (controller/processor): Controller
2. Categories of Data Subjects
As determined by the Customer, including travelers and other customers of the Customer.
3. Categories of Personal Data Transferred
Personal Data transferred by Customer is provided in accordance with the Agreement, and may include but is not limited to:
- Information in connection with a unique online identifier, such as a cookie ID, mobile device ID, hashed or plain email address, advertising ID, and Customer-assigned customer ID numbers.
- Information in connection with an individual’s device, such as IP address, device type, browser type, date and time stamp of clicks and web visits, URLs visited, and other technical information.
- Information in connection with an individual's travel, such as the number and types of travelers, currency/rates/fares/fees, search and booking information (such as departure and arrival date, and destination country or city), reward or loyalty program information, and accommodation or service preferences (such as room, flight seat or car type, and facilities and amenities preferences).
4. Sensitive Data Transferred (If Applicable)
Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures: N/A.
5. Frequency of the Transfer
The frequency of the transfer (e.g. whether the Personal Data is transferred on a one-off or continuous basis): On a continuous basis.
6. Nature of the Processing
The Personal Data will be processed and transferred as described in the Agreement and DPA.
7. Purpose(s) of the transfer and further processing
The Personal Data will be transferred and further processed for the provision of the Sojern Services as described in the Agreement and DPA.
8. Duration of Processing
Personal data will be retained for as long as necessary taking into account the purpose of the processing, and in compliance with applicable laws, including laws on the statute of limitations and applicable Data Protection Law.
9. Sub-Processor Transfers
For international data transfer to (Sub)processors, also specify subject matter, nature and duration of the processing: For the subject matter and nature of the processing, reference is made to the Agreement and DPA. The processing will take place for the duration of the Agreement.
10. Competent Supervisory Authority
The competent authority for the processing of Personal Data relating to data subjects located in the EEA is the regulatory authority of Ireland.
The competent authority for the processing of Personal Data relating to data subjects located in the UK is the UK Information Commissioner.
The competent authority for the processing of Personal Data relating to data subjects located in Switzerland is the Swiss Federal Data Protection and Information Commissioner.
11. Technical and Organizational Measures
Sojern implements the following technical security measures:
- General. Sojern will establish, implement, and maintain appropriate administrative, technical and organizational measures that are designed to protect against unauthorized or unlawful processing of Personal Data and against accidental loss or destruction of, or damage to, Personal Data. These measures will be adequate to comply with applicable Data Protection Law and Sojern will comply at all times with its information security policies and information security program.
- Information Security Policies and Standards. Sojern will maintain information security policies, standards, and procedures. These policies, standards, and procedures shall be kept up to date, and revised whenever relevant changes are made to the information systems that use or store Personal Data.
- Vulnerability Management. Sojern will maintain a vulnerability management program for all systems that process Personal Data that includes without limitation internal and external vulnerability scanning with risk rating findings and formal remediation plans to address any identified vulnerabilities.
- Risk Assessment. Sojern will conduct periodic risk assessments to identify and assess reasonably foreseeable risks to the security, confidentiality, and integrity of records containing Personal Data and evaluate and improve, where necessary, the effectiveness of its safeguards for limiting those risks.
- Data Classification. Sojern will maintain policies and procedures to classify sensitive information assets, clarify security responsibilities, and promote awareness for all employees.
- Encryption. Sojern will implement industry standard encryption mechanisms and strong cipher suites (AES 256- bit is recommended) for storage and transmission. Sojern will accept connections over encrypted channels (TLS is recommended).
- Network Security. Sojern will secure its network by employing a defense-in-depth approach that utilizes commercially available equipment and industry standard techniques, including without limitation firewalls, intrusion detection systems, access control lists, and routing protocols.
- Virus and Malware Controls. Sojern will protect Personal Data from malicious code and will install and maintain anti-virus and malware protection software on any system that handles Personal Data.
- Access Control. Sojern will practice the principle of least privilege where access to Personal Data is only granted to those within the organization who have a business need for such access and permissions will be limited to the minimum amount required to perform the specific job function.
- Processing Location. Personal Data will be Processed by Sojern in the United States, subject to applicable Data Protection Law that may require otherwise.
- Incident Response. Sojern will maintain a data security incident response program and will document all suspected data security incidents. Sojern will investigate any data security incidents and take all necessary steps to eliminate or contain the data security incident.
- Personnel. Sojern will maintain an information security awareness and training program and will train critical Sojern personnel on data protection measures and general cybersecurity protections.
- Vendor. Sojern will maintain a vendor management program that will assess all vendors with whom Sojern exchanges Personal Data. Such vendors will be held to data security standards no less restrictive than those set forth herein.
12. Subprocessors.
Subprocessors are listed at www.sojern.com/legal/partner-list/.