GDPR, Privacy, Sub Processors, Data Processing (DPA) Access and Support
GDPR COMPLIANCE STATEMENT
GDPR COMPLIANCE STATEMENT (Odyssey)
Effective Date:1st January 2025
Last Updated: 4th March 2026
Odyssey, a software platform developed and operated by Creative Technology NZ Ltd, is committed to maintaining appropriate technical and organisational measures to protect personal data. While we are based in New Zealand, we recognise the global nature of data processing and are fully committed to complying with the General Data Protection Regulation (GDPR) (EU 2016/679) for all clients and data subjects located in the European Union and United Kingdom.
1. Our Role in Data Processing
Odyssey acts as a data processor on behalf of its clients, who are typically multi-day tour operators. These clients are the data controllers who determine the purposes and means of processing the personal data of their customers (data subjects).
2. Scope of Personal Data Collected
Odyssey processes only the personal data that is:
Supplied directly by our clients (the data controllers),
Provided by data subjects via integrated online forms (e.g., Cognito Forms),
Necessary for the fulfilment of tour operations (e.g., name, contact details, medical or access requirements).
Odyssey does not use this data for our own marketing, analytics, or profiling.
3. Data Storage and Security
Data Location: All client data is stored on dedicated physical servers hosted in a secure colocation environment at the SiteHost datacenter in Auckland, New Zealand.
No Shared Hosting: Odyssey infrastructure is not shared with third parties.
Sub-Processors (Odyssey managed): Mailjet, Cognito Forms, TinyURL, and Webhook.site.
Client-Enabled Integrations: Xero.
Data Access: Odyssey staff may access data only for onboarding, technical support, or maintenance purposes, and always under strict confidentiality.
4. Data Subject Rights
Odyssey supports our clients in responding to data subject rights requests, including:
Access, correction, or deletion of personal data
Data portability and the right to object or restrict processing
Clients are encouraged to inform data subjects of their rights under GDPR and ensure consent is appropriately obtained.
5. International Transfers
Under Article 46 of the GDPR, New Zealand has an existing adequacy decision from the European Commission for data transfers. Odyssey ensures that all third-party tools we use also adhere to secure and lawful transfer mechanisms.
6. Commitment to Compliance
Odyssey maintains:
A clear Privacy Policy outlining how we process and store data
A comprehensive Data Processing Agreement (DPA) available to all clients
Internal policies and controls to ensure secure and lawful data processing
DATA PROCESSING AGREEMENT (DPA)
Between:
Odyssey (Creative Technology NZ Ltd)
(“Processor”)
and
[Client Name]
(“Controller”)
Effective Date:1st January 2025
Last Updated: 4th March 2026
1. Background and Scope
This Data Processing Agreement (“DPA”) sets out the terms under which Odyssey processes personal data on behalf of the Client, in accordance with applicable data protection legislation including the General Data Protection Regulation (EU/UK GDPR) and New Zealand Privacy Act 2020.
2. Definitions
Controller: The entity which determines the purposes and means of the processing of personal data.
Processor: Odyssey, acting under the instructions of the Controller.
Sub-processor: A third-party processor engaged by Odyssey to assist in processing personal data.
Personal Data: Any information relating to an identified or identifiable natural person.
3. Nature and Purpose of Processing
Odyssey processes personal data to provide its SaaS-based tour management platform for multi-day tour operators, including but not limited to:
Managing customer bookings, communications, and itineraries
Facilitating supplier coordination and logistics
Generating reports, labels, and operational documentation
Enabling customer mobile itinerary delivery (no personal data stored in app)
4. Categories of Data Subjects and Data
Data Subjects: Clients’ customers and tour participants
Types of Personal Data:
Name, contact details, travel preferences
Health or accessibility information (when explicitly provided)
Communication history
Booking and payment metadata
Odyssey does not process special category data unless entered voluntarily by the data subject or controller and subject to additional safeguards.
