Data Processing Agreement (Article 28 GDPR)
Version 1.0 · effective {{EFFECTIVE_DATE}}
between the Customer as controller (the organization that uses ALiSiO, identified in the Account or Order)
and {{PROVIDER_NAME}}, {{PROVIDER_ADDRESS}}, company ID {{PROVIDER_ID}} ("Provider") as processor.
This Data Processing Agreement ("DPA") forms part of the ALiSiO Terms of Service ("Terms"). It is concluded by acceptance in the Service or by signature. Terms defined in the GDPR (Regulation (EU) 2016/679) have the same meaning here.
1. Subject matter and duration
1.1 The Provider processes personal data on behalf of the Customer in order to provide the ALiSiO service ("Service"). Subject matter, nature and purpose of the processing, the types of personal data and the categories of data subjects are described in Annex 1.
1.2 This DPA applies for as long as the Provider processes personal data on behalf of the Customer, including the period after the end of the Terms until deletion under Section 11.
2. Instructions
2.1 The Provider processes personal data only on documented instructions of the Customer, unless required to do so by Union or Member State law; in that case the Provider informs the Customer before processing unless the law prohibits such information.
2.2 The Terms, this DPA, the configuration of the Account by the Customer and its Users (for example activated Modules, retention settings, connected channels) constitute the Customer's documented instructions. Further instructions are given in text form.
2.3 The Provider informs the Customer without undue delay if it considers that an instruction infringes data protection law, and may suspend the instruction until the Customer confirms or changes it.
3. Confidentiality
The Provider ensures that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that they process the data only as instructed.
4. Security of processing
4.1 The Provider implements the technical and organizational measures described in Annex 2 (Technical and Organizational Measures, "TOMs").
4.2 The TOMs are subject to technical progress. The Provider may replace them with adequate alternatives provided the level of security is not reduced. Significant changes are documented in a new version of Annex 2.
5. Support access
5.1 Provider staff access a Customer's Account only where necessary for onboarding, support requested by the Customer, the security of the Service or the remedy of a defect.
5.2 Such access uses a separate support login. It is logged in the Customer's Account, is visible to the Customer, is marked on every screen and expires after at most 24 hours.
6. Subprocessors
6.1 The Customer gives the Provider general written authorization to engage subprocessors. The subprocessors engaged at the effective date of this DPA are listed in Annex 3; the current list is published at https://beta.alisio.rozum.one/legal/subprocessors.
6.2 The Provider notifies the Customer of any intended addition or replacement of a subprocessor at least 30 days in advance, by email to the notification email address in the Account and by a notice in the Service. Anyone may additionally subscribe to such notices on the subprocessor page.
6.3 The Customer may object to the change in text form within that notice period on reasonable grounds relating to data protection. The parties will try to find a solution in good faith. If no solution is found, the Customer may terminate the affected Modules or the Terms with effect before the change takes effect; prepaid fees for the period after termination are refunded.
6.4 Where a subprocessor must be replaced at short notice to protect the security or continuity of the Service, the Provider may do so before the end of the notice period and informs the Customer without undue delay; Section 6.3 applies accordingly.
6.5 The Provider concludes a contract with each subprocessor that imposes data protection obligations equivalent to those in this DPA, in particular sufficient guarantees for appropriate technical and organizational measures. The Provider remains responsible to the Customer for the performance of its subprocessors.
6.6 Third parties that the Customer connects to its Account under its own contract (for example online travel agencies, payment service providers or fiscal service providers contracted by the Customer) are not subprocessors of the Provider.
7. Transfers to third countries
The Provider transfers personal data to a country outside the European Economic Area only if the conditions of Chapter V GDPR are met, in particular on the basis of an adequacy decision (including the EU–U.S. Data Privacy Framework for certified recipients) or standard contractual clauses adopted by the European Commission. The legal basis for each subprocessor is stated in Annex 3.
8. Data subject rights
8.1 Taking into account the nature of the processing, the Provider assists the Customer by appropriate technical and organizational measures in responding to requests of data subjects. The Service contains functions to export and to erase the data of an individual guest and to set retention periods.
8.2 If a data subject contacts the Provider directly, the Provider forwards the request to the Customer without undue delay and does not answer it itself unless instructed.
