Data Processing Agreement
1. Parties and scope
This Data Processing Agreement ("DPA") forms part of HOSTELELLA's Terms and governs the processing of personal data that HERMANOS VARELA LUIS SL ("HOSTELELLA") carries out on behalf of the Customer when providing the Service.
Processor: HERMANOS VARELA LUIS SL, Tax ID (CIF) B67073320, Travessera de les Corts 356, Local 2, 08029 Barcelona, Spain.
Commercial Registry: Barcelona Commercial Registry, Section 8, Sheet B-509004, entry 4 (I/A 4); background: Volume 46087, Folio 53.
Legal contact: legal@hostelella.com
Controller: the business Customer that uses or contracts HOSTELELLA.
Acceptance of the Terms or of HOSTELELLA's legal flow implies acceptance of this DPA by the Customer when carried out by a person with sufficient authority to bind it. Users without such authority accept their obligations of use, confidentiality, security and compliance to the maximum extent permitted by law, without replacing the Customer's responsibility as Controller.
2. Roles
For personal data contained in documents, records, messages, staff/shift data or business information uploaded or configured by the Customer, the Customer acts as Controller and HOSTELELLA as Processor. HOSTELELLA acts as an independent Controller for accounts, security, billing, support and Service communications.
3. Subject matter, duration and nature of processing
| Subject matter | Provision of a B2B SaaS platform for operational, document, analytical, team and shift management. |
|---|---|
| Duration | For as long as there is an account, contract or use of the Service, plus the retention periods defined by law, the DPA, retention or valid Customer instructions. |
| Nature | Hosting, storage, consultation, classification, OCR/AI extraction, AI-assisted shift generation, transformation, transmission, support, backup, security and deletion. |
| Purpose | To provide, maintain, protect and support the Service in accordance with the Customer's instructions and the Terms. Service improvement does not authorize training AI models with Customer Data unless under express authorization or specific contract. |
4. Categories of data subjects and data
| Data subjects | Customer users, employees and workers (including, where applicable, lawfully employed minors), candidates or collaborators, customers, suppliers, professional contacts, representatives and other third parties included in the Customer's documents or records. |
|---|---|
| Data | Identification, professional contact, role, labor and workforce-planning data (contract hours and type, department/area, minimum rest, availability, shift-band preferences, minor-age indicator, shifts, clock-ins/attendance and absences/time off), commercial/accounting documents, amounts, taxes, orders, communications, technical metadata, logs and data needed for security. |
| Special categories | The Service is not generally designed to process special categories under Article 9 GDPR. However, absence management may include sick leave that reveals data concerning health. In that case, the Customer must have an adequate legal basis (typically Art. 9.2.b GDPR) and apply safeguards; HOSTELELLA minimizes such data and does not transmit the reason/type of the absence to AI providers. The Customer must not record diagnoses or clinical details in free-text fields. |
5. Customer instructions
HOSTELELLA will process personal data only in accordance with: (i) the Terms and this DPA, (ii) the Customer's configuration and actions, (iii) reasonable documented instructions, and (iv) applicable legal obligations. HOSTELELLA will inform the Customer if it considers that an instruction infringes data-protection law, unless legally prohibited.
Instructions must be in writing or by verifiable means, including Service configuration, support tickets, order forms, contracts or communications from an authorized administrator. HOSTELELLA may refuse instructions that are unreasonable, insecure, unlawful, incompatible with the Service architecture or that compromise other customers.
6. Customer obligations
- Have a legal basis and comply with information duties regarding employees, workers, customers, suppliers and third parties.
- Comply with the labor law applicable to shift planning (working hours, rest, night work, protection of minors) and, where there is workers' legal representation, inform it of the parameters, rules and instructions of the algorithmic or AI systems that affect working conditions (Art. 64.4.d of the Workers' Statute).
- Not upload unnecessary, unlawful, excessive or specially sensitive data without a legal basis and safeguards.
- Configure roles, permissions and access in accordance with the least-privilege principle.
- Apply the required human review to AI-generated proposals before their publication or application, and not use them as the sole basis for decisions with significant effect on individuals.
- Handle data-subject rights when HOSTELELLA acts as a processor.
- Keep its own copies or exports where law or operational risk requires.
