DATA PROCESSING AGREEMENT (DPA)

Vezpa - Property Management System

Contract under art. 28 EU Regulation 2016/679 (GDPR) and CCPA/CPRA Service Provider Addendum

Version 1.0 - Effective April 19, 2026

📌 Legal precedence: this document is a courtesy translation of the Italian original. In case of any discrepancy between this translation and the Italian version, the Italian version shall prevail as the legally binding reference. Italian original available here: https://vezpa.it/dpa/.
Purpose of this document: this Data Processing Agreement (DPA) governs the processing of personal data of guests of hospitality properties using the Vezpa platform. The property (Data Controller / "Business" under CCPA) entrusts Vezpa (Data Processor / "Service Provider" under CCPA) with the processing of such data. The DPA is an integral part of the Terms of Service and is accepted together with the property's registration. GDPR references apply when the Data Controller processes personal data of individuals in the European Economic Area. This DPA also acts as a Service Provider contract for purposes of the California Consumer Privacy Act (CCPA) as amended by CPRA where the Data Controller is subject to it.
To whom it applies: this DPA applies whenever the property uses Vezpa to process personal data of individuals other than the property itself (typically: guests, their companions, booking contacts). It does not apply to the processing of data of the property's professional users, for which Vezpa operates as an independent Data Controller (see Privacy Policy).

1. Parties

Data Controller ("Controller" / Business under CCPA) The hospitality property that subscribes to Vezpa, as identified in its account (business name, VAT ID, office, legal representative).
Data Processor ("Processor" / Service Provider under CCPA / "Vezpa") Vezpa di Paolo Vezzola, VAT ID 04449070988, with office in via San Zeno 67, 25015 Desenzano del Garda (BS), Italy. PEC: [email protected] · Email: [email protected]

2. Subject Matter and Duration (art. 28.3 GDPR)

The Data Controller instructs the Data Processor to process personal data on its behalf through the Vezpa platform. Processing lasts for the duration of the subscription agreement between the parties and ceases upon its termination, subject to Section 14.

3. Nature, Purposes, and Types of Data Processed

3.1 Purposes

3.2 Categories of Data Subjects / Consumers (CCPA)

3.3 Types of Personal Data Processed

Sensitive data (art. 9 GDPR / "sensitive personal information" under CPRA): the identity document may contain sensitive data (e.g., place of birth). The Data Controller declares that it has an appropriate legal basis under art. 9.2 GDPR (typically subsections b, f, or g) or applicable US state law, and instructs the Data Processor to limit the processing of such data to communications required by law to public authorities and to retention within the prescribed terms.

4. Instructions from the Data Controller (art. 28.3.a GDPR / CCPA)

The Data Processor processes personal data exclusively on the basis of the Data Controller's documented instructions. General instructions are contained in this DPA, in the Privacy Policy, and in the Terms of Service. Specific instructions may be issued by the Data Controller via:

Should the Data Processor believe that an instruction violates the GDPR, CCPA, or other applicable provisions, it will immediately inform the Data Controller.

Under the CCPA/CPRA, Vezpa as Service Provider: (a) will not sell or share personal information; (b) will not retain, use, or disclose personal information outside the direct business relationship with the Data Controller; (c) will not retain, use, or disclose personal information for any purpose other than the specific purposes set forth in this DPA; and (d) will comply with applicable CCPA obligations and provide the same level of privacy protection required by the CCPA.

5. Obligations of the Data Processor (art. 28.3.b-h GDPR / CCPA)

The Data Processor commits to:

  1. Confidentiality: process data in a confidential manner and ensure that persons authorized to process are bound by confidentiality obligations;
  2. Security: adopt the technical and organizational measures in Annex B, adequate to the risk;
  3. Sub-processors: comply with the conditions of Section 6;
  4. Assistance to the Data Controller: assist the Data Controller in fulfilling its obligations, in particular:
  5. Return / deletion of data upon termination, as provided in Section 14;
  6. Information: make available to the Data Controller all information necessary to demonstrate compliance with this DPA.

6. Sub-processors (art. 28.2 and 28.4 GDPR / CCPA)

6.1 General Authorization

The Data Controller authorizes the Data Processor to appoint the sub-processors listed at vezpa.it/subprocessors and those that will subsequently be added according to the procedure described here.

