Data Processing Agreement

Host Compliance API

Version 1.0 | May 2026

This Data Processing Agreement governs the processing of personal data by Trippz B.V. on behalf of the Platform in connection with the Host Compliance API. It forms part of the commercial relationship governed by the Framework Agreement between the parties.

Trippz B.V. — Daalsesingel 51 O4.10, 3511 SW Utrecht, The Netherlands
Chamber of Commerce: 78453925 — support@trippz.com

Parties

Processor

Entity: Trippz B.V.

Address: Daalsesingel 51 O4.10, 3511 SW Utrecht, The Netherlands

Chamber of Commerce: 78453925

Representative: Ingmar Lambregts, CEO

Contact: support@trippz.com

Controller

You – as user of Trippz for Hosts – are the Controller.

Each referred to individually as a Party and together as the Parties.

Background

The Parties have entered into a Framework Agreement under which Trippz provides the Platform with access to the Host Compliance API. In connection with this API, Trippz processes personal data on behalf of the Platform.

This DPA sets out the terms under which Trippz processes such personal data, in accordance with Article 28 of Regulation (EU) 2016/679 (GDPR).

In the event of any conflict between this DPA and the Framework Agreement, the provisions of this DPA shall prevail with respect to the processing of personal data.

1. Definitions

In this DPA, the following terms have the meanings set out below:

  • Controller: the Platform, which determines the purposes and means of processing personal data of hosts and guests on its platform.
  • Processor: Trippz B.V., which processes personal data on behalf of the Controller.
  • Data Subject: a natural person whose personal data is processed under this DPA, including guests staying at accommodations connected to the Platform, and hosts registered on the Platform.
  • Personal Data: any information relating to an identified or identifiable natural person, as defined in Article 4(1) GDPR.
  • Special Category Data: biometric data for the purpose of uniquely identifying a natural person, and other categories listed in Article 9(1) GDPR.
  • Processing: any operation performed on personal data, as defined in Article 4(2) GDPR.
  • Sub-processor: any third party engaged by Trippz to process personal data under this DPA.
  • Host Compliance API: Trippz's API product for PMS systems, providing digital guest registration, direct connections to government authorities, real-time ID verification, tourist tax collection, and automated remittance to hosts.
  • Framework Agreement: the commercial agreement between the Parties governing access to Trippz services.

2. Subject Matter and Duration

2.1 Subject matter

Trippz processes personal data on behalf of the Platform for the purpose of providing the Host Compliance API, including:

  • Digital guest registration and transmission of guest data to local government authorities
  • Real-time ID verification of guests (Italy only, where activated, pursuant to Article 109 TULPS)
  • Tourist tax calculation and collection from guests
  • Automated remittance of collected tourist tax to hosts

2.2 Duration

This DPA enters into force on the date of signature and remains in effect for the duration of the Framework Agreement. Upon termination of the Framework Agreement, the obligations of this DPA continue to apply until all personal data has been deleted or returned in accordance with Clause 6.

3. Nature, Purpose and Legal Basis of Processing

3.1 Nature of processing

Trippz collects, stores, transmits, and deletes personal data of guests and hosts as necessary to deliver the Host Compliance API services. Processing includes transmission of guest data to government registration systems and, where applicable, biometric verification via Veriff.

3.2 Purpose of processing

Personal data is processed solely for the purpose of enabling the Platform's hosts to comply with their legal obligations under applicable local laws, including guest registration and tourist tax obligations. Trippz does not process personal data for any other purpose.

3.3 Legal basis

Guest registration data is processed on the basis of legal obligation (Article 6.1.c GDPR), as hosts are legally required to register guests with the relevant authorities in each jurisdiction.

Biometric data processed by Veriff for ID verification is processed on the basis of substantial public interest under Member State law (Article 9.2.g GDPR). The applicable Member State law is Article 109 of the Italian Testo Unico delle Leggi di Pubblica Sicurezza (TULPS), which requires accommodation providers to verify the identity of guests at the moment of entry (hic et nunc). The Italian Council of State confirmed on 21 November 2025 that real-time digital verification via biometric technology satisfies this requirement. This applies only in Italy and only where ID verification is activated for a property.

3.4 Categories of data subjects

  • Guests: individuals staying at accommodations connected to the Platform
  • Hosts: accommodation providers registered on the Platform (limited to account and property data)

3.5 Categories of personal data

Guest data (fields collected depend on jurisdiction and local authority requirements):

  • Date of arrival and number of nights
  • First name and last name
  • Date of birth and place of birth
  • Gender
  • Nationality and citizenship
  • Identity document type and number
  • Place of issue of identity document
  • Email address and phone number
  • Signature

Special category data (Italy only, where ID verification is activated):

  • Biometric data: facial image captured during ID verification, processed by Veriff solely for the purpose of matching the guest to their identity document. Biometric data is not retained by Trippz after verification is complete.

