Data Processing Agreement

1. Objective and application

1.1

The Hospitable entity that is party to the Agreement (“Hospitable”, “Processor” or “Data Importer”) has entered into a software-as-a-service agreement or other agreement (the “Agreement”) with its customers (“Customer”, “Controller” or “Data Exporter”), collectively, the “Parties”, under which Hospitable provides property and vacation-rental management, automation and related “Software-as-a-Service” services (the “Services”). Hospitable may engage Hospitable R&D B.V. and other Hospitable group companies as Sub-processors, as listed in Appendix 2. The Services do not include the Excluded Services described in Section 2.6.

1.2

This Data Processing Agreement (“DPA”) forms an integral part of, and is incorporated into, the Agreement and any other agreements, addenda, order forms, policies, or other documents entered into between the Parties, whether executed by mutual signature or accepted by the Customer through a click-through or similar electronic acceptance mechanism (collectively, the “Agreement”). This DPA governs Hospitable’s Processing of Customer Personal Data on behalf of the Customer and shall apply from the date on which Hospitable first Processes Customer Personal Data and for so long as such Processing continues. By entering into or accepting the Agreement, each Party shall be deemed to have entered into and agreed to be bound by this DPA.

1.3

This DPA satisfies the requirements for a binding controller–processor contract under Article 28 of Regulation (EU) 2016/679 (“GDPR”) and equivalent requirements under applicable Data Protection Legislation. Appendix 1 describes the processing; Appendix 2 addresses Sub-processors; and Appendix 3 incorporates transfer safeguards where required. The Appendices form part of this DPA.

1.4

If there is a conflict concerning the processing of Customer Personal Data, the following order of precedence applies: (a) applicable Standard Contractual Clauses; (b) this DPA; and (c) the Agreement.

1.1

The Hospitable entity that is party to the Agreement (“Hospitable”, “Processor” or “Data Importer”) has entered into a software-as-a-service agreement or other agreement (the “Agreement”) with its customers (“Customer”, “Controller” or “Data Exporter”), collectively, the “Parties”, under which Hospitable provides property and vacation-rental management, automation and related “Software-as-a-Service” services (the “Services”). Hospitable may engage Hospitable R&D B.V. and other Hospitable group companies as Sub-processors, as listed in Appendix 2. The Services do not include the Excluded Services described in Section 2.6.

1.2

This Data Processing Agreement (“DPA”) forms an integral part of, and is incorporated into, the Agreement and any other agreements, addenda, order forms, policies, or other documents entered into between the Parties, whether executed by mutual signature or accepted by the Customer through a click-through or similar electronic acceptance mechanism (collectively, the “Agreement”). This DPA governs Hospitable’s Processing of Customer Personal Data on behalf of the Customer and shall apply from the date on which Hospitable first Processes Customer Personal Data and for so long as such Processing continues. By entering into or accepting the Agreement, each Party shall be deemed to have entered into and agreed to be bound by this DPA.

1.3

This DPA satisfies the requirements for a binding controller–processor contract under Article 28 of Regulation (EU) 2016/679 (“GDPR”) and equivalent requirements under applicable Data Protection Legislation. Appendix 1 describes the processing; Appendix 2 addresses Sub-processors; and Appendix 3 incorporates transfer safeguards where required. The Appendices form part of this DPA.

1.4

If there is a conflict concerning the processing of Customer Personal Data, the following order of precedence applies: (a) applicable Standard Contractual Clauses; (b) this DPA; and (c) the Agreement.

2. Definitions and roles

Capitalised terms used but not defined in this DPA shall have the meanings given to them in the Agreement. The following terms shall have the meanings set out below. Where a term is defined under applicable Data Protection Legislation, that term shall have the meaning assigned to it under such Data Protection Legislation.

  • “Business Purposes” means the provision, operation, support and performance of the Services in accordance with the Agreement and this DPA, and any other purpose or Processing activity specifically documented by the Customer in Appendix 1.

  • “Controller” means the natural or legal person, public authority, agency or other body that, alone or jointly with others, determines the purposes and means of the Processing of Personal Data.

  • “Customer Account Email Address” means the email address associated with the Customer’s primary Hospitable account or such other email address designated by the Customer for notices or communications relating to this DPA. Where appropriate, Hospitable may also send notices to another authorised user or contact designated by the Customer.

  • “Customer Personal Data” means Personal Data contained in or forming part of Service Data that Hospitable Processes on behalf of the Customer in connection with the provision of the Services under the Agreement. Customer Personal Data may include, depending on the Services used by the Customer, Personal Data relating to Guests, prospective Guests, property owners, authorised users, contractors, service providers, or other individuals with whom the Customer interacts through the Services.

  • “Data Protection Legislation” means all privacy, data protection and data security laws and regulations applicable to the Processing of Customer Personal Data under this DPA, including, to the extent applicable: (a) Regulation (EU) 2016/679 (the “GDPR”); (b) any national legislation supplementing or implementing the GDPR; (c) the GDPR as incorporated into the laws of the United Kingdom (the “UK GDPR”) and the UK Data Protection Act 2018; (d) applicable United States federal and state privacy and data protection laws, including the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act (“CCPA”); (e) the Australian Privacy Act 1988 (Cth); and (f) any legislation that amends, replaces or supersedes any of the foregoing.

  • “Data Subject” means an identified or identifiable natural person to whom Personal Data relates.

  • “Documentation” means the documentation, specifications, instructions, help materials and other information concerning the Services made available by Hospitable from time to time through its website, Help Center, developer documentation, or otherwise in connection with the Services.

  • “DPA” means this Data Processing Agreement, including its Appendices, Annexes and any documents expressly incorporated into or referenced by it.

  • “European Economic Area” or “EEA” means the Member States of the European Union together with Iceland, Liechtenstein and Norway.

  • “EU Member State” means any then-current member state of the European Union.

  • “Guest” means an identified or identifiable natural person who makes, seeks to make, or is associated with a reservation, booking, inquiry or stay relating to a property managed by the Customer through the Services.

  • “Guest Information” means information relating to a Guest that is Processed through the Services on behalf of the Customer, which may include, depending on the Services used, the Guest’s name, contact details, profile information, reservation and stay details, booking source, communications, reviews, preferences, special requests, transaction or payment-related information, verification information, rental agreements and other information provided by or concerning the Guest. To the extent Guest Information constitutes Personal Data, it shall constitute Customer Personal Data for the purposes of this DPA.

  • “Personal Data” means any information relating to an identified or identifiable natural person and includes any equivalent term, such as “personal information” or “personally identifiable information,” to the extent such term is defined and regulated under applicable Data Protection Legislation.

  • “Personal Data Breach” means an actual breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise Processed.

  • “Processor” and “Sub-processor” means a natural or legal person, public authority, agency or other body that Processes Personal Data on behalf of a Controller.

  • “Process”, “Processed” and “Processing” mean any operation or set of operations performed on Personal Data or sets of Personal Data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

  • “Services” means the products and services provided or made available by Hospitable to the Customer under the Agreement, including the applicable Hospitable software, platform, applications, APIs, Documentation, features and associated services subscribed to, purchased, enabled or otherwise used by the Customer from time to time.

  • “Service Data” has the meaning given to it in the Agreement and, for purposes of this DPA, includes electronic data, text, messages, communications and other materials submitted to, collected through, transmitted to, Processed by or stored within the Services by or on behalf of the Customer, including data obtained from third-party booking channels or other services connected by the Customer to the Services.

  • “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of Personal Data to third countries adopted by the European Commission pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended, replaced or superseded from time to time, applying the module or modules appropriate to the relevant transfer.

  • “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under Section 119A of the Data Protection Act 2018, as amended, replaced or superseded from time to time.

  • “US Data Protection Laws” means applicable United States federal and state laws governing privacy, data protection or the Processing of Personal Data, including the CCPA and any successor, replacement or amending legislation, in each case solely to the extent applicable to the relevant Processing under this DPA.

2.3

The Customer represents and warrants that it enters into the Agreement and this DPA solely in the course of its trade, business, craft, or profession and not as a consumer. The Services are intended exclusively for business and professional use. To the maximum extent permitted by applicable law, any statutory rights, protections, or remedies that apply solely to consumers shall not apply to the Agreement or this DPA.

2.4

Customer is the controller and Hospitable is the processor of Customer Personal Data, except where Customer acts as a processor for another controller, in which case Hospitable acts as Customer’s Sub-processor. Each Party shall comply with the obligations applicable to its role. Hospitable may process limited personal data as an independent controller where necessary to administer the commercial relationship, secure and improve its Services, prevent abuse, meet legal obligations, improve and develop its products and services and generate analytics and benchmarking using account, usage, telemetry and technical data, or aggregated data that does not include Customer Content, communicate with Customer about its products, or when approved by the Controller, or as otherwise described in its privacy notice, including account, usage, telemetry and technical data generated by the use of the Services; such processing is outside this DPA.

