1. Parties and scope
1.1. This Data Processing Agreement (the “DPA”) is concluded between Ovilo, as processor, and the Customer, as controller, and forms part of the Ovilo Terms of Service (the “Terms”). It applies automatically, without a separate signature, whenever Ovilo processes personal data on behalf of the Customer in providing the Service.
1.2. This DPA sets out the terms required by Article 28(3) of Regulation (EU) 2016/679 (“GDPR”). Where the Customer itself acts as a processor on behalf of another controller, Ovilo acts as its sub-processor, and the Customer confirms that its instructions and this DPA have been authorised by that controller.
1.3. This DPA does not apply to personal data that Ovilo processes as a controller for its own purposes, such as account, billing and website data. That processing is described in the Ovilo Privacy Policy.
2. Definitions
Terms used in this DPA and defined in the GDPR, such as “personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach”, have the meaning given in the GDPR. Capitalised terms not defined here have the meaning given in the Terms. In addition:
- “Customer Personal Data” means personal data contained in Customer Data that Ovilo processes on behalf of the Customer.
- “Sub-processor” means another processor engaged by Ovilo to carry out specific processing activities on Customer Personal Data.
- “Data Protection Law” means the GDPR, the Lithuanian Law on the Legal Protection of Personal Data and other data protection laws of the EU and its Member States that apply to the processing.
3. Details of the processing
3.1. Subject matter: provision of the Service, a cloud property management system for accommodation providers.
3.2. Nature of the processing: collection, recording, organisation, storage, retrieval, consultation, use, transmission to Third-Party Services enabled by the Customer, alignment, restriction, erasure and destruction, carried out by automated means.
3.3. Purpose: to provide the functions of the Service to the Customer, including reservation and availability management, channel synchronisation, the online booking engine, online check-in and kiosk, guest messaging, folios, payments and invoicing, guest registration with public registers, reporting and analytics, and related support, and to carry out the Customer’s other documented instructions.
3.4. Duration: for the term of the Terms and until the Customer Personal Data is deleted in accordance with section 13.
3.5. The categories of data subjects are listed in Annex 1, the types of personal data in Annex 2, and the security measures in Annex 3.
4. The Customer’s responsibilities
4.1. The Customer is responsible for the lawfulness of the processing of Customer Personal Data, including having a legal basis for it, providing the required information to data subjects, and obtaining consents where required.
4.2. The Customer must not use the Service to process special categories of personal data or data relating to criminal convictions unless this is strictly necessary and lawful, for example an accessibility need that a guest has asked the Customer to accommodate.
5. Processing on documented instructions
5.1. Ovilo processes Customer Personal Data only on documented instructions from the Customer, including with regard to transfers to third countries, unless required to do so by EU or Member State law to which Ovilo is subject. In that case, Ovilo informs the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
5.2. The Customer’s documented instructions are the Terms, this DPA, the Customer’s configuration and use of the Service, including the integrations it enables, and any further written instructions agreed between the parties.
5.3. Ovilo immediately informs the Customer if, in its opinion, an instruction infringes Data Protection Law.
5.4. Ovilo does not sell Customer Personal Data or use it for its own purposes. Ovilo may create anonymised and aggregated statistics from which no individual can be identified, as described in the Terms.
6. Confidentiality
Ovilo ensures that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that they access the data only to the extent necessary for their tasks.
7. Security of processing
7.1. Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as well as the risks for the rights and freedoms of natural persons, Ovilo implements appropriate technical and organisational measures in accordance with Article 32 GDPR. The measures are described in Annex 3.
7.2. Ovilo may update the measures as technology develops, provided that the overall level of security is not reduced.
7.3. The Customer is responsible for the security measures within its own control, including managing Users and their permissions, protecting credentials, and securing its own devices and the kiosk devices it operates.
8. Sub-processors
8.1. The Customer grants Ovilo general written authorisation to engage Sub-processors. Ovilo engages Sub-processors in the following categories:
- application hosting and database hosting;
- content delivery, file storage, document rendering and protection against automated abuse;
- email delivery;
- SMS and WhatsApp message delivery;
- application error monitoring;
- push notification delivery;
- channel connectivity providers that connect the Service with online travel agencies, where the Customer uses channel synchronisation.