5. Controller Obligations
The Controller:
Ensures lawful basis (e.g. consent or contract) for the processing of personal data
Notifies data subjects of their rights and the processing activities
Is responsible for fulfilling data subject access requests
6. Processor Obligations
Odyssey agrees to:
Process data only on the documented instructions of the Controller
Implement appropriate technical and organisational measures to protect data
Limit access to authorised personnel only
Notify the Controller promptly of any data breach within 48 hours of discovery, and
Provide a description of the breach, what areas of data it is affecting.
As the process unfolds of discovery, then any information that is known about the consequences or the appropriate measures to take to remedy the breach, will be advised to the Controller in a timely manner.
Assist the Controller with data subject requests, risk assessments, and audits
7. Sub-Processing
Odyssey uses the following GDPR-compliant sub-processors:
Mailjet – transactional email delivery
Webhook.site – processing and inspection of webhook payloads used in system integrations
Cognito Forms – customer form data collection ( optional )
TinyURL – generation of shortened links used in system communications ( optional )
Odyssey will inform the Controller of any intended changes regarding new sub-processors and allow for reasonable objection.
Client-Enabled IntegrationsThe Odyssey platform may allow the Client to connect or enable integrations with third-party services (for example accounting, communication, or operational tools).
Where the Client chooses to enable such integrations:
the Client determines whether the integration is activated and what data is transmitted;
the third-party service provider will process data under the terms of the Client’s own agreement with that provider;
Odyssey acts only as a technical conduit facilitating the transfer of data as instructed by the Client.
Accordingly, such third-party services are considered Client-Enabled Integrations, and the Client is responsible for ensuring that the use of those services complies with applicable data protection laws.
Odyssey is not responsible for the independent processing of personal data carried out by those third-party providers once data has been transmitted to them in accordance with the Client’s instructions.
8. Data Transfers
Odyssey stores all client data on secure, private servers in Auckland, New Zealand. Transfers to New Zealand are lawful under the EU’s adequacy decision. Any third-party processors will operate under equivalent safeguards (e.g., SCCs).
9. Data Retention and Deletion
Upon termination of the service or at the Controller’s request:
Odyssey will delete or return all personal data unless legal obligations require otherwise.
Backups will be securely erased on the next scheduled overwrite cycle.
10. Liability and Indemnity
Each party shall be liable for their respective compliance with applicable data protection laws. Odyssey’s liability is limited to the extent permitted under the SaaS Agreement.
11. Governing Law and Jurisdiction
This DPA is governed by the laws of New Zealand, without prejudice to the rights of EU/UK data subjects under GDPR.
Odyssey Sub-Processor Register
Company: Creative Technology NZ Ltd
Platform: Odyssey Tour Management Platform
Last Updated: 4th March 2026
1. Overview
Odyssey uses a limited number of third-party service providers (“Sub-Processors”) to support platform functionality such as transactional email delivery, form submissions, webhook integrations, and operational communications.
Creative Technology NZ Ltd ensures that any Sub-Processors process personal data only for the purposes required to deliver the Odyssey platform.
Some integrations may be enabled directly by the client, in which case the client determines whether the integration is used and what data is transmitted.
2. Core Sub-Processors (Managed by Odyssey)
Sub-Process
Purpose
Data Processed
Location
Safeguards
Mailjet
Delivery of transactional emails generated by the Odyssey platform
Email address, message metadata, and message content required for delivery
EU / Global infrastructure
Data Processing Agreement, GDPR compliance commitments
Cognito Forms
Collection of customer information through secure online forms
Name, contact details, booking information submitted via forms
United States
Data Processing Agreement, GDPR compliance commitments
TinyURL
Generation of shortened links used in system communications or itineraries
URL links and associated metadata used to generate shortened URLs
United States
Vendor privacy commitments
Processing and inspection of webhook payloads used in system integrations and automation workflows
Webhook payload data which may include operational system data depending on configuration
European Union
Vendor privacy commitments; webhook payload storage is temporary and not retained long-term
3. Client-Enabled Integrations
These services may be connected directly by clients depending on their operational needs.
