Data Processing Agreement
Last updated: 2026-06-10
Need a signed copy for procurement? Download the DPA as a PDF and send the countersigned version to [email protected].
Download PDFThis Data Processing Agreement ("DPA") forms part of the service agreement between the Customer and Resort Buggy and reflects the requirements of Article 28 of the EU General Data Protection Regulation (GDPR). This template is published for transparency and is pending formal legal review — before an EU customer signs, the executed version will be reviewed by legal counsel.
1. Parties
Data controller: the Customer — the resort, golf club, or other property organization that subscribes to the service and determines the purposes of processing.
Data processor: Resort Buggy, operated by [Legal Entity Name] ("Resort Buggy"), which processes personal data on the Customer's behalf to provide the service.
2. Subject matter and duration
The subject matter is the processing of personal data necessary to operate Resort Buggy's on-demand transport dispatch service for the Customer's property. Processing lasts for the duration of the service agreement, plus the retention periods set out in our Privacy Policy (ride history: 12 months by default, configurable; backups: 30 days).
3. Nature and purpose of processing
Collection, storage, transmission, display, and deletion of personal data for the sole purpose of dispatching rides at the Customer's property: connecting guests requesting pickups with drivers, showing live ride status, and giving the Customer operational reporting.
4. Categories of personal data
- Staff (admins, drivers): name, email (admins), access codes, IP address, browser information
- Guests: name or room/villa identifier (provided by the Customer), access code, pickup/dropoff selections, GPS location while the app is actively in use, push notification token (if opted in)
- No payment data, guest email addresses, or guest phone numbers are processed
5. Categories of data subjects
- The Customer's staff: administrators and drivers
- The Customer's guests or members using the service
6. Processor obligations
Resort Buggy shall:
- Process personal data only on the Customer's documented instructions, including with regard to international transfers
- Ensure persons authorized to process the data are bound by confidentiality
- Implement the technical and organizational measures in the Annex below
- Engage sub-processors only under the conditions in Section 7
- Assist the Customer in responding to data subject requests (access, correction, deletion, export, objection)
- Assist the Customer with security, breach notification, and impact-assessment obligations under Articles 32–36 GDPR
- Delete or return all personal data at the end of the service, at the Customer's choice, and delete remaining copies unless law requires retention
- Make available information necessary to demonstrate compliance and allow for and contribute to audits, including inspections, conducted by the Customer or its mandated auditor
- Notify the Customer without undue delay — and in any case within 72 hours — after becoming aware of a personal data breach affecting the Customer's data
7. Sub-processors
The Customer grants general authorization for the sub-processors listed below. This list is public and kept current on this page.
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Cloud hosting and storage of all service data | Germany / Finland (EU) |
| Resend, Inc. | Transactional email delivery (admin notifications) | United States |
| Cloudflare, Inc. | Anti-spam verification (Turnstile) on web forms | United States (global network) |
| Esri Inc. | Satellite imagery tiles for in-app maps | United States |
| CARTO (CartoDB Inc.) | Basemap label tiles for in-app maps | Spain (EU) / United States |
| OpenStreetMap Foundation (Nominatim) | Address search (geocoding) in the admin map editor | United Kingdom |
We will notify customers by email at least 30 days before adding or replacing a sub-processor. The Customer may object on reasonable data-protection grounds; if we cannot resolve the objection, the Customer may terminate the affected service.
8. International transfers
All service data is hosted and processed on Hetzner Cloud in the European Union. Where a sub-processor processes limited personal data outside the EEA (Resend, Cloudflare, Esri, and CARTO, United States), the transfer is safeguarded by the EU Standard Contractual Clauses (SCCs) and, where applicable, the EU–US Data Privacy Framework. Geocoding queries to OpenStreetMap Nominatim (United Kingdom) are covered by the EU's adequacy decision for the UK. For UK customers, the UK International Data Transfer Addendum to the SCCs applies.
Annex: Technical and Organizational Measures (TOMs)
- Encryption: TLS for all traffic in transit; the production database is encrypted at rest (LUKS, AES-256); database access restricted to the application over a private network
- Access control: token-based authentication (JWT) with strict role separation between guests, drivers, and admins; guest access codes expire automatically at checkout and can be revoked instantly
- Tenant isolation: every database query is scoped to the Customer's property ID at the application layer — no cross-property data visibility
- Data minimization: we collect only the data needed to dispatch a ride; no payment data, no guest contact details, no cross-site tracking
- Backup & recovery: automated daily database backups, client-side encrypted before off-box upload, with 30-day retention
- Incident response: security reports acknowledged within 24 hours; confirmed breaches notified within 72 hours
Full details on our Security page.
Contact
Questions about this DPA, or need it countersigned? [email protected]