Skip to main content

New announcement. Learn more

GDPR, Privacy, Sub Processors, Data Processing (DPA) Access and Support

GDPR COMPLIANCE STATEMENT

GDPR COMPLIANCE STATEMENT (Odyssey)

Effective Date:1st January 2025
Last Updated: 4th March 2026

Odyssey, a software platform developed and operated by Creative Technology NZ Ltd, is committed to maintaining appropriate technical and organisational measures to protect personal data. While we are based in New Zealand, we recognise the global nature of data processing and are fully committed to complying with the General Data Protection Regulation (GDPR) (EU 2016/679) for all clients and data subjects located in the European Union and United Kingdom.

1. Our Role in Data Processing

Odyssey acts as a data processor on behalf of its clients, who are typically multi-day tour operators. These clients are the data controllers who determine the purposes and means of processing the personal data of their customers (data subjects).

2. Scope of Personal Data Collected

Odyssey processes only the personal data that is:

  • Supplied directly by our clients (the data controllers),

  • Provided by data subjects via integrated online forms (e.g., Cognito Forms),

  • Necessary for the fulfilment of tour operations (e.g., name, contact details, medical or access requirements).

Odyssey does not use this data for our own marketing, analytics, or profiling.

3. Data Storage and Security

  • Data Location: All client data is stored on dedicated physical servers hosted in a secure colocation environment at the SiteHost datacenter in Auckland, New Zealand.

  • No Shared Hosting: Odyssey infrastructure is not shared with third parties.

  • Sub-Processors (Odyssey managed): Mailjet, Cognito Forms, TinyURL, and Webhook.site.

  • Client-Enabled Integrations: Xero.

  • Data Access: Odyssey staff may access data only for onboarding, technical support, or maintenance purposes, and always under strict confidentiality.

4. Data Subject Rights

Odyssey supports our clients in responding to data subject rights requests, including:

  • Access, correction, or deletion of personal data

  • Data portability and the right to object or restrict processing

Clients are encouraged to inform data subjects of their rights under GDPR and ensure consent is appropriately obtained.

5. International Transfers

Under Article 46 of the GDPR, New Zealand has an existing adequacy decision from the European Commission for data transfers. Odyssey ensures that all third-party tools we use also adhere to secure and lawful transfer mechanisms.

6. Commitment to Compliance

Odyssey maintains:

  • A clear Privacy Policy outlining how we process and store data

  • A comprehensive Data Processing Agreement (DPA) available to all clients

  • Internal policies and controls to ensure secure and lawful data processing

DATA PROCESSING AGREEMENT (DPA)

Between:
Odyssey (Creative Technology NZ Ltd)
(“Processor”)
and
[Client Name]
(“Controller”)

Effective Date:1st January 2025
Last Updated: 4th March 2026


1. Background and Scope

This Data Processing Agreement (“DPA”) sets out the terms under which Odyssey processes personal data on behalf of the Client, in accordance with applicable data protection legislation including the General Data Protection Regulation (EU/UK GDPR) and New Zealand Privacy Act 2020.

2. Definitions

  • Controller: The entity which determines the purposes and means of the processing of personal data.

  • Processor: Odyssey, acting under the instructions of the Controller.

  • Sub-processor: A third-party processor engaged by Odyssey to assist in processing personal data.

  • Personal Data: Any information relating to an identified or identifiable natural person.

3. Nature and Purpose of Processing

Odyssey processes personal data to provide its SaaS-based tour management platform for multi-day tour operators, including but not limited to:

  • Managing customer bookings, communications, and itineraries

  • Facilitating supplier coordination and logistics

  • Generating reports, labels, and operational documentation

  • Enabling customer mobile itinerary delivery (no personal data stored in app)

4. Categories of Data Subjects and Data

  • Data Subjects: Clients’ customers and tour participants

  • Types of Personal Data:

    • Name, contact details, travel preferences

    • Health or accessibility information (when explicitly provided)

    • Communication history

    • Booking and payment metadata

Odyssey does not process special category data unless entered voluntarily by the data subject or controller and subject to additional safeguards.

