Data Processing Agreement
1. Parties and definitions
This Data Processing Agreement ("DPA") is concluded between Newbookclloud Retail S.r.l. ("Processor") and the business Customer identified on the corresponding order form ("Controller"). Capitalised terms not defined here carry the meaning ascribed to them by Regulation (EU) 2016/679 ("GDPR") and D.lgs. 196/2003 as amended.
2. Subject matter and duration
The Processor processes personal data on behalf of the Controller solely to provide the add-on modules subscribed to on newbookclloud.org. Duration of processing coincides with the term of the underlying service contract, plus a 90-day grace period for data export, plus any legally required retention.
3. Nature and purposes of processing
Processing consists of reading, computing on, and — where the module requires it — writing back to the Controller's Wubook account via the Wubook API using the authorisation token obtained through Wubook Login. Purposes are strictly limited to the functionality described on the corresponding module page.
4. Categories of data subjects and data
Data subjects: hotel guests of the Controller, staff members of the Controller, corporate account contacts. Personal data: name, contact details, reservation details (dates, room, meal plan), folio charges, preferences noted by staff. No special-category data under Art. 9 GDPR is processed unless the Controller unilaterally decides to record it in Wubook.
5. Controller instructions
The Processor shall process personal data only on documented instructions from the Controller, including transfers of personal data to a third country outside the EEA, unless required to do so by Union or Member State law to which the Processor is subject. In the latter case, the Processor shall inform the Controller of that legal requirement before processing, unless prohibited by law on important grounds of public interest.
6. Technical and organisational measures (Art. 32 GDPR)
Encryption at rest (AES-256) and in transit (TLS 1.3). Access control based on the principle of least privilege, with quarterly access reviews. Multi-factor authentication mandatory for all staff. Immutable audit logging of all access to Controller data, retained 25 months. Vulnerability scans weekly. Independent penetration test annually. Personnel bound by written confidentiality obligations under Art. 28.3.b GDPR. Detailed technical measures list available on request to security@newbookclloud.org.
7. Sub-processors (Annex B)
The Processor engages the following sub-processors, which the Controller authorises through acceptance of this DPA: (a) Hetzner Online GmbH (DE) — compute in Frankfurt; (b) OVHcloud SAS (FR) — cold backups mirrored to Milan; (c) Stripe Payments Europe Ltd (IE) — payment processing; (d) Postmark Inc. — EU region (LON) — transactional email; (e) TeamSystem S.p.A. (IT) — Fatture in Cloud e-invoicing bridge. The Processor shall inform the Controller of any intended addition or replacement of a sub-processor at least 30 days in advance, giving the Controller the opportunity to object.
8. International transfers
No routine international transfers occur. Ad-hoc transfers, where they occur, take place under the European Commission Standard Contractual Clauses adopted in Decision 2021/914 with all required supplementary measures per the EDPB Recommendations 01/2020.
9. Breach notification
The Processor shall notify the Controller without undue delay, and in any event within 48 hours, of any personal data breach affecting Controller data, providing the information required by Art. 33.3 GDPR to allow the Controller to comply with its notification obligation to the Garante.
10. Data subject requests
The Processor shall assist the Controller in fulfilling its obligation to respond to data subject requests under Chapter III GDPR, providing technical and organisational support as reasonably requested.
11. Audit
The Controller may request, no more than once per calendar year, evidence of the Processor's compliance with this DPA. On-site audits are possible with 30 days notice and are conducted at the Controller's cost, save where the audit reveals material non-compliance.
12. Return or deletion of data
Upon termination of the service contract, the Controller may request within 90 days the export of all data processed. After that period, all data is deleted from active systems within 30 days and from backups within 180 days, save for data required to be retained by Union or Italian law.
13. Governing law
This DPA is governed by Italian law and forms an integral part of the underlying Terms of Service. Jurisdiction: Tribunale di Roma.