Data Processing Agreement

DPA version: 2026-08-07

This Data Processing Agreement (“DPA”) forms part of the agreement under which a hotel, property manager, or accommodation provider (“Customer”) uses the Snapstay services (“Agreement”). It applies when Customer-controlled personal data is processed by:

Processor: Snapstay OÜ, registry code 17386920, Harju maakond, Tallinn, Kesklinna linnaosa, Ahtri tn 12, 15551, Estonia (“Snapstay”).

Customer is the controller (or a processor authorized to appoint Snapstay), and Snapstay is the processor. If Customer accepts an order form or Terms that incorporate this DPA, this DPA is executed with the Agreement. If a separate signature is required, contact [email protected].

1. Definitions and priority

“Data Protection Law” means the GDPR and applicable EEA member-state data-protection law. “Customer Data,” “controller,” “processor,” “data subject,” “personal data,” “personal data breach,” “processing,” and “supervisory authority” have their GDPR meanings.

If this DPA conflicts with the Agreement on processing Customer Data, this DPA controls. The Standard Contractual Clauses (“SCCs”), where used, control over conflicting commercial terms.

2. Scope and instructions

Snapstay will process Customer Data only:

  1. to provide, secure, support, and improve the contracted services as described in Annex 1;
  2. on Customer’s documented instructions in the Agreement, configuration, support request, or other written direction; and
  3. as EU or member-state law requires, after informing Customer unless law prohibits that notice.

Snapstay will immediately inform Customer if, in its opinion, an instruction infringes Data Protection Law and may suspend the affected processing while the parties resolve it. Customer is responsible for lawful instructions, notices, lawful bases, data accuracy, and not supplying unnecessary personal or special-category data.

3. Confidentiality and security

Snapstay ensures that people authorized to process Customer Data are bound by confidentiality and access it only as needed for their duties. Snapstay maintains measures appropriate to risk, including the measures in Annex 2, and may update them without materially reducing overall protection.

4. Subprocessors

Customer gives general written authorization for the subprocessors in Annex 3. Snapstay remains responsible for each subprocessor’s data-protection obligations to the extent required by Article 28(4).

Snapstay will give Customer at least 30 days’ notice before a new subprocessor begins processing Customer Data, normally through the account or Customer’s recorded email. Customer may object during that period on reasonable data-protection grounds. The parties will work in good faith on a reasonable alternative; if none is available, either party may terminate the affected feature or service without penalty for the unused affected period.

An entry marked disabled is not authorized to receive Customer Data merely because it appears in the annex. Snapstay must complete the stated gate and give any required change notice before enabling it.

5. Assistance

Taking into account the nature of processing and information available, Snapstay will reasonably assist Customer with:

If a person sends Snapstay a request concerning Customer Data, Snapstay will notify Customer without undue delay and will not respond substantively except on Customer’s instructions or as law requires.

6. Personal data breaches

Snapstay will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Data. As information becomes available, notice will describe the nature of the breach, affected categories/approximate numbers, likely consequences, measures taken or proposed, and a contact point. Snapstay’s notice is not an admission of fault. Customer remains responsible for its controller notifications; Snapstay will provide reasonable assistance.

7. Return and deletion

During the Agreement, Customer may export or request deletion of Customer Data using available features or a documented support instruction. On termination or a valid instruction, Snapstay will delete or return Customer Data, at Customer’s choice, unless law requires retention.

Operational deletion from active systems is targeted within 30 days. Isolated backup copies expire under Snapstay’s documented backup cycle and are not restored for ordinary processing. If disaster recovery restores previously deleted data, Snapstay will reapply recorded deletion/restriction instructions. Legally retained data remains protected and is used only for the required purpose.

8. Audits and information

Snapstay will make available information reasonably necessary to demonstrate Article 28 compliance. Once per year, and additionally following a substantiated incident or regulator request, Customer may request relevant independent reports or a reasonable audit by an independent, confidential auditor.

Audits must use existing evidence first, avoid access to other customers’ data or security-sensitive systems, occur on reasonable notice during business hours, and not unreasonably disrupt the service. Customer bears its audit costs unless the audit identifies a material Snapstay breach.

9. International transfers

Snapstay will not transfer Customer Data outside the EEA unless Data Protection Law permits the transfer. Where an adequacy decision does not apply, Snapstay will use the applicable controller-to-processor or processor-to-processor SCC module and supplementary measures as required. Snapstay will provide relevant safeguard information on request, subject to lawful redaction.

If Customer is a processor, it confirms that its controller has authorized Snapstay and the subprocessors/transfers in this DPA.

10. Liability and duration

The Agreement’s liability terms apply to this DPA except where Data Protection Law requires otherwise. This DPA remains effective while Snapstay processes Customer Data.

Annex 1: Processing details

This annex describes the Customer Data covered by the documented instructions.

Annex 2: Technical and organizational measures

Snapstay’s measures include:

Annex 3: Authorized subprocessors

The precise account region, accepted contract, transfer mechanism, and private evidence record must be approved before real Customer Data. Customer-facing notices will identify material changes.

Subprocessor Purpose and data Processing location/transfer note Status
Fly.io, Inc. Application/database/cache/image-service hosting; Customer Data and service logs Primary deployment Amsterdam, Netherlands; verify support/subprocessor access and transfer safeguards authorized only after launch evidence approval
Cloudflare, Inc. R2 object storage and encrypted PostgreSQL backups; property content and database backup data Buckets configured WEUR; verify support/subprocessor access and transfer safeguards authorized only after launch evidence approval
Stripe group entity identified in the account Subscription billing and hotel-authorized payments; account, transaction, guest/payment metadata Verify account region, roles, subprocessors, and transfer basis authorized only after launch evidence approval
Resend, Inc. Transactional email and delivery events; recipient, message, booking/account content Verify retention, subprocessors, and transfer basis authorized only after launch evidence approval
Functional Software, Inc. (Sentry) Error reporting; request/account/guest context if present in an error EU project/retention and transfers must be verified authorized only after launch evidence approval
Better Stack, Inc. Service metrics/monitoring; operational identifiers and any incidental telemetry EU source/retention and transfers must be verified authorized only after launch evidence approval
Channex and its contracting entity Channel management; property, inventory, booking, guest, and channel data Verify account entity, subprocessors, locations, and transfers authorized only after launch evidence approval
Google entity identified in the account Maps/geocoding and the currently configured Gemini review-draft function; property queries and, for review drafts, display name/rating/source/body Verify product-specific Article 28 terms, retention/no-training settings, subprocessors, and transfers authorized only after launch evidence approval
Customer-selected payment, booking, channel, or review provider Customer-directed integration data needed for that provider As configured/contracted by Customer; Customer authorizes the recipient and Snapstay verifies its own subprocessor role where applicable feature-specific authorization
TensorX Optional dashboard AI; operator prompts and minimized current-property tool results Terms/DPA, Article 28(4), subprocessors, EU/transfer claims, retention, and no-training terms must be verified disabled; not authorized to receive Customer Data

PostHog is disabled and is not an authorized Customer Data subprocessor under this version. Enabling analytics requires valid consent where applicable, a DPA update/notice, and completed contract/transfer/retention evidence.