Data Processing Addendum
Last updated: September 7, 2026
Effective date: September 7, 2026
This Data Processing Addendum (“DPA”) forms part of the Bookazoid Terms of Service, an Order Form, or another agreement governing a Customer’s use of Bookazoid (the “Agreement”) whenever Metalprotekt LLC processes Customer Personal Data on behalf of the Customer.
This DPA is between Metalprotekt LLC (“Bookazoid”, “Processor”, “we”, “us”, or “our”) and the Customer identified in the Agreement (“Customer”).
1. Definitions
“Applicable Data Protection Law” means privacy and data protection law applicable to the relevant processing of Customer Personal Data, including the EU GDPR and UK GDPR where applicable.
“Customer Personal Data” means personal data contained in Customer Data that Bookazoid processes on behalf of Customer in connection with the Service.
“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing”, and “Supervisory Authority” have the meanings given by Applicable Data Protection Law.
“Subprocessor” means a third party appointed by Bookazoid to process Customer Personal Data on behalf of Customer.
“EU SCCs” means the European Commission Standard Contractual Clauses for transfers of personal data to third countries adopted by Commission Implementing Decision (EU) 2021/914, as amended or replaced.
“UK Addendum” means the then-current International Data Transfer Addendum to the EU Standard Contractual Clauses approved under UK data protection law.
2. Roles and scope
Customer is the Controller of Customer Personal Data or acts as a Processor on behalf of another Controller. Bookazoid acts as Customer’s Processor or Subprocessor, as applicable.
Customer determines the purposes and essential means of processing Customer Personal Data. Bookazoid processes Customer Personal Data only to provide, secure, maintain, support, and troubleshoot the Service in accordance with Customer’s documented instructions, the Agreement, this DPA, and Applicable Data Protection Law.
Bookazoid may use aggregated or de-identified information that no longer constitutes Customer Personal Data to understand and improve the Service.
The subject matter, duration, nature, purpose, categories of Data Subjects, and categories of Customer Personal Data are described in Annex 1.
3. Customer instructions and responsibilities
Customer instructs Bookazoid to process Customer Personal Data as reasonably necessary to:
- provide and operate the Service;
- perform the Agreement and Customer’s configuration or actions within the Service;
- provide support requested by Customer;
- secure, maintain, and troubleshoot the Service;
- use Subprocessors in accordance with this DPA; and
- comply with other documented instructions agreed by the parties.
Customer is responsible for ensuring that its instructions and use of the Service comply with Applicable Data Protection Law, including requirements relating to notices, lawful bases, data minimization, retention, and Data Subject rights.
If Bookazoid reasonably believes that a Customer instruction infringes Applicable Data Protection Law, Bookazoid may notify Customer and suspend the affected processing to the extent necessary while the parties address the issue, unless prohibited by law.
4. Confidentiality and personnel
Bookazoid will ensure that personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations and receive access only where reasonably necessary for their responsibilities.
Authorized Bookazoid personnel may access Customer Personal Data from Belarus where reasonably necessary to operate, support, secure, or maintain the Service.
5. Security
Bookazoid will maintain reasonable technical and organizational measures appropriate to the nature of Customer Personal Data and the risks of processing. Current categories of measures are described in Annex 2.
Customer acknowledges that security is a shared responsibility. Customer is responsible for its Users, passwords, account configuration, permissions, devices, exports, integrations, and internal handling of Customer Data.
6. Personal Data Breach
Bookazoid will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data where notification is required by Applicable Data Protection Law.
To the extent information is reasonably available, the notice will include information needed for Customer to understand the nature and likely consequences of the incident and the measures taken or proposed by Bookazoid.
Bookazoid’s notification of an incident does not constitute an admission of fault or liability.
7. Data Subject requests and compliance assistance
Taking into account the nature of the processing and the information available to Bookazoid, we will provide reasonable assistance to Customer with:
- Data Subject requests relating to Customer Personal Data;
- security-of-processing obligations;
- Personal Data Breach assessment and notification;
- data protection impact assessments where required; and
- consultation with supervisory authorities where required.