2.5

Independent controller processing. Hospitable acts as an independent controller, and not as a processor, where it (a) acts as merchant of record in connection with Direct Premium, Hospitable Payments or any similar feature, including collecting guest payments, processing refunds, chargebacks, reserves and payouts, and calculating or remitting lodging or other taxes; (b) performs identity, fraud, sanctions, customer-due-diligence or anti-money-laundering checks required by law or by its payment partners; (c) contracts directly with a Guest; or (d) operates a marketplace or lead-matching service between property owners and property managers. Such processing is governed by the applicable product terms and Hospitable’s privacy notice and is outside this DPA.

2.6

Excluded Services. This DPA does not apply to, and Hospitable shall have no responsibility or liability under this DPA for, the processing of Personal Data by (a) Direct by Host, or any other website, platform or service that Customer does not receive under the Agreement; or (b) any insurer or other third party providing insurance, damage-protection or damage-waiver products (together, “Excluded Services”). Excluded Services are neither Services nor Sub-processors under this DPA. Where Customer elects to make Customer Personal Data, listings or property information available to an Excluded Service, such disclosure is made on Customer’s instruction under Section 7.3, and the operator of the Excluded Service processes such data under its own terms and privacy notice.

Capitalised terms used but not defined in this DPA shall have the meanings given to them in the Agreement. The following terms shall have the meanings set out below. Where a term is defined under applicable Data Protection Legislation, that term shall have the meaning assigned to it under such Data Protection Legislation.

  • “Business Purposes” means the provision, operation, support and performance of the Services in accordance with the Agreement and this DPA, and any other purpose or Processing activity specifically documented by the Customer in Appendix 1.

  • “Controller” means the natural or legal person, public authority, agency or other body that, alone or jointly with others, determines the purposes and means of the Processing of Personal Data.

  • “Customer Account Email Address” means the email address associated with the Customer’s primary Hospitable account or such other email address designated by the Customer for notices or communications relating to this DPA. Where appropriate, Hospitable may also send notices to another authorised user or contact designated by the Customer.

  • “Customer Personal Data” means Personal Data contained in or forming part of Service Data that Hospitable Processes on behalf of the Customer in connection with the provision of the Services under the Agreement. Customer Personal Data may include, depending on the Services used by the Customer, Personal Data relating to Guests, prospective Guests, property owners, authorised users, contractors, service providers, or other individuals with whom the Customer interacts through the Services.

  • “Data Protection Legislation” means all privacy, data protection and data security laws and regulations applicable to the Processing of Customer Personal Data under this DPA, including, to the extent applicable: (a) Regulation (EU) 2016/679 (the “GDPR”); (b) any national legislation supplementing or implementing the GDPR; (c) the GDPR as incorporated into the laws of the United Kingdom (the “UK GDPR”) and the UK Data Protection Act 2018; (d) applicable United States federal and state privacy and data protection laws, including the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act (“CCPA”); (e) the Australian Privacy Act 1988 (Cth); and (f) any legislation that amends, replaces or supersedes any of the foregoing.

  • “Data Subject” means an identified or identifiable natural person to whom Personal Data relates.

  • “Documentation” means the documentation, specifications, instructions, help materials and other information concerning the Services made available by Hospitable from time to time through its website, Help Center, developer documentation, or otherwise in connection with the Services.

  • “DPA” means this Data Processing Agreement, including its Appendices, Annexes and any documents expressly incorporated into or referenced by it.

  • “European Economic Area” or “EEA” means the Member States of the European Union together with Iceland, Liechtenstein and Norway.

  • “EU Member State” means any then-current member state of the European Union.

  • “Guest” means an identified or identifiable natural person who makes, seeks to make, or is associated with a reservation, booking, inquiry or stay relating to a property managed by the Customer through the Services.

  • “Guest Information” means information relating to a Guest that is Processed through the Services on behalf of the Customer, which may include, depending on the Services used, the Guest’s name, contact details, profile information, reservation and stay details, booking source, communications, reviews, preferences, special requests, transaction or payment-related information, verification information, rental agreements and other information provided by or concerning the Guest. To the extent Guest Information constitutes Personal Data, it shall constitute Customer Personal Data for the purposes of this DPA.

  • “Personal Data” means any information relating to an identified or identifiable natural person and includes any equivalent term, such as “personal information” or “personally identifiable information,” to the extent such term is defined and regulated under applicable Data Protection Legislation.

  • “Personal Data Breach” means an actual breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise Processed.

  • “Processor” and “Sub-processor” means a natural or legal person, public authority, agency or other body that Processes Personal Data on behalf of a Controller.

  • “Process”, “Processed” and “Processing” mean any operation or set of operations performed on Personal Data or sets of Personal Data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

  • “Services” means the products and services provided or made available by Hospitable to the Customer under the Agreement, including the applicable Hospitable software, platform, applications, APIs, Documentation, features and associated services subscribed to, purchased, enabled or otherwise used by the Customer from time to time.

  • “Service Data” has the meaning given to it in the Agreement and, for purposes of this DPA, includes electronic data, text, messages, communications and other materials submitted to, collected through, transmitted to, Processed by or stored within the Services by or on behalf of the Customer, including data obtained from third-party booking channels or other services connected by the Customer to the Services.

  • “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of Personal Data to third countries adopted by the European Commission pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended, replaced or superseded from time to time, applying the module or modules appropriate to the relevant transfer.

  • “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under Section 119A of the Data Protection Act 2018, as amended, replaced or superseded from time to time.

  • “US Data Protection Laws” means applicable United States federal and state laws governing privacy, data protection or the Processing of Personal Data, including the CCPA and any successor, replacement or amending legislation, in each case solely to the extent applicable to the relevant Processing under this DPA.

2.3

The Customer represents and warrants that it enters into the Agreement and this DPA solely in the course of its trade, business, craft, or profession and not as a consumer. The Services are intended exclusively for business and professional use. To the maximum extent permitted by applicable law, any statutory rights, protections, or remedies that apply solely to consumers shall not apply to the Agreement or this DPA.

2.4

Customer is the controller and Hospitable is the processor of Customer Personal Data, except where Customer acts as a processor for another controller, in which case Hospitable acts as Customer’s Sub-processor. Each Party shall comply with the obligations applicable to its role. Hospitable may process limited personal data as an independent controller where necessary to administer the commercial relationship, secure and improve its Services, prevent abuse, meet legal obligations, improve and develop its products and services and generate analytics and benchmarking using account, usage, telemetry and technical data, or aggregated data that does not include Customer Content, communicate with Customer about its products, or when approved by the Controller, or as otherwise described in its privacy notice, including account, usage, telemetry and technical data generated by the use of the Services; such processing is outside this DPA.

2.5

Independent controller processing. Hospitable acts as an independent controller, and not as a processor, where it (a) acts as merchant of record in connection with Direct Premium, Hospitable Payments or any similar feature, including collecting guest payments, processing refunds, chargebacks, reserves and payouts, and calculating or remitting lodging or other taxes; (b) performs identity, fraud, sanctions, customer-due-diligence or anti-money-laundering checks required by law or by its payment partners; (c) contracts directly with a Guest; or (d) operates a marketplace or lead-matching service between property owners and property managers. Such processing is governed by the applicable product terms and Hospitable’s privacy notice and is outside this DPA.

2.6

Excluded Services. This DPA does not apply to, and Hospitable shall have no responsibility or liability under this DPA for, the processing of Personal Data by (a) Direct by Host, or any other website, platform or service that Customer does not receive under the Agreement; or (b) any insurer or other third party providing insurance, damage-protection or damage-waiver products (together, “Excluded Services”). Excluded Services are neither Services nor Sub-processors under this DPA. Where Customer elects to make Customer Personal Data, listings or property information available to an Excluded Service, such disclosure is made on Customer’s instruction under Section 7.3, and the operator of the Excluded Service processes such data under its own terms and privacy notice.

3. Documented instructions

3.1

Hospitable shall process Customer Personal Data only on Customer’s documented instructions, including to provide, maintain, support, secure and improve the Services and as configured or used by Customer. The Agreement, this DPA, Customer’s use of the Services and written instructions consistent with them constitute documented instructions.

3.2

Hospitable may process Customer Personal Data where required by Union or Member State law to which it is subject. Unless legally prohibited on important grounds of public interest, Hospitable shall inform Customer of that legal requirement before processing.

3.3

Hospitable shall immediately inform Customer if, in its opinion, an instruction infringes Data Protection Legislation. Hospitable may suspend the affected processing until Customer confirms or modifies the instruction. Instructions outside the scope of the Agreement may be declined by Hospitable or performed at Hospitable's then-current rates. Hospitable has no obligation to monitor or legally review Customer's instructions.

3.4

Hospitable shall not sell or share Customer Personal Data, retain, use or disclose it outside the direct business relationship with Customer, or combine it with personal data obtained from another person except as permitted by Data Protection Legislation and necessary to provide or improve the Services, detect security incidents, prevent fraudulent or illegal activity, or comply with law. To the extent U.S. Data Protection Legislation applies, Hospitable shall provide the same level of privacy protection required of a service provider or processor, permit Customer to take reasonable steps to verify and remediate compliance, and notify Customer if Hospitable determines it can no longer meet an applicable obligation.

3.5

Data from booking channels. Customer Personal Data that Hospitable obtains from a connected booking channel is also subject to the terms that the channel imposes on Hospitable. Where those terms are stricter than this DPA, including as to permitted use, retention, deletion or onward disclosure, Hospitable may apply them, and doing so is not a breach of this DPA. Sections 2.4 and 9.3 and Appendix 1, Section 5.1(b) apply to such data only to the extent the relevant channel's terms permit.

