Legal · Version 3.2.0 · Last updated 2026-07-26
Guest Talk data processing addendum
This Data Processing Addendum ("DPA") forms part of the Master Subscription Agreement between Guest Talk OU ("Processor", "Guest Talk", "we") and the Customer identified in the Order Form ("Controller", "Customer", "you") for the provision of the Guest Talk hospitality SaaS platform ("Service"). It is executed to comply with Article 28 of Regulation (EU) 2016/679 ("GDPR"), the equivalent provisions of the UK GDPR, the Swiss Federal Act on Data Protection ("revFADP"), and the Estonian Personal Data Protection Act 2019 ("IKS"). In case of conflict between the Master Subscription Agreement and this DPA on any matter concerning the processing of personal data, this DPA prevails.
1. Parties
Processor. Guest Talk OU, registered under number 14892715 at Sepapaja tn 6, 15551 Tallinn, Estonia. VAT: EE102847391. Data Protection Officer: dpo@talkg.fabriza.org.
Controller. The Customer as identified in the Order Form. Where the Customer is itself acting as processor for a further controller (for example, a hotel management company operating on behalf of a hotel owner), the Customer represents that it has authority to enter into this DPA on behalf of the ultimate controller and warrants that the controller's data protection rights are preserved.
2. Subject matter, duration, nature and purpose
The subject matter of the processing is the provision of the Service by Processor to Controller in accordance with the Master Subscription Agreement. The duration matches the Subscription Term and any post-termination retrieval window (see Section 16). The nature of the processing includes collection, recording, structuring, storage, retrieval, disclosure, adaptation, transmission and erasure of personal data by automated means. The purpose is to enable Controller to manage its accommodation operation, including reservations, guest communications, distribution across online travel agencies, payments, staff scheduling and financial reporting.
3. Types of personal data processed
The Service processes the following categories of personal data as directed by Controller:
- Guest identity data (full name, date of birth where required for police registration, nationality, gender where volunteered, preferred language).
- Guest contact data (email, telephone, postal address).
- Booking and stay data (reservation reference, arrival and departure dates, room or bed assignment, rate plan, associated guests, special requests).
- Payment references (opaque payment method identifiers held by our payment sub-processor Stripe; the Service does not itself hold primary account numbers or card verification values).
- Guest communications (message content, timestamps, delivery statuses, template references) exchanged over email, SMS, WhatsApp Business, and the Guest Talk mobile app.
- Staff account data (full name, work email, role, worked-hours logs where Operations module is used).
- Optional travel document identifiers (passport or national ID number and expiry) where Controller has enabled the police-registration feature to comply with national law.
- Aggregate operational metrics (occupancy, ADR, RevPAR, message response times) derived from the above but not themselves identifying individual guests.
4. Categories of data subjects
- Guests (past, current and prospective) of Controller's accommodation.
- Staff employed or contracted by Controller.
- Job applicants where Controller uses the optional Careers module.
- Corporate account and travel agent contacts (bookers on behalf of guests).
- Vendors and partners (for example, laundry service contacts) where Controller stores their details in the Operations module.
5. Controller obligations
Controller shall (a) ensure that its processing instructions to Processor are lawful under GDPR and other applicable law; (b) provide any notices and obtain any consents required from data subjects; (c) maintain a lawful basis for uploading each category of personal data to the Service; (d) provide Processor with sufficient information to enable Processor to assess the legality of new processing activities Controller requests; and (e) refrain from uploading special categories of personal data (Article 9 GDPR) unless expressly agreed in writing with Processor, including agreement on the additional safeguards to be applied.
6. Processor obligations
Processor shall, in accordance with Article 28(3) GDPR:
- Process personal data only on documented instructions from Controller (including with regard to transfers), unless required to do otherwise by Union or Member State law to which Processor is subject; in such a case Processor shall inform Controller of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.
- Ensure that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Implement the technical and organisational measures set out in Annex II.
