1. Introduction
This Data Protection Addendum (“DPA”) forms part of the commercial agreement (Terms of Use, Carrier Purchase Agreement, agency/corporate agreement, or other written contract — the “Agreement”) between Tavaktech LTD (“cealio” / “Muyki-equivalent operator” herein “cealio”) and the counterparty (“Customer” — which may be a corporate booker, agency, or Carrier, as context requires).
In providing Platform services, cealio processes personal data relating to Customer representatives, End Users, Guests, and (for Carriers) driver/vehicle-related data. cealio may act as a controller and/or processor depending on the processing activity. This DPA sets out the terms of such processing.
Contact: hello@cealio.com · Address: Office 106, 9 Brewers Lane, Richmond, Surrey, TW9 1HH, UK · Company No.: 16563260
2. Definitions
- Applicable Data Protection Laws: GDPR, UK GDPR, KVKK, and other privacy laws applicable to a Party.
- Customer Account Data: data about Customer and its users that cealio processes as an independent controller (account, billing, compliance).
- Customer Content: Guest/passenger and messaging/booking content that cealio processes on Customer’s behalf as a processor (e.g. agency uploading passenger lists).
- Personal Data, Processing, Controller, Processor, Data Subject, Sub-processor, Data Breach: as under Applicable Data Protection Laws.
- Service: cealio Platform and related support.
3. Roles of the Parties
3.1 cealio as Processor
For Customer Content that Customer uploads or instructs cealio to process (e.g. agency bulk passenger data for bookings Customer controls), cealio acts as Processor and will process only on documented instructions to provide the Service.
3.2 cealio as Controller
For Customer Account Data, marketing preferences (where lawful), security logs, and cealio’s own booking relationships with consumer End Users, cealio acts as Controller under its Privacy & Cookie Policy and Privacy Notice.
3.3 Carrier context
When Carriers receive Guest data to perform a Job, they process such data as independent controllers or as processors for cealio/Customer as specified in the Carrier Purchase Agreement and job instructions. Carriers must not use Guest data for their own marketing.
3.4 Customer obligations
Customer warrants it has provided notices and obtained consents/legal bases required to share Personal Data with cealio, and will not instruct cealio to process data unlawfully. Customer shall not upload special-category data unless expressly agreed.
4. Sub-processing
Customer authorizes cealio to engage Sub-processors (hosting, email/SMS, payments, maps, support tools). cealio will impose data-protection obligations materially no less protective than this DPA and remains responsible for Sub-processor performance.
cealio will provide notice of material new Sub-processors that Process Customer Content (e.g. via email or partner portal) at least ten (10) days in advance where practicable. Customer may object on reasonable data-protection grounds; Parties will discuss in good faith. If unresolved, Customer may terminate the affected Service for convenience.
5. Security measures
cealio implements technical and organizational measures appropriate to risk, including:
- access control on a need-to-know / least-privilege basis;
- authentication and credential lifecycle management;
- encryption in transit (TLS) and encryption at rest where appropriate;
- network segmentation and monitoring;
- personnel confidentiality and training;
- vendor security assessment;
- incident response procedures;
- backups and recovery measures.
Customer is responsible for securing its own account credentials and devices.
6. Security reviews
Upon written request no more than once per calendar year, and subject to confidentiality, cealio will respond to reasonable security questionnaires regarding this DPA.
7. Data Breach notification
Upon becoming aware of a confirmed Data Breach affecting Customer Content, cealio will notify Customer without undue delay and, where GDPR-style rules apply to the Processor role, within 72 hours where feasible, describing known details and mitigation steps. Customer is responsible for notifications to authorities/Data Subjects required of a Controller, unless law assigns that duty otherwise.
8. Data Subject rights
cealio will provide reasonable assistance for Customer to respond to Data Subject requests relating to Customer Content, to the extent Customer cannot do so via self-service. If assistance requires significant resources, it may be chargeable at pre-agreed rates.
If cealio receives a request directly regarding Customer Content, it will redirect the Data Subject to Customer where appropriate, unless legally required to respond directly.
9. Return or deletion
Upon termination of the Agreement and Customer’s written request, cealio will delete or return Customer Content from active systems within a reasonable period, except for copies retained as required by law or for dispute/security logs, which remain protected under this DPA until deletion.
10. International transfers
Where Personal Data is transferred internationally, cealio will ensure an appropriate transfer mechanism (SCCs, adequacy, or other lawful tool) as required by Applicable Data Protection Laws.
Türkiye (KVKK)
Processing and transfers will comply with KVKK and Board regulations.
CCPA / similar
Where applicable to Customer Content, cealio acts as a service provider / processor and will not sell Personal Data or retain it for purposes other than providing the Service.
11. Annex 1 — Details of processing (Processor role)
| Item | Description |
|---|---|
| Purpose | Provide booking/dispatch Platform features instructed by Customer |
| Duration | Term of Agreement + limited retention |
| Data subjects | Guests/passengers, Customer staff End Users |
| Data categories | Identity, contact, trip details, limited payment references, support content |
| Sensitive data | Not intended; Customer must not send unless agreed |
| Frequency | Continuous / per booking |
12. Annex 2 — Controller processing (Account Data)
Account, billing, compliance, and security data are processed by cealio as Controller as described in the Privacy & Cookie Policy.
13. Miscellaneous
13.1 Notices under this DPA: hello@cealio.com. 13.2 Governing law: as in the Agreement, unless Applicable Data Protection Laws require otherwise. 13.3 This DPA prevails over the Agreement on data-protection conflicts. 13.4 Liability for regulatory fines: each Party bears fines caused by its own non-compliance; Contractual liability caps in the Agreement apply to other damages except where prohibited.
14. Contact
Tavaktech LTD Office 106, 9 Brewers Lane, Richmond, Surrey, TW9 1HH, UK Email: hello@cealio.com