Data Protection

Data Processing Addendum

Annex 1 to the Service Agreement — how Sarucci processes personal data on your behalf.Version 1.0

This Data Processing Addendum (“DPA”) is incorporated into and forms part of the Service Agreement (“Agreement”) between Sarucci Inc. (“Provider”, “Processor”) and the Client identified in the Agreement (“Client”, “Controller”). This DPA reflects the parties’ agreement with respect to the processing of Personal Data in compliance with the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”), the UK GDPR, and the UK Data Protection Act 2018. In the event of any conflict between this DPA and the Agreement, this DPA shall prevail in respect of data protection matters.

1.Definitions

Terms such as “personal data”, “processing”, “controller”, “processor”, “data subject”, and “supervisory authority” have the meanings given in Article 4 GDPR. “Sub-processor” means any processor engaged by Provider to process Personal Data on behalf of Client. “Data Protection Laws” means the GDPR, the UK GDPR, the UK Data Protection Act 2018, and any other applicable laws relating to the processing of personal data.

2.Roles of the Parties

As between the parties, Client is the Controller and Provider is the Processor in respect of Personal Data contained within Client Data. Provider will process Personal Data only on behalf of Client and in accordance with Client’s documented instructions, including instructions communicated through Client’s configuration and use of the Platform, except where otherwise required by applicable law (in which case Provider shall inform Client of that legal requirement before processing, unless that law prohibits such information).

3.Subject Matter and Details of Processing

The subject matter, nature, duration, and purpose of processing, the types of Personal Data, and categories of data subjects are set out in Annex A (Description of Processing) to this DPA.

4.Provider Obligations

Provider shall:

  • Process Personal Data only on Client’s documented instructions, including with regard to international transfers, unless required to do otherwise by applicable law.
  • Ensure that persons authorised to process Personal Data are subject to appropriate confidentiality obligations.
  • Implement the technical and organisational security measures set out in Annex B (Security Measures), taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to data subjects.
  • Not engage a sub-processor without Client’s prior general or specific written authorisation. Provider has Client’s general authorisation to engage the sub-processors listed in Annex C (Sub-processors), subject to Provider giving Client at least thirty (30) days’ prior written notice of any intended addition or replacement, during which Client may object on reasonable data protection grounds. If Client objects and the parties cannot resolve the objection, Client may suspend or terminate the Agreement with respect to the affected Services without penalty.
  • Impose data protection obligations on each sub-processor that are substantially the same as those set out in this DPA, and remain liable to Client for the performance of each sub-processor’s obligations.
  • Taking into account the nature of the processing, assist Client by appropriate technical and organisational measures, insofar as reasonably possible, for the fulfilment of Client’s obligations to respond to requests from data subjects exercising their rights under Chapter III of the GDPR.
  • Assist Client in ensuring compliance with the obligations relating to security of processing, breach notification, data protection impact assessments, and prior consultation with supervisory authorities, taking into account the nature of processing and the information available to Provider.
  • Notify Client without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Client Data, and provide Client with sufficient information to allow Client to meet its own notification obligations.
  • At Client’s election, and within thirty (30) days following termination or expiry of the Agreement, delete or return all Personal Data to Client, and delete existing copies, unless applicable law requires Provider to retain some or all of the Personal Data, in which case Provider shall isolate and protect that data from further processing except to the extent required by such law.
  • Make available to Client all information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR, and allow for and contribute to audits, including inspections, conducted by Client or an auditor mandated by Client, no more than once per twelve (12) month period (or more frequently following a Personal Data Breach or as required by a supervisory authority), on at least thirty (30) days’ prior written notice and subject to reasonable confidentiality safeguards.
  • Maintain a written record of all categories of processing activities carried out on behalf of Client, in accordance with Article 30(2) GDPR.
  • Promptly notify Client if, in Provider’s opinion, an instruction from Client infringes the GDPR or other applicable Data Protection Laws.

5.Client Obligations

Client shall:

  • Ensure that its instructions to Provider regarding the processing of Personal Data comply with applicable Data Protection Laws, and that Client has, and will maintain, a valid legal basis for the collection and onward transmission of Personal Data to Provider for processing in accordance with this DPA.
  • Be solely responsible for the accuracy, quality, and legality of Personal Data and the means by which Client acquired any Personal Data uploaded to or processed within the Platform.
  • Comply with its own transparency obligations to data subjects, including any necessary notices regarding the use of the Platform.