Host data:

  • Encrypted property identifier (host ID)
  • Property address

4. Obligations of Processor

4.1 Instructions

Trippz processes personal data only on documented instructions from the Controller, as set out in this DPA and the Framework Agreement. If Trippz believes an instruction infringes GDPR or applicable data protection law, it will notify the Controller without undue delay.

4.2 Confidentiality

Trippz ensures that all personnel authorised to process personal data under this DPA are bound by confidentiality obligations and are informed of the relevant data protection requirements.

4.3 Security

Trippz implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. These measures are set out in Annex III of this DPA.

4.4 Sub-processors

Trippz has the Controller's general authorisation to engage the sub-processors listed in Annex II of this DPA. Trippz will notify the Controller of any intended addition or replacement of a sub-processor at least 30 days in advance, giving the Controller the opportunity to object. Trippz ensures that all sub-processors are bound by data protection obligations equivalent to those set out in this DPA.

4.5 Assistance to the Controller

Trippz assists the Controller in fulfilling its obligations under Articles 32 to 36 GDPR, including:

  • Responding to requests from data subjects to exercise their rights
  • Notifying the Controller of any personal data breach within 72 hours of becoming aware of it
  • Supporting data protection impact assessments where requested

4.6 Data subject rights

If Trippz receives a request from a data subject exercising their GDPR rights, Trippz will notify the Controller within 5 business days and await instructions before responding. Trippz will not respond to data subject requests directly unless authorised to do so by the Controller.

4.7 Records of processing

Trippz maintains a record of all categories of processing activities carried out on behalf of the Controller, in accordance with Article 30(2) GDPR.

4.8 Audit rights

Trippz makes available to the Controller all information necessary to demonstrate compliance with this DPA. Upon reasonable written notice, the Controller may conduct or commission an audit of Trippz's processing activities. Trippz may satisfy this obligation by providing its current SOC2 Type 2 audit report as evidence of compliance with technical and organisational security measures.

5. Obligations of the Controller

The Controller is responsible for:

  • Ensuring that personal data submitted to Trippz via the Host Compliance API is accurate and collected in compliance with applicable law
  • Ensuring that the legal basis for processing personal data of guests and hosts is established prior to transmission to Trippz
  • Informing data subjects that their personal data will be processed by Trippz on the Controller's behalf, including transmission to government authorities as required by local law
  • Ensuring that hosts on the Platform are informed of their obligations under applicable local law. In Italy, Trippz stores the digitally signed Alloggiati Web transmission receipt on behalf of the host and delivers it by email after each successful transmission. Trippz retains this receipt for 5 years.
  • Notifying Trippz of any changes to the Platform's processing activities that may affect the nature of personal data submitted via the API

6. Data Retention and Deletion

6.1 Retention periods

Trippz retains personal data for the periods set out in Annex I of this DPA, in line with the legally required retention periods per country. After the applicable retention period, personal data is permanently deleted from Trippz systems.

6.2 Deletion on termination

Upon termination of the Framework Agreement, Trippz will, at the Controller's choice, either return all personal data to the Controller or permanently delete it within 30 days of the termination date. Trippz will confirm deletion in writing. Trippz may retain personal data beyond this period only where required to do so by applicable law, in which case Trippz will notify the Controller of the legal obligation and the categories of data retained.

6.3 Special category data

Biometric data processed by Veriff for ID verification is not retained by Trippz after verification is complete. Veriff's own data retention practices are governed by Veriff's data processing agreement with Trippz.

7. International Data Transfers

All personal data processed under this DPA is stored on EU-based servers operated by Exoscale in Frankfurt, Germany. Trippz does not transfer personal data outside the European Economic Area.

Government registration systems to which guest data is transmitted are operated by EU Member State authorities and are located within the EU.

Veriff is headquartered in Estonia (EU) and processes biometric data within the EU. Where Veriff processes data outside the EEA, appropriate safeguards are in place under Veriff's own data processing agreements.

8. Personal Data Breach

In the event of a personal data breach affecting data processed under this DPA, Trippz will:

  • Notify the Controller without undue delay and in any event within 72 hours of becoming aware of the breach
  • Provide the Controller with sufficient information to meet its own notification obligations under Articles 33 and 34 GDPR
  • Cooperate fully with the Controller to investigate, contain, and remediate the breach

The notification will include at minimum: a description of the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences of the breach, and the measures taken or proposed to address it.

