Data Processing Agreement
1. Parties and scope
This Data Processing Agreement ("DPA") forms part of HOSTELELLA's Terms and governs the processing of personal data that HERMANOS VARELA LUIS SL ("HOSTELELLA") carries out on behalf of the Customer when providing the Service.
Processor: HERMANOS VARELA LUIS SL, Tax ID (CIF) B67073320, Travessera de les Corts 356, 08029 Barcelona, Spain.
Commercial Registry: Barcelona Commercial Registry, Section 8, Sheet B-509004, entry 4 (I/A 4); background: Volume 46087, Folio 53.
Legal contact: legal@hostelella.com
Controller: the business Customer that uses or contracts HOSTELELLA.
Acceptance of the Terms or of HOSTELELLA's legal flow implies acceptance of this DPA by the Customer when carried out by a person with sufficient authority to bind it. Users without such authority accept their obligations of use, confidentiality, security and compliance to the maximum extent permitted by law, without replacing the Customer's responsibility as Controller.
2. Roles
For personal data contained in documents, records, messages, staff/shift data or business information uploaded or configured by the Customer, the Customer acts as Controller and HOSTELELLA as Processor. HOSTELELLA acts as an independent Controller for accounts, security, trials, subscriptions, billing, payments, fraud prevention, support and Service communications. Data processed by Stripe to charge HOSTELELLA or the Customer does not, for that reason alone, become Customer Data subject to this DPA; Stripe's role depends on the specific activity and is described in the Privacy Policy and Sub-processors Annex.
HOSTELELLA's own marketing. When HOSTELELLA writes to a user about its own product — news, tips, offers — it acts as an independent Controller, with that person's consent and outside the scope of this DPA. That activity is never fed by Customer Data: not by documents, not by the registered team, not by shifts, clock-ins, suppliers, products or amounts. The only source of recipients is the person's voluntary registration and their express opt-in in the preference centre.
Emails the Customer sends from the platform. Purchase orders and claims the Customer addresses to its suppliers through the Service are processed on the Customer's behalf and under its instruction. The Customer is the actual sender and is responsible for the lawfulness of those messages towards their recipients; HOSTELELLA does not turn them into its own communications and does not use them for any commercial purpose.
3. Subject matter, duration and nature of processing
| Subject matter | Provision of a B2B SaaS platform for operational, document, analytical, team and shift management. |
|---|---|
| Duration | For as long as there is an account, contract or use of the Service, plus the retention periods defined by law, the DPA, retention or valid Customer instructions. |
| Nature | Hosting, storage, consultation, classification, OCR/AI extraction, AI-assisted shift generation, transformation, transmission, support, backup, security and deletion. |
| Purpose | To provide, maintain, protect and support the Service in accordance with the Customer's instructions and the Terms. Improvement within the mandate is limited to those instructions. General product improvement uses only minimal telemetry or demonstrably anonymous/aggregated data and does not authorize repurposing Customer personal data or training AI models. |
4. Categories of data subjects and data
| Data subjects | Customer users, employees and workers (including, where applicable, lawfully employed minors), candidates or collaborators, customers, suppliers, professional contacts, representatives and other third parties included in the Customer's documents or records. |
|---|---|
| Data | Identification, professional contact, role, labor and workforce-planning data (contract hours and type, department/area, minimum rest, availability, shift-band preferences, minor-age indicator, shifts, clock-ins/attendance — including, where the Customer enables presence verification at clock-in/out, the result of that verification (inside/outside and approximate distance), without the worker's coordinates — and absences/time off), commercial/accounting documents, amounts, taxes, orders, communications, technical metadata, logs and data needed for security. |
| Special categories | The Service is not generally designed to process special categories under Article 9 GDPR. However, absence management may include sick leave that reveals data concerning health. In that case, the Customer must have an adequate legal basis (typically Art. 9.2.b GDPR) and apply safeguards; HOSTELELLA minimizes such data and does not transmit the reason/type of the absence to AI providers. The Customer must not record diagnoses or clinical details in free-text fields. |
5. Customer instructions
HOSTELELLA will process personal data only in accordance with: (i) the Terms and this DPA, (ii) the Customer's configuration and actions, (iii) reasonable documented instructions, and (iv) applicable legal obligations. HOSTELELLA will inform the Customer if it considers that an instruction infringes data-protection law, unless legally prohibited.
