Skip to content

WORK IN PROGRESS. The content of this page is not final and has not been legally reviewed. It is updated when the legal review is complete.

Data processing agreement (DPA)

The guesthouse is the controller of its guest data; Gjestly is the processor. This agreement (GDPR article 28) comes with the subscription and is signed digitally.

  1. 1. Parties and roles

    The guesthouse: controller. Gjestly: processor.

  2. 2. Nature, purpose and duration of processing

    This section is under legal review and is not final.

  3. 3. Categories of data subjects and data

    Guests (name, contact, booking history), the guesthouse's users.

  4. 4. Sub-processors

    See the table below.

  5. 5. Security measures

    This section is under legal review and is not final.

  6. 6. Assistance, deletion and return

    On termination: export of the data in a readable format, then deletion after the agreed deadline.

  7. 7. Audit

    This section is under legal review and is not final.

Sub-processors

VendorRoleWhat is processedData locationTransfer basis
SupabaseDatabase and authenticationBookings, guest register, invoices, user accountsNot confirmed yetNot confirmed yet
VercelApplication hostingTraffic to the websites and booking pagesNot confirmed yetNot confirmed yet
StripePayment processingPayments. Card data is processed by Stripe, never by GjestlyThe Stripe group (global)EU-US Data Privacy Framework
ResendTransactional emailEmail addresses and booking confirmationsNot confirmed yetNot confirmed yet

The fields that are not confirmed yet are filled in once the vendor agreements have been reviewed. If you need them before that, get in touch and we will send what we have.