Last updated: 13 September 2026 · This Data Processing Agreement forms part of the HOTEL Ready Terms of Service.
1. What This Agreement Covers
This Data Processing Agreement ("DPA") applies whenever Hotel Consult Ltd, Vitoshka Zornitsa Street, 1415 Sofia, Bulgaria (the "Processor") processes personal data on behalf of the Customer (the "Controller") in providing the HOTEL Ready service. It implements Article 28 of Regulation (EU) 2016/679 ("GDPR"). It is entered into by accepting the Terms of Service; on request we also provide it as a signed document.
It covers the personal data of the Controller's staff processed inside the app. It does not cover data for which we are ourselves the controller (website visits, pilot enquiries, manager billing contacts) — that processing is described in the Privacy Policy.
2. Details of the Processing
| Subject matter | Provision of the HOTEL Ready staff training platform |
|---|---|
| Duration | The term of the Customer's subscription, plus the deletion period in section 9 |
| Nature and purpose | Hosting and storage of account and training data; generation of AI practice dialogues and automated training feedback; display of results to the Controller's authorised managers |
| Categories of data | Staff: first name, last name, department, job title, login PIN (hashed), training results and progress, voice recordings when answering by voice (transcribed, not stored). Managers/administrators: email address, IP address and browser data at login |
| Categories of data subjects | The Controller's employees, trainees and managers |
| Special categories | None — the service neither requires nor requests them |
3. The Controller's Instructions
We process this personal data only on the Controller's documented instructions, including regarding transfers outside the EU/EEA, unless EU or Member State law requires otherwise — in which case we inform the Controller before processing, unless that law forbids it. The Terms of Service, this DPA and the Controller's use of the service's settings constitute the complete instructions. We will inform the Controller immediately if, in our opinion, an instruction infringes the GDPR.
4. Confidentiality
Only persons who need access to provide the service receive it, and every such person is bound by a contractual or statutory duty of confidentiality.
5. Security (Article 32 GDPR)
We implement appropriate technical and organisational measures, including: encryption of all data in transit (HTTPS/TLS); storage of PINs and passwords only as bcrypt hashes; hosting of the training database in the EU; role-based access limited to the respective organisation's authorised managers; separation of AI processing from identity data (the AI providers receive conversation text and, for spoken answers, the voice recording — never names or PINs); voice recordings not stored, and conversation transcripts kept on the end device rather than our servers; and regular review of these measures. We assist the Controller in ensuring compliance with Articles 32–36 GDPR, taking into account the nature of the processing and the information available to us.
6. Sub-processors
The Controller gives general authorisation for these sub-processors:
| Sub-processor | Purpose | Location / transfer safeguard |
|---|---|---|
| Supabase | Database hosting for account and training data | EU |
| Anthropic | Generation of AI dialogue and evaluation (conversation text only) | USA — EU–US Data Privacy Framework |
| ElevenLabs | Voice synthesis and speech-to-text transcription (text to be read aloud; staff voice recordings when answering by voice) | USA — EU standard contractual clauses |
| Vercel | Application hosting (technical request data) | USA — EU–US Data Privacy Framework |
| Resend | Delivery of service emails to the Controller's managers, including department reports (aggregated figures, no staff names) | USA — EU–US Data Privacy Framework |
Each sub-processor is bound by data protection obligations equivalent to this DPA, and we remain fully liable to the Controller for their performance. We give at least 30 days' notice of any intended addition or replacement (by email or in the app); the Controller may object on reasonable data protection grounds, and if we cannot offer a solution, the Controller may terminate the affected subscription without penalty.
7. Assisting With Data Subject Rights
Taking into account the nature of the processing, we assist the Controller with appropriate technical and organisational measures in fulfilling requests under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection) — primarily through the deletion and management functions built into the manager dashboard, and beyond that on request. If a data subject contacts us directly, we forward the request to the Controller without undue delay and do not respond on the merits unless the Controller asks us to.
8. Personal Data Breach
We notify the Controller without undue delay, and no later than 48 hours, after becoming aware of a personal data breach affecting the Controller's data, providing the information reasonably needed for the Controller's obligations under Articles 33–34 GDPR: the nature of the breach, categories and approximate numbers of data subjects and records concerned, likely consequences, and the measures taken or proposed. We document all breaches and cooperate in their investigation.
9. Deletion and Return
During the subscription, the Controller can delete staff profiles and training data at any time through the dashboard. Upon termination of the service, we delete or — at the Controller's choice, expressed within 14 days — return all personal data processed under this DPA within 30 days, and delete existing copies, unless EU or Member State law requires longer storage. Deletion from backups follows within the regular backup rotation cycle.
10. Audits
We make available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR, and answer reasonable written audit questionnaires within 30 days. The Controller (or an auditor it mandates who is not our competitor) may conduct an audit, including an inspection, no more than once per year with at least 30 days' notice, during business hours, without disrupting operations, at the Controller's cost, and under confidentiality.
11. International Transfers
Personal data is stored in the EU. Where processing by a sub-processor involves a transfer outside the EU/EEA, it takes place only under Chapter V GDPR: an adequacy decision (including the EU–US Data Privacy Framework) or the European Commission's standard contractual clauses, as listed in section 6.
12. Liability, Term and Law
This DPA takes effect with the Terms of Service and lasts as long as we process personal data on the Controller's behalf. The liability provisions of the Terms of Service apply, except where the GDPR provides otherwise (Article 82). This DPA is governed by Bulgarian law; in case of conflict between this DPA and the Terms of Service, this DPA prevails for data protection matters. It exists in English and Bulgarian; in case of differences, the English version prevails.
Contact
Hotel Consult Ltd · UIC 204073745 · Vitoshka Zornitsa Street, 1415 Sofia, Bulgaria · hello@hotel-ready.com · +359 899 823 448 · To receive this DPA as a countersigned document, email us with your company details.