Draft — pending legal review

Data Processing Agreement

Last updated: 2026-06-16

Roles

This agreement applies where Stay Now processes personal data on the host's behalf. The host is the controller; Stay Now is the processor. It supplements our Terms of Service.

Subject matter and duration

We process guest and operational personal data to provide the service, for as long as the host's account is active and for any statutory retention that follows.

Processing instructions

We process personal data only on the host's documented instructions, including those given through the product, unless required otherwise by law.

Confidentiality

People authorized to process the data are bound by confidentiality and access it on a least-privilege basis.

Security measures

We apply technical and organizational measures appropriate to the risk, including per-organization encryption of guest data in a dedicated vault, isolation between organizations, audit logging, and enforced retention and deletion.

Sub-processors

The host authorizes the sub-processors listed on our Sub-processors page. We announce additions at least 30 days in advance so the host can object.

Data subject requests

We assist the host in responding to data subject requests, including through the product's data-rights and retention features.

Breach notification

We notify the host without undue delay after becoming aware of a personal data breach affecting their data, with the information needed to meet their own notification duties.

International transfers

Where personal data is transferred outside the EU/EEA, we rely on an appropriate transfer mechanism such as Standard Contractual Clauses, as indicated on the Sub-processors page.

Return and deletion

On closure, owner-controlled records are returned and organization-scoped data is deleted, subject to statutory retention of guest registrations.

Contact

Data protection contact: dpo@stay-now.eu.

Stay Now