Draft v0.1 — to be reviewed by a professional before publication

Personal data processing agreement — Sonnette

To be verified by a professional before any publication or signature:

  • The list of sub-processors (Scaleway, transactional email provider, Stripe) must be completed with their exact company names and countries of establishment once they are contractually chosen, and confirmed compliant with the CNIL’s standard contractual clauses.
  • The 48-hour notification deadline to the Customer (article 8) must be confirmed compatible with the 72-hour deadline the Customer itself has towards the CNIL (article 33 GDPR).
  • Confirm that no health data is collected by the Software (the free-text “remarks” field must be framed accordingly in the help) before stating, as this document does, that no health-data approved hosting (HDS) is required.
  • Have a DPO or a lawyer specializing in GDPR validate the default retention periods (article 6.4) and the audit clause (article 11), in particular their practical arrangements.
  • Verify that no current or future sub-processor transfers data outside the European Union; should that ever be the case, this article will need to be rewritten with the appropriate safeguards (standard contractual clauses, adequacy decision).

Preamble

This data processing agreement (“the Agreement”) is entered into between:

  • The Customer, the hotel identified when subscribing to Sonnette, acting as data controller within the meaning of Regulation (EU) 2016/679 of 27 April 2016 (“GDPR”), hereafter “the Controller”;
  • Sonnette, a company in formation, represented by Samuel Wieder, being registered as a SASU, hereafter “the Processor”,

and constitutes the “personal data” schedule to the Terms of sale and use (cgv-cgu.md), in accordance with article 28 of the GDPR.

1. Roles

1.1. The Customer is controller of the personal data of its own guests (travelers, bookers) that it enters or imports into the Software.

1.2. Sonnette is processor within the meaning of article 28 of the GDPR: it processes this data on behalf of the Customer and according to its documented instructions, in the course of providing the Software.

1.3. Beds24 (channel manager and booking engine) is not a sub-processor of Sonnette: it is a service provider of the Customer’s own choosing, subscribed to and configured directly by the Customer. Data sharing between Sonnette and Beds24 takes place on the Customer’s instruction and under the Customer’s responsibility.

2. Subject, duration, nature and purposes of the processing

2.1. Subject: this Agreement governs the processing of personal data carried out by Sonnette for the performance of the main contract (provision of the Software).

2.2. Duration: the Agreement applies for the entire duration of the main contract and until the completion of the data-return and erasure operations set out in article 10.

2.3. Nature of the operations: collection, recording, structuring, storage, modification, consultation, disclosure (to the Customer and, on the Customer’s instruction, to booking platforms), erasure, backup and archiving.

2.4. Purposes: managing bookings, invoicing and payments, and the hotel’s relationship with its guests (including sending emails and messaging with booking platforms), complying with the hotel’s legal obligations (invoicing, accounting, police registration forms, tourist tax), producing operating statistics on the Customer’s behalf.

3. Categories of data and of data subjects

3.1. Categories of data subjects: the hotel’s guests (travelers, bookers, persons staying at the hotel) and, incidentally, the Users of the Software employed by the Customer.

3.2. Categories of data processed:

  • identity (last name, first name, title, date of birth where required for the police registration form, nationality, ID document number and type for foreign travelers);
  • contact details (postal address, email, phone number);
  • stay data (dates, room, rate, preferences, stay history);
  • invoicing and payment data (amounts, payment method — with no full card data retained, this being handled by Stripe on the Beds24 side);
  • police registration forms for the travelers concerned, under the conditions set out by the regulations applicable to the hospitality industry.

3.3. No health data is collected by design; the free-text “remarks” field is framed within the Software’s built-in help to remind users that it must not contain such data.

4. Instructions from the Controller

4.1. Sonnette processes data only on the Customer’s documented instructions, evidenced in particular by the configuration of the Software (setting up the property, choosing retention periods where configurable, the Beds24 connection) and by this Agreement.

4.2. If Sonnette considers that an instruction from the Customer constitutes a breach of the GDPR or of any other provision of EU or Member State law relating to data protection, it will inform the Customer immediately.

