Data Processing Agreement
Version 1.0 · Effective 1 August 2026
This Data Processing Agreement ("DPA") is entered into between the Customer (as identified in the ItReserve account) in its capacity as Controller, and ItReserve d.o.o., ul. Vuka Karadžića 3, 81000 Podgorica, Crna Gora, PIB 64928153, CRPS 4-0089267/X, in its capacity as Processor.
This DPA forms part of and is incorporated into the Terms of Service governing the Customer's use of ItReserve services. In the event of any conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA prevails. By accepting the Terms of Service, the Customer also accepts this DPA on behalf of itself and, where applicable, on behalf of each Permitted Affiliate who uses the services.
1. Definitions
In this DPA, the following terms have the meanings set out below. Terms used but not defined here have the meanings given to them in the Terms of Service or in GDPR.
- Controller — the natural or legal person who determines the purposes and means of the processing of personal data; in this DPA, the Customer.
- Processor — the natural or legal person who processes personal data on behalf of the Controller; in this DPA, ItReserve d.o.o.
- Personal Data — any information relating to an identified or identifiable natural person ("Data Subject"), as defined in GDPR Article 4(1).
- Processing — any operation or set of operations performed on personal data, including collection, recording, storage, adaptation, retrieval, use, disclosure, erasure, or destruction.
- Data Subject — any identified or identifiable natural person whose personal data is processed under this DPA, including hotel guests, hotel staff, and billing contacts.
- Sub-Processor — any third party engaged by the Processor to carry out processing activities on behalf of the Controller.
- GDPR — Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, and its national implementations including the Montenegrin Zakon o zaštiti ličnih podataka.
- Supervisory Authority — a public authority established by a member state or Montenegro pursuant to GDPR Article 51, including the AZLP.
- Standard Contractual Clauses — the clauses adopted by the European Commission for international data transfers, as updated from time to time.
- Data Breach — a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
2. Subject Matter, Nature, and Duration of Processing
ItReserve processes personal data solely for the purpose of providing the Module subscription services described in the Terms of Service. The nature of processing is the automated reading of and writing to data within the Customer's Reservit property-management system via the Reservit API, including storing API call logs, user-configuration data, and operational results generated by the Modules.
The duration of processing corresponds to the active Subscription period. Upon cancellation or termination of all Subscriptions, ItReserve will cease active processing and retain data only as required by this DPA and applicable law, before deleting it in accordance with Section 13 below.
3. Purpose and Categories of Processing
3.1 Purpose
ItReserve processes personal data exclusively to operate the Modules subscribed to by the Customer against the Customer's Reservit installation. This includes retrieving reservation data, guest-profile data, revenue figures, and operational records accessible through the Reservit API; applying the Module's analytical or operational logic to that data; and writing outputs (such as updated rates, housekeeping schedules, or communication triggers) back to Reservit where the Module's functionality requires it.
3.2 Types of Personal Data Processed
- Hotel guest data accessed via Reservit API: guest name, email address, nationality, stay dates, room type, booking source, and other fields stored in the Customer's Reservit PMS that are surfaced by the relevant API endpoint. The scope of guest data varies by Module.
- Hotel staff email addresses: email addresses of hotel staff recorded as system users in the Customer's Reservit instance, used for Module notification delivery and dashboard access provisioning.
- Billing and account contact data: name, email address, company name, billing address, and payment reference of the individual who manages the ItReserve account on behalf of the property.
- API credential data: the Reservit API Key supplied by the Customer, stored in encrypted form to authenticate API requests.
- Usage log data: pseudonymised records of API call volumes, timestamps, response codes, and Module-generated audit trails.
3.3 Categories of Data Subjects
- Hotel guests who have made reservations recorded in the Customer's Reservit PMS;
- Hotel staff (front-desk employees, revenue managers, housekeeping coordinators, and system administrators) whose accounts are configured in Reservit;
- The Customer's billing and administrative contacts;
- Any additional individuals whose data may be present in the Reservit PMS as a result of the Customer's own data-collection activities.
4. Obligations of the Processor (ItReserve)
4.1 Processing Only on Documented Instructions
ItReserve shall process personal data only on documented instructions from the Controller (the Customer), which are embodied in the Terms of Service, this DPA, and the Module subscription configuration. If ItReserve is required by applicable law to process data beyond those instructions, ItReserve shall inform the Customer before processing, unless that law prohibits disclosure for reasons of public interest.
