Host Logic
  • Login Register
Home › Trust Center › Data Processing Agreement

Data Processing Agreement (DPA)

Effective date: 10 August 2026 Version: 1.0

Notice of amendment (10 August 2026). Section 4 gains an instruction covering anonymisation, and Section 9 gains a corresponding exception for anonymised data. This amendment takes effect on publication and replaces the previous version of this DPA, effective 14 June 2026.

This Data Processing Agreement ("DPA") forms part of the Terms of Service ("Agreement") between HOST LOGIC LIMITED ("Host Logic", "Processor", "we", "us") and the customer that accepts the Agreement ("Customer", "Controller", "you"). It governs the processing of personal data carried out by Host Logic on the Customer's behalf in the course of providing the Host Logic platform and services (the "Services").

Where the Customer acts as a controller of personal data and Host Logic processes that data on the Customer's documented instructions, this DPA applies and reflects the parties' obligations under Article 28 of Regulation (EU) 2016/679 ("GDPR") and the UK GDPR. In case of conflict between this DPA and the Agreement on matters of data protection, this DPA prevails.

1. Roles of the Parties

For personal data that the Customer submits to or generates through the Services (including guest contact details and communications), the Customer is the controller and Host Logic is the processor. Where the Customer is itself a processor acting on behalf of a third-party controller, Host Logic is a sub-processor. Host Logic acts as an independent controller only for limited account, billing, security, and service-improvement data, as described in our Privacy Policy.

2. Subject Matter, Duration, Nature and Purpose

  • Subject matter: processing of personal data necessary to provide the Services.
  • Duration: the term of the Agreement, plus any period required for deletion or return of data under Section 9.
  • Nature and purpose: hosting, storage, transmission, automated communication, AI-assisted classification and response generation, analytics, and related processing operations performed to deliver the Services.

3. Categories of Data Subjects and Personal Data

Data subjects may include: the Customer's staff and authorised users, and the Customer's guests or end-customers.

Categories of personal data may include: names, email addresses, phone numbers, reservation and stay details, message and communication content, and technical identifiers (such as IP address). Host Logic does not require special categories of personal data (Article 9 GDPR) to deliver the Services and instructs Customers not to submit them unless separately agreed in writing.

4. Customer Instructions

Host Logic processes personal data only on the Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by EU or Member State law (in which case Host Logic will inform the Customer, unless legally prohibited). The Agreement, this DPA, and the configuration choices made by the Customer through the Services constitute the Customer's complete and final instructions. Host Logic will inform the Customer if, in its opinion, an instruction infringes applicable data protection law.

The Customer additionally instructs Host Logic to create anonymised and aggregated data from the personal data processed under this DPA, using techniques designed to ensure that the resulting data is no longer personal data within the meaning of Article 4(1) GDPR. Such anonymisation is carried out as part of the provision of the Services. The resulting anonymised data is not personal data and is governed by Section 4.3 of the Terms of Service.

5. Confidentiality

Host Logic ensures that persons authorised to process the personal data are bound by appropriate confidentiality obligations and are granted access on a least-privilege, need-to-know basis.

6. Security of Processing (Article 32)

Host Logic implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • encryption of personal data in transit (TLS 1.2+) and at rest (AES-256);
  • strict access controls, authentication, and least-privilege service accounts;
  • runtime secret management with no plaintext credentials stored in application code;
  • separation of development, staging, and production environments;
  • continuous monitoring, alerting, and audit logging;
  • regular review of the effectiveness of these measures.

7. Subprocessors

The Customer provides general authorisation for Host Logic to engage subprocessors to support the provision of the Services. A current list of subprocessors is published at hostlogic.io/legal/subprocessor_list. Host Logic imposes data protection obligations on each subprocessor that are no less protective than those in this DPA and remains responsible for each subprocessor's performance.

Host Logic will give notice of any intended addition or replacement of a subprocessor, giving the Customer the opportunity to object on reasonable data-protection grounds by contacting [email protected].

8. Data Subject Rights, Assistance and Breach Notification

Taking into account the nature of the processing, Host Logic assists the Customer with appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights under Chapter III GDPR, and to comply with the Customer's obligations under Articles 32 to 36 (security, breach notification, and data protection impact assessments).

Host Logic notifies the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, and provides the information reasonably required for the Customer to meet its own notification obligations.

9. Return and Deletion of Data

Upon termination of the Services, or earlier on the Customer's request, Host Logic deletes or returns all personal data processed on the Customer's behalf and deletes existing copies, unless EU or Member State law requires continued storage. Account holders can trigger immediate deletion and anonymisation directly from the account settings page; the deletion process is described in Section 8 of the Privacy Policy.

This Section does not apply to anonymised and aggregated data created in accordance with Section 4, which is not personal data and which Host Logic may continue to retain and use after termination.

10. Audits

Host Logic makes available to the Customer information reasonably necessary to demonstrate compliance with Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to reasonable confidentiality and security arrangements and reasonable notice. Host Logic may satisfy audit requests by providing relevant third-party certifications or assessment reports where available.

11. International Data Transfers

Where the provision of the Services involves the transfer of personal data outside the EEA or the UK, such transfers are made subject to an appropriate transfer mechanism, including the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum (IDTA), or another lawful safeguard, together with any supplementary measures required.

12. Liability and Governing Law

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement. This DPA is governed by the laws of Ireland, and the courts of Ireland have exclusive jurisdiction, without prejudice to mandatory data-subject rights under the GDPR.

13. Contact

HOST LOGIC LIMITED
Venture Hub, 136 Capel Street, Dublin, D01 T2C9, Ireland
CRO No. 809382
[email protected]

Host Logic

AI-powered automation for property managers and hospitality operators.

Legal

  • Terms of Service
  • Privacy Policy
  • DPA
  • Trust Center

© 2026 HOST LOGIC LIMITED. CRO No. 809382. Registered in Ireland.