HOSTELELLA Legal documentation

Security Policy

Version 1.9 Effective 29 August 2026 Art. 32 GDPR

HOSTELELLA applies reasonable technical and organizational measures appropriate to the risk to protect the confidentiality, integrity, availability and resilience of the Service. This policy summarizes the main measures without disclosing details that could weaken security.

1. Governance and access

2. Data protection

3. Application and API

4. Communications and preferences

5. AI processing and minimization

When AI features are used, HOSTELELLA applies specific controls to reduce the exposure of personal data:

6. Operations, monitoring and continuity

7. Reasonable limitations

This policy summarizes security controls without disclosing details that could weaken the Service. Measures may vary by environment, plan, managed provider and risk. No system is absolutely secure; HOSTELELLA will maintain appropriate and proportionate measures, but the Customer must apply its own internal controls.

8. Sub-processors

HOSTELELLA selects providers that offer adequate security measures for the purpose of the processing. The main sub-processors are published in the Sub-processors Annex.

9. Jurisdiction and international governmental access

The jurisdiction of the infrastructure for each service is identified in the Sub-processors Annex. For non-personal data held in the Union, HOSTELELLA applies legal review of third-country authority requests, response minimization, access controls and encryption where appropriate; it will reject or challenge requests conflicting with Union law where there are reasonable grounds and notify the Customer where legally permitted. Providers will be subject to equivalent commitments to the applicable extent.

10. Customer responsibilities

The Customer must protect its devices, accounts and credentials, use strong passwords, limit permissions, review active users, report suspicious access and keep its own copies/exports where required by its operational risk or regulations.