Version 1.0 · effective date to follow

Data Processing Agreement (Article 28 GDPR)

Version 1.0 · effective {{EFFECTIVE_DATE}}

between the Customer as controller (the organization that uses ALiSiO, identified in the Account or Order)

and {{PROVIDER_NAME}}, {{PROVIDER_ADDRESS}}, company ID {{PROVIDER_ID}} ("Provider") as processor.

This Data Processing Agreement ("DPA") forms part of the ALiSiO Terms of Service ("Terms"). It is concluded by acceptance in the Service or by signature. Terms defined in the GDPR (Regulation (EU) 2016/679) have the same meaning here.

1. Subject matter and duration

1.1 The Provider processes personal data on behalf of the Customer in order to provide the ALiSiO service ("Service"). Subject matter, nature and purpose of the processing, the types of personal data and the categories of data subjects are described in Annex 1.

1.2 This DPA applies for as long as the Provider processes personal data on behalf of the Customer, including the period after the end of the Terms until deletion under Section 11.

2. Instructions

2.1 The Provider processes personal data only on documented instructions of the Customer, unless required to do so by Union or Member State law; in that case the Provider informs the Customer before processing unless the law prohibits such information.

2.2 The Terms, this DPA, the configuration of the Account by the Customer and its Users (for example activated Modules, retention settings, connected channels) constitute the Customer's documented instructions. Further instructions are given in text form.

2.3 The Provider informs the Customer without undue delay if it considers that an instruction infringes data protection law, and may suspend the instruction until the Customer confirms or changes it.

3. Confidentiality

The Provider ensures that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that they process the data only as instructed.

4. Security of processing

4.1 The Provider implements the technical and organizational measures described in Annex 2 (Technical and Organizational Measures, "TOMs").

4.2 The TOMs are subject to technical progress. The Provider may replace them with adequate alternatives provided the level of security is not reduced. Significant changes are documented in a new version of Annex 2.

5. Support access

5.1 Provider staff access a Customer's Account only where necessary for onboarding, support requested by the Customer, the security of the Service or the remedy of a defect.

5.2 Such access uses a separate support login. It is logged in the Customer's Account, is visible to the Customer, is marked on every screen and expires after at most 24 hours.

6. Subprocessors

6.1 The Customer gives the Provider general written authorization to engage subprocessors. The subprocessors engaged at the effective date of this DPA are listed in Annex 3; the current list is published at https://beta.alisio.rozum.one/legal/subprocessors.

6.2 The Provider notifies the Customer of any intended addition or replacement of a subprocessor at least 30 days in advance, by email to the notification email address in the Account and by a notice in the Service. Anyone may additionally subscribe to such notices on the subprocessor page.

6.3 The Customer may object to the change in text form within that notice period on reasonable grounds relating to data protection. The parties will try to find a solution in good faith. If no solution is found, the Customer may terminate the affected Modules or the Terms with effect before the change takes effect; prepaid fees for the period after termination are refunded.

6.4 Where a subprocessor must be replaced at short notice to protect the security or continuity of the Service, the Provider may do so before the end of the notice period and informs the Customer without undue delay; Section 6.3 applies accordingly.

6.5 The Provider concludes a contract with each subprocessor that imposes data protection obligations equivalent to those in this DPA, in particular sufficient guarantees for appropriate technical and organizational measures. The Provider remains responsible to the Customer for the performance of its subprocessors.

6.6 Third parties that the Customer connects to its Account under its own contract (for example online travel agencies, payment service providers or fiscal service providers contracted by the Customer) are not subprocessors of the Provider.

7. Transfers to third countries

The Provider transfers personal data to a country outside the European Economic Area only if the conditions of Chapter V GDPR are met, in particular on the basis of an adequacy decision (including the EU–U.S. Data Privacy Framework for certified recipients) or standard contractual clauses adopted by the European Commission. The legal basis for each subprocessor is stated in Annex 3.

