1. Purpose & Roles
This Data Processing Addendum (“DPA”) applies where CYVERNA processes personal data on behalf of the Customer through CYVERNA Hotel PMS. The Customer/Hotel is the Data Fiduciary/controller for Hotel-controlled data and CYVERNA is the Data Processor/service provider, except for CYVERNA’s separate processing for its own billing, security, subscription, support administration and legal compliance.
2. Customer Instructions
CYVERNA will process Customer personal data only to provide, secure, support, maintain and improve the contracted service within documented Customer configuration/instructions and applicable law. The Customer is responsible for the lawfulness, accuracy and scope of those instructions.
3. Confidentiality & Personnel
CYVERNA will restrict Customer personal data to personnel/service providers who need access for the service and who are bound by appropriate confidentiality obligations. The Customer must impose equivalent confidentiality/least-privilege controls on Hotel users.
4. Security
CYVERNA will maintain reasonable technical and organisational safeguards within its service scope, including appropriate access control, secure credential handling, logging, backups/availability controls and incident handling. The Customer remains responsible for its hosting account (where Customer-hosted), endpoint/network security, password practices, user access and configuration.
5. Subprocessors & Third-Party Connectors
CYVERNA may use subprocessors needed to deliver the contracted service. Customer-configured OTAs, payment gateways, WhatsApp/SMS/email, OCR/AI, locks/IoT and accounting connectors are separately authorised by the Customer and are governed by their own terms. The Customer should review each provider’s data location, security and privacy terms.
6. Personal Data Breach Cooperation
If CYVERNA becomes aware of a confirmed breach of Customer personal data within CYVERNA’s processor scope, CYVERNA will notify the Customer without undue delay, provide information reasonably available to it, and cooperate with containment and legally required notifications. The Customer is responsible for its Data Fiduciary notification decisions unless law directly imposes a separate CYVERNA obligation.
7. Data Principal Requests
CYVERNA will provide reasonable technical assistance for access, correction, erasure, export, consent and grievance requests as instructed by the Customer and supported by the service. CYVERNA will not independently disclose Hotel-controlled guest data to a requester without Customer instruction or legal requirement.
8. Return, Export & Deletion
Upon termination or a valid Customer instruction, CYVERNA will support export/return/deletion consistent with the commercial agreement, backup lifecycle, legal retention and technical feasibility. Customer must preserve statutory records before requesting deletion.
9. Audit & Evidence
CYVERNA may provide relevant security/compliance evidence, logs or questionnaire responses reasonably necessary to demonstrate processor obligations, subject to confidentiality, security and commercial limits. Customer may not use audit rights to obtain source code, other customers’ data or information that would compromise Platform security.
10. Liability & Responsibility Allocation
Each party remains responsible for obligations that applicable law assigns to it. To the maximum extent permitted by law, Customer remains responsible for Hotel purposes, notices/consents, data accuracy, staff access, statutory retention, guest responses and third-party connectors it selects. This DPA does not enlarge CYVERNA’s liability beyond the signed commercial agreement, and no clause excludes liability that law makes non-excludable.