- Respect the conditions for engaging sub-processors set out in Section 10.
- Taking into account the nature of the processing, assist Controller by appropriate technical and organisational measures for the fulfilment of Controller's obligation to respond to requests for exercising the data subject's rights under Chapter III GDPR.
- Assist Controller in ensuring compliance with the obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessment, prior consultation) taking into account the nature of processing and the information available to Processor.
- At the choice of Controller, delete or return all personal data to Controller after the end of the provision of services relating to processing, and delete existing copies unless Union or Member State law requires storage.
- Make available to Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 and allow for and contribute to audits, including inspections, conducted by Controller or another auditor mandated by Controller, in accordance with Section 17.
- Immediately inform Controller if, in its opinion, an instruction infringes GDPR or other Union or Member State data protection provisions.
- Maintain records of processing activities carried out on behalf of Controller in accordance with Article 30(2) GDPR.
- Designate a Data Protection Officer under Article 37 GDPR where required by law.
- Cooperate on request with any competent supervisory authority in the performance of its tasks.
7. Documented instructions
Controller's initial documented instructions are set out in this DPA and in the Master Subscription Agreement, together with any subsequent instructions Controller gives via the workspace configuration (for example, enabling or disabling optional integrations), through the Documentation, or via written notice to Processor. Processor shall action reasonable additional written instructions to the extent they are compatible with the Service. Instructions that would require material additional work may be subject to a change order at Processor's then-current professional services rates.
8. Confidentiality
Processor shall ensure that access to personal data is limited to personnel who need such access to fulfil Processor's obligations. All Processor personnel with such access are bound by written confidentiality obligations that survive termination of their engagement. Processor conducts background checks on employees with access to production personal data to the extent permitted by applicable law.
9. Security measures
Processor implements the technical and organisational measures set out in Annex II. Processor may update the measures from time to time provided that the overall level of protection is not materially diminished.
10. Sub-processors
10.1 General authorisation. Controller grants Processor general authorisation to engage sub-processors listed in Annex III for the processing operations described in this DPA. Processor shall enter into contractual arrangements with each sub-processor that impose data protection obligations no less protective than those set out in this DPA.
10.2 Notification of change. Processor shall notify Controller of any intended addition or replacement of sub-processors at least 30 days in advance by updating the public list at /legal/privacy and sending an email to workspace administrators. Controller may object to any such addition on reasonable grounds relating to data protection within 15 days of the notice by written notice to dpo@talkg.fabriza.org. If Processor cannot accommodate the objection through commercially reasonable means, Controller may terminate the Service (or the affected portion) with a pro-rata refund of prepaid unused fees, as its exclusive remedy for the objection.
10.3 Liability. Processor remains fully liable to Controller for the performance of a sub-processor's obligations under this DPA.
11. Data subject rights assistance
Processor provides built-in tools inside the Service (workspace administrator can export, redact and delete personal data on individual data subjects) that enable Controller to respond directly to most Article 15-22 requests without Processor's intervention. Where a request cannot be actioned via the built-in tools, Processor shall provide reasonable assistance on Controller's written request. Where Processor receives a request directly from a data subject, it will not respond substantively (except to acknowledge receipt and direct the data subject to Controller) and will forward the request to Controller within two business days.
12. Personal data breach notification
Processor shall notify Controller without undue delay, and in any event within 24 hours of confirmed awareness, of any personal data breach affecting personal data processed on behalf of Controller. The notification shall include, to the extent known at the time: (a) the nature of the breach, including the categories and approximate number of data subjects and records concerned; (b) the name and contact of the DPO or another contact point; (c) the likely consequences; and (d) the measures taken or proposed to address the breach and mitigate its adverse effects. Processor shall provide follow-up information as it becomes available and cooperate with Controller in Controller's own notification obligations to supervisory authorities and data subjects under Articles 33 and 34 GDPR.