6.International Transfers

Provider shall not transfer Personal Data outside the European Economic Area (“EEA”) or the United Kingdom unless it has taken such measures as are necessary to ensure the transfer is in compliance with applicable Data Protection Laws. Such measures may include (without limitation): (a) transferring data to a country or territory that is subject to an adequacy decision by the European Commission or, as relevant, the UK Secretary of State; (b) entering into the Standard Contractual Clauses approved by the European Commission (Commission Implementing Decision (EU) 2021/914), incorporated by reference into this DPA and completed as set out in Annex D; or (c) for transfers subject to UK GDPR, the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, issued by the UK Information Commissioner, incorporated by reference and completed as set out in Annex D.

Where Annex D Standard Contractual Clauses apply, in the event of any conflict between the terms of this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses shall prevail.

7.Liability

The liability of each party arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitations and exclusions of liability set out in Section 10 (Limitation of Liability) of the Agreement. Each party remains subject to the fines and penalties that may be imposed on a controller or processor (as applicable) by a supervisory authority under Article 83 GDPR.

8.Term

This DPA shall remain in effect for as long as Provider processes Personal Data on behalf of Client under the Agreement, and shall automatically terminate upon expiry or termination of the Agreement, save that the obligations relating to confidentiality, deletion/return of Personal Data, and liability shall survive in accordance with their terms and the Agreement.

Annex A: Description of Processing

A.1 Categories of Data Subjects

  • Client’s employees, contractors, and authorised Users (e.g., General Managers, Revenue Managers, Commercial Directors) who access the Platform
  • Where applicable, individuals identifiable from hotel performance, booking, or revenue data uploaded by Client

A.2 Categories of Personal Data

  • Account and identity data: names, job titles, business email addresses, phone numbers
  • Platform usage data: IP addresses, device identifiers, log-in data, session activity
  • Hotel performance and revenue data uploaded or connected by Client, to the extent it identifies an individual
  • Communications data: support tickets, emails, survey responses
  • Audio and transcript data: voice recordings and the transcripts derived from them, where a User interacts with the Platform’s real-time voice consultant

Provider does not require, and Client shall not knowingly upload, special category data (Article 9 GDPR), criminal offence data, or personal data relating to children, to the Platform.

A.3 Nature and Purpose of Processing

Provider processes Personal Data for the purpose of providing, maintaining, securing, and supporting the Sarucci Revenue Intelligence Platform as described in the Agreement, including hosting, account administration, customer support, billing, security and fraud prevention, and (in anonymised/aggregated form only) service improvement.

A.4 Duration of Processing

Personal Data will be processed for the duration of the Agreement and thereafter in accordance with Section 7.4 of the Agreement (export and deletion) and the retention periods set out in the Privacy Policy.

A.5 Frequency of Transfer

Continuous, for the duration that Client and its Users access and use the Platform.

Annex B: Technical and Organisational Security Measures

Provider maintains the following technical and organisational measures, and may update them from time to time provided such updates do not materially decrease the overall level of security:

  • SOC 2 Type II certification, subject to annual independent audit
  • Encryption of data in transit using TLS 1.2 or higher
  • Encryption of data at rest using AES-256
  • Role-based access controls (RBAC) and enforcement of least-privilege principles
  • Multi-factor authentication (MFA) for all Platform access by Provider personnel and Users
  • Regular penetration testing conducted by independent third-party security firms
  • Formal incident response and Personal Data Breach notification procedures, including the 72-hour notification commitment in Section 4 of this DPA
  • Logical separation of Client Data from data belonging to other customers
  • Maintenance of audit logs for access to Personal Data and key system events
  • Secure software development lifecycle practices, including code review and vulnerability management
  • Business continuity and disaster recovery procedures, including regular backups

Annex C: Authorised Sub-processors

As of the Effective Date, Provider engages the sub-processors listed in the table below. Where a sub-processor is identified below by category rather than by name, Provider will identify the engaged entity and its location on the sub-processor page before that sub-processor begins processing Personal Data. An up-to-date list, including entity names and locations, is maintained at sarucci.com/sub-processors and is incorporated by reference into this Annex.

