HOSTELELLA Legal documentation

Data Processing Agreement

Version 1.5 Effective 27 June 2026 Art. 28 GDPR

1. Parties and scope

This Data Processing Agreement ("DPA") forms part of HOSTELELLA's Terms and governs the processing of personal data that HERMANOS VARELA LUIS SL ("HOSTELELLA") carries out on behalf of the Customer when providing the Service.

Processor: HERMANOS VARELA LUIS SL, Tax ID (CIF) B67073320, Travessera de les Corts 356, Local 2, 08029 Barcelona, Spain.
Commercial Registry: Barcelona Commercial Registry, Section 8, Sheet B-509004, entry 4 (I/A 4); background: Volume 46087, Folio 53.
Legal contact: legal@hostelella.com
Controller: the business Customer that uses or contracts HOSTELELLA.

Acceptance of the Terms or of HOSTELELLA's legal flow implies acceptance of this DPA by the Customer when carried out by a person with sufficient authority to bind it. Users without such authority accept their obligations of use, confidentiality, security and compliance to the maximum extent permitted by law, without replacing the Customer's responsibility as Controller.

2. Roles

For personal data contained in documents, records, messages, staff/shift data or business information uploaded or configured by the Customer, the Customer acts as Controller and HOSTELELLA as Processor. HOSTELELLA acts as an independent Controller for accounts, security, billing, support and Service communications.

3. Subject matter, duration and nature of processing

Subject matterProvision of a B2B SaaS platform for operational, document, analytical, team and shift management.
DurationFor as long as there is an account, contract or use of the Service, plus the retention periods defined by law, the DPA, retention or valid Customer instructions.
NatureHosting, storage, consultation, classification, OCR/AI extraction, AI-assisted shift generation, transformation, transmission, support, backup, security and deletion.
PurposeTo provide, maintain, protect and support the Service in accordance with the Customer's instructions and the Terms. Service improvement does not authorize training AI models with Customer Data unless under express authorization or specific contract.

4. Categories of data subjects and data

Data subjectsCustomer users, employees and workers (including, where applicable, lawfully employed minors), candidates or collaborators, customers, suppliers, professional contacts, representatives and other third parties included in the Customer's documents or records.
DataIdentification, professional contact, role, labor and workforce-planning data (contract hours and type, department/area, minimum rest, availability, shift-band preferences, minor-age indicator, shifts, clock-ins/attendance and absences/time off), commercial/accounting documents, amounts, taxes, orders, communications, technical metadata, logs and data needed for security.
Special categoriesThe Service is not generally designed to process special categories under Article 9 GDPR. However, absence management may include sick leave that reveals data concerning health. In that case, the Customer must have an adequate legal basis (typically Art. 9.2.b GDPR) and apply safeguards; HOSTELELLA minimizes such data and does not transmit the reason/type of the absence to AI providers. The Customer must not record diagnoses or clinical details in free-text fields.

5. Customer instructions

HOSTELELLA will process personal data only in accordance with: (i) the Terms and this DPA, (ii) the Customer's configuration and actions, (iii) reasonable documented instructions, and (iv) applicable legal obligations. HOSTELELLA will inform the Customer if it considers that an instruction infringes data-protection law, unless legally prohibited.

Instructions must be in writing or by verifiable means, including Service configuration, support tickets, order forms, contracts or communications from an authorized administrator. HOSTELELLA may refuse instructions that are unreasonable, insecure, unlawful, incompatible with the Service architecture or that compromise other customers.

6. Customer obligations

7. Authorized personnel and confidentiality

HOSTELELLA will limit access to authorized personnel who need to process data to provide or protect the Service. Such personnel will be subject to contractual or statutory confidentiality obligations.

8. Security measures

HOSTELELLA will apply technical and organizational measures appropriate to the risk, including access control, least privilege, encryption in transit, secrets management, activity logging, monitoring, backups, continuity, logical segregation and an incident response process. The Security Policy describes the main measures and is incorporated by reference.

Measures may evolve to improve security, compliance or resilience, always maintaining a level of protection that is not materially lower for data processed as a processor.

9. Automated processing and artificial intelligence

Where the Customer enables AI features (e.g., document extraction, the assistant or AI-assisted shift generation), HOSTELELLA will process data on behalf of the Customer and in accordance with these safeguards:

10. Sub-processors

The Customer authorizes HOSTELELLA to use sub-processors to provide the Service, provided they are subject to substantially equivalent data-protection obligations and, at a minimum, to those required by Article 28 GDPR. The main list is maintained in the Sub-processors Annex, which includes, among others, the AI providers used when the corresponding features are enabled.

HOSTELELLA will notify material changes in sub-processors at least thirty (30) days in advance where reasonably possible. For urgent changes due to security, continuity or provider replacement, notification may be given as soon as feasible. The Customer may object on substantiated data-protection grounds within ten (10) business days of notification; if the objection prevents provision of the Service, the parties will cooperate to find a reasonable alternative or terminate the affected service. HOSTELELLA remains liable to the Customer for the sub-processors' compliance under the GDPR.

11. International transfers

Where an international transfer outside the EEA occurs, HOSTELELLA will apply a valid mechanism under Articles 44 to 49 GDPR, including adequacy decisions, Standard Contractual Clauses, the EU-US Data Privacy Framework where applicable and supplementary measures where appropriate. For processor-to-sub-processor transfers, the corresponding SCC module or another valid mechanism will apply. Certain AI and communications providers are located in the United States.

12. Assistance to the Customer

Taking into account the nature of the processing, HOSTELELLA will reasonably assist the Customer with:

13. Personal data breaches

HOSTELELLA will notify the Customer without undue delay after becoming aware of a personal data breach affecting data processed as a processor. HOSTELELLA will aim to provide an initial notification within forty-eight (48) hours where reasonably possible. The notification will include the information reasonably available and may be completed in phases.

14. Deletion and return

Upon termination of the service, HOSTELELLA will delete or return data processed as a processor in accordance with the Customer's reasonable instructions, except for retention required by law, security, audit, fraud prevention or defense of claims. Deletion of backups will follow the technical backup cycle, normally up to ninety (90) days unless legal retention, incident investigation or a documented technical limitation applies.

15. Audits

HOSTELELLA will make available reasonable information to demonstrate compliance with this DPA. Direct audits must be requested with reasonable notice, be limited to what is necessary, not compromise the security or confidentiality of other customers and may be subject to reasonable costs. Except for a relevant incident or authority requirement, no more than one direct audit per calendar year will be carried out.

16. Liability

Liability arising from this DPA is governed by the liability limits of the Terms, unless applicable law imposes a different regime. The Customer is responsible for the instructions, data and legal bases it determines as Controller, as well as for compliance with labor law and the information obligations arising from the use of AI features in the employment context.