This Data Processing Agreement ("DPA") forms part of the Terms of Service between you, the Subscriber (the Controller), and Go Wild Booking Ltd (the Processor), trading as Go Wild Booking. It applies only to End User Data and other personal data that we process on your behalf when you use the Service. It does not apply to personal data we collect about you as our customer, which is described in our Privacy Policy.
This DPA is intended to meet Article 28 of the UK GDPR. Capitalised terms not defined here have the meaning given in the Terms.
1. Roles and scope
You are the controller of End User Data. You determine the purposes and means of that processing. We are your processor. We process End User Data only to provide the Service to you.
Each party will comply with the data-protection laws that apply to it. Nothing in this DPA makes us the controller of End User Data, and nothing makes you the controller of the account data we hold about you as our customer.
The subject matter, duration, nature, purpose, types of data, and categories of data subject are set out in Annex A.
2. Instructions
We will process End User Data only on your documented instructions, unless UK law requires us to process it. In that case we will tell you before processing, unless the law prohibits that notice.
Your documented instructions are: (a) these Terms and this DPA; (b) your configuration and use of the Service (including the data you and your End Users enter, and the messages you choose to send); and (c) any other written instructions you give us that we accept.
We will tell you without undue delay if, in our opinion, an instruction infringes UK GDPR or other applicable data-protection law. We are not obliged to provide legal advice.
3. Confidentiality
We will ensure that people we authorise to process End User Data are under an appropriate duty of confidentiality, whether by contract or by statutory obligation, and that they process it only as needed to provide the Service.
4. Security
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, we will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 UK GDPR. Those measures are summarised in Annex C.
5. Subprocessors
You give us general written authorisation to engage subprocessors in the categories listed in Annex B so we can provide the Service (for example hosting, email, SMS, WhatsApp, and payment infrastructure).
We will impose data-protection obligations on each subprocessor that are substantially similar to those in this DPA, including appropriate security. We remain responsible to you for a subprocessor's performance of those obligations.
We will tell you of a material change to subprocessors in a category that processes End User Data, by email or a notice in the Service, before that change takes effect where reasonably practicable. You may object on reasonable data-protection grounds within fourteen (14) days. If you object and we cannot reasonably provide an alternative, you may terminate the affected Service as set out in the Terms.
A current description of subprocessor categories is in Annex B. We will provide further detail on request at [email protected].
6. International transfers
We will not transfer End User Data outside the United Kingdom (or, where applicable, the EEA) except: (a) on your instructions, including through your choice to use a feature that requires it (for example WhatsApp / Meta); (b) to a country covered by UK adequacy regulations; or (c) subject to appropriate safeguards under UK GDPR Chapter V, such as the UK International Data Transfer Addendum or equivalent standard contractual clauses, together with any supplementary measures reasonably required.
7. Assistance with End User rights
Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to fulfil your duty to respond to End User requests under UK GDPR Chapter III (access, rectification, erasure, restriction, objection, and portability).
If an End User contacts us about data you control, we will not treat ourselves as the controller. We will direct them to you where we can identify the relevant account, and we will tell you about the request so you can instruct us. You remain responsible for responding to the End User.
8. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting End User Data we process for you. That notice will include, as far as we then know: the nature of the breach; the categories and approximate number of data subjects and records concerned; likely consequences; and measures taken or proposed to address it.
You are responsible for notifying the ICO and End Users where the law requires the controller to do so. We will provide reasonable information to help you meet those duties.
9. DPIAs and further assistance
Taking into account the nature of processing and the information available to us, we will assist you with data protection impact assessments and prior consultation with the ICO under Articles 35 and 36 UK GDPR, where those duties arise from your use of the Service. We may charge a reasonable fee for assistance that goes beyond providing documentation and standard product features, unless the need for that extra work is caused by our breach of this DPA.
10. Return and deletion
When the Service ends, we will, at your choice, delete End User Data or return it to you, then delete remaining copies, unless UK law requires storage. If you do not tell us otherwise, you instruct us to delete End User Data after a thirty (30) day grace period so you can export what you need. Backup copies may persist for a short additional period until they rotate in the ordinary course, and will remain subject to this DPA until they are removed.
11. Information and audits
We will make available to you the information reasonably necessary to demonstrate compliance with Article 28 UK GDPR, and will allow and contribute to audits, including inspections, by you or an auditor you mandate, subject to the rest of this clause.
