Trust · SAAS-405
Data processing agreement
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the Tetrea platform operator (“Processor”, “Tetrea”) and the subscribing hospitality organisation (“Controller”, “Customer”). It applies when Tetrea processes personal data in Customer Data on the Customer’s instructions while providing Tetrea.
1. Roles
Customer determines the purposes and means of processing guest, staff, and operational personal data entered into Tetrea. Tetrea processes that data only to provide the subscribed services, including hosting, backups, support (when authorised), entitlement enforcement, and integrations the Customer enables (for example platform Channex sync or guest payment capture configured by the Customer).
For marketing-site visitors and Customer account billing contacts, Tetrea may act as an independent controller as described in the Privacy Policy.
2. Subject matter and duration
Processing continues for the term of the subscription and any post-cancellation retention / read-only grace period, then ceases except for archival copies required by law or secure deletion backups that expire on a fixed schedule.
3. Nature and purpose
Processing includes storage, retrieval, transmission, display, and deletion of:
- guest identity and contact details, stay history, preferences, and registration data;
- reservation, folio, payment reference, and accounting records;
- staff user accounts, roles, and operational assignments;
- F&B, tours, transfers, and other module data the Customer entitles and uses.
Categories of data subjects include guests, accompanying persons, Customer staff, and vendors the Customer records. Special-category data should not be uploaded unless the Customer has a lawful basis and configures fields accordingly (for example accessibility notes).
4. Customer instructions
Customer instructs Tetrea to process personal data solely to deliver Tetrea features the Customer uses, to comply with law, and to follow documented configuration (modules, integrations, retention settings). Tetrea will inform the Customer if an instruction appears unlawful, unless prohibited from doing so.
5. Confidentiality and security
Tetrea implements appropriate technical and organisational measures, including:
- authentication, role-based access, and optional MFA;
- tenant isolation and least-privilege platform administration;
- encryption in transit; encryption at rest where the hosting tier provides it;
- audit logging for financial and support-sensitive actions;
- vulnerability and dependency hygiene on a continuous basis.
6. Subprocessors
Customer authorises Tetrea to engage subprocessors strictly necessary to host and operate the service (cloud infrastructure, transactional email, SaaS billing PSP, and the platform Channex connection when Channel is entitled). Tetrea remains responsible for subprocessors’ performance. Material changes to core subprocessors will be reflected in product or legal notices with a reasonable objection window where required by law.
7. International transfers
Where personal data is transferred outside the Customer’s jurisdiction, Tetrea will ensure an appropriate transfer mechanism (such as contractual clauses) is in place with relevant subprocessors.
8. Assistance
Taking into account the nature of processing, Tetrea will assist the Customer with data-subject requests, security assessments, and DPIAs that reasonably relate to Tetrea, via support channels. Customer remains responsible for responding to guests and for lawful bases for processing.
9. Personal data breaches
Tetrea will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide information reasonably available to help the Customer meet its own notification duties.
10. Return and deletion
Upon written request at the end of the service, or after the retention window expires, Tetrea will delete or return Customer Data (including personal data) from active systems, except where retention is required by law or needed to resolve disputes. Export formats available in product (for example CSV or PDF) may be used for return.
11. Audits
Customer may request information reasonably necessary to demonstrate compliance with this DPA, no more than once per year unless a confirmed breach warrants an additional review. On-site audits require reasonable notice, confidentiality, and cost allocation if they exceed standard questionnaire responses.
12. Liability and order of precedence
Liability under this DPA is subject to the limitations in the Terms of Service. If there is a conflict between this DPA and the Terms regarding personal data processing, this DPA prevails.
13. Contact
DPA and privacy notices: [email protected] · Contact
This DPA is a platform commercial draft for launch readiness (SAAS-405). Counsel may issue a signed executable form for enterprise customers before broad public sale.