7. Authorized personnel and confidentiality
HOSTELELLA will limit access to authorized personnel who need to process data to provide or protect the Service. Such personnel will be subject to contractual or statutory confidentiality obligations.
8. Security measures
HOSTELELLA will apply technical and organizational measures appropriate to the risk, including access control, least privilege, encryption in transit, secrets management, activity logging, monitoring, backups, continuity, logical segregation and an incident response process. The Security Policy describes the main measures and is incorporated by reference.
Measures may evolve to improve security, compliance or resilience, always maintaining a level of protection that is not materially lower for data processed as a processor.
9. Automated processing and artificial intelligence
Where the Customer enables AI features (e.g., document extraction, the assistant or AI-assisted shift generation), HOSTELELLA will process data on behalf of the Customer and in accordance with these safeguards:
- Decision support with human review: AI features are assistance tools; shift proposals require approval by a person with a manager role or above. No solely automated decisions with legal or significant effects within the meaning of Art. 22 GDPR are made.
- Minimization and pseudonymization: before sending information to AI providers, unnecessary data is excluded and, where possible, data is pseudonymized (e.g., the shift generator operates with initials and operational data, not full names; the reason/type of absences is not transmitted).
- No training: HOSTELELLA does not use Customer Data to train its own or third parties' models, unless under express authorization or specific contract. AI sub-processors are contractually subject to no-training controls over commercial data.
- AI framework (EU 2024/1689): where an AI feature is used in the employment context, the Customer acts as the deployer and must ensure lawful use, human oversight and information to affected persons and their legal representation.
10. Sub-processors
The Customer authorizes HOSTELELLA to use sub-processors to provide the Service, provided they are subject to substantially equivalent data-protection obligations and, at a minimum, to those required by Article 28 GDPR. The main list is maintained in the Sub-processors Annex, which includes, among others, the AI providers used when the corresponding features are enabled.
HOSTELELLA will notify material changes in sub-processors at least thirty (30) days in advance where reasonably possible. For urgent changes due to security, continuity or provider replacement, notification may be given as soon as feasible. The Customer may object on substantiated data-protection grounds within ten (10) business days of notification; if the objection prevents provision of the Service, the parties will cooperate to find a reasonable alternative or terminate the affected service. HOSTELELLA remains liable to the Customer for the sub-processors' compliance under the GDPR.
11. International transfers
Where an international transfer outside the EEA occurs, HOSTELELLA will apply a valid mechanism under Articles 44 to 49 GDPR, including adequacy decisions, Standard Contractual Clauses, the EU-US Data Privacy Framework where applicable and supplementary measures where appropriate. For processor-to-sub-processor transfers, the corresponding SCC module or another valid mechanism will apply. Certain AI and communications providers are located in the United States.
12. Assistance to the Customer
Taking into account the nature of the processing, HOSTELELLA will reasonably assist the Customer with:
- exercise of data-subject rights;
- security of processing and personal data breaches;
- impact assessments and prior consultations where necessary, including, where applicable, assessment of AI use in the employment context;
- reasonable deletion, export or return of data.
13. Personal data breaches
HOSTELELLA will notify the Customer without undue delay after becoming aware of a personal data breach affecting data processed as a processor. HOSTELELLA will aim to provide an initial notification within forty-eight (48) hours where reasonably possible. The notification will include the information reasonably available and may be completed in phases.
14. Deletion and return
Upon termination of the service, HOSTELELLA will delete or return data processed as a processor in accordance with the Customer's reasonable instructions, except for retention required by law, security, audit, fraud prevention or defense of claims. Deletion of backups will follow the technical backup cycle, normally up to ninety (90) days unless legal retention, incident investigation or a documented technical limitation applies.
15. Audits
HOSTELELLA will make available reasonable information to demonstrate compliance with this DPA. Direct audits must be requested with reasonable notice, be limited to what is necessary, not compromise the security or confidentiality of other customers and may be subject to reasonable costs. Except for a relevant incident or authority requirement, no more than one direct audit per calendar year will be carried out.
16. Liability
Liability arising from this DPA is governed by the liability limits of the Terms, unless applicable law imposes a different regime. The Customer is responsible for the instructions, data and legal bases it determines as Controller, as well as for compliance with labor law and the information obligations arising from the use of AI features in the employment context.