Data Processing Agreement
Version dated 30 September 2026
This English version is provided for convenience. The French version prevails.
This agreement is concluded under Article 28 of Regulation (EU) 2016/679 (“GDPR”) between:
- the Customer: the operator of the hotel establishment that has subscribed to the Dexlo software, identified on the purchase order or in the written subscription exchange, acting as controller;
- Dexlo: Adam Ben Hadj Ali, sole proprietor (entrepreneur individuel, EI), trade name Dexlo, 41 rue Ernest Renan, 92310 Sèvres, France (SIREN 109 281 824, RCS Nanterre, registered on 2 September 2026; contact@dexlo.fr), acting as processor.
Hereinafter together “the Parties”.
Whereas the Customer has subscribed to a licence to use the standardised Dexlo software, under the conditions of the Terms of Sale. This use leads Dexlo to process, on behalf of the Customer, data that may constitute personal data. This agreement sets out the conditions of this processing, in accordance with Article 28 GDPR.
This agreement forms an integral part of the contract and prevails over the Terms of Sale for everything relating to the processing of personal data.
1. Definitions
The terms “personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach” and “supervisory authority” have the meaning given to them in Article 4 GDPR.
2. Roles of the Parties
2.1. The Customer is the controller. It determines the purposes and means of the processing, and ensures its lawfulness and that data subjects are informed.
2.2. Dexlo is the processor. It processes the data only on documented instructions from the Customer.
2.3. The processing operations for which Dexlo acts as controller (user accounts, invoicing, support, security of the service, as well as business prospecting and the demo requests received through its website) do not fall within the scope of this agreement. They are described in the privacy policy.
3. Subject matter, nature, purpose and duration of the processing
3.1. Subject matter. The processing, by Dexlo, of the operating data of the Customer’s establishment for the purpose of providing the Dexlo software.
3.2. Nature of the operations. Collection through connection to the Customer’s property management system (PMS) or through import of exports provided by the Customer; recording; storage; structuring; calculation and formatting; consultation by the Customer’s authorised users; transmission to the sub-processors listed in Annex 1; erasure.
When the price-sending feature is activated for the establishment during onboarding, Dexlo also transmits to the Customer’s PMS, on explicit action by a user of the Customer, the price that user has chosen for a night. By default, a decision is only recorded in the Dexlo software; no price is changed in the PMS without this action.
3.3. Purposes. Exclusively:
- measuring the gap between the establishment’s published rates and those of a competitor panel;
- measuring the booking pace and forecast occupancy;
- producing alerts and pricing recommendations for the Customer and, where applicable, transmitting to its PMS the prices it decides to send there;
- producing the periodic reports provided for in the contract;
- ensuring the security, continuity and proper functioning of the service.
No other purpose. Dexlo does not reuse the Customer’s data for its own account, nor to build market references, indices or statistics exploited for the benefit of third parties.
3.4. Duration. This agreement takes effect on the date of subscription and remains in force for the entire term of the contract, plus the time needed to perform Article 11.
4. Categories of data processed
4.1. Data actually processed
| Category | Content | Source |
|---|---|---|
| Bookings | Technical booking identifier, status, source channel, creation, cancellation and last-modification timestamps, arrival and departure dates, requested room category | Customer’s PMS or exports |
| Rates | Establishment’s published rates, history | Customer’s PMS or exports |
| Occupancy | Occupancy per night, capacity | Customer’s PMS or exports |
| Booking pace | Derived from the booking timestamps | Calculated by Dexlo |
| Establishment | Name, type, city, geographical coordinates, competitor panel | Customer |
| Access accounts | Business email address, password hash, role | Customer (see clause 2.3) |
The list of fields read from the PMS is closed: nine fields, described in the privacy policy.
4.2. Expressly excluded data
Dexlo collects no directly identifying data of the establishment’s end customers: no surname, first name, email address, telephone number, postal address, payment data, identity document, guest profile identifier, review content or number of persons per booking.
