SafariBook Privacy notice
SafariBook legal

Lodge Data Processing Terms

Data Processing Addendum (DPA) · Version 1.3 · Last updated 22 August 2026

These Data Processing Terms are provided by Jason Degiorgio, a UK sole trader trading as SafariBook, Inn on the Lake Hotel, Watling Street, Gravesend, Kent, DA12 3HB, United Kingdom. Privacy contact: hello@safari-book.com.

How these terms apply. These Data Processing Terms form part of a SafariBook pilot agreement, service agreement, order form, onboarding email or other written arrangement when that arrangement expressly refers to these terms or to the published SafariBook Data Processing Terms. They continue for as long as SafariBook processes personal data for the lodge.

1. Parties, roles, definitions and precedence

  1. The lodge or safari operator using a SafariBook workspace is the Lodge.
  2. For guest and trip information and other personal data the Lodge causes SafariBook to process on its behalf (Lodge Personal Data), the Lodge normally acts as controller and SafariBook acts as processor.
  3. SafariBook acts as an independent controller for limited SafariBook business and operational purposes where SafariBook determines the purposes and means, including account/security administration, support and privacy correspondence, legal compliance, supplier administration, contract evidence and genuinely anonymised or aggregate service statistics.
  4. Applicable Data Protection Law means, to the extent applicable to the relevant processing: the UK GDPR and Data Protection Act 2018; the Kenya Data Protection Act 2019 and regulations made under it; and any other mandatory data-protection law identified in the parties' written pilot/service arrangement.
  5. If these terms conflict with another agreement between the parties on Lodge Personal Data, these terms take precedence for that processing except where mandatory law requires otherwise.

2. Processing details and documented instructions

  1. The subject matter, duration, nature and purpose of processing, categories of personal data and categories of data subject are set out in Annex A.
  2. The Lodge's use and configuration of SafariBook, these terms, the applicable pilot/service agreement and any saved written instructions from the Lodge constitute documented instructions for Lodge Personal Data.
  3. SafariBook will process Lodge Personal Data only for the purposes and operations described in Annex A or as otherwise documented by the Lodge, unless Applicable Data Protection Law binding on SafariBook requires processing. Where legally permitted, SafariBook will inform the Lodge before carrying out processing required by law.
  4. SafariBook will tell the Lodge if it considers a documented instruction to infringe Applicable Data Protection Law where SafariBook has a duty to do so.

3. The Lodge's 24-month standing retention instruction

  1. The Lodge instructs SafariBook to keep each guest trip and its related SafariBook content for up to 24 months after the trip's scheduled departure date, unless the Lodge instructs SafariBook to delete it earlier.
  2. This instruction covers the guest/party name and email, language, stay dates, private guest-book token, game drives, wildlife sightings, guide notes and captions, delivery records and guest engagement events linked to that trip.
  3. SafariBook currently enforces this instruction through a daily deletion process. When a trip reaches the retention limit, the trip and related records are deleted through database relationships and the private guest link stops working.
  4. The Lodge may delete a trip sooner through SafariBook where available or may send a written deletion instruction.
  5. If the Lodge corrects a scheduled departure date before deletion, the corrected date becomes the reference date for the 24-month period.
  6. A supplier may retain limited backup, security or transactional metadata temporarily under its protected deletion cycle. Such residual copies are kept beyond ordinary use and are not used for routine service purposes.

4. Lodge responsibilities

The Lodge is responsible for:

  1. determining and documenting an appropriate lawful basis and providing required privacy information;
  2. ensuring its instructions are lawful and limited to what is necessary;
  3. keeping information, including departure dates, sufficiently accurate for the intended use;
  4. limiting staff access to authorised people and removing access promptly;
  5. protecting private guest links and deciding who may receive them;
  6. not intentionally entering passport details, payment-card data, precise location data, health information or other unnecessary sensitive information;
  7. where Kenyan law applies, minimising family details that may constitute sensitive personal data. The Lodge should use a lead-guest name or neutral party label where practicable and should not enter children's full names, family relationships or other Kenyan sensitive personal data unless necessary, lawful and separately safeguarded;
  8. ensuring any international transfer it specifically instructs or causes has a lawful transfer basis and required safeguards; and
  9. promptly passing processor instructions needed for rights requests, complaints, incidents, regulator enquiries or deletion requests.

5. SafariBook processor obligations

For Lodge Personal Data processed as processor, SafariBook will:

  1. process it only on documented instructions as set out in section 2;
  2. ensure authorised persons are subject to appropriate confidentiality obligations;
  3. implement appropriate technical and organisational measures having regard to the risk, including Annex C;
  4. assist the Lodge, taking account of the nature of processing and information available, with data-subject rights, security, personal-data breaches, DPIAs and prior consultation where applicable;
  5. notify the Lodge without undue delay after becoming aware of a personal-data breach affecting Lodge Personal Data and provide reasonably available information;
  6. where section 43(3) of the Kenya Data Protection Act 2019 applies, notify the Lodge without delay and, where reasonably practicable, within 48 hours of becoming aware of the breach;
  7. maintain information reasonably necessary to demonstrate compliance; and
  8. allow and contribute to reasonable audits or inspections under section 11.