3.1

Hospitable shall process Customer Personal Data only on Customer’s documented instructions, including to provide, maintain, support, secure and improve the Services and as configured or used by Customer. The Agreement, this DPA, Customer’s use of the Services and written instructions consistent with them constitute documented instructions.

3.2

Hospitable may process Customer Personal Data where required by Union or Member State law to which it is subject. Unless legally prohibited on important grounds of public interest, Hospitable shall inform Customer of that legal requirement before processing.

3.3

Hospitable shall immediately inform Customer if, in its opinion, an instruction infringes Data Protection Legislation. Hospitable may suspend the affected processing until Customer confirms or modifies the instruction. Instructions outside the scope of the Agreement may be declined by Hospitable or performed at Hospitable's then-current rates. Hospitable has no obligation to monitor or legally review Customer's instructions.

3.4

Hospitable shall not sell or share Customer Personal Data, retain, use or disclose it outside the direct business relationship with Customer, or combine it with personal data obtained from another person except as permitted by Data Protection Legislation and necessary to provide or improve the Services, detect security incidents, prevent fraudulent or illegal activity, or comply with law. To the extent U.S. Data Protection Legislation applies, Hospitable shall provide the same level of privacy protection required of a service provider or processor, permit Customer to take reasonable steps to verify and remediate compliance, and notify Customer if Hospitable determines it can no longer meet an applicable obligation.

3.5

Data from booking channels. Customer Personal Data that Hospitable obtains from a connected booking channel is also subject to the terms that the channel imposes on Hospitable. Where those terms are stricter than this DPA, including as to permitted use, retention, deletion or onward disclosure, Hospitable may apply them, and doing so is not a breach of this DPA. Sections 2.4 and 9.3 and Appendix 1, Section 5.1(b) apply to such data only to the extent the relevant channel's terms permit.

4. Confidentiality and security

4.1

Hospitable shall ensure that persons authorised to process Customer Personal Data are bound by confidentiality obligations and access it only as necessary for their duties.

4.2

Taking into account the state of the art, implementation costs, and the nature, scope, context and purposes of processing as well as the risk to data subjects, Hospitable shall implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data. The measures are described in Appendix 1 and may be updated provided the overall level of protection is not materially reduced.

4.3

Customer is responsible for using the Services securely, managing its users and credentials, configuring permissions and retention settings, and assessing whether the Services and Hospitable’s measures are appropriate for Customer’s processing. Customer shall not provide Customer Personal Data that is unnecessary for the Services or prohibited by the Agreement.

4.4

Hospitable tests, assesses and evaluates, in accordance with its security programme, the effectiveness of relevant safeguards and maintains processes for timely restoration of access following an incident. Security measures are risk-based and may differ between Services. Customer expressly acknowledges that no online service can eliminate all risk and shall promptly notify Hospitable of suspected compromise of Customer credentials, accounts, connected channels or integrations.

4.1

Hospitable shall ensure that persons authorised to process Customer Personal Data are bound by confidentiality obligations and access it only as necessary for their duties.

4.2

Taking into account the state of the art, implementation costs, and the nature, scope, context and purposes of processing as well as the risk to data subjects, Hospitable shall implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data. The measures are described in Appendix 1 and may be updated provided the overall level of protection is not materially reduced.

4.3

Customer is responsible for using the Services securely, managing its users and credentials, configuring permissions and retention settings, and assessing whether the Services and Hospitable’s measures are appropriate for Customer’s processing. Customer shall not provide Customer Personal Data that is unnecessary for the Services or prohibited by the Agreement.

4.4

Hospitable tests, assesses and evaluates, in accordance with its security programme, the effectiveness of relevant safeguards and maintains processes for timely restoration of access following an incident. Security measures are risk-based and may differ between Services. Customer expressly acknowledges that no online service can eliminate all risk and shall promptly notify Hospitable of suspected compromise of Customer credentials, accounts, connected channels or integrations.

5. Assistance and data-subject requests

5.1

Taking into account the nature of the processing, Hospitable shall assist Customer, through appropriate technical and organisational measures insofar as possible, to fulfil Customer’s obligation to respond to requests for access, rectification, erasure, restriction, portability, objection and rights concerning automated decision-making. Assistance beyond the self-service functionality of the Services is provided at Hospitable's then-current rates.

5.2

If Hospitable receives a request from a data subject concerning Customer Personal Data, it shall, unless legally prohibited and provided it can reasonably identify the Customer concerned, notify Customer or refer the data subject to Customer, and not respond substantively except on Customer’s documented instructions. Customer is responsible for verifying the requester’s identity and responding to the request. To the extent Customer cannot fulfil a request using the Services, Hospitable shall provide reasonable assistance.

5.3

Taking into account the nature of processing and information available to Hospitable, Hospitable may reasonably assist Customer with security obligations, Personal Data Breach notifications, data-protection impact assessments and prior consultations under Articles 32–36 GDPR. Assistance beyond the standard functionality of the Services and publicly available Hospitable support articles may be subject to reasonable fees where permitted by law.

5.4

Where Customer requests assistance, it shall provide the information reasonably necessary to identify the relevant data, data subject, account, property or reservation and shall ensure that its request does not expose another customer’s data or undermine the security of the Services. Hospitable may use secure procedures to authenticate the request and deliver responsive information.

5.1

Taking into account the nature of the processing, Hospitable shall assist Customer, through appropriate technical and organisational measures insofar as possible, to fulfil Customer’s obligation to respond to requests for access, rectification, erasure, restriction, portability, objection and rights concerning automated decision-making. Assistance beyond the self-service functionality of the Services is provided at Hospitable's then-current rates.

5.2

If Hospitable receives a request from a data subject concerning Customer Personal Data, it shall, unless legally prohibited and provided it can reasonably identify the Customer concerned, notify Customer or refer the data subject to Customer, and not respond substantively except on Customer’s documented instructions. Customer is responsible for verifying the requester’s identity and responding to the request. To the extent Customer cannot fulfil a request using the Services, Hospitable shall provide reasonable assistance.

5.3

Taking into account the nature of processing and information available to Hospitable, Hospitable may reasonably assist Customer with security obligations, Personal Data Breach notifications, data-protection impact assessments and prior consultations under Articles 32–36 GDPR. Assistance beyond the standard functionality of the Services and publicly available Hospitable support articles may be subject to reasonable fees where permitted by law.

5.4

Where Customer requests assistance, it shall provide the information reasonably necessary to identify the relevant data, data subject, account, property or reservation and shall ensure that its request does not expose another customer’s data or undermine the security of the Services. Hospitable may use secure procedures to authenticate the request and deliver responsive information.

6. Personal data breach

6.1

Hospitable shall notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

6.2

Where complete information is not initially available, Hospitable may provide it in phases without undue delay, in accordance with the law. Hospitable shall take reasonable steps to contain, investigate and mitigate the breach and cooperate with Customer. Hospitable’s notification is not an admission of fault or liability. Customer remains responsible for potential notifications to supervisory authorities and data subjects unless applicable law expressly requires Hospitable to notify directly. Customer shall bear its own costs of notification and remediation, except to the extent the Personal Data Breach was caused by Hospitable's breach of this DPA, in which case Section 12 applies.

6.3

Customer shall coordinate external communications concerning a Personal Data Breach and shall not identify Hospitable publicly without prior consultation and written approval of Hospitable. Hospitable may withhold information that would compromise security, legal privilege, applicable legal obligation, another customer or an active investigation, while providing sufficient information for Customer to comply with its obligations. The Parties shall document decisions and cooperate to avoid inconsistent notices.

6.1

Hospitable shall notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

6.2

Where complete information is not initially available, Hospitable may provide it in phases without undue delay, in accordance with the law. Hospitable shall take reasonable steps to contain, investigate and mitigate the breach and cooperate with Customer. Hospitable’s notification is not an admission of fault or liability. Customer remains responsible for potential notifications to supervisory authorities and data subjects unless applicable law expressly requires Hospitable to notify directly. Customer shall bear its own costs of notification and remediation, except to the extent the Personal Data Breach was caused by Hospitable's breach of this DPA, in which case Section 12 applies.

6.3

Customer shall coordinate external communications concerning a Personal Data Breach and shall not identify Hospitable publicly without prior consultation and written approval of Hospitable. Hospitable may withhold information that would compromise security, legal privilege, applicable legal obligation, another customer or an active investigation, while providing sufficient information for Customer to comply with its obligations. The Parties shall document decisions and cooperate to avoid inconsistent notices.

7. Sub-processors

7.1

Customer grants Hospitable general written authorisation to appoint Sub-processors. Hospitable shall maintain a current list at the location specified in Appendix 2 and shall provide notice of an addition or replacement at the location specified in Appendix 2, except where an emergency requires accelerated appointment to maintain security (confidentiality, integrity and availability) or service or business continuity.

7.2

Hospitable shall impose on each Sub-processor, by written contract, data-protection obligations that provide substantially the same level of protection as this DPA, insofar as applicable to the Sub-processor’s services. Hospitable remains responsible to Customer for the performance of its Sub-processors’ obligations to the extent required by Data Protection Legislation, subject to Section 12.

