SVOYAGER Data Processing & Privacy Addendum (DPA)

Last updated: 31 May 2026

This Data Processing & Privacy Addendum (DPA) forms part of the agreement between SVOYAGER CONCIERGE & CONSULTANCY - FZCO, operating under the brand name SVOYAGER (SVOYAGER, we, our, us or Processor), and the business customer, partner, agency, platform, publisher or other entity using SVOYAGER's B2B photo widget, hosted partner links, API, white-label access or related services (Customer, Partner, you, your or Controller).

This DPA applies to the processing of personal data in connection with SVOYAGER's generation, validation, preview and final file delivery of photos for passports, visas, IDs and other documents, together with partner tracking, billing, reporting and related technical services. This DPA supplements, and does not replace, the main commercial agreement, partner terms, order form, pricing agreement or platform terms, and applies only to data processing and privacy obligations.

1. Purpose

SVOYAGER provides AI-enabled photo processing, document photo formatting, partner tracking, hosted photo flows, embedded widgets and B2B API access for travel, visa, relocation, immigration and related partners. In the course of providing these services, SVOYAGER may process personal data on behalf of the Partner and, where applicable, the Partner's end users. This DPA sets out the privacy, security, data handling, retention, confidentiality, subprocessor and deletion commitments applicable to such services.

2. Roles of the Parties

2.1 Partner as Controller. For B2B partner use cases, the Partner generally acts as the Controller of personal data relating to its own customers, users, leads, clients or website visitors, and determines why its users are offered the photo service, how it is presented, the applicable legal basis, the integration model, and how the Partner communicates with its users about privacy, consent, payment and service terms.

2.2 SVOYAGER as Processor. SVOYAGER acts as a Processor when it processes personal data on behalf of the Partner to provide the B2B photo widget, hosted partner link, API, white-label access, reporting and related services, only in accordance with the Partner's documented instructions, as necessary to provide the services, as required by applicable law, and as permitted under the main agreement, this DPA and applicable privacy laws.

2.3 SVOYAGER as Independent Controller in Limited Cases. SVOYAGER may act as an independent Controller for limited purposes, including partner account management, billing, invoicing, accounting and tax compliance, fraud prevention, abuse detection and security monitoring, legal claims, compliance and dispute management, and direct communications with Partners regarding the service.

2.4 Subprocessors. SVOYAGER may use subprocessors to deliver the services, including SNAPFLOW LLC as an underlying AI photo-processing provider. Those providers process data only as necessary to deliver the photo-processing, hosting, storage, security, payment or infrastructure services.

3. Scope of Processing

This DPA applies to personal data processed through SVOYAGER-hosted partner links (the Partner sends users to a tracked SVOYAGER-hosted link, for example https://svoyager.com/{locale}/passport-photo?ref={code}), the embedded SVOYAGER widget (embedded on the Partner's own surface, with processing routed through SVOYAGER's backend), and the SVOYAGER B2B API / white-label access (the Partner connects to SVOYAGER's API using SVOYAGER-issued credentials).

4. Categories of Personal Data

The personal data processed may include uploaded user photos, generated previews and final no-watermark photos, printable photo sheets where supported, selected document type/country/specification code, technical metadata (file type, file size, request ID, processing status, timestamps, error/issue codes), user email address where required for delivery/payment/support, Partner/campaign/tenant/affiliate/tracking identifiers or API key identifier, IP address, browser/device metadata, logs and security events, payment status/order/transaction/billing metadata, and support communications. Where possible, the Partner should minimize the personal data shared with SVOYAGER.

5. Categories of Data Subjects

Data subjects may include the Partner's customers and website visitors, visa/immigration/relocation/travel/document service clients, end users generating passport/visa/ID/document photos, Partner employees or authorized users managing the account, SVOYAGER B2C users, and individuals contacting support regarding the photo service.

6. Processing Instructions

The Partner instructs SVOYAGER to process personal data only for the purposes described in this DPA and the applicable agreement. SVOYAGER will not process personal data for any unrelated purpose unless required by law, required for security, fraud prevention or abuse prevention, expressly authorized by the Partner, or necessary to provide, maintain or improve the contracted service in a way permitted by this DPA. If SVOYAGER believes an instruction violates applicable data protection law, it may notify the Partner and suspend the relevant processing until clarified.

