Data Processing Agreement

Last updated: September 2026

Draft template — placeholders in [brackets] must be completed, and this DPA should be reviewed by a Spanish data-protection lawyer before it is relied upon with real customers.

1. Parties and roles

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you, the host ("Controller"), and Mikel Llobera Guelbenzu, tax ID 21752467X, Andreu Vidal, 18, Sant Adrià de Besòs, 08930, Barcelona("Processor", operator of Registroom). It reflects Article 28 GDPR. The Controller determines the purposes and means of processing guest personal data; the Processor processes it on the Controller's behalf.

2. Subject matter, nature and purpose

The Processor processes guest personal data solely to provide the Service: collecting guest identity data, generating and transmitting the legally required traveller registration to the authorities, calculating and collecting the tourist tax, and, where enabled, backing up records and sending notifications. Processing lasts for the term of the Controller's subscription plus the retention period below.

3. Categories of data and data subjects

Data subjects: the Controller's guests (including, where applicable, minors). Categories: identification data (name, document type and number, nationality, date of birth), contact data (email, phone), address, reservation details, and the identity-document image processed transiently for OCR (not stored). Some of this may constitute sensitive or special-category data under national law and is treated accordingly.

4. Processor obligations

  • Process personal data only on the Controller's documented instructions, including for transfers, unless required by law.
  • Ensure persons authorised to process the data are bound by confidentiality.
  • Implement appropriate technical and organisational security measures (Section 8).
  • Engage sub-processors only under Section 6 and impose equivalent data-protection obligations on them.
  • Assist the Controller, taking into account the nature of processing, in responding to data-subject rights requests.
  • Assist the Controller with security, breach notification, and data-protection impact assessments.
  • Notify the Controller without undue delay after becoming aware of a personal-data breach.
  • At the Controller's choice, delete or return the personal data at the end of the service, and delete existing copies unless retention is legally required.
  • Make available information necessary to demonstrate compliance and allow for and contribute to audits.

5. Controller obligations

The Controller warrants that it has a valid legal basis to collect and submit the guest data, that it provides guests with the required privacy information and (where relevant) obtains consent, and that its instructions comply with data-protection law.

6. Sub-processors

The Controller authorises the following sub-processors. We will inform the Controller of intended changes and give an opportunity to object.

Sub-processorPurposeLocation
SupabaseDatabase & file storageeu-west-1 (EU)
VercelApplication hostingEU / global edge
Google (Drive, OAuth, Gemini)Optional backup, host sign-in, document OCREU / US (SCCs)
StripePayment processingEU / US (SCCs)
TelegramOptional host notificationsGlobal
Gmail / SMTPOptional email deliveryEU / US (SCCs)

7. International transfers

Personal data is stored in the eu-west-1 region. Where a sub-processor processes data outside the EEA, transfers are covered by an adequacy decision or EU Standard Contractual Clauses with appropriate supplementary measures.

8. Security measures

  • Encryption in transit (TLS) and at rest; sensitive guest fields (identity data, registration file, receipt) are additionally encrypted at the application layer (AES-256-GCM). Host portal passwords are stored encrypted, never in plaintext.
  • Strict tenant isolation: each host can access only their own data, enforced in the application and by database access controls.
  • Least-privilege access, authenticated administrative access, and secrets kept server-side.
  • Access logging of guest-record views for accountability.
  • Regular dependency and configuration review.

9. Retention and deletion

Guest records are retained for the period required by Spanish short-term-rental law (approximately three years after check-out) and then automatically deleted. The Controller can delete its account and all associated data at any time from Settings → Profile, which erases the guest data it controls.

10. Liability and governing law

Each party's liability under this DPA is subject to the limitations in the Terms of Service. This DPA is governed by the laws of Spain, with jurisdiction as set out in the Terms.

11. Contact

Data-protection contact: soporte@registroom.com.

Privacy PolicyTerms of ServiceHelp