If Bookazoid receives a Data Subject request that clearly concerns Customer Personal Data, we may direct the requester to Customer and will not independently respond on the merits except on Customer’s instruction or where required by law.
8. Subprocessors
Customer gives Bookazoid general authorization to engage Subprocessors to provide the Service.
Bookazoid will require each Subprocessor that processes Customer Personal Data to be bound by data-protection obligations appropriate to the services it performs and substantially consistent with Bookazoid’s obligations under this DPA.
Our current Subprocessor list is available at https://bookazoid.com/subprocessors/.
Bookazoid will provide reasonable advance notice of a new Subprocessor that is expected to process Customer Personal Data. Unless a different period is stated in an applicable Order Form, Customer may object on reasonable data-protection grounds within 30 days after notice.
If the parties cannot reasonably resolve a valid objection, Customer may stop using the affected feature or terminate the affected Service. This is Customer’s sole remedy for an unresolved objection to a new Subprocessor, except where Applicable Data Protection Law requires otherwise.
9. International data transfers
Bookazoid is established in Belarus and its primary production infrastructure is hosted by DigitalOcean in the United States. Customer Personal Data may therefore be transferred to or processed in Belarus and the United States.
Where Applicable Data Protection Law requires a specific safeguard for a restricted international transfer, the parties will use the applicable mechanism described below or another lawful mechanism agreed by the parties.
9.1 EEA transfers
If Customer Personal Data protected by the EU GDPR is transferred to Bookazoid in a country that is not covered by an applicable adequacy decision, the EU SCCs are incorporated into this DPA and apply to that transfer.
Unless the parties agree otherwise in writing:
- Module Two (Controller to Processor) applies where Customer is a Controller and Bookazoid is a Processor;
- Module Three (Processor to Processor) applies where Customer is a Processor and Bookazoid is its Subprocessor;
- the description of the transfer is set out in Annex 1;
- the technical and organizational measures are set out in Annex 2;
- the authorized Subprocessors are identified through Annex 3 and the public Subprocessor list;
- for general authorization of Subprocessors, the notice period is 30 days;
- the optional independent dispute-resolution provision in Clause 11 is not selected; and
- where the SCCs require selection of the law and courts of an EU Member State, the parties select Ireland and the courts of Ireland, unless a mandatory rule requires another valid selection.
The competent supervisory authority is determined under Clause 13 of the applicable EU SCC module and Applicable Data Protection Law.
9.2 United Kingdom transfers
If Customer Personal Data protected by the UK GDPR is transferred to Bookazoid in a manner that requires appropriate safeguards, the parties agree that the UK Addendum applies to the EU SCCs described above and is incorporated into this DPA to the extent permitted by UK law.
The parties intend the required UK Addendum tables and appendix information to be completed using the party information in the Agreement and the transfer, security, and Subprocessor information in Annexes 1-3 of this DPA. Where necessary to make the transfer mechanism effective, the parties will execute or otherwise formally adopt the then-current ICO-approved Addendum or IDTA.
Customer remains responsible for completing any transfer risk assessment or data-protection test that Applicable Data Protection Law requires Customer, as transfer initiator, to complete. Bookazoid will provide reasonable information available to it to support that assessment.
9.3 Transfers to DigitalOcean
DigitalOcean, LLC is Bookazoid’s primary hosting Subprocessor. Bookazoid requires DigitalOcean to process Customer Personal Data under DigitalOcean’s applicable data processing terms.
DigitalOcean states in its current DPA that it uses applicable recognized transfer mechanisms for EEA, Swiss, and UK personal data, including its relevant Data Privacy Framework participation where applicable and fallback contractual transfer mechanisms where necessary.
10. Government and legal requests
Bookazoid will disclose Customer Personal Data to a governmental authority or other third party only where required or permitted by applicable law, valid legal process, or Customer instruction.
Where legally permitted, Bookazoid will notify Customer of a binding request specifically seeking Customer Personal Data and will reasonably limit disclosure to what is required.
11. Return and deletion
Upon termination of the Service, and subject to the Agreement, Bookazoid will delete or return Customer Personal Data at Customer’s choice where technically feasible, unless applicable law requires continued retention.
