📌 Legal precedence: this document is a courtesy translation of the Italian original. In case of any discrepancy between this translation and the Italian version,
the Italian version shall prevail as the legally binding reference. Italian original available here:
https://vezpa.it/dpa/.
Purpose of this document: this Data Processing Agreement (
DPA) governs the processing of personal data of the
guests of accommodation properties using the Vezpa platform. The property (
Data Controller under GDPR /
Organization under PIPEDA) entrusts Vezpa (
Data Processor under GDPR /
service provider / third party under PIPEDA) with the processing of such data. The DPA is an integral part of the
Terms of Service and is accepted at the time the property registers.
Who this applies to: this DPA applies whenever the property uses Vezpa to process personal data of persons other than the property itself (typically: guests, their companions, reservation contacts).
It does not apply to the processing of data of the property's professional users, for which Vezpa operates as autonomous Data Controller (see the
Privacy Policy).
1. Parties
| Data Controller / Organization ("Controller") |
The accommodation property that subscribes to the Vezpa subscription, as identified in its account (business name, VAT/BN, registered office, legal representative). |
| Data Processor / Third Party ("Processor" / "Vezpa") |
Vezpa di Paolo Vezzola, VAT 04449070988, registered office at via San Zeno 67, 25015 Desenzano del Garda (BS), Italy. PEC: [email protected] · Email: [email protected] |
2. Subject Matter and Duration (GDPR art. 28.3)
The Controller instructs the Processor to process personal data on its behalf through the Vezpa platform. The processing lasts for the duration of the subscription contract between the parties and ends upon its termination, subject to the provisions of Section 14.
3. Nature, Purposes and Types of Data Processed
3.1 Purposes
- Management of reservations, stay and check-in/check-out
- Fulfilment of the Controller's legal obligations toward public authorities (AlloggiatiWeb, ISTAT, PayTourist, Feratel/Meldeamt, SES.HOSPEDAJES, NTAK, eVisitor, SEF, UbyPort, eTurizem; and, where applicable for Canadian Controllers, Canada Revenue Agency and provincial tax authorities)
- Communication of reservation data to OTA channels and to the channel manager activated by the property
- Sending communications to the guest (confirmations, pre-check-in, payments)
- Processing of payments via Booking Engine or Stripe link
- Production of reports and statistics for the Controller
3.2 Categories of Individuals (Data Subjects)
- Property guests and their companions
- Persons booking on behalf of others
- Emergency contacts possibly provided by the guest
3.3 Types of Personal Data Processed
- Identifying and personal data (first name, last name, date and place of birth, citizenship, gender)
- Identity documents (type, number, date of issue, issuing authority, scanned or photographed image)
- Textual data extracted from the document via automatic OCR
- Contact data (email, phone, address)
- Reservation and stay data
- Payment data (handled by Stripe, not stored on Vezpa)
Sensitive information (GDPR art. 9 / PIPEDA sensitive personal information): the identity document may contain sensitive information (e.g. place of birth). The Controller declares that it has an appropriate legal basis under GDPR art. 9.2 (typically lett. b, f or g) or, for Canadian Organizations, meaningful consent / legal authority under PIPEDA, and instructs the Processor to limit the processing of such data to communications required by law to public authorities and to retention within the prescribed periods.
4. Controller's Instructions (GDPR art. 28.3.a)
The Processor processes personal data solely on the basis of the Controller's documented instructions. General instructions are contained in this DPA, in the Privacy Policy, in the Canadian Privacy Rights notice and in the Terms of Service. Specific instructions may be given by the Controller via:
- Configurations in its own account (activation/deactivation of government connectors, OTAs, retention)
- Written communication to [email protected] or via PEC to [email protected]
If the Processor considers that an instruction infringes the GDPR, PIPEDA, Quebec Law 25 or other applicable law, it will immediately inform the Controller.