5. Controller Obligations

The Controller:

  • Ensures lawful basis (e.g. consent or contract) for the processing of personal data

  • Notifies data subjects of their rights and the processing activities

  • Is responsible for fulfilling data subject access requests

6. Processor Obligations

Odyssey agrees to:

  • Process data only on the documented instructions of the Controller

  • Implement appropriate technical and organisational measures to protect data

  • Limit access to authorised personnel only

  • Notify the Controller promptly of any data breach within 48 hours of discovery, and

    • Provide a description of the breach, what areas of data it is affecting.

    • As the process unfolds of discovery, then any information that is known about the consequences or the appropriate measures to take to remedy the breach, will be advised to the Controller in a timely manner.

  • Assist the Controller with data subject requests, risk assessments, and audits

7. Sub-Processing

Odyssey uses the following GDPR-compliant sub-processors:

  • Mailjet – transactional email delivery

  • Webhook.site – processing and inspection of webhook payloads used in system integrations

  • Cognito Forms – customer form data collection ( optional )

  • TinyURL – generation of shortened links used in system communications ( optional )

Odyssey will inform the Controller of any intended changes regarding new sub-processors and allow for reasonable objection.

Client-Enabled IntegrationsThe Odyssey platform may allow the Client to connect or enable integrations with third-party services (for example accounting, communication, or operational tools).

Where the Client chooses to enable such integrations:

  • the Client determines whether the integration is activated and what data is transmitted;

  • the third-party service provider will process data under the terms of the Client’s own agreement with that provider;

  • Odyssey acts only as a technical conduit facilitating the transfer of data as instructed by the Client.

Accordingly, such third-party services are considered Client-Enabled Integrations, and the Client is responsible for ensuring that the use of those services complies with applicable data protection laws.

Odyssey is not responsible for the independent processing of personal data carried out by those third-party providers once data has been transmitted to them in accordance with the Client’s instructions.

8. Data Transfers

Odyssey stores all client data on secure, private servers in Auckland, New Zealand. Transfers to New Zealand are lawful under the EU’s adequacy decision. Any third-party processors will operate under equivalent safeguards (e.g., SCCs).

9. Data Retention and Deletion

Upon termination of the service or at the Controller’s request:

  • Odyssey will delete or return all personal data unless legal obligations require otherwise.

  • Backups will be securely erased on the next scheduled overwrite cycle.

10. Liability and Indemnity

Each party shall be liable for their respective compliance with applicable data protection laws. Odyssey’s liability is limited to the extent permitted under the SaaS Agreement.

11. Governing Law and Jurisdiction

This DPA is governed by the laws of New Zealand, without prejudice to the rights of EU/UK data subjects under GDPR.

Odyssey Sub-Processor Register

Company: Creative Technology NZ Ltd
Platform: Odyssey Tour Management Platform
Last Updated: 4th March 2026


1. Overview

Odyssey uses a limited number of third-party service providers (“Sub-Processors”) to support platform functionality such as transactional email delivery, form submissions, webhook integrations, and operational communications.

Creative Technology NZ Ltd ensures that any Sub-Processors process personal data only for the purposes required to deliver the Odyssey platform.

Some integrations may be enabled directly by the client, in which case the client determines whether the integration is used and what data is transmitted.


2. Core Sub-Processors (Managed by Odyssey)

Sub-Process

Purpose

Data Processed

Location

Safeguards

Mailjet

Delivery of transactional emails generated by the Odyssey platform

Email address, message metadata, and message content required for delivery

EU / Global infrastructure

Data Processing Agreement, GDPR compliance commitments

Cognito Forms

Collection of customer information through secure online forms

Name, contact details, booking information submitted via forms

United States

Data Processing Agreement, GDPR compliance commitments

TinyURL

Generation of shortened links used in system communications or itineraries

URL links and associated metadata used to generate shortened URLs

United States

Vendor privacy commitments

Webhook.site

Processing and inspection of webhook payloads used in system integrations and automation workflows

Webhook payload data which may include operational system data depending on configuration

European Union

Vendor privacy commitments; webhook payload storage is temporary and not retained long-term


3. Client-Enabled Integrations

These services may be connected directly by clients depending on their operational needs.