7.3

Customer acknowledges that Sub-processors may include infrastructure and hosting providers, communications providers, customer-support systems, analytics and monitoring providers, payment and identity-verification providers, and other vendors needed for the provision of Services or particular features. A Sub-processor processes only the data reasonably required for its contracted function. Customer’s activation of an optional integration may constitute an instruction to disclose Customer Personal Data to the integration provider; where that provider acts independently rather than as Hospitable’s Sub-processor, Customer is responsible for its relationship with that provider.

7.4

Customer may object to a new Sub-processor on reasonable data-protection grounds by written notice to Hospitable within fifteen (15) days of the notice given under Section 7.1. The Parties shall discuss the objection in good faith. If Hospitable does not, in its discretion, address the objection, Customer's sole and exclusive remedy is to terminate the affected Service by written notice. If Customer does not object within that period, the new Sub-processor is deemed approved. Notices under Section 7.1 may be given on the sub-processor list page, described in Appendix 2 or to the Customer Account Email Address.

7.1

Customer grants Hospitable general written authorisation to appoint Sub-processors. Hospitable shall maintain a current list at the location specified in Appendix 2 and shall provide notice of an addition or replacement at the location specified in Appendix 2, except where an emergency requires accelerated appointment to maintain security (confidentiality, integrity and availability) or service or business continuity.

7.2

Hospitable shall impose on each Sub-processor, by written contract, data-protection obligations that provide substantially the same level of protection as this DPA, insofar as applicable to the Sub-processor’s services. Hospitable remains responsible to Customer for the performance of its Sub-processors’ obligations to the extent required by Data Protection Legislation, subject to Section 12.

7.3

Customer acknowledges that Sub-processors may include infrastructure and hosting providers, communications providers, customer-support systems, analytics and monitoring providers, payment and identity-verification providers, and other vendors needed for the provision of Services or particular features. A Sub-processor processes only the data reasonably required for its contracted function. Customer’s activation of an optional integration may constitute an instruction to disclose Customer Personal Data to the integration provider; where that provider acts independently rather than as Hospitable’s Sub-processor, Customer is responsible for its relationship with that provider.

7.4

Customer may object to a new Sub-processor on reasonable data-protection grounds by written notice to Hospitable within fifteen (15) days of the notice given under Section 7.1. The Parties shall discuss the objection in good faith. If Hospitable does not, in its discretion, address the objection, Customer's sole and exclusive remedy is to terminate the affected Service by written notice. If Customer does not object within that period, the new Sub-processor is deemed approved. Notices under Section 7.1 may be given on the sub-processor list page, described in Appendix 2 or to the Customer Account Email Address.

8. International transfers

8.1

Customer authorizes Hospitable and its Sub-processors to potentially process Customer Personal Data in the United States and in the other countries listed in Appendix 2. Where Data Protection Legislation requires it, Hospitable shall ensure that each transfer is covered by an adequacy decision, the Standard Contractual Clauses or another lawful transfer mechanism.

8.2

For a restricted transfer governed by the GDPR for which no adequacy decision applies, the EU SCCs are incorporated by reference as set out in Appendix 3. The appropriate module applies according to the Parties’ roles. For a restricted transfer governed by UK Data Protection Legislation, the EU SCCs as modified by the UK Addendum are incorporated by reference.

8.3

If a transfer mechanism is invalidated or materially changed, the Parties shall cooperate in good faith to implement a valid replacement. Hospitable shall make information reasonably necessary for Customer’s transfer assessment available by providing its standard transfer impact assessment summary, subject to confidentiality and security restrictions.

8.4

Hospitable shall assess, as required by applicable law, whether the law and practice of a destination country could prevent compliance with the relevant transfer safeguards. Where necessary, Hospitable shall adopt supplementary contractual, technical or organizational measures. If Hospitable concludes that appropriate safeguards cannot be maintained, it shall suspend the affected transfer or processing and inform Customer unless prohibited by law.

8.1

Customer authorizes Hospitable and its Sub-processors to potentially process Customer Personal Data in the United States and in the other countries listed in Appendix 2. Where Data Protection Legislation requires it, Hospitable shall ensure that each transfer is covered by an adequacy decision, the Standard Contractual Clauses or another lawful transfer mechanism.

8.2

For a restricted transfer governed by the GDPR for which no adequacy decision applies, the EU SCCs are incorporated by reference as set out in Appendix 3. The appropriate module applies according to the Parties’ roles. For a restricted transfer governed by UK Data Protection Legislation, the EU SCCs as modified by the UK Addendum are incorporated by reference.

8.3

If a transfer mechanism is invalidated or materially changed, the Parties shall cooperate in good faith to implement a valid replacement. Hospitable shall make information reasonably necessary for Customer’s transfer assessment available by providing its standard transfer impact assessment summary, subject to confidentiality and security restrictions.

8.4

Hospitable shall assess, as required by applicable law, whether the law and practice of a destination country could prevent compliance with the relevant transfer safeguards. Where necessary, Hospitable shall adopt supplementary contractual, technical or organizational measures. If Hospitable concludes that appropriate safeguards cannot be maintained, it shall suspend the affected transfer or processing and inform Customer unless prohibited by law.

9. Return and deletion

9.1

During the term, Customer may access, export or delete Customer Personal Data using available Service functionality. After termination or expiry of the Agreement, Customer may export Customer Personal Data during the retrieval period set out in the Agreement, and making the data available for export in this way satisfies any obligation to return it. Hospitable shall then delete Customer Personal Data within the period set out in Appendix 1, unless the law requires it to be retained or Hospitable is keeping the account available for reactivation under Appendix 1.

9.2

Where retention is legally required or Customer Personal Data remains in secure backups, Hospitable shall logically isolate it from further processing except for the required operation, retention or restoration, continue to protect it under this DPA, and delete it in accordance with its normal backup cycle. On written express request, Hospitable may confirm completion of deletion.

9.3

Customer must export any Customer Personal Data it wishes to keep before the retrieval period ends. Hospitable is not required to store or return data in a format different from standard export functionality already available in the Services. Hospitable may at any time during or after the term create anonymised, aggregated or de-identified information from Customer Personal Data. Deletion obligations shall not apply to any information that Hospitable has anonymized, aggregated, de-identified, decomposed, irreversibly transformed, or otherwise processed in such a manner that it no longer constitutes Personal Data or can no longer reasonably be linked, directly or indirectly, to an identified or identifiable individual. Hospitable may retain and use such information for its legitimate business purposes, including analytics, service improvement, security, benchmarking, and statistical purposes, provided that Hospitable does not attempt to re-identify any individual from such information.

9.1

During the term, Customer may access, export or delete Customer Personal Data using available Service functionality. After termination or expiry of the Agreement, Customer may export Customer Personal Data during the retrieval period set out in the Agreement, and making the data available for export in this way satisfies any obligation to return it. Hospitable shall then delete Customer Personal Data within the period set out in Appendix 1, unless the law requires it to be retained or Hospitable is keeping the account available for reactivation under Appendix 1.

9.2

Where retention is legally required or Customer Personal Data remains in secure backups, Hospitable shall logically isolate it from further processing except for the required operation, retention or restoration, continue to protect it under this DPA, and delete it in accordance with its normal backup cycle. On written express request, Hospitable may confirm completion of deletion.

9.3

Customer must export any Customer Personal Data it wishes to keep before the retrieval period ends. Hospitable is not required to store or return data in a format different from standard export functionality already available in the Services. Hospitable may at any time during or after the term create anonymised, aggregated or de-identified information from Customer Personal Data. Deletion obligations shall not apply to any information that Hospitable has anonymized, aggregated, de-identified, decomposed, irreversibly transformed, or otherwise processed in such a manner that it no longer constitutes Personal Data or can no longer reasonably be linked, directly or indirectly, to an identified or identifiable individual. Hospitable may retain and use such information for its legitimate business purposes, including analytics, service improvement, security, benchmarking, and statistical purposes, provided that Hospitable does not attempt to re-identify any individual from such information.

10. Audit and information

10.1

Hospitable shall make available information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA. Hospitable may satisfy this obligation by providing relevant third-party certifications, summaries of penetration tests, independent audit reports, security documentation, security or privacy whitepapers, and written responses, subject to appropriate confidentiality restrictions and to the extent that providing such responses does not impose an unreasonable or disproportionate administrative burden on, or materially disrupt, Hospitable’s ordinary business operations.

10.2

If such information is insufficient to demonstrate compliance, Customer may request, no more than once in any twelve-month period, an audit conducted through an independent qualified auditor bound by confidentiality. Additional audits may be conducted only where required by a supervisory authority or following a material Personal Data Breach affecting Customer Personal Data, and shall be limited to the scope of that breach. Customer shall provide at least sixty (60) days’ notice, minimise disruption, comply with Hospitable’s security procedures, and bear its audit costs. Hospitable may charge reasonable costs for assistance beyond ordinary cooperation. Audits shall not provide access to other customers’ data, systems that would create a security risk, or Hospitable’s trade secrets unrelated to compliance. Audits shall be conducted remotely or by document review wherever possible; any on-site audit shall be limited to one (1) business day during normal business hours. The auditor must be approved by Hospitable (such approval not to be unreasonably withheld) and must not be a competitor of Hospitable. Audit findings are Hospitable's confidential information.

