Data Processing Addendum

By signing up for a Host Account on Hosperly, the Host is fully accepting this Data Protection Addendum (herein DPA). 

This Addendum governs the Processing of Personal Data by Hosperly on behalf of the Host in connection with the provision of the Services and is intended to comply with Article 28 of Regulation (EU) 2016/679 -GDPR- and other applicable data protection legislation.

1. Definitions

“Authorized User” means an individual authorised by a Host to access and use the Services on the Host’s behalf, including the Host’s employees, personnel and other authorised representatives.

“Controller” means the entity that determines the purposes and means of the Processing of Personal Data.

“Guest(s)” means individual(s) who make or hold a reservation at a property managed through the Services.

“Host Personal Data” means Personal Data relating to Host, Guests and other individuals that is provided, submitted, uploaded or otherwise made available by or on behalf of the Host to Hosperly through or in connection with the Services, and which Hosperly Processes on behalf of the Host for the provision of the Services.

“Data Protection Laws” means all applicable laws and regulations relating to the protection of Personal Data and privacy applicable to the Processing under the Agreement, including the GDPR and member state law, as applicable.

“Data Subject” means an identified or identifiable natural person to whom Personal Data relates (herein data subjects or guests)

“Personal Data” means any information relating to an identified or identifiable natural person.

“Personal Data Breach” means an unlawful or accidental destruction, alteration or damage or loss, unauthorized disclosure of, or access to Personal Data, transmitted, stored or otherwise Processed by Hosperly under this DPA.

“Processing” has the meaning given to it under applicable Data Protection Laws and includes any operation performed on Personal Data, including collection, recording, organisation, storage, alteration, retrieval, consultation, use, disclosure, transmission and deletion.

“Processor” means the entity that Processes Personal Data on behalf of and in accordance with the documented instructions of the Controller.

“Standard Contractual Clauses” means contractual clauses adopted by the European Commission based on the GDPR;

“Sub-processor” means any third party appointed by Hosperly to Process Host Personal Data on behalf of the Host.

2. Scope and Roles

2.1 The Host and Hosperly acknowledge that, in relation to Host Personal Data Processed through the Services, the Host acts as the Controller and Hosperly acts as the Processor.

2.2 The Host determines the purposes and means of the Processing of Host Personal Data and is responsible for ensuring that the Processing is lawful and that it has an appropriate legal basis for the Processing.

2.3 Hosperly shall Process Host Personal Data only on behalf of the Host and in accordance with the Host’s documented instructions, as set out in this DPA, the Agreement and the configuration and use of the Services by the Host.

2.4 Nothing in this DPA prevents Hosperly from Processing Personal Data for purposes for which Hosperly acts as an independent Controller, including account administration, billing, security, fraud prevention, legal compliance, Host relationship management and other purposes described in the Hosperly Privacy Policy.

3. Description of Processing

3.1 The subject matter of the Processing is the provision and operation of the Services, including the hosting, storage, organisation, transmission and other Processing of Host Personal Data necessary to provide the Services.

3.2 Depending on how the Host uses the Services, Host Personal Data may relate to:

  • Guests and prospective Guests;
  • Booking platforms;
  • property owners and managers;
  • Host’s employees and other Authorized Users;
  • any users authorised by the Host to access the Services; and
  • other individuals whose Personal Data is entered into the Services by or on behalf of the Host.

3.3 Categories of Personal Data may include, depending on the Host’s use of the Services:

  • name and contact details;
  • ID, Passport, photos or other identification information; 
  • booking and reservation information and contacts;
  • dates of arrival and departure;
  • property, room and accommodation information;
  • communication and correspondence records;
  • payment-related and transaction information;
  • preferences and information relating to the Guest’s stay;
  • reports;
  • information contained in documents or other content uploaded by the Host; 

3.4 The Services are not intended to require the Processing of special categories of Personal Data. Where the Host chooses to enter such data into the Services, the Host remains responsible for ensuring that the Processing is lawful and that both appropriate safeguards are in place and Guest’s consent has been given.

4. Host’s Instructions

4.1 Hosperly shall Process Host Personal Data only on documented instructions from the Host, unless Processing is required by applicable law.

4.2 The Agreement, this DPA, the Host’s use and configuration of the Services, and written instructions provided by the Host constitute the Host’s documented instructions.

4.3 If Hosperly is required by law to Process Host Personal Data other than in accordance with the Host’s instructions, Hosperly shall, unless prohibited by law, inform the Host of that legal requirement before carrying out the relevant Processing.

4.4 Hosperly shall promptly inform the Host if, in its reasonable opinion, an instruction infringes applicable Data Protection Laws.

5. Host Responsibilities

5.1 The Host is responsible for:

a. determining the purposes and means of Processing Host Personal Data;

b. ensuring that the Processing has an appropriate legal basis;

c. providing all required privacy notices and information to Data Subjects;

d. ensuring that the Personal Data provided to Hosperly is collected and disclosed lawfully;

e. determining whether any special categories of Personal Data or other sensitive information should be entered into the Services;

f. configuring and using the Services in accordance with applicable Data Protection Laws;

g. responding to requests from Data Subjects where the Host acts as Controller; and

h. providing lawful and documented instructions to Hosperly.

