This Data Processing Agreement ("DPA") forms part of the Terms of Service between Scicolone Consulting FZ-LLC, a free zone company registered with the Ras Al Khaimah Economic Zone (RAKEZ), United Arab Emirates (registration number RAKEZ202610000, commercial licence 47034656), of RAKEZ Business Zones, Ras Al Khaimah, United Arab Emirates ("Camille", "Processor") and the operator that accepts it ("Operator", "Controller"), together the "Parties". It governs Camille's processing of personal data on the Operator's behalf in connection with the Camille / Camille Go embeddable AI destination expert (the "Service").
Effective date: on the Operator's acceptance of the Terms or first deployment of the Service.
"GDPR" means Regulation (EU) 2016/679. "Indonesia PDP Law" means Law No. 27 of 2022 on Personal Data Protection. "UAE PDPL" means UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. "CCPA" means the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act (CPRA) and its regulations, and "Comparable U.S. State Privacy Laws" means the Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Texas TDPSA, and other U.S. state laws of similar effect. "Applicable Data Protection Law" means whichever of these (and any other privacy law) applies to a given processing activity. "Personal Data", "Controller", "Processor", "Processing", "Data Subject", and "Personal Data Breach" have the meanings given in the GDPR (and the equivalent Indonesia PDP Law terms Pengendali / Prosesor apply where that law governs). "Sub-processor" means any third party engaged by Camille to process Personal Data under this DPA.
2.1 Lead and visitor data (Camille as Processor). For Personal Data that visitors provide or that is collected through the Service on the Operator's website — names, email addresses, phone numbers, conversation content, IP address and user-agent — the Operator is the Controller and Camille is the Processor, acting only on the Operator's documented instructions (Annex 1).
2.2 Aggregated analytics (Camille as independent Controller). Separately, Camille produces anonymized, aggregated statistics about travel demand (e.g. destination interest, budget bands, conversion rates) derived from visitor interactions. For this activity Camille acts as an independent Controller on the legal basis of its legitimate interests. The aggregates are produced so that no individual can be singled out — grouped by destination and day, with cohorts below a minimum size dropped — and contain no name, email, IP address, or session identifier. The Operator agrees to disclose this aggregated analytics in its own privacy notice to visitors. Enterprise and white-label deployments are excluded from this aggregation unless their order form or contract states otherwise.
3.1 The Operator warrants it has a valid legal basis to collect the Personal Data via the Service and to have Camille process it, and that it has provided all required notices to Data Subjects (including referencing Camille as a Processor, and the anonymized analytics in clause 2.2).
3.2 The Operator's instructions to Camille are set out in this DPA, the Terms, and the configuration the Operator chooses in the dashboard.
3.3 Where the Operator activates the optional Identity Reconciliation feature (linking a Data Subject's pseudonymous browsing or conversation history to their identified profile upon consent), the Operator additionally warrants that, before activation: (a) its privacy notice already discloses this specific linkage, effective from a date the Operator can evidence, and it will not treat history collected before that date as linkable; (b) it has completed a data protection impact assessment for this processing, or has determined in good faith that one is not required, and can produce that assessment on request; and (c) it will honour a Data Subject's withdrawal of consent and erasure request through the mechanism Camille provides (clause 6). Camille's role for this processing remains that of Processor under clause 2.1. Camille provides consent-capture, revocation, and erasure tooling and, on request, template notice language, but the warranties in this clause 3.3 require the Operator's own action before the feature is switched on for its site and are not satisfied by that tooling's mere availability.
Camille shall:
5.1 The Operator gives general authorisation to the Sub-processors listed in Annex 2.
5.2 Camille will give the Operator at least 14 days' notice of any intended addition or replacement of a Sub-processor (by email and/or a published list), during which the Operator may object on reasonable data-protection grounds.
5.3 Camille will impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA.
Camille will, without undue delay, forward to the Operator any request it receives directly from a Data Subject relating to the Operator's data, and will assist the Operator in fulfilling it, including operator-level erasure and visitor-level export or erasure by email or session identifier.
Camille will notify the Operator without undue delay after becoming aware of a Personal Data Breach affecting the Operator's data, with the information the Operator needs to meet its own notification duties. Indonesia PDP Law: where it applies, notification to the affected Data Subject and the authority must be made within 3×24 hours (72 hours).