Service
Purpose
Data Processed
Location
Safeguards
Xero
Accounting integration for invoicing and payment reconciliation
Customer billing details, invoice data, payment references, business contact details
New Zealand / Global infrastructure
Data Processing Agreement and vendor security commitments
This integration is optional and configured directly by the client within their own Xero account.
4. Infrastructure Provider
Provider
Purpose
Location
SiteHost
Colocation datacenter hosting Odyssey servers
Auckland, New Zealand
Odyssey infrastructure operates on dedicated physical servers owned and managed by Creative Technology NZ Ltd within the SiteHost datacenter.
5. Data Transfer Safeguards
Where personal data may be processed outside New Zealand, Odyssey ensures appropriate safeguards including:
Data Processing Agreements with vendors
Standard Contractual Clauses where required
Vendor privacy and security commitments
New Zealand is recognised by the European Commission as providing an adequate level of protection for personal data.
6. Changes to Sub-Processors
Odyssey may update this list as the platform evolves.
Clients will be notified of material changes to Sub-Processors in accordance with contractual obligations.
PRIVACY POLICY
Effective Date:1st January 2025
Last Updated: 4th March 2026
Company: Odyssey (Creative Technology NZ Limited)
Website: https://myodyssey.app
Contact: info@myodyssey.app
1. Overview
At Odyssey, we are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you or your organisation use our software and services.
We comply with applicable privacy laws, including the New Zealand Privacy Act 2020, the UK General Data Protection Regulation (UK GDPR), and the EU General Data Protection Regulation (EU GDPR).
2. Who This Policy Applies To
This policy applies to:
Clients (tour operators and tourism businesses using Odyssey)
Clients’ customers (travellers whose data is managed via Odyssey)
Visitors to our website
3. What Data We Collect
Depending on how you interact with us, we may collect:
From Clients:
Business name and contact details
User account information
Booking data
Operational and tour content
From Clients’ Customers (via Odyssey platform):
Name and contact information
Tour and itinerary preferences
Health and accessibility information (where voluntarily submitted)
Communications and booking interactions
From Website Visitors:
Browsing activity (via analytics)
Contact form submissions
Email marketing preferences
4. How We Collect Data
We collect personal data through:
Online forms completed by customers (hosted via Cognito Forms)
Direct data entry by our clients
Secure third-party integrations (with appropriate safeguards)
We do not collect personal information via our mobile itinerary app. The app only displays non-identifying itinerary content.
Odyssey processes only the personal data necessary to deliver the services requested by the client. Clients are encouraged to avoid storing unnecessary personal data within the platform.
5. How We Use Your Data
We process personal data to:
Provide and maintain the Odyssey software platform
Enable itinerary creation and customer communications
Manage logistics (e.g., transport, accommodation, meals, activities)
Support administration, analytics, and reporting
Odyssey does not sell, rent, or share client customer data with third parties for marketing purposes.
6. Data Storage and Security
Customer data is stored on dedicated physical servers hosted in a secure colocation environment in Auckland, New Zealand.
No data is shared with third parties unless necessary for service delivery (see below).
Security protocols include encrypted communications (HTTPS/TLS), server firewall protection, access controls, login logging, failed login alerts, system activity monitoring, and regular backups stored separately from production systems.
Backup systems are logically isolated from the primary production environment to support secure disaster recovery.
Access to production systems is restricted to authorised Odyssey personnel responsible for platform maintenance and support.
Automated backups are performed twice daily. Backup copies are stored on a separate backup server within the datacenter and on external storage connected to the server infrastructure. Backup systems are isolated from the primary production environment to support reliable recovery in the event of hardware or operational failure.
7. Third-Party Tools & Sub-Processors
We may use the following GDPR-compliant services:
Mailjet -Transactional email delivery infrastructure (processes recipient email addresses and message metadata necessary for delivery)
Webhook.site - processing and inspection of webhook payloads used for system integrations; webhook payloads are stored temporarily and not retained long-term
Additional services that may be used depending on platform configuration include:
Cognito Forms – form-based data collection
TinyURL – URL abbreviation tool
Xero – accounting integration configured directly by the client
These services process data on our behalf under strict data protection terms.