This exclusion is structural: the list of fields read by the connector contains none of them, and the data model that receives bookings contains no column that could receive them. Details are set out in the privacy policy.
The service collects no sensitive data within the meaning of Article 9 GDPR, nor any data relating to criminal convictions or offences within the meaning of Article 10.
4.3. Categories of data subjects
- The Customer’s users authorised to access the service (the Customer’s employees, executives and contractors).
- Where applicable, and indirectly, the establishment’s end customers: the booking data processed contains no directly identifying identifier, but a technical booking identifier may, when matched against the Customer’s systems, be linked to a person. The Parties agree to treat such data as personal data, as a precaution and without admission, and to apply this entire agreement to it.
5. Instructions of the Customer
5.1. Dexlo processes the data only on documented instructions from the Customer. The contract, this agreement and the settings made by the Customer in the service constitute such instructions.
5.2. Dexlo informs the Customer immediately if it considers that an instruction infringes the GDPR or another provision of Union law or French law relating to data protection. It may then suspend the execution of the instruction concerned until it is regularised.
5.3. If Dexlo is required to carry out a transfer under Union law or the law of a Member State, it informs the Customer before the processing, unless the law prohibits such information on grounds of public interest.
6. Confidentiality and authorised persons
6.1. Dexlo ensures that the persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
6.2. As of the date hereof, Dexlo is operated by a single person, the publisher, who is the only person authorised to access production data. There is therefore no team, no internal authorisation procedure and no segregation of duties.
6.3. Access to production data is limited to what is necessary for the performance of the contract and the security of the service.
7. Security of processing
7.1. Dexlo implements appropriate technical and organisational measures within the meaning of Article 32 GDPR. These measures are described in Annex 2.
7.2. The measures in Annex 2 are those in place on the date of this agreement. They may change, without the level of security being reduced.
7.3. The Customer acknowledges that it is responsible for assessing whether these measures are appropriate to the risks of its processing, and for managing the authorisations of its own users.
8. Sub-processing
8.1. The Customer gives Dexlo a general authorisation to engage the sub-processors listed in Annex 1, in accordance with Article 28(2) GDPR.
8.2. Dexlo informs the Customer, in writing and at least thirty (30) days in advance, of any addition or replacement of a sub-processor.
8.3. The Customer may object to the change, in writing and with reasons, within that period. Failing agreement, the Customer may terminate the contract without penalty, with effect from the date on which the change comes into force.
8.4. The engagement of a sub-processor is subject to the conditions of Article 28(2) and (4) GDPR. Dexlo remains fully liable to the Customer for the performance by its sub-processors of their data protection obligations. It provides the Customer, on request, with the contractual conditions applicable to each of them.
9. Assistance to the Customer
9.1. Rights of data subjects (Articles 12 to 22 GDPR)
Dexlo assists the Customer, by appropriate technical and organisational measures and insofar as possible, to enable it to respond to requests to exercise rights.
If a request is addressed directly to Dexlo, Dexlo does not respond to the data subject: it forwards the request to the Customer without delay and at the latest within five (5) business days.
9.2. Obligations under Articles 32 to 36 GDPR
Taking into account the nature of the processing and the information available to it, Dexlo assists the Customer with: the security of the processing; the notification of breaches; communication to data subjects; carrying out a data protection impact assessment and, where applicable, the prior consultation of the supervisory authority.
9.3. Cost
The assistance provided for in this article is included in the subscription within reasonable limits. A manifestly excessive or repetitive request may be invoiced, on the basis of a quotation accepted in advance by the Customer.
10. Personal data breach
10.1. Dexlo notifies the Customer of any personal data breach concerning the data processed on its behalf, as soon as possible after becoming aware of it, and at the latest forty-eight (48) hours thereafter.
10.2. The notification is sent by email to the contact designated by the Customer and includes, to the extent that the information is available: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and the contact details of a contact point.
