General principles

AMENITIZ SOLUTIONS (hereinafter "Amenitiz") protects the Personal Data processed through the implementation of appropriate technical, physical and organizational measures. Such measures ensure that Amenitiz provides its clients and employees with sufficient guarantees so that the processing meets the requirements of the regulations relating to the protection of Personal Data (hereinafter the "Regulations"), including in particular the General Regulation on the Protection of Personal Data 2016/679 adopted on April 27, 2016 (hereinafter the "GDPR"), and thus guarantees the protection of the rights of the Data Subject.

Under this Agreement, Subscriber acts as the Data Controller and Amenitiz acts as the Data Processor as supplier/service provider.

Capitalized terms not defined below shall be interpreted in accordance with the definition given to them in Article 4 of the GDPR.

Processing of Personal Data

Roles and Obligations - The obligations of the Data Controller and the Data Processor are defined within this Agreement.

Limitation of Processing - The Data Processor and any person acting under its authority who has access to Personal Data will only process Personal Data on the documented instructions of the Data Controller, unless it is legally required to do so.

Processing Instructions - The Data Processor shall only process Personal Data upon documented instruction from the Data Controller and in accordance with this Agreement. The instructions shall include, among other things, the purpose and duration of the Processing, its nature and purposes, the type of Personal Data and the categories of Data Subjects, the rights and obligations of the Data Controller. The Data Controller shall provide the Data Processor with sufficiently clear instructions. The Data Processor shall immediately inform the Data Controller if any of its instructions appear to constitute a breach of the Regulations.

Sensitive Data - Where the Data Controller requests the Data Processor to process Sensitive Data, the Data Controller shall be responsible for defining the measures to be implemented in this respect and for ensuring that the Processing complies with the Regulations and any other applicable law. In any case, when processing Sensitive Data as a data processor, the Data Processor shall not be required to ensure that the Processing has a legal basis that complies with the Regulations and shall not be liable in this respect as this is an obligation of the Data Controller.

Compliance with the Regulations - Each of the Parties undertakes to comply with the principles and obligations set out in the Regulations, that is the GDPR and any other appliable data protection law, whether acting as a Data Controller or as a Data Processor, respectively.

Data Processor’s workforce - The Data Processor shall ensure that any person under its control has received specific training appropriate to their duties and provide evidence of this training to the Data Controller upon request. The Data Processor guarantees that the persons authorized to process Personal Data are committed to confidentiality or are subject to an appropriate legal obligation of confidentiality and have available an evidence if requested by the Data Controller to demonstrate compliance with the GDPR.

Termination- Unless Regulations require the retention of Personal Data and subject to a written request from the Data Controller, retained Personal Data shall, at the option of the Data Controller, be deleted, returned by the Data Processor at the end of the contract between the Parties or provided to another Data Processor designated by the Data Controller. The Data Controller acknowledges that such operations (1) will be strictly limited to the Personal Data retained by the Data Processor at the time of the request and provided by the Data Controller (2) will take into account the safeguarding requirements, policies and standards regarding security.

On termination of the provision of the Services, the Data Processor shall, at the choice of the Data Controller, delete or return all Personal Data processed on its behalf within thirty (30) days, and delete existing copies, unless Union or Member State law requires storage of the Personal Data. Personal Data contained in backups is purged in the ordinary rotating backup cycle, which completes within ninety (90) days.

Sub-processors

The Data Processor has the Data Controller’s general authorisation for the engagement of sub-processors from an agreed list that is part of this Agreement. The Data Processor shall specifically inform in writing the Data Controller of any intended changes of that list through the addition or replacement of sub-processors at least fifteen days (15) in advance, thereby giving the controller sufficient time to be able to object to such changes prior to the engagement of the concerned sub-processor(s). The Data Processor shall provide the Data Controller with the information necessary to enable the controller to exercise the right to object.

If the Data Controller rejects a sub-processor, it must be done based on objective reasons. Both parties will act on good faith to find a solution.

Written information under this clause is given by email to the contact address held on the Data Controller’s account and by notice in the customer area.

Location and transfer of Personal Data

Location of the Processing of Personal Data - The Personal Data subject to Processing must be processed:

  • In the European Economic Area ("EEA");
  • Failing that, in a third country or an international organization which the European Commission has determined by decision provides an adequate level of protection;
  • Failing that, by any recipient offering appropriate guarantees within the meaning of Article 46 of the GDPR.

Security

The Data Processor takes all necessary measures for the security of the Personal Data and follows the instructions communicated by the Data Controller. The Data Processor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk.

