Data Processing Agreement (DPA)
1. Parties and Incorporation
This Data Processing Agreement ("DPA") is entered into between GuestAI, Inc., a Delaware corporation with its registered office at 1111B S Governors Ave, #58573, Dover, DE 19904, USA ("Provider" or "Processor"), and the customer identified in the applicable MyGuest Trial & Subscription Order Form ("Customer" or "Controller").
This DPA is incorporated by reference into, and forms an integral part of, the Order Form. By signing the Order Form, Customer accepts this DPA in the version published at myguest.ai/dpa as of the date of signature. In case of conflict between this DPA and the Order Form regarding the processing of personal data, this DPA prevails.
2. Definitions
"GDPR" means Regulation (EU) 2016/679. "Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Personal Data Breach" and "Supervisory Authority" have the meanings given in the GDPR. "Services" means the AI-based guest-communication services described in the Order Form (MyGuest Chat, Voice, Hub, One).
3. Subject Matter, Roles and Instructions
Customer acts as Controller and Provider acts as Processor with respect to Personal Data processed through the Services. Provider will process Personal Data only on documented instructions from Customer, including with regard to international transfers, unless required to do otherwise by EU or Member State law; in such case Provider will inform Customer of that legal requirement before processing, unless the law prohibits this. The Order Form, this DPA and Customer's use and configuration of the Services constitute Customer's complete documented instructions.
4. Details of Processing
Subject matter Provision of AI guest-communication agents (text and voice) for Customer's hospitality operations.
Duration
The term of the Order Form, plus the deletion period in Section 12.
Nature of processing
Receiving, recording, transcribing, analysing and responding to guest communications; call routing; logging; generation of conversation summaries; monitoring dashboard.
Purpose
Answering and routing guest enquiries and calls on behalf of Customer.
Categories of data subjects
Guests and prospective guests of Customer; callers to Customer's phone lines; Customer's staff members identified in routing structures and knowledge-base content.
Categories of personal data
Name; phone number; e-mail address; content of voice calls and chat messages (including voice recordings and transcripts); reservation related details disclosed by the data subject (dates, room type, requests); technical metadata (call time, duration, channel).
Special categories
Not intended. Data subjects may spontaneously disclose special category data in free-form communication; Provider does not use such data for any purpose other than delivering the Services.
5. Customer (Controller) Obligations
Customer is responsible for: (a) the lawfulness of the Processing it instructs, including an appropriate legal basis and any required notices to guests; (b) the accuracy and lawfulness of knowledge-base content and materials it provides; (c) ensuring its instructions comply with applicable data protection law. During the Trial Period the parties will use test scenarios and avoid processing real guest Personal Data where practicable.
6. Processor Obligations
Provider will:
process Personal Data only on Customer's documented instructions (Section 3);
ensure that persons authorised to process Personal Data are bound by confidentiality obligations;
implement the technical and organisational measures described in Annex 1 (Article 32 GDPR);
respect the sub-processing conditions in Section 8;
taking into account the nature of the processing, assist Customer with appropriate technical and
organisational measures in responding to Data Subject requests (Section 10);
assist Customer in ensuring compliance with Articles 32–36 GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of processing and the information available to Provider;
delete or return Personal Data at the end of the provision of Services (Section 12);
make available the information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits (Section 13).
Provider will immediately inform Customer if, in its opinion, an instruction infringes the GDPR or other applicable data protection provisions.
7. Security
Provider implements and maintains appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as set out in Annex 1. Provider may update these measures from time to time, provided the updates do not materially reduce the overall level of protection.
8. Sub-processors
Customer grants Provider general authorisation to engage sub-processors for the provision of the Services. The categories of sub-processors engaged, together with their location and the applicable transfer mechanism, are published at myguest.ai/subprocessors and include, at the date of this version: large-language-model provider (USA — DPF/SCC); speech synthesis and recognition provider (USA — DPF/SCC); telephony infrastructure provider (USA — SCC); cloud hosting provider (EU — DPF/SCC).
