Data Processing Agreement (DPA)
Last updated: August 10, 2026
This Data Processing Agreement (hereinafter, "DPA") forms part of the Zobooq Terms & Conditions and governs the processing of personal data that VACATIOLABS, S.L.U. carries out on behalf of each customer when providing the Service, pursuant to Article 28 of Regulation (EU) 2016/679 (GDPR).
By accepting the Terms & Conditions and using the Service, the customer (data controller) and VACATIOLABS, S.L.U. (data processor) enter into this DPA. It does not need to be signed separately; if your organization needs a signed copy, write to us at legal@zobooq.com.
1. Parties and roles
With respect to the data of third parties (mainly guests, but also the customer's contacts or staff) entered into the Service, the parties and their roles are:
- Data controller: the customer who contracts the Service and decides what data they enter and for what purpose.
- Data processor: VACATIOLABS, S.L.U. (NIF B93814903), which processes that data solely to provide the Service following the controller's instructions.
2. Subject matter and scope
The subject matter of the processing is the provision of the Service described in the Terms: booking management, booking engine and accommodation website, connection with channels/OTAs, communications with guests and traveler registration. The processor will process the personal data contained in the bookings, guest profiles, communications and documents that the controller uploads or manages on the platform. The nature, purpose, types of data and categories of data subjects are detailed in Annex I.
3. Duration
The processing will last as long as the contractual relationship is in force (while the customer's account is active). Upon its termination, the provisions of the return and deletion clause will apply, without prejudice to the legal retention periods.
4. Obligations of the processor
As data processor, VACATIOLABS, S.L.U. undertakes to:
- Process the personal data only following the documented instructions of the controller, including those relating to international transfers, unless required by law.
- Ensure that the persons authorized to process the data have committed to respecting confidentiality.
- Apply the appropriate technical and organizational measures described in Annex II (Art. 32 GDPR).
- Not engage another processor (sub-processor) without authorization; the general authorization regulated in the sub-processors clause and Annex III applies.
- Assist the controller, as far as possible, so that it can fulfill its obligation to respond to requests to exercise data subjects' rights.
- Make available to the controller the tools to access, export, rectify and delete the data directly from the application.
- Notify the controller, without undue delay, of any personal data breaches of which it becomes aware.
- Make available to the controller the information necessary to demonstrate compliance and allow reasonable audits or inspections.
- At the controller's choice, delete or return the personal data once the provision of the Service has ended, unless it must retain it due to a legal obligation.
- Keep a record of the processing activities carried out on behalf of the controller.
5. Obligations of the controller
The controller warrants that it has a legal basis to process the data it enters into the Service (for example, that of its guests), that it has informed the data subjects where appropriate —including the information on the disclosure of data to the authorities in the context of traveler registration— and that its instructions comply with the GDPR. The controller is the one who decides the purposes and means of the processing.
6. Sub-processors
The controller generally authorizes the processor to engage the sub-processors listed in Annex III to provide the Service. The processor imposes on each sub-processor, by contract, the same data protection obligations. Before incorporating or replacing a sub-processor, the processor will give reasonable advance notice (for example, by updating this page); the controller may object on reasonable grounds and, if the objection prevents the provision of the Service, terminate the contract.
7. International transfers
When a sub-processor is located outside the European Economic Area, the transfer is covered by an adequacy decision or by the European Commission's Standard Contractual Clauses, together with any additional measures that may apply. Annex III indicates the location of each sub-processor.
8. Security breaches
In the event of a personal data breach, the processor will notify the controller without undue delay after becoming aware of it, providing the available information so that the controller can, where applicable, notify the supervisory authority (AEPD) and the data subjects within the legal deadlines.
9. Liability
The liability of each party is governed by Article 82 of the GDPR and by the limitation of liability clause of the Terms & Conditions. Each party is liable for the breach of the obligations that the GDPR attributes to it in its respective role.
Annex I — Details of the processing
Categories of data subjects
- The controller's guests (natural persons who make or appear in a booking).
- The controller's contacts, suppliers or collaborators who appear in the documentation.
- Users authorized by the controller to access its account.
Categories of personal data
- Identifying data: first name and surname.
- Contact data: address, email and telephone.
- Identity document data collected for traveler registration (document type and number, date of birth, nationality and other data required by traveler registration regulations).
- Booking and stay data: dates, accommodation, number of guests and communications.
- Financial data: booking amounts and, where applicable, payment details.
Purpose and nature of the processing
Storage, organization, consultation and processing of booking, guest and communication data for the purpose of providing the functions of the Service contracted by the controller, including the communication of traveler data to the authorities when the controller uses that function.
The Service is not designed to process special categories of data (Art. 9 GDPR). The controller undertakes not to enter this type of data unless strictly necessary and in accordance with the law.
Annex II — Security measures
The processor applies, as a minimum, the following technical and organizational measures (Art. 32 GDPR), which may evolve in order to maintain an adequate level of security:
- Encryption in transit of all communications (HTTPS/TLS).
- Encryption at rest of sensitive secrets (integration credentials) using managed keys.
- Role-based access control and the principle of least privilege.
- Logical isolation between the data of different customers.
- Storage of passwords using robust hash functions (never in plain text).
- Audit logging of operations.
- Periodic backups of the database.
- Data minimization: only the data necessary for each function is sent to the sub-processors.
- Procedures for the detection, management and notification of security incidents.
Annex III — Sub-processors
The controller authorizes the following sub-processors. The activation of each integration depends on the controller connecting or using it; if it is not used, no data is communicated to the corresponding sub-processor.
| Sub-processor / function | Purpose | Location and transfers |
|---|---|---|
| Payment processing (Stripe) | Collection of subscriptions and, where applicable, of bookings. | EU / USA — Standard Contractual Clauses. |
| Connection with channels/OTAs (channel manager) | Synchronization of availability, prices and bookings with the connected portals. | EU / United Kingdom — with adequate safeguards. |
| Transactional email delivery (Resend) | Confirmations, invitations and Service notices. | USA — Standard Contractual Clauses. |
| Hosting and infrastructure (Digital Value, S.L.) | Hosting, database and Service infrastructure. | Spain (EU). |
| Advertising (Meta), only if you connect it | Management of advertising campaigns on networks that the controller activates. | USA — with adequate safeguards. |
| Behavioral analytics (Microsoft Clarity), only with the user's consent | Heatmaps and session recordings of the backoffice to improve usability; the recordings mask the data entered. | USA — EU-U.S. Data Privacy Framework. |
This list is kept up to date on this page. Payment providers and booking portals may act, with respect to certain data, as independent controllers under their own regulations.
Related documents
Zobooq is a project of VACATIOLABS, S.L.U. This document is governed by Spanish law.