Introduction
This Data Processing Agreement ("DPA") forms part of the agreement between Hospitia LLC ("Processor") and the customer entity that has accepted the Hospitia Terms of Service ("Controller"). It governs the processing of personal data by Hospitia on behalf of the Controller in connection with the Hospitia hotel compliance inspection platform.
This DPA applies where Hospitia processes personal data that is subject to the EU General Data Protection Regulation (EU 2016/679) ("GDPR"), the UK GDPR, the California Consumer Privacy Act ("CCPA"), or other applicable data protection laws.
Definitions
Terms used but not defined in this DPA have the meaning given to them in the Hospitia Terms of Service or in applicable data protection law. In this DPA:
- Controller means the customer entity that determines the purposes and means of personal data processing.
- Processor means Hospitia LLC, which processes personal data on behalf of the Controller.
- Personal Data means any information relating to an identified or identifiable natural person processed under this DPA.
- Processing has the meaning given under applicable data protection law.
Scope and Purpose of Processing
3.1Subject Matter
Hospitia processes personal data solely to provide the inspection platform services described in the Terms of Service — including ingesting and analysing inspection photos, generating compliance scores, and producing reports.
3.2Categories of Data
Personal data processed may include:
- Names and email addresses of hotel staff and brand inspectors.
- Photos of hotel premises that may incidentally capture individuals.
- Inspection session metadata (timestamps, device identifiers).
- Any personal data the Controller uploads as part of brand configuration or contracts.
3.3Duration
Processing continues for the term of the Controller's subscription and for such additional period as is needed to comply with legal obligations or complete orderly termination. Upon termination, Hospitia will delete or return personal data per the Controller's documented instructions or, absent such instructions, within 90 days.
Processor Obligations
Hospitia will:
- Process personal data only on documented instructions from the Controller, including those set out in this DPA and the Terms of Service.
- Ensure that persons authorised to process personal data are subject to appropriate confidentiality obligations.
- Implement the technical and organisational security measures described in Section 6.
- Notify the Controller without undue delay (and in any event within 72 hours) after becoming aware of a personal data breach that affects Controller personal data.
- Assist the Controller in responding to data subject rights requests to the extent Hospitia holds the relevant data.
- Provide all information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits conducted by the Controller or a mandated auditor.
Sub-processors
The Controller authorises Hospitia to engage sub-processors in connection with the services. Hospitia will maintain a current list of sub-processors and notify the Controller at least 14 days before engaging a new sub-processor. The Controller may reasonably object to a new sub-processor within that period.
Hospitia ensures that sub-processors are bound by data protection obligations equivalent to those in this DPA.
Security Measures
Hospitia implements and maintains the following measures:
- AES-256 encryption of personal data at rest.
- TLS 1.2 or higher for all data in transit.
- Role-based access controls limiting data access to authorised personnel.
- Regular backups with a minimum 30-day retention.
- Logical tenant isolation at the application and database layers.
- Audit logging of access to personal data.
- A documented incident response procedure.
International Transfers
If Hospitia transfers personal data originating in the European Economic Area, the United Kingdom, or Switzerland to a country not recognised as providing an adequate level of protection, such transfer will be governed by the applicable Standard Contractual Clauses (Module 2: Controller to Processor) adopted by the European Commission, or an equivalent lawful transfer mechanism.
Controller Obligations
The Controller represents and warrants that:
- It has a lawful basis for the personal data it provides to Hospitia for processing.
- It will provide any notices and obtain any consents required under applicable law before submitting personal data to the platform.
- Its instructions to Hospitia comply with applicable data protection law.
Liability
Each party's liability under this DPA is subject to the limitations and exclusions set out in the Hospitia Terms of Service, except to the extent that applicable data protection law requires a different allocation of liability between Controller and Processor.
Governing Law
This DPA is governed by the laws of the State of Florida, United States, unless a different governing law is required by applicable data protection legislation (in which case that legislation's requirements take precedence for matters covered by it).
Contact & DPA Requests
Enterprise customers requiring a countersigned DPA should contact us at privacy@hospitia.tech. We review and return executed DPAs within five business days.
