Skip to content

DATA PROCESSING AGREEMENT

Data Processing Agreement

Last updated: August 1, 2026

This Data Processing Agreement (“DPA”) forms part of the ConcierBot Terms of Service between the operator of ConcierBot (“Processor”, “we”) and the customer (“Controller”, “you”) and applies to the processing of personal data carried out by us on your behalf through the Service. Where the Controller is subject to the EU General Data Protection Regulation (GDPR) or UK GDPR, this DPA reflects the requirements of Article 28 GDPR. In case of conflict between this DPA and the Terms of Service on data protection matters, this DPA prevails.

1. Definitions and roles

  1. Terms such as “personal data”, “processing”, “data subject”, “controller”, “processor”, “subprocessor”, and “personal data breach” have the meanings given in the GDPR.
  2. As between the parties, the Controller (the lodging operator) determines the purposes and means of processing guest personal data and is the controller. ConcierBot processes that personal data only on the Controller’s behalf and is the processor.
  3. Each party complies with its respective obligations under applicable data protection law.

2. Details of the processing (Annex A)

Subject matter

Provision of the ConcierBot AI concierge and guest-guide service to the Controller.

Duration

For the term of the Terms of Service, until deletion or return of personal data in accordance with Section 9.

Nature and purpose of processing

Hosting, storage, organization, generation of guest-facing content and translations, delivery of AI chat responses, and related operations necessary to provide the Service.

Types of personal data

  • Guest chat inputs (question text) submitted to the AI assistant;
  • Access logs (IP address, browser information, access date and time);
  • Language preference;
  • Where the Controller enables the guest registration ledger feature (supporting recordkeeping under Japan's Hotel Business Act / 旅館業法): guest full name, and, where the Controller additionally enables the field, address, occupation, phone number, email address, and number of guests; for guests identifying as non-Japanese nationals, nationality and passport number; and a handwritten signature image, where the Controller enables signature collection;
  • Where the Controller enables guest commerce (in-room ordering, activity bookings, and similar): order details (items, quantity, delivery/pickup method and time), order amount, payment status, guest name, guest email, room name, and order notes;
  • Where the Controller connects a property management system or otherwise records reservations: reservation details such as guest name, contact information, country, language, number of guests, and stay dates, and, where applicable, pet-related details and a signed pet agreement including a signature image;
  • Any additional personal data the Controller chooses to submit to the Service.

Categories of data subjects

  • Guests of the Controller’s property who use the guest page or AI assistant;
  • The Controller’s admin users and staff.

3. Processor obligations

ConcierBot will:

  1. process personal data only on the Controller’s documented instructions, including with regard to international transfers, unless required to do otherwise by applicable law (in which case we will inform the Controller unless legally prohibited). The Terms of Service and this DPA constitute the Controller’s documented instructions;
  2. ensure that persons authorized to process the personal data are bound by confidentiality obligations;
  3. implement appropriate technical and organizational security measures as required by Article 32 GDPR (see Section 4);
  4. respect the conditions for engaging subprocessors set out in Section 5;
  5. assist the Controller, taking into account the nature of the processing, in responding to data subject requests (Section 6);
  6. assist the Controller in ensuring compliance with Articles 32–36 GDPR (security, breach notification, and data protection impact assessments), taking into account the information available to us;
  7. at the Controller’s choice, delete or return personal data after the end of the provision of services (Section 9); and
  8. make available to the Controller information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits (Section 10).

We will inform the Controller if, in our opinion, an instruction infringes the GDPR or other applicable data protection law.

4. Security measures

Taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing, we implement appropriate technical and organizational measures, including as appropriate:

  • encryption of personal data in transit (TLS/SSL);
  • hashed storage of authentication credentials;
  • access controls to databases and administrative systems;
  • logging and monitoring of access;
  • measures to restore availability and access to personal data in a timely manner in the event of an incident; and
  • a process for regularly reviewing the effectiveness of these measures.

Guest GPS location data is processed only in the browser for distance calculation and is not stored on our servers.