5. Processor's Obligations (GDPR art. 28.3.b-h)
The Processor undertakes to:
- Confidentiality: process the data confidentially and ensure that persons authorized to process are bound by a duty of confidentiality;
- Security: adopt the technical and organizational measures set out in Annex B, appropriate to the risk;
- Sub-processors: comply with the conditions in Section 6;
- Assistance to the Controller: assist the Controller in fulfilling its obligations, in particular:
- Responding to individual rights requests (GDPR arts. 15-22; PIPEDA Principle 9; Quebec Law 25) within timeframes that allow the Controller to respond within the 30-day legal deadline;
- Notifying the Controller of a data breach within 24 hours of discovery (Section 7);
- Supporting DPIA (art. 35) and prior consultations (art. 36), and Privacy Impact Assessments under Quebec Law 25;
- Demonstrating compliance through documentation and, where requested, audit (Section 9).
- Return / deletion of data at the end, as provided in Section 14;
- Information: make available to the Controller all information necessary to demonstrate compliance with this DPA.
6. Sub-processors (GDPR art. 28.2 and 28.4)
6.1 General Authorization
The Controller authorizes the Processor to appoint the sub-processors listed at vezpa.it/subprocessors and those that will subsequently be added according to the procedure described here.
6.2 Notice of Change
The Processor notifies the Controller of its intention to add or replace a sub-processor with at least 30 days' notice, by email to the registered address and/or notice in the dashboard. Within that period the Controller may object with reasons. In case of an unresolvable objection, either party may terminate the contract with cessation of the relevant processing.
6.3 Obligations on Sub-processors
The Processor imposes in writing on the sub-processors data protection obligations equivalent to those set out here, and is liable to the Controller for the sub-processors' activities.
7. Data Breach (GDPR art. 33 / PIPEDA breach of security safeguards)
In the event of a personal data breach affecting data processed on behalf of the Controller, the Processor will:
- Notify the Controller without undue delay and in any case within 24 hours of discovery;
- Provide the information in GDPR art. 33.3 (nature, categories and approximate number of individuals and records affected, likely consequences, measures adopted or proposed);
- Cooperate with the Controller in communications to individuals and to the Supervisory Authority;
- Document the incident and the actions taken.
Notice to the Controller is given by email to the registered address and PEC, where available. The Controller remains responsible for external notifications (Italian Data Protection Authority (Garante), Office of the Privacy Commissioner of Canada (OPC) under PIPEDA for real risk of significant harm, Commission d'acces a l'information (CAI) for Quebec Law 25, individuals) under GDPR arts. 33-34, PIPEDA and applicable provincial law.
8. Rights of Individuals (GDPR art. 28.3.e / PIPEDA Principle 9)
If an individual contacts the Processor directly to exercise rights regarding data processed on behalf of the Controller, the Processor forwards the request to the Controller without delay and does not respond on behalf of the Controller unless otherwise instructed.
The Processor makes available to the Controller, in the dashboard and via API, features for:
- Export of an individual's data (access and portability)
- Rectification
- Deletion or anonymization
- Restriction of processing
For requests requiring manual technical intervention, the Processor responds within 10 business days from receipt of the Controller's instruction.
9. Audit (GDPR art. 28.3.h)
The Processor provides the Controller, on request, with information and documentation demonstrating compliance with this DPA, including:
- Summary of implemented security measures
- List of sub-processors with locations and transfer bases
- Record of processing activities (relevant extracts)
- Certifications of sub-processors (ISO 27001, SOC 2, DPF) where available
The Controller may carry out audits (directly or through independent third parties bound by confidentiality) with at least 30 days' notice, during working hours, without disrupting operations and no more than once a year (save for a data breach). Each party bears its own costs.
10. Cross-border Transfers (GDPR Chapter V / PIPEDA / Quebec Law 25)
The list of sub-processors indicating the location and legal basis for the transfer is published at vezpa.it/subprocessors. For transfers not covered by an adequacy decision, the Processor adopts:
- Standard Contractual Clauses 2021/914 and supplementary measures where necessary (documented Transfer Impact Assessment);
- Or other appropriate safeguards under GDPR art. 46.
For Canadian personal information transferred outside Canada, the Processor uses contractual means (including this DPA and EU SCCs) to ensure a comparable level of protection, as required by PIPEDA and, for Quebec residents, Quebec Law 25's rules on transfers outside Quebec.
