Rechtliches
Auftragsverarbeitungsvertrag.
Die Bedingungen nach Artikel 28, unter denen HotelOS personenbezogene Daten im Auftrag eines Hotels verarbeitet. Gilt für jeden Geschäftskunden, ohne gesonderte Unterschrift.
Dieses Dokument liegt auf Englisch vor. Übersetzungen unserer Rechtsdokumente veröffentlichen wir nicht; verbindlich ist die englische Fassung.
Scope and incorporation
This Data Processing Agreement forms part of the Terms of Service at /legal/terms between Island Inventions Inc. ("HotelOS", "Processor") and the business customer using the platform ("Customer", "Controller"). It applies automatically wherever HotelOS processes personal data on the Customer's behalf, and it needs no separate signature to take effect.
Customers whose procurement requires a signed, dated counterpart — or a version on their own paper — can request one from [email protected]. We return executed copies within five business days.
It is written to satisfy Article 28 of Regulation (EU) 2016/679 (GDPR), the UK GDPR, and equivalent obligations under Japan's APPI and Singapore's PDPA.
Roles of the parties
The Customer is the controller of the personal data in its workspace and is responsible for the lawfulness of the collection, for the notices given to data subjects, and for any consent required. HotelOS is the processor and acts only on the Customer's documented instructions.
HotelOS is an independent controller for a narrow set of data described in our Privacy Policy — account administration, billing, security and platform telemetry. That processing is governed by the Privacy Policy at /legal/privacy, not by this agreement.
Subject matter, duration, nature and purpose
- Subject matter
- Provision of the HotelOS platform — Desk, Flow, Clarity, Command, Calm Kitchen and On hand — and the support, hosting and integration services around it.
- Duration
- The term of the Terms of Service, plus the wind-down period described in section 13 below.
- Nature and purpose
- Collection, storage, structuring, retrieval, transmission to systems the Customer connects, and deletion of personal data, so the Customer can run its hotel operations.
- Categories of data subject
- The Customer's guests and prospective guests, its staff and contractors, and its business contacts.
- Categories of personal data
- Identification and contact details; stay, reservation and folio records; payment tokens issued by the Customer's payment provider; requests, preferences and correspondence; staff scheduling and task records; and accounting entries. Special-category data is not required by the platform and should not be entered into it, save for accessibility or dietary notes a guest volunteers.
Processing instructions
HotelOS processes personal data only on the Customer's documented instructions, which comprise this agreement, the Terms of Service, the configuration the Customer chooses in the product, and any further written instruction the parties agree. We will not process it for our own purposes, and we will never sell it.
If the law requires us to process data beyond those instructions, we will tell the Customer first unless the law forbids that notice. If we consider an instruction to breach data protection law, we will say so promptly and may pause the affected processing until it is resolved.
Confidentiality
Access to Customer personal data is limited to personnel who need it to deliver or support the services. Every such person is bound by a written confidentiality obligation that survives the end of their engagement, is trained in data protection, and holds only the least privilege their role requires. Administrative access is logged, and privileged sessions are recorded and reviewed after the fact.
Technical and organisational measures
HotelOS maintains the measures set out below, and will not materially weaken them during the term. Our full posture is published at /trust.
- Encryption of personal data with AES-256 at rest and TLS 1.3 in transit, under per-tenant key management. Bring-your-own-key is available on the enterprise tier.
- Per-tenant data residency in the United States (Virginia), European Union (Frankfurt) or Asia-Pacific (Singapore), elected at provisioning, with stateful data, object storage and backups held in the elected region.
- Row-level tenant isolation enforced in the database itself, so a defect in application code cannot expose one customer's records to another.
- Role-based, least-privilege access scoped to property, brand and folio; SAML 2.0 and OIDC single sign-on against Okta, Microsoft Entra and Google Workspace; SCIM provisioning and de-provisioning.
- An append-only, cryptographically chained audit log across every product surface, exportable in CSV or Parquet, retained seven years by default.
- Continuous write-ahead-log backup with point-in-time recovery and daily snapshots replicated to a second region; targeted recovery time of four hours and recovery point of five minutes.
- Secure development practices — peer review, dependency scanning, secret scanning, and a staging environment that never receives production credentials.
- Documented incident response, business continuity and disaster recovery plans, tested and revised on a defined cadence.
- A coordinated vulnerability disclosure policy with safe harbour for good-faith researchers, at [email protected].