9. Assistance
The Provider assists the Customer, taking into account the nature of processing and the information available to it, in ensuring compliance with Articles 32 to 36 GDPR (security, notification of breaches, data protection impact assessments and prior consultation). The Provider may charge reasonable costs for assistance that goes beyond providing information it already has, unless the need for assistance results from a breach by the Provider.
10. Personal data breaches
10.1 The Provider notifies the Customer without undue delay, and at the latest within 48 hours, after becoming aware of a personal data breach affecting the Customer's data.
10.2 The notification contains, as far as available, the information listed in Article 33(3) GDPR. Information not yet available is provided in phases without undue further delay.
10.3 The Provider takes the necessary measures to secure the data and to mitigate possible adverse consequences and documents the breach.
11. Deletion and return
11.1 After the end of the Terms the Customer may export its data for 30 days using the export functions of the Service or on request.
11.2 The Provider then deletes the personal data, unless Union or Member State law requires storage. Backups are overwritten in the regular backup cycle (currently within 30 days). The Provider confirms deletion on request.
12. Information and audits
12.1 The Provider makes available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR, in particular this DPA, the current TOMs and the list of subprocessors.
12.2 The Customer may carry out audits, including inspections, itself or through an independent auditor bound to confidentiality, as a rule not more than once per year, with at least 30 days' notice, during normal business hours and without disproportionate disruption of the Provider's operations. The Customer bears its own costs. Where the Provider can demonstrate compliance through current certifications or reports, these replace an on-site audit unless there are concrete indications of a breach.
13. Records of processing
The Provider keeps a record of all categories of processing activities carried out on behalf of the Customer in accordance with Article 30(2) GDPR.
14. Liability
Liability is governed by Article 82 GDPR and, as between the parties, by the Terms.
15. Changes to this DPA
Changes to this DPA and to Annex 2 follow Section 14 of the Terms (notice at least 30 days in advance, right to object and to terminate). Changes to Annex 3 (subprocessors) follow Section 6 of this DPA.
16. Final provisions
16.1 In case of conflict between this DPA and the Terms, this DPA prevails in all matters of personal data protection.
16.2 Should any provision of this DPA be invalid, the remaining provisions remain effective.
Annex 1 — Description of the processing
Nature and purpose. Provision of a cloud property management system to the Customer: management of reservations and room plans; registration of guests as required by the law of the property's country; folios, invoices and recording of payments; guest communication (confirmations, reminders, guest page, kiosk, access codes); connection to channels and other services the Customer activates; reports; backups, security and support.
Processing operations. Collection via the Service and via connected channels, storage, organization, retrieval, use, disclosure by transmission to recipients chosen by the Customer, restriction, anonymization and erasure (including automatic erasure according to the retention settings of the Account), backup and restoration.
Categories of data subjects.
- guests and accompanying persons, including children;
- bookers, payers and contact persons of companies (for example travel agencies, employers of business travellers);
- Users of the Customer (employees and other authorized persons);
- other persons whose data the Customer enters (for example suppliers, service providers).
Types of personal data.
- identification data: name, salutation, date of birth, nationality, gender where required by registration law;
- contact data: postal address, email address, phone number, preferred language;
- identity document data where required by law or chosen by the Customer: document type, number, issuing country or authority, validity; images of identity documents are processed only if the Customer activates document recognition (see Annex 3) and are not stored permanently;
- stay data: dates, room, number and age group of guests, arrival time, special requests, notes, access codes;
- billing and payment data: folios, invoices, amounts, payment method, payment references; no complete payment card numbers;
- tax-related data: tourist or city tax category and exemption reason, reference to the supporting document;
- signatures on registration forms, where used;
- content of communication between the Customer and guests sent through the Service;
- technical data of Users and guests using the Service: IP address, browser information, login and action logs.
Special categories of data (Art. 9 GDPR). Not intended. The Customer does not enter such data unless necessary and lawful (Terms, Section 5.5).
Duration. For the term of the Terms plus the period under Section 11. Within that period the retention settings chosen by the Customer apply.
Location. The Service is hosted in the European Union (Germany). Backups are stored encrypted in the European Union. Transfers outside the EEA only as stated in Annex 3.
Annex 2 — Technical and organizational measures
See the document "ALiSiO Technical and Organizational Measures", version 1.0, published at https://beta.alisio.rozum.one/legal/toms, which forms part of this DPA.
Annex 3 — Subprocessors
See the document "ALiSiO Subprocessors", version 1.0, published at https://beta.alisio.rozum.one/legal/subprocessors, which forms part of this DPA.