SGSimple Guests
Sign inSign upBook a demo

SGSimple Guests · Legal

Data Processing Agreement

How SMN Properties OÜ processes guest data on behalf of the accommodation providers that use Simple Guests, under GDPR Article 28.

Last updated 25 September 2026·Operated by SMN Properties OÜ, Estonia

Terms of ServicePrivacy PolicyData Processing Agreement

Contents

  1. 1. Subject matter and duration
  2. 2. Nature of the processing
  3. 3. Your instructions
  4. 4. Confidentiality
  5. 5. Security
  6. 6. Sub-processors
  7. 7. International transfers
  8. 8. Helping you
  9. 9. Deletion and return
  10. 10. Audits
  11. 11. Liability, term and governing law

This Data Processing Agreement ("DPA") forms part of the Terms of Service between SMN Properties OÜ, a company registered in Estonia that operates the Simple Guests platform (simpleguests.com) ("Processor", "we"), and the accommodation provider using Simple Guests ("Controller", "you"). It applies whenever we process personal data on your behalf, as required by Article 28 of the EU General Data Protection Regulation ("GDPR"). If this DPA and the Terms conflict on data protection, this DPA prevails.

1. Subject matter and duration#

We process guest personal data to provide Simple Guests: collecting guest registration data, digital check-in (ID scan, confirmation, signature and, where you enable it, the face check), submitting or keeping the records your configured authorities require, and sending check-in messages. Processing lasts for as long as you use the service, plus the retention periods in section 9.

2. Nature of the processing#

  • Data subjects: your guests (including members of a group booking), and people who contact your property through the Receptionist Agent if you enable it.
  • Personal data: identity document fields (name, document number and type, nationality, date of birth, sex, expiry, issuing country), document images, signatures, booking details (dates, party size, room), contact details used to send check-in links, and messages sent to the Receptionist Agent.
  • Special category data (optional): if you switch on the face check, a selfie and a photo of the guest's ID are compared to verify identity (biometric data under GDPR Article 9). This happens only with the guest's explicit consent. We delete both photos immediately after the comparison, and our storage removes any left behind after one day. We keep only the result, a match score, the number of attempts and when consent was given.
  • Processing operations: collection, storage, automated reading of documents (OCR), face comparison where enabled, transmission to authorities you configure, messaging, retention and deletion.

3. Your instructions#

We process personal data only on your documented instructions: this DPA, the Terms, and the settings you choose in the dashboard (for example which authorities to submit to, which messaging channels to use, and whether the face check or Receptionist Agent is on). If we believe an instruction breaks data protection law, we will tell you. If EU or Member State law requires us to process data otherwise, we will tell you first unless that law forbids it.

You are responsible for having a lawful basis for the processing, for giving guests the information they are entitled to, and — if you enable the face check — for keeping it genuinely optional, offering an in-person ID check instead, and carrying out any data protection impact assessment your law requires.

4. Confidentiality#

Everyone we authorise to process personal data is bound by confidentiality. Access to guest data is limited to what is needed to run, secure and support the service. Viewing guest documents in the dashboard, and any exceptional access across customer accounts by our team, is recorded in an audit log.

5. Security#

We apply technical and organisational measures appropriate to the risk (GDPR Article 32), including:

  • Encryption in transit (TLS) and at rest (encrypted database and storage).
  • Tenant isolation enforced in the database (row-level security), so one customer's records cannot be read in another's context.
  • Government portal credentials encrypted with AES-256-GCM envelope encryption; never written to logs.
  • Document and face-check photos held in private storage, uploaded through short-lived signed links, and removed automatically after one day.
  • Signed, expiring per-booking check-in links; rate limits and a regenerate option for property links.
  • Least-privilege access for staff and services, and audit logging of sensitive actions.
  • Automated retention jobs that anonymise guest records once their legal retention period ends.

