Hotels In Alibaug

Hotels In Alibaug

DPA

Data Processing Agreement

Processing Terms for Hotel Data

Effective date: July 16, 2026

1. Roles

For guest and staff data uploaded by a hotel, the hotel acts as the primary data owner and decision maker for operational processing, and GPNext Technologies acts as the service provider processing such data on the hotel’s behalf for the limited purposes of operating and supporting the software.

2. Subject matter and duration

Processing covers hosting, storing, transmitting, organizing, retrieving, securing, backing up, displaying, and supporting hotel data for the duration of the hotel’s subscription and any reasonable retention, backup, legal, or support period that follows.

3. Categories of data

Processed data may include hotel account details, staff records, guest identity and contact information, stay history, room and travel details, ID metadata, ID proof images, and audit logs relating to platform access and reporting activity.

4. Provider obligations

The provider will process hotel data only to deliver the platform, maintain security, support integrations, troubleshoot issues, provide customer support, meet contractual obligations, and comply with applicable legal requirements. The provider will use reasonable safeguards to protect data and restrict access to authorized persons who need it for service delivery.

5. Hotel obligations

The hotel is responsible for deciding what data to upload, ensuring the legality of collection and disclosure, providing required notices, obtaining any required consents, handling user-facing privacy requests, and confirming that its instructions to the provider are lawful.

6. Sub-processors and service providers

The provider may use infrastructure, storage, delivery, analytics, support, or integration vendors where reasonably necessary to operate the service. Such vendors may process hotel data only within the scope needed to provide their portion of the service.

7. Security and incident handling

The provider will maintain reasonable administrative, technical, and organizational safeguards. If the provider becomes aware of a confirmed security incident materially affecting hotel data under its control, it will take reasonable steps to contain, investigate, and communicate the issue to the affected hotel as appropriate.

8. Data return and deletion

Upon subscription end, the provider may retain data for limited periods needed for legal compliance, fraud prevention, backups, logs, support, or dispute handling. After such period, the provider may delete or de-identify data unless continued retention is required by law or written agreement.

9. Audit and cooperation

The provider may offer reasonable information about its processing practices on request, subject to confidentiality, security, and practicality limits. The hotel may not require access to systems, source code, or other customers’ data as part of such requests.

10. Contact

For data processing requests or contract questions, contact GPNext Technologies at checkin.hotelsinalibaug@gmail.com.