Sub-processing
The Customer gives general authorisation for HotelOS to engage the sub-processors published at /legal/subprocessors. Each is security-reviewed before onboarding and bound by a written contract imposing data protection obligations no less protective than this agreement. HotelOS remains fully liable to the Customer for its sub-processors' performance.
We give at least 30 days' notice by email to account owners before adding or replacing a sub-processor. The Customer may object on reasonable data protection grounds within that period; if we cannot offer a workable alternative, the Customer may terminate the affected service and receive a refund of fees paid for the unused portion of its term.
Assistance with data-subject requests
The platform provides self-service tools for finding, exporting, correcting and deleting an individual's records, so the Customer can answer most requests without involving us. Where a request cannot be handled with those tools, we assist at no additional charge and within the time the Customer needs to meet its own deadline.
If a data subject contacts HotelOS directly about data we hold as processor, we will not respond substantively. We forward the request to the Customer without undue delay and support the answer.
Assistance with impact assessments and regulators
Taking into account the nature of the processing and the information available to us, HotelOS assists the Customer with data protection impact assessments, prior consultations with a supervisory authority, and the security obligations in Articles 32 to 36 of the GDPR. Our trust pack — covering architecture, controls, sub-processors and the transfer mechanisms we rely on — is available under NDA and normally answers an assessment on its own.
Personal data breach
HotelOS notifies the Customer without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting the Customer's personal data. The notice describes what we know of the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. Where the full picture is not yet available, we send what we have and follow up in phases rather than waiting.
A written remediation plan follows within 14 days. We cooperate with the Customer's own notification duties to regulators and data subjects, and we do not notify the Customer's data subjects on the Customer's behalf unless asked to.
Deletion and return
On termination, and at the Customer's choice, HotelOS returns or deletes the personal data it processes on the Customer's behalf. For 30 days after termination the workspace data remains available for export in open, machine-readable formats, and we assist with a structured export at no charge.
After that window we delete the data from live systems, and from backups as those backups age out on their normal rotation — no later than 90 days after termination. We certify the deletion in writing on request. Data we are required by law to retain is kept only for that purpose and stays subject to this agreement while it exists.
Audits and information rights
HotelOS makes available the information needed to demonstrate compliance with Article 28, including the trust pack, our security documentation, and audit reports as our certification programme produces them.
Where that is not sufficient, the Customer may audit HotelOS, itself or through an independent auditor bound by confidentiality and not a competitor of ours, once in any 12-month period on 30 days' written notice — and more often where a regulator requires it or following a confirmed breach. Audits take place in business hours, must not unreasonably disrupt operations, and must not compromise other customers' confidentiality. Each party bears its own costs.
International transfers
Where HotelOS transfers personal data out of the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, the transfer is governed by the European Commission's Standard Contractual Clauses (Decision 2021/914), which are incorporated into this agreement by reference and take effect on the transfer starting.
- Module Two (controller to processor) applies where the Customer is a controller; Module Three (processor to processor) applies where the Customer is itself a processor.
- The Customer is the data exporter and HotelOS the data importer. The optional docking clause applies; the audit and sub-processor terms above complete Clauses 8.9 and 9. The general authorisation option in Clause 9(a) applies with the 30-day notice period stated above.
- The governing law is that of Ireland and the competent courts are the Irish courts, unless the exporter is established in another Member State whose law and courts the parties instead select.
- For UK transfers, the ICO's International Data Transfer Addendum (version B1.0) applies to the Clauses. For Swiss transfers, references to the GDPR are read as references to the FADP and the Federal Data Protection and Information Commissioner is the competent authority.
- Annexes I to III of the Clauses are populated by sections 3 and 6 of this agreement and by the sub-processor list at /legal/subprocessors.
Customers who elect EU residency keep their stateful data, object storage and backups in Frankfurt; the transfer mechanisms above cover the residual support and administrative access described in the Privacy Policy.
Liability and order of precedence
Liability under this agreement is subject to the limitations in the Terms of Service, except where the applicable data protection law does not permit that. In the event of conflict, the Standard Contractual Clauses prevail over this agreement, and this agreement prevails over the Terms of Service, in each case only on the point of conflict.
Contact and executed copies
Data Protection Officer, Island Inventions Inc., San Francisco, California, USA — [email protected]. Write to that address for a countersigned copy of this agreement, for the Standard Contractual Clauses we rely on, or for the trust pack under NDA.
Weitere Rechtsdokumente
Fragen zu diesem Dokument?
Fragen zu Datenschutz und Vertrag beantwortet ein Mensch, keine Warteschlange. Schreiben Sie uns — Antwort innerhalb eines Werktags.