10.3

Hospitable may inform and cooperate with Customer if a supervisory authority initiates an inquiry specifically concerning Hospitable’s processing of Customer Personal Data, unless prohibited by law.

10.4

Audit reports and security materials are Hospitable’s confidential information and may be used solely to assess compliance with this DPA. Customer shall not conduct vulnerability scans, penetration tests or attempts to access systems without Hospitable’s prior written authorisation. Any accidental findings shall be reported promptly and confidentially, and the Parties shall cooperate on a reasonable remediation plan proportionate to risk.

10.1

Hospitable shall make available information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA. Hospitable may satisfy this obligation by providing relevant third-party certifications, summaries of penetration tests, independent audit reports, security documentation, security or privacy whitepapers, and written responses, subject to appropriate confidentiality restrictions and to the extent that providing such responses does not impose an unreasonable or disproportionate administrative burden on, or materially disrupt, Hospitable’s ordinary business operations.

10.2

If such information is insufficient to demonstrate compliance, Customer may request, no more than once in any twelve-month period, an audit conducted through an independent qualified auditor bound by confidentiality. Additional audits may be conducted only where required by a supervisory authority or following a material Personal Data Breach affecting Customer Personal Data, and shall be limited to the scope of that breach. Customer shall provide at least sixty (60) days’ notice, minimise disruption, comply with Hospitable’s security procedures, and bear its audit costs. Hospitable may charge reasonable costs for assistance beyond ordinary cooperation. Audits shall not provide access to other customers’ data, systems that would create a security risk, or Hospitable’s trade secrets unrelated to compliance. Audits shall be conducted remotely or by document review wherever possible; any on-site audit shall be limited to one (1) business day during normal business hours. The auditor must be approved by Hospitable (such approval not to be unreasonably withheld) and must not be a competitor of Hospitable. Audit findings are Hospitable's confidential information.

10.3

Hospitable may inform and cooperate with Customer if a supervisory authority initiates an inquiry specifically concerning Hospitable’s processing of Customer Personal Data, unless prohibited by law.

10.4

Audit reports and security materials are Hospitable’s confidential information and may be used solely to assess compliance with this DPA. Customer shall not conduct vulnerability scans, penetration tests or attempts to access systems without Hospitable’s prior written authorisation. Any accidental findings shall be reported promptly and confidentially, and the Parties shall cooperate on a reasonable remediation plan proportionate to risk.

11. Customer responsibilities

11.1

Customer warrants that its instructions and processing of Customer Personal Data, including its collection and disclosure to Hospitable, comply with Data Protection Legislation. Customer is responsible for the accuracy, quality and lawfulness of Customer Personal Data and for providing all required notices and establishing a valid legal basis.

11.2

Customer shall configure and use the Services in accordance with Data Protection Legislation, respond to data-subject requests and regulatory inquiries, and ensure that its users and connected platforms or integrations have appropriate authority. If Customer uses direct-booking, payment, guest-screening, communications, AI-assisted messaging, smart-device, or third-party integration features, Customer shall provide any additional notices and obtain any consents required for those features.

11.3

Customer shall not instruct Hospitable to process special categories of personal data or criminal-conviction data unless expressly supported by the applicable Service and lawful safeguards are in place. Customer shall promptly notify Hospitable if its instructions change in a way that materially affects the processing described in Appendix 1.

11.4

Customer determines the content and timing of automated messages, templates and workflows and remains responsible for reviewing their suitability, accuracy and legal basis. Where AI-assisted functionality is used, Customer shall apply appropriate human oversight having regard to the context and shall not rely on the Services to make decisions producing legal or similarly significant effects concerning a person unless expressly supported by the Service and permitted by law. Customer is responsible for disclosing to recipients, where the law requires it, that a message was written or sent with the help of AI.

11.5

Customer shall defend, indemnify and hold harmless Hospitable and its affiliates from and against all claims, fines, penalties, damages, losses, costs and expenses (including reasonable legal fees) arising out of or relating to (a) Customer’s breach of this Section 11; (b) Customer’s instructions; (c) the lack of a valid legal basis, notice or consent for the Processing of Customer Personal Data; or (d) Customer’s integrations and connected booking channels. Fines are covered only to the extent permitted by applicable law.

11.1

Customer warrants that its instructions and processing of Customer Personal Data, including its collection and disclosure to Hospitable, comply with Data Protection Legislation. Customer is responsible for the accuracy, quality and lawfulness of Customer Personal Data and for providing all required notices and establishing a valid legal basis.

11.2

Customer shall configure and use the Services in accordance with Data Protection Legislation, respond to data-subject requests and regulatory inquiries, and ensure that its users and connected platforms or integrations have appropriate authority. If Customer uses direct-booking, payment, guest-screening, communications, AI-assisted messaging, smart-device, or third-party integration features, Customer shall provide any additional notices and obtain any consents required for those features.

11.3

Customer shall not instruct Hospitable to process special categories of personal data or criminal-conviction data unless expressly supported by the applicable Service and lawful safeguards are in place. Customer shall promptly notify Hospitable if its instructions change in a way that materially affects the processing described in Appendix 1.

11.4

Customer determines the content and timing of automated messages, templates and workflows and remains responsible for reviewing their suitability, accuracy and legal basis. Where AI-assisted functionality is used, Customer shall apply appropriate human oversight having regard to the context and shall not rely on the Services to make decisions producing legal or similarly significant effects concerning a person unless expressly supported by the Service and permitted by law. Customer is responsible for disclosing to recipients, where the law requires it, that a message was written or sent with the help of AI.

11.5

Customer shall defend, indemnify and hold harmless Hospitable and its affiliates from and against all claims, fines, penalties, damages, losses, costs and expenses (including reasonable legal fees) arising out of or relating to (a) Customer’s breach of this Section 11; (b) Customer’s instructions; (c) the lack of a valid legal basis, notice or consent for the Processing of Customer Personal Data; or (d) Customer’s integrations and connected booking channels. Fines are covered only to the extent permitted by applicable law.

12. Liability

12.1

Subject to Section 12.4, Hospitable shall not be responsible or liable under this DPA to Customer:

  1. for any indirect, exemplary, incidental, punitive, special or consequential damages; or

  2. for any amounts that exceed the fees actually paid by Controller to Hospitable under the Agreement in the twelve (12) months prior to the act that gave rise to the relevant claim. This is a single aggregate cap for all claims under the Agreement and this DPA combined, including claims relating to Sub-processors, and does not create a separate or additional cap.

12.2

For any claim relating to the processing of Customer Personal Data, however framed, this Section 12 applies instead of the limitation of liability provisions in the Agreement.

12.3

Nothing in this Section 12 limits or excludes any liability that cannot be limited or excluded by applicable law.

12.4

The limitations and exclusions in Section 12.1 shall not apply to Customer’s liability for breach of Section 11 or under Section 11.5. Hospitable shall only be liable for damage caused by Processing where it has not complied with obligations of this DPA specifically directed to processors or has acted outside or contrary to Customer’s lawful instructions.

12.5

Hospitable shall not be liable for any Personal Data Breach or other incident to the extent caused by Customer’s configuration, credentials, users, integrations, connected booking channels, payment providers or other systems or actions outside Hospitable’s reasonable control.

12.6

Any suspension of Processing by Hospitable in accordance with Sections 3.3, 8.4 or 13.2 shall not constitute a breach of the Agreement or this DPA, shall not give rise to any liability of Hospitable, and shall not relieve Customer of its obligation to pay the fees.

12.1

Subject to Section 12.4, Hospitable shall not be responsible or liable under this DPA to Customer:

  1. for any indirect, exemplary, incidental, punitive, special or consequential damages; or

  2. for any amounts that exceed the fees actually paid by Controller to Hospitable under the Agreement in the twelve (12) months prior to the act that gave rise to the relevant claim. This is a single aggregate cap for all claims under the Agreement and this DPA combined, including claims relating to Sub-processors, and does not create a separate or additional cap.

12.2

For any claim relating to the processing of Customer Personal Data, however framed, this Section 12 applies instead of the limitation of liability provisions in the Agreement.

12.3

Nothing in this Section 12 limits or excludes any liability that cannot be limited or excluded by applicable law.

12.4

The limitations and exclusions in Section 12.1 shall not apply to Customer’s liability for breach of Section 11 or under Section 11.5. Hospitable shall only be liable for damage caused by Processing where it has not complied with obligations of this DPA specifically directed to processors or has acted outside or contrary to Customer’s lawful instructions.

12.5

Hospitable shall not be liable for any Personal Data Breach or other incident to the extent caused by Customer’s configuration, credentials, users, integrations, connected booking channels, payment providers or other systems or actions outside Hospitable’s reasonable control.

12.6

Any suspension of Processing by Hospitable in accordance with Sections 3.3, 8.4 or 13.2 shall not constitute a breach of the Agreement or this DPA, shall not give rise to any liability of Hospitable, and shall not relieve Customer of its obligation to pay the fees.

