Data Processing Agreement
1 Introduction
1.1 The Customer and Zaplar have entered into the Agreement. This data processing agreement (the “DPA”) constitutes an appendix to the Agreement.
1.2 While delivering services under the Agreement, Zaplar will process personal data and other information on behalf of the Customer.
1.3 For this reason, the parties confirm that this DPA sets out and regulates the conditions for Zaplar’s processing of, and provision of, personal data on behalf of the Customer.
2 Definitions
Unless the context or circumstances clearly indicate otherwise, definitions or terms used in this document shall have the meaning set forth below and any such definition or term which is used in the General Data Protection Regulation and which is not defined below shall be understood as having the meaning ascribed to it in the General Data Protection Regulation.
“Customer” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data, where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
“Controller” means the customer within the meaning of the General Data Protection Regulation.
“Installation” means the installation of the Customer of Zaplar within the scope of this DPA, as further specified in the Schedule.
“Other Beneficiary” means natural persons, legal entities from time to time to processing of personal data regarding the Customer’s Data Processing Agreement.
“Processor” means a natural or legal person, public authority, agency or another body which processes personal data on behalf of the Controller.
3 Documents
3.1 This DPA consists of this document and the attached instruction. In the event of any contradiction between the documents and the instructions, this document shall prevail, unless otherwise specified or unless another document expressly states otherwise.
3.2 Irrespective of what the Parties have otherwise agreed regarding conflicts, the provisions of this DPA shall always constitute an integral part of the Agreement and be understood as an integral part and shall relate to processing of personal data.
4 Generally regarding the processing
4.1 The Customer is the Controller of the personal data processed in connection with performance and provision of services under the Agreement and its appendices.
4.2 Zaplar is to be considered as Processor on behalf of the Customer. As a Processor, Zaplar is responsible for carrying out all processing of personal data on behalf of the Customer in accordance with this DPA, the Instruction, and the General Data Protection Regulation.
4.3 Zaplar has provided sufficient warranties regarding implementation of appropriate technical and organisational measures in such manner that the processing of personal data fulfils the requirements of the General Data Protection Regulation and Other Regulatory Regime, and to ensure that the rights of the data subjects are protected. The Customer represents and warrants that it has obtained and maintains all consents, authorisations, and other lawful grounds required to permit Zaplar to process personal data in accordance with this DPA and the Instruction, and that it has fulfilled its obligations to inform the relevant data subjects accordingly.
4.4 Taking into account the nature of the processing, Zaplar shall, through appropriate technical and organisational measures, assist the Customer, to the extent possible, so that the Customer can fulfil its obligation to respond to requests regarding exercise of the rights of the data subjects in accordance with Chapter III of the General Data Protection Regulation.
4.5 If Zaplar considers that an Instruction or other instruction or communication from the Customer infringes the General Data Protection Regulation or Other Regulatory Regime, Zaplar shall promptly notify the Customer, and Zaplar may suspend performance of the relevant processing until the Customer confirms or amends the instruction in writing, without liability to Zaplar for any resulting delay.
5 Purpose and type of personal data, etc.
The Instruction shall, inter alia, state the subject of the processing, the duration, nature and purpose of the processing, the type of personal data, and the categories of data subjects.
6 Validity of the Data Processing Agreement
This DPA shall apply as from execution of the Agreement and shall remain in force for as long as Zaplar or any subprocessor retained by Zaplar processes personal data on behalf of the Customer within the scope of the undertakings arising from this DPA, the Agreement, and appendices.
7 Zaplar’s personnel, etc.
7.1 Zaplar, its employees, and other persons carrying out work under Zaplar’s supervision, and who are given access to personal data by the Customer, may only process such personal data as instructed by the Customer, unless otherwise follows from an obligation under EU or applicable national law.
7.2 Zaplar shall ensure that its employees and all other persons for whom Zaplar is responsible and who are authorised to process personal data covered by this DPA undertake to observe confidentiality (unless such person is subject to a relevant and appropriate statutory duty of confidentiality).
8 Security
8.1 Zaplar shall take all necessary security measures required in accordance with Article 32 of the General Data Protection Regulation and this DPA.
8.2 In assessing the appropriate level of security in accordance with the clause above, particular account shall be taken of the risks that are presented by the processing, in particular from accidental or unlawful destruction, loss or alteration, or from unauthorised disclosure of, or access to, the personal data transmitted, stored, or otherwise processed.
8.3 Taking into account the type of the processing and the information in possession of Zaplar, Zaplar shall assist the Customer in ensuring that the latter’s obligations regarding security can be fulfilled in the manner which follows from Article 32 of the General Data Protection Regulation.
9 Personal data breach
9.1 Taking into account the type of processing and the information reasonably available to Zaplar, Zaplar shall provide the Customer with reasonable assistance to enable the Customer to fulfil its obligations under Articles 33–34 of the General Data Protection Regulation. Zaplar shall be entitled to compensation on a time and material basis for providing such assistance.