6.2 Notice of Change

The Data Processor will notify the Data Controller of its intention to add or replace a sub-processor with at least 30 days notice, via email to the registered address and/or dashboard notice. Within such period, the Data Controller may object on reasoned grounds. In case of unresolved objection, either party may terminate the relevant processing contract.

6.3 Obligations toward Sub-processors

The Data Processor imposes on sub-processors in writing data protection obligations equivalent to those provided here, and is liable to the Data Controller for the sub-processors' conduct.

7. Data Breach (art. 33 GDPR / US state breach notification laws)

In the event of a personal data breach involving data processed on behalf of the Data Controller, the Data Processor will:

Notice to the Data Controller occurs via email to the registered address and PEC, if available. The Data Controller remains responsible for external notifications (Italian Data Protection Authority (Garante), state Attorneys General where applicable under US state breach laws, data subjects) under arts. 33-34 GDPR and applicable US law.

8. Data Subject / Consumer Rights (art. 28.3.e GDPR / CCPA)

If a data subject or consumer contacts the Data Processor directly to exercise rights relating to data processed on behalf of the Data Controller, the Data Processor forwards the request to the Data Controller without delay and does not respond on behalf of the Data Controller except as otherwise instructed.

The Data Processor makes available to the Data Controller, through the dashboard and API, features for:

For requests requiring manual technical intervention, the Data Processor responds within 10 business days of receipt of the Data Controller's instruction.

9. Audit (art. 28.3.h GDPR)

The Data Processor provides the Data Controller, upon request, with information and documentation demonstrating compliance with this DPA, including:

The Data Controller may conduct audits (directly or through independent third parties subject to confidentiality) with at least 30 days' notice, during business hours, without interrupting operations, and at a frequency of no more than once per year (except for data breaches). Each party bears its own costs.

10. International Data Transfers (Chapter V GDPR)

The list of sub-processors with location and legal basis for transfer is published at vezpa.it/subprocessors. For transfers not covered by an adequacy decision, the Data Processor adopts:

11. Role of the Data Controller

The Data Controller declares and warrants that it:

12. Confidentiality

Each party maintains strictly confidential all information received from the other party in the performance of this DPA, for the duration of the contract and for the 5 years following.

13. Liability

Each party's liability under art. 82 GDPR toward data subjects and under applicable US state law toward consumers remains governed by law. Between the parties, the contractual liability regime is that set out in the Terms of Service (Sections 9-10), subject to the non-derogable allocation provided by art. 82 GDPR.

14. Termination of Processing

Upon termination of the contract for any reason, the Data Processor will:

  1. Make available to the Data Controller tools to export its own data in structured format (CSV/JSON) for 30 days from termination;
  2. After 30 days, delete or anonymize the data processed on behalf of the Data Controller from production systems;
  3. Delete data from backups within the next rotation cycle (typically within 90 days);
  4. Retain data that Vezpa is required to retain by law (typically: billing data and security logs) only for the time required by applicable regulation, maintaining adequate security measures thereon.

15. Changes

The Data Processor may modify this DPA to reflect regulatory developments (e.g., new SCCs, decisions of the Italian Data Protection Authority (Garante), US state privacy law amendments) or organizational changes. Material changes are communicated to the Data Controller with at least 30 days' notice. If the Data Controller does not accept, it may terminate without penalty for the unused portion of the subscription.

16. Governing Law

This DPA is governed by Italian law. For disputes, Section 16 of the Terms of Service applies. Users located in the United States may additionally pursue small claims in their local state court as provided in the Terms of Service.

Annex A - Summary Description of Processing

Item Description
Nature of processing Collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, transmission to OTA channels and public authorities, deletion
Purposes See Section 3.1
Categories of data subjects See Section 3.2
Categories of data See Section 3.3
Duration For the entire duration of the contract. Specific retention for data categories as per Privacy Policy Section 6

Annex B - Technical and Organizational Security Measures (art. 32 GDPR)

Technical Measures

Organizational Measures

Annex C - Authorized Sub-processors

The current list is published and kept up to date at vezpa.it/subprocessors. At the time of contracting, the list includes (among others):

Contact for DPA Matters

Data Processor:
Vezpa di Paolo Vezzola
Email: [email protected]
PEC: [email protected]
Desenzano del Garda, via San Zeno 67, Italy


© 2022-2026 Vezpa - All rights reserved | Privacy Policy | Terms of Service | Cookie Policy | California Privacy Rights | DPA | Sub-processors