8. Data Retention
We retain personal data:
As long as necessary to fulfil the purpose it was collected for
As required under law or contractual agreement
Or until our clients request deletion
Upon termination of service, we follow secure data deletion protocols unless otherwise instructed by the client.
9. International Data Transfers
Odyssey is based in New Zealand, an adequate jurisdiction under the EU and UK GDPR. Where applicable, data transfers to any third parties will be governed by standard contractual clauses (SCCs) or other recognised safeguards.
10. Your Rights
Depending on your location, you may have the following rights:
Access to your personal data
Correction of incorrect or outdated data
Deletion of your data ("right to be forgotten")
Objection to or restriction of processing
Data portability (for EU/UK residents)
11. Cookies and Website Analytics
Our website may use cookies and analytics tools to improve user experience and understand visitor interactions. No personally identifiable information is collected through cookies unless explicitly submitted by you (e.g., contact form).
12. Updates to This Policy
We may update this policy from time to time to reflect changes in law or our services.
DATA ACCESS & SUPPORT POLICY
Effective Date:1st January 2025
Last Updated: 4th March 2026
Company: Odyssey (Creative Technology NZ Limited)
Website: https://myodyssey.app
Contact: support@myodyssey.app
1. Purpose
This policy outlines how Odyssey manages data access for clients and provides technical support in a secure, structured, and transparent way. It supports our commitment to data protection, operational continuity, and customer service excellence.
2. Scope
This policy applies to:
Odyssey clients (subscribed tour operators)
Odyssey personnel with access to client data
Customer support and onboarding teams
Any party requesting support that may involve accessing Odyssey systems or data
3. Client Data Ownership
Clients retain full ownership and control over the customer and operational data they input into Odyssey. Odyssey (Creative Technology NZ Limited) acts as a Data Processor, processing such data only on behalf of, and under the instruction of, the client.
Clients are responsible for:
The accuracy of their own customer and supplier data
Managing access permissions for their staff
Complying with applicable data protection laws as a Data Controller
4. Data Access by Odyssey Support Team
Odyssey support staff may access limited client data only when:
Required to assist with technical issues, onboarding, or troubleshooting
Authorised explicitly by the client
Operating under appropriate confidentiality and security controls
Access is always:
Time-limited and logged
Role-based (only essential staff have access)
Monitored for compliance and audit purposes
5. Support Channels
Clients can request help or raise tickets through:
Email: support@myodyssey.app
Knowledge base: A library of self-help guides and training videos
We aim to respond to support queries:
Critical or High Priority Issues: Within 1 business day
Standard Requests: Within 2 business days
6. Self-Service Tools
Clients are encouraged to use Odyssey's built-in and self-help tools, including:
Online documentation (via help icons in the Odyssey)
Onboarding checklists and training resources
Role-based permissions to control staff access
7. Data Export and Portability
Clients may export data from Odyssey at any time through available tools. Data is provided in commonly used formats (e.g., CSV) to support:
Internal reporting
Data backups
Transition planning
Upon termination of service, Odyssey can support data exports as part of offboarding. Custom export services may incur additional charges.
8. Data Access Requests (Third Parties / Individuals)
In accordance with data protection law, individuals whose data is processed in Odyssey (e.g., tour participants) may request access to their personal data.
Odyssey will:
Direct such requests to the relevant client (data controller)
Provide technical support to the client if needed
Not respond directly to the data subject unless legally required
9. Data Security During Support
To maintain confidentiality and data security:
All support team members are trained in privacy and data handling
Remote access is secured via encrypted protocols
Personal data viewed during support is never copied, stored, or shared outside the platform
We do not download or retain personal data unless specifically instructed by the client for support
10. Client Responsibilities
To ensure effective support and data security, clients must:
Provide authorised contacts to liaise with our support team
Maintain up-to-date user access permissions in Odyssey
Inform us immediately of suspected data breaches or security concerns
11. Amendments
We may update this policy to reflect changes to our support processes, data handling procedures, or applicable regulations. We recommend reviewing this page periodically for the latest version.