13. Data protection impact assessment
Processor shall provide reasonable assistance to Controller in performing data protection impact assessments and prior consultations with supervisory authorities under Articles 35 and 36 GDPR, to the extent such assistance relates to processing carried out by Processor on behalf of Controller.
14. International transfers
Processor shall not transfer personal data outside the European Economic Area except in accordance with the safeguards set out in Chapter V GDPR. Where a transfer relies on the Standard Contractual Clauses adopted in Commission Implementing Decision (EU) 2021/914, Module 2 (controller-to-processor) and Module 3 (processor-to-processor) are hereby incorporated by reference between the parties, with the following elections: Clause 7 (docking) does not apply; Clause 9 (sub-processors) option 2 (general written authorisation) applies with a 30-day notice period; Clause 11 (redress) does not offer an independent dispute resolution body; Clause 17 (governing law) is the law of Estonia; Clause 18 (choice of forum) is Harju Maakohus. Annex I and Annex II to the SCCs are set out in this DPA (Annex I herein and Annex II herein). Annex III to the SCCs is the sub-processor list in Annex III herein.
15. Records
Processor maintains a record of processing activities in respect of processing carried out on behalf of Controller in accordance with Article 30(2) GDPR. Extracts of the record relating to Controller's data will be provided on written request from Controller once per year at no charge.
16. Return or deletion of personal data
On termination or expiry of the Service, Processor shall, at Controller's written election within 30 days of termination, (a) return all personal data to Controller via the built-in export tools or a mutually-agreed data transfer mechanism, or (b) delete all personal data. Absent an election, Processor shall retain the workspace for 30 days in a suspended state to enable Controller to export data, then delete personal data. Backups containing personal data are overwritten in the normal course of backup rotation within 90 days; during this period backups remain encrypted and access is restricted to a small number of authorised personnel with break-glass procedures. Processor shall certify deletion in writing on Controller's request.
17. Audit rights
17.1 Third-party reports. Processor shall make available its most recent independent audit reports (SOC 2 Type II, ISO/IEC 27001 certification, penetration testing summary) under a mutual non-disclosure agreement. In the ordinary course this is deemed to satisfy Controller's audit rights.
17.2 Direct audit. No more than once per calendar year, and following at least 30 days' written notice, Controller may conduct or commission an on-site audit of Processor's premises, systems and records relevant to the processing under this DPA. The audit shall be conducted during business hours, without unreasonable interference with Processor's operations, subject to reasonable confidentiality obligations, and at Controller's expense unless the audit reveals material non-compliance, in which case Processor shall bear reasonable costs.
17.3 Supervisory authority. Nothing in this Section limits any right of a supervisory authority to conduct an audit or inspection under GDPR.
18. Liability
The liability of each party under this DPA is subject to the aggregate liability cap set out in the Master Subscription Agreement. This DPA is without prejudice to the direct rights of data subjects under Article 82 GDPR to claim compensation from either party for damage suffered as a result of an infringement of GDPR.
19. Term
This DPA takes effect on the date of the Master Subscription Agreement and continues until the return or deletion of all personal data in accordance with Section 16.
20. Governing law
This DPA is governed by the laws of the Republic of Estonia, without prejudice to the mandatory data protection laws of the jurisdictions of the data subjects. Disputes are subject to the exclusive jurisdiction of Harju Maakohus (Tallinn), without prejudice to any remedies available to a data subject or supervisory authority.
Annex I — Processing details
List of parties. Data exporter: Controller as identified in the Order Form. Data importer: Guest Talk OU.
Description of transfer. Continuous transfer of personal data as necessary for the operation of the Guest Talk hospitality SaaS platform, initiated by Controller's use of the Service.
Categories of data subjects, categories of personal data, frequency, nature, purpose, retention. As set out in Sections 2 to 4 and 6 of the Privacy Policy at /legal/privacy.
Sensitive data. No special categories of personal data unless expressly agreed and configured.