Service

Purpose

Data Processed

Location

Safeguards

Xero

Accounting integration for invoicing and payment reconciliation

Customer billing details, invoice data, payment references, business contact details

New Zealand / Global infrastructure

Data Processing Agreement and vendor security commitments

This integration is optional and configured directly by the client within their own Xero account.


4. Infrastructure Provider

Provider

Purpose

Location

SiteHost

Colocation datacenter hosting Odyssey servers

Auckland, New Zealand

Odyssey infrastructure operates on dedicated physical servers owned and managed by Creative Technology NZ Ltd within the SiteHost datacenter.

5. Data Transfer Safeguards

Where personal data may be processed outside New Zealand, Odyssey ensures appropriate safeguards including:

  • Data Processing Agreements with vendors

  • Standard Contractual Clauses where required

  • Vendor privacy and security commitments

New Zealand is recognised by the European Commission as providing an adequate level of protection for personal data.


6. Changes to Sub-Processors

Odyssey may update this list as the platform evolves.

Clients will be notified of material changes to Sub-Processors in accordance with contractual obligations.

PRIVACY POLICY

Effective Date:1st January 2025
Last Updated: 4th March 2026

Company: Odyssey (Creative Technology NZ Limited)
Website: https://myodyssey.app
Contact: info@myodyssey.app

1. Overview

At Odyssey, we are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you or your organisation use our software and services.

We comply with applicable privacy laws, including the New Zealand Privacy Act 2020, the UK General Data Protection Regulation (UK GDPR), and the EU General Data Protection Regulation (EU GDPR).

2. Who This Policy Applies To

This policy applies to:

  • Clients (tour operators and tourism businesses using Odyssey)

  • Clients’ customers (travellers whose data is managed via Odyssey)

  • Visitors to our website

3. What Data We Collect

Depending on how you interact with us, we may collect:

From Clients:

  • Business name and contact details

  • User account information

  • Booking data

  • Operational and tour content

From Clients’ Customers (via Odyssey platform):

  • Name and contact information

  • Tour and itinerary preferences

  • Health and accessibility information (where voluntarily submitted)

  • Communications and booking interactions

From Website Visitors:

  • Browsing activity (via analytics)

  • Contact form submissions

  • Email marketing preferences

4. How We Collect Data

We collect personal data through:

  • Online forms completed by customers (hosted via Cognito Forms)

  • Direct data entry by our clients

  • Secure third-party integrations (with appropriate safeguards)

We do not collect personal information via our mobile itinerary app. The app only displays non-identifying itinerary content.

Odyssey processes only the personal data necessary to deliver the services requested by the client. Clients are encouraged to avoid storing unnecessary personal data within the platform.

5. How We Use Your Data

We process personal data to:

  • Provide and maintain the Odyssey software platform

  • Enable itinerary creation and customer communications

  • Manage logistics (e.g., transport, accommodation, meals, activities)

  • Support administration, analytics, and reporting

Odyssey does not sell, rent, or share client customer data with third parties for marketing purposes.

6. Data Storage and Security

  • Customer data is stored on dedicated physical servers hosted in a secure colocation environment in Auckland, New Zealand.

  • No data is shared with third parties unless necessary for service delivery (see below).

  • Security protocols include encrypted communications (HTTPS/TLS), server firewall protection, access controls, login logging, failed login alerts, system activity monitoring, and regular backups stored separately from production systems. 

  • Backup systems are logically isolated from the primary production environment to support secure disaster recovery.

  • Access to production systems is restricted to authorised Odyssey personnel responsible for platform maintenance and support.  

  • Automated backups are performed twice daily. Backup copies are stored on a separate backup server within the datacenter and on external storage connected to the server infrastructure. Backup systems are isolated from the primary production environment to support reliable recovery in the event of hardware or operational failure.

7. Third-Party Tools & Sub-Processors

We may use the following GDPR-compliant services:

  • Mailjet -Transactional email delivery infrastructure (processes recipient email addresses and message metadata necessary for delivery)

  • Webhook.site - processing and inspection of webhook payloads used for system integrations; webhook payloads are stored temporarily and not retained long-term

Additional services that may be used depending on platform configuration include:

  • Cognito Forms – form-based data collection

  • TinyURL – URL abbreviation tool

  • Xero – accounting integration configured directly by the client

These services process data on our behalf under strict data protection terms.

