SUB-PROCESSORS

Vezpa - Property Management System

List under GDPR art. 28.4 / PIPEDA third parties

Last updated: April 19, 2026

📌 Legal precedence: this document is a courtesy translation of the Italian original. In case of any discrepancy between this translation and the Italian version, the Italian version shall prevail as the legally binding reference. Italian original available here: https://vezpa.it/subprocessors/.
Purpose of this page: lists the providers (sub-processors / third parties) that Vezpa uses to deliver the service, each with location, purpose and legal basis for the transfer of data. This list is an integral part of the Data Processing Agreement.
Notice of change: any addition or replacement is communicated to the Data Controllers / Organizations (customer properties) with at least 30 days' notice by email and dashboard, allowing the right to object (GDPR art. 28.2; equivalent rights under PIPEDA and Quebec Law 25).

1. Active Sub-processors

1.1 Infrastructure and Storage

Provider Location Purpose Data processed Transfer basis
DigitalOcean LLC
101 Ave of the Americas, New York, NY 10013, USA
EU servers (Frankfurt - FRA1) + USA headquarters Server hosting, PostgreSQL database, Redis, Spaces object storage, CDN All platform data EU DPF SCCs as fallback

1.2 Payments

Provider Location Purpose Data processed Transfer basis
Stripe Payments Europe Ltd
1 Grand Canal Street Lower, Dublin, Ireland
(with Stripe Inc., San Francisco, CA, USA)
EU (IE) + USA Card payment processing, anti-fraud, guest payment links Card data (handled by Stripe, not stored by Vezpa), email, amount, reference reservation EU DPF

1.3 Communications

Provider Location Purpose Data processed Transfer basis
IONOS SE
Elgendorfer Str. 57, 56410 Montabaur, Germany
EU (DE) Transactional emails, vezpa.it email server, PEC Recipient email address, email content, metadata EU
Google LLC - Firebase Cloud Messaging
1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA
(via Google Ireland Ltd)
EU (IE) + USA Sending push notifications to mobile and desktop devices Device FCM token, technical identifiers, notification payload (only reservation metadata, no sensitive PII) EU DPF

1.4 OTA Channel Manager

Provider Location Purpose Data processed Transfer basis
STAAH Limited
Auckland, New Zealand
New Zealand Synchronization of reservations, availability and rates with approximately 60 OTA channels Reservation data (guest name, dates, room, rate, contacts) EU Adequacy (Decision 2013/65/EU)

1.5 In-app Purchase and App Distribution

Provider Location Purpose Data processed Transfer basis
Apple Distribution International Ltd
Hollyhill Industrial Estate, Hollyhill, Cork, Ireland
(with Apple Inc., Cupertino, CA, USA)
EU (IE) + USA Distribution on App Store iOS/macOS, subscription management (StoreKit) Store account ID, purchase token, subscription status EU SCC - Apple does not participate in the DPF; USA transfers are governed by SCC 2021/914
Google Ireland Ltd / Google LLC
Gordon House, Barrow Street, Dublin 4, Ireland
(with Google LLC, USA)
EU (IE) + USA Distribution on Play Store Android, subscription management (Play Billing) Store account ID, purchase token, subscription status EU DPF
Microsoft Ireland Operations Ltd / Microsoft Corp.
One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland
EU (IE) + USA Distribution on Microsoft Store Windows, subscription management Store account ID, subscription status EU DPF

1.6 Optional Integrations (only if activated by the property)

Provider Location Purpose Data processed Transfer basis
Tuya Smart (Hangzhou Tuya Information Technology Co., Ltd.)
Hangzhou, China
China Smart lock and home automation management Device identifiers, access events SCC Optional

2. Recipients as Autonomous Data Controllers

The following entities are not sub-processors but autonomous Data Controllers / Organizations that receive data for legal obligations or for their own relationship with the individual. They are listed here for transparency:

2.1 Public Authorities (legal obligation of the Controller)

Government connectors are activated only if the property is located in the corresponding jurisdiction. Connection credentials are configured by the property itself; Vezpa does not store credentials in plaintext.

2.2 OTAs and Metasearch (contractual relationship with the traveller)

OTA channels activated by the property receive reservation and inventory data. They fall into the category:

Each OTA applies its own privacy notice. Transfers to OTAs outside the EU/Canada are governed by their direct contracts with the property and/or with the traveller.

3. Legend

4. Change Log

Date Change
April 19, 2026 First publication of the public list

Contact

For questions about sub-processors or to object to a change:

[email protected]
PEC: [email protected]

Canadian Organizations may also contact the Office of the Privacy Commissioner of Canada - OPC (www.priv.gc.ca). Quebec Organizations may contact Commission d'acces a l'information (CAI, www.cai.gouv.qc.ca).


© 2022-2026 Vezpa - All rights reserved | Privacy Policy | Terms of Service | Cookie Policy | DPA | Sub-processors | Canadian Privacy Rights