LIVE rate updates last houravg s sync properties live
Legal / Data Processing Agreement

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the HubPMS Terms of Service between the customer (the property — the controller) and Mirage Global Technologies LLC (the processor), and applies wherever the GDPR or equivalent law governs the guest personal data processed in the service.

1 · Subject matter, duration, nature and purpose

Processing of guest personal data as necessary to provide the HubPMS property management service (reservations, folios, communications, check-in, connected channels), for the duration of the customer's subscription plus the wind-down periods in the Terms. Processing operations: storage, retrieval, transmission to channels the controller connects, erasure.

2 · Categories of data and data subjects

Data subjects: the controller's guests and staff. Categories: identification and contact details, stay details, communication content, payment references (never card numbers), and — where the controller enables online check-in — identity document details and signature. No special categories are intended to be processed.

3 · Instructions and confidentiality

We process guest data only on the controller's documented instructions, including as given through the service's settings, and inform the controller if an instruction appears to infringe data protection law. Persons authorised to process are bound by confidentiality. Operator access to a customer workspace is logged in an immutable audit trail.

4 · Security (Art. 32)

Technical and organisational measures include: encryption in transit (TLS); per-tenant row-level isolation enforced at the database layer; credentials and access tokens stored only as salted hashes; separated customer and operator access models, with operator access to customer workspaces time-limited and recorded in an immutable audit log; append-only event logs for reservations; request rate limiting; daily backups encrypted with AES-256 and retained for 14 days; and secrets kept outside the codebase and the repository.

5 · Sub-processors (Art. 28(2))

The controller grants general authorisation for the sub-processors listed in the Privacy Policy §4 (cloud hosting — United States; Stripe — payments; Anthropic — AI text processing when enabled). We notify DPA customers at least 14 days before adding or replacing a sub-processor; the controller may object on reasonable data-protection grounds, in which case the affected feature may be disabled for that customer. Sub-processors are engaged under their written data-protection terms (the standard data processing agreements that form part of their service terms), providing safeguards consistent with Art. 28(4).

6 · International transfers

Transfers of EU/EEA data to the United States are made under the European Commission's Standard Contractual Clauses (Module 2, controller-to-processor), which are incorporated into this DPA by reference, supplemented by the measures in §4.

7 · Assistance, breaches, audits

Taking into account the nature of processing, we assist the controller with data subject requests (the service includes selective erasure and full export), with Art. 32–36 obligations, and we notify the controller of a personal data breach affecting their data without undue delay with the information required by Art. 33(3). We make available the information reasonably necessary to demonstrate compliance and allow audits, which start with our documentation and written answers; on-site audits require reasonable notice and confidentiality.

8 · Return and deletion

At the end of the service, the controller can export all data in a machine-readable form. We delete personal data within 90 days of account closure, except billing records retained under legal obligation (Art. 17(3)(b)) for 7 years. Data deleted from live systems may persist in encrypted backups until those backups cycle out, within 14 days.

Version 1.0 — effective 26 August 2026.

See it on your own hotel — free for 5 days.