8.2. The current list of Sub-processors, including their names, the processing they carry out and their location, is provided to the Customer on request at hello@ovilo.io.
8.3. Ovilo informs the Customer of any intended addition or replacement of a Sub-processor by email or in the Service at least 30 days in advance. The Customer may object on reasonable grounds relating to data protection within that period. The parties will discuss the objection in good faith. If it cannot be resolved, the Customer may terminate the affected part of the Service before the change takes effect and receive a pro rata refund of prepaid Fees for the unused period.
8.4. Ovilo imposes on each Sub-processor, by written contract, data protection obligations that provide at least the same level of protection as this DPA, in particular sufficient guarantees of appropriate technical and organisational measures. Ovilo remains fully liable to the Customer for the performance of the Sub-processors’ obligations.
8.5. Third-Party Services that the Customer chooses to connect or use, such as online travel agencies, payment providers under the Customer’s own agreements, public registers such as e.turistas (NTIS), and the Customer’s own email or messaging accounts, are not Sub-processors of Ovilo. Ovilo transmits data to them on the Customer’s instructions, and they process it under their own terms, as controllers or as the Customer’s own processors.
9. Assistance with data subject requests
9.1. Taking into account the nature of the processing, Ovilo assists the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling its obligation to respond to requests of data subjects exercising their rights under Chapter III GDPR. The Service allows the Customer to access, correct, export and delete guest data.
9.2. If Ovilo receives a request directly from a data subject concerning Customer Personal Data, it forwards the request to the Customer without undue delay and does not respond to it, other than to refer the data subject to the Customer, unless the Customer instructs otherwise.
10. Assistance with security, impact assessments and consultations
Taking into account the nature of the processing and the information available to it, Ovilo assists the Customer in ensuring compliance with its obligations under Articles 32 to 36 GDPR, including security of processing, notification of personal data breaches, data protection impact assessments and prior consultation with the supervisory authority.
11. Personal data breaches
11.1. Ovilo notifies the Customer of a personal data breach affecting Customer Personal Data without undue delay and in any event within 48 hours after becoming aware of it.
11.2. The notification includes, to the extent then available, the information set out in Article 33(3) GDPR: the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned; a contact point for more information; the likely consequences; and the measures taken or proposed to address the breach and mitigate its effects. Where the information cannot be provided at the same time, it is provided in phases without undue further delay.
11.3. Ovilo takes reasonable steps to contain and investigate the breach and to mitigate its effects. The Customer, as controller, is responsible for any notification to the supervisory authority and to data subjects. A notification by Ovilo is not an acknowledgement of fault or liability.
12. International transfers
12.1. The Service’s application and database are hosted in the European Union. Ovilo transfers Customer Personal Data to a country outside the European Economic Area, or allows a Sub-processor to access it from such a country, only in compliance with Chapter V GDPR.
12.2. Such transfers are based on an adequacy decision of the European Commission, including the EU–U.S. Data Privacy Framework for certified recipients, or on the Standard Contractual Clauses adopted by the European Commission, in particular Module 3 (processor to processor), together with supplementary measures where a transfer assessment shows they are necessary. The Customer authorises such transfers to the Sub-processors made available under section 8.2.
12.3. Transfers that the Customer itself initiates by connecting Third-Party Services are the Customer’s responsibility.
13. Deletion and return of data
13.1. During the term, the Customer can delete Customer Personal Data using the functions of the Service or ask Ovilo to do so.
13.2. After the Terms end, the Customer may, for 30 days, request an export of Customer Data in a commonly used machine-readable format. After that period, Ovilo deletes the Customer Personal Data, including copies held by Sub-processors, within 90 days, unless EU or Member State law requires its storage.
13.3. Deleted data may remain in encrypted backups until they are overwritten, within 35 days of deletion. Until then, it remains protected under this DPA and is not actively processed. On request, Ovilo confirms the deletion in writing.
14. Information and audits
14.1. Ovilo makes available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, including a description of its security measures, the list of Sub-processors and reasonable answers to security questionnaires.
