Data Processing Addendum
Last updated: Pending legal configuration
This is a structural legal template. Professional legal review is required before commercial launch. Jurisdiction-specific details, legal entity information, and registered addresses must be confirmed by qualified counsel.
1. Roles
The organization subscribing to HospitalityOS is the Controller. HospitalityOS is the Processor. Specific entity details are confirmed during legal review.
2. Subject Matter
This DPA applies to the processing of personal data by HospitalityOS on behalf of the Controller in connection with the HospitalityOS platform.
3. Duration
This DPA applies for the duration of the Controller's subscription and thereafter as necessary for the purposes described.
4. Nature and Purpose
Processing is necessary to provide the HospitalityOS platform — property management, reservations, operations, commercial, intelligence, and optional Xperio3D spatial intelligence.
5. Data Categories
Categories of personal data processed include: account data (name, email, role), operational data (properties, reservations, guests, operations), and optionally spatial data (property measurements, layout — no guest PII).
6. Data Subjects
Data subjects include authorized users of the platform and guests of the Controller's properties.
7. Processor Obligations
HospitalityOS processes personal data only on documented instructions from the Controller, in compliance with applicable data protection law.
8. Confidentiality
Personnel with access to personal data are bound by confidentiality obligations.
9. Security
HospitalityOS implements appropriate technical and organizational security measures. See our Security page for details.
10. Subprocessors
HospitalityOS uses subprocessors to provide the service. A subprocessor registry is maintained and available upon request. We do not invent subprocessors.
11. International Transfers
Where data is transferred internationally, appropriate safeguards are applied. Specific mechanisms are confirmed during legal review.
12. Data Subject Requests
HospitalityOS assists the Controller in responding to data subject requests where appropriate.
13. Incident Handling
HospitalityOS notifies the Controller of personal data breaches without undue delay after becoming aware of a breach.
14. Deletion and Return
Upon termination, HospitalityOS deletes or returns personal data at the Controller's choice, subject to legal retention obligations.
15. Audits
The Controller may audit HospitalityOS's compliance with this DPA subject to appropriate notice and confidentiality.
16. Instructions
HospitalityOS does not process personal data for its own purposes except as necessary to provide the service.
17. Annexes
Specific annexes — including subprocessor lists, security measures, and transfer mechanisms — are maintained separately and available upon request.