1. Definitions and roles
- Terms such as “personal data”, “processing”, “data subject”, “controller”, “processor”, “subprocessor”, and “personal data breach” have the meanings given in the GDPR.
- As between the parties, the Controller (the lodging operator) determines the purposes and means of processing guest personal data and is the controller. ConcierBot processes that personal data only on the Controller’s behalf and is the processor.
- Each party complies with its respective obligations under applicable data protection law.
2. Details of the processing (Annex A)
Subject matter
Provision of the ConcierBot AI concierge and guest-guide service to the Controller.
Duration
For the term of the Terms of Service, until deletion or return of personal data in accordance with Section 9.
Nature and purpose of processing
Hosting, storage, organization, generation of guest-facing content and translations, delivery of AI chat responses, and related operations necessary to provide the Service.
Types of personal data
- Guest chat inputs (question text) submitted to the AI assistant;
- Access logs (IP address, browser information, access date and time);
- Language preference;
- Any additional personal data the Controller chooses to submit to the Service.
Categories of data subjects
- Guests of the Controller’s property who use the guest page or AI assistant;
- The Controller’s admin users and staff.
3. Processor obligations
ConcierBot will:
- process personal data only on the Controller’s documented instructions, including with regard to international transfers, unless required to do otherwise by applicable law (in which case we will inform the Controller unless legally prohibited). The Terms of Service and this DPA constitute the Controller’s documented instructions;
- ensure that persons authorized to process the personal data are bound by confidentiality obligations;
- implement appropriate technical and organizational security measures as required by Article 32 GDPR (see Section 4);
- respect the conditions for engaging subprocessors set out in Section 5;
- assist the Controller, taking into account the nature of the processing, in responding to data subject requests (Section 6);
- assist the Controller in ensuring compliance with Articles 32–36 GDPR (security, breach notification, and data protection impact assessments), taking into account the information available to us;
- at the Controller’s choice, delete or return personal data after the end of the provision of services (Section 9); and
- make available to the Controller information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits (Section 10).
We will inform the Controller if, in our opinion, an instruction infringes the GDPR or other applicable data protection law.
4. Security measures
Taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing, we implement appropriate technical and organizational measures, including as appropriate:
- encryption of personal data in transit (TLS/SSL);
- hashed storage of authentication credentials;
- access controls to databases and administrative systems;
- logging and monitoring of access;
- measures to restore availability and access to personal data in a timely manner in the event of an incident; and
- a process for regularly reviewing the effectiveness of these measures.
Guest GPS location data is processed only in the browser for distance calculation and is not stored on our servers.
5. Subprocessors
- The Controller provides general authorization for ConcierBot to engage subprocessors to provide the Service, subject to this Section.
- We impose data protection obligations on subprocessors that are substantially equivalent to those in this DPA, and remain liable to the Controller for a subprocessor’s performance of its obligations.
- A current list of subprocessors is available on request. We will give the Controller notice of the addition or replacement of a subprocessor, giving the Controller the opportunity to object on reasonable data protection grounds.
Current subprocessors (categories)
- AI / LLM providers — generation of guest content, translations, and AI chat responses (guest chat text is processed);
- Payment processing — subscription billing for the Controller (guest payment card data, where online guest payments are enabled, is handled directly by the payment processor);
- Cloud hosting and database infrastructure — hosting and storage of the Service and its data.
6. Assistance with data subject rights
Taking into account the nature of the processing, we assist the Controller by appropriate technical and organizational measures, insofar as possible, in fulfilling the Controller’s obligation to respond to requests to exercise data subject rights (access, rectification, erasure, restriction, portability, and objection). Where a data subject contacts us directly, we will, unless legally required to act, refer the request to the Controller.
7. Personal data breach
We notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s personal data, and provide the Controller with information reasonably available to us to assist the Controller in meeting its obligations under Articles 33 and 34 GDPR (including the nature of the breach, likely consequences, and measures taken or proposed).
8. International transfers
Personal data is processed on servers in Japan. Japan has received an adequacy decision from the European Commission (January 2019), providing a lawful basis for transfers from the EEA.
Where personal data is transferred to a subprocessor in a country without an adequacy decision (for example, the United States, for AI processing), such transfers are made under the European Commission’s Standard Contractual Clauses (SCC, 2021, Module Two: controller-to-processor / processor-to-processor as applicable), together with any supplementary measures required, which are incorporated into this DPA by reference. For UK transfers, the UK International Data Transfer Addendum applies.
9. Deletion and return of data
At the Controller’s choice, we delete or return all personal data to the Controller after the end of the provision of services, and delete existing copies, unless applicable law requires storage of the personal data. The Controller can also delete data from the admin dashboard during the term.
10. Audits and information
We make available to the Controller information necessary to demonstrate compliance with Article 28 GDPR. On reasonable prior written request, and no more than once per year (unless required by a supervisory authority or following a personal data breach), we will contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, subject to reasonable confidentiality and security conditions. Where available, we may satisfy audit requests by providing relevant third-party certifications or reports.
11. Term, liability, and general
- This DPA takes effect together with the Terms of Service and continues for as long as we process personal data on the Controller’s behalf.
- Each party’s liability under this DPA is subject to the limitations of liability set out in the Terms of Service.
- This DPA is governed by the same law and jurisdiction as the Terms of Service, except where the SCC or mandatory data protection law require otherwise.
- To request a countersigned copy of this DPA or the current subprocessor list, contact contact@concierbot.com.
ConcierBot — Data Protection
Email: contact@concierbot.com