14.2. Where this information is not sufficient, Ovilo allows for and contributes to audits, including inspections, conducted by the Customer or by an independent auditor mandated by the Customer who is bound by confidentiality and is not a competitor of Ovilo. The Customer gives at least 30 days’ written notice, audits are carried out during business hours without unreasonably disrupting Ovilo’s operations, do not give access to data of other customers, and take place no more than once in any 12 months, unless a supervisory authority requires it or a personal data breach has occurred.
14.3. Each party bears its own costs of an audit, and the Customer bears the costs of the auditor it engages. If the audit reveals a material breach of this DPA by Ovilo, Ovilo bears the reasonable costs of the audit and promptly remedies the breach.
15. Liability
The liability of each party under this DPA is subject to the limitations and exclusions of liability in the Terms, to the extent permitted by law. This does not limit the rights of data subjects under Article 82 GDPR.
16. Precedence, term and changes
16.1. In matters of personal data processing, this DPA prevails over the Terms. Where the parties have concluded Standard Contractual Clauses, those clauses prevail over this DPA.
16.2. This DPA remains in force as long as Ovilo processes Customer Personal Data on behalf of the Customer.
16.3. Ovilo may amend this DPA in accordance with the procedure for changes set out in the Terms. Amendments will not reduce the level of protection of Customer Personal Data, unless required by law.
Annex 1. Categories of data subjects
Depending on how the Customer uses the Service, Customer Personal Data may concern:
- guests and prospective guests of the Customer, including accompanying persons and children;
- persons who make or pay for bookings, and contact persons of companies and travel agents that book with the Customer;
- visitors of the Customer’s booking engine and online check-in pages;
- the Customer’s personnel, to the extent their data is contained in Customer Data, for example in task assignments or message history.
Annex 2. Types of personal data
Depending on how the Customer uses the Service, the following types of personal data may be processed:
- Identification and contact data: name, email address, phone number, postal address, preferred language, company and position.
- Stay and booking data: dates, rooms or pitches, number and type of guests, rates, booking source and channel reference, requests, preferences, notes, reviews, vehicle registration number, and door or access codes.
- Guest registration data required by law, such as for e.turistas (NTIS): date of birth, nationality, identity document type, number, issuing country and expiry date, place of residence, purpose of the visit.
- Payment and invoicing data: amounts, currency, payment status and method, transaction references from payment providers, folios, invoices and the billing details on them. Ovilo does not store full payment card numbers.
- Communication data: content and metadata of emails, SMS, WhatsApp and other messages sent through the Service.
- Consent and preference data: marketing, email and SMS consent flags.
- Booking engine usage data: session identifiers, referral and campaign parameters, and searches and booking steps.
Special categories of personal data are not intended to be processed; see section 4.2. Frequency of processing: continuous, for the duration of the Service.
Annex 3. Technical and organisational measures
Ovilo applies the following measures. Ovilo does not currently hold ISO 27001, SOC 2 or similar certifications.
- Encryption in transit: connections to the Service and between its components over public networks are encrypted with TLS.
- Encryption at rest: data in the database and file storage is encrypted at rest by the hosting providers.
- Hosting: the application and the database are hosted in EU regions of established cloud providers.
- Customer separation: each customer’s data is logically separated by organisation, and access is checked on every request.
- Access control in the Service: role-based permissions set by the Customer, email verification for invitations, passwords stored only as salted hashes, and session cookies marked HttpOnly and Secure.
- Least privilege: access to production systems and data is limited to authorised personnel who need it for their tasks.
- Logging and monitoring: audit records of significant actions in the Service, application error monitoring, and technical logs kept for up to 30 days.
- Abuse protection: rate limiting and bot protection on public booking endpoints.
- Backups and recovery: automated database backups, retained for up to 35 days, from which data can be restored.
- Vulnerability management: software dependencies are kept up to date, and security fixes are applied promptly.
- Incident response: suspected security incidents are investigated, contained and documented, and customers are notified in accordance with section 11.
Contact
Questions about this document can be sent to hello@ovilo.io.