7. Data Protection Principles and Security

SVOYAGER will apply appropriate technical and organizational safeguards designed to protect personal data against unauthorized access, disclosure, alteration, loss, misuse or destruction, and will process personal data in line with the principles of lawfulness, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability. All data transmitted to and from SVOYAGER services must be protected using industry-standard encrypted transport (TLS/HTTPS).

8. Data Storage Options

Option A — Temporary Cloud Storage. Customer images, preview outputs, final outputs and associated processing data may be temporarily stored within secure cloud infrastructure for operational purposes (preview access, final delivery, email recovery, order completion, refund/remake support, abuse prevention, debugging, billing verification, partner reporting). Recommended SVOYAGER defaults: preview images 24 hours; final no-watermark files 24 hours; order metadata up to 7 years where needed for tax/accounting/legal; technical logs 30 to 180 days. Where the underlying provider supports configurable retention, SVOYAGER may select a period between 2 hours and 14 days unless a shorter or longer period is required by law, security, support or the Partner's configuration.

Option B — Stateless / No-storage Processing. Where technically available, uploaded images are sent for processing and processed outputs are returned directly (for example as Base64), with persistent storage minimized or disabled. This option is recommended for Partners with heightened privacy, compliance, financial, government, healthcare, immigration or enterprise requirements.

9. Data Ownership

The Partner, or the Partner's end user where applicable, retains all rights, ownership and interest in uploaded images, generated previews, final photo outputs and related user content. SVOYAGER does not claim ownership of uploaded user photos or final generated photo files, and receives only the rights necessary to process the photo, generate outputs, deliver the service, provide support, operate/secure/improve the service, comply with legal obligations and enforce the applicable agreement.

10. No Sale, No Advertising, No AI Training Without Permission

SVOYAGER will not sell Partner or end-user personal data, will not use uploaded images, generated outputs or end-user personal data for third-party advertising, and will not use Partner or end-user image data for AI model training unless expressly authorized in writing (where applicable), permitted under applicable law, and clearly disclosed in the applicable privacy notice. SVOYAGER will require its subprocessors to observe the same restrictions unless expressly authorized.

11. Partner Privacy Responsibilities

The Partner is responsible for providing appropriate privacy notices and obtaining any required consent or legal basis from its end users before sending personal data to SVOYAGER, and for clearly informing users that their photo will be processed to generate a document photo, that the service may involve automated processing, that SVOYAGER and subprocessors may process the image and metadata, that payment may be required for the final file, and that a generated photo does not guarantee approval by any authority. The Partner must not describe the service in a misleading way.

12. Confidentiality and Access

SVOYAGER personnel, contractors and authorized subprocessors with access to personal data are subject to confidentiality obligations appropriate to the nature of the information. Access is limited to authorized personnel with a legitimate business, technical, security, support or operational need.

13. Security Monitoring and Audits

SVOYAGER performs periodic reviews and monitoring to identify, prevent and mitigate security risks, including infrastructure monitoring, access control, role-based access, vulnerability assessments, dependency updates, API abuse monitoring, logging/alerting, credential rotation and incident response. Upon reasonable written request, and subject to confidentiality and security limitations, SVOYAGER may provide information reasonably necessary to demonstrate compliance with this DPA.

14. Subprocessors and Infrastructure Providers

SVOYAGER may use reputable third-party subprocessors and infrastructure providers, subject to appropriate contractual confidentiality, security and data-protection obligations. Current subprocessors include SNAPFLOW LLC (AI photo processing), Supabase (database/auth/application backend), Stripe (payments), Vercel including Vercel Blob (hosting and temporary file storage/delivery), Resend (transactional email), Upstash (rate-limiting and idempotency) and Sentry (error monitoring/observability). AWS is the underlying cloud infrastructure of Supabase and Vercel and is not engaged directly as a separate subprocessor. The current list is published at /legal/subprocessors.

15. Changes to Subprocessors

SVOYAGER may add, replace or remove subprocessors from time to time. For enterprise Partners, SVOYAGER may provide prior notice of material subprocessor changes where required by the applicable agreement. If the Partner has a reasonable data-protection objection to a new subprocessor, it may notify SVOYAGER in writing and the parties will work in good faith to resolve it.

