AMENITIZ SOLUTIONS (hereinafter "Amenitiz") protects the Personal Data processed through the implementation of appropriate technical, physical and organizational measures. Such measures ensure that Amenitiz provides its clients and employees with sufficient guarantees so that the processing meets the requirements of the regulations relating to the protection of Personal Data (hereinafter the "Regulations"), including in particular the General Regulation on the Protection of Personal Data 2016/679 adopted on April 27, 2016 (hereinafter the "GDPR"), and thus guarantees the protection of the rights of the Data Subject.
Under this Agreement, Subscriber acts as the Data Controller and Amenitiz acts as the Data Processor as supplier/service provider.
Capitalized terms not defined below shall be interpreted in accordance with the definition given to them in Article 4 of the GDPR.
Roles and Obligations - The obligations of the Data Controller and the Data Processor are defined within this Agreement.
Limitation of Processing - The Data Processor and any person acting under its authority who has access to Personal Data will only process Personal Data on the documented instructions of the Data Controller, unless it is legally required to do so.
Processing Instructions - The Data Processor shall only process Personal Data upon documented instruction from the Data Controller and in accordance with this Agreement. The instructions shall include, among other things, the purpose and duration of the Processing, its nature and purposes, the type of Personal Data and the categories of Data Subjects, the rights and obligations of the Data Controller. The Data Controller shall provide the Data Processor with sufficiently clear instructions. The Data Processor shall immediately inform the Data Controller if any of its instructions appear to constitute a breach of the Regulations.
Sensitive Data - Where the Data Controller requests the Data Processor to process Sensitive Data, the Data Controller shall be responsible for defining the measures to be implemented in this respect and for ensuring that the Processing complies with the Regulations and any other applicable law. In any case, when processing Sensitive Data as a data processor, the Data Processor shall not be required to ensure that the Processing has a legal basis that complies with the Regulations and shall not be liable in this respect as this is an obligation of the Data Controller.
Compliance with the Regulations - Each of the Parties undertakes to comply with the principles and obligations set out in the Regulations, that is the GDPR and any other appliable data protection law, whether acting as a Data Controller or as a Data Processor, respectively.
Data Processor’s workforce - The Data Processor shall ensure that any person under its control has received specific training appropriate to their duties and provide evidence of this training to the Data Controller upon request. The Data Processor guarantees that the persons authorized to process Personal Data are committed to confidentiality or are subject to an appropriate legal obligation of confidentiality and have available an evidence if requested by the Data Controller to demonstrate compliance with the GDPR.
Termination- Unless Regulations require the retention of Personal Data and subject to a written request from the Data Controller, retained Personal Data shall, at the option of the Data Controller, be deleted, returned by the Data Processor at the end of the contract between the Parties or provided to another Data Processor designated by the Data Controller. The Data Controller acknowledges that such operations (1) will be strictly limited to the Personal Data retained by the Data Processor at the time of the request and provided by the Data Controller (2) will take into account the safeguarding requirements, policies and standards regarding security.
On termination of the provision of the Services, the Data Processor shall, at the choice of the Data Controller, delete or return all Personal Data processed on its behalf within thirty (30) days, and delete existing copies, unless Union or Member State law requires storage of the Personal Data. Personal Data contained in backups is purged in the ordinary rotating backup cycle, which completes within ninety (90) days.
The Data Processor has the Data Controller’s general authorisation for the engagement of sub-processors from an agreed list that is part of this Agreement. The Data Processor shall specifically inform in writing the Data Controller of any intended changes of that list through the addition or replacement of sub-processors at least fifteen days (15) in advance, thereby giving the controller sufficient time to be able to object to such changes prior to the engagement of the concerned sub-processor(s). The Data Processor shall provide the Data Controller with the information necessary to enable the controller to exercise the right to object.
If the Data Controller rejects a sub-processor, it must be done based on objective reasons. Both parties will act on good faith to find a solution.
Written information under this clause is given by email to the contact address held on the Data Controller’s account and by notice in the customer area.
Location of the Processing of Personal Data - The Personal Data subject to Processing must be processed:
The Data Processor takes all necessary measures for the security of the Personal Data and follows the instructions communicated by the Data Controller. The Data Processor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk.
The Data Processor shall notify the Data Controller of any Personal Data Breach affecting Personal Data processed on the Data Controller’s behalf without undue delay and in any event within forty-eight (48) hours of becoming aware of it. The notification shall at least:
Where and in so far as it is not possible to provide all of that information at the same time, it may be provided in phases without further undue delay.
For the purposes of Article 33(1) GDPR, the Data Controller is deemed to become aware of the Personal Data Breach when the Data Processor notifies it in accordance with this clause. The Data Processor shall cooperate with and assist the Data Controller in any notification the Data Controller is required to make to a supervisory authority or to Data Subjects.
Data Protection Impact Assessments - Taking into account the nature of the Processing and the information available to the Data Processor, the Data Processor shall assist the Data Controller when the Data Controller considers that a data protection impact assessment is necessary in view of the nature, scope, context and purposes of the Processing.
Exercise of Data Subjects' Rights - When the Data Controller receives a request from a Data Subject wishing to exercise his or her rights and whose Personal Data is or has been processed by the Data Processor, it shall inform the Data Processor as soon as possible, so that the Data Processor may be in a position to provide the Data Controller with the assistance required to process such request. The Data Controller will inform the Data Processor of the request in writing.