8. Data Retention

We retain personal data:

  • As long as necessary to fulfil the purpose it was collected for

  • As required under law or contractual agreement

  • Or until our clients request deletion

Upon termination of service, we follow secure data deletion protocols unless otherwise instructed by the client.

9. International Data Transfers

Odyssey is based in New Zealand, an adequate jurisdiction under the EU and UK GDPR. Where applicable, data transfers to any third parties will be governed by standard contractual clauses (SCCs) or other recognised safeguards.

10. Your Rights

Depending on your location, you may have the following rights:

  • Access to your personal data

  • Correction of incorrect or outdated data

  • Deletion of your data ("right to be forgotten")

  • Objection to or restriction of processing

  • Data portability (for EU/UK residents)

11. Cookies and Website Analytics

Our website may use cookies and analytics tools to improve user experience and understand visitor interactions. No personally identifiable information is collected through cookies unless explicitly submitted by you (e.g., contact form).

12. Updates to This Policy

We may update this policy from time to time to reflect changes in law or our services.

DATA ACCESS & SUPPORT POLICY

Effective Date:1st January 2025
Last Updated: 4th March 2026

Company: Odyssey (Creative Technology NZ Limited)
Website: https://myodyssey.app
Contact: support@myodyssey.app

1. Purpose

This policy outlines how Odyssey manages data access for clients and provides technical support in a secure, structured, and transparent way. It supports our commitment to data protection, operational continuity, and customer service excellence.

2. Scope

This policy applies to:

  • Odyssey clients (subscribed tour operators)

  • Odyssey personnel with access to client data

  • Customer support and onboarding teams

  • Any party requesting support that may involve accessing Odyssey systems or data

3. Client Data Ownership

Clients retain full ownership and control over the customer and operational data they input into Odyssey. Odyssey (Creative Technology NZ Limited) acts as a Data Processor, processing such data only on behalf of, and under the instruction of, the client.

Clients are responsible for:

  • The accuracy of their own customer and supplier data

  • Managing access permissions for their staff

  • Complying with applicable data protection laws as a Data Controller

4. Data Access by Odyssey Support Team

Odyssey support staff may access limited client data only when:

  • Required to assist with technical issues, onboarding, or troubleshooting

  • Authorised explicitly by the client

  • Operating under appropriate confidentiality and security controls

Access is always:

  • Time-limited and logged

  • Role-based (only essential staff have access)

  • Monitored for compliance and audit purposes

5. Support Channels

Clients can request help or raise tickets through:

We aim to respond to support queries:

  • Critical or High Priority Issues: Within 1 business day

  • Standard Requests: Within 2 business days

6. Self-Service Tools

Clients are encouraged to use Odyssey's built-in and self-help tools, including:

  • Online documentation (via help icons in the Odyssey)

  • Onboarding checklists and training resources

  • Role-based permissions to control staff access

7. Data Export and Portability

Clients may export data from Odyssey at any time through available tools. Data is provided in commonly used formats (e.g., CSV) to support:

  • Internal reporting

  • Data backups

  • Transition planning

Upon termination of service, Odyssey can support data exports as part of offboarding. Custom export services may incur additional charges.

8. Data Access Requests (Third Parties / Individuals)

In accordance with data protection law, individuals whose data is processed in Odyssey (e.g., tour participants) may request access to their personal data.

Odyssey will:

  • Direct such requests to the relevant client (data controller)

  • Provide technical support to the client if needed

  • Not respond directly to the data subject unless legally required

9. Data Security During Support

To maintain confidentiality and data security:

  • All support team members are trained in privacy and data handling

  • Remote access is secured via encrypted protocols

  • Personal data viewed during support is never copied, stored, or shared outside the platform

  • We do not download or retain personal data unless specifically instructed by the client for support

10. Client Responsibilities

To ensure effective support and data security, clients must:

  • Provide authorised contacts to liaise with our support team

  • Maintain up-to-date user access permissions in Odyssey

  • Inform us immediately of suspected data breaches or security concerns

11. Amendments

We may update this policy to reflect changes to our support processes, data handling procedures, or applicable regulations. We recommend reviewing this page periodically for the latest version.

 

This product has been added to your cart

CHECKOUT