8. Data subject rights

8.1 Taking into account the nature of the processing, the Provider assists the Customer by appropriate technical and organizational measures in responding to requests of data subjects. The Service contains functions to export and to erase the data of an individual guest and to set retention periods.

8.2 If a data subject contacts the Provider directly, the Provider forwards the request to the Customer without undue delay and does not answer it itself unless instructed.

9. Assistance

The Provider assists the Customer, taking into account the nature of processing and the information available to it, in ensuring compliance with Articles 32 to 36 GDPR (security, notification of breaches, data protection impact assessments and prior consultation). The Provider may charge reasonable costs for assistance that goes beyond providing information it already has, unless the need for assistance results from a breach by the Provider.

10. Personal data breaches

10.1 The Provider notifies the Customer without undue delay, and at the latest within 48 hours, after becoming aware of a personal data breach affecting the Customer's data.

10.2 The notification contains, as far as available, the information listed in Article 33(3) GDPR. Information not yet available is provided in phases without undue further delay.

10.3 The Provider takes the necessary measures to secure the data and to mitigate possible adverse consequences and documents the breach.

11. Deletion and return

11.1 After the end of the Terms the Customer may export its data for 30 days using the export functions of the Service or on request.

11.2 The Provider then deletes the personal data, unless Union or Member State law requires storage. Backups are overwritten in the regular backup cycle (currently within 30 days). The Provider confirms deletion on request.

12. Information and audits

12.1 The Provider makes available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR, in particular this DPA, the current TOMs and the list of subprocessors.

12.2 The Customer may carry out audits, including inspections, itself or through an independent auditor bound to confidentiality, as a rule not more than once per year, with at least 30 days' notice, during normal business hours and without disproportionate disruption of the Provider's operations. The Customer bears its own costs. Where the Provider can demonstrate compliance through current certifications or reports, these replace an on-site audit unless there are concrete indications of a breach.

13. Records of processing

The Provider keeps a record of all categories of processing activities carried out on behalf of the Customer in accordance with Article 30(2) GDPR.

14. Liability

Liability is governed by Article 82 GDPR and, as between the parties, by the Terms.

15. Changes to this DPA

Changes to this DPA and to Annex 2 follow Section 14 of the Terms (notice at least 30 days in advance, right to object and to terminate). Changes to Annex 3 (subprocessors) follow Section 6 of this DPA.

16. Final provisions

16.1 In case of conflict between this DPA and the Terms, this DPA prevails in all matters of personal data protection.

16.2 Should any provision of this DPA be invalid, the remaining provisions remain effective.


Annex 1 — Description of the processing

Nature and purpose. Provision of a cloud property management system to the Customer: management of reservations and room plans; registration of guests as required by the law of the property's country; folios, invoices and recording of payments; guest communication (confirmations, reminders, guest page, kiosk, access codes); connection to channels and other services the Customer activates; reports; backups, security and support.

Processing operations. Collection via the Service and via connected channels, storage, organization, retrieval, use, disclosure by transmission to recipients chosen by the Customer, restriction, anonymization and erasure (including automatic erasure according to the retention settings of the Account), backup and restoration.

Categories of data subjects.

Types of personal data.

Special categories of data (Art. 9 GDPR). Not intended. The Customer does not enter such data unless necessary and lawful (Terms, Section 5.5).

Duration. For the term of the Terms plus the period under Section 11. Within that period the retention settings chosen by the Customer apply.

Location. The Service is hosted in the European Union (Germany). Backups are stored encrypted in the European Union. Transfers outside the EEA only as stated in Annex 3.

Annex 2 — Technical and organizational measures

See the document "ALiSiO Technical and Organizational Measures", version 1.0, published at https://beta.alisio.rozum.one/legal/toms, which forms part of this DPA.

Annex 3 — Subprocessors

See the document "ALiSiO Subprocessors", version 1.0, published at https://beta.alisio.rozum.one/legal/subprocessors, which forms part of this DPA.