Instructions must be in writing or by verifiable means, including Service configuration, support tickets, order forms, contracts or communications from an authorized administrator. HOSTELELLA may refuse instructions that are unreasonable, insecure, unlawful, incompatible with the Service architecture or that compromise other customers.
5.1 Additional instructions: protected learning (not available)
HOSTELELLA is designing a protected learning feature whereby the Customer could instruct that aggregated signals about the reading quality of its documents contribute to improving the accuracy of the Service for every business. This feature is not available and cannot be enabled under this DPA in its current version. Until it is, no Customer data leaves its perimeter towards shared learning.
When it is offered, it will be governed by the following conditions, which will be incorporated into the corresponding version of this DPA:
- it will constitute an additional and specific instruction from the Customer, given by the person holding the business owner role, never an implicit authorization derived from the contract;
- it will be prospective: it will only reach events occurring after the instruction, never historical data;
- it will be revocable at any time, with immediate effect on future contributions;
- no documents, text, names, tax IDs, suppliers, products or amounts will leave the Customer Data — only aggregated signals within minimum-size cohorts and with publication delay;
- HOSTELELLA will not publish any aggregated result without meeting the minimum thresholds of businesses and samples defined in its impact assessment;
- the Customer's instruction does not replace the legal basis the Customer must hold towards the individuals whose data appears in its documents, and does not cure an invalid one;
- if a derived result were still attributable to a specific Customer, it will be deleted or rebuilt when the instruction is revoked; aggregates demonstrated to be genuinely anonymous are neither attributable nor individually reversible, and this will be stated before the instruction is requested.
6. Customer obligations
- Have a legal basis and comply with information duties regarding employees, workers, customers, suppliers and third parties.
- Comply with the labor law applicable to shift planning (working hours, rest, night work, protection of minors) and, where there is workers' legal representation, inform it of the parameters, rules and instructions of the algorithmic or AI systems that affect working conditions (Art. 64.4.d of the Workers' Statute).
- Not upload unnecessary, unlawful, excessive or specially sensitive data without a legal basis and safeguards.
- Configure roles, permissions and access in accordance with the least-privilege principle. In particular, regarding the daily working-time record (Art. 34.9 Workers' Statute): the Customer is responsible for whom it grants manager, admin or owner permissions, which entail seeing and correcting the clock-ins of lower-ranked people; for keeping the record confidential from the rest of the staff; and for deciding whether to share with the team the presence ("who is working now") that the Service offers as an optional feature without times or deviations.
- Restrict or refrain from enabling any feature it cannot lawfully use in its country, sector, collective agreement or workplace. Technical availability is not legal advice or authorization.
- Organise and document the working-time record in accordance with labour law (collective bargaining, company agreement or employer decision after consulting workers' representatives), inform its staff of its existence and purpose, include it in its record of processing activities and, if it enables location verification, comply with the information duty of Art. 90 LOPDGDD and document its proportionality.
- Apply the required human review to AI-generated proposals before their publication or application, and not use them as the sole basis for decisions with significant effect on individuals.
- Handle data-subject rights when HOSTELELLA acts as a processor.
- Keep its own copies or exports where law or operational risk requires.
7. Authorized personnel and confidentiality
HOSTELELLA will limit access to authorized personnel who need to process data to provide or protect the Service. Such personnel will be subject to contractual or statutory confidentiality obligations. Access for support, security, continuity, compliance or incident investigation is subject to least privilege, need to know and risk-proportionate logging; indiscriminate commercial access is prohibited.
8. Security measures
HOSTELELLA will apply technical and organizational measures appropriate to the risk, including access control, least privilege, encryption in transit, secrets management, activity logging, monitoring, backups, continuity, logical segregation and an incident response process. The Security Policy describes the main measures and is incorporated by reference.
Measures may evolve to improve security, compliance or resilience, always maintaining a level of protection that is not materially lower for data processed as a processor.