4.2 Confidentiality
ItReserve ensures that persons authorised to process personal data are subject to contractual or statutory obligations of confidentiality. Access to personal data is limited to personnel who need it to perform their job functions. ItReserve operates a principle of least-privilege access control: no employee has access to any personal data beyond what is necessary for their role.
4.3 Security Measures
ItReserve shall implement and maintain appropriate technical and organisational security measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include, without limitation:
- Encryption of personal data at rest using AES-256 or equivalent;
- Encryption of personal data in transit using TLS 1.2 or higher;
- Multi-factor authentication for all administrative and infrastructure access;
- Role-based access control with regular access-rights reviews;
- Automated security patching for operating systems and dependencies;
- Immutable audit logs for all access to production personal data stores;
- Penetration testing at least annually by a qualified third party;
- A formal information-security policy reviewed annually.
4.4 Staff Training
ItReserve provides mandatory data-protection training to all staff with access to personal data at the time of employment and on a recurring annual basis. Training covers GDPR obligations, recognition of phishing and social-engineering attacks, incident reporting procedures, and acceptable-use rules for personal data.
4.5 Sub-Processor Agreements
Before engaging any Sub-Processor to process personal data on behalf of the Controller, ItReserve shall enter into a written agreement with that Sub-Processor imposing equivalent data-protection obligations to those in this DPA. ItReserve remains fully liable to the Controller for the performance of its Sub-Processors' obligations.
4.6 Assistance with Data Subject Rights
ItReserve shall assist the Controller in fulfilling its obligations to respond to requests from Data Subjects exercising their rights under GDPR (access, rectification, erasure, restriction, portability, objection). Where a Data Subject submits a request directly to ItReserve, ItReserve shall promptly forward it to the Controller and cooperate as required.
4.7 Assistance with Security and Breach Obligations
ItReserve shall assist the Controller in ensuring compliance with GDPR Articles 32–36, including security of processing, notification of breaches, data-protection impact assessments, and prior consultation with supervisory authorities.
5. Obligations of the Controller (Customer)
5.1 Lawful Basis
The Customer, as Controller, is solely responsible for establishing and maintaining a lawful basis under GDPR Article 6 for processing the personal data of its hotel guests and staff. The Customer warrants that it has carried out all necessary privacy notices, consent collection, or other lawful-basis steps with respect to its Reservit data prior to enabling ItReserve's access.
5.2 Data Quality and Accuracy
The Customer is responsible for the accuracy and completeness of personal data present in its Reservit PMS. ItReserve processes that data as provided; it is not responsible for errors or inaccuracies in the source data.
5.3 Data Subject Requests
The Customer is responsible for receiving, evaluating, and responding to Data Subject requests. The Customer shall inform ItReserve within 5 business days of any Data Subject request that requires ItReserve's cooperation to fulfil (for example, erasure of guest data from Module logs).
5.4 Instructions
The Customer shall ensure that its instructions to ItReserve comply with applicable law. If the Customer provides an instruction that ItReserve believes would violate GDPR or other applicable law, ItReserve shall inform the Customer of that belief before processing. The Customer is responsible for the consequences of any instruction it issues.
6. Sub-Processor List and Approval Process
The following Sub-Processors are approved by the Customer upon acceptance of this DPA:
| Sub-Processor category | Processing activity | Location |
|---|---|---|
| Cloud infrastructure provider | Hosting, storage, and network transit of all service data | EEA |
| Transactional email service | Delivery of operational emails to hotel staff and account contacts | EEA |
| Payment processor | Payment processing for subscription billing (billing contact data only) | EEA |
ItReserve shall notify the Customer at least 14 days in advance of any intended addition or replacement of a Sub-Processor by updating the sub-processor list at itreserve.org/dpa. The Customer may object to a new Sub-Processor on reasonable grounds within 14 days of notification by emailing support@itreserve.org. If no resolution is reached within a further 14 days, either party may terminate the relevant subscription without penalty, and ItReserve will issue a pro-rata refund.