When the Data Processor receives a request from a Data Subject wishing to exercise his/her rights, he/she shall inform the Data Controller in writing. In accordance with the Regulations, the Data Controller is liable for handling such request. The Data Processor is only liable for following the additional instructions of the Data Controller on how to deal with the request.
The Data Processor shall assist the Data Controller in responding to requests from Data Subjects exercising their rights under Chapter III GDPR, and shall provide the assistance requested within five (5) business days of the Data Controller’s request, or sooner where necessary to allow the Data Controller to comply with the deadline in Article 12(3) GDPR.
Information to the Data Subjects - The Data Controller, at the time of collection of the Personal Data, must provide the Data Subjects of the Processing operations with information regarding the Personal Data Processing.
The Data Controller, or an auditor mandated by the Data Controller, shall be entitled to conduct audits, including inspections, to assess the Data Processor’s compliance with this Agreement and with Article 28 GDPR. The Data Processor shall make available to the Data Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and shall contribute to such audits.
Audits shall be carried out on reasonable prior notice, during business hours, and in a manner that does not disproportionately disrupt the Data Processor’s operations. The Data Processor shall immediately inform the Data Controller if, in its opinion, an instruction infringes the GDPR or other applicable data protection provisions.
Purpose of the processing: provision of the Services supplied by Amenitiz Solutions to the Data Controller under the services agreement between the Parties.
Sub-purposes. In the course of providing the Services, the Data Processor carries out the following processing operations on behalf of the Data Controller:
Collection, recording, organisation, structuring, storage, retrieval, consultation, use, disclosure by transmission to the recipients identified in this Appendix, restriction, erasure and destruction of Personal Data, carried out through the Amenitiz property-management platform for the sub-purposes listed above.
The term of the services agreement between the Parties, plus the period required to return and/or delete Personal Data in accordance with the Termination clause, and any longer statutory retention period applicable to specific categories of data (see Retention periods below).
The Data Controller determines the legal basis for the processing under Article 6 GDPR and, where applicable, Article 9 GDPR. This Agreement governs the processing carried out by the Data Processor on the Data Controller’s behalf and on its documented instructions.
The Personal Data processed concerns the following categories of Data Subjects:
Free-text fields in the Services, in particular guest notes and guest preferences, are populated by the Data Controller. Where the Data Controller enters information revealing a special category of Personal Data within the meaning of Article 9 GDPR — for example accessibility or mobility requirements — the Data Controller is responsible for establishing a valid condition for that processing under Article 9(2) GDPR and for informing the Data Subjects accordingly. The Data Processor applies additional technical and organisational security measures to those fields, appropriate to the nature of the data and the risk to Data Subjects.
| Category of Personal Data | Examples | Retention period |
|---|---|---|
| Identification and contact data | Name, email, telephone, postal address, nationality, date of birth where collected | Term of the services agreement, plus up to 30 days for the deletion cycle. Copies held in backups are purged in the ordinary rotating backup cycle. |
| Booking and stay data | Dates, room, rate, channel, guest notes and preferences, arrival and departure | Term of the services agreement, plus up to 30 days for the deletion cycle. |
| Data of the Data Controller’s users | Name, business email, role, access and activity logs | Term of the services agreement, plus up to 30 days for the deletion cycle. |
| Economic and financial data — invoicing | Invoices, receipts, credit notes, amounts, tax identifiers | For the period required by the accounting and tax legislation applicable to the Data Controller in its country of establishment. |
| Payment card data | Card number and security code submitted at booking or at the front desk | Not stored in the clear by the Data Processor. Card data is tokenised in the card-data vault of the Data Processor’s provider and processed by the payment service provider; the token is retained for the term of the services agreement and deleted with the guest record. |
| Technical and connection data | IP address, device and browser data, application logs | 30 days. |
| Identity document data | Document type and number, where the traveller-registration law applicable to the Data Controller requires it to be collected | For the period laid down by that national legislation. |
Personal Data processed under this Agreement is transferred to recipients established outside the European Economic Area, in particular in the United States, where sub-processors engaged by the Data Processor provide part of the Services, including hosting-adjacent services, payment processing, transactional messaging, media hosting and technical monitoring, as well as backups.
These transfers are carried out on the basis of appropriate safeguards under Chapter V GDPR, namely the standard contractual clauses adopted by the European Commission and/or the EU–US Data Privacy Framework where the recipient is certified under it. The Data Processor obtains from each recipient the information necessary to assess the risk of the transfer and to verify that the required safeguards are in place.
The detailed list of the recipients concerned, stating the function of each recipient, the country in which it processes Personal Data and the transfer instrument relied upon, is provided to the Data Controller on request at privacy@amenitiz.com.
The Data Processor engages the sub-processors identified in the List of Authorised Sub-processors, which forms part of this Agreement. The list states, for each sub-processor, its function, the country in which it processes Personal Data and, where processing takes place outside the European Economic Area, the transfer instrument relied upon. The current list is provided to the Data Controller on request at privacy@amenitiz.com. Changes to the list are notified in accordance with the Sub-processors clause.
Version 1.1 — Effective 10 September 2026. Last updated: 10 September 2026.
Material changes to this Agreement take effect thirty (30) days after they are notified to Data Controllers. Notification is given by publishing the updated Agreement on this page and, in addition, by email to the contact address held on the Data Controller’s account or by notice in the customer area. Changes to the List of Authorised Sub-processors follow the specific notice period set out in the Sub-processors clause.
1.1 — 10 September 2026 — International transfers section corrected; sub-purposes, categories of Data Subjects, retention periods, sub-processor governance, audit and breach clauses updated.
1.0 — 20 March 2026 — First published version.