Data Processing Agreement (DPA)
Effective from: 10 August 2026. This Data Processing Agreement («DPA») is entered into pursuant to Article 28 of Regulation (EU) 2016/679 («GDPR») and the BDSG (Bundesdatenschutzgesetz) (BDSG). It forms an integral part of the Terms and Conditions and applies automatically to every Customer whose use of a Sitehotelminder Module involves the processing of personal data on the Customer’s behalf.
Independence and non-affiliation
Sitehotelminder is an independent third-party marketplace and is not affiliated with, sponsored by or endorsed by SiteMinder Limited or its parent company. Nothing in this DPA creates any obligation on SiteMinder Limited or brings SiteMinder Limited within the scope of this DPA.
1. Parties
The Controller («Controller») is the Customer hotel that has purchased one or more Modules on sitehotelminder.org and that determines the purposes and means of processing of personal data of its guests, prospects and staff.
The Processor («Processor» or «Sitehotelminder») is Sitehotelminder GmbH, a limited liability company organised under the laws of Germany, Handelsregister HRB 234567, registered under USt-IdNr. DE347591268, with its registered seat at Musterstraße 42, 10115 Berlin, Deutschland, represented by its Director Thomas Bergmann.
The Controller and the Processor are together referred to as the «Parties». By accepting the Terms and Conditions at Order and by activating any Module that processes personal data, the Controller enters into this DPA in accordance with Article 28(9) GDPR (agreement in electronic form).
2. Definitions
Capitalised terms not defined here have the meaning given to them in Article 4 GDPR. In particular:
- Personal data: any information relating to an identified or identifiable natural person.
- Processing: any operation performed on personal data.
- Sub-processor: a third party engaged by the Processor to process personal data on behalf of the Controller.
- Data subject: the individual to whom the personal data relate.
- Supervisory authority: the competent public authority for personal data protection, in Germany Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI), BlnBDI-BE-2024-08-15.
3. Subject matter and duration
The subject matter of this DPA is the processing by Sitehotelminder, on behalf of the Controller, of personal data of the Controller’s guests, prospects and staff, strictly for the purpose of operating the Modules subscribed to on sitehotelminder.org. This DPA takes effect on the day the first Module involving personal data is activated and remains in force for the duration of any active Subscription, plus the retention periods listed in section 7(g).
4. Nature and purpose of the processing
Processing performed by Sitehotelminder on behalf of the Controller consists of reading, writing, synchronising, aggregating, archiving and deleting personal data through the official SiteMinder API in order to (i) operate the subscribed Modules; (ii) store and use the Controller’s SiteMinder API key to authenticate calls; (iii) synchronise reservations, guest records and rate plans; (iv) generate operational and analytical reports; (v) support the guest journey, including the digital registration card and pre-arrival communications; and (vi) provide technical support on request. Sitehotelminder does not process the personal data for its own purposes.
5. Types of personal data
| Data category | Examples |
|---|---|
| Guest identification | First name, last name, salutation, nationality, date of birth (where required by local police-registration law) |
| Guest contact | Email address, mobile telephone number, postal address of residence |
| Reservation | Booking reference, arrival and departure dates, room number, rate plan, price, number of guests, special requests |
| Identification document | Type, number and expiry date of the ID document uploaded to the digital registration card Module (where enabled and authorised by local law) |
| Hotel staff | Business email, first and last name, role, sign-in log for the Client Area |
| Communications | Content of automated pre-arrival messages sent through the Module, delivery status |
No special category of data within the meaning of Article 9 GDPR is processed unless the Controller has expressly enabled a specific Module that requires it (for example, dietary preferences in an F&B Module), in which case the Controller warrants that a valid Article 9(2) legal basis exists.
6. Categories of data subjects
- Guests of the Controller’s hotel (past, current and confirmed future).
- Prospects who have initiated a reservation but not completed it.
- Staff members of the Controller with access to the Client Area.
- Corporate contacts of the Controller (for group bookings and long-stay accounts).
7. Processor obligations under Article 28(3) GDPR
(a) Documented instructions
Sitehotelminder processes personal data only on documented instructions from the Controller. Acceptance of the Terms, Order of a Module and configuration in the Client Area jointly constitute the initial documented instructions. Additional instructions are given in writing by email. Where an instruction infringes GDPR or German law, Sitehotelminder informs the Controller without undue delay.
(b) Confidentiality
Sitehotelminder ensures that every person authorised to process personal data has committed to confidentiality in writing or is under an appropriate statutory obligation of confidentiality. Access to production data is restricted to a named list of engineers, protected by multi-factor authentication.
(c) Security measures (Article 32 GDPR)
Sitehotelminder implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption in transit with TLS 1.3; older TLS versions refused.
- Encryption at rest with AES-256 for personal data and for stored SiteMinder API keys.
- Passwordless authentication (magic link) for the Client Area; no password reuse risk.
- Role-based access control with least-privilege by default.
- Immutable access logs retained for twelve (12) months.
- Weekly vulnerability scans and a defined patching SLA.
