Note on this version (v1.1, April 2026). Earlier versions of this document were styled as a "Data Processing Agreement" in which the Partner was named as the Data Controller and Tek a Hike Limited as the Data Processor for event participant data. That framing was inaccurate under the Jamaica Data Protection Act, 2020 ("JDPA"): Tek a Hike determines the purposes and means of processing participant data on the Platform — registration schema, waiver content, security controls, retention schedules, and the data-subject rights surface — so Tek a Hike is the Controller. Partners receive a limited recipient view of participants who book their events and act as Tek a Hike's processor only for in-platform actions. This Annex now reflects that, and Partners are asked to re-accept it.
1. Parties and background
This Data Sharing & Processing Annex ("Annex") supplements the Partner Agreement between Tek a Hike Limited ("Tek a Hike", "Controller", "we") and the Partner ("Recipient", "Limited Processor", "you").
Tek a Hike is the Data Controller for personal data processed through the Platform — including data about participants who book Partner's events. Tek a Hike makes a limited recipient view of that data available to Partner so Partner can deliver the booked experience and steward the booking.
2. Subject matter, scope, and purpose
- Subject matter: the limited Participant Personal Data Tek a Hike makes available to Partner about hikers who book Partner's events.
- Permitted purposes (DSA.2): roll-call and head-count, day-of safety briefings, replying to participants through the in-platform inbox, sending Tek a Hike-issued safety / weather / meeting-point updates, recording attendance and incident outcomes back to the Platform, and honouring the waiver and disclosed special requirements.
- Prohibited uses: export, copy, scrape, sync, or extraction for external CRMs, mailing lists, marketing platforms, profiling, resale, or any onward disclosure not authorised by Tek a Hike.
- Duration: for as long as Partner has access to participant data through the Platform, plus the post-termination period in DSA.8 needed to delete copies.
3. Categories of data subjects and personal data
- Data subjects: hikers and participants who register through the Platform for Partner's events.
- Participant Personal Data shared with Partner: name, contact details supplied for the booking, party size, emergency contact (where collected), declared special requirements relevant to safety, attendance status, in-platform messages, and payout-relevant booking metadata.
4. Tek a Hike's obligations as Controller
Tek a Hike will:
- Maintain a lawful basis under the JDPA for each category of processing and disclose it in the Privacy Policy.
- Provide participants with the information required by JDPA Articles 13–14 at the point of collection.
- Operate the data-subject rights surface (access, rectification, erasure, restriction, portability, objection, withdrawal of consent) and respond within 30 days.
- Implement and maintain appropriate technical and organisational security measures — TLS 1.2+ in transit, encryption at rest for sensitive fields, RBAC, MFA on admin accounts, audit logging, vulnerability management.
- Notify the Office of the Information Commissioner and affected participants of any reportable personal data breach within 72 hours of becoming aware, in line with JDPA Articles 33–34.
- Maintain records of processing activities and a sub-processor register, available to Partner on reasonable written request.
- Honour the retention schedule published in the Privacy Policy and delete or anonymise data when those schedules expire.
5. Partner's obligations as Recipient and Limited Processor
Partner will:
- Use Participant Personal Data only for the purposes set out in section 2 and only on Tek a Hike's documented instructions through the Platform.
- Restrict access to staff and guides who genuinely need it to deliver the booking, and ensure they are bound by appropriate confidentiality obligations.
- Not export, copy, scrape, sync, or otherwise extract participant contact details for any external CRM, mailing list, marketing platform, or third party not authorised by Tek a Hike.
- Forward to Tek a Hike, without undue delay, any participant rights request, complaint, or correction received offline so we can fulfil it from the system of record.
- Notify Tek a Hike's Data Protection Office at hello@tekahike.com within 24 hours of becoming aware of any incident affecting participant data in Partner's possession or control (lost or stolen device, misdirected message, unauthorised access, etc.) so Tek a Hike can meet its 72-hour regulatory clock.
- Apply reasonable technical and organisational safeguards to any participant data on Partner-controlled devices: lock screens, encrypted storage, no shared accounts, prompt deletion of obsolete copies.
- Delete or destroy any local copies of Participant Personal Data within 30 days of the experience completing, unless retention is required by law (for example, an incident report needed for an insurance claim).