13. Contact, term and termination

13.1

The Parties’ privacy contacts are: for Hospitable, the privacy contact identified in Hospitable’s then-current privacy notice at https://hospitable.com/privacy; and for Customer, the account administrator or another contact notified to Hospitable. Customer shall keep its contact information current.

13.2

This DPA terminates automatically when Hospitable no longer processes Customer Personal Data, without affecting provisions intended to survive, including confidentiality, deletion, audit, liability and transfer terms. Termination of this DPA does not independently terminate the Agreement; however, Hospitable may suspend affected processing where continued processing would violate Data Protection Legislation.

13.1

The Parties’ privacy contacts are: for Hospitable, the privacy contact identified in Hospitable’s then-current privacy notice at https://hospitable.com/privacy; and for Customer, the account administrator or another contact notified to Hospitable. Customer shall keep its contact information current.

13.2

This DPA terminates automatically when Hospitable no longer processes Customer Personal Data, without affecting provisions intended to survive, including confidentiality, deletion, audit, liability and transfer terms. Termination of this DPA does not independently terminate the Agreement; however, Hospitable may suspend affected processing where continued processing would violate Data Protection Legislation.

14. Miscellaneous

14.1

Governing Law and Dispute Resolution. This DPA is governed by and construed in accordance with the laws of the Netherlands, and the courts of the Netherlands have jurisdiction, unless the Agreement specifies another Dutch court or mandatory law requires otherwise. The governing-law and forum provisions of the EU SCCs are stated separately in Appendix 3 and prevail for disputes under those clauses.

14.2

Amendments. Hospitable may update this DPA where reasonably necessary to reflect changes in Data Protection Legislation, the Services or processing, provided it does not materially reduce the protection of Customer Personal Data. Material changes shall be notified in accordance with the Agreement. Other amendments must be in writing and agreed by the Parties.

14.3

Severability and Entire Agreement. If a provision is invalid or unenforceable, it shall be modified to the minimum extent necessary and the remainder remains effective. This DPA and its Appendices constitute the Parties’ entire agreement regarding its subject matter and supersede prior data-processing terms concerning the same processing.

14.4

Notices and third-party rights. Notices under this DPA may be delivered using the notice method in the Agreement, through the Services, or by email to the designated privacy contacts. Except for rights expressly granted to data subjects under the Standard Contractual Clauses or mandatory law, no person other than the Parties has a right to enforce this DPA.

14.5

Cooperation. Each Party shall provide information within its control that is reasonably required for the other Party to demonstrate compliance with applicable Data Protection Legislation. Neither Party is required to disclose legally privileged information, information that would compromise security, or another customer’s confidential information. The Parties shall seek a secure alternative where such restrictions prevent direct disclosure.

14.1

Governing Law and Dispute Resolution. This DPA is governed by and construed in accordance with the laws of the Netherlands, and the courts of the Netherlands have jurisdiction, unless the Agreement specifies another Dutch court or mandatory law requires otherwise. The governing-law and forum provisions of the EU SCCs are stated separately in Appendix 3 and prevail for disputes under those clauses.

14.2

Amendments. Hospitable may update this DPA where reasonably necessary to reflect changes in Data Protection Legislation, the Services or processing, provided it does not materially reduce the protection of Customer Personal Data. Material changes shall be notified in accordance with the Agreement. Other amendments must be in writing and agreed by the Parties.

14.3

Severability and Entire Agreement. If a provision is invalid or unenforceable, it shall be modified to the minimum extent necessary and the remainder remains effective. This DPA and its Appendices constitute the Parties’ entire agreement regarding its subject matter and supersede prior data-processing terms concerning the same processing.

14.4

Notices and third-party rights. Notices under this DPA may be delivered using the notice method in the Agreement, through the Services, or by email to the designated privacy contacts. Except for rights expressly granted to data subjects under the Standard Contractual Clauses or mandatory law, no person other than the Parties has a right to enforce this DPA.

14.5

Cooperation. Each Party shall provide information within its control that is reasonably required for the other Party to demonstrate compliance with applicable Data Protection Legislation. Neither Party is required to disclose legally privileged information, information that would compromise security, or another customer’s confidential information. The Parties shall seek a secure alternative where such restrictions prevent direct disclosure.

Appendix 1 — Details of Processing

1. Subject matter and duration

Hospitable processes Customer Personal Data to provide the Services selected, configured and used by Customer under the Agreement. Processing continues for the term of the Agreement and the deletion period described below, unless otherwise required by law.

Hospitable processes Customer Personal Data to provide the Services selected, configured and used by Customer under the Agreement. Processing continues for the term of the Agreement and the deletion period described below, unless otherwise required by law.

2. Nature and purposes

Depending on Customer’s use and configuration, processing may include collection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission, synchronisation, combination, restriction, deletion and other operations necessary for:

  • property and listing management, including synchronising content, availability, calendars, rates, reservations and related information with booking channels;

  • guest and prospective-guest communications, unified inbox functions, message templates, automation and AI-assisted drafting or responses configured by Customer;

  • reservation administration, direct-booking websites and widgets operated by Hospitable, rental agreements, guest portals, security-deposit and payment-related facilitation, and guest verification or screening where enabled;

  • task, team, owner, cleaner and maintenance workflows; smart-lock, thermostat and other device integrations; reviews, reporting, analytics, dynamic pricing and financial or owner statements;

  • customer support, onboarding, troubleshooting, service communications, fraud and abuse prevention, security, availability, backup and disaster recovery; and

  • integrations, APIs and connected third-party services selected or authorised by Customer.

Hospitable processes this information to perform Customer’s instructions and operate the Services, including exchanging data with booking channels and integrations authorised by Customer. Hospitable does not determine Customer’s purposes for managing properties, communicating with guests, arranging stays or administering reservations. Feature availability varies by plan, jurisdiction and configuration; inclusion in this Appendix does not mean every category is processed for every Customer.

Depending on Customer’s use and configuration, processing may include collection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission, synchronisation, combination, restriction, deletion and other operations necessary for:

  • property and listing management, including synchronising content, availability, calendars, rates, reservations and related information with booking channels;

  • guest and prospective-guest communications, unified inbox functions, message templates, automation and AI-assisted drafting or responses configured by Customer;

  • reservation administration, direct-booking websites and widgets operated by Hospitable, rental agreements, guest portals, security-deposit and payment-related facilitation, and guest verification or screening where enabled;

  • task, team, owner, cleaner and maintenance workflows; smart-lock, thermostat and other device integrations; reviews, reporting, analytics, dynamic pricing and financial or owner statements;

  • customer support, onboarding, troubleshooting, service communications, fraud and abuse prevention, security, availability, backup and disaster recovery; and

  • integrations, APIs and connected third-party services selected or authorised by Customer.

Hospitable processes this information to perform Customer’s instructions and operate the Services, including exchanging data with booking channels and integrations authorised by Customer. Hospitable does not determine Customer’s purposes for managing properties, communicating with guests, arranging stays or administering reservations. Feature availability varies by plan, jurisdiction and configuration; inclusion in this Appendix does not mean every category is processed for every Customer.

3. Categories of data subjects

  • Customer’s personnel, account users, team members, contractors, owners, cleaners and service providers;

  • guests, prospective guests, occupants and persons communicating about a reservation or property;

  • property owners, managers, vendors and other contacts whose data Customer submits or synchronises; and

  • other individuals whose personal data Customer chooses to process through the Services.

  • Customer’s personnel, account users, team members, contractors, owners, cleaners and service providers;

  • guests, prospective guests, occupants and persons communicating about a reservation or property;

  • property owners, managers, vendors and other contacts whose data Customer submits or synchronises; and

  • other individuals whose personal data Customer chooses to process through the Services.

4. Categories of personal data

identity and contact data, such as name, email address, telephone number, username, profile details and communication preferences;

  • reservation and stay data, including dates, party size, booking status, platform identifiers, special requests, messages, reviews and rental-agreement information;

  • property, listing and operational data, including addresses, access instructions, task assignments, owner or vendor details and device events;

  • transaction and financial-administration data, such as prices, fees, taxes, deposits, payout or payment status and limited payment-related identifiers (payment-card data is generally processed by payment providers where applicable);

  • account, authentication, usage and technical data, including IP address, device/browser data, logs, integration tokens and audit records, except to the extent Processed by Hospitable as an independent controller under Section 2.4;

  • support content and attachments supplied by Customer or its users; and

  • identity-verification or guest-screening results where Customer enables such features, which may include identification-document information and verification status. Customer shall not submit special-category data unless expressly supported and lawful.

The content of communications and support materials may incidentally reveal additional information chosen by Customer or a data subject, including accessibility needs, dietary preferences or other sensitive circumstances. Such incidental content is not required by Hospitable and Customer should avoid collecting or entering it unless necessary, lawful and appropriately protected. Hospitable does not intentionally use message content to infer special-category data on Customer’s behalf unless a specific contracted feature expressly provides for that processing.

