Legal

Data Processing Addendum

The Article 28 contract between a host, as data controller, and Hostbnb, as their processor. It applies automatically — there is nothing to sign.

In effect from Sep 16, 2026

The short version

  • If you host guests from the UK or EU, the law requires a written contract between you and us before we touch their data. This is it.
  • It takes effect automatically when you accept the Terms. You do not need to sign or request anything.
  • We process guest data only on your instructions, keep it confidential, and help you answer guests' rights requests.
  • We tell you before adding a new sub-processor, and you can object.
  • On termination we delete or return the data, at your choice.

This summary is a reading aid and is not part of the agreement. Where it differs from the text below, the text below is what applies.

Contents+

Nothing to sign

This addendum is incorporated into the Terms of Service and takes effect when you accept them. If your organisation needs a counter-signed copy on paper, write to legal@hostbnb.example.com and we will send one.

This Addendum is between the Hostbnb account holder ("Controller", "you") and [Registered company name] of [Street address], [City], [Prefecture / state], [Postal code], [Country] ("Processor", "we"). It applies where you use Hostbnb to process personal data subject to the EU General Data Protection Regulation, the UK GDPR, or another law that requires equivalent terms. Where it conflicts with the Terms of Service, this Addendum wins on data protection matters.

1. Roles

You are the controller of the personal data you put into Hostbnb and the personal data your guests give you through your guest page. You decide what to collect and why. We are your processor and act only on your instructions.

For our own account data about you — your email, your plan, your billing — we are an independent controller, and the Privacy Policy governs that. This Addendum does not cover it.

You confirm you have a lawful basis for the guest data you process, that you have given your guests the information the law requires, and that your instructions to us do not put us in breach.

2. Subject matter, duration, nature and purpose

Subject matterProviding the Hostbnb guest concierge service to you.
DurationFor as long as your account is open, plus the deletion periods in section 10.
Nature and purposeHosting, storing, indexing, retrieving, translating and displaying the content of your guest pages; generating AI concierge answers from it; and giving you analytics about your own pages.
Types of personal dataGuest names where a guest chooses to give one; the text of guest tips, comments and concierge questions; device and usage data tied to a guest page; and any personal data you choose to put into your own guide content.
Categories of data subjectYour guests, prospective guests, and anyone a host or guest names in content they submit.

Don't put special category data into Hostbnb

Hostbnb is not designed for health data, biometric or genetic data, data revealing race, religion, political opinions, trade union membership or sexual orientation, or for government identifiers such as passport or ID numbers. Do not put it into a guide, a property record, or a concierge conversation, and do not approve a guest tip containing it.

3. Processing only on your instructions

We process personal data only on your documented instructions, including on international transfers, unless a law we are subject to requires otherwise — in which case we will tell you before processing, unless that law forbids us from telling you.

Your use of the product is itself an instruction: publishing a page instructs us to display it, adding a recommendation instructs us to look it up, and enabling the concierge instructs us to send the relevant guide passages to our AI provider so it can answer. You can give additional instructions in writing, and we will tell you if we think one of them breaches data protection law.

4. Confidentiality

Everyone we allow to process this data is bound by a duty of confidence that survives the end of their engagement, is trained on their obligations, and gets access only to what their job requires.

5. Security

We maintain technical and organisational measures appropriate to the risk, as required by Article 32. These are described in the Security section of the Privacy Policy and include encryption in transit and at rest, bcrypt password hashing, signed HttpOnly cookies, least-privilege production access with logging, and optional check-in-code protection for the sensitive parts of a guest page.

We review these measures as the service changes, and may improve them. We will not degrade the overall level of security during the term.

6. Sub-processors

You give us general authorisation to engage sub-processors. The current list, with what each does and where, is at Sub-processors.

We impose data protection obligations on each of them that are no less protective than these, and we remain fully liable to you for their performance. Before adding or replacing one we will give at least 30 days' notice by email and on that page. If you have a reasonable data protection objection, tell us within those 30 days at privacy@hostbnb.example.com and we will work with you on a fix; if we cannot find one, you may terminate the affected part of the service and we will refund the unused period.

7. Helping you with data subject rights

The product is built so you can answer most requests yourself, immediately: you can read, edit, export and delete any guest tip, comment, conversation or property from your dashboard without asking us.

Where you need more, we will help you with appropriate technical and organisational measures, taking into account the nature of the processing. If a guest sends their request to us instead of you, we will not answer it on your behalf — we will tell them to contact you and pass the request on to you without undue delay.

8. Helping you with breaches and assessments

We will notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting your data. The notice will describe the nature of the breach, the categories and approximate number of people and records affected, the likely consequences, and the measures taken or proposed. As the controller, notifying your supervisory authority and your guests is your call and your duty; we will give you what you need to make it.

We will also give you reasonable help with data protection impact assessments and prior consultations under Articles 35 and 36, insofar as they relate to our processing and you cannot get the information yourself.

9. Audits

We will make available the information needed to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you appoint. In practice: write to privacy@hostbnb.example.com and we will answer your questionnaire and share the documentation we hold. An on-site inspection may be requested no more than once a year — unless a regulator or a breach requires otherwise — on 30 days' notice, during business hours, without disrupting our operations, subject to confidentiality, and at your cost.

10. Deletion and return

At the end of the service, you choose whether we delete the personal data or return it. Deleting a property or closing your account deletes its data from the live service immediately, and from backups within 35 days. You can export your content yourself at any time, and for 30 days after an account closes.

We keep data after that only where a law we are subject to requires it — invoices and tax records being the usual case — and only for as long as that law requires, under continuing confidentiality.

11. International transfers

Where we transfer personal data out of the UK or EEA to a country without an adequacy decision, the transfer is governed by the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), or Module Three where onward transfer to a sub-processor makes that the right module, with the UK International Data Transfer Addendum where the UK GDPR applies. Those clauses are incorporated into this Addendum by reference and take precedence over it if they conflict.

ClauseSelection
Docking clause (17)Applies
Clause 9 — sub-processorsOption 2, general written authorisation, with 30 days' notice
Clause 11 — independent dispute resolutionOptional wording does not apply
Clause 17 — governing lawThe law of the EU member state of your supervisory authority, or Ireland where none applies
Clause 18(b) — forumThe courts of the member state whose law governs under Clause 17
Annexes I–IIIPopulated by sections 2, 5 and 6 of this Addendum and the Sub-processors page

12. Other laws

Where you are subject to the California Consumer Privacy Act, we are your "service provider": we do not sell or share personal information, do not retain, use or disclose it for any purpose other than performing the service, and do not combine it with personal information from another source except as the Act permits. Where Japan's Act on the Protection of Personal Information applies, we act as a party entrusted with the handling of personal data under Article 25 and will exercise the necessary supervision over our sub-processors.

13. Liability and term

The liability limits in the Terms of Service apply to this Addendum, except where the law does not permit them to. This Addendum takes effect when you accept those Terms and ends when they do, apart from the obligations in sections 4, 10 and 11, which survive for as long as we hold any of your data.