5. Subprocessors

  1. The Controller provides general authorization for ConcierBot to engage subprocessors to provide the Service, subject to this Section.
  2. We impose data protection obligations on subprocessors that are substantially equivalent to those in this DPA, and remain liable to the Controller for a subprocessor’s performance of its obligations.
  3. A current list of subprocessors is available on request. We will give the Controller notice of the addition or replacement of a subprocessor, giving the Controller the opportunity to object on reasonable data protection grounds.

Current subprocessors

  • Anthropic PBC (United States) — AI chat assistant, generation of guest-facing content and translations; guest chat text is processed.
  • Google LLC (United States; global infrastructure) — Places API / Geocoding API for nearby-place information (the property address is processed).
  • Stripe, Inc. (United States) — subscription billing for the Controller and, where the Controller enables online guest payments, processing of guest card payments; card data is handled directly by Stripe.
  • Vercel Inc. (United States) — application hosting and compute; compute region configured to Tokyo, Japan.
  • Neon, Inc. (database hosted on AWS in Singapore, region ap-southeast-1) — primary database; this is where the personal data described in Annex A is stored.
  • Upstash, Inc. (United States) — Redis-compatible cache used for rate limiting and short-lived session data.
  • Resend, Inc. (United States) — delivery of transactional email.
  • Sentry (Functional Software, Inc., United States) — error monitoring.

This list reflects the subprocessors we use as of the date of this DPA. A current list is available on request, and we will give notice of material additions or replacements as described above.

6. Assistance with data subject rights

Taking into account the nature of the processing, we assist the Controller by appropriate technical and organizational measures, insofar as possible, in fulfilling the Controller’s obligation to respond to requests to exercise data subject rights (access, rectification, erasure, restriction, portability, and objection). Where a data subject contacts us directly, we will, unless legally required to act, refer the request to the Controller.

7. Personal data breach

We notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s personal data, and provide the Controller with information reasonably available to us to assist the Controller in meeting its obligations under Articles 33 and 34 GDPR (including the nature of the breach, likely consequences, and measures taken or proposed).

8. International transfers

Our application compute (Vercel) runs in Tokyo, Japan. The primary database in which personal data is stored is hosted in Singapore, operated by our database subprocessor, Neon, on AWS infrastructure (AWS region ap-southeast-1). Singapore has not received an adequacy decision from the European Commission or the UK.

Personal data is also processed by subprocessors located outside Japan, principally in the United States (see Section 5 for the list and role of each subprocessor). Transfers of personal data from the EEA and UK to Singapore, the United States, or any other country without an adequacy decision are made under the European Commission’s Standard Contractual Clauses (SCC, 2021, Module Two: controller-to-processor / Module Three: processor-to-processor, as applicable to each subprocessor), together with any supplementary measures required, which are incorporated into this DPA by reference. For UK transfers, the UK International Data Transfer Addendum (IDTA) applies.

9. Deletion and return of data

At the Controller’s choice, we delete or return all personal data to the Controller after the end of the provision of services, and delete existing copies, unless applicable law requires storage of the personal data. The Controller can also delete data from the admin dashboard during the term.

10. Audits and information

We make available to the Controller information necessary to demonstrate compliance with Article 28 GDPR. On reasonable prior written request, and no more than once per year (unless required by a supervisory authority or following a personal data breach), we will contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, subject to reasonable confidentiality and security conditions. Where available, we may satisfy audit requests by providing relevant third-party certifications or reports.

11. Term, liability, and general

  1. This DPA takes effect together with the Terms of Service and continues for as long as we process personal data on the Controller’s behalf.
  2. Each party’s liability under this DPA is subject to the limitations of liability set out in the Terms of Service.
  3. This DPA is governed by the same law and jurisdiction as the Terms of Service, except where the SCC or mandatory data protection law require otherwise.
  4. To request a countersigned copy of this DPA or the current subprocessor list, contact contact@concierbot.com.

ConcierBot — Data Protection

Email: contact@concierbot.com

Data Processing Agreement (DPA) / データ処理契約 | ConcierBot