Data Processing Agreement
ReserveWithIt d.o.o. — Version 1.1 — Last updated: 1 June 2024
1. Definitions
"GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data.
"Controller" means the Customer who has purchased a ReserveWithIt module and who determines the purposes and means of processing of Personal Data of hotel guests.
"Processor" means ReserveWithIt d.o.o., which processes Personal Data on behalf of the Controller to deliver the contracted module functionality.
"Personal Data", "data subject", "processing", "personal data breach", and "supervisory authority" have the meanings given in GDPR Art. 4.
"Sub-processor" means any third party appointed by the Processor to process Personal Data in connection with the Services.
"Services" means the specific ReserveWithIt module(s) purchased by the Controller, as described on the relevant product pages.
"Restricted Transfer" means a transfer of Personal Data to a country not covered by an adequacy decision under GDPR Art. 45.
"SCCs" means the Standard Contractual Clauses for the transfer of personal data to third countries, as adopted by the European Commission under Commission Decision 2021/914.
2. Scope and nature of processing
2.1 Subject matter: Processing of Personal Data of hotel guests retrieved from the Controller's Reservit account (or other hotel PMS) for the purpose of delivering the contracted module functionality.
2.2 Duration: The Processor processes Personal Data for the duration of the active module subscription. On termination, the Processor will delete or return Personal Data as set out in Section 8.
2.3 Nature of processing: Retrieval, temporary storage, transformation, transmission to module-specific functions, writeback to the Controller's Reservit account, and deletion. No processing for the Processor's own purposes.
2.4 Types of Personal Data processed: Guest names and contact details; reservation dates and room type; guest preferences (pillow type, dietary, language, transport); identification document metadata (document type, expiry date — no document image stored beyond 30-day window); stay history and LTV scores (CRM Link only); email addresses (Email Automation only).
2.5 Categories of data subjects: Hotel guests who have made reservations at the Controller's property through the Reservit system.
2.6 Purpose of processing: Strictly limited to delivering the contracted module functionality (e.g., pre-arrival portal data collection, CRM synchronisation, email automation triggers). No processing for Processor's own research, marketing, or commercial purposes.
3. Controller's obligations
3.1 The Controller shall ensure that: (a) it has a lawful basis under GDPR for the processing it instructs the Processor to carry out; (b) hotel guests are informed of the processing through appropriate privacy notices; (c) any consent required for specific processing activities has been obtained; and (d) it notifies the Processor promptly of any changes to instructions that affect the lawfulness of processing.
3.2 The Controller shall not instruct the Processor to process Personal Data in a manner that would violate applicable data protection law.
4. Processor's obligations
4.1 The Processor shall: (a) process Personal Data only on documented instructions from the Controller (as set out in this DPA and the product configuration settings); (b) ensure that authorised personnel are bound by appropriate confidentiality obligations; (c) assist the Controller in fulfilling data subject rights requests, security obligations, and breach notification duties, to the extent the Processor has relevant capabilities; (d) delete or return Personal Data to the Controller at the end of the contract (see Section 8); (e) make available all information necessary to demonstrate compliance with this DPA; and (f) allow and contribute to audits by the Controller or an auditor mandated by the Controller, on reasonable prior written notice.
4.2 The Processor shall inform the Controller promptly if, in the Processor's opinion, any instruction infringes GDPR or other applicable EU data protection law.
5. Sub-processors
5.1 Current sub-processors:
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Hetzner Online GmbH | Infrastructure and data storage | Germany (EU) | EEA — no transfer |
| Mailgun Technologies (EU) | Email delivery (Email Automation module only) | Ireland (EU) | EEA — no transfer |
| Reservit SAS (read/write via API) | API calls to retrieve and update reservation data | France (EU) | EEA — no transfer |
5.2 The Processor will impose data protection obligations on each sub-processor equivalent to those in this DPA. The Processor is liable to the Controller for the acts and omissions of sub-processors.
5.3 The Processor will give the Controller at least 30 days' written notice before adding or replacing sub-processors. The Controller may object within 14 days. If the Processor cannot accommodate the objection, the Controller may terminate the relevant module subscription with a pro-rata refund.
6. Security measures
The Processor implements the following technical and organisational measures to protect Personal Data:
- AES-256 encryption for Personal Data and API credentials stored at rest
- TLS 1.3 for all Personal Data in transit
- Role-based access controls — minimum necessary access for staff
- Multi-factor authentication for administrative system access
- Automated intrusion detection and alerting
- Annual penetration testing by independent third-party security firm
- Segregated environments (production/development) with no real Personal Data in development
- Logging and monitoring of access to Personal Data stores
- Staff training on data protection obligations (annual)
7. Personal data breach notification
7.1 The Processor will notify the Controller without undue delay and in any case within 72 hours of becoming aware of a personal data breach affecting Personal Data processed under this DPA.
7.2 Breach notifications will include, to the extent available at the time: (a) a description of the nature of the breach; (b) categories and approximate number of data subjects affected; (c) categories and approximate number of records affected; (d) name and contact details of the data protection contact; (e) likely consequences of the breach; and (f) measures taken or proposed to address the breach.
7.3 The Controller is responsible for notifying relevant supervisory authorities and data subjects of any breach, as required by GDPR Arts. 33 and 34. The Processor will provide reasonable assistance in preparing such notifications.
8. Return and deletion of data
8.1 On termination of any Module subscription, the Processor will, at the Controller's election, either: (a) return all Personal Data processed under the terminated Module in a machine-readable format (CSV) within 14 days; or (b) securely delete all such Personal Data within 30 days of termination.
8.2 The Processor will provide written confirmation of deletion within 14 days of completing deletion.
8.3 The Processor may retain Personal Data for longer than the periods in 8.1 only where required by applicable law, in which case the Processor will notify the Controller of the legal requirement, limit processing to that purpose, and delete as soon as the legal obligation no longer applies.
9. International transfers
9.1 Transfers of Personal Data from the EEA to ReserveWithIt d.o.o. (Montenegro) are permissible without additional safeguards, as Montenegro benefits from an EU adequacy decision (Commission Decision 2012/484/EU).
9.2 Where Personal Data is transferred to sub-processors outside the EEA who do not benefit from an adequacy decision, the Processor will ensure that SCCs are in place and will make copies available to the Controller on request.
10. Governing law and disputes
This DPA is governed by the law of Montenegro. Disputes are subject to the exclusive jurisdiction of the Osnovni sud u Podgorici. EU data subjects' rights under applicable supervisory authority oversight are not affected. The AZLP (Agencija za zaštitu ličnih podataka, reg. 05-030/26-2241) is the competent supervisory authority for ReserveWithIt d.o.o.