10.3. If all the information cannot be provided at once, it is provided in phases, without undue delay.
10.4. Notification to the supervisory authority and, where applicable, to data subjects is the responsibility of the Customer, as controller. Dexlo does not notify the CNIL on its behalf.
10.5. Dexlo documents any breach and makes this documentation available to the Customer.
11. Handling of data at the end of the contract and reversibility
11.1. Customer’s choice. At the end of the contract, for whatever reason, the Customer chooses between the return of the data and its erasure. Failing a choice expressed within thirty (30) days following the end of the contract, Dexlo proceeds with erasure.
11.2. Return. On a request made during the term of the contract or within thirty (30) days following its end, Dexlo provides the Customer with an export of the data of its establishment, in a commonly used, machine-readable structured format. This provision is included in the subscription for a first request.
The scope of the return comprises: the bookings, the rate observations, the observed PMS rates, the tracked competitors, the pricing recommendations and the decision log. The format is one CSV file per dataset, in UTF-8. Delivery takes place within thirty (30) days of the request.
11.3. Erasure. After return, or failing a request for return, Dexlo erases the data and the existing copies within thirty (30) days from the end of the period in clause 11.1, unless there is a legal obligation to retain them.
11.4. Backups. The host’s backups retain the data until the end of their retention period. Dexlo does not carry out item-by-item erasure in them; they are not used and expire according to their cycle. Deleted data may therefore remain in these backups until they expire; the backup retention period is provided to the Customer on request.
11.5. Proof. Dexlo certifies the erasure in writing, at the Customer’s request.
11.6. Revocation of access. The Customer may at any time revoke, in its own management system, the access granted to Dexlo. This revocation stops any new collection and any sending of prices to the PMS.
12. Transfers outside the European Union
12.1. The application, the database and the cache are hosted in the European Union, in the Frankfurt region (Germany). The authenticated interface is served by Vercel, which may run it outside the European Union: operating data does not pass through it, but the session token is read there by the access control.
12.2. Some sub-processors are established outside the European Union, or are connected to it. They are identified as such in Annex 1.
12.3. Any transfer of data outside the European Union is subject to the conditions of Chapter V GDPR. Dexlo provides the Customer, on request and for each sub-processor concerned, with the information it has on the safeguards governing these transfers.
13. Information and audits
13.1. Dexlo makes available to the Customer all information necessary to demonstrate compliance with the obligations of Article 28 GDPR.
13.2. Audits. The Customer may have an audit carried out, no more than once a year, subject to thirty (30) days’ written notice, during business hours, without disrupting operations, and subject to a confidentiality undertaking by the auditor. The auditor may not be a competitor of Dexlo.
13.3. Given the size of the organisation, it is agreed that Dexlo responds primarily by documentary means (questionnaire, configuration items, attestations from its own sub-processors). An on-site audit is carried out only where this response is demonstrably insufficient.
13.4. The costs of the audit are borne by the Customer, unless the audit reveals a substantial breach by Dexlo.
14. Liability
14.1. Each Party is liable for the damage caused by processing that infringes the GDPR, under the conditions of Article 82 thereof.
14.2. The limitations of liability stipulated in the Terms of Sale apply to this agreement to the extent permitted by law. They may not limit the rights of data subjects or prevent penalties imposed by a supervisory authority.
15. Final provisions
15.1. Duration: see clause 3.4.
15.2. Amendment. Any amendment is made by written addendum. By way of exception, updates to Annex 1 follow the procedure in Article 8.
15.3. Changes in the law. If a legislative, regulatory or case-law development renders a provision non-compliant, the Parties will consult each other in order to bring it into compliance.
15.4. Partial nullity. The nullity of one provision does not affect the others.
15.5. Governing law and jurisdiction. This agreement is governed by French law. Failing amicable resolution, any dispute falls within the exclusive jurisdiction of the Nanterre Economic Activities Court (tribunal des activités économiques de Nanterre).
