Data processing

Your guests' data (Art. 28 GDPR)

Last updated: 29 July 2026 · version 2026-07-28

When you use Ospitia to handle your guests' data, you are the controller and we are the processor. This agreement governs that relationship and is required by law: Art. 28 GDPR forbids a controller from entrusting data to a processor without a contract containing specific terms. Those terms are the articles below. It forms an integral part of the terms of service and is to be read together with the privacy notice. This English version is a courtesy translation: in case of conflict, the Italian text prevails.

1. Subject matter, duration, nature and purpose

Subject matter: the processing of personal data which you, as controller, entrust to Elite Properties SRL for the provision of Ospitia.

Duration: for the term of the service contract, and for the time strictly needed for the deletion or return operations under article 9.

Nature and purpose: collection, recording, organisation, storage, retrieval, use, disclosure to recipients designated by the controller or required by law, erasure. The purposes are those of the service: managing bookings and stays, guest communications, filings with authorities, collections, day-to-day operation of the properties.

Types of data and categories of data subjects: those listed below. We do not process biometric data or special categories under Art. 9 GDPR on your behalf: entering such data falls outside the agreed purposes and is your sole responsibility.

Category of data subjectsTypes of dataPurpose
Guests and co-guestsName, date and place of birth, nationality, identity document (type, number, photo), contact details, stay detailsPublic security, statistical and tax filings; managing the stay
Guests — communicationsMessages exchanged with the property, language, stated preferencesGuest support, including AI-generated drafts
Guests — paymentsAmounts, references, payment status, transaction identifiersDeposits, tourist tax, extra services. Full card details never reach our systems
Guests — accessDoor-opening events: date, time, device, code usedSecurity and reconstruction of access, if you use connected locks
Customer's staffName, role, contact details, shifts, tasks performedManaging cleaning and operational tasks
Owners and suppliersIdentity and tax details needed for statements and invoicesStatements and invoicing on the customer's behalf

Controller's obligations and rights: you determine the purposes and means, identify the legal basis towards the guest, provide them with the required notice and answer their requests. You have the right to issue instructions to us and to verify how we carry them out, under article 10.

2. Processing only on documented instructions

We process the data only on your documented instructions, including as regards transfers to third countries. Documented instructions comprise: this agreement, the terms of service, the settings you configure in the product, and requests you send us in writing.

We process data beyond your instructions only where required by Union or Member State law; in that case we inform you before processing, unless the law prohibits it on important grounds of public interest.

If we consider that an instruction of yours infringes the GDPR or other data protection law, we tell you immediately and may suspend its execution until you confirm or amend it (Art. 28(3), final paragraph).

3. Confidentiality

Persons authorised to process the data on our behalf are bound by a statutory or contractual duty of confidentiality, receive written instructions and access only the data needed for their task. We keep a record of authorisations and revoke them when the relationship ends.

4. Security measures (Art. 32)

We implement technical and organisational measures appropriate to the risk. Concretely, not as boilerplate:

  • encryption of data in transit and at rest;
  • isolation between organisations: every database query is bound to the organisation of the session, and that binding is enforced in shared code rather than left to individual discipline;
  • role-based access control, with per-feature permissions and expiring sessions;
  • immutable audit records on sensitive operations;
  • automatic deletion of data when its retention window closes, with no manual step;
  • minimisation: AI providers receive the minimum needed to produce the individual response, and identity documents never leave the European Union;
  • continuity and recovery: backups and documented restore procedures;
  • monitoring of errors and anomalous access, with automatic alerting.

Measures may evolve: we may replace them with measures of at least equivalent effectiveness, never lower.

5. Sub-processors

You give us general authorisation to engage the sub-processors listed in the privacy notice, which is the official, current list. Each sub-processor is bound by contract to the same obligations this agreement places on us, and we remain fully liable to you for their performance.

We notify you of any addition or replacement with at least 30 days' notice. Within that period you may object on reasonable data protection grounds: if no alternative can be found, you may terminate without penalty, with a pro-rata refund of the unused period.

6. Assistance with data subject rights

A guest wishing to access, rectify, erase or port their data addresses you, the controller. We assist with appropriate technical measures: export in open formats, lookup by guest or booking, targeted deletion.

If a request reaches us directly, we do not answer it on the merits: we forward it to you without undue delay and in any case within 5 working days, and remain available for the technical execution.

One limit to know: erasure cannot go beyond statutory retention obligations. Where those fall on you (five years for public security filings, ten for tax documents) the archive is yours, as explained in the compliance liability statement.

7. Assistance with security, breaches and impact assessments

Taking into account the nature of the processing and the information available to us, we assist you in complying with Arts. 32 to 36 GDPR.

  • Personal data breaches: we inform you without undue delay and in any case within 24 hours of becoming aware, with the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences and the measures taken. The 24 hours exist to leave you usable margin inside the 72 hours you owe the supervisory authority.
  • Notification to the authority and to data subjects: yours as controller. We supply everything needed and do not notify third parties on your behalf without your agreement, unless required by law.
  • Impact assessments (DPIA) and prior consultation: we make available the product's technical documentation and the assessments we have already carried out, including the one on AI features applied to check-in documents.

8. Transfers outside the European Union

Guest data is stored in the European Union. Some AI providers are based in the United States and receive only the content strictly needed to generate the individual response: those transfers rely on the Standard Contractual Clauses approved by the European Commission, with a transfer impact assessment and supplementary measures.

Guests' identity documents are not transferred outside the European Union. Should such a transfer ever become necessary, we would tell you beforehand, under the same procedure as for sub-processors.

9. Deletion or return at the end of the relationship

On termination, at your choice, we delete or return all personal data processed on your behalf, and delete existing copies.

  • You can export the data in open formats before and after account closure.
  • Absent a different instruction from you, we proceed to permanent deletion 30 days after closure.
  • Only data we are required to keep by Union or national law is retained, for the time strictly necessary and without further processing.

10. Information and audits

We make available all information necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits, including inspections, conducted by you or by an auditor you mandate who is not a competitor of ours.

  • Reasonable notice, normally 30 days, save for justified urgency or a request from a supervisory authority.
  • One audit per contract year is at our cost; further audits, unless following a confirmed breach, are at yours.
  • Audits take place during working hours, without compromising the security and confidentiality of other customers' data.
  • Information obtained is subject to confidentiality.

11. Liability

Each party is liable for damage caused by its own breach of GDPR obligations, under Art. 82. The liability limits in article 9 of the terms of service apply to this agreement as well, save for what the law does not allow to be limited: in particular, no limit operates towards data subjects or the supervisory authority.

In case of conflict between this agreement and the terms of service, for data protection matters this agreement prevails.