Data Processing Addendum
Privacy and data processing schedule for Customer Data
| Term | Meaning |
|---|---|
| Legal Owner | ENTERACT LLC |
| Product | Prehoos |
| Effective date | July 30, 2024 |
1. Introduction
This Data Processing Addendum ("DPA") forms part of the Prehoos Terms of Service or other agreement between ENTERACT LLC and Customer for use of Prehoos. This DPA applies where Company processes Personal Data on behalf of Customer in connection with the Services.
2. Definitions
Capitalized terms not defined in this DPA have the meaning given in the Terms. "Data Protection Laws" means all privacy, data protection, and cybersecurity laws applicable to the processing of Personal Data under the Agreement, which may include GDPR, UK GDPR, Swiss data protection law, U.S. state privacy laws, and other applicable laws. "Personal Data" means information relating to an identified or identifiable natural person or other information regulated as personal information under Data Protection Laws.
3. Roles of the parties
Customer is generally the controller, business, or equivalent decision-maker for Customer Data. Company is generally the processor, service provider, contractor, or equivalent service provider when processing Personal Data on behalf of Customer. The parties acknowledge that their roles may vary depending on the processing activity and applicable law.
4. Processing instructions
Company will process Personal Data only on documented instructions from Customer, including the Agreement, this DPA, Customer configuration, Customer use of the Platform, Customer support requests, Order Forms, and written instructions accepted by Company, unless required by law. Company will inform Customer if it believes an instruction violates Data Protection Laws, unless prohibited by law.
5. Details of processing
| Term | Meaning |
|---|---|
- Subject matter
- Provision of Prehoos hospitality operations software, support, security, maintenance, integrations, reporting, automation, and related services.
- Duration User
- For the subscription term and any post-termination retention period required for export, backup, legal compliance, security, or dispute resolution.
- Customer Data
- For the subscription term and any post-termination retention period required for export, backup, legal compliance, security, or dispute resolution.
- Nature and purpose
- Hosting, storing, transmitting, organizing, retrieving, displaying, analyzing, securing, supporting, and processing Customer Data to provide Prehoos.
- Categories of data subjects
- Hotel guests, prospective guests, visitors, booking contacts, staff, contractors, owners, managers, administrators, suppliers, customers, support contacts, and business contacts.
- Categories of Personal Data
- Contact details, identity details, booking records, room records, stay details, folio records, POS-related records, payment references, preferences, messages, staff records, access logs, audit logs, support data, business data, and other data submitted by Customer.
- Sensitive data
- Customer should not submit sensitive data unless necessary for lawful hospitality operations and supported by the applicable plan and configuration. Customer is responsible for lawful basis and notices.
6. Confidentiality
Company will ensure that personnel authorized to process Personal Data are bound by confidentiality obligations or are under an appropriate statutory obligation of confidentiality.
7. Security measures
Company will implement and maintain appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Measures may include access controls, authentication, encryption in transit, logging, backup controls, vulnerability management, personnel confidentiality, and incident response procedures. Current measures are summarized in the Security Overview.
8. Subprocessors
Customer authorizes Company to engage subprocessors to provide the Services. Company will maintain a Subprocessor List describing subprocessors and their processing purposes. Company will impose data protection obligations on subprocessors that are substantially similar to those in this DPA. Company remains responsible for subprocessors performance of their data protection obligations to the extent required by applicable law.
Company will provide notice of material new subprocessors by updating the Subprocessor List or by another reasonable method. Customer may object to a new subprocessor on reasonable data protection grounds within the notice period stated in the Subprocessor List or Order Form. If the parties cannot resolve the objection, Customer may terminate the affected Services according to the Agreement.
9. Data subject requests
Taking into account the nature of the processing, Company will provide reasonable assistance to Customer, through technical and organizational measures where possible, to help Customer respond to requests from individuals exercising rights under Data Protection Laws. If Company receives a request directly concerning Customer Data, Company may refer the requester to Customer unless required by law to respond directly.
10. Personal data breach
Company will notify Customer without undue delay after becoming aware of a Personal Data breach affecting Customer Data. The notice will include information reasonably available to Company, which may include the nature of the breach, affected data, likely consequences, mitigation steps, and contact point. Company may provide information in phases as it becomes available. Customer is responsible for determining whether notices to individuals, regulators, or others are required.
11. Assistance and audits
Company will provide reasonable information necessary to demonstrate compliance with this DPA, such as security summaries, policies, audit summaries, certifications if available, or responses to reasonable questionnaires. On-site audits require reasonable notice, written scope, confidentiality, security requirements, and may be limited to once per year unless required after a confirmed material breach. Customer will bear audit costs unless applicable law requires otherwise.
12. Return and deletion
Upon termination or expiration of the Services, Company will make Customer Data available for export for the period stated in the Terms, Order Form, or applicable policy. After that period, Company may delete or anonymize Customer Data according to normal retention and backup cycles, unless legal obligations require retention. Backup copies may be retained for limited periods and isolated from active processing where commercially reasonable.
13. International transfers
Where Personal Data is transferred from the European Economic Area, United Kingdom, Switzerland, or another jurisdiction requiring transfer safeguards to a country not recognized as providing adequate protection, the parties will use appropriate safeguards, which may include Standard Contractual Clauses, the UK International Data Transfer Addendum, or other lawful transfer mechanisms. The parties will cooperate in good faith to implement required transfer terms.
14. U.S. state privacy service provider terms
To the extent U.S. state privacy laws apply and Company processes Personal Data as a service provider, processor, contractor, or similar role, Company will not sell or share Personal Data processed on behalf of Customer; will not retain, use, or disclose it outside the business purposes described in the Agreement except as permitted by law; and will provide the level of privacy protection required by applicable law.
15. Customer obligations
Customer is responsible for the lawfulness, accuracy, quality, and content of Customer Data; providing privacy notices; obtaining consents where required; honoring data subject rights; configuring user permissions and integrations; and ensuring its instructions comply with Data Protection Laws.
16. Conflict
If this DPA conflicts with the Terms, this DPA controls for the processing of Personal Data. If Standard Contractual Clauses apply and conflict with this DPA, the Standard Contractual Clauses control for the restricted transfer.
Annex A: Technical and organizational measures
| Measure | Summary |
|---|---|
- Access control
- Role-based access, least privilege, administrative access restrictions, and user authentication controls.
- Transmission security
- Encryption in transit using industry-standard protocols where supported.
- Storage protection
- Logical separation, database access controls, secure configuration, and backup controls appropriate to the hosting environment.
- Availability and resilience
- Backups, monitoring, recovery processes, and maintenance practices designed to support continuity.
- Logging and monitoring
- Application, access, security, and diagnostic logs used for troubleshooting and security review.
- Personnel controls
- Confidentiality obligations and access restrictions for personnel with operational access.
- Incident response
- Processes to identify, investigate, contain, remediate, and notify customers of relevant security incidents.
- Subprocessor management
- Vendor review, contractual obligations, and maintained Subprocessor List.
