1. Subject matter, duration, nature and purpose
Subject matter: the processing of personal data which you, as controller, entrust to Elite Properties SRL for the provision of Ospitia.
Duration: for the term of the service contract, and for the time strictly needed for the deletion or return operations under article 9.
Nature and purpose: collection, recording, organisation, storage, retrieval, use, disclosure to recipients designated by the controller or required by law, erasure. The purposes are those of the service: managing bookings and stays, guest communications, filings with authorities, collections, day-to-day operation of the properties.
Types of data and categories of data subjects: those listed below. We do not process biometric data or special categories under Art. 9 GDPR on your behalf: entering such data falls outside the agreed purposes and is your sole responsibility.
| Category of data subjects | Types of data | Purpose |
|---|---|---|
| Guests and co-guests | Name, date and place of birth, nationality, identity document (type, number, photo), contact details, stay details | Public security, statistical and tax filings; managing the stay |
| Guests — communications | Messages exchanged with the property, language, stated preferences | Guest support, including AI-generated drafts |
| Guests — payments | Amounts, references, payment status, transaction identifiers | Deposits, tourist tax, extra services. Full card details never reach our systems |
| Guests — access | Door-opening events: date, time, device, code used | Security and reconstruction of access, if you use connected locks |
| Customer's staff | Name, role, contact details, shifts, tasks performed | Managing cleaning and operational tasks |
| Owners and suppliers | Identity and tax details needed for statements and invoices | Statements and invoicing on the customer's behalf |
Controller's obligations and rights: you determine the purposes and means, identify the legal basis towards the guest, provide them with the required notice and answer their requests. You have the right to issue instructions to us and to verify how we carry them out, under article 10.
2. Processing only on documented instructions
We process the data only on your documented instructions, including as regards transfers to third countries. Documented instructions comprise: this agreement, the terms of service, the settings you configure in the product, and requests you send us in writing.
We process data beyond your instructions only where required by Union or Member State law; in that case we inform you before processing, unless the law prohibits it on important grounds of public interest.
3. Confidentiality
Persons authorised to process the data on our behalf are bound by a statutory or contractual duty of confidentiality, receive written instructions and access only the data needed for their task. We keep a record of authorisations and revoke them when the relationship ends.
4. Security measures (Art. 32)
We implement technical and organisational measures appropriate to the risk. Concretely, not as boilerplate:
- encryption of data in transit and at rest;
- isolation between organisations: every database query is bound to the organisation of the session, and that binding is enforced in shared code rather than left to individual discipline;
- role-based access control, with per-feature permissions and expiring sessions;
- immutable audit records on sensitive operations;
- automatic deletion of data when its retention window closes, with no manual step;
- minimisation: AI providers receive the minimum needed to produce the individual response, and identity documents never leave the European Union;
- continuity and recovery: backups and documented restore procedures;
- monitoring of errors and anomalous access, with automatic alerting.
Measures may evolve: we may replace them with measures of at least equivalent effectiveness, never lower.
5. Sub-processors
You give us general authorisation to engage the sub-processors listed in the privacy notice, which is the official, current list. Each sub-processor is bound by contract to the same obligations this agreement places on us, and we remain fully liable to you for their performance.
We notify you of any addition or replacement with at least 30 days' notice. Within that period you may object on reasonable data protection grounds: if no alternative can be found, you may terminate without penalty, with a pro-rata refund of the unused period.
6. Assistance with data subject rights
A guest wishing to access, rectify, erase or port their data addresses you, the controller. We assist with appropriate technical measures: export in open formats, lookup by guest or booking, targeted deletion.
If a request reaches us directly, we do not answer it on the merits: we forward it to you without undue delay and in any case within 5 working days, and remain available for the technical execution.
7. Assistance with security, breaches and impact assessments
Taking into account the nature of the processing and the information available to us, we assist you in complying with Arts. 32 to 36 GDPR.
- Personal data breaches: we inform you without undue delay and in any case within 24 hours of becoming aware, with the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences and the measures taken. The 24 hours exist to leave you usable margin inside the 72 hours you owe the supervisory authority.
- Notification to the authority and to data subjects: yours as controller. We supply everything needed and do not notify third parties on your behalf without your agreement, unless required by law.
- Impact assessments (DPIA) and prior consultation: we make available the product's technical documentation and the assessments we have already carried out, including the one on AI features applied to check-in documents.
8. Transfers outside the European Union
Guest data is stored in the European Union. Some AI providers are based in the United States and receive only the content strictly needed to generate the individual response: those transfers rely on the Standard Contractual Clauses approved by the European Commission, with a transfer impact assessment and supplementary measures.
Guests' identity documents are not transferred outside the European Union. Should such a transfer ever become necessary, we would tell you beforehand, under the same procedure as for sub-processors.
9. Deletion or return at the end of the relationship
On termination, at your choice, we delete or return all personal data processed on your behalf, and delete existing copies.
- You can export the data in open formats before and after account closure.
- Absent a different instruction from you, we proceed to permanent deletion 30 days after closure.
- Only data we are required to keep by Union or national law is retained, for the time strictly necessary and without further processing.
10. Information and audits
We make available all information necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits, including inspections, conducted by you or by an auditor you mandate who is not a competitor of ours.
- Reasonable notice, normally 30 days, save for justified urgency or a request from a supervisory authority.
- One audit per contract year is at our cost; further audits, unless following a confirmed breach, are at yours.
- Audits take place during working hours, without compromising the security and confidentiality of other customers' data.
- Information obtained is subject to confidentiality.
11. Liability
Each party is liable for damage caused by its own breach of GDPR obligations, under Art. 82. The liability limits in article 9 of the terms of service apply to this agreement as well, save for what the law does not allow to be limited: in particular, no limit operates towards data subjects or the supervisory authority.
In case of conflict between this agreement and the terms of service, for data protection matters this agreement prevails.