16. International Data Transfers

Personal data may be processed in countries where SVOYAGER, its infrastructure providers, subprocessors or service providers operate. Where required by applicable law, SVOYAGER will use appropriate transfer mechanisms, which may include Standard Contractual Clauses, the UK International Data Transfer Addendum, adequacy decisions, contractual safeguards, data localization settings where available, or stateless processing mode where supported.

17. API Keys and Access Controls

SVOYAGER may issue API keys, client IDs, partner IDs, tenant IDs, embed tokens or other credentials. The Partner is responsible for keeping credentials confidential, not exposing secret keys in front-end code, restricting access to authorized employees and systems, promptly rotating keys if compromise is suspected, notifying SVOYAGER of unauthorized use, and ensuring API usage complies with the applicable agreement and documentation.

18. Usage Data, Logs and Partner Reporting

SVOYAGER may process technical and usage data for API usage tracking, partner attribution, billing and invoicing, revenue-share or commission calculation, fraud prevention, debugging, service analytics, SLA monitoring, product improvement and security monitoring. SVOYAGER should avoid exposing unnecessary end-user personal data in Partner dashboards unless required for support, billing or the specific integration model.

19. Payment Data

Where SVOYAGER processes payments directly, payment card data is handled by a PCI-compliant payment processor such as Stripe. SVOYAGER does not store full card numbers, CVC codes or sensitive payment authentication data on its own servers, and may store limited payment metadata such as payment status, order ID, transaction ID, amount, currency, receipt URL, refund status, Partner attribution, invoice metadata and tax/accounting records.

20. Data Subject Requests

To the extent required by applicable law, SVOYAGER will provide reasonable assistance to the Partner in responding to data subject requests (access, correction, deletion, restriction, objection, portability, withdrawal of consent). The Partner is responsible for verifying the requester's identity and determining whether the request should be fulfilled. If SVOYAGER receives a request directly from a Partner's end user, it may direct the user to the Partner, respond directly where legally required, request verification, or cooperate with the Partner.

21. Data Deletion

Upon Partner request, termination of the services or expiry of the applicable retention period, SVOYAGER will delete or anonymize personal data in accordance with the applicable retention configuration, unless retention is required by law or necessary for tax records, accounting records, dispute resolution, fraud prevention, security investigations, legal claims or compliance obligations.

22. Security Incidents

SVOYAGER maintains reasonable procedures to detect, investigate and respond to security incidents involving personal data. If SVOYAGER becomes aware of a confirmed personal data breach affecting Partner personal data, it will notify the Partner without undue delay after becoming aware, with available details of the incident, affected data, likely consequences, measures taken and a contact point. SVOYAGER may delay notification where required by law enforcement, regulators or security investigations.

23. Accuracy and Official Requirements

SVOYAGER may provide automated formatting, cropping, background adjustment, validation and compliance checks based on selected photo specifications. However, official requirements may change and vary by jurisdiction, authority, embassy, consulate, visa center or application type. Unless expressly agreed otherwise, SVOYAGER does not guarantee acceptance by any government authority, visa approval, passport issuance, immigration approval, consular approval or acceptance by a third-party application center.

24. Governing Law and Order of Precedence

This DPA is governed by the laws of the United Arab Emirates as applied in the Emirate of Dubai (consistent with the SVOYAGER Photo Partner & API/Widget Terms), unless a different governing law is expressly specified in the main agreement. If there is a conflict between this DPA and the main agreement, the following order applies unless otherwise stated: mandatory applicable data protection law; this DPA for data protection matters; the main commercial agreement; the order form or pricing schedule; and the API/product documentation.

25. Governing Language

This DPA may be published in several languages for convenience. The English-language version prevails. In the event of any discrepancy, conflict or ambiguity between the English version and a translation, the English version applies, unless otherwise expressly required by the mandatory rules of applicable law.

26. Term and Contact

This DPA remains in effect for as long as SVOYAGER processes personal data on behalf of the Partner; provisions on confidentiality, security, deletion, audit records, legal compliance and liability survive termination to the extent required by law or the main agreement. For privacy, security or data processing inquiries, contact privacy@svoyager.com or hello@svoyager.com.