Loading...

Data Processing Agreement

This Data Processing Agreement ("Agreement") forms part of the Master Services Agreement or Terms of Service ("Terms") between you ("Controller" or "Customer") and Senti‑Consulting, trading as Host Smarter, with registered office at 391 chemin de la Fruitière, 74290 Talloires‑Montmin, France ("Processor").

1.Definitions

  • Personal Data: any information relating to an identified or identifiable natural person.
  • Processing: any operation performed on Personal Data as defined in GDPR Article 4(2).
  • Sub‑processor: any third party appointed by Processor to process Personal Data on behalf of Controller.
  • Regulation: the EU General Data Protection Regulation 2016/679 ("GDPR") and any applicable national data‑protection law.

2.Subject Matter and Duration

  • Subject Matter: provision of Host Smarter's platform and services, which involve Processing Personal Data submitted by Controller.
  • Duration: for the term of the Terms plus any additional period during which Processor retains Personal Data in accordance with Section 8 below.

3.Nature and Purpose of Processing

  • Nature: collection, storage, analysis, transmission, and deletion of Personal Data.
  • Purpose: to deliver pricing recommendations, listing management, analytics, marketing communications (if opted in), and related services as described in the Terms.

4.Types of Personal Data and Categories of Data Subjects

Data Subjects: Controller's end users (e.g., property hosts) and related individuals whose data appears in listings.

Categories of Personal Data:

  • Identification data (name, email, billing address)
  • Payment data (credit card information processed via Stripe)
  • Property details (availability, rates, occupancy, amenities, reviews)

5.Controller Obligations

  • Ensure compliance with all applicable data‑protection laws when collecting and submitting Personal Data to Processor.
  • Provide clear instructions to Processor and ensure lawful basis for Processing.
  • Maintain records of processing activities under its responsibility.

6.Processor Obligations

  • Process Personal Data only on documented instructions from Controller, including onward transfers to Sub‑processors.
  • Ensure personnel with access to Personal Data are bound by confidentiality.
  • Implement and maintain appropriate technical and organizational measures to protect data, including:

    • Encryption in transit and at rest
    • Access controls and authentication
    • Regular security assessments and audits
  • Assist Controller in fulfilling data‑subject rights (access, rectification, deletion, restriction, portability).
  • Notify Controller without undue delay of any Personal Data breach and cooperate in breach‑management.

7.Sub‑processing

Controller authorizes Processor to engage Sub‑processors, including:

  • Stripe, Inc. for payment processing
  • Hosting and infrastructure providers (e.g., cloud services)

Processor will:

  • Conduct due diligence and require Sub‑processors to adhere to obligations no less protective than this Agreement
  • Remain fully liable for Sub‑processor acts or omissions

8.International Data Transfers

  • Processor may transfer Personal Data across borders under lawful mechanisms such as Standard Contractual Clauses or adequacy decisions.
  • Processor ensures equivalent safeguards apply to transferred data.

9.Data Retention and Deletion

  • Processor retains Personal Data only as long as needed to provide services and for one year after the last use or contract termination, unless law requires otherwise.
  • Upon expiry of retention, Processor will securely delete or return all Personal Data, at Controller's choice.

10.Audit and Inspection

  • Controller may audit Processor's compliance once per year, upon reasonable notice, during business hours, and subject to confidentiality constraints.
  • Processor will provide evidence of technical and organizational measures.

11.Liability

Each party's liability under this Agreement is governed by the liability provisions in the Terms, subject to applicable mandatory law.

12.Miscellaneous

  • This Agreement is governed by the law specified in the Terms.
  • Any amendment must be in writing and signed by both parties.
  • If any provision is held invalid, the remainder stays in effect, and the parties will replace the invalid term with a lawful, equivalent provision.

By using Host Smarter's services, you acknowledge and agree to the terms of this Data Processing Agreement.

Stop guessing. Start hosting smarter with personalized analytics and coaching. Tailored strategies for your property, your guests, your success.