Data Processing Agreement
Last updated: 2026-08-31
Need a signed copy for procurement? Download the DPA as a PDF and send the countersigned version to [email protected].
Download PDFThis Data Processing Agreement ("DPA") forms part of the service agreement between the Customer and Resort Buggy and gives effect to Article 28 of the EU General Data Protection Regulation (GDPR).
1. Parties
Data controller: the Customer — the resort, golf club, or other property organization that subscribes to the service and determines the purposes of processing.
Data processor: Resort Buggy, operated by NORTHDAN SOFT SRL, CUI RO44282833, registered office Iuliu Maniu 19C, Aiud, Alba, Romania ("Resort Buggy"), which processes personal data on the Customer's behalf to provide the service.
2. Subject matter and duration
The subject matter is the processing of personal data necessary to operate Resort Buggy's on-demand transport dispatch service for the Customer's property. Processing lasts for the duration of the service agreement, and all data is deleted or returned at the end of the agreement, or earlier at the Customer's request. Backups are retained for 30 days.
Guest identity is deleted on a schedule; the ride record is not. Ninety days after a guest's stated checkout — or immediately, when the Customer removes a guest from the console — we delete the guest's name, contact details, special requests, messages and the guest record itself. We do not delete the ride. A ride record — its times, its pick-up and drop-off points, its duration and its outcome — is retained as operational history and, after deletion, is attached to nobody. Data already exported through the partner API is unaffected, because it never contained a guest's identity to begin with: no name, no identifier, no contact detail crosses that boundary at any time.
The same 30-day window applies to every anonymous session: on properties using villa QR codes, when the stay closes; and for a code posted at a venue, from the moment that session ends. In both cases the session's chat messages are deleted, the typed name is reset to the name of the villa or the venue, and the device's access code stops working. Guests with no checkout date on file are never reached by the 90-day rule, because their access has no end date; the count is shown in the Customer's console. Full detail is in our Privacy Policy.
3. Nature and purpose of processing
Collection, storage, transmission, display, and deletion of personal data for the purposes of dispatching rides at the Customer's property and recording the condition of the Customer's vehicles: connecting guests requesting pickups with drivers, showing live ride status, and giving the Customer operational reporting.
Guest and staff message translation runs on infrastructure we operate. Adding or replacing a translation provider is a sub-processor change and is notified under Section 7.
4. Categories of personal data
- Staff (admins, drivers): name, email (admins), access codes, IP address, browser information
- Drivers, additionally, where the Customer switches on vehicle checks: the answers a named driver gave about a vehicle's condition at the start and end of a shift, any free text they typed with an answer, photographs of the vehicle they took, the odometer readings they entered, a permanent count of shifts that ended without their own end check, and any fault they report about a vehicle with its category, note and photograph
- Drivers, additionally: free-text notes a driver types about a ride he is or was assigned to, stored under his name with the time and the language he wrote in, read by the Customer's administrators on the ride's record and in the ride export
- Drivers, additionally: rides a driver records for guests who waved him down, stored under his name and his vehicle with no guest attached, and counted in his own and his vehicle's figures
- Drivers, additionally: spans a driver declares on a ride he is carrying out — that other guests have stopped him, or that he is waiting outside a door — each stored under his name with when it began, when it ended and how, and any note he attached
- Staff, additionally: counts and averages per named staff member, derived from the records above when the Customer's administrators read a reporting screen or export — jobs done, checks completed, rides taken, declined or let pass, minutes spent waiting outside doors, and the average minutes a job took. No separate per-person figure is stored
- Guests: name or room/villa identifier (provided by the Customer, or a first name the guest types herself when she scans a code posted at a venue), access code, email address where the Customer supplies one for pre-arrival messaging, pickup/dropoff selections, GPS location while the app is actively in use, the location at the moment a ride is called, on codes the resort marks Require location, checked against the property outline plus the resort's allowed distance, special requests and any free text entered with a ride or booking request, chat messages and any photos sent in chat, push notification token (if opted in)
- Guests and staff, where the Customer switches on Hold phone numbers: a telephone number in international (E.164) form, held so the Customer's front desk can call the person. A guest's number is erased at checkout; a staff member's is erased when the record is deleted or the Customer turns the setting off. Only the Customer's administrators can read a number
- No payment data is processed
5. Categories of data subjects
- The Customer's staff: administrators and drivers
- The Customer's guests or members using the service
6. Processor obligations
Resort Buggy shall:
- Process personal data only on the Customer's documented instructions, including with regard to international transfers, unless Union or Member State law requires otherwise; where it does, we will inform the Customer of that requirement before processing, unless the law prohibits it on important grounds of public interest
- Ensure persons authorized to process the data are bound by confidentiality
- Implement the technical and organizational measures in the Annex below
- Engage sub-processors only under the conditions in Section 7
- Assist the Customer in responding to data subject requests (access, correction, deletion, export, objection)
- Assist the Customer with security, breach notification, and impact-assessment obligations under Articles 32–36 GDPR
- Delete or return all personal data at the end of the service, at the Customer's choice, and delete remaining copies unless law requires retention
- Make available the information necessary to demonstrate compliance and allow for and contribute to audits, including inspections, conducted by the Customer or its mandated auditor: on 30 days' written notice, once in any 12-month period and additionally after a personal data breach affecting the Customer or where a supervisory authority requires it, during business hours, by an auditor bound by confidentiality and who is not our competitor, at the Customer's cost, and we may satisfy an audit request in the first instance with our current security documentation
- Notify the Customer without undue delay — and in any case within 72 hours — after becoming aware of a personal data breach affecting the Customer's data
- Include in that notification the nature of the breach, the categories and approximate number of data subjects and records affected, our contact point, the likely consequences, and the measures taken or proposed; and supplement it as further information becomes available
- Inform the Customer immediately if, in our opinion, an instruction infringes the GDPR or other Union or Member State data protection law
- Where the Customer is subject to a data protection law other than the GDPR, negotiate in good faith and execute an addendum reflecting that law's requirements, and provide the information the Customer needs for its own regulatory filings
7. Sub-processors
The Customer grants general authorization for the sub-processors listed below — every sub-processor that handles personal data we process on a Customer's behalf. This list is public and kept current on this page.