7. Data Subject Request Handling
ItReserve's role in fulfilling Data Subject requests is limited to providing the Controller with the data it holds in its own systems (Module logs, configuration data) relating to the Data Subject. ItReserve does not have direct access to the full Reservit PMS data of the Customer; the Customer must address requests for data held within Reservit directly through its Reservit account.
ItReserve will provide a data extract or deletion confirmation within 15 business days of receiving a documented request from the Controller. The Controller is responsible for consolidating ItReserve's response with any data held in Reservit and responding to the Data Subject within the 30-day GDPR deadline.
8. Data Breach Notification Procedure
In the event of a confirmed or reasonably suspected Data Breach affecting personal data processed under this DPA, ItReserve shall:
- Notify the Controller without undue delay and no later than 48 hours after becoming aware of the Breach, to allow the Controller to meet its own 72-hour notification obligation to the AZLP;
- Provide, in that notification or as soon as it becomes available: the nature of the breach; the categories and approximate volume of Personal Data and Data Subjects affected; the likely consequences; the measures taken or proposed to address the breach; and a contact point for further information;
- Cooperate fully with the Controller and, where required, with the Supervisory Authority in investigation and remediation;
- Document the breach and remediation actions in ItReserve's internal incident register.
The Controller is responsible for notifying the AZLP and, where required, the affected Data Subjects. ItReserve shall provide reasonable assistance in preparing such notifications.
9. Return and Deletion of Data on Termination
Upon termination or expiry of all Subscriptions, ItReserve shall, at the Controller's written election:
- Return: Provide an export of all personal data held in ItReserve systems relating to the Controller's account in a structured, machine-readable format (CSV or JSON) within 30 days of the termination date; or
- Delete: Securely delete all such personal data within 30 days, except where ItReserve is required by law to retain certain records (such as billing records for 7 years under accounting law).
If the Controller does not make a written election within 90 days of termination, ItReserve will proceed with secure deletion. ItReserve will provide a written certificate of deletion upon request.
10. International Transfers
ItReserve stores and processes data within the EEA or in countries covered by a European Commission adequacy decision. Where a Sub-Processor is located in a third country not covered by an adequacy decision, ItReserve ensures that appropriate safeguards — namely, the Standard Contractual Clauses (SCC) approved by the European Commission, supplemented by a Transfer Impact Assessment where required — are in place before the transfer occurs. Documentation of transfer safeguards is available to the Controller upon written request.
11. Audit Rights
The Controller has the right to audit ItReserve's compliance with this DPA no more than once per calendar year, on 30 days' written notice, at the Controller's own expense. ItReserve may satisfy an audit request by providing the Controller with the most recent third-party audit report (such as ISO 27001 certification or SOC 2 Type II report) and a written attestation of compliance. If the Controller requires a bespoke audit beyond what third-party reports cover, the parties shall agree in writing on the scope, timing, and cost allocation before the audit commences. Audits must not unreasonably disrupt ItReserve's business operations.
12. Governing Law
This DPA is governed by the laws of Montenegro. Where GDPR applies directly, the relevant provisions of GDPR take precedence over Montenegrin law to the extent of any conflict. Disputes arising from this DPA shall be resolved in accordance with the dispute resolution clause in the Terms of Service — i.e., before the Osnovni sud u Podgorici, Montenegro.
13. Data Protection Contact
For all matters arising under this DPA, including Sub-Processor objections, data-subject request assistance, breach notifications, audit requests, or general compliance enquiries, the Controller should contact ItReserve's designated data-protection contact:
- Email: support@itreserve.org (subject line: "DPA / Data Protection")
- Post: ItReserve d.o.o., Data Protection, ul. Vuka Karadžića 3, 81000 Podgorica, Crna Gora
- Phone: +382 20 218 735
ItReserve aims to respond to all DPA-related enquiries within 5 business days.
14. Order of Precedence and Entire Agreement
In the event of inconsistency between this DPA and any other agreement between the parties relating to the processing of personal data (including any prior DPA or data-processing clauses in the Terms of Service), this DPA prevails. This DPA, together with the Terms of Service and any applicable Standard Contractual Clauses, constitutes the entire agreement between the parties relating to the processing of personal data by ItReserve on behalf of the Controller. Amendments to this DPA must be made in writing. ItReserve may update this DPA from time to time to reflect changes in law or practice, with 30 days' notice to the Controller.