Mutual assistance

The Data Processor shall notify the Data Controller of any Personal Data Breach affecting Personal Data processed on the Data Controller’s behalf without undue delay and in any event within forty-eight (48) hours of becoming aware of it. The notification shall at least:

  • describe the nature of the Personal Data Breach including, where possible, the categories and approximate number of Data Subjects concerned and the categories and approximate number of Personal Data records concerned;
  • communicate the name and contact details of the contact point from whom more information can be obtained;
  • describe the likely consequences of the Personal Data Breach;
  • describe the measures taken or proposed to be taken by the Data Processor to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.

Where and in so far as it is not possible to provide all of that information at the same time, it may be provided in phases without further undue delay.

For the purposes of Article 33(1) GDPR, the Data Controller is deemed to become aware of the Personal Data Breach when the Data Processor notifies it in accordance with this clause. The Data Processor shall cooperate with and assist the Data Controller in any notification the Data Controller is required to make to a supervisory authority or to Data Subjects.

Data Protection Impact Assessments - Taking into account the nature of the Processing and the information available to the Data Processor, the Data Processor shall assist the Data Controller when the Data Controller considers that a data protection impact assessment is necessary in view of the nature, scope, context and purposes of the Processing.

Exercise of Data Subjects' Rights - When the Data Controller receives a request from a Data Subject wishing to exercise his or her rights and whose Personal Data is or has been processed by the Data Processor, it shall inform the Data Processor as soon as possible, so that the Data Processor may be in a position to provide the Data Controller with the assistance required to process such request. The Data Controller will inform the Data Processor of the request in writing.

When the Data Processor receives a request from a Data Subject wishing to exercise his/her rights, he/she shall inform the Data Controller in writing. In accordance with the Regulations, the Data Controller is liable for handling such request. The Data Processor is only liable for following the additional instructions of the Data Controller on how to deal with the request.

The Data Processor shall assist the Data Controller in responding to requests from Data Subjects exercising their rights under Chapter III GDPR, and shall provide the assistance requested within five (5) business days of the Data Controller’s request, or sooner where necessary to allow the Data Controller to comply with the deadline in Article 12(3) GDPR.

Information to the Data Subjects - The Data Controller, at the time of collection of the Personal Data, must provide the Data Subjects of the Processing operations with information regarding the Personal Data Processing.

Audit

The Data Controller, or an auditor mandated by the Data Controller, shall be entitled to conduct audits, including inspections, to assess the Data Processor’s compliance with this Agreement and with Article 28 GDPR. The Data Processor shall make available to the Data Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and shall contribute to such audits.

Audits shall be carried out on reasonable prior notice, during business hours, and in a manner that does not disproportionately disrupt the Data Processor’s operations. The Data Processor shall immediately inform the Data Controller if, in its opinion, an instruction infringes the GDPR or other applicable data protection provisions.

Appendix 1

Purpose of the processing and sub-purposes

Purpose of the processing: provision of the Services supplied by Amenitiz Solutions to the Data Controller under the services agreement between the Parties.

Sub-purposes. In the course of providing the Services, the Data Processor carries out the following processing operations on behalf of the Data Controller:

  • Reservation management — recording, modifying and cancelling guest bookings received directly, at the front desk or through connected online travel agencies (channel manager), including guest identity, contact and stay details and booking-related correspondence;
  • Booking engine operation — collecting the guest identity, contact, stay and payment details submitted through the booking engine on the Data Controller’s website;
  • Guest communications — sending transactional and scheduled emails and SMS messages to guests (booking confirmations, pre-arrival, in-stay and post-stay messages) and centralising guest–hotelier correspondence in a unified inbox, using guest contact details and booking data;
  • Payment processing — collecting payment card and bank details and transmitting them to the Data Processor’s payment service providers and card-data vault for the authorisation, pre-authorisation, settlement, refund and chargeback handling of bookings, deposits and point-of-sale charges (AmenitizPay);
  • Invoicing and fiscal compliance — generating invoices, receipts and credit notes from booking, guest and billing data and, where the law of the Data Controller’s country requires it, transmitting them to certified fiscalisation or electronic-invoicing intermediaries;
  • Front-desk operations — check-in and check-out, guest registration records including, where the applicable national law requires it, identity document details, room assignment and point-of-sale billing;
  • Website hosting — hosting the Data Controller’s public website and the content, images and forms published on it, where the Data Controller uses the website-builder feature;
  • Reporting and analytics — producing occupancy, revenue and performance reports for the Data Controller from booking and billing data;
  • Support and service administration — providing technical support at the Data Controller’s request, maintaining the security, availability and performance of the Services, and creating and restoring backups.

