Data processing agreement
In force since 29 August 2026
This agreement forms part of the terms of service between GuestSync LLC ("processor", "we") and the property owner who engages us ("controller", "you"). It applies automatically from the day we take over your guest operation — you do not need to request or sign anything separately, though we will sign a copy on request.
1. Roles
In running your guest operation we process personal data about your guests. You are the controller of that data: it belongs to the relationship between you and your guest, and you decide the purposes it serves. We are your processor and act only on your instructions.
Data about you as our client — your contact and billing details — we process as controller, under our privacy policy. This agreement does not cover that.
2. What we process, and why
- Subject matter — running the guest side of your short-term rental: messaging, calls, check-in and check-out, reviews and issue handling.
- Duration — for as long as we provide the service to you.
- Data subjects — your guests, and the people they book on behalf of.
- Categories of data — names, contact details, booking and stay dates, arrival details, access codes issued, the content of messages and calls, and any identity or registration data your jurisdiction requires you to collect.
- We process no special categories of data deliberately. If a guest volunteers health or accessibility information in a message, we handle it only to serve that stay.
3. Our obligations
- We process guest data only on your documented instructions, which include these terms and the settings you configure in your systems. If we believe an instruction breaks the law, we will tell you.
- Everyone we authorise is bound by confidentiality.
- We apply appropriate technical and organisational security measures — see section 6.
- We assist you in answering guest requests to access, correct or delete their data.
- We assist you with breach notification and with any impact assessment you have to carry out.
- On termination we delete guest data in our possession, or return it, at your choice — except anything we must retain by law.
- We make available the information you need to demonstrate we comply, and will accept an audit or answer a questionnaire on reasonable notice, once a year or after a breach.
4. Subprocessors
You authorise us to use the following subprocessors:
- Kross Booking — the property management system in which guest communication takes place.
- Our DNS and email routing provider (United States).
- Our email provider — the mailbox in which correspondence is received.
- Your own smart lock provider, whose software you give us access to. We act inside your account, not ours.
We identify them here by function. The current list naming each company is available on request and we will send it to any client who asks, so that you can carry out your own assessment.
We remain responsible for our subprocessors' performance. If we add or replace one we will tell you at least 30 days beforehand, and you may object — in which case you can terminate at no cost, which you can do anyway, since there is no lock-in.
5. International transfers
We are established in the United States, so guest data reaches us there. Where you are subject to the GDPR or UK GDPR, transfers rely on the European Commission's Standard Contractual Clauses as incorporated in our providers' data processing terms, together with the measures in section 6. On request we will enter into the Standard Contractual Clauses directly with you.
6. Security
- Access to your systems is granted through your own accounts, so you can revoke it yourself at any moment without asking us.
- Only named members of our team hold access to any given property, on a least-privilege basis. Credentials are never shared outside that list, never sent over chat, and never reused between clients.
- We create and revoke guest access codes. We do not change master codes or add permanent users.
- All access is revoked and confirmed to you in writing within 24 hours of termination.
- Traffic to our systems is encrypted in transit.
7. Breaches
If we become aware of a breach affecting your guests' data we will notify you without undue delay and in any case within 48 hours, with what we know: what happened, which data and roughly how many people are affected, the likely consequences and what we are doing about it. Notifying the supervisory authority and the guests is your decision as controller; we will give you what you need to make it.
8. Liability and precedence
The limitation of liability in the terms of service applies to this agreement. Where this agreement conflicts with the terms of service on the processing of guest data, this agreement prevails. It is governed by the laws of the State of Florida, without prejudice to any mandatory protection available to data subjects under their own law.