5. Confidentiality

Sonnette ensures that persons authorized to process personal data under this Agreement commit to confidentiality or are subject to an appropriate statutory duty of confidentiality.

6. Security

6.1. Sonnette implements the following technical and organizational measures, appropriate to the risk:

  • encryption of data in transit (HTTPS/TLS) and at rest (database, files, archives);
  • encrypted backups, including a copy stored off the main hosting site, with regularly tested restores;
  • logging of access and sensitive operations (activity log, audit log);
  • role-based access control, with each User given credentials and permissions matching their role at the hotel (front desk, housekeeping, management, accounting);
  • strengthened authentication (two-factor authentication) for administrator and owner accounts;
  • regular security testing (internal audits, robustness testing, periodic external penetration testing) and monitoring of vulnerabilities in software dependencies.

6.2. These measures evolve with the state of the art; Sonnette may strengthen them without notifying the Customer, provided the overall level of protection is not degraded.

7. Sub-processors

7.1. The Customer gives Sonnette general authorization to use the following sub-processors, to the extent strictly necessary to provide the Software:

Sub-processor Function Data location
Scaleway hosting of the application and databases France
[transactional email provider — to be completed once chosen] sending emails to the hotel’s guests and notifications to be completed
Stripe billing of the Sonnette subscription (Stripe Billing); on the Beds24 side, processing online payments for stays, under the Customer’s own contractual responsibility towards Beds24 to be completed per Stripe’s documentation

7.2. Sonnette informs the Customer of any planned change involving the addition or replacement of sub-processors, with reasonable notice allowing the Customer to object to the change for a legitimate data-protection reason.

7.3. Sonnette ensures, through a written contract, that each sub-processor offers sufficient guarantees and is bound by data-protection obligations at least equivalent to those in this Agreement.

8. Data breach notification

8.1. Sonnette notifies the Customer of any personal data breach it becomes aware of within a maximum of forty-eight (48) hours of becoming aware of it, so as to allow the Customer to meet its own notification obligations (the 72-hour deadline to the CNIL set out in article 33 of the GDPR).

8.2. This notification describes, as far as possible: the nature of the breach, the categories and approximate number of persons and records concerned, the likely consequences, and the measures taken or proposed.

9. Assistance to the Controller

Sonnette assists the Customer, as far as possible and taking into account the nature of the processing, to: respond to requests to exercise data subjects’ rights (access, rectification, erasure, portability, objection), carry out a data protection impact assessment where necessary, and liaise with the supervisory authority if needed.

10. Fate of the data at the end of the contract

10.1. At the end of the main contract, for whatever reason, the Customer may obtain a full export of its data in an open format, under the conditions of article 10 of the Terms of sale and use.

10.2. Unless the Customer requests otherwise, Sonnette permanently erases the Customer’s data ninety (90) days after the effective date of the end of the contract, except for data that Sonnette or the Customer must retain under a legal obligation (in particular the tax archive, handed to the Customer, and accounting records subject to a ten-year retention period).

11. Audit

Sonnette makes available to the Customer the information necessary to demonstrate compliance with the obligations set out in this Agreement and in article 28 of the GDPR, and allows reasonable audits, including inspections, to be carried out by the Customer or an auditor it appoints, subject to reasonable notice and under arrangements that preserve the security and confidentiality of Sonnette’s other Customers (as the infrastructure is shared per isolated tenant, an audit covers only the requesting Customer’s own data).

12. Transfers outside the European Union

As things stand, no data processed under this Agreement is transferred outside the European Economic Area: the hosting provider (Scaleway) and the sub-processors listed in article 7 are established in, or operate from, the European Union for the data concerned. Should a transfer outside the EU ever become necessary, it would only be implemented after informing the Customer in advance and putting in place the appropriate safeguards provided for by the GDPR (in particular the European Commission’s standard contractual clauses).

13. Liability

Each party is liable for damage caused by processing carried out in breach of the GDPR obligations specifically incumbent on it. The liability and cap provisions set out in article 13 of the Terms of sale and use apply to this Agreement.


This agreement is the “personal data” schedule to the Terms of sale and use (cgv-cgu.md). See also politique-confidentialite-site.md for data processed outside the use of the Software.