Customer Personal Data may remain for a limited period in backups or disaster-recovery systems until overwritten or deleted in the ordinary backup lifecycle, provided that it remains protected and is not restored for ordinary business use except as needed for recovery, security, or legal reasons.
12. Audits and information
Bookazoid will make available information reasonably necessary to demonstrate compliance with this DPA and Applicable Data Protection Law.
Where legally required and reasonable documentation is insufficient, Customer may request an audit. Audits must be coordinated in advance, conducted during normal business hours, avoid unreasonable disruption, protect other customers’ information, and be subject to appropriate confidentiality obligations.
Customer bears its audit costs unless Applicable Data Protection Law requires otherwise or the audit identifies a material breach by Bookazoid.
13. Liability and order of precedence
The liability provisions and limitations in the Agreement apply to this DPA to the maximum extent permitted by Applicable Data Protection Law.
If this DPA conflicts with the Agreement on a matter concerning processing of Customer Personal Data, this DPA controls for that matter. If the EU SCCs or UK Addendum apply and conflict with this DPA, the applicable mandatory transfer clauses control.
14. Term
This DPA remains in effect for as long as Bookazoid processes Customer Personal Data on behalf of Customer.
Annex 1 – Details of processing
| Subject matter | Processing Customer Personal Data to provide the Bookazoid property-management and operational software service. |
|---|---|
| Duration | For the term of the Agreement and any limited post-termination period required for deletion, backup cycling, security, dispute, or legal obligations. |
| Nature and purpose | Hosting, storing, organizing, retrieving, displaying, calculating, transmitting, backing up, securing, supporting, troubleshooting, exporting, and otherwise processing data as needed to provide the Service according to Customer instructions. |
| Frequency | Continuous or as initiated by Customer and its Users during use of the Service. |
| Data Subjects | Customer Users and staff; guests; occupants; travelers; visitors; payers; property owners; vendors; contractors; contacts; and other individuals whose data Customer chooses to process through Bookazoid. |
| Categories of Personal Data | Names; business and personal contact details; account identifiers; authentication and access data; IP and technical data; booking and stay information; occupancy information; property-related records; payer and invoice information; taxes, fees, charges, and financial records that do not require Bookazoid to store full payment-card numbers; owner and vendor information; communications; transactional email recipient details and message content where Customer Data is included in a Service email; operational notes; housekeeping and maintenance records; audit and activity records; and other Customer-submitted data. |
| Sensitive / special-category data | The Service does not require Customers to submit special-category or highly sensitive data as a general rule. Customers may nevertheless submit such data where lawful and genuinely necessary for their operations. Customer is responsible for ensuring a valid legal basis and appropriate safeguards. |
| Customer obligations | Customer determines the purpose of processing, ensures lawfulness and transparency, configures access permissions, and gives lawful instructions. |
Annex 2 – Technical and organizational measures
Bookazoid applies measures appropriate to the Service and the relevant risk, which may include:
- user authentication and secure session controls;
- password hashing and credential protection;
- role-based and permission-based access controls;
- least-privilege access for personnel;
- TLS or equivalent encryption for data in transit;
- logging and audit trails for relevant application activity;
- infrastructure, availability, and security monitoring;
- backup and recovery procedures;
- controlled production access;
- security updates and vulnerability remediation processes;
- incident-response procedures;
- Subprocessor due diligence and contractual protection; and
- physical infrastructure security provided by Bookazoid’s hosting provider.
Specific measures may evolve as Bookazoid’s architecture changes, provided that the overall level of protection is not materially reduced during the term of a paid Service without a valid reason and appropriate safeguards.
Annex 3 – Authorized Subprocessors
The current list of authorized Subprocessors is maintained at https://bookazoid.com/subprocessors/ and is incorporated into this DPA by reference.
As of the effective date of this DPA, the primary infrastructure Subprocessor is:
| Subprocessor | Purpose | Primary processing location |
|---|---|---|
| DigitalOcean, LLC | Cloud hosting, infrastructure, storage, backup and related platform services | United States |
| Brevo (Sendinblue SAS or applicable Brevo contracting entity) | Transactional email delivery and related delivery logging | European Union |