- Documented incident-response plan tested at least annually.
- Encrypted backups stored in a separate EU region, tested for recoverability.
- Segregation of environments (production, staging, development) with no personal data in non-production environments.
(d) Sub-processors
The Controller grants the Processor general authorisation to engage sub-processors, subject to the notification and objection rights described below. The current list of sub-processors is:
| Sub-processor | Role | Location |
|---|---|---|
| Zenthoryx | Payment service provider (EUR-NX rail) | European Union |
| European cloud hosting provider | Production hosting of application and database | European Union |
| Transactional email provider | Delivery of magic-link, invoice and service emails | European Union |
Sitehotelminder notifies the Controller of any intended change to the list of sub-processors, giving details of the new sub-processor and its role, at least thirty (30) days before the change takes effect. The Controller has the right to object to the change on reasonable grounds within that period; if the objection cannot be resolved by the Parties, the Controller may terminate the affected Subscription without penalty. Sitehotelminder imposes on every sub-processor, by written contract, obligations that are at least as protective as those set out in this DPA.
(e) Assistance with data subject rights
Taking into account the nature of the processing, Sitehotelminder assists the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller’s obligation to respond to requests for exercising the data subject’s rights under Articles 15 to 22 GDPR. Standard export and deletion features are available from the Client Area at no charge.
(f) Assistance with breach notification and DPIA
Sitehotelminder assists the Controller in ensuring compliance with the obligations under Articles 32 to 36 GDPR. In the event of a personal data breach affecting personal data processed on the Controller’s behalf, Sitehotelminder escalates internally within 24 hours and notifies the Controller in writing without undue delay and in any event no later than 36 hours after becoming aware of the breach, so that the Controller can meet its own 72-hour deadline under Article 33 GDPR. The notification includes, so far as available at the time, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed to address the breach and mitigate its adverse effects.
(g) Deletion or return of data on termination
At the choice of the Controller, expressed in writing at the latest thirty (30) days after termination of the Subscription, Sitehotelminder either deletes or returns to the Controller all personal data processed on its behalf, and deletes any existing copies, unless retention is required by German or EU law (in particular for invoices, retained for ten years under German tax law). Deletion is performed within ninety (90) days of the termination and confirmed in writing on request. SiteMinder API keys are irreversibly deleted within thirty (30) days of termination.
(h) Audit rights
Sitehotelminder makes available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. Audits may be performed once per calendar year, on thirty (30) days’ written notice, at the Controller’s expense, during business hours and in a manner that does not disrupt Sitehotelminder’s operations or the confidentiality of other customers’ data. As an alternative to on-site audit, the Controller accepts the current independent audit report (ISO 27001, SOC 2 Type II or equivalent) issued to Sitehotelminder.
8. International transfers
All personal data processed under this DPA is stored and processed within the European Economic Area. Sitehotelminder performs no international transfer to a third country within the meaning of Chapter V GDPR. Should this ever change, Sitehotelminder will put in place, before any transfer, a lawful transfer mechanism (standard contractual clauses adopted by the European Commission, adequacy decision or binding corporate rules) and will notify the Controller in advance.
9. Liability
Each Party is liable for damage caused by processing in breach of GDPR to the extent provided by Article 82 GDPR. As between the Parties, Sitehotelminder’s aggregate liability under this DPA is subject to the liability cap stated in the Terms and Conditions, save for liability that cannot lawfully be limited, including for wilful misconduct or gross negligence.
10. Term and termination
This DPA is effective for the term of the underlying Subscription and any related retention period. Termination of the Subscription terminates the operational obligations of this DPA, save for those obligations that by their nature survive termination, including confidentiality, security of retained data, and cooperation with supervisory authorities.
11. Governing law and jurisdiction
This DPA is governed by the laws of Germany, in particular the BDSG and, within its territorial scope, Regulation (EU) 2016/679. Any dispute arising out of or in connection with this DPA falls within the exclusive jurisdiction of the Amtsgericht Berlin-Mitte (Basic Court of Berlin), without prejudice to the mandatory competence of the supervisory authority in matters within its remit.
12. Signatures — acceptance by use of the service
In accordance with Article 28(9) GDPR, this DPA is validly concluded in electronic form. Acceptance is manifested by acceptance of the Terms and Conditions and by activation of any Module that processes personal data. A copy of this DPA in force on the date of activation is available at any time in the Client Area under «Legal documents». A signed PDF copy is issued on written request to dpo@sitehotelminder.org.
13. Contact
Sitehotelminder GmbH
Musterstraße 42, 10115 Berlin, Deutschland
Director: Thomas Bergmann
Data Protection Officer: dpo@sitehotelminder.org
Telephone: +49 30 4278 5934
Email: privacy@sitehotelminder.org · support@sitehotelminder.org
HRB 234567 —
IBAN: DE89 3704 0044 0532 0130 00
Supervisory authority: Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI), Friedrichstraße 219, 10969 Berlin, BlnBDI-BE-2024-08-15.
Effective from 3 August 2026. Next scheduled review: 3 February 2027.