Data Processing Agreement
Version 2026-08.2
- Service provider
- TO BE FILLED IN
- Registration number
- TO BE FILLED IN
- Registered office
- TO BE FILLED IN
- Contact for data protection
- support@dundesk.com
1. The parties and their roles
This agreement is concluded between you, the dunDesk customer, as controller, and us, as processor, and governs the processing we carry out on the personal data you enter into the application — principally your guests' data.
You decide what data you enter, why, and how long you keep it. We process it only in order to provide the application to you, on your instructions.
For data about you and the users of your account we are the controller, and the rules are in the Privacy Policy. The two roles do not mix.
2. Subject matter, nature, purpose and duration
Subject matter and purpose: providing the dunDesk booking-management application, with the features you use — the calendar, reservations, arrivals, housekeeping, prices, reports, printable documents and the record of money received from guests.
Nature of the processing: storage, organisation, consultation, alteration, erasure, generation of documents and reports, as well as backups and the technical operations the service needs to run.
Duration: the term of the contract between us, plus the retention period in section 10.
3. Categories of data subjects and of data
Data subjects: your guests and the people who book with you, as well as anyone you mention in the application's free-text notes.
Categories of data:
| Where | What |
|---|---|
| The contact record | The name, if you fill it in; the phone number; the free-text notes you write |
| The reservation | The guest's name, arrival and departure dates, rooms, head count, status, the channel it came through, amounts and notes |
| Payments received | The amounts received from the guest, the method, the date and the note |
The application does not ask for and has no fields for identity-document numbers, national identification numbers or guests' card details. Free-text notes, however, are yours: if you write such data there, or data in special categories — health data, for instance — you do so on your own responsibility and you answer for the basis of that processing. We advise against it.
4. Your instructions
We process the data only on your documented instructions. The contract between us, this agreement and your use of the application's features constitute those instructions; using a feature is the instruction to do what that feature does.
If the law obliges us to process otherwise, we tell you beforehand, unless the law itself forbids it. If an instruction of yours appears to us to infringe data-protection law, we say so.
We do not use your guests' data for our own purposes, do not combine it with another customer's data, and do not use it to train any automated system.
5. Confidentiality
The people who have access to the data on our side are bound by confidentiality and have access only to the extent needed to maintain and support the application. Support access to a customer's data happens on a concrete need and is recorded in the application's journal.
6. Security measures
We apply technical and organisational measures appropriate to the risk:
- Separation of customers. Every business's data is separated in the database, and every query the application makes is filtered by the business and the property you are standing in. That separation is verified automatically by our test battery on every change to the application.
- Role-based permissions. The users you add receive only the permissions of their role; reception does not see what the administrator sees.
- Encryption in transit. All traffic between the browser and the application is encrypted.
- Passwords. Kept only in irreversibly encrypted form; nobody, ourselves included, can read them.
- Activity journal. Important actions on the data are recorded, with their author and the moment they happened.
- Backups. The database is backed up periodically and the copies are kept separately from the system running the application. The backup frequency and how long copies are kept are to be filled in here.
- Updates. The application and the platform it runs on are kept current, and changes pass an automated test battery before they reach customers.
7. Sub-processors
By accepting this agreement you authorise us to use sub-processors for parts of the processing. Each of them is bound by contract to obligations at least as strict as our own.
| Provider | For what | Where |
|---|---|---|
| to be filled in | Hosting of the servers and the database | European Union |
| to be filled in | Sending the application's emails | European Union |
| Oblio | Issuing invoices to you | Romania |
| to be filled in | Payment processing, once online payment opens | European Union |
Invoicing and payment processing concern your customer data, not your guests' data.
When we intend to change or add a sub-processor, we tell you at least 30 days in advance. If you have a reasoned objection, you may raise it within that period; if we cannot reach a solution, you may terminate the contract without penalty for the remaining period.
8. The assistance we give you
Guests' requests. The application gives you the means to answer them yourself: you can consult, correct and delete a guest's data directly in the application. If you nonetheless need our help to answer a request, we give it within a reasonable time.
If one of your guests approaches us directly, we do not answer on the merits: we point them to you and inform you.
Assessments and consultations. We make available the information we hold that you need for an impact assessment or for a consultation with the supervisory authority.
9. Security breaches
If we become aware of a security breach affecting your data, we inform you without undue delay and within 48 hours at the latest of becoming aware. We tell you what happened, which categories of data and how many people are affected, the likely consequences and the measures we have taken.
Notifying the supervisory authority and, where required, the data subjects is yours as controller; we provide the information you need.
10. What happens to the data on termination
On termination of the contract we keep your data for 30 days, during which you can export it from the application, and then delete it from our systems. Existing backups are deleted at the end of their normal retention cycle.
You may ask us in writing, within that period, for immediate deletion; we carry it out. After that moment we keep only what the law obliges us to keep.
11. Verification and information
On request we make available the information needed to demonstrate compliance with this agreement. An on-site inspection is announced at least 30 days in advance, takes place at most once a year outside incident cases, during working hours and without affecting other customers, and its costs are borne by you.
12. Transfers outside the European Economic Area
We do not transfer the data outside the European Economic Area. Should a future sub-processor require such a transfer, we announce it under section 7 and carry it out only with the safeguards the law requires.
13. Liability
The limitations of liability in the Terms of Service apply to this agreement as well, to the extent the law allows. They do not affect the rights of data subjects, nor the liability provided by Article 82 of Regulation 679/2016.
14. Duration and amendment
The agreement enters into force upon acceptance and lasts as long as we process your data. We may amend it under the same conditions as the Terms of Service: a new version is published and the application asks you to accept it at your next sign-in.
15. Language
This document is written in Romanian and translated into English. In case of any discrepancy, the Romanian version prevails.