HospitalityOS

Data Processing Addendum

Last updated: Pending legal configuration

This is a structural legal template. Professional legal review is required before commercial launch. Jurisdiction-specific details, legal entity information, and registered addresses must be confirmed by qualified counsel.

1. Roles

The organization subscribing to HospitalityOS is the Controller. HospitalityOS is the Processor. Specific entity details are confirmed during legal review.

2. Subject Matter

This DPA applies to the processing of personal data by HospitalityOS on behalf of the Controller in connection with the HospitalityOS platform.

3. Duration

This DPA applies for the duration of the Controller's subscription and thereafter as necessary for the purposes described.

4. Nature and Purpose

Processing is necessary to provide the HospitalityOS platform — property management, reservations, operations, commercial, intelligence, and optional Xperio3D spatial intelligence.

5. Data Categories

Categories of personal data processed include: account data (name, email, role), operational data (properties, reservations, guests, operations), and optionally spatial data (property measurements, layout — no guest PII).

6. Data Subjects

Data subjects include authorized users of the platform and guests of the Controller's properties.

7. Processor Obligations

HospitalityOS processes personal data only on documented instructions from the Controller, in compliance with applicable data protection law.

8. Confidentiality

Personnel with access to personal data are bound by confidentiality obligations.

9. Security

HospitalityOS implements appropriate technical and organizational security measures. See our Security page for details.

10. Subprocessors

HospitalityOS uses subprocessors to provide the service. A subprocessor registry is maintained and available upon request. We do not invent subprocessors.

11. International Transfers

Where data is transferred internationally, appropriate safeguards are applied. Specific mechanisms are confirmed during legal review.

12. Data Subject Requests

HospitalityOS assists the Controller in responding to data subject requests where appropriate.

13. Incident Handling

HospitalityOS notifies the Controller of personal data breaches without undue delay after becoming aware of a breach.

14. Deletion and Return

Upon termination, HospitalityOS deletes or returns personal data at the Controller's choice, subject to legal retention obligations.

15. Audits

The Controller may audit HospitalityOS's compliance with this DPA subject to appropriate notice and confidentiality.

16. Instructions

HospitalityOS does not process personal data for its own purposes except as necessary to provide the service.

17. Annexes

Specific annexes — including subprocessor lists, security measures, and transfer mechanisms — are maintained separately and available upon request.