Skip to content

Data Processing Agreement

DRAFT — this document requires review by qualified legal counsel before it is legally binding.

What this page is

This is a template of EZ2Stay's standard data processing terms, published so a hostel can review our approach to data protection before signing up. It describes how EZ2Stay processes personal data on a hostel's behalf when guests use the platform.

The document that actually governs a specific hostel's account is the signable Data Processing Agreement executed as part of that hostel's contract with EZ2Stay SRL — not this page. Where the two differ, the signed DPA controls.

Controller and processor

For guest data collected through the platform, the hostel operating the account is the data controller: it decides why guest data is collected and sets its own retention and access rules within the limits EZ2Stay sets by design. EZ2Stay SRL is the processor, acting only on the hostel's documented instructions.

EZ2Stay SRL's registered address is available on request until it is published on this site; see also the Imprint page for the current legal-notice details.

What gets processed

Processing under this DPA covers the guest journey end to end:

  • Check-in details submitted by the guest
  • ID document images used for identity verification
  • Biometric selfies used to match the guest to their ID
  • Stay data (dates, bed/room assignment, access codes)
  • Payment status and metadata — EZ2Stay does not store full card numbers; card data is handled by Stripe

Security measures

Secrets and PII are encrypted with AES-256-GCM. Access to sensitive guest data is logged, so who viewed what and when can be reconstructed.

Subprocessors that handle personal data on EZ2Stay's behalf are listed at /legal/subprocessors, which is kept current as the list changes.

Retention

Two retention rules are fixed by the platform, not left to hostel configuration:

  • Biometric selfies: deleted ≤30 days after checkout — not configurable
  • ID documents: kept 90 days by default; the hostel, as controller, can configure a different retention period in the platform's settings

Data subject requests

EZ2Stay supports the hostel in responding to guest requests to access, correct, or delete their data. Deletion honors legal retention exceptions where they apply — for example, guest registration records kept under Romania's HG 237/2001 tourism rules, and invoice data kept under Romanian fiscal law.

A guest data-subject request should go to the hostel first, as controller; EZ2Stay carries out the deletion or export once the hostel instructs it to.

Breach notification

If EZ2Stay becomes aware of a personal data breach affecting a hostel's guest data, EZ2Stay will notify the hostel without undue delay, consistent with GDPR.

This is a template, not legal advice

This page describes EZ2Stay's general approach and is not legal advice. The signable Data Processing Agreement executed with each customer is the governing agreement for that customer's account.

Contact

Questions about this DPA, or to request the signable version for your account: contact@ez2stay.com.