Recipients. The sub-processors listed in Annex III.
Retention period. As set out in Section 16 above and Section 6 of the Privacy Policy.
Annex II — Technical and organisational measures
- Pseudonymisation of user identifiers in secondary systems (analytics, logs) where feasible.
- Encryption of personal data at rest using AES-256 with keys managed in AWS KMS; automatic key rotation every 12 months.
- Encryption in transit using TLS 1.3 for all public endpoints; TLS 1.2+ for internal service-to-service traffic; mTLS between core services.
- Segregation of production and non-production environments in separate VPCs with no direct network connectivity.
- Role-based access control with least privilege; quarterly access reviews.
- Mandatory multi-factor authentication for all Processor personnel and available (and enforced by default from 2026-Q3) for Controller users.
- Centralised identity provider (Okta) with SCIM lifecycle management for Processor personnel.
- Immutable audit logs with cryptographic checksums, retained for 12 months.
- Automated vulnerability scanning on container images before deployment; block on critical CVEs without accepted risk documentation.
- Manual penetration testing performed annually by an independent CREST-accredited firm; executive summary shared under NDA.
- Documented software development lifecycle with mandatory code review and static analysis before merge to main.
- Change management process with tracked approvals; production deploys via CI/CD only, never manual.
- Web application firewall in front of all public endpoints; DDoS mitigation via Cloudflare Enterprise.
- Backup of primary databases hourly (point-in-time recovery to any second within the last 35 days) and daily encrypted snapshots retained 90 days.
- Business continuity plan with quarterly tabletop exercises; annual full failover test to secondary region.
- Documented incident response process aligned with NIST SP 800-61; on-call rotation with 15-minute page-response SLA for critical incidents.
- Physical security by hosting sub-processor (AWS eu-central-1); Processor personnel have no physical access to servers.
- Data centre physical controls: 24x7 security, biometric access, video surveillance, tempered environment monitoring.
- Data destruction on decommissioning: AWS EBS volumes are wiped per NIST 800-88 Purge standards.
- Vendor risk management: annual re-assessment of every sub-processor with access to personal data.
- Employee onboarding includes GDPR training within the first two weeks and annual refresher training thereafter.
- Written information security policies reviewed annually, aligned with ISO/IEC 27001 Annex A.
Annex III — Sub-processors
- Amazon Web Services EMEA SARL — hosting (eu-central-1, Frankfurt) — Luxembourg (EU).
- Cloudflare, Inc. — CDN, DDoS — United States (SCCs).
- Stripe Payments Europe, Ltd. — payments — Ireland (EU).
- Postmark (ActiveCampaign LLC) — transactional email — United States (SCCs).
- Zendesk International Ltd. — support ticketing — Ireland (EU).
- Fathom Analytics — marketing analytics — Canada (adequacy).
- Twilio Ireland Ltd. — SMS & voice 2FA — Ireland (EU).
- Meta Platforms Ireland Ltd. — WhatsApp Business API — Ireland (EU).
- HubSpot Ireland Ltd. — marketing CRM (marketing lists only) — Ireland (EU).
- Datadog EMEA SAS — APM, RUM — France (EU).
- Loggly (SolarWinds Ireland Ltd.) — log aggregation — Ireland (EU).
- Sentry (Functional Software Ireland Ltd.) — error tracking — Ireland (EU).
Contact and version history
DPO: dpo@talkg.fabriza.org. Legal: legal@talkg.fabriza.org. Postal: Guest Talk OU, Sepapaja tn 6, 15551 Tallinn, Estonia.
- v3.2.0 (2026-07-26) — expanded Annex II to 22 measures; refreshed sub-processor annex; added revFADP alignment.
- v3.1.0 (2026-03-01) — explicit incorporation of SCC 2021/914 Modules 2 and 3.
- v3.0.0 (2026-01-15) — full alignment with EDPB Guidelines 05/2021 on Article 28.