DATA PROCESSING AGREEMENT (DPA)

Vezpa - Property Management System

Agreement under GDPR art. 28 (EU Regulation 2016/679), aligned with PIPEDA and Quebec Law 25 for Canadian Organizations

Version 1.0 - In force since April 19, 2026

📌 Legal precedence: this document is a courtesy translation of the Italian original. In case of any discrepancy between this translation and the Italian version, the Italian version shall prevail as the legally binding reference. Italian original available here: https://vezpa.it/dpa/.
Purpose of this document: this Data Processing Agreement (DPA) governs the processing of personal data of the guests of accommodation properties using the Vezpa platform. The property (Data Controller under GDPR / Organization under PIPEDA) entrusts Vezpa (Data Processor under GDPR / service provider / third party under PIPEDA) with the processing of such data. The DPA is an integral part of the Terms of Service and is accepted at the time the property registers.
Who this applies to: this DPA applies whenever the property uses Vezpa to process personal data of persons other than the property itself (typically: guests, their companions, reservation contacts). It does not apply to the processing of data of the property's professional users, for which Vezpa operates as autonomous Data Controller (see the Privacy Policy).

1. Parties

Data Controller / Organization ("Controller") The accommodation property that subscribes to the Vezpa subscription, as identified in its account (business name, VAT/BN, registered office, legal representative).
Data Processor / Third Party ("Processor" / "Vezpa") Vezpa di Paolo Vezzola, VAT 04449070988, registered office at via San Zeno 67, 25015 Desenzano del Garda (BS), Italy. PEC: [email protected] · Email: [email protected]

2. Subject Matter and Duration (GDPR art. 28.3)

The Controller instructs the Processor to process personal data on its behalf through the Vezpa platform. The processing lasts for the duration of the subscription contract between the parties and ends upon its termination, subject to the provisions of Section 14.

3. Nature, Purposes and Types of Data Processed

3.1 Purposes

3.2 Categories of Individuals (Data Subjects)

3.3 Types of Personal Data Processed

Sensitive information (GDPR art. 9 / PIPEDA sensitive personal information): the identity document may contain sensitive information (e.g. place of birth). The Controller declares that it has an appropriate legal basis under GDPR art. 9.2 (typically lett. b, f or g) or, for Canadian Organizations, meaningful consent / legal authority under PIPEDA, and instructs the Processor to limit the processing of such data to communications required by law to public authorities and to retention within the prescribed periods.

4. Controller's Instructions (GDPR art. 28.3.a)

The Processor processes personal data solely on the basis of the Controller's documented instructions. General instructions are contained in this DPA, in the Privacy Policy, in the Canadian Privacy Rights notice and in the Terms of Service. Specific instructions may be given by the Controller via:

If the Processor considers that an instruction infringes the GDPR, PIPEDA, Quebec Law 25 or other applicable law, it will immediately inform the Controller.

5. Processor's Obligations (GDPR art. 28.3.b-h)

The Processor undertakes to:

  1. Confidentiality: process the data confidentially and ensure that persons authorized to process are bound by a duty of confidentiality;
  2. Security: adopt the technical and organizational measures set out in Annex B, appropriate to the risk;
  3. Sub-processors: comply with the conditions in Section 6;
  4. Assistance to the Controller: assist the Controller in fulfilling its obligations, in particular:
  5. Return / deletion of data at the end, as provided in Section 14;
  6. Information: make available to the Controller all information necessary to demonstrate compliance with this DPA.

6. Sub-processors (GDPR art. 28.2 and 28.4)

6.1 General Authorization

The Controller authorizes the Processor to appoint the sub-processors listed at vezpa.it/subprocessors and those that will subsequently be added according to the procedure described here.

6.2 Notice of Change

The Processor notifies the Controller of its intention to add or replace a sub-processor with at least 30 days' notice, by email to the registered address and/or notice in the dashboard. Within that period the Controller may object with reasons. In case of an unresolvable objection, either party may terminate the contract with cessation of the relevant processing.

6.3 Obligations on Sub-processors

The Processor imposes in writing on the sub-processors data protection obligations equivalent to those set out here, and is liable to the Controller for the sub-processors' activities.