6. Sub-processors

  1. The Lodge gives SafariBook written authorisation to use the sub-processors listed in Annex B for the stated purposes.
  2. For a new or replacement material sub-processor, SafariBook will obtain the Lodge's prior general or specific written authorisation to the extent required by Applicable Data Protection Law. Where general authorisation is permitted, SafariBook will give reasonable advance notice where practicable so the Lodge can raise a reasonable documented objection.
  3. Where Kenyan law requires prior authorisation for a third-party processor, SafariBook will not appoint that third party for the relevant Kenyan Lodge Personal Data until the required Lodge authorisation is in place.
  4. SafariBook will appoint sub-processors under written terms requiring protection appropriate to the relevant processing and applicable obligations.
  5. SafariBook remains responsible to the Lodge for sub-processors' data-protection obligations to the extent required by Applicable Data Protection Law.

7. International transfers

  1. SafariBook will not make a restricted international transfer except on documented instructions, as necessary to provide the instructed service through an authorised sub-processor, or where required by law, and only where permitted by Applicable Data Protection Law.
  2. UK restricted transfers: an applicable mechanism may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another mechanism permitted by UK law.
  3. Transfers from Kenya: where Lodge Personal Data is transferred from Kenya, SafariBook and the Lodge will identify and document a permitted transfer condition and required safeguards. The transfer record should identify, as applicable, the recipient, country/territory, purpose, data categories and safeguard or other lawful transfer basis.
  4. SafariBook's main production database is currently configured in the EU (Ireland). Use by a Kenyan lodge therefore involves an international transfer from Kenya to the EU, and supplier infrastructure may create additional transfers. Those flows must be recorded in SafariBook's maintained sub-processor/international-transfer record before real Kenyan guest data is introduced.
  5. SafariBook does not intentionally require Kenyan sensitive personal data for the ordinary service. A proposed transfer of such data outside Kenya must not begin unless the parties have separately documented the lawful processing basis, obtained consent where Kenyan law requires it, and confirmed appropriate safeguards.
  6. Publication of these terms alone is not proof that a particular supplier transfer mechanism has been completed. Supplier-specific transfer evidence is maintained separately.

8. Data-subject rights and complaints

  1. If SafariBook receives a request directly relating to Lodge Personal Data, it will not respond on the merits except where required by law or authorised by the Lodge.
  2. SafariBook will, where appropriate, direct the person to the Lodge, notify the Lodge and provide reasonable technical or organisational assistance.
  3. Assistance can include locating, correcting or exporting information, restricting access, disabling a guest link, or deleting Lodge Personal Data on documented instruction.
  4. Nothing prevents a data subject from complaining to a competent regulator, including the UK Information Commissioner's Office or, where Kenyan law applies, the Office of the Data Protection Commissioner.

9. Security and personal-data breaches

  1. SafariBook will maintain security measures appropriate to the nature and risk of the service. Current measures are summarised in Annex C and may evolve provided the overall level of protection is not materially reduced.
  2. For a breach affecting Lodge Personal Data, SafariBook will provide available information about the nature of the incident, affected categories, likely consequences where known, relevant contact point, and mitigation/remedial action.
  3. Information may be provided in phases where necessary.
  4. SafariBook will maintain an internal record of material personal-data breaches and remedial action as required.
  5. The Lodge remains responsible for controller notifications to regulators and affected individuals where required, with SafariBook providing processor assistance. Under Kenyan law, where the statutory threshold is met, the controller's notification to the Data Commissioner is generally required within 72 hours of awareness.

10. Return and deletion; end of service

  1. These terms continue for as long as SafariBook processes Lodge Personal Data.
  2. Unless the Lodge gives a different instruction, already-created guest SafariBooks may remain available only until their individual 24-month deletion date.
  3. The Lodge may instruct earlier deletion or, before deletion, request a reasonable copy in a commonly used electronic format where technically practicable.
  4. SafariBook will delete remaining copies under its control after the applicable instruction, except where Applicable Data Protection Law requires retention. Protected backup copies may remain beyond routine use until overwritten under the provider's normal recovery cycle.
  5. If a database backup is restored, SafariBook's procedure is to reapply applicable deletion instructions before normal service resumes.

11. Audit and compliance information

  1. SafariBook will provide information reasonably necessary to demonstrate compliance with these terms.
  2. The Lodge may conduct or appoint an independent auditor to conduct an audit where reasonably necessary. Unless a serious incident or regulator requires otherwise, audits must be on reasonable notice, during normal business hours, normally no more than once in any 12-month period and must avoid unnecessary access to other customers' information or confidential security information.
  3. Existing independent reports, supplier compliance material, policies and written responses may be used first where they reasonably satisfy the request.