Audits are limited to data, systems, and staff relevant to our processing of End User Data for you. Unless we have suffered a personal data breach or the ICO requires it, audits are not more than once in any twelve (12) month period, on at least thirty (30) days' written notice, during normal business hours, and in a way that does not unreasonably disrupt the Service or other customers. You must keep confidential information you learn confidential. We may satisfy an audit request in the first instance by providing written answers, security summaries, or independent reports we have. On-site inspection is available if that material is not reasonably sufficient.
12. Your duties as controller
You confirm that:
- You have a lawful basis to collect and use End User Data, and your instructions are lawful.
- You will provide End Users with your own privacy notice before or at the point their personal data is collected through the Service, as required by the Terms of Service and by UK GDPR Articles 13 and 14. That notice must name you as controller and must not present Go Wild Booking as the controller of the booking.
- You will obtain any consent, or satisfy any other condition, required for electronic mail, SMS, or WhatsApp messages, including under PECR.
- You will not instruct us to process special-category data (such as health or medical information in booking notes) unless you have a UK GDPR Article 9 condition and the processing is necessary for the booking.
- You are responsible for the content, accuracy, and minimisation of data you and your staff enter into the Service.
13. Duration and conflicts
This DPA starts when you first accept the Terms or use the Service, and continues until we have deleted or returned End User Data as required above. Clauses that by their nature should survive (including confidentiality, deletion, and audit of residual copies) remain in force until that data is gone.
If this DPA conflicts with the Terms on the processing of End User Data, this DPA prevails. This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, as in the Terms.
Questions about this DPA: [email protected].
Go Wild Booking Ltd
Company number 16414166
Registered office: Orchard Bank, Bishopswood, Ross-On-Wye, United Kingdom, HR9 5QX
Not registered for VAT.
Privacy: [email protected]
Cancellations: [email protected]
General: [email protected]
Website: https://gowildbooking.com
Annex A — Details of processing
Subject matter. Hosting and operation of a booking and operations platform for outdoor adventure and hire businesses, including guest-facing checkout, diaries, and operational messaging.
Duration. The term of the Subscriber's account, plus the deletion period in clause 10.
Nature and purpose. Collection, storage, organisation, retrieval, transmission, display, and deletion of booking records, and sending operational notifications, in order to provide the Service to the Controller.
Categories of data subject. End Users (guests and other customers of the Controller); other individuals whose personal data the Controller chooses to upload (for example staff names on a daily sheet, or a child's name included in an adult's booking).
Types of personal data. Identity and contact data (name, email, phone number); booking details (activity, date, time, party size, notes, booking reference); payment status and amounts associated with a booking (card details are handled by the Controller's payment provider, not stored by us as cardholder data); message content and delivery metadata for email, SMS, and WhatsApp sent or received through the Service; and technical logs created while providing the Service.
Special-category data. Not required by the Service. The Controller may choose to include health or similar notes in a booking. If they do, that data is processed only on their instructions and they must have a valid Article 9 condition.
Annex B — Subprocessor categories
We may use subprocessors in the following categories to process End User Data:
- Secure cloud hosting and infrastructure.
- Transactional email delivery.
- SMS delivery, where the Controller uses SMS features.
- Meta Platforms, Inc. and affiliates, for WhatsApp Business Platform message delivery, where the Controller uses WhatsApp features.
- Payment processors, where the Controller takes guest payments through the Service. Guest card payments are taken through the Controller's own payment provider account.
Using a feature (for example WhatsApp or card checkout) is an instruction to transfer the relevant data to the provider of that feature.
Annex C — Security measures
We maintain technical and organisational measures appropriate to a multi-tenant booking platform, including:
- Access controls and least-privilege access to production systems.
- Encryption of data in transit where appropriate (HTTPS/TLS).
- Authentication of Subscriber accounts, including support for keeping credentials confidential as described in the Terms.
- Isolation of customer data in a multi-tenant architecture so one Subscriber cannot access another's End User Data through normal use of the Service.
- Logging, monitoring, and measures aimed at detecting and responding to unauthorised access.
- Staff confidentiality undertakings for those who may access production data.
- Backup and restoration processes for service continuity, with backups protected to a standard comparable to live data.
No method of transmission or storage is completely secure. These measures are designed to reduce risk, not to eliminate it.