Agreements

Data processing addendum

Effective 27 September 2026. Forms part of the terms of service between JetNova AI (the processor) and each subscribing agency (the controller).

1. Scope and roles

When an agency uses the B2C bot, Buraq B2B, the email desks or the administrative applications, personal data of its customers, guests, open clients, staff, sub-agents and suppliers is processed. For that data the agency is the controller and JetNova AI is the processor. Where the agency itself is a processor for another agency above it, the same terms flow down.

2. Details of processing

Subject matter
Providing the products described in the terms of service.
Duration
The subscription term plus the export and deletion period.
Nature and purpose
Hosting, storing, transmitting, analysing with AI models and tools, and displaying data to answer customers, make and manage bookings, run wallets and settlement, send messages, and keep records.
Categories of data subjects
Travellers and their companions, guests, open clients, agency staff, sub-agent staff, supplier contacts.
Categories of data
Identity and contact details, passport and travel-document details, dates of birth, nationality, itineraries and bookings, payment references (not full card numbers), conversation content including voice and attachments, usage and audit records, wallet and ledger entries.
Special categories
Only what a booking incidentally reveals (for example meal or assistance requests, or religious travel such as Umrah); not used for any other purpose.

3. Instructions

We process personal data only on the agency's documented instructions, which are the terms of service, this addendum, the settings the agency configures (capabilities, switches, workflows, retention) and reasonable written instructions consistent with them. If an instruction appears to break the law we say so before acting.

4. Confidentiality

People with access to personal data are bound by confidentiality and given access only as their role requires. Administrative access to production data is limited, logged and reviewed.

5. Security

Taking into account the state of the art and the risk, we maintain measures including: encryption in transit; encryption of connected credentials at rest; salted one-way password hashing; expiring sessions and optional one-time-password steps for sensitive actions; signature verification of inbound webhooks; agency isolation enforced before any query; role-based access; audit logs; separation of staging and production; recovery points before production changes; and a vulnerability disclosure process described on the security page.

6. Sub-processors

The agency authorises the sub-processors listed on the sub-processors page, which also states each one's location and purpose. We bind each to obligations no less protective than these. We give at least 30 days' notice by email before adding or replacing a sub-processor; an agency may object on reasonable data-protection grounds, and if we cannot resolve the objection the agency may terminate the affected service without penalty.

Travel suppliers (GDSs, airlines, hotels) and payment providers that the agency connects under its own contracts are independent recipients chosen by the agency, not our sub-processors.

7. Assistance

We help the agency respond to data-subject requests: the products let staff find, export and delete a customer's data, and we act on requests forwarded to privacy@jetnova-ai.com within the time the law allows the agency. We help with data-protection impact assessments and consultations with authorities where our processing is concerned.

8. Personal data breaches

We notify the agency without undue delay, and in any event within 48 hours of becoming aware of a breach affecting its data, with what we know, what we are doing and a contact, and we keep the agency informed as we learn more.

9. Return and deletion

During the term the agency can export bookings, reports, ledger and conversations from the products. Within 30 days after termination we delete or anonymise the agency's personal data, except what we must keep by law, and confirm in writing on request.

10. Audit

We make available the information needed to show compliance with this addendum, including summaries of our security measures and sub-processor list, and answer reasonable security questionnaires. Where that is not enough, the agency or an auditor it appoints may audit, once a year on 30 days' notice, during business hours, under confidentiality, at the agency's cost, without disturbing other agencies' data.

11. International transfers

Where personal data is transferred outside the country it was collected in, we rely on the sub-processors' standard contractual clauses or equivalent safeguards and on our own obligations under this addendum.

12. Liability and precedence

Liability under this addendum is subject to the limits in the terms of service. If this addendum conflicts with the terms, this addendum prevails for the processing of personal data.

Breach-notice window (48 hours), sub-processor notice period (30 days) and the audit terms are proposed defaults for the owner's confirmation with counsel.