Data Processing Addendum
Article 28 RGPD · RIGHT HOTELS SAS · Hotelminder (mindermod.org)
1. Definitions
This Data Processing Addendum (the “DPA”) forms an integral part of the Terms of Service concluded between Hotelminder — RIGHT HOTELS SAS, SIREN 849 917 208, registered office at 7 Allée Jacques Cartier, 93160 Noisy-Le-Grand, France — and the subscribing hotel (the “Customer”). Its purpose is to set out, in accordance with Article 28 of Regulation (EU) 2016/679 (the “RGPD”), the terms on which Hotelminder, in its capacity as processor, will process on behalf of the Customer, in its capacity as controller, the personal data flowing through the subscribed modules and connecting to the Customer’s SiteMinder tenant. For the purposes of this DPA, the terms “personal data”, “processing”, “controller”, “processor”, “sub-processor”, “data subject”, “supervisory authority”, “personal data breach”, “pseudonymisation” and “special categories of personal data” carry the meanings assigned to them at Article 4 RGPD. “Applicable Data Protection Law” means the RGPD, the French Loi Informatique et Libertés n° 78-17 modifiée and any binding decision of a competent supervisory authority or court.
2. Subject-matter and duration
The subject-matter of the processing is the delivery of the subscribed modules that connect to the Customer’s SiteMinder tenant and, where the Customer has opted for it, of the ancillary guest-communication modules that read or write reservation-level personal data. The duration of the processing is coextensive with the term of the Terms of Service, subject to the post-termination return or deletion obligations set out at Section 13 below.
3. Nature and purpose of the processing
Hotelminder processes personal data solely to (i) provision and operate the subscribed modules against the Customer’s SiteMinder tenant, (ii) execute the documented instructions of the Customer entered into the dashboard or transmitted via authenticated channels, (iii) provide first-line troubleshooting when a Customer user asks for support, (iv) meet security obligations relating to the processing (Article 32 RGPD), and (v) meet legal obligations relating to the processing (Articles 33-34 RGPD, cooperation with the supervisory authority). Hotelminder does not process personal data received under this DPA for any other purpose and does not combine it with other datasets except as strictly required for the operation of a specific feature explicitly enabled by the Customer.
4. Categories of data and data subjects
The categories of data subjects concerned are: (a) authorised users of the Customer’s dashboard (owners, general managers, revenue managers, front-desk staff, third-party consultants authorised by the Customer), and (b) hotel guests whose reservations transit through the SiteMinder tenant to which the subscribed modules connect. The categories of personal data processed are: for category (a), identity data (name, business email, role) and authentication data (hashed password, TOTP secret, session id); for category (b), reservation-level data (guest name, arrival and departure date, room type, rate code, stay value), contact data captured by the Customer (guest email, guest phone number), stay-preference notes and, where the Customer has enabled a specific module, message content exchanged with the guest. No special category of data within the meaning of Article 9 RGPD is processed. No data relating to criminal convictions or offences within the meaning of Article 10 RGPD is processed.
5. Obligations of Hotelminder as processor
Hotelminder undertakes, in accordance with Article 28(3) RGPD, to:
- Process personal data only on the documented instructions of the Customer, including with regard to international transfers, unless required to do so otherwise by Union or Member State law to which Hotelminder is subject, in which case Hotelminder informs the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
- Ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Take all measures required pursuant to Article 32 RGPD, as detailed at Annex II below.
- Respect the conditions referred to at Article 28(2) and (4) RGPD for engaging sub-processors, as detailed at Section 6 below and at Annex III.
- Assist the Customer, taking into account the nature of the processing, by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer’s obligation to respond to requests for exercising the data subject’s rights under Chapter III RGPD.
- Assist the Customer in ensuring compliance with the obligations under Articles 32 to 36 RGPD, in particular data-breach notification and, where applicable, data protection impact assessments and prior consultation.
- At the choice of the Customer, delete or return all personal data at the end of the provision of services relating to processing, and delete existing copies, unless Union or Member State law requires storage of the personal data.
- Make available to the Customer all information necessary to demonstrate compliance with the obligations of Article 28 RGPD and allow for and contribute to audits, as detailed at Section 11 below.