12. General

  1. Liability and commercial terms are governed by the applicable SafariBook service/pilot agreement. If there is no separate governing-law clause, these terms are governed by the laws of England and Wales.
  2. The governing-law clause does not exclude mandatory Kenyan or other Applicable Data Protection Law obligations that apply to the relevant processing.
  3. Nothing in these terms reduces either party's obligations under Applicable Data Protection Law.
  4. SafariBook may update these terms for law, suppliers, security or service changes. Material changes will be communicated before taking effect where reasonably practicable, and any new authorisation required for a sub-processor or materially different processing must be obtained before that processing begins.

Annex A — Processing description

Subject matter: Hosting and operating SafariBook for the Lodge, including lodge/staff access, guide profiles, game-drive logging, generation/display of private guest SafariBooks, transactional delivery, support, limited guest-engagement events, offline operation and related security.

Duration: For the Lodge's use of SafariBook and, for existing guest SafariBooks, until deletion under the standing 24-month instruction or earlier documented instruction.

Nature and purpose: Collection, recording, organisation, storage, retrieval, display, transmission, local-device caching for offline operation, synchronisation, support, security, deletion and limited aggregation necessary to provide, secure and maintain SafariBook on Lodge instructions.

Categories of data subjects: Lodge administrators; guides and authorised staff; safari guests and family/group members named in a trip; people whose details/images are intentionally included in lodge/guide content; and people who contact support in connection with the Lodge service.

Types of personal data: names, work/guest email, account/user identifiers and roles; language and guide profile details/photo; guest/party name, stay dates and assigned guide; private guest token/link status; drives, sightings, counts, notes, captions and story information; transactional delivery status/provider identifiers/errors; guest engagement events with a random event/session key and no persistent guest analytics identifier; staff device-local offline context/drafts/queues; authentication/security technical information such as timestamps, IP/user agent/audit events where available; and support/privacy correspondence.

Sensitive personal data: not designed to be required. Free-text can contain sensitive information if Lodge staff enter it. Kenyan law also treats certain family details as sensitive personal data; Kenyan Lodges must minimise such data and should not enter children's full names or explicit family relationships unless necessary, lawful and separately safeguarded.

Children: children may be members of a guest party, but SafariBook does not currently request age or date of birth. The Lodge determines necessity and is responsible for required transparency, authority, lawful basis and safeguards.

Annex B — Authorised sub-processors

Sub-processorPurposeCurrent location / transfer note
SupabaseDatabase, authentication, object storage and server/edge functions.Main SafariBook project is configured in the EU (Ireland). Supplier/onward-transfer details are maintained in the separate transfer record.
VercelWebsite hosting, static delivery and edge/network infrastructure.Processing locations and onward transfers are maintained in the separate supplier transfer record.
ResendTransactional SafariBook email delivery and associated delivery/technical records.Processing locations, provider retention and onward transfers are maintained in the separate supplier transfer record.
GoDaddyBusiness mailbox hosting for hello@safari-book.com, including lodge support and privacy correspondence.Processing locations, mailbox terms and onward transfers are maintained in the separate supplier transfer record.

The Lodge authorises these listed sub-processors for the stated purposes. Publication here does not remove SafariBook's obligation to complete applicable supplier-contract and international-transfer checks before processing that requires them.

Annex C — Current technical and organisational measures

  • authenticated staff access and invitation-only lodge workspaces;
  • tenant isolation and role-based Row Level Security;
  • least-privilege separation between browser roles and trusted service-role operations;
  • private, high-entropy guest-book links rather than public guest accounts;
  • private guide-photo storage and controlled signed access;
  • HTTPS/TLS in transit and provider-managed infrastructure security;
  • security headers including Content Security Policy, HSTS, frame denial and restrictive browser permissions;
  • user-scoped offline drafts and sync queues, with local user data cleared on sign-out where implemented;
  • service-worker caching limited to application-shell/static assets rather than Supabase API responses;
  • access restrictions around delivery configuration and service secrets;
  • multi-factor authentication on relevant infrastructure and mailbox administrator accounts;
  • compromised-password screening for SafariBook staff authentication;
  • version-pinned, first-party hosting of the Supabase browser client;
  • daily managed database backups with the last seven days available for restoration on the current Supabase Pro configuration, unless changed and documented;
  • a recovery procedure that reapplies applicable deletion instructions before normal service resumes after a restore;
  • routine patching and version-controlled database/source changes;
  • data minimisation, automatic 24-month guest-trip deletion and removal of persistent guest analytics identifiers; and
  • an operational data inventory/ROPA and retention documentation reviewed as the service changes.
Kenyan pilot launch condition. Supplier-specific transfer and contract verification, and any required Kenyan registration or other regulator steps, remain separate implementation requirements before real Kenyan guest data is introduced.
© 2026 SafariBookPrivacy notice · hello@safari-book.com