Sub-processor / CategoryPurpose of ProcessingLocation of Processing
Google Cloud EMEA Limited / Google LLC (Google Cloud Platform)Hosting and execution of the Platform, managed database services, object storage, asynchronous task queues, container registry and scheduled jobsEuropean Union (Belgium) and United Kingdom (London)
Google LLC / Google Cloud EMEA Limited (Firebase — Hosting, Authentication, Cloud Firestore)Delivery of the Platform web application, user authentication and storage of user-configured application stateEuropean Union and United States
Amazon Web Services EMEA SARL / Amazon Web Services, Inc.Supplementary hosting, compute and storage for Platform servicesEuropean Union (Ireland and Frankfurt) and United States
Zoho Corporation Private LimitedDelivery of transactional and system email (account, security, rate-publishing and report notifications) and operation of the support mailboxIndia and European Union
Anthropic PBCLarge language model processing for the Platform’s AI analyst, AI consultant and agentic advisor featuresUnited States
OpenAI Ireland Limited / OpenAI, L.L.C.Large language model processing, embeddings and document retrieval for the Platform’s AI featuresEuropean Union and United States
Google LLC (Gemini API)Large language model processing for the Platform’s AI featuresEuropean Union and United States
RunPod, Inc.GPU compute for the Platform’s real-time voice consultant (speech recognition, speech synthesis and avatar rendering) and for machine learning model trainingEuropean Union and United States
Google Maps Platform (Google LLC)Map rendering and geocoding on the Platform’s market and competitor intelligence screensEuropean Union and United States
Analytics providerAnonymised and aggregated Platform usage analyticsEuropean Union and United States
Stripe Payments Europe, Limited / Stripe, Inc.Subscription billing, invoicing and payment processing. No payment card data is stored by ProviderIreland and United States

Provider will give Client at least thirty (30) days’ advance written notice of any new or replacement sub-processor, in accordance with Section 4 of this DPA.

For the avoidance of doubt, property management systems and other third-party systems that Client connects to the Platform — including Oracle OPERA Cloud (OHIP) and Cloudbeds — are not sub-processors of Provider. Where Client authorises such a connection, Provider exchanges Client Data with that system on Client’s instruction, and Client’s relationship with that system’s provider is governed by Client’s own agreement with it.

Annex D: International Transfer Mechanism

D.1 EU Standard Contractual Clauses

Where Provider transfers Personal Data originating from the EEA to a country not subject to an adequacy decision, the parties adopt the Standard Contractual Clauses for the transfer of personal data to third countries pursuant to the GDPR, as set out in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (“EU SCCs”), as follows:

  • Module Two (Controller to Processor) applies to transfers of Personal Data from Client (as data exporter) to Provider (as data importer).
  • Clause 7 (Docking Clause): not used.
  • Clause 9 (Sub-processors): Option 2 (general written authorisation) applies, with the notice period specified in Section 4 of this DPA.
  • Clause 11 (Redress): the optional language is not used.
  • Clause 17 (Governing Law): the laws of Ireland.
  • Clause 18 (Choice of Forum and Jurisdiction): the courts of Ireland.
  • Annex I and Annex II of the EU SCCs are deemed populated by reference to Annexes A and B of this DPA respectively, and Annex III (sub-processors) by reference to Annex C of this DPA.

D.2 UK International Data Transfer Addendum

Where Provider transfers Personal Data originating from the United Kingdom, the parties adopt the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, issued by the UK Information Commissioner’s Office under section 119A(1) of the UK Data Protection Act 2018, which shall be read together with the EU SCCs as completed in Section D.1 above, with Tables 1–4 of the UK Addendum deemed completed by reference to the parties’ details in the Agreement and Annexes A–C of this DPA, and the start date being the Effective Date of the Agreement.

D.3 Other Transfer Mechanisms

Nothing in this Annex D prevents the parties from relying on an applicable adequacy decision, or agreeing in writing to rely on an alternative valid transfer mechanism in place of the SCCs or UK Addendum, to the extent permitted by applicable Data Protection Laws.

Questions about this document? Contact us at [email protected]