As of 12 August 2026
Data Processing Agreement (Annex 1)
Preamble
This agreement is Annex 1 to the terms of service and is concluded together with the service agreement. It governs the processing of personal information carried out by Norman Voellings, Urbanização Quinta da Torre 20, 8365-184 Armação de Pêra, Portugal (the “Processor”), on behalf of the Client (the “Controller”).
The Processor acts as a service provider on the Controller's behalf. It does not sell or share personal information, does not retain, use or disclose it for any purpose other than performing the services, and does not combine it with personal information from other sources except as permitted for the Controller's purposes.
Where the Controller's guests or enquirers are located in the European Union or the United Kingdom, the GDPR applies in addition and the provisions of this annex are to be read as GDPR processor terms.
1. Subject matter and duration
The subject matter is the processing of personal data in the course of the services described in the service agreement: operating the Client's website, receiving and forwarding guest enquiries submitted through the enquiry form, and operating the editorial system.
The duration corresponds to the term of the service agreement. This agreement ends with it, but not before the obligations under clause 8 have been fulfilled.
2. Nature and purpose of processing, categories of data and data subjects
Nature of processing: collection, storage, organisation, retrieval, comparison, transmission to the portals engaged by the Controller, and deletion — solely for the purpose of providing the contractually agreed services.
Categories of data subjects: people who make contact or enquire through a form on the Controller's website, and staff of the Controller with access to the editorial system.
Categories of data for enquirers: the details given in the form — typically name, email address, optionally a telephone number, the dates wanted, the number of travellers and the message in the free-text field.
Categories of data for the Controller's staff: user name, name, time of last access and the edits recorded in the change history. Passwords are stored only as a cryptographic derivation.
Guest booking and payment data are not part of this processing. The Processor operates neither a booking engine nor inventory control nor a property management system (clause 3 of the General Terms). Bookings run through the Controller's own booking engine; for the data processed there, that engine's provider is the Controller's processor, not the provider of this website. The website merely hands the guest over.
The Controller does not enter special categories of data — in particular health, dietary or assistance requirements — into the form fields. Where such processing is intended, it must be agreed separately in advance.
3. Instructions
The Processor processes the data only on the Controller's documented instructions. The service agreement including this annex is the initial instruction; further instructions are given in text form to the address stated in the legal notice.
If the Processor considers an instruction to infringe data protection law, it informs the Controller and may suspend execution until the Controller confirms the instruction.
Where the Processor is required by law to process data, it informs the Controller before processing unless that law prohibits such information.
4. Confidentiality
The Processor ensures that persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. The obligation survives the end of their engagement.
Access is granted only to persons who need it to perform the agreement.
5. Technical and organisational measures
The Processor maintains appropriate technical and organisational measures, in particular:
encrypted transport of all content over TLS; storage of passwords only as a salted cryptographic derivation; lock-out of an account after repeated failed attempts; named individual logins instead of shared credentials.
separation of data by tenant, enforced server-side and not only in the interface; separation of booking operations and the editorial system into separate databases; database access server-side only, with no key reaching the browser.
a change history attributed to the acting person; logging of security-relevant errors; security headers and suppression of version disclosure by the web server.
daily backups retained for 30 days, with restoration tested at least annually.
The Processor may develop these measures further provided the level of protection is not reduced. Material changes are documented and disclosed to the Controller on request.
6. Sub-processors
The Controller authorises the sub-processors listed below. The current version of this list is available at https://direktstay.de/us/legal/avv.
Hostinger International Ltd., Lithuania — server operation and the booking engine database, including portal bookings.
Supabase Inc., United States — editorial system database, orders, enquiries and error log.
Resend, Inc., United States — forwarding guest enquiries from the enquiry form to the Controller.
The Processor gives at least 30 days' prior notice in text form of any intended change to this list. The Controller may object on reasoned data protection grounds within 14 days of receipt. Where a reasoned objection is made and no agreed solution is found, the Controller may terminate the affected part of the services for cause.
The Processor imposes on each sub-processor obligations equivalent to those agreed here and remains liable for the sub-processor's conduct as for its own.
7. Personal data breaches
The Processor notifies the Controller of any personal data breach without undue delay and in any event within 24 hours of becoming aware of it, in text form, to the address nominated by the Controller.
The notification contains the information required by Article 33(3) GDPR so far as it is available to the Processor: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. Where not all information is available, the Processor notifies what it knows within the deadline and supplies the remainder without undue delay.
The Controller nominates an address for this purpose and keeps it current. Notification of the supervisory authority and communication to data subjects are the Controller's responsibility; the Processor supports the Controller in both.
8. Deletion and return
On termination of the service agreement the Processor returns or deletes the processed data at the Controller's choice. Exports are provided in a common machine-readable format.
If the Controller does not make a choice within 30 days of the end of the contract, the Processor deletes the data. Existing backup copies are deleted when their regular retention period expires.
Deletion does not take place where a statutory retention obligation applies. In that case the data is restricted and processed solely for the purpose of retention.
9. Assistance to the Controller
The Processor assists the Controller by appropriate technical and organisational measures in responding to requests from data subjects. A request for access is answered across all data sets held by the Processor, brought together in one response.
Where a data subject approaches the Processor directly, the Processor forwards the request to the Controller without undue delay and does not respond itself.
The Processor also assists the Controller in ensuring security of processing, breach notification and data protection impact assessments, and provides the information required for its part of the processing. Where state privacy law grants consumers rights of access, correction or deletion, the Processor assists the Controller in meeting them within the statutory deadlines.
10. Records and audits
The Processor makes available all information necessary to demonstrate compliance with its obligations and allows for and contributes to audits, including inspections.
Audits are carried out with reasonable notice, during normal business hours and without avoidable disruption to operations. The Processor may satisfy an audit request with meaningful evidence where that serves the purpose of the audit.
11. Location of processing
The Processor uses data centres in the European Union for server operation. The Controller acknowledges that personal information is therefore processed outside the United States.
Where personal data subject to the GDPR is transferred to a sub-processor outside the European Economic Area, the transfer takes place on the basis of an adequacy decision or the European Commission's standard contractual clauses together with any supplementary measures required. On the list in clause 6 this concerns Supabase Inc. (standard contractual clauses) and Resend, Inc. (standard contractual clauses).
12. No processing for own purposes
The Processor does not process the Controller's data for its own purposes. This excludes in particular the training or improvement of machine learning models, cross-client analysis and product metrics based on identifiable data.
Live data of the Controller is not used in test or development environments.
13. Final provisions
In all other respects the terms of service apply. In the event of conflict between those terms and this annex, this annex prevails on questions of data protection.
Amendments to this annex must be made in text form.
If any provision is held unenforceable, the remaining provisions stay in force.