Sources of Customer Personal Data may include Customer and its authorised users; guests and prospective guests; property owners and service providers; booking channels such as Airbnb, Vrbo, Booking.com or Agoda; Customer-selected integrations; direct-booking websites or forms operated by Hospitable; and technical interaction with the Services. Customer controls which accounts, listings, properties and integrations are connected and is responsible for ensuring that the resulting disclosure to Hospitable is authorised.

identity and contact data, such as name, email address, telephone number, username, profile details and communication preferences;

  • reservation and stay data, including dates, party size, booking status, platform identifiers, special requests, messages, reviews and rental-agreement information;

  • property, listing and operational data, including addresses, access instructions, task assignments, owner or vendor details and device events;

  • transaction and financial-administration data, such as prices, fees, taxes, deposits, payout or payment status and limited payment-related identifiers (payment-card data is generally processed by payment providers where applicable);

  • account, authentication, usage and technical data, including IP address, device/browser data, logs, integration tokens and audit records, except to the extent Processed by Hospitable as an independent controller under Section 2.4;

  • support content and attachments supplied by Customer or its users; and

  • identity-verification or guest-screening results where Customer enables such features, which may include identification-document information and verification status. Customer shall not submit special-category data unless expressly supported and lawful.

The content of communications and support materials may incidentally reveal additional information chosen by Customer or a data subject, including accessibility needs, dietary preferences or other sensitive circumstances. Such incidental content is not required by Hospitable and Customer should avoid collecting or entering it unless necessary, lawful and appropriately protected. Hospitable does not intentionally use message content to infer special-category data on Customer’s behalf unless a specific contracted feature expressly provides for that processing.

Sources of Customer Personal Data may include Customer and its authorised users; guests and prospective guests; property owners and service providers; booking channels such as Airbnb, Vrbo, Booking.com or Agoda; Customer-selected integrations; direct-booking websites or forms operated by Hospitable; and technical interaction with the Services. Customer controls which accounts, listings, properties and integrations are connected and is responsible for ensuring that the resulting disclosure to Hospitable is authorised.

5. Frequency and retention

5.1

Transfers and processing occur on a continuous or event-driven basis while Customer uses the Services. Hospitable retains Customer Personal Data for the duration of the Agreement and, after termination or expiry, only as follows:

(a) Retrieval. Customer may export Customer Personal Data during the retrieval period set out in the Agreement.

(b) Account preservation. Unless Customer asks Hospitable to delete its data at or after termination, Customer instructs Hospitable to keep its account and Customer Personal Data for up to twenty-four (24) months after the retrieval period ends, solely so that Customer can reactivate its account. During that period, Hospitable shall not use the preserved data for any other purpose. Hospitable shall delete it promptly if Customer asks, and shall remind Customer of this option before the period ends.

(c) Deletion. At the end of the preservation period, or after Customer's deletion request if earlier, Hospitable shall delete or anonymise Customer Personal Data in its active systems without undue delay. Backup copies shall be deleted or overwritten in the ordinary course of Hospitable's backup cycles and shall not be restored except for disaster recovery.

(d) Legal retention and claims. Hospitable may retain limited Customer Personal Data for longer where (i) applicable law requires it, (ii) Customer instructs Hospitable to do so to meet Customer's own legal obligations, or (iii) it is reasonably necessary to establish, exercise or defend legal claims relating to the Agreement, in which case for no longer than the applicable limitation period and in any event no more than five (5) years after termination. Data retained under this paragraph shall be restricted, protected under this DPA and used only for the purpose for which it is retained.

A different period applies where stated in the Agreement or where Customer configures another supported retention period.

5.1

Transfers and processing occur on a continuous or event-driven basis while Customer uses the Services. Hospitable retains Customer Personal Data for the duration of the Agreement and, after termination or expiry, only as follows:

(a) Retrieval. Customer may export Customer Personal Data during the retrieval period set out in the Agreement.

(b) Account preservation. Unless Customer asks Hospitable to delete its data at or after termination, Customer instructs Hospitable to keep its account and Customer Personal Data for up to twenty-four (24) months after the retrieval period ends, solely so that Customer can reactivate its account. During that period, Hospitable shall not use the preserved data for any other purpose. Hospitable shall delete it promptly if Customer asks, and shall remind Customer of this option before the period ends.

(c) Deletion. At the end of the preservation period, or after Customer's deletion request if earlier, Hospitable shall delete or anonymise Customer Personal Data in its active systems without undue delay. Backup copies shall be deleted or overwritten in the ordinary course of Hospitable's backup cycles and shall not be restored except for disaster recovery.

(d) Legal retention and claims. Hospitable may retain limited Customer Personal Data for longer where (i) applicable law requires it, (ii) Customer instructs Hospitable to do so to meet Customer's own legal obligations, or (iii) it is reasonably necessary to establish, exercise or defend legal claims relating to the Agreement, in which case for no longer than the applicable limitation period and in any event no more than five (5) years after termination. Data retained under this paragraph shall be restricted, protected under this DPA and used only for the purpose for which it is retained.

A different period applies where stated in the Agreement or where Customer configures another supported retention period.

6. Technical and organisational measures

Hospitable maintains a documented security programme proportionate to the risk and designed to preserve confidentiality, integrity, availability and resilience. Current measures include, by way of example and as appropriate to the relevant system and Service, and may evolve over time:

  • access controls based on least privilege, authentication controls, account lifecycle management and periodic access review;

  • encryption of data in transit using industry-standard protocols and encryption at rest where appropriate;

  • logging, monitoring, alerting, vulnerability management, secure development and change-management practices;

  • segregation of customer environments or logical access boundaries, network and infrastructure protections, and malware or endpoint controls;

  • availability, backup, recovery, business-continuity and incident-response procedures that are periodically exercised;

  • personnel confidentiality obligations, security and privacy training, and processes for reporting suspected incidents;

  • vendor due diligence, contractual security and privacy requirements, and ongoing risk management for relevant Sub-processors; and

  • periodic independent assurance activities. Hospitable has obtained a SOC 2 Type II report; current assurance information may be made available subject to confidentiality and access controls.

Hospitable applies these controls according to system architecture and risk. Measures supporting data-subject rights and processor assistance include search, export, correction and deletion functionality where available; procedures for handling verified privacy requests; segregation of duties; approval and logging of privileged access; and controlled support access. Measures supporting data minimisation and retention include collection limited to enabled functions, configurable settings where available, deletion workflows and lifecycle rules. Measures supporting accountability include policies, training, risk assessments, incident records, vendor reviews and independent assurance.

For Customer Personal Data transmitted through connected booking channels, payment providers, smart devices or integrations, security is shared across the relevant systems. Hospitable protects the portions within its control; Customer shall select reputable integration providers, restrict tokens and permissions, revoke unused connections and follow provider security guidance. Customer must not transmit passwords, full payment-card details or identity documents through ordinary messages or support channels unless Hospitable expressly provides a secure workflow for that purpose.

Hospitable maintains a documented security programme proportionate to the risk and designed to preserve confidentiality, integrity, availability and resilience. Current measures include, by way of example and as appropriate to the relevant system and Service, and may evolve over time:

  • access controls based on least privilege, authentication controls, account lifecycle management and periodic access review;

  • encryption of data in transit using industry-standard protocols and encryption at rest where appropriate;

  • logging, monitoring, alerting, vulnerability management, secure development and change-management practices;

  • segregation of customer environments or logical access boundaries, network and infrastructure protections, and malware or endpoint controls;

  • availability, backup, recovery, business-continuity and incident-response procedures that are periodically exercised;

  • personnel confidentiality obligations, security and privacy training, and processes for reporting suspected incidents;

  • vendor due diligence, contractual security and privacy requirements, and ongoing risk management for relevant Sub-processors; and

  • periodic independent assurance activities. Hospitable has obtained a SOC 2 Type II report; current assurance information may be made available subject to confidentiality and access controls.

Hospitable applies these controls according to system architecture and risk. Measures supporting data-subject rights and processor assistance include search, export, correction and deletion functionality where available; procedures for handling verified privacy requests; segregation of duties; approval and logging of privileged access; and controlled support access. Measures supporting data minimisation and retention include collection limited to enabled functions, configurable settings where available, deletion workflows and lifecycle rules. Measures supporting accountability include policies, training, risk assessments, incident records, vendor reviews and independent assurance.

For Customer Personal Data transmitted through connected booking channels, payment providers, smart devices or integrations, security is shared across the relevant systems. Hospitable protects the portions within its control; Customer shall select reputable integration providers, restrict tokens and permissions, revoke unused connections and follow provider security guidance. Customer must not transmit passwords, full payment-card details or identity documents through ordinary messages or support channels unless Hospitable expressly provides a secure workflow for that purpose.

7. Customer controls and feature-specific processing

Customer determines which properties, booking channels, users, integrations and automation rules are connected to the Services. Customer may use available account controls to grant and revoke user access, manage roles, connect or disconnect channels, edit property and reservation information, configure message rules, and export or delete supported data. Hospitable processes changes submitted through those controls as Customer’s instructions. Removing an integration prevents new synchronisation but may not delete information already received; Customer should use the applicable deletion controls or submit a verified request where additional deletion is required.

For direct bookings and guest portals, Customer determines the booking terms, required fields, notices and communications presented to guests. Payment credentials and transactions may be handled by independent payment providers under their own terms or, where Hospitable acts as merchant of record, by Hospitable as an independent controller in accordance with Section 2.5. For smart-device and operational integrations, Customer determines which properties and personnel receive access or tasks. For AI-assisted messaging, Customer determines the prompts, templates, knowledge and automation settings and is responsible for reviewing output appropriate to the context. Hospitable may use transient or logged technical information to operate, secure and troubleshoot these features in accordance with this DPA.