Nature of the processing

Collection, recording, organisation, structuring, storage, retrieval, consultation, use, disclosure by transmission to the recipients identified in this Appendix, restriction, erasure and destruction of Personal Data, carried out through the Amenitiz property-management platform for the sub-purposes listed above.

Duration of the processing

The term of the services agreement between the Parties, plus the period required to return and/or delete Personal Data in accordance with the Termination clause, and any longer statutory retention period applicable to specific categories of data (see Retention periods below).

Legal basis

The Data Controller determines the legal basis for the processing under Article 6 GDPR and, where applicable, Article 9 GDPR. This Agreement governs the processing carried out by the Data Processor on the Data Controller’s behalf and on its documented instructions.

Categories of Data Subjects

The Personal Data processed concerns the following categories of Data Subjects:

  • Guests and prospective guests of the Data Controller, including, where a booking covers them, accompanying persons and minors travelling as part of a family booking;
  • Employees and authorised users of the Data Controller who operate the Services;
  • Visitors to the Data Controller’s website hosted through the Services.

Special categories of data (Article 9 GDPR)

Free-text fields in the Services, in particular guest notes and guest preferences, are populated by the Data Controller. Where the Data Controller enters information revealing a special category of Personal Data within the meaning of Article 9 GDPR — for example accessibility or mobility requirements — the Data Controller is responsible for establishing a valid condition for that processing under Article 9(2) GDPR and for informing the Data Subjects accordingly. The Data Processor applies additional technical and organisational security measures to those fields, appropriate to the nature of the data and the risk to Data Subjects.

Categories of Personal Data and retention periods (“Shelf life”)

Category of Personal DataExamplesRetention period
Identification and contact dataName, email, telephone, postal address, nationality, date of birth where collectedTerm of the services agreement, plus up to 30 days for the deletion cycle. Copies held in backups are purged in the ordinary rotating backup cycle.
Booking and stay dataDates, room, rate, channel, guest notes and preferences, arrival and departureTerm of the services agreement, plus up to 30 days for the deletion cycle.
Data of the Data Controller’s usersName, business email, role, access and activity logsTerm of the services agreement, plus up to 30 days for the deletion cycle.
Economic and financial data — invoicingInvoices, receipts, credit notes, amounts, tax identifiersFor the period required by the accounting and tax legislation applicable to the Data Controller in its country of establishment.
Payment card dataCard number and security code submitted at booking or at the front deskNot stored in the clear by the Data Processor. Card data is tokenised in the card-data vault of the Data Processor’s provider and processed by the payment service provider; the token is retained for the term of the services agreement and deleted with the guest record.
Technical and connection dataIP address, device and browser data, application logs30 days.
Identity document dataDocument type and number, where the traveller-registration law applicable to the Data Controller requires it to be collectedFor the period laid down by that national legislation.

International transfers (Part III of the Appendix)

Personal Data processed under this Agreement is transferred to recipients established outside the European Economic Area, in particular in the United States, where sub-processors engaged by the Data Processor provide part of the Services, including hosting-adjacent services, payment processing, transactional messaging, media hosting and technical monitoring, as well as backups.

These transfers are carried out on the basis of appropriate safeguards under Chapter V GDPR, namely the standard contractual clauses adopted by the European Commission and/or the EU–US Data Privacy Framework where the recipient is certified under it. The Data Processor obtains from each recipient the information necessary to assess the risk of the transfer and to verify that the required safeguards are in place.

The detailed list of the recipients concerned, stating the function of each recipient, the country in which it processes Personal Data and the transfer instrument relied upon, is provided to the Data Controller on request at privacy@amenitiz.com.

List of Authorised Sub-processors

The Data Processor engages the sub-processors identified in the List of Authorised Sub-processors, which forms part of this Agreement. The list states, for each sub-processor, its function, the country in which it processes Personal Data and, where processing takes place outside the European Economic Area, the transfer instrument relied upon. The current list is provided to the Data Controller on request at privacy@amenitiz.com. Changes to the list are notified in accordance with the Sub-processors clause.

Version, effective date and notification of changes

Version 1.1 — Effective 10 September 2026. Last updated: 10 September 2026.

Material changes to this Agreement take effect thirty (30) days after they are notified to Data Controllers. Notification is given by publishing the updated Agreement on this page and, in addition, by email to the contact address held on the Data Controller’s account or by notice in the customer area. Changes to the List of Authorised Sub-processors follow the specific notice period set out in the Sub-processors clause.

Change log

1.1 — 10 September 2026 — International transfers section corrected; sub-purposes, categories of Data Subjects, retention periods, sub-processor governance, audit and breach clauses updated.

1.0 — 20 March 2026 — First published version.