Upon Customer's written request, Provider will disclose the full, current list of sub-processors by name. Such list constitutes Provider's confidential information within the meaning of the confidentiality provisions of the Order Form; Customer will use it solely to assess data protection compliance and will not disclose it to third parties, other than advisors and supervisory authorities bound by confidentiality or professional secrecy.
Provider will inform Customer of intended additions or replacements of sub-processors at least fourteen (14) days in advance (e-mail or update notice on the sub-processor page with subscription option is sufficient). Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected Services with notice, without penalty for the unexpired period. Provider imposes on each sub-processor data protection obligations equivalent to those in this DPA and remains fully liable to Customer for the performance of its sub-processors.
9. International Transfers
Provider is established in the United States. Transfers of Personal Data from the EEA to Provider and to sub processors located outside the EEA take place on the basis of: (a) an adequacy decision, including the EU–U.S.
Data Privacy Framework where the recipient is certified; or (b) the Standard Contractual Clauses adopted by the European Commission (Decision (EU) 2021/914), Module Two (controller-to-processor), which are hereby incorporated by reference and deemed executed by the parties upon signature of the Order Form, with Customer as data exporter and Provider as data importer, and with Annexes completed by the details in Section 4 and Annex 1 of this DPA.
10. Data Subject Rights
Provider will promptly notify Customer of any request received directly from a Data Subject (access, rectification, erasure, restriction, portability, objection) and will not respond to it except on Customer's documented instructions, unless legally required. Provider will provide reasonable assistance, including retrieval or deletion of specific conversation records where technically feasible.
11. Personal Data Breach
Provider will notify Customer without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting Customer's Personal Data. The notification will describe, to the extent known: the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed. Provider will cooperate with Customer and take reasonable steps to mitigate the effects of the breach. Provider's notification is not an acknowledgement of fault or liability.
12. Deletion and Return
Upon termination or expiry of the Order Form, Provider will, at Customer's choice, delete or return all Personal Data processed on Customer's behalf within fourteen (14) days, and delete existing copies, unless EU or Member State law requires further storage. Deletion from backup systems occurs in the ordinary backup rotation cycle, during which the data remains protected by this DPA and is not otherwise processed.
13. Audits
Provider will make available, on request, information reasonably necessary to demonstrate compliance with this DPA, including summaries of relevant third-party certifications or audit reports of Provider and its sub processors. Where such information is reasonably insufficient, Customer may conduct an audit (itself or through an independent auditor bound by confidentiality) no more than once per twelve (12) months, on at least thirty (30) days' notice, during business hours, without disruption to Provider's operations, and at Customer's cost. Audit rights do not extend to information concerning other customers or to Provider's proprietary models, prompts and configurations.
14. Liability; Term; Miscellaneous
The limitations of liability agreed in the Order Form apply to this DPA, except to the extent liability cannot be limited under applicable data protection law. This DPA takes effect upon signature of the Order Form and remains in force for as long as Provider processes Personal Data on Customer's behalf. This DPA is governed by the law specified in the Order Form. Provider may update this DPA for new versions of the Order Form; the version accepted by Customer remains applicable to the existing Order Form unless the parties agree otherwise. This DPA may be made available in other language versions for convenience; in case of any discrepancy, the English version prevails.
Annex 1 — Technical and Organisational Measures (Art. 32 GDPR)
Encryption of Personal Data in transit (TLS 1.2+) and at rest.
Access control: role-based access, least-privilege, unique accounts, multi-factor authentication for administrative access.
Logging and monitoring of access to production systems; interaction logging within the Services.
Environment separation (test / production); pseudonymised or synthetic data used in testing where practicable.
Sub-processor due diligence and contractual flow-down of data protection obligations.
Data retention: call recordings retained for up to 12 months and transcripts/summaries for up to 24 months, or shorter as configured by Customer, then deleted.
Backup and recovery procedures; periodic review of security measures.
• Personnel: confidentiality undertakings and data protection awareness training.
Incident response procedure covering detection, escalation, containment and notification.