Personal Data is stored in the European Union (Supabase, Frankfurt). Certain Sub-processors (Annex 2) operate in the United States; such transfers are made under the Standard Contractual Clauses (SCCs) incorporated into Camille's agreements with those Sub-processors. Where the Indonesia PDP Law applies, cross-border transfer of Indonesian Personal Data relies on binding contractual safeguards — SCC-style clauses that ensure a level of protection equivalent to the Indonesia PDP Law — as permitted by that law's cross-border transfer provisions. Where the UAE PDPL applies, transfers rely on the recipient jurisdiction offering an adequate level of protection (the EU) and on appropriate contractual safeguards as permitted by the PDPL's cross-border provisions. The Parties agree to enter into such clauses where required.
Where the CCPA or a Comparable U.S. State Privacy Law applies to the Operator's data, the Operator is the business and Camille is its service provider (a "processor" or "contractor" under the comparable laws). With respect to personal information the Operator discloses to Camille under this DPA, Camille:
Deidentified / aggregate data. The anonymized, aggregated analytics in clause 2.2 are intended to be deidentified and aggregate consumer information outside the definition of personal information. Camille will maintain the deidentification, will not attempt to reidentify the data, and will contractually bind any recipient to the same.
Where the Operator is established in, or processes Personal Data of individuals in, the Kingdom of Saudi Arabia, the Personal Data Protection Law (Royal Decree M/19 of 2021, as amended by Royal Decree M/148 of 2023) and its Implementing Regulations (the "PDPL") apply, and this clause 8B applies in addition to the rest of this DPA. The Operator remains the Controller and is responsible for its own registration (if applicable), notices, consents, Records of Processing Activities, data protection impact assessments, and breach notification to the Saudi Data & AI Authority ("SDAIA") within 72 hours, as required by the PDPL. Camille will notify the Operator without undue delay of any Personal Data Breach affecting the Operator's data (clause 7) to enable the Operator to meet that deadline.
International transfers of PDPL-covered Personal Data outside the Kingdom are made on the basis of the Kingdom's Standard Contractual Clauses (Controller-to-Processor module, published by SDAIA, September 2024, incorporated by reference and summarized as Annex 4, unmodified and in full), together with the transfer risk assessment summarized in Annex 4A. Camille will flow down equivalent safeguards to its Sub-processors under the Processor-to-Processor module or contractually equivalent terms, and will provide the Operator, on reasonable request, with the information needed to complete the Operator's own transfer risk assessment and Record of Processing Activities.
9.1 Liability is subject to the limitations in the Terms.
9.2 This DPA runs for as long as Camille processes Personal Data for the Operator.
9.3 Governing law and jurisdiction: this DPA is governed by the laws of the United Arab Emirates, and the Parties submit to the exclusive jurisdiction of the courts of the Emirate of Ras Al Khaimah, United Arab Emirates, consistent with the Terms.
Annex 1
Annex 2
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database & authentication (data at rest) | European Union (Frankfurt) |
| Vercel | Application hosting & request delivery | United States / global edge |
| Resend | Transactional & lead-notification email | United States |
| Paddle | Payment processing & billing for Operator subscription payments, acting as merchant of record | United Kingdom |
| Anthropic | LLM inference (not used to train models, per Anthropic's API terms) | United States |
| Sentry | Application error monitoring. Receives technical error reports when a request fails unexpectedly: the error, its stack trace, and diagnostic context about the failed request | United States |
| ElevenLabs | Real-time voice processing for the optional voice call (speech to text and text to speech); neither the audio nor the resulting transcript is retained, on a zero-day retention schedule, and they are not used to train models | United States |
| Meta Platforms, Inc. | WhatsApp Business Cloud API message delivery, for Operators who enable the WhatsApp channel | United States |
Annex 3
Annex 4
Where clause 8B applies, the Parties incorporate by reference, in full and without modification, the Standard Contractual Clauses for the Transfer of Personal Data Outside the Kingdom published by the Saudi Data & AI Authority (SDAIA), September 2024 (official text: sdaia.gov.sa), Controller-to-Processor module (Operator as Exporter, Camille as Importer). Camille further incorporates the Processor-to-Processor module of the same Clauses between itself and each Sub-processor listed in Annex 2 that processes Personal Data outside the Kingdom, or contractually equivalent safeguards where a given Sub-processor has not yet adopted the Kingdom's clauses.
Annex 4A
Camille maintains a Transfer Risk Assessment covering its processing and transfers relevant to the Kingdom, addressing: the processing lifecycle (Annex 1); the categories of Personal Data transferred and the frequency of transfer (continuous, for the duration of the Service); the safeguards and security measures applied by each Sub-processor (Annex 3); and confirmation that the transfer does not implicate the Kingdom's national security or vital interests. Camille will provide a copy of the current Transfer Risk Assessment to the Operator on reasonable request, to support the Operator's own assessment under the PDPL.
Questions about this DPA or a data request: privacy@camille.travel
← Back to camille.travelgo.camille.travel