9. Liability

Each Party is liable for damages caused by processing that infringes this DPA or GDPR to the extent attributable to that Party's actions or omissions. Trippz's liability is limited as set out in the Framework Agreement and the General Terms and Conditions of Trippz.

Trippz is not liable for any fines, penalties, or assessments imposed on the Controller by supervisory authorities or government bodies as a result of the Controller's failure to fulfil its obligations as data controller.

10. Governing Law and Jurisdiction

This DPA is governed by Dutch law. Any disputes arising from or in connection with this DPA shall be submitted exclusively to the District Court of Utrecht, the Netherlands.

Annex I — Data Retention Periods

Personal data processed under this DPA is retained for the following periods. After the applicable period, data is permanently deleted from Trippz systems.

CountryRetention periodLegal basisNotes
Italy30 days from check-out (personal data fields)Article 109 TULPS; DM 16 September 2021, Article 4-bisPersonal data fields deleted after 30 days. Alloggiati Web transmission receipt stored by Trippz on behalf of the host and delivered by email after each transmission. Receipt retained by Trippz for 5 years. Biometric data deleted immediately after verification.
Spain3 years from check-outOrder INT/1922/2003, Ministry of Interior—
France6 months from check-out (registration); 6 years (tax records)Code de sécurité intérieure; French tax lawLawyer review recommended
Germany1 year from departureBundesmeldegesetz (BMG) ss.29/30Tax record retention may require longer period. Lawyer to confirm.
Netherlands7 years from check-outAWR Article 52—
All other countries3 years from check-outGDPR Article 5(1)(e)Unless local law requires otherwise

Annex II — Approved Sub-processors

The following sub-processors are approved for use in connection with the Host Compliance API. Trippz will provide 30 days notice of any intended changes to this list.

Sub-processorLocationData processedPurpose
ExoscaleFrankfurt, Germany (EU)All personal dataCloud hosting and data storage
MailtrapEUGuest email addressTransactional email delivery (e.g. registration link to guest)
VeriffEstonia (EU)Biometric data, identity document dataReal-time ID verification (Italy only, where activated). Special category data under Article 9 GDPR.
Alloggiati Web (Italian State Police)Italy (EU)Guest registration dataGovernment guest registration system (Italy)
Istat / Ricestat / ROSS1000 / TurismaticaItaly (EU)Guest registration dataStatistical reporting (Italy)
SES HospedajesSpain (EU)Guest registration dataGovernment guest registration system (Spain)
SEF PortugalPortugal (EU)Guest registration dataGovernment guest registration system (Portugal)
eTurizem / AJPESSlovenia (EU)Guest registration dataGovernment guest registration system (Slovenia)
FeratelEUGuest registration dataTourist tax and registration (selected municipalities)
AVSEUGuest registration dataTourist tax and registration (selected municipalities)

Annex III — Technical and Organisational Security Measures

Trippz implements the following technical and organisational measures to ensure an appropriate level of security for personal data processed under this DPA.

Certification

  • SOC1 Type 2: covers financial information handling and internal controls
  • SOC2 Type 2: covers security, availability, and privacy of data and infrastructure
  • GDPR compliant: all processing activities conducted in accordance with GDPR

Infrastructure

  • All data stored on EU-based servers operated by Exoscale in Frankfurt, Germany
  • Nightly backups with verified recovery procedures
  • No data stored or processed outside the European Economic Area

Encryption

Data is encrypted automatically, in real time, prior to writing to storage and decrypted when read from storage. As a result, hackers and malicious users are unable to read sensitive data directly from database files. MySQL Enterprise TDE uses industry standard AES algorithms.

Access control

  • Access to personal data restricted to Trippz personnel on a need-to-know basis
  • Access rights granted by role and reviewed periodically
  • All access logged and monitored
  • Remote access requires multi-factor authentication

Incident response

  • Personal data breaches notified to the Controller within 72 hours of detection
  • Internal incident response procedure maintained

Data minimisation and deletion

  • Only personal data fields required by the relevant authority are collected
  • Identity document copies and scans are not collected or stored
  • Biometric data processed by Veriff is deleted immediately after verification is complete
  • Personal data is deleted after the applicable retention period per Annex I

Vendor security

  • All sub-processors are bound by data processing agreements with equivalent security obligations
  • Veriff holds ISO 27001 certification and processes biometric data in compliance with Article 9 GDPR safeguards