Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the agreement between Visby (“Processor” or “Visby”) and the hotel or enterprise customer (“Controller” or “Customer”) for Visby for Hotels and related partner products. For the consumer Visby app, Visby typically acts as an independent controller — see the Privacy Policy.
Note: This public DPA is a working template for procurement. Customers may request a signed PDF via hello@visbytravel.com. Have counsel review before relying on it in a regulated engagement.
1. Roles
- Customer is the controller of guest and staff personal data it uploads or connects to Visby (e.g. messaging channels, PMS-related fields, team emails).
- Visby is the processor of that Customer personal data when providing the hotel product.
- Visby may engage subprocessors listed at /subprocessors.
2. Processing details
- Subject matter: hosting and processing Customer data to provide concierge, messaging, integrations, analytics dashboards, and related features.
- Duration: for the term of the Customer agreement, plus limited retention for legal/security purposes.
- Nature: storage, transmission, display, AI-assisted drafting where enabled, channel sync, and deletion on instruction.
- Types of data: may include guest contact details, message content, stay references, staff account emails/roles, and integration metadata — as configured by Customer.
- Data subjects: Customer’s guests, staff, and other individuals Customer chooses to process through the Service.
3. Processor obligations
- Process Customer personal data only on documented instructions (including this DPA).
- Ensure personnel authorized to process data are bound by confidentiality.
- Implement appropriate technical and organizational measures (see Security).
- Assist with data subject requests, DPIAs, and breach notices to the extent reasonably possible.
- Delete or return Customer personal data on termination, subject to legal holds.
- Make available information reasonably necessary to demonstrate compliance.
4. Subprocessors
Customer authorizes Visby to use the subprocessors at /subprocessors. Visby will impose data-protection obligations no less protective than this DPA. Material additions will be posted to that page; Customer may object on reasonable data-protection grounds within 15 days of notice.
5. International transfers
Where Customer personal data is transferred from the EEA/UK/Switzerland to a country without an adequacy decision, Visby relies on appropriate safeguards such as Standard Contractual Clauses (SCCs) with subprocessors, and will provide copies on request where available.
6. Security incidents
Visby will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data, and will provide information reasonably available to help Customer meet its own notification duties.
7. Audits
Upon reasonable written request (no more than once annually, absent a breach), Visby will provide security documentation and, when available, SOC 2 or equivalent reports under NDA. On-site audits require mutual agreement and protect other customers’ confidentiality.
8. Governing terms
If there is a conflict between this DPA and the commercial Terms for hotel services, this DPA controls for data-protection matters. Consumer app use remains governed by the Terms of Use and Privacy Policy.