11. Role of the Controller
The Controller declares and warrants that it has:
- Provided individuals with the notice required under GDPR arts. 13-14 and/or PIPEDA Principle 8 (Openness);
- Obtained any legal bases (consent, contract, legal obligation) necessary for the processing;
- Given lawful instructions to the Processor;
- Ensured the proper retention and deletion of data after withdrawal from the Vezpa platform.
12. Confidentiality
Each party keeps strictly confidential all information received from the other party in the performance of this DPA, for the duration of the contract and for the 5 years following.
13. Liability
Each party's liability toward individuals under GDPR art. 82 or applicable Canadian law remains governed by the law. As between the parties, the contractual liability regime is that set out in the Terms of Service (Sections 9-10), subject to the mandatory allocation set out in GDPR art. 82.
14. Cessation of Processing
Upon termination of the contract for any reason, the Processor will:
- Make available to the Controller tools to export its data in a structured format (CSV/JSON) for 30 days after termination;
- After 30 days, delete or anonymize the data processed on behalf of the Controller from production systems;
- Delete the data from backups by the following rotation cycle (typically within 90 days);
- Retain data that Vezpa is required by law to keep (typically: billing data and security logs) only for the periods imposed by applicable law, maintaining appropriate security measures on them.
15. Changes
The Processor may amend this DPA to reflect regulatory developments (e.g. new SCCs, Italian Data Protection Authority (Garante) measures, OPC or CAI guidance, Quebec Law 25 amendments) or organizational changes. Material changes are communicated to the Controller with at least 30 days' notice. If the Controller does not accept, it may terminate without penalty for the unused part of the subscription.
16. Governing Law
This DPA is governed by Italian law. For disputes, Section 16 of the Terms of Service applies. For Canadian Controllers, the mandatory consumer and privacy protection rules of their province apply. Quebec residents retain the protections of Law 25.
Annex A - Summary Description of the Processing
| Item |
Description |
| Nature of the processing |
Collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, transmission to OTA channels and public authorities, deletion |
| Purposes |
See Section 3.1 |
| Categories of individuals |
See Section 3.2 |
| Categories of data |
See Section 3.3 |
| Duration |
For the entire duration of the contract. Specific retention for categories of data as per Privacy Policy Section 6 |
Annex B - Technical and Organizational Security Measures (GDPR art. 32 / PIPEDA Principle 7)
Technical measures
- Encryption in transit: HTTPS/TLS 1.2+, HSTS
- Encryption at rest: sensitive fields with django-cryptography, encrypted volumes and snapshots at infrastructure level (DigitalOcean)
- Password hashing with salted PBKDF2 (Django default)
- Authentication: rotating JWT (15-min access, 180-day refresh with blacklist), optional TOTP 2FA
- Bot blocker and rate limiting to prevent automated attacks
- Role-based access control (manager/assistant/housekeeper/observer)
- Backups managed by the infrastructure provider in the EU
- Application and access logs for anomaly detection
- App-side Secure Storage: Keychain iOS/macOS, EncryptedSharedPreferences Android, DPAPI Windows
Organizational measures
- Vezpa currently operates as a sole proprietorship without employees; any external collaborators are appointed in writing as Processors or authorized persons with confidentiality obligations
- Documented incident response procedure
- Record of processing activities (art. 30) kept up to date
- DPA with the main sub-processors
- Privacy by Design and by Default in development phases
- Separation of production / staging / development environments
Annex C - Authorized Sub-processors
The current list is published and kept up to date at vezpa.it/subprocessors. At the time of entry into the contract, the list includes (among others):
- DigitalOcean LLC - infrastructure (EU Frankfurt + USA DPF)
- Stripe - payments (EU/USA DPF)
- Google LLC - Firebase Cloud Messaging (USA DPF)
- IONOS SE - email (DE)
- STAAH Limited - OTA channel manager (NZ, adequacy)
- Apple Distribution International Ltd (IE) / Apple Inc. - in-app purchase (Apple does not participate in the DPF; USA transfers via SCC 2021/914)
- Google LLC / Microsoft Corp. - in-app purchase (USA, certified active under the DPF)
- Tuya Smart - smart locks (CN, only if activated by the property, SCC)
© 2022-2026 Vezpa - All rights reserved |
Privacy Policy |
Terms of Service |
Cookie Policy |
DPA |
Sub-processors |
Canadian Privacy Rights