Data Processing Agreement

1 Introduction

1.1 The Customer and Zaplar have entered into the Agreement. This data processing agreement (the “DPA”) supplements the Agreement.

1.2 Within the undertakings arising from the Agreement, Zaplar will process personal data and other information on behalf of the Customer.

1.3 For that reason, the Parties confirm that this DPA shall regulate the conditions for Zaplar’s processing of, and access to, personal data on behalf of the Customer.

2 Definitions

Unless the circumstances clearly indicate otherwise, definitions or terms used in this document shall be defined as set forth below and any such definition or term which is used in the General Data Protection Regulation and which is not stated below shall be defined as follows from Article 4 of the General Data Protection Regulation. Definitions are also set out in the Agreement.

“Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.

“General Data Protection Regulation” means Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC.

“Instruction” means the instructions the Customer gives Zaplar within the scope of this DPA, as further set out in Sub-Appendix 1.

“Other Regulatory Regime” means national laws applicable from time to time to processing of personal data (excluding the General Data Protection Regulation).

“Processor” means a natural or legal person, public authority, agency or another body which processes personal data on behalf of the Controller.

3 Documents

3.1 This DPA consists of this document and the attached instruction. In the event of any contradiction between the documents and the instructions, this document shall prevail, unless otherwise specified or unless another document expressly states otherwise.

3.2 Irrespective of what the Parties have otherwise agreed regarding conflicts, the provisions of this DPA shall take precedence over all other provisions of the Agreement and its appendices in cases where the conflict relates to processing of personal data.

4 Generally regarding the processing

4.1 The Customer is the Controller of the personal data processed in connection with performance and provision of services under the Agreement and its appendices.

4.2 Zaplar is to be considered as Processor on behalf of the Customer. As a Processor, Zaplar is responsible for carrying out all processing of personal data on behalf of the Customer in accordance with this DPA, the Instruction, and the General Data Protection Regulation.

4.3 Zaplar has provided sufficient warranties regarding implementation of appropriate technical and organisational measures in such manner that the processing of personal data fulfils the requirements of the General Data Protection Regulation and Other Regulatory Regime, and to ensure that the rights of the data subjects are protected. The Customer represents and warrants that it has obtained and maintains all consents, authorisations, and other lawful grounds required to permit Zaplar to process personal data in accordance with this DPA and the Instruction, and that it has fulfilled its obligations to inform the relevant data subjects accordingly.

4.4 Taking into account the nature of the processing, Zaplar shall, through appropriate technical and organisational measures, assist the Customer, to the extent possible, so that the Customer can fulfil its obligation to respond to requests regarding exercise of the rights of the data subjects in accordance with Chapter III of the General Data Protection Regulation.

4.5 If Zaplar considers that an Instruction or other instruction or communication from the Customer infringes the General Data Protection Regulation or Other Regulatory Regime, Zaplar shall promptly notify the Customer, and Zaplar may suspend performance of the relevant processing until the Customer confirms or amends the instruction in writing, without liability to Zaplar for any resulting delay.

5 Purpose and type of personal data, etc.

The Instruction shall, inter alia, state the subject of the processing, the duration, nature and purpose of the processing, the type of personal data, and the categories of data subjects.

6 Validity of the Data Processing Agreement

This DPA shall apply as from execution of the Agreement and shall remain in force for as long as Zaplar or any subprocessor retained by Zaplar processes personal data on behalf of the Customer within the scope of the undertakings arising from this DPA, the Agreement, and appendices.

7 Zaplar’s personnel, etc.

7.1 Zaplar, its employees, and other persons carrying out work under Zaplar’s supervision, and who are given access to personal data by the Customer, may only process such personal data as instructed by the Customer, unless otherwise follows from an obligation under EU or applicable national law.

7.2 Zaplar shall ensure that its employees and all other persons for whom Zaplar is responsible and who are authorised to process personal data covered by this DPA undertake to observe confidentiality (unless such person is subject to a relevant and appropriate statutory duty of confidentiality).

8 Security

8.1 Zaplar shall take all necessary security measures required in accordance with Article 32 of the General Data Protection Regulation and this DPA.

8.2 In assessing the appropriate level of security in accordance with the clause above, particular account shall be taken of the risks that are presented by the processing, in particular from accidental or unlawful destruction, loss or alteration, or from unauthorised disclosure of, or access to, the personal data transmitted, stored, or otherwise processed.

8.3 Taking into account the type of the processing and the information in possession of Zaplar, Zaplar shall assist the Customer in ensuring that the latter’s obligations regarding security can be fulfilled in the manner which follows from Article 32 of the General Data Protection Regulation.

9 Personal data breach

9.1 Taking into account the type of processing and the information reasonably available to Zaplar, Zaplar shall provide the Customer with reasonable assistance to enable the Customer to fulfil its obligations under Articles 33–34 of the General Data Protection Regulation. Zaplar shall be entitled to compensation on a time and material basis for providing such assistance.