9.2 Zaplar shall notify the Customer without undue delay, and in any event within seventy-two (72) hours, after Zaplar becomes aware of and has confirmed a personal data breach affecting personal data processed under this DPA.
10 Impact assessment and prior consultation
Zaplar shall, taking into account the nature of the processing and the information available to Zaplar, and to the extent reasonably practicable and proportionate to the information available to Zaplar, assist the Customer in fulfilling its obligations, if any, regarding the performance of a data protection impact assessment and/or prior consultation with a supervisory authority in accordance with Articles 35 and 36 of the General Data Protection Regulation. Zaplar shall be entitled to compensation on a time and material basis for providing such assistance.
11 Instruction
11.1 Zaplar shall process personal data covered by this DPA only on the Customer’s documented instructions, which shall include: (i) the Instruction set out in Sub-Appendix 1; (ii) any other written instruction issued by the Customer from time to time; and (iii) processing that is reasonably necessary to perform the Agreement, even if not separately documented. Zaplar may also process personal data where required to do so by EU law or the national law of a Member State to which Zaplar is subject, or to the extent reasonably necessary for Zaplar’s own legal, regulatory, security, or compliance purposes, or to establish, exercise, or defend legal claims, in each case consistent with applicable data protection law. If Zaplar considers that an instruction infringes applicable data protection law, it shall promptly inform the Customer.
11.2 The Instruction may be updated from time to time by written agreement between the Parties. Zaplar shall not be obliged to comply with an updated Instruction to the extent it would require material changes to Zaplar’s systems, services, or security measures, unless the Parties agree on appropriate adjustments to timeline, scope, and fees.
12 Subprocessors
12.1 The Customer provides Zaplar with a general written authorisation to engage subprocessors to carry out processing of personal data under this DPA, subject to the notification and objection mechanism in clause 12.2.
12.2 Zaplar shall give the Customer at least thirty (30) days’ prior written notice of any intended appointment of a new subprocessor or replacement of an existing subprocessor, identifying the subprocessor and the processing activities concerned. The Customer may object to such appointment or replacement on reasonable, documented data protection grounds by notifying Zaplar in writing within fifteen (15) days of receipt of such notice. If the Customer does not object within such period, the new subprocessor shall be deemed approved.
12.3 Zaplar shall ensure that each subprocessor is bound by a written agreement before that subprocessor begins processing personal data in connection with the Agreement. That agreement shall impose data protection obligations on the subprocessor that are no less protective of personal data than those set out in this DPA, to the extent relevant to the processing carried out by that subprocessor.
12.4 The data processing agreement between Zaplar and any subprocessor shall specifically provide that the subprocessor may only engage a further subprocessor in accordance with the same general authorisation and notice/objection mechanism set out in clauses 12.1 and 12.2 of this DPA.
12.5 Zaplar shall, from time to time, maintain an updated list of the subprocessors that are retained and have been retained, and the country in which these subprocessors conduct their operations. At the request of the Customer, Zaplar shall provide the Customer with a copy of the list.
12.6 Zaplar shall exercise reasonable care in the selection and oversight of any subprocessor and shall remain responsible for ensuring that its subprocessors are contractually bound as required by the Agreement. Neither Party shall be liable to the other for indirect or consequential loss arising out of or in connection with this DPA.
12.7 A Party’s right to seek redress from the other Party under Article 82(5) of the General Data Protection Regulation shall not be restricted by clause 17.1 or by the amount specified in the Agreement’s limitation of liability.
13 Termination of the Data Processing Agreement
13.1 Upon termination of this DPA, the Customer shall, within fifteen (15) days, provide Zaplar with written instructions indicating whether it wishes for the personal data to be returned to the Customer or deleted. Any costs reasonably incurred by Zaplar in connection with the return of personal data to the Customer, including costs of extraction, formatting, and secure transmission, shall be borne by the Customer. Should the Customer fail to provide such instructions, Zaplar shall have the right to delete the personal data processed under this DPA, unless otherwise required by national legislation or EU law.
13.2 After termination of this DPA, Zaplar may not keep any personal data received under this DPA, and as soon as Zaplar has complied with the clause above, Zaplar’s right to process or otherwise use the personal data ceases, unless storage of the personal data is required by national legislation or EU law or Zaplar has a legal basis to process relevant personal data. The Customer is solely responsible for exporting and retaining any personal data it requires for its own purposes prior to any deletion in accordance with this clause.
14 Amendments
Zaplar shall be entitled to amend or supplement this DPA, in whole or in part, provided that such amendment does not materially adversely affect the Customer. Zaplar shall inform the Customer in writing of any such amendment, and the Customer may object to the amendment by notifying Zaplar in writing within thirty (30) days of receipt of such notice. If the Customer does not object within such period, the amendment shall be deemed accepted. Any other amendments or supplements to this DPA shall only be applicable if made in writing and signed by authorised representatives of the Parties.
Helping exceptional hoteliers do their best work.
We believe great hospitality is about being present with the guest, not spending time infront of a screen.