6. Sub-processors#

You authorise us to use the sub-processors listed below. We impose data protection obligations on each of them that are at least as protective as this DPA, and we remain responsible for their performance. We will give you at least 30 days' notice before adding or replacing a sub-processor, by email to your account owner and by updating this page. If you object on reasonable data protection grounds, we will try to find an alternative; if we can't, you may end the affected part of the service without penalty.

Sub-processorPurposeLocationTransfer safeguard
Amazon Web Services EMEA SARL (AWS)API and background processing, document and photo storage, document reading (OCR), and the optional face check (Amazon Rekognition)EU — Ireland (eu-west-1)Within the EU. AI-services opt-out applied: content is not stored or used to improve AWS services.
Supabase Inc.Managed Postgres database holding guest registration and account recordsEU regionData stored in the EU; EU Standard Contractual Clauses for any remote access from outside the EU
Vercel Inc.Hosting of the guest check-in and staff web apps; check-in requests pass through its networkGlobal edge network (nearest location to the user)EU–US Data Privacy Framework and EU Standard Contractual Clauses
Postmark (ActiveCampaign, LLC)Transactional email — check-in links and staff account emailUnited StatesEU–US Data Privacy Framework and EU Standard Contractual Clauses
Stripe Payments Europe, Ltd.Subscription billing (staff and company billing data only — no guest data)EU / United StatesEU Standard Contractual Clauses
Meta Platforms Ireland Ltd. (WhatsApp Business Platform)Sending check-in links and, if enabled, Receptionist Agent messages over WhatsAppEU / United StatesEU–US Data Privacy Framework and EU Standard Contractual Clauses — only when you enable WhatsApp
Twilio Inc.Sending check-in links by SMSUnited StatesEU–US Data Privacy Framework and EU Standard Contractual Clauses — only when SMS is used
Anthropic, PBCDrafting answers to guests' questions for the Receptionist Agent add-onUnited StatesEU Standard Contractual Clauses — only when you enable the Receptionist Agent

Government authorities you configure (for example SES.HOSPEDAJES or the Mossos d'Esquadra) receive data because you are legally required to send it; they are recipients, not our sub-processors.

7. International transfers#

Guest data is stored in the EU. Where a sub-processor processes personal data outside the European Economic Area, the transfer is covered by an adequacy decision (such as the EU–US Data Privacy Framework) or by the European Commission's Standard Contractual Clauses, as shown in section 6.

8. Helping you#

  • Data subject requests: we will help you answer requests from guests (access, correction, erasure and so on), mainly through the dashboard, and forward any request we receive directly to you without answering it ourselves.
  • Personal data breaches: we will notify you without undue delay after becoming aware of a breach affecting your data, with the information you need to meet your own obligations, and keep you updated as we investigate.
  • Impact assessments and authorities: we will give you reasonable information to help with data protection impact assessments (including for the face check) and any consultation with a supervisory authority.

9. Deletion and return#

Guest records are kept for the retention period your jurisdiction requires (for example three years in Spain) and then anonymised automatically. When your subscription ends, you can ask us for a copy of your data; we then delete or anonymise guest personal data within 90 days, except where the law requires us to keep it for longer, in which case we keep it only for that purpose.

10. Audits#

We will make available the information needed to show compliance with this DPA and allow reasonable audits, by you or an independent auditor you appoint, with at least 30 days' notice, during business hours, no more than once a year (unless a supervisory authority requires it or a breach has occurred), and subject to confidentiality.

11. Liability, term and governing law#

Liability under this DPA is subject to the limits in the Terms of Service, except where the law does not allow them to be limited. This DPA lasts as long as we process personal data for you. It is governed by the laws of Estonia. Questions: hello@simpleguests.com.

SG

Simple Guests (simpleguests.com) is a platform operated by SMN Properties OÜ, a private limited company registered in Estonia.

Questions about this document: hello@simpleguests.com

SGSimple Guests

Simple Guests · Guest registration for hotels, hostels & Airbnbs

hello@simpleguests.com
Terms·Privacy