7. Data Breach (GDPR art. 33 / PIPEDA breach of security safeguards)

In the event of a personal data breach affecting data processed on behalf of the Controller, the Processor will:

Notice to the Controller is given by email to the registered address and PEC, where available. The Controller remains responsible for external notifications (Italian Data Protection Authority (Garante), Office of the Privacy Commissioner of Canada (OPC) under PIPEDA for real risk of significant harm, Commission d'acces a l'information (CAI) for Quebec Law 25, individuals) under GDPR arts. 33-34, PIPEDA and applicable provincial law.

8. Rights of Individuals (GDPR art. 28.3.e / PIPEDA Principle 9)

If an individual contacts the Processor directly to exercise rights regarding data processed on behalf of the Controller, the Processor forwards the request to the Controller without delay and does not respond on behalf of the Controller unless otherwise instructed.

The Processor makes available to the Controller, in the dashboard and via API, features for:

For requests requiring manual technical intervention, the Processor responds within 10 business days from receipt of the Controller's instruction.

9. Audit (GDPR art. 28.3.h)

The Processor provides the Controller, on request, with information and documentation demonstrating compliance with this DPA, including:

The Controller may carry out audits (directly or through independent third parties bound by confidentiality) with at least 30 days' notice, during working hours, without disrupting operations and no more than once a year (save for a data breach). Each party bears its own costs.

10. Cross-border Transfers (GDPR Chapter V / PIPEDA / Quebec Law 25)

The list of sub-processors indicating the location and legal basis for the transfer is published at vezpa.it/subprocessors. For transfers not covered by an adequacy decision, the Processor adopts:

For Canadian personal information transferred outside Canada, the Processor uses contractual means (including this DPA and EU SCCs) to ensure a comparable level of protection, as required by PIPEDA and, for Quebec residents, Quebec Law 25's rules on transfers outside Quebec.

11. Role of the Controller

The Controller declares and warrants that it has:

12. Confidentiality

Each party keeps strictly confidential all information received from the other party in the performance of this DPA, for the duration of the contract and for the 5 years following.

13. Liability

Each party's liability toward individuals under GDPR art. 82 or applicable Canadian law remains governed by the law. As between the parties, the contractual liability regime is that set out in the Terms of Service (Sections 9-10), subject to the mandatory allocation set out in GDPR art. 82.

14. Cessation of Processing

Upon termination of the contract for any reason, the Processor will:

  1. Make available to the Controller tools to export its data in a structured format (CSV/JSON) for 30 days after termination;
  2. After 30 days, delete or anonymize the data processed on behalf of the Controller from production systems;
  3. Delete the data from backups by the following rotation cycle (typically within 90 days);
  4. Retain data that Vezpa is required by law to keep (typically: billing data and security logs) only for the periods imposed by applicable law, maintaining appropriate security measures on them.

15. Changes

The Processor may amend this DPA to reflect regulatory developments (e.g. new SCCs, Italian Data Protection Authority (Garante) measures, OPC or CAI guidance, Quebec Law 25 amendments) or organizational changes. Material changes are communicated to the Controller with at least 30 days' notice. If the Controller does not accept, it may terminate without penalty for the unused part of the subscription.

16. Governing Law

This DPA is governed by Italian law. For disputes, Section 16 of the Terms of Service applies. For Canadian Controllers, the mandatory consumer and privacy protection rules of their province apply. Quebec residents retain the protections of Law 25.

Annex A - Summary Description of the Processing

Item Description
Nature of the processing Collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, transmission to OTA channels and public authorities, deletion
Purposes See Section 3.1
Categories of individuals See Section 3.2
Categories of data See Section 3.3
Duration For the entire duration of the contract. Specific retention for categories of data as per Privacy Policy Section 6

Annex B - Technical and Organizational Security Measures (GDPR art. 32 / PIPEDA Principle 7)

Technical measures

Organizational measures

Annex C - Authorized Sub-processors

The current list is published and kept up to date at vezpa.it/subprocessors. At the time of entry into the contract, the list includes (among others):

Contact for DPA matters

Data Processor:
Vezpa di Paolo Vezzola
Email: [email protected]
PEC: [email protected]
Desenzano del Garda, via San Zeno 67, Italy

Canadian Controllers may also contact the Office of the Privacy Commissioner of Canada - OPC (www.priv.gc.ca). Quebec Controllers may contact Commission d'acces a l'information (CAI, www.cai.gouv.qc.ca).


© 2022-2026 Vezpa - All rights reserved | Privacy Policy | Terms of Service | Cookie Policy | DPA | Sub-processors | Canadian Privacy Rights