This Data Processing Agreement ("DPA") forms part of the Terms of Service between SMN Properties OÜ, a company registered in Estonia that operates the Simple Guests platform (simpleguests.com) ("Processor", "we"), and the accommodation provider using Simple Guests ("Controller", "you"). It applies whenever we process personal data on your behalf, as required by Article 28 of the EU General Data Protection Regulation ("GDPR"). If this DPA and the Terms conflict on data protection, this DPA prevails.
1. Subject matter and duration#
We process guest personal data to provide Simple Guests: collecting guest registration data, digital check-in (ID scan, confirmation, signature and, where you enable it, the face check), submitting or keeping the records your configured authorities require, and sending check-in messages. Processing lasts for as long as you use the service, plus the retention periods in section 9.
2. Nature of the processing#
- Data subjects: your guests (including members of a group booking), and people who contact your property through the Receptionist Agent if you enable it.
- Personal data: identity document fields (name, document number and type, nationality, date of birth, sex, expiry, issuing country), document images, signatures, booking details (dates, party size, room), contact details used to send check-in links, and messages sent to the Receptionist Agent.
- Special category data (optional): if you switch on the face check, a selfie and a photo of the guest's ID are compared to verify identity (biometric data under GDPR Article 9). This happens only with the guest's explicit consent. We delete both photos immediately after the comparison, and our storage removes any left behind after one day. We keep only the result, a match score, the number of attempts and when consent was given.
- Processing operations: collection, storage, automated reading of documents (OCR), face comparison where enabled, transmission to authorities you configure, messaging, retention and deletion.
3. Your instructions#
We process personal data only on your documented instructions: this DPA, the Terms, and the settings you choose in the dashboard (for example which authorities to submit to, which messaging channels to use, and whether the face check or Receptionist Agent is on). If we believe an instruction breaks data protection law, we will tell you. If EU or Member State law requires us to process data otherwise, we will tell you first unless that law forbids it.
You are responsible for having a lawful basis for the processing, for giving guests the information they are entitled to, and — if you enable the face check — for keeping it genuinely optional, offering an in-person ID check instead, and carrying out any data protection impact assessment your law requires.
4. Confidentiality#
Everyone we authorise to process personal data is bound by confidentiality. Access to guest data is limited to what is needed to run, secure and support the service. Viewing guest documents in the dashboard, and any exceptional access across customer accounts by our team, is recorded in an audit log.
5. Security#
We apply technical and organisational measures appropriate to the risk (GDPR Article 32), including:
- Encryption in transit (TLS) and at rest (encrypted database and storage).
- Tenant isolation enforced in the database (row-level security), so one customer's records cannot be read in another's context.
- Government portal credentials encrypted with AES-256-GCM envelope encryption; never written to logs.
- Document and face-check photos held in private storage, uploaded through short-lived signed links, and removed automatically after one day.
- Signed, expiring per-booking check-in links; rate limits and a regenerate option for property links.
- Least-privilege access for staff and services, and audit logging of sensitive actions.
- Automated retention jobs that anonymise guest records once their legal retention period ends.
6. Sub-processors#
You authorise us to use the sub-processors listed below. We impose data protection obligations on each of them that are at least as protective as this DPA, and we remain responsible for their performance. We will give you at least 30 days' notice before adding or replacing a sub-processor, by email to your account owner and by updating this page. If you object on reasonable data protection grounds, we will try to find an alternative; if we can't, you may end the affected part of the service without penalty.
| Sub-processor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Amazon Web Services EMEA SARL (AWS) | API and background processing, document and photo storage, document reading (OCR), and the optional face check (Amazon Rekognition) | EU — Ireland (eu-west-1) | Within the EU. AI-services opt-out applied: content is not stored or used to improve AWS services. |
| Supabase Inc. | Managed Postgres database holding guest registration and account records | EU region | Data stored in the EU; EU Standard Contractual Clauses for any remote access from outside the EU |
| Vercel Inc. | Hosting of the guest check-in and staff web apps; check-in requests pass through its network | Global edge network (nearest location to the user) | EU–US Data Privacy Framework and EU Standard Contractual Clauses |
| Postmark (ActiveCampaign, LLC) | Transactional email — check-in links and staff account email | United States | EU–US Data Privacy Framework and EU Standard Contractual Clauses |
| Stripe Payments Europe, Ltd. | Subscription billing (staff and company billing data only — no guest data) | EU / United States | EU Standard Contractual Clauses |
| Meta Platforms Ireland Ltd. (WhatsApp Business Platform) | Sending check-in links and, if enabled, Receptionist Agent messages over WhatsApp | EU / United States | EU–US Data Privacy Framework and EU Standard Contractual Clauses — only when you enable WhatsApp |
| Twilio Inc. | Sending check-in links by SMS | United States | EU–US Data Privacy Framework and EU Standard Contractual Clauses — only when SMS is used |
| Anthropic, PBC | Drafting answers to guests' questions for the Receptionist Agent add-on | United States | EU Standard Contractual Clauses — only when you enable the Receptionist Agent |
Government authorities you configure (for example SES.HOSPEDAJES or the Mossos d'Esquadra) receive data because you are legally required to send it; they are recipients, not our sub-processors.
7. International transfers#
Guest data is stored in the EU. Where a sub-processor processes personal data outside the European Economic Area, the transfer is covered by an adequacy decision (such as the EU–US Data Privacy Framework) or by the European Commission's Standard Contractual Clauses, as shown in section 6.
8. Helping you#
- Data subject requests: we will help you answer requests from guests (access, correction, erasure and so on), mainly through the dashboard, and forward any request we receive directly to you without answering it ourselves.
- Personal data breaches: we will notify you without undue delay after becoming aware of a breach affecting your data, with the information you need to meet your own obligations, and keep you updated as we investigate.
- Impact assessments and authorities: we will give you reasonable information to help with data protection impact assessments (including for the face check) and any consultation with a supervisory authority.
9. Deletion and return#
Guest records are kept for the retention period your jurisdiction requires (for example three years in Spain) and then anonymised automatically. When your subscription ends, you can ask us for a copy of your data; we then delete or anonymise guest personal data within 90 days, except where the law requires us to keep it for longer, in which case we keep it only for that purpose.
10. Audits#
We will make available the information needed to show compliance with this DPA and allow reasonable audits, by you or an independent auditor you appoint, with at least 30 days' notice, during business hours, no more than once a year (unless a supervisory authority requires it or a breach has occurred), and subject to confidentiality.
11. Liability, term and governing law#
Liability under this DPA is subject to the limits in the Terms of Service, except where the law does not allow them to be limited. This DPA lasts as long as we process personal data for you. It is governed by the laws of Estonia. Questions: hello@simpleguests.com.