Annex 1: Sub-processors
Providers used by Dexlo to perform the service.
| Provider | Role | Data transmitted | Place of processing |
|---|---|---|---|
| Render | Hosting of the application, the database and the cache | All the data processed | European Union, Frankfurt (Germany). Company governed by U.S. law: access from the United States cannot be ruled out. |
| Vercel | Hosting of the service’s authenticated interface | Requests from the Customer’s users (IP address, pages requested) and, on protected pages, the session token (user identifier and role, signed), read by the access control. Operating data (bookings, rates, recommendations) is exchanged directly between the browser and the application hosted by Render, without passing through Vercel. | Execution region not fixed: the interface may run outside the European Union. Company governed by U.S. law. |
| Sentry | Monitoring of technical errors | Technical error reports, which may include technical elements of the request concerned | European Union |
| DataForSEO | Collection of competitors’ public rates | Search subjects: establishments, locations, dates. No Customer data. | Not applicable: no personal data is transmitted to it. |
The following are not sub-processors:
- The Customer’s property management system (PMS). It is the Customer’s tool, under its own contract. Dexlo connects to it with the access granted by the Customer: it receives data from it and, when the sending feature is activated, transmits to it the prices the Customer decides to send. Dexlo is not its principal.
- The public sources queried (weather services, local event services, a public geocoding service), to which an establishment location or a search subject is transmitted, and no personal data.
Annex 2: Technical and organisational measures
Measures in place on the date of this agreement.
A. Access control and authentication
- Passwords never stored in plain text: bcrypt hash, 12 rounds.
- Signed session token, set in an httpOnly cookie, marked secure (transmitted over HTTPS only) and SameSite=Strict in production; CSRF protection by double submission, mandatory in production.
- Partitioning: an account only accesses the data of the establishment to which it is linked.
- Public sign-up closed: accounts are created by the publisher.
- Allowed origins limited to the official interface.
- No multi-factor authentication at this stage (declared, not promised).
B. Encryption and hosting
- In transit: access to the service over HTTPS only.
- At rest, PMS access secrets: each establishment’s access token is encrypted (Fernet, a dedicated key separate from the session signing key), and is decrypted only when it is used. It does not appear in any log, not even in encrypted form.
- Database hosting: Render, which reports ISO 27001 and SOC 2 Type 2 certifications.
C. Production configuration guard
The application refuses to start in production if the configuration is dangerous: authentication bypass enabled, a secret left at its default value, missing at-rest encryption key, development database, or SQL query echo enabled. This guard is structural: it does not depend on a human check.
D. Minimisation and control of sending
- Closed allowlist of nine fields read from the PMS; no directly identifying field is included in it.
- Destination data model with no column that could receive directly identifying data.
- Sending prices to the PMS: only when the feature is activated for the establishment, during onboarding and depending on the compatibility of the PMS, and only on explicit action by a user of the Customer, from a night’s file. By default, a decision is only recorded in the Dexlo software.
- Missing data is never filled in with an estimated value: it is declared, with its reason.
E. Logging and monitoring
- Application logging excludes the query string, request bodies and authentication headers.
- Retention of application logs: seven (7) days.
- A correlation identifier per request, enabling incidents to be traced.
- Monitoring of technical errors (see Annex 1).
F. Location
- Hosting of the application, the API, the worker, the database and the cache in the European Union, Frankfurt region (Germany).
- The authenticated interface is served by Vercel, which may run it outside the European Union. It does not receive operating data; it reads the session token for access control.
G. Organisation
- A single person accesses production data (clause 6.2).
- Method rule (organisational, not technically enforced): development through branches and review before release to production; no writing to production from a development environment. Stated here as an internal rule, not as a technical guarantee.
H. Backups
- Continuous database backups; restore window: the last three (3) days.
- The backup retention period is provided to the Customer on request (clause 11.4).
No measure other than those described in this annex is declared under this agreement.