Data Processing Agreement
Last updated: 2026-08-25
This agreement applies when Stayolo processes personal data on your behalf as a host — principally your guests' data. It forms part of the Terms of Service and takes effect automatically when you create an account. It is written to satisfy Article 28 of the UK and EU GDPR. No signature is required; if your organisation needs a countersigned copy, email [email protected].
1. Roles
For guest personal data, you are the controller and Stayolo is the processor. You decide why and how guest data is used; we process it only to provide the service.
For your own account and billing data we act as controller in our own right — see the Privacy Policy. That data sits outside this agreement.
2. Scope of processing
- Subject matter: providing a direct-booking website, taking bookings and payments, and communicating with guests on your behalf.
- Duration: while your account is open, plus the retention periods in the Privacy Policy.
- Nature and purpose: storage, retrieval, transmission, display and deletion of guest data to operate your booking site.
- Categories of data subject: your guests, and people who enquire without booking.
- Categories of data: name, email address, phone number, country, stay dates, party size, price and payment status, messages, reviews.
- Special categories: none requested or required. Do not enter special-category data into free-text fields.
3. Our obligations
- We process guest data only on your documented instructions — your use of the product being those instructions — unless required otherwise by law, in which case we will tell you first unless prohibited from doing so.
- Everyone we allow to access guest data is bound by confidentiality.
- We maintain the technical and organisational measures described in section 6.
- We engage sub-processors only under section 4.
- We assist you, so far as reasonably possible, in responding to data-subject requests and in meeting your obligations on security, breach notification and impact assessments (GDPR Arts. 32–36).
- On termination we delete guest data within 30 days, except where law requires retention — booking records kept for tax purposes being the usual case.
- We make available the information needed to demonstrate compliance, and allow audits under section 7.
4. Sub-processors
You give general authorisation for us to engage sub-processors. The current categories, what each receives and where, are listed at /subprocessors.
We give at least 30 days' notice before adding or replacing one, and you may object on reasonable data-protection grounds — with the alternative-or-terminate outcome set out on that page. Each sub-processor is bound by written terms no less protective than these, and we remain liable to you for their performance.
5. International transfers
Where a sub-processor is outside the EEA or UK, we rely on an adequacy decision where one exists and otherwise on the European Commission's Standard Contractual Clauses — with the UK International Data Transfer Addendum where the UK GDPR applies — plus additional safeguards such as encryption in transit and data minimisation. Copies are available from [email protected].
6. Security measures
- Encryption of all data in transit using TLS.
- Passwords stored only as salted, computationally hard hashes.
- Signed, HTTP-only session cookies; single-use, expiring links for email verification and password reset.
- Card data never touching our systems — handled entirely by a PCI-DSS certified payment provider.
- Access to production data restricted to personnel who need it to operate the service.
- Tenant isolation: every query is scoped to the owning account, so one host cannot reach another's data.
- Regular dependency updates, and rate limiting on authentication and booking endpoints.
7. Audits
On reasonable written notice, and no more than once a year unless a regulator requires otherwise, we will provide the information reasonably necessary to demonstrate compliance with this agreement. Where a documented answer is insufficient, we will cooperate with an audit by you or an independent auditor bound by confidentiality, at your cost, arranged so as not to disrupt the service or the privacy of other customers.
8. Personal data breaches
We will notify you without undue delay, and in any event within 48 hours of becoming aware, of any breach affecting guest data you control. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records involved, the likely consequences, and the measures taken. You remain responsible for notifying your supervisory authority and affected guests where required.
9. Data-subject requests
Guests exercising their rights will normally be directed to you, as controller. Where a guest contacts us directly we will not respond substantively beyond acknowledging receipt, and will forward the request to you without undue delay. The product gives you the ability to access, correct, export and delete guest records; where you need our help beyond that, email [email protected].
10. Liability and precedence
Liability under this agreement is subject to the limitations in the Terms of Service, except where those limits are not permitted by data-protection law. If this agreement conflicts with the Terms on the processing of personal data, this agreement prevails.
Questions, or need a countersigned copy for your records? Email [email protected].