← Back to home

Data Processing Agreement

Last updated: August 2026

This Data Processing Agreement (DPA) sets out the Art. 28 GDPR terms under which Partelisto processes guest check-in data on behalf of a host. It applies to every host who collects guest data through Partelisto and forms part of the Terms of Service. Where this DPA and the Terms conflict on data protection, this DPA prevails. It is provided in good faith as a working template and should be reviewed by a Spanish data-protection professional before commercial launch.

Parties

Controller: you, the host or property manager who uses Partelisto to collect guest data (the "Controller"). Processor: Mikhail Petrusheuski (self-employed / autónomo), trading as Partelisto, NIE Z1493872G, Avinguda de la Vila Joiosa 12, 03502 Benidorm (Alicante), Spain — support@partelisto.es (the "Processor"). By using Partelisto to collect guest data you accept this DPA.

Subject-matter, nature and purpose

The Processor processes personal data solely to provide the service: collecting guest check-in data via the guest link and form, generating the check-in PDF/CSV, storing it for the host, and producing or transmitting the SES.HOSPEDAJES traveller register. The Processor does not process the data for any other purpose and never for its own purposes.

Duration

Processing lasts for as long as the host uses the service, plus any retention period required by law (see Retention in the Privacy Policy). This DPA remains in force while the Processor holds any of the Controller’s guest data.

Categories of data and data subjects

Data subjects: the host’s guests, including accompanying minors. Categories of data: name and surnames, date of birth, sex, nationality, identity document type and number, contact phone or email, residence, relationship for minors, stay dates and a typed or drawn signature. No special-category data is required; the Processor does not ask for or store photos or scans of identity documents.

Roles

For guest check-in data the Controller determines the purposes and means and the Processor acts only on the Controller’s behalf. For the Processor’s own account, billing and support data, Partelisto is an independent controller under its Privacy Policy — that data is outside this DPA.

Processing on documented instructions

The Processor processes guest data only on the Controller’s documented instructions, which are given through the configuration and use of the service and this DPA, including for any transfer to a third country, unless required to do otherwise by EU or Member State law (in which case the Processor informs the Controller first, unless the law forbids it). Transmission of the register to SES.HOSPEDAJES is a documented instruction from the Controller in fulfilment of its legal obligation.

Confidentiality

The Processor ensures that persons authorised to process the guest data are bound by confidentiality and process it only as needed to provide the service.

Security measures (Art. 32)

The Processor implements appropriate technical and organisational measures: EU-hosted infrastructure, encryption in transit, access restricted by role and by tenant, tenant isolation between hosts, and data minimisation (no ID scans). The Processor never requests guest passwords. Measures are reviewed as the service evolves.

Sub-processors

The Controller gives general authorisation for the Processor to engage sub-processors needed to run the service (hosting/storage, database, authentication and — for host billing only — payment processing via Stripe; guests never pay). Current sub-processor categories are listed in the Privacy Policy and available in full at support@partelisto.es. The Processor imposes equivalent data-protection obligations on each sub-processor and remains liable for their performance. The Processor will give reasonable notice of any intended change and the Controller may object on reasonable data-protection grounds.

Assistance with data subject rights

Taking account of the nature of the processing, the Processor assists the Controller with appropriate measures to respond to guests exercising access, rectification, erasure, restriction, portability and objection. If a guest contacts the Processor directly, the Processor forwards the request to the Controller and does not respond on the merits itself.

Assistance with security, breaches and DPIAs

The Processor assists the Controller in ensuring compliance with Arts. 32–36 GDPR, taking into account the nature of processing and the information available to the Processor, including with security, personal-data-breach handling, data protection impact assessments and prior consultation.

Personal data breach

The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting the guest data, with the information the Controller needs to meet its own notification duties (Arts. 33–34). Notification is sent to the host’s account contact and via support@partelisto.es.

International transfers

Guest register data is hosted within the EU/EEA and is not transferred outside the EU by the Processor. Where a sub-processor could involve a transfer, it is covered by an adequacy decision or the appropriate safeguards under Chapter V GDPR.

Return or deletion of data

On termination, or on the Controller’s request, the Processor deletes or returns the guest data and deletes existing copies, unless EU or Member State law requires storage — in particular the traveller-register retention that applies to professionally-obliged hosts. Where a record must be kept, only the minimum proof-of-filing is retained and the identifying guest data is deleted.

Audits and information

The Processor makes available to the Controller the information necessary to demonstrate compliance with Art. 28 and allows for and contributes to reasonable audits, including inspections, conducted by the Controller or an auditor it mandates, on reasonable notice and subject to confidentiality.

Liability and governing law

Liability follows Art. 82 GDPR and the limitations in the Terms of Service, to the extent permitted by law. This DPA is governed by Spanish law. Questions: support@partelisto.es.