Legal

Data Processing Agreement (DPA)

pursuant to Art. 28 GDPR, between the Customer ("Controller") and stayBoardApps ("Processor")

This is a courtesy translation. The German-language version at stay-board.com/avv.html is legally binding. This agreement supplements Stay-Board's Terms and Conditions (§ 8) and automatically becomes part of the contract as soon as the Customer uses the software to process personal data of guests. A separately signed version is available on request via [email protected].

1. Subject Matter and Duration of Processing

(1) The subject matter of this agreement is the processing of personal data of the Customer's guests (hereinafter "guest data") by the Processor on behalf of the Customer in connection with the use of the "Stay-Board" software.

(2) The duration of this agreement corresponds to the term of the main contract (Terms and Conditions) between the parties. It does not end automatically upon termination, but only once guest data has been fully deleted or returned in accordance with clause 9.

2. Nature and Purpose of Processing

The Processor processes guest data exclusively for the purpose of providing the "Stay-Board" software, in particular for the booking calendar, reservation and guest management, digital guest-registration capture (Meldeschein, if the corresponding module is activated), invoicing, and the related storage, modification, transmission to users authorised by the Customer, and deletion.

3. Categories of Personal Data

The following categories of guests' personal data may be processed in the course of use:

Special categories of personal data within the meaning of Art. 9 GDPR are not intended for the core scope of guest management. The Customer undertakes not to process any special categories of personal data via the software unless separately agreed in writing.

4. Categories of Data Subjects

Guests of the Customer whose data the Customer records in the course of using the software.

5. Obligations of the Processor

(1) The Processor processes guest data exclusively on the Customer's documented instructions, including the purposes set out in this agreement and the main contract, unless it is required to carry out other processing under European Union or Member State law.

(2) Persons authorised to process guest data have been bound to confidentiality or are subject to an appropriate statutory duty of confidentiality.

(3) The Processor supports the Customer, to a reasonable extent, in fulfilling data subjects' rights (access, rectification, erasure, restriction) and with data protection impact assessments, insofar as this is possible given the nature of the processing and the information available to the Processor.

6. Technical and Organisational Measures

The Processor takes the measures referred to in Art. 32 GDPR, in particular:

7. Sub-processors

(1) The Customer grants the Processor general authorisation to engage the following sub-processors in providing the software:

(2) An agreement is in place with each sub-processor that ensures a level of data protection equivalent to this agreement.

(3) The Processor will inform the Customer of intended changes concerning the addition or replacement of further sub-processors with reasonable advance notice. The Customer may object to such a change for an important, comprehensible reason within 14 days of notification.

8. Customer's Audit Rights

The Customer has the right to satisfy itself of the Processor's compliance with the obligations set out in this agreement, in particular by obtaining information and evidence (e.g. certifications of the infrastructure provider used). On-site audits are possible upon prior notice with a reasonable lead time and with due regard to ongoing operations.

9. Reporting of Data Protection Breaches

The Processor will notify the Customer without undue delay as soon as it becomes aware of a breach of the protection of personal data affecting the Customer's guest data, and will support the Customer in fulfilling its notification and communication obligations under Art. 33, 34 GDPR.

10. Deletion and Return of Data

After termination of the main contract, guest data attributed to the Customer will be made available for export for a transition period of 30 days and then deleted, unless statutory retention obligations (e.g. the guest-registration requirement) require otherwise. This period corresponds to § 5(5) of the Terms and Conditions.

11. Final Provisions

(1) Amendments and additions to this agreement require text form.

(2) Should individual provisions of this agreement be or become invalid, the validity of the remaining provisions shall remain unaffected.

(3) The law of the Federal Republic of Germany applies.

Last updated: July 2026