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Cloud hosting and storage of all service data | Finland (hosting) and Germany (backups), EU |
| Resend, Inc. | Email delivery — pre-arrival emails to guests and notifications to property administrators | United States |
| Cloudflare, Inc. | Delivery and protection of application traffic, and anti-spam verification on web forms | United States (global edge network) |
| Esri Inc. | Satellite imagery tiles for in-app maps | United States |
| CARTO (CartoDB Inc.) | Basemap label tiles for in-app maps | Spain (EU) / United States |
| OpenStreetMap Foundation (Nominatim) | Address search (geocoding) in the admin map editor | United Kingdom |
| OpenAI | Illustrated property map generation from satellite imagery — no personal data | United States |
| Anthropic PBC | Support-report triage — the text of a problem report sent from the property console, the screen it was sent from and the browser trail attached to it | United States |
We will notify customers by email at least 30 days before adding or replacing a sub-processor. The Customer may object on reasonable data-protection grounds. While an objection is open we will not use the new sub-processor for that Customer's data. If we cannot resolve the objection, the Customer may terminate the affected service without penalty, and we refund the fees paid for the part of the term not provided.
Where the agreement is transferred to a successor under Section 20 of the Terms, this DPA transfers with it and the successor becomes the processor on the same terms; that transfer is not a sub-processor change.
8. International transfers
The service database, uploaded files and backups are stored on Hetzner Cloud in the European Union, and the application that processes them runs there. Application traffic reaches it through Cloudflare's global edge network, so Cloudflare processes personal data in transit. Where a sub-processor processes personal data outside the EEA — Cloudflare, Resend and Esri (United States) and CARTO (Spain and the United States) — the transfer is safeguarded by the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module Three, processor to processor) and, where that sub-processor is certified, the EU–US Data Privacy Framework. Geocoding queries to OpenStreetMap Nominatim (United Kingdom) are covered by the EU's adequacy decision for the UK. For UK customers, the UK International Data Transfer Addendum to the SCCs applies.
Where those Clauses apply, Sections 1, 3, 4 and 5 of this DPA are the description of the parties and of the transfer, the Annex of Technical and Organizational Measures is the description of the security measures, and the sub-processor table in Section 7 is the list of authorised sub-processors. The competent supervisory authority is the one identified on the Customer's Order Form, or where none is identified, the authority of the Customer's place of establishment in the EEA.
9. The Customer's obligations and rights
The Customer determines the purposes and means of the processing, and instructs Resort Buggy through this DPA, the service agreement, and the configuration choices it makes in its console. The Customer warrants that it has a lawful basis for the personal data it enters or has collected on its behalf, and that it has given its guests and staff the information required by Articles 13 and 14 GDPR.
The Customer is responsible for the accuracy of the data it provides, for the access it grants its own staff, and for recording a checkout date for each guest — without one, the retention schedule in Section 2 cannot run, and the count of affected guests is shown in the Customer's console.
The Customer may audit our compliance as set out in Section 6, object to a new sub-processor as set out in Section 7, and require deletion or return of its data at any time.
10. Precedence, term and governing law
This DPA forms part of the service agreement. Where it conflicts with any other part of that agreement on the processing of personal data, this DPA prevails. It takes effect when the service agreement does and ends when the last processing of the Customer's personal data ends.
This DPA is governed by the law of Romania and the courts of Alba County, Romania have exclusive jurisdiction, unless the service agreement provides otherwise. Nothing in this Section limits a data subject's rights under the GDPR or the jurisdiction of a supervisory authority.
Annex: Technical and Organizational Measures (TOMs)
- Encryption: TLS for all traffic in transit; the production database is encrypted at rest (LUKS, AES-256); database access restricted to the application over a private network
- Access control: token-based authentication (JWT) with strict role separation between guests, drivers, and admins; guest access codes end automatically at checkout, after a set number of hours counted from their first use, or after one ride, and can be revoked instantly
- Tenant isolation: every query is scoped to the Customer's property; no data is visible across properties
- Data minimization: we collect only the data needed to dispatch a ride, to reach a guest before arrival where the Customer asks us to, to call a guest or a staff member where the Customer switches phone numbers on, and to record the condition of a vehicle where the Customer switches vehicle checks on; no payment data, no cross-site tracking
- Backup & recovery: automated daily database backups, client-side encrypted before off-box upload, with 30-day retention
- Incident response: security reports acknowledged within 24 hours; confirmed breaches notified within 72 hours
Full details on our Security page.
Execution
This DPA takes effect for the Customer when the service agreement is signed. Where a Customer requires a separately executed copy, both parties complete the block below.
| The Customer | NORTHDAN SOFT SRL | |
|---|---|---|
| Name | ||
| Title | ||
| Signature | ||
| Date |
Contact
Questions about this DPA, or need it countersigned? [email protected]