Data protection and GDPR compliance – data processing agreement

1. DATA PROCESSING AGREEMENT
This Data Processing agreement “Agreement” is entered into by and between:

Data controller: Clients using the Hunt Admin platform both through test and subscription

Data processor: Hunt Admin, Company registration no. 46116038, Denmark, Europe

2. Purpose
The Data Processor provides a SaaS platform used by the Data Controller to manage customer bookings, CRM, client communications plus several other relevant functions such as campaign e-mailing, marketing efforts etc. Processing of personal data is done solely on instructions from the Data Controller.

3. Categories of Personal Data for your company and your end-clients

  • Company owner and employee names, emails and phone numbers
  • End-client name, email, phone number, address and other personal data relevant for booking such as requests, conditions, objectives etc.
  • Travel details, booking history, media materials
  • Personal documents passports, licences, photo documentation etc.
  • Payment data (if applicable)
  • IP addresses and browser metadata

For a full overview of personal data contact Data Processor at contact@huntadmin.com

4. Duration
The agreement remains valid as long as the Data Processor processes personal data on behalf of the Controller.

5. Security Measures
The Data Processor implements appropriate technical and organizational measures including:

  • HTTPS with TLS 1.3 with encryption
  • User based access control
  • Third party authentication flow with Auth0

6. Sub-processors
The Data Processor uses sub-processors as listed below (see Section 8). Changes will be provided in this section 8 when implemented

7. International Data Transfers
The Processor uses Standard Contractual Clauses (SCC) or equivalent mechanisms.

8. Sub-Processor List

Name Purpose Content Legal basis
MongoDB atlas Database All user data Standard contractual clauses (SCC)
SendGrid E-mail sending e-Mail, name Standard contractual clauses (SCC)
AWS Storage Documents Standard contractual clauses (SCC)
Auth0 Authentication e-Mail, name Standard contractual clauses (SCC)

9. Data Subject Rights
The Data Processor assists the Data Controller in fulfilling requests to access, correct, or delete personal data if requested. Note in this regard that the Data Controller has the option to access and correct personal data directly.

10. Breach Notification
In the event of a breach, the Data processor will notify the Data controller without undue delay and no later than 48 hours after becoming aware.

11. Termination
In termination situations, data will be deleted upon request. Data Controller is responsible for deletion but can ask Data processer for assistance

Last update 4th of October 2025