Skip to main content

Data Processing Agreement (DPA)

Last updated: July 30, 2026

Responsible: UNOZERO

This Data Processing Agreement (DPA) forms an integral part of the B2B Terms of Service between UNOZERO ("Processor") and the Hotel Establishment ("Controller"). It is a GDPR compliance requirement for hotels operating in the European Economic Area or with guests located there.

1. Purpose and Scope

The Processor shall process guests' Personal Data (PII) solely in accordance with the Controller's documented instructions — that is, to operate the WhatsApp booking bot and associated channels. The Processor shall not process such data for any other purpose without the Controller's prior written consent.

2. Security Measures

UNOZERO will implement appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing, and against accidental loss, destruction, or damage, including: • Encryption in transit (TLS) and at rest. • Role-based access control to systems storing Personal Data. • Periodic backups and disaster recovery plans. • Periodic review of the security practices of our subprocessors (Meta, OpenAI/Anthropic, Stripe, AWS/Google Cloud).

3. Data Breach Notification

In the event of a confirmed security breach affecting the Controller's Personal Data, UNOZERO will notify the Controller without undue delay, and in no case later than seventy-two (72) hours after becoming aware of the incident, providing the information necessary (nature of the breach, categories and approximate volume of data affected, measures taken and recommended) for the Controller to comply with its own legal notification obligations to the competent supervisory authority and, where applicable, to the affected individuals.

4. Data Deletion

Upon termination of the SaaS contract, UNOZERO will delete or return all of the Controller's Personal Data held in its active databases within a maximum of 30 days, retaining only: • Transactional data required for tax or accounting obligations. • Conversational data that has already been properly anonymized and incorporated into our training models, which loses its status as "Personal Data" and therefore falls outside the scope of this DPA. The Controller may request the export of its Personal Data at any time prior to termination, at its own responsibility.