9.2 Zaplar shall notify the Customer without undue delay, and in any event within seventy-two (72) hours, after Zaplar becomes aware of and has confirmed a personal data breach affecting personal data processed under this DPA.

10 Impact assessment and prior consultation

Zaplar shall, taking into account the nature of the processing and the information available to Zaplar, and to the extent reasonably practicable and proportionate to the information available to Zaplar, assist the Customer in fulfilling its obligations, if any, regarding the performance of a data protection impact assessment and/or prior consultation with a supervisory authority in accordance with Articles 35 and 36 of the General Data Protection Regulation. Zaplar shall be entitled to compensation on a time and material basis for providing such assistance.

11 Instruction

11.1 Zaplar shall process personal data covered by this DPA only on the Customer’s documented instructions, which shall include: (i) the Instruction set out in Sub-Appendix 1; (ii) any other written instruction issued by the Customer from time to time; and (iii) processing that is reasonably necessary to perform the Agreement, even if not separately documented. Zaplar may also process personal data (a) where required to do so by EU law or the national law of a Member State to which Zaplar is subject, in which case Zaplar shall inform the Customer of that legal requirement before processing unless prohibited on important public interest grounds; or (b) to the extent reasonably necessary for Zaplar’s own legal, regulatory, security, or compliance purposes, or to establish, exercise, or defend legal claims, in each case consistent with applicable data protection law. If Zaplar considers that an instruction infringes applicable data protection law, it shall promptly inform the Customer.

11.2 The Instruction may be updated from time to time by written agreement between the Parties. Zaplar shall not be obliged to comply with an updated Instruction to the extent it would require material changes to Zaplar’s systems, services, or security measures, unless the Parties agree on appropriate adjustments to timeline, scope, and fees.

12 Subprocessors

12.1 The Customer provides Zaplar with a general written authorisation to engage subprocessors to carry out processing of personal data under this DPA, subject to the notification and objection mechanism in clause 12.2.

12.2 Zaplar shall give the Customer at least thirty (30) days’ prior written notice of any intended appointment of a new subprocessor or replacement of an existing subprocessor, identifying the subprocessor and the processing activities concerned. The Customer may object to such appointment or replacement on reasonable, documented data protection grounds by notifying Zaplar in writing within fifteen (15) days of receipt of such notice. If the Customer does not object within such period, the new subprocessor shall be deemed approved. If the Customer objects on reasonable grounds and the Parties are unable to resolve the objection through good-faith negotiation, the Customer’s sole remedy shall be to terminate the affected services (or the Agreement, to the extent it cannot be performed without the subprocessor) on written notice, without liability to Zaplar for such termination; provided that such termination right shall not apply to the extent Zaplar, at its own discretion, decides to either (a) refrain from appointing such new subprocessor, or (b) ensure that such new subprocessor does not process the Customer’s personal data.

12.3 Zaplar shall ensure that each subprocessor is bound by a written agreement before that subprocessor begins processing personal data in connection with the Agreement. That agreement shall impose data protection obligations on the subprocessor that are no less protective of personal data than those set out in this DPA, to the extent relevant to the processing carried out by that subprocessor.

12.4 The data processing agreement between Zaplar and any subprocessor shall specifically provide that the subprocessor may only engage a further subprocessor in accordance with the same general authorisation and notice/objection mechanism set out in clauses 12.1 and 12.2 of this DPA.

12.5 Zaplar shall, from time to time, maintain an updated list of the subprocessors that are retained and have been retained, and the country in which these subprocessors conduct their operations. At the request of the Customer, Zaplar shall provide the Customer with a copy of the list.

12.6 Zaplar shall exercise reasonable care in the selection and oversight of any subprocessor and shall remain responsible for ensuring that its subprocessors are contractually bound as required by the Agreement. Neither Party shall be liable to the other for indirect or consequential loss arising out of or in connection with this DPA.

12.7 A Party’s right to seek redress from the other Party under Article 82(5) of the General Data Protection Regulation shall not be restricted by clause 17.1 or by the amount specified in the Agreement’s limitation of liability.

13 Termination of the Data Processing Agreement

13.1 Upon termination of this DPA, the Customer shall, within fifteen (15) days, provide Zaplar with written instructions indicating whether it wishes for the personal data to be (i) returned to the Customer, and if so, where and how it shall be returned, or (ii) deleted. Any costs reasonably incurred by Zaplar in connection with the return of personal data to the Customer, including costs of extraction, formatting, and secure transmission, shall be borne by the Customer. Should the Customer fail to provide such instructions, Zaplar shall have the right to delete the personal data processed under this DPA, unless otherwise required by national legislation or EU law.

