As of 12 August 2026
Data Processing Agreement (Annex 1)
Preamble
This agreement is Annex 1 to the terms and conditions and is concluded together with the service agreement. It governs the processing of personal data carried out by Norman Voellings, Urbanização Quinta da Torre 20, 8365-184 Armação de Pêra, Portugal (the “Processor”), on behalf of the Client (the “Controller”).
References to the GDPR are to be read as references to the UK GDPR and the Data Protection Act 2018 where those apply to the Controller. The Controller remains the controller and assesses the lawfulness of the processing.
1. Subject matter and duration
The subject matter is the processing of personal data in the course of the services described in the service agreement: operating the Client's website, receiving and forwarding guest enquiries submitted through the enquiry form, and operating the editorial system.
The duration corresponds to the term of the service agreement. This agreement ends with it, but not before the obligations under clause 8 have been fulfilled.
2. Nature and purpose of processing, categories of data and data subjects
Nature of processing: collection, storage, organisation, retrieval, comparison, transmission to the portals engaged by the Controller, and deletion — solely for the purpose of providing the contractually agreed services.
Categories of data subjects: people who make contact or enquire through a form on the Controller's website, and staff of the Controller with access to the editorial system.
Categories of data for enquirers: the details given in the form — typically name, email address, optionally a telephone number, the dates wanted, the number of travellers and the message in the free-text field.
Categories of data for the Controller's staff: user name, name, time of last access and the edits recorded in the change history. Passwords are stored only as a cryptographic derivation.
Guest booking and payment data are not part of this processing. The Processor operates neither a booking engine nor inventory control nor a property management system (clause 3 of the General Terms). Bookings run through the Controller's own booking engine; for the data processed there, that engine's provider is the Controller's processor, not the provider of this website. The website merely hands the guest over.
The Controller does not enter special categories of data — in particular health, dietary or assistance requirements — into the form fields. Where such processing is intended, it must be agreed separately in advance.
3. Instructions
The Processor processes the data only on the Controller's documented instructions. The service agreement including this annex is the initial instruction; further instructions are given in text form to the address stated in the legal notice.
If the Processor considers an instruction to infringe data protection law, it informs the Controller and may suspend execution until the Controller confirms the instruction.
Where the Processor is required by law to process data, it informs the Controller before processing unless that law prohibits such information.
4. Confidentiality
The Processor ensures that persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. The obligation survives the end of their engagement.
Access is granted only to persons who need it to perform the agreement.
5. Technical and organisational measures
The Processor maintains appropriate technical and organisational measures, in particular:
encrypted transport of all content over TLS; storage of passwords only as a salted cryptographic derivation; lock-out of an account after repeated failed attempts; named individual logins instead of shared credentials.
separation of data by tenant, enforced server-side and not only in the interface; separation of booking operations and the editorial system into separate databases; database access server-side only, with no key reaching the browser.
a change history attributed to the acting person; logging of security-relevant errors; security headers and suppression of version disclosure by the web server.
daily backups retained for 30 days, with restoration tested at least annually.
The Processor may develop these measures further provided the level of protection is not reduced. Material changes are documented and disclosed to the Controller on request.
6. Sub-processors
The Controller authorises the sub-processors listed below. The current version of this list is available at https://direktstay.de/uk/legal/avv.
Hostinger International Ltd., Lithuania — server operation and the booking engine database, including portal bookings.
Supabase Inc., United States — editorial system database, orders, enquiries and error log.
Resend, Inc., United States — forwarding guest enquiries from the enquiry form to the Controller.
The Processor gives at least 30 days' prior notice in text form of any intended change to this list. The Controller may object on reasoned data protection grounds within 14 days of receipt. Where a reasoned objection is made and no agreed solution is found, the Controller may terminate the affected part of the services for cause.
The Processor imposes on each sub-processor obligations equivalent to those agreed here and remains liable for the sub-processor's conduct as for its own.
7. Personal data breaches
The Processor notifies the Controller of any personal data breach without undue delay and in any event within 24 hours of becoming aware of it, in text form, to the address nominated by the Controller.
The notification contains the information required by Article 33(3) GDPR so far as it is available to the Processor: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. Where not all information is available, the Processor notifies what it knows within the deadline and supplies the remainder without undue delay.
The Controller nominates an address for this purpose and keeps it current. Notification of the supervisory authority and communication to data subjects are the Controller's responsibility; the Processor supports the Controller in both.
8. Deletion and return
On termination of the service agreement the Processor returns or deletes the processed data at the Controller's choice. Exports are provided in a common machine-readable format.
If the Controller does not make a choice within 30 days of the end of the contract, the Processor deletes the data. Existing backup copies are deleted when their regular retention period expires.
Deletion does not take place where a statutory retention obligation applies. In that case the data is restricted and processed solely for the purpose of retention.
9. Assistance to the Controller
The Processor assists the Controller by appropriate technical and organisational measures in responding to requests from data subjects. A request for access is answered across all data sets held by the Processor, brought together in one response.
Where a data subject approaches the Processor directly, the Processor forwards the request to the Controller without undue delay and does not respond itself.
The Processor also assists the Controller in ensuring security of processing, breach notification and data protection impact assessments, and provides the information required for its part of the processing. The competent supervisory authority for the Controller is the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow SK9 5AF, ico.org.uk.
10. Records and audits
The Processor makes available all information necessary to demonstrate compliance with its obligations and allows for and contributes to audits, including inspections.
Audits are carried out with reasonable notice, during normal business hours and without avoidable disruption to operations. The Processor may satisfy an audit request with meaningful evidence where that serves the purpose of the audit.
11. Processing outside the United Kingdom and the European Union
The Processor uses data centres in the European Union for server operation.
Where a sub-processor is established outside the United Kingdom or the European Economic Area, or can access data from there, transfers take place only on the basis of adequacy regulations or the International Data Transfer Agreement or the UK Addendum to the European Commission's standard contractual clauses, together with any supplementary measures required. On the list in clause 6 this concerns Supabase Inc. (standard contractual clauses) and Resend, Inc. (standard contractual clauses).
12. No processing for own purposes
The Processor does not process the Controller's data for its own purposes. This excludes in particular the training or improvement of machine learning models, cross-client analysis and product metrics based on identifiable data.
Live data of the Controller is not used in test or development environments.
13. Final provisions
In all other respects the terms and conditions apply. In the event of conflict between those terms and this annex, this annex prevails on questions of data protection.
Amendments to this annex must be made in text form.
If any provision is held invalid, the remaining provisions stay in force.