5.2 The Host shall not instruct Hosperly to Process Personal Data in a manner that would violate applicable Data Protection Laws.

6. Confidentiality

6.1 Hosperly shall ensure that persons authorised to Process Host Personal Data are subject to an appropriate duty of confidentiality, whether by contract, professional obligation or other legally binding obligation.

6.2 Hosperly shall ensure that access to Host Personal Data is limited to personnel who require access for the performance of their duties and that such access is subject to appropriate access controls.

7. Security of Processing

7.1 Taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the Processing and the risks to the rights and freedoms of Data Subjects, Hosperly shall implement appropriate technical and organisational measures to protect Host Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data.

7.2 Such measures may include, as appropriate:

  • access controls and authentication mechanisms;
  • encryption of Personal Data in transit and, where appropriate, at rest;
  • secure development and change management practices;
  • logging and monitoring;
  • backup and recovery procedures;
  • personnel confidentiality and security training;
  • incident response procedures; and
  • regular testing and review of security measures.

8. Personal Data Breaches

8.1 Hosperly shall notify the Host without undue delay-and in any case within 48 hours- after becoming aware of a Personal Data Breach affecting Host Personal Data.

8.2 Where reasonably practicable, Hosperly shall provide the Host with relevant information concerning the breach, including, to the extent available:

a. the nature of the breach;

b. the categories and approximate number of Data Subjects affected;

c. the categories and approximate number of Personal Data records affected;

d. the likely consequences of the breach; and

e. the measures taken or proposed to address and mitigate the breach.

8.3 Hosperly shall reasonably cooperate with the Host in relation to the investigation, containment and remediation of a Personal Data Breach.

8.4 Hosperly shall not notify affected Data Subjects or a supervisory authority regarding a Personal Data Breach involving Host Personal Data and only the Host is responsible to assess whether notification is required and make the notification.

9. Assistance with Data Subject Rights

9.1 Taking into account the nature of the Processing, Hosperly shall provide reasonable assistance to the Host in responding to requests from Data Subjects exercising their rights under applicable Data Protection Laws.

9.2 Where technically and legally feasible, Hosperly shall provide functionality enabling the Host to access, correct, export, restrict or delete Host Personal Data.

9.3 If Hosperly receives a Data Subject request relating to Host Personal Data, Hosperly shall, unless required by law to respond directly, refer the request to the Host and shall not respond to it independently.

10. Sub-processors

Hosperly shall maintain an up-to-date list of relevant Sub-processors, which will be made available to the Host at all times through the following hyperlink: [insert hyperlink]. The Sub-processors listed on the relevant webpage as of the date of execution of this Agreement shall be deemed accepted and authorized by the Host upon signature of the Agreement.

Where required by applicable law, Hosperly shall inform the Host of the appointment or replacement of Sub-processors and provide the Host with an opportunity to object on reasonable data protection grounds.

Hosperly shall only engage Sub-processors that are parties to written agreements with Hosperly containing data protection obligations no less protective that the obligations of this DPA.

11. International Transfers

11.1 Hosperly shall not transfer Host Personal Data outside the European Economic Area (“EEA”) except in accordance with applicable Data Protection Laws.

11.2 Where required, such transfers shall be subject to an appropriate transfer mechanism, including an adequacy decision, the European Commission’s Standard Contractual Clauses or another lawful transfer mechanism.

12. Retention, Return and Deletion

Hosperly shall retain Host Personal Data only for the duration of the Services.

Upon termination or expiry of the Services, Hosperly shall, at the Host’s choice, delete or return Host Personal Data, unless applicable law requires continued retention.

13. Audit, Records

13.1 Hosperly shall make available to the Host information reasonably necessary to demonstrate compliance with the obligations applicable to processors under Article 28 of the GDPR.

13.2 Where applicable, such information may include relevant security documentation, certifications, audit reports, summaries of third-party assessments or other appropriate compliance information.

13.3 The Host may, subject to reasonable prior written notice and confidentiality obligations, conduct an audit where required by applicable Data Protection Laws and where the information reasonably available from Hosperly is insufficient to demonstrate compliance. Any such audit shall be subject to prior scheduling and agreement between the parties regarding the date, time, scope and practical arrangements of the audit.

13.4 Audits shall be conducted during normal business hours and in a manner that does not unreasonably disrupt Hosperly’s operations or compromise the security or confidentiality of other Hosts’ information. Host will bear the costs of Hosperly for the audit. Hosperly may reasonably reschedule an audit where necessary to avoid material operational disruption, provided that the parties agree on an alternative date and time.

13.5 Where required by Data Protection Laws, Hosperly will maintain a record, in electronic form, of all categories of processing activities carried out on behalf of the Host in the provision of the Services.

14. DPIA, Supervisory Authority

14.1. Where applicable, Hosperly shall, upon request, cooperate with the Supervisory Authority in the performance of its tasks, as foreseen in the GDPR.

14.1. Where applicable, upon Host’s request, Hosperly will reasonably cooperate and assist Host to carry out a Data Protection Impact Assessment, related to Host’s use of the Services.

15. Contact for Privacy

Privacy-related requests and communications concerning the Processing of Host Personal Data and this DPA may be submitted through partnerships@hosperly.com