13.2 After termination of this DPA, Zaplar may not keep any personal data received under this DPA, and as soon as Zaplar has complied with the clause above, Zaplar’s right to process or otherwise use the personal data ceases (unless storage of the personal data is required by national legislation or EU law or Zaplar has a legal basis to process relevant personal data). The Customer is solely responsible for exporting and retaining any personal data it requires for its own purposes prior to any deletion in accordance with this clause 18, and Zaplar shall have no liability for any loss of data following such deletion.

14 Amendments

Zaplar shall be entitled to amend or supplement this DPA, in whole or in part, provided that such amendment does not materially adversely affect the Customer. Zaplar shall inform the Customer in writing of any such amendment, and the Customer may object to the amendment by notifying Zaplar in writing within thirty (30) days of receipt of such notice. If the Customer does not object within such period, the amendment shall be deemed accepted. Any other amendments or supplements to this DPA shall only be applicable if made in writing and signed by authorised representatives of the Parties.

SUB-APPENDIX 1 – THE INSTRUCTION

The following document is the Instruction. Definitions used in this Instruction shall have the same meaning as in the Agreement, unless the circumstances clearly indicate otherwise.

15 Contact details

15.1 Customer (Controller) As set out in the Agreement.

15.2 Zaplar (Processor) As set out in the Agreement.

16 Processing of Personal Data

16.1 Subject matter of the Processing The subject matter of Zaplar’s Processing of Personal Data on behalf of the Customer is: The Customer’s personal data processed in connection with performance and provision of services under the Agreement.

16.2 Purpose of each Processing The purpose of Zaplar’s Processing of Personal Data on behalf of the Customer is: To provide the services under the Agreement.

16.3 Categories of Processing The measures carried out by Zaplar as part of the Processing of Personal Data on behalf of the Customer are: Compute, storage and such other Services as described in the Agreement and in the services and initiated by Customer from time to time.

16.4 Categories of Personal Data Zaplar is entitled to Process the following categories of Personal Data on behalf of the Customer: All personal data used uploaded to the services under the Agreement by the Customer.

16.5 Categories of sensitive Personal Data Zaplar is entitled to Process the following categories of sensitive Personal Data on behalf of the Customer: Any sensitive personal data uploaded to the services under the Agreement by the Customer.

16.6 Categories of Data Subjects Zaplar is entitled to Process Personal Data relating to the following categories of Data Subjects: Any data subjects uploaded to the services under the Agreement by the Customers, such as guests, customers, vendors, and representatives thereof.

17 Duration of the Processing

Zaplar will Process Personal Data during the following time period: As between Zaplar and the Customer, the duration of the data processing under this DPA is determined by Customer.

18 Security measures

Technical and organisational security measures

Zaplar maintains an information security programme designed to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services. This programme is applied consistently to all personal data processed on behalf of the Customer. On the technical side, Zaplar applies security measures appropriate to the risk, including: encryption of personal data in transit using TLS 1.2 or higher; encryption at rest using AES-256 with keys managed in AWS Key Management Service, covering databases, object storage, and backups; automated daily encrypted backups of production databases with a defined retention period, and multi-AZ replication of the production database for redundancy; role-based access control through centralised single sign-on with multi-factor authentication enforced for all personnel; least-privilege access to production systems, where standing access is limited to read-only and elevated access is granted on a time-limited, per-need basis; logging and audit trails of access to production systems, with centralised monitoring and automated alerting to on-call personnel; network security measures including web application firewalls and private networking for data stores; infrastructure defined as code and subject to automated security scanning prior to deployment; and segregation of production from non-production environments. On the organisational side, access to personal data is granted strictly on a need-to-know basis, is subject to review, and is promptly revoked when no longer required. All personnel with access to personal data are bound by confidentiality undertakings. Zaplar maintains a structured incident response process with continuous monitoring, automated alerting, and defined on-call responsibilities. Business continuity and disaster recovery arrangements, including redundant infrastructure and automated encrypted backups, are intended to ensure timely restoration of availability and access to personal data in the event of a physical or technical incident. These measures are reviewed on an ongoing basis and may be updated provided the level of protection is not reduced.

19 Approved subprocessors

The Customer has approved Zaplar’s use of the following subprocessors:

Amazon Web Services (Amazon Web Services EMEA SARL) — Cloud infrastructure hosting — Sweden (for EU customers) and United States (for North American customers). Stripe Payments Europe, Limited (Ireland) — Payment processing — EU and United States. Channex.io LTD (UK) — Channel manager — EU. Anthropic, PBC (United States) — AI features — United States. OpenAI, L.L.C.; OpenAI Ireland Ltd. — AI features — United States. BoldSign (Syncfusion, Inc., United States) — Electronic document signing — Sweden (for EU customers) and United States (for North American customers). Datadog, Inc. (United States) — Infrastructure monitoring and logging — EU. Sentry (Functional Software, Inc., United States) — Error and crash reporting — EU. PostHog, Inc. (United States) — Product analytics and session replay — EU.

Helping exceptional hoteliers do their best work.

We believe great hospitality is about being present with the guest, not spending time infront of a screen.