6. Sub-processors
The Customer grants Hotelminder a general written authorisation, in accordance with Article 28(2) RGPD, to engage sub-processors, subject to (i) Hotelminder informing the Customer of any intended change concerning the addition or replacement of sub-processors with at least fifteen (15) calendar days’ prior notice via the changelog page and by email to the dashboard administrator, thereby giving the Customer the opportunity to object to such changes on documented and reasonable grounds relating to data protection, and (ii) each sub-processor being bound by written obligations that offer sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing meets the requirements of the RGPD. If the Customer’s objection is not resolved by the Parties within a reasonable additional period, the Customer may terminate the affected portion of the Service without penalty. The current list of sub-processors is set out at Annex III.
7. International transfers
Hotelminder undertakes to keep personal data within the European Economic Area whenever practicable. Where a sub-processor is located outside the EEA or where, due to redundancy configuration, personal data may transit through infrastructure located outside the EEA, the transfer takes place solely under one of the following instruments: (i) an adequacy decision of the European Commission adopted under Article 45 RGPD, including the EU-US Data Privacy Framework where a US recipient is certified under it; or (ii) the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, in the module applicable to the underlying relationship — Module Two (controller to processor) for the flow between the Customer and Hotelminder, and Module Three (processor to sub-processor) for the flow between Hotelminder and the concerned sub-processor. In every case Hotelminder documents the transfer with a Transfer Impact Assessment identifying the supplementary technical, contractual and organisational measures that ensure a level of protection essentially equivalent to that guaranteed within the EEA, in particular end-to-end encryption in transit and at rest. Where the Customer or a competent authority requests a copy of the SCCs applicable to a given transfer, Hotelminder provides it within thirty (30) days.
8. Security measures (Annex II by reference)
Hotelminder implements, in accordance with Article 32 RGPD, the technical and organisational measures detailed at Annex II. These measures are designed to ensure a level of security appropriate to the risk posed by the processing, having regard to the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing. The measures are reviewed at least annually and adjusted to reflect changes in the risk landscape, in the state of the art or in the composition of the Service.
9. Assistance with DPIA, DSAR and breach notification
Hotelminder assists the Customer with the DPIA obligation of Articles 35-36 RGPD where the Customer, on the basis of guidance from its DPO or from the CNIL, considers a DPIA necessary in relation to a Service feature. Hotelminder makes available the technical documentation required to describe the processing, the security measures already applied and the residual risk. In relation to data-subject rights requests (DSAR) that Hotelminder receives in error and that are in fact addressed to the Customer, Hotelminder forwards the request to the Customer without undue delay and does not respond directly. In relation to personal data breaches, Hotelminder notifies the Customer without undue delay, and in any event within forty-eight (48) hours of becoming aware of the breach, so that the Customer, as controller, can meet the seventy-two (72) hour notification obligation of Article 33 RGPD; the notification contains, insofar as available, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed to address the breach and to mitigate its effects. Hotelminder cooperates with the Customer to notify the affected data subjects under Article 34 RGPD where required.
10. Return or deletion
Upon the effective date of termination of the Service, the Customer may, within a window of thirty (30) days, export the personal data through the dashboard’s export tooling in a structured, commonly used and machine-readable format. At the expiry of that window, and in any event no later than sixty (60) days after termination, Hotelminder deletes the personal data from its active systems. Backups containing personal data are rotated on a ninety (90) day cycle, at the end of which they are irreversibly destroyed. Hotelminder issues, at the Customer’s written request, a certificate of deletion.
11. Audit rights
The Customer has the right, at its own cost and no more than once per calendar year, to audit Hotelminder’s compliance with this DPA. The audit may be conducted (i) on the basis of an up-to-date third-party attestation, such as an ISO 27001 certification or a SOC 2 Type II report, which Hotelminder makes available under NDA, (ii) through a written questionnaire, or (iii) by an on-site inspection conducted by the Customer or by an independent auditor mandated by the Customer, agreed at least thirty (30) days in advance, at reasonable times, without disrupting the Service and without accessing personal data of any other Customer. Any audit performed as part of a duly-mandated inspection by a competent supervisory authority is not subject to the once-per-year cap.
12. Liability
Liability under this DPA is governed by Article 82 RGPD and by the limitation of liability provisions of the Terms of Service. Each Party is liable for the damage caused by processing that infringes the RGPD or that infringes the documented instructions given under this DPA. Where Hotelminder and the Customer are involved in the same processing and are jointly liable, they may make appropriate arrangements between themselves consistent with Article 82(4) and (5) RGPD.