- Recognise that if Partner re-collects participant data outside the Platform — in-person sign-up sheets, off-platform marketing consent, follow-up questionnaires, social-media remarketing — Partner becomes a separate Data Controller for that re-collected data and is independently responsible under the JDPA. Tek a Hike's lawful basis does not extend to it.
6. Sub-processors engaged by Tek a Hike
Tek a Hike engages the following categories of sub-processor to operate the Platform. By accepting this Annex, Partner is informed of and authorises these engagements:
- Hosting (cloud infrastructure provider).
- Transactional email delivery.
- SMS delivery (Twilio).
- Payments (Stripe, Scotiabank).
No third-party analytics, advertising, or profiling sub-processor. Tek a Hike does not engage Google Analytics, Meta Pixel, Segment, Mixpanel, Hotjar, advertising networks, or any other third-party analytics or profiling service for personal data, and does not share Participant Personal Data, hiker accounts, or partner accounts with any such service. All platform analytics are first-party and based on aggregated site and platform usage activity (page views, feature usage, error rates) collected, processed, and stored on Tek a Hike's own infrastructure.
Tek a Hike will:
- Impose written obligations on each sub-processor that are no less protective than this Annex.
- Maintain an up-to-date sub-processor list in the partner dashboard.
- Give at least 30 days' notice before adding or replacing a sub-processor that handles participant data. Partner may object on reasonable data-protection grounds, in which case the parties will work in good faith to find a solution, failing which Partner may terminate the affected service.
7. Security measures
Tek a Hike implements appropriate technical and organisational measures to protect personal data, including:
- TLS 1.2+ encryption in transit and encryption at rest for sensitive fields (waiver, contact, special-requirement notes).
- Role-based access control, MFA on administrative accounts, and audit logging.
- Secure software development lifecycle, vulnerability scanning, and timely patching.
- Backups, business continuity planning, and periodic access reviews.
8. Personal data breaches
- Tek a Hike (Controller) notifies the Office of the Information Commissioner and affected participants within 72 hours of becoming aware of a reportable personal data breach (JDPA Articles 33–34).
- Partner must notify Tek a Hike's Data Protection Office within 24 hours of becoming aware of any incident affecting participant data in Partner's possession or control. Partner's notification must include the nature of the incident, the categories and approximate number of participants affected, the likely consequences, and the containment / remediation steps already taken.
9. Data subject rights
Tek a Hike operates the data-subject rights surface from the system of record. Partner will:
- Forward any rights request, complaint, or correction request received offline to Tek a Hike without undue delay.
- Not respond to or attempt to fulfil rights requests independently using exported data.
- Provide reasonable assistance (for example, retrieving a paper roll-call or incident note) when Tek a Hike needs it to fulfil a request.
10. Records and audit
- Tek a Hike maintains records of processing activities as required by the JDPA.
- On reasonable written request, and not more than once per year unless required by a regulator or following a confirmed breach, Tek a Hike will make available information necessary to demonstrate compliance with this Annex, and allow audits by Partner or an independent auditor mandated by Partner, at Partner's cost, subject to reasonable confidentiality and security restrictions.
11. International transfers
Where personal data is transferred outside Jamaica through a sub-processor, Tek a Hike ensures an adequate level of protection in line with the JDPA, using approved transfer mechanisms (such as standard contractual clauses) where required.
12. Retention and deletion of Partner-held copies
- Active bookings: Partner may hold Participant Personal Data for as long as the booking is active.
- Completed experiences: Partner deletes local copies (printed roll-calls, exported lists, in-message attachments) within 30 days of the experience date, unless a longer retention is required by law (for example, insurance/incident files).
- Termination of the Partner Agreement: Partner deletes or destroys all Participant Personal Data in its possession within 30 days, except where retention is required by law, and confirms deletion in writing on Tek a Hike's request.
- Tek a Hike-held records follow the retention schedule published in the Privacy Policy.
13. Liability
Each party's liability under this Annex is subject to the liability cap and exclusions in the Partner Agreement, except where higher liability cannot be limited by law.
14. Order of precedence
In the event of conflict between this Annex, the Partner Agreement, and the Terms of Service, this Annex prevails for matters concerning the processing of personal data.
15. Contact
Tek a Hike Limited — Data Protection Office Kingston, Jamaica Email: hello@tekahike.com