SUB-PROCESSORS

Vezpa - Property Management System

List under art. 28.4 GDPR / Service Providers under CCPA

Last updated: April 19, 2026

📌 Legal precedence: this document is a courtesy translation of the Italian original. In case of any discrepancy between this translation and the Italian version, the Italian version shall prevail as the legally binding reference. Italian original available here: https://vezpa.it/subprocessors/.
Purpose of this page: it lists the providers (sub-processors under the GDPR, Service Providers under the CCPA) that Vezpa uses to deliver the service, each with location, purpose, and legal basis for data transfer. The list is an integral part of the Data Processing Agreement. GDPR references apply when Vezpa processes personal data of individuals in the European Economic Area.
Notice of change: any additions or replacements are communicated to Data Controllers (customer properties) with at least 30 days' notice via email and dashboard, allowing exercise of the right to object (art. 28.2 GDPR).

1. Active Sub-processors

1.1 Infrastructure and Storage

Provider Location Purpose Data Processed Transfer Basis
DigitalOcean LLC
101 Ave of the Americas, New York, NY 10013, USA
EU servers (Frankfurt - FRA1) + USA headquarters Server hosting, PostgreSQL database, Redis, Spaces object storage, CDN All platform data EU DPF SCCs as fallback

1.2 Payments

Provider Location Purpose Data Processed Transfer Basis
Stripe Payments Europe Ltd
1 Grand Canal Street Lower, Dublin, Ireland
(with Stripe Inc., San Francisco, CA, USA)
EU (IE) + USA Card payment processing, anti-fraud, guest payment links Card data (handled by Stripe, not stored by Vezpa), email, amount, booking reference EU DPF

1.3 Communications

Provider Location Purpose Data Processed Transfer Basis
IONOS SE
Elgendorfer Str. 57, 56410 Montabaur, Germany
EU (DE) Transactional emails, vezpa.it email server, PEC Recipient email address, email content, metadata EU
Google LLC - Firebase Cloud Messaging
1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA
(via Google Ireland Ltd)
EU (IE) + USA Push notification delivery to mobile and desktop devices Device FCM token, technical identifiers, notification payload (booking metadata only, no sensitive PII) EU DPF

1.4 OTA Channel Manager

Provider Location Purpose Data Processed Transfer Basis
STAAH Limited
Auckland, New Zealand
New Zealand Synchronization of bookings, availability, and rates with ~60 OTA channels Booking data (guest name, dates, room, rate, contacts) EU adequacy (Decision 2013/65/EU)

1.5 In-app Purchase and App Distribution

Provider Location Purpose Data Processed Transfer Basis
Apple Distribution International Ltd
Hollyhill Industrial Estate, Hollyhill, Cork, Ireland
(with Apple Inc., Cupertino, CA, USA)
EU (IE) + USA App Store iOS/macOS distribution, subscription management (StoreKit) Store account ID, purchase tokens, subscription status EU SCC — Apple does not participate in the DPF; US transfers governed by SCC 2021/914
Google Ireland Ltd / Google LLC
Gordon House, Barrow Street, Dublin 4, Ireland
(with Google LLC, USA)
EU (IE) + USA Play Store Android distribution, subscription management (Play Billing) Store account ID, purchase tokens, subscription status EU DPF
Microsoft Ireland Operations Ltd / Microsoft Corp.
One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland
EU (IE) + USA Microsoft Store Windows distribution, subscription management Store account ID, subscription status EU DPF

1.6 Optional Integrations (Only if Activated by the Property)

Provider Location Purpose Data Processed Transfer Basis
Tuya Smart (Hangzhou Tuya Information Technology Co., Ltd.)
Hangzhou, China
China Smart locks and home automation management Device identifiers, access events SCCs Optional

2. Recipients Acting as Independent Controllers

The following parties are not sub-processors but independent Data Controllers that receive data for legal obligations or for their own relationship with the data subject. They are listed here for transparency:

2.1 Public Authorities (Data Controller's Legal Obligation)

Government connectors are activated only if the property is located in the corresponding country. The credentials for the connection are configured by the property itself; Vezpa does not retain credentials in clear text.

2.2 OTAs and Metasearch (Contractual Relationship with the Traveler)

OTA channels activated by the property receive booking and inventory data. They fall into the following categories:

Each OTA applies its own privacy notice. Transfers to non-EU OTAs are governed by their direct contracts with the property and/or with the traveler.

3. Legend

4. Change History

Date Change
April 19, 2026 First publication of the public list

Contact

For questions about sub-processors or to object to a change:

[email protected]
PEC: [email protected]


© 2022-2026 Vezpa - All rights reserved | Privacy Policy | Terms of Service | Cookie Policy | California Privacy Rights | DPA | Sub-processors