Data Processing Agreement
Last updated: 27 August 2026 · GDPR Article 28 · Irish Data Protection Act 2018 · DPC IE-14872
· I ·Parties
This Data Processing Agreement (the "DPA") is entered into between the Customer identified in the applicable Terms of Service (the "Controller") and GuestlinePortal Ltd, a company incorporated in Ireland under CRO 728 419, having its registered office at 21 Grafton Street, Dublin D02 XH54, Ireland (the "Processor"). The DPA forms part of the Terms of Service and applies to all processing of personal data carried out by the Processor on behalf of the Controller through the Service.
· II ·Subject-matter and duration
The subject-matter of the processing is the provision of GuestlinePortal Irish Rezlynx modules to the Controller. Processing is carried out for the duration of the subscription contract and for 30 days after termination to allow the Controller to retrieve its data. Thereafter data is permanently deleted, except for records the Processor is required by Irish law to retain (financial records for seven years to comply with Revenue Commissioners record-keeping obligations).
· III ·Nature and purpose of processing
The Processor processes personal data for the sole purpose of providing the Service — synchronising reservations with the Rezlynx PMS, generating Revenue-compliant Irish invoices, routing payment authorisations through Bank of Ireland and AIB, publishing rate and inventory to Irish-market OTAs, producing regional benchmark reports and applying yield management recommendations. No other purpose. No use for the Processor's own marketing. No training of external AI models.
· IV ·Categories of data subjects and personal data
Data subjects: hotel guests, corporate booking contacts, employees of the Controller who use the Client Portal. Categories of personal data: identification data (full name, guest ID, email), contact data (phone, address, city, county, Eircode), reservation data (arrival, departure, room type, rate plan, guest count), financial data (invoice line items with VAT breakdown, payment card token, IBAN for SEPA), and interaction data (loyalty points, feedback, ticket transcripts). No special categories of personal data under Article 9 GDPR are processed by the Service.
· V ·Processor obligations
- Process personal data only on documented instructions from the Controller (including on transfers).
- Ensure that persons authorised to process personal data are under a written obligation of confidentiality.
- Implement appropriate technical and organisational measures — TLS 1.3 in transit, AES-256 at rest, hardware key MFA for production access, quarterly penetration tests, ISO/IEC 27001-aligned security baseline.
- Assist the Controller in responding to data subject requests under Articles 15–22 GDPR.
- Assist the Controller in complying with Articles 32–36 GDPR (security, breach notification, DPIA).
- At the choice of the Controller, delete or return all personal data at the end of the contract.
- Make available to the Controller all information necessary to demonstrate compliance with this DPA and Article 28 GDPR.
· VI ·Sub-processors
The Controller authorises the Processor to engage the following sub-processors: (a) EU-Central-1 cloud infrastructure provider for data storage and compute (Dublin failover); (b) mail relay provider hosted in Dublin for transactional email; (c) bank connectivity — Bank of Ireland Payment Acceptance and AIB Merchant Services — for payment processing on the Controller's behalf. The Processor will inform the Controller of any addition or replacement of sub-processors 30 days in advance and the Controller may object on reasonable grounds relating to data protection.
· VII ·International transfers
No personal data is transferred outside the European Economic Area. All processing, storage and support activities take place in the EU. If a transfer becomes necessary, it will be governed by the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) with a Transfer Impact Assessment carried out beforehand.
· VIII ·Breach notification
The Processor will notify the Controller of any personal data breach affecting the Controller's data without undue delay and in any event within 48 hours of becoming aware of the breach. Notification is sent to the security contact on file for the Controller and includes the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences and the measures taken or proposed. The Controller is responsible for notifying the DPC where required.
· IX ·Audit
The Controller may, on 30 days' written notice, audit the Processor's compliance with this DPA once every 12 months, or more frequently in the event of a breach. Audits are conducted during Irish business hours at the Processor's registered office, subject to reasonable confidentiality undertakings. The Processor may satisfy audit requests by providing a copy of a third-party audit report (ISO/IEC 27001 or SOC 2 Type II) covering the relevant period.
· X ·Retention and deletion
On termination of the subscription contract personal data is retained for 30 days to allow retrieval. Thereafter data is permanently deleted from production systems within 7 days and from backup systems within a further 90 days. Financial records required by the Revenue Commissioners are retained for seven years as a legal obligation of the Processor.
· XI ·Contact
DPA-related correspondence should be addressed to the Data Protection Officer at dpo@guestlineportal.com or to the Data Protection Officer, GuestlinePortal Ltd, 21 Grafton Street, Dublin D02 XH54, Ireland, Ireland.