13. Governing law and jurisdiction
This DPA is governed exclusively by French law. Any dispute arising out of or in connection with this DPA falls within the exclusive jurisdiction of the Tribunal de Commerce de Bobigny, without prejudice to any mandatory rule of the RGPD or of the Loi Informatique et Libertés.
Annex I — Description of the processing
- Controller: the subscribing hotel identified in the order form.
- Processor: RIGHT HOTELS SAS — Hotelminder, 7 Allée Jacques Cartier, 93160 Noisy-Le-Grand, France.
- Categories of data subjects: Customer users of the dashboard; hotel guests whose reservations transit through the SiteMinder tenant.
- Categories of personal data: identity, contact, authentication, reservation-level, communication content where a communication module is subscribed.
- Special categories: none.
- Nature of the processing: hosting, storage, retrieval, transmission to and from the SiteMinder tenant, transformation for the purpose of the subscribed module.
- Purposes: delivery of the subscribed modules and ancillary support.
- Duration: life of the subscription, plus the return-or-deletion window at Section 10.
- Frequency: continuous, event-driven.
Annex II — Technical and organisational measures
- Encryption in transit — TLS 1.3 with modern cipher suites; HSTS with a two-year max-age and preload; certificate rotation automated.
- Encryption at rest — AES-256 for databases, object storage and backups; keys managed in a dedicated KMS with per-tenant scoping.
- Tenant isolation — each Customer’s data is scoped by an immutable tenant identifier enforced at query time; cross-tenant queries are denied at the ORM layer.
- Access control — role-based access control based on the principle of least privilege; mandatory multi-factor authentication (WebAuthn or TOTP) for every Hotelminder staff member with production access; quarterly access reviews with sign-off by the CTO.
- Secret management — centralised secret store with time-boxed leases; no long-lived credentials in source code.
- Change management — every production change follows peer review, automated tests, staged rollout and immediate rollback capability.
- Vulnerability management — dependency scanning at each build; monthly review of open advisories; SLA of 72 hours for critical patches.
- Penetration testing — annual test by an accredited external party; remediation tracked in a public-facing summary made available to the Customer under NDA.
- Logging and monitoring — application, security and access logs centralised in Datadog EU; retention 13 months for security events; alerting on anomalous access patterns.
- Backup and disaster recovery — encrypted daily backups on OVHcloud Roubaix, replicated to an EEA secondary; documented RTO 4 h and RPO 15 min; annual restore drill.
- Physical security — provided by OVHcloud Roubaix under ISO 27001 certification; no physical access by Hotelminder personnel.
- Personnel — background checks proportionate to role; contractual duty of confidentiality; annual security-awareness training.
- Incident response — 24/7 on-call rotation; documented runbooks; post-mortem within 15 days of resolution.
- Data minimisation — configuration surface constrained to the minimum data required for each module; default retention aligned with the tables published in the Privacy Policy.
- ISO 27001 alignment — the security programme is aligned with ISO 27001 Annex A controls; formal certification is targeted for the current calendar year.
Annex III — Approved sub-processors
| Sub-processor | Role | Location | Transfer instrument if outside EEA |
|---|---|---|---|
| OVHcloud SAS | Application hosting, database, backups | Roubaix, France | N/A |
| Cloudflare (EU entity) | Edge routing, CDN, bot management | EEA edge nodes | EU-US DPF for parent group |
| Stripe Payments Europe Ltd. | Card payments on the checkout page | Ireland; onward flow to USA | SCCs 2021/914 Module 3 |
| Postmark (ActiveCampaign LLC) | Transactional email delivery | United States | SCCs 2021/914 Module 3 |
| Datadog EU | Observability, security event logging | Frankfurt, Germany | N/A |
| Sentry EU (Functional Software Ireland Ltd.) | Error tracking | Frankfurt, Germany | N/A |
Contact
Data Protection Officer: Camille Dubois-Renard, dpo@mindermod.org. Registered office: RIGHT HOTELS SAS, 7 Allée Jacques Cartier, 93160 Noisy-Le-Grand, France. Regulator: CNIL, cnil.fr — déclaration n° 2224789. Hosting: OVHcloud Roubaix, France.