If Customer enables an optional feature that requires additional categories of personal data or a new processing purpose, the product interface, Documentation, order form or another written notice may supplement this Appendix. If Customer uses identity verification or guest screening, Customer is responsible for giving any required notices and obtaining any required consents, including written releases under biometric privacy laws. Hospitable does not store biometric identifiers or templates. Hospitable is not a consumer reporting agency, and verification and screening results are not consumer reports. Customer shall not use them for any purpose that would require compliance with the Fair Credit Reporting Act (FCRA) or equivalent laws. Customer’s activation and use of the feature constitutes a documented instruction only where the supplement identifies the relevant processing and remains consistent with Data Protection Legislation. Materially different processing that cannot reasonably be understood from the Services requires written agreement between the Parties.

Customer determines which properties, booking channels, users, integrations and automation rules are connected to the Services. Customer may use available account controls to grant and revoke user access, manage roles, connect or disconnect channels, edit property and reservation information, configure message rules, and export or delete supported data. Hospitable processes changes submitted through those controls as Customer’s instructions. Removing an integration prevents new synchronisation but may not delete information already received; Customer should use the applicable deletion controls or submit a verified request where additional deletion is required.

For direct bookings and guest portals, Customer determines the booking terms, required fields, notices and communications presented to guests. Payment credentials and transactions may be handled by independent payment providers under their own terms or, where Hospitable acts as merchant of record, by Hospitable as an independent controller in accordance with Section 2.5. For smart-device and operational integrations, Customer determines which properties and personnel receive access or tasks. For AI-assisted messaging, Customer determines the prompts, templates, knowledge and automation settings and is responsible for reviewing output appropriate to the context. Hospitable may use transient or logged technical information to operate, secure and troubleshoot these features in accordance with this DPA.

If Customer enables an optional feature that requires additional categories of personal data or a new processing purpose, the product interface, Documentation, order form or another written notice may supplement this Appendix. If Customer uses identity verification or guest screening, Customer is responsible for giving any required notices and obtaining any required consents, including written releases under biometric privacy laws. Hospitable does not store biometric identifiers or templates. Hospitable is not a consumer reporting agency, and verification and screening results are not consumer reports. Customer shall not use them for any purpose that would require compliance with the Fair Credit Reporting Act (FCRA) or equivalent laws. Customer’s activation and use of the feature constitutes a documented instruction only where the supplement identifies the relevant processing and remains consistent with Data Protection Legislation. Materially different processing that cannot reasonably be understood from the Services requires written agreement between the Parties.

Appendix 2 — Sub-processors

The current list of Sub-processors, including their functions and processing locations, is made available through Hospitable’s Trust Center at https://trust.hospitable.com/ or another location notified to Customer. Customer authorises the listed Sub-processors and may subscribe to or receive update notices as described in Section 7. If the list is not accessible, Customer may request a current copy from Hospitable’s privacy contact at [email protected].

Hospitable R&D B.V. (Netherlands) and Hospitable, Inc. (United States), and other potential Hospitable Group Companies act as Sub-processors for hosting, operating, and supporting the Services.

The current list of Sub-processors, including their functions and processing locations, is made available through Hospitable’s Trust Center at https://trust.hospitable.com/ or another location notified to Customer. Customer authorises the listed Sub-processors and may subscribe to or receive update notices as described in Section 7. If the list is not accessible, Customer may request a current copy from Hospitable’s privacy contact at [email protected].

Hospitable R&D B.V. (Netherlands) and Hospitable, Inc. (United States), and other potential Hospitable Group Companies act as Sub-processors for hosting, operating, and supporting the Services.

Appendix 3 — International transfer terms

1. Incorporation

Where a Party makes a restricted transfer of Customer Personal Data subject to the GDPR and no adequacy decision applies, the EU SCCs are incorporated by reference and completed as follows. Their text is not modified by this DPA, and any conflict is resolved in favour of the EU SCCs.

Where a Party makes a restricted transfer of Customer Personal Data subject to the GDPR and no adequacy decision applies, the EU SCCs are incorporated by reference and completed as follows. Their text is not modified by this DPA, and any conflict is resolved in favour of the EU SCCs.

SCC provision

Selection / completion

Modules

Module Two (controller to processor) applies where Customer is a controller and Hospitable is a processor. Module Three (processor to processor) applies where Customer is a processor and Hospitable is a Sub-processor.

Clause 7 — Docking

The optional docking clause does not apply.

Clause 9(a) — Sub-processors

Option 2 (general written authorisation) applies.

Clause 11 — Redress

The optional language does not apply.

Clause 17 — Governing law

Option 1 applies. The law of the Netherlands governs.

Clause 18 — Forum

The courts of the Netherlands have jurisdiction.

Annex I.A — Parties

Data exporter: Customer, with details in the Agreement; role is controller or processor as applicable. Data importer: the Hospitable entity that is party to the Agreement; role is processor or Sub-processor. Activities are those described in Appendix 1.

Annex I.B — Transfer

Data subjects, categories of data, frequency, nature, purposes and retention are described in Appendix 1. The transfer is continuous or event-driven. Sensitive data is not intended unless expressly supported, documented and protected by appropriate safeguards. Customer Personal Data is primarily hosted in the United States. Other processing locations are listed in Appendix 2.

Annex I.C — Supervisory authority

Determined under Clause 13. Where Hospitable’s Dutch establishment is the relevant criterion: Autoriteit Persoonsgegevens (Dutch Data Protection Authority), Hoge Nieuwstraat 8, 2514 EL The Hague; P.O. Box 93374, 2509 AJ The Hague, the Netherlands; [email protected].

Annex II — Security measures

The measures are described in Appendix 1, Section 6.

Annex III — Sub-processors

The authorised Sub-processors are identified in Appendix 2.

2. United Kingdom. For a restricted transfer subject to UK Data Protection Legislation, the UK Addendum is incorporated and modifies the EU SCCs. Tables 1–3 are completed using the information in this DPA, the Agreement and the EU SCC selections above. In Table 4, either Party may end the Addendum as permitted by Section 19. The laws of England and Wales govern the UK Addendum and the courts specified by it have jurisdiction.

3. Transfers by Sub-processors. For Module Three transfers, the subject matter, nature and duration are the relevant portions of the Services and Sub-processor functions described in Appendices 1 and 2. Hospitable shall provide the Customer with information reasonably necessary to understand the transfer chain and safeguards, subject to confidentiality and security limitations.

4. Alternative mechanism. The foregoing clauses do not apply where the relevant transfer is covered by an adequacy decision or another lawful transfer mechanism selected by Hospitable that provides an essentially equivalent and legally valid level of protection.

5. Requests from public authorities. For transfers subject to the SCCs, and where legally permitted, Hospitable shall notify the relevant data exporter of a binding request from a public authority for Customer Personal Data and shall review the legality of the request. If there are reasonable grounds to consider the request unlawful, Hospitable shall challenge it and seek interim measures where appropriate. Hospitable shall disclose only the minimum data legally required and shall document requests and responses. Where permitted, Hospitable may provide aggregate information about such requests.

6. Government access and transparency. Hospitable or, where applicable, its sub-processors shall reasonably maintain appropriate policies or processes for handling government requests and, where required for the transfer assessment, provide information about requests received that is reasonably available and may lawfully be disclosed. Nothing in this section requires action that would place Hospitable in breach of applicable law.

2. United Kingdom. For a restricted transfer subject to UK Data Protection Legislation, the UK Addendum is incorporated and modifies the EU SCCs. Tables 1–3 are completed using the information in this DPA, the Agreement and the EU SCC selections above. In Table 4, either Party may end the Addendum as permitted by Section 19. The laws of England and Wales govern the UK Addendum and the courts specified by it have jurisdiction.

3. Transfers by Sub-processors. For Module Three transfers, the subject matter, nature and duration are the relevant portions of the Services and Sub-processor functions described in Appendices 1 and 2. Hospitable shall provide the Customer with information reasonably necessary to understand the transfer chain and safeguards, subject to confidentiality and security limitations.

4. Alternative mechanism. The foregoing clauses do not apply where the relevant transfer is covered by an adequacy decision or another lawful transfer mechanism selected by Hospitable that provides an essentially equivalent and legally valid level of protection.

5. Requests from public authorities. For transfers subject to the SCCs, and where legally permitted, Hospitable shall notify the relevant data exporter of a binding request from a public authority for Customer Personal Data and shall review the legality of the request. If there are reasonable grounds to consider the request unlawful, Hospitable shall challenge it and seek interim measures where appropriate. Hospitable shall disclose only the minimum data legally required and shall document requests and responses. Where permitted, Hospitable may provide aggregate information about such requests.

6. Government access and transparency. Hospitable or, where applicable, its sub-processors shall reasonably maintain appropriate policies or processes for handling government requests and, where required for the transfer assessment, provide information about requests received that is reasonably available and may lawfully be disclosed. Nothing in this section requires action that would place Hospitable in breach of applicable law.