9. Automated processing and artificial intelligence
Where the Customer enables AI features (e.g., document extraction, the assistant or AI-assisted shift generation), HOSTELELLA will process data on behalf of the Customer and in accordance with these safeguards:
- Decision support with human review: AI features are assistance tools; shift proposals require approval by a person with a manager role or above. No solely automated decisions with legal or significant effects within the meaning of Art. 22 GDPR are made.
- Minimization and pseudonymization: before sending information to AI providers, unnecessary data is excluded and, where possible, data is pseudonymized (e.g., the shift generator operates with initials and operational data, not full names; the reason/type of absences is not transmitted).
- No training: HOSTELELLA does not use Customer Data to train its own or third parties' models, unless under express authorization or specific contract. AI sub-processors are contractually subject to no-training controls over commercial data.
- AI framework (EU 2024/1689): HOSTELELLA may be the provider or downstream provider of the integrated system and the Customer the deployer; each party retains its mandatory duties. Both apply AI-literacy measures to their personnel. The Customer will classify and document employment use, follow instructions, ensure competent human oversight with authority, inform workers and their representatives in advance where required, retain logs under its control and notify serious incidents to HOSTELELLA.
10. Sub-processors
The Customer authorizes HOSTELELLA to use sub-processors to provide the Service, provided they are subject to substantially equivalent data-protection obligations and, at a minimum, to those required by Article 28 GDPR. The main list is maintained in the Sub-processors Annex, which includes, among others, the AI providers used when the corresponding features are enabled.
HOSTELELLA will notify material changes in sub-processors at least thirty (30) days in advance where reasonably possible. For urgent changes due to security, continuity or provider replacement, notification may be given as soon as feasible. The Customer may object on substantiated data-protection grounds within ten (10) business days of notification; if the objection prevents provision of the Service, the parties will cooperate to find a reasonable alternative or terminate the affected service. HOSTELELLA remains liable to the Customer for the sub-processors' compliance under the GDPR.
11. International transfers
Where an international transfer outside the EEA occurs, HOSTELELLA will apply a valid mechanism under Articles 44 to 49 GDPR, including adequacy decisions, Standard Contractual Clauses, the EU-US Data Privacy Framework where applicable and supplementary measures where appropriate. For processor-to-sub-processor transfers, the corresponding SCC module or another valid mechanism will apply. Certain AI and communications providers are located in the United States. HOSTELELLA will verify adequacy certification where relied on, execute the applicable module of Decision (EU) 2021/914 where required, and document the transfer assessment and necessary supplementary measures. The Customer may request information about the safeguards used.
12. Assistance to the Customer
Taking into account the nature of the processing, HOSTELELLA will reasonably assist the Customer with:
- exercise of data-subject rights;
- security of processing and personal data breaches;
- impact assessments and prior consultations where necessary, including employment geolocation/monitoring or employment AI use where it may create high risk;
- reasonable deletion, export or return of data.
13. Personal data breaches
HOSTELELLA will notify the Customer without undue delay after becoming aware of a personal data breach affecting data processed as a processor. HOSTELELLA will aim to provide an initial notification within forty-eight (48) hours where reasonably possible. The notification will include the information reasonably available and may be completed in phases.
14. Deletion and return
Upon termination, at the Customer's choice, HOSTELELLA will return data processed as a processor and erase remaining copies, or erase them directly, unless Union or Member State law requires retention. Records HOSTELELLA must retain as an independent controller for billing, security, fraud or legal claims will be separated, minimized and restricted to those purposes; they do not extend the mandate or authorize retention of Customer content. Backups will be erased in their technical cycle, normally within ninety (90) days; until then they remain isolated and are not restored except for continuity or incident response.
15. Audits
HOSTELELLA will make available reasonable information to demonstrate compliance with this DPA. Direct audits must be requested with reasonable notice, be limited to what is necessary, not compromise the security or confidentiality of other customers and may be subject to reasonable costs where extraordinary or repetitive, never so as to prevent exercise of Article 28(3)(h) GDPR. Except for a relevant incident or authority requirement, no more than one direct audit per calendar year will be carried out.
16. Liability
Liability arising from this DPA is governed by the liability limits of the Terms, unless applicable law imposes a different regime. The Customer is responsible for the instructions, data and legal bases it determines as Controller, as well as for compliance with labor law and the information obligations arising from the use of AI features in the employment context.