Data Processing Addendum
Protectum Data Processing Agreement – Mutual
Last updated: July 26, 2026
This Data Processing Agreement (the “DPA”), entered into by the partner that is a party to the terms of services and/or agreement(s) that refer to this DPA (the “Partner”) and Dmytro Pavlov Autónomo (along with its affiliates, “Protectum”), governs the processing of Personal Data that Partner uploads or otherwise provides Protectum or that Protectum provides Partner in connection with the integration of Protectum and Partner services.
This DPA is incorporated into the relevant Protectum terms of service and agreement(s) and any applicable addendums and/or attachments under which Protectum and Partner may integrate their respective services and/or products (referred to collectively in this DPA as the “Protectum Contract”). Collectively, the DPA and the Protectum Contract are referred to in this DPA as the “Agreement.” In the event of any conflict or inconsistency between any of the terms of the Agreement, the provisions of the following documents (in order of precedence) shall prevail: (a) this DPA; (b) the Protectum Contract. Except as specifically amended in this DPA, the Protectum Contract remains unchanged and in full force and effect.
1. Definitions
“Data Protection Requirements” refers to the General Data Protection Regulation (GDPR), and any other applicable laws or regulations related to: (a) privacy, data security, and the protection of Personal Data; and (b) the Processing of Personal Data.
“EU Personal Data” means Personal Data governed by the General Data Protection Regulation within the European Union.
“General Data Protection Regulation” refers to Regulation (EU) 2016/679 of the European Parliament and Council, along with any associated directives, regulations, or national implementations.
“Partner Personal Data” refers to Personal Data that the Partner uploads or provides to Protectum in connection with the integration of Protectum and Partner services. In this context, the Partner acts as the data controller, and Protectum acts as the data processor.
“Personal Data” means any information related to an identifiable individual that:
- can identify, contact, or locate the individual directly;
- can be combined with other data to achieve such identification; or
- is otherwise defined as “personal data” or “personal information” under applicable data protection laws.
“Personal Data Breach” refers to any unauthorized or unlawful destruction, loss, alteration, access to, or disclosure of Partner Personal Data.
“Process” (and related terms like “Processing”) refers to any operation or series of operations performed on Personal Data, whether automated or manual, including collection, storage, organization, use, transmission, or deletion.
“Protectum Personal Data” refers to Personal Data that Protectum provides to the Partner in connection with service integration. In this case, Protectum acts as the data controller, and the Partner acts as the data processor.
“SCCs” refers to the Standard Contractual Clauses adopted by the European Commission for international data transfers.
“Subprocessor” refers to any third party that processes Personal Data on behalf of a data processor.
“Supervisory Authority” refers to an independent public body established under Article 51 of the GDPR or any other relevant data protection authority with jurisdiction over the Partner.
2. Nature of Data Processing
Each data processor agrees to Process Personal Data on behalf of a data controller in connection with the Agreement solely for the purposes specified in the Agreement.
Categories of Data Subjects
- Partner employees, agents, and other administrators accessing Protectum services and/or products to provide services to Partner’s end users.
- Protectum employees, agents, and other administrators accessing Partner services and/or products to provide services to Protectum’s end users.
- End users of both Partner and Protectum.
- Residents, household members, guests, and other authorized users of the Protectum Booking Service.
Categories of Personal Data Processed
- Login ID information including name, email address, and mobile phone number.
- Access user and guest information including name, email address, mobile phone number, and location.
- Remote access control information and transactions, including access requests and events.
- Card, pass, household, and public-booking-link identifiers used to establish booking eligibility.
- Resource bookings, including resource, time, access window, status, channel, cancellation information, references, and related audit and controller-synchronization records.
3. Compliance with Laws
The parties agree to comply with their respective obligations under all applicable Data Protection Requirements, including but not limited to laws and regulations governing the collection, processing, storage, and transfer of Personal Data.
4. Data Controller Obligations
- Each party, in their capacity as a data controller, agrees to:
- determine the purposes and general means of the data processor’s Processing of Personal Data in accordance with the Agreement; and
- comply with its protection, security, and other obligations with respect to Personal Data prescribed by Data Protection Requirements for data controllers.
- Each data controller agrees to, at the other party’s request, designate a single point of contact responsible for receiving and responding to data subject requests that a data processor receives from data subjects relating to such data controller’s Personal Data.
5. Data Processor Obligations
5.1 Processing Requirements
- Process Personal Data solely to provide, support, and enhance the other party’s services (including reporting and analytics), using adequate technical and organizational measures to ensure security. The data processor must not Process Personal Data for any other purposes and shall promptly notify the data controller in writing if it cannot meet the requirements of this DPA.
- Inform the data controller immediately if it believes any instructions received violate applicable Data Protection Requirements.
- Take commercially reasonable steps to ensure compliance by (i) its employees and (ii) any third parties acting on its behalf.
- Ensure all employees, authorized agents, and Subprocessors comply with confidentiality obligations, including after their engagement ends.
- If Subprocessors are engaged, (i) remain accountable for their actions and omissions in relation to Personal Data; and (ii) ensure contractual commitments obligate Subprocessors to uphold the same level of data protection and security as this DPA.
- Provide, upon request, a list of Subprocessors used in connection with their services. All Subprocessors used by Protectum are deemed approved by this Agreement.
5.2 Notice
Inform the data controller promptly if aware of:- Non-compliance with this DPA or applicable Data Protection Requirements;
- Legally binding disclosure requests from law enforcement authorities, unless prohibited by law;
- Notifications, inquiries, or investigations from Supervisory Authorities regarding Personal Data;
- Complaints or data subject requests (e.g., access, erasure, portability) related to the data controller’s Personal Data. The processor will not respond substantively without the data controller's written consent.
5.3 Assistance
Provide reasonable support to the data controller in:- Responding to data subject requests (e.g., access, correction, deletion) for Personal Data being processed;
- Investigating and addressing Personal Data Breaches, including notifications to authorities and affected individuals;
- Preparing data protection impact assessments and conducting consultations with Supervisory Authorities, as necessary.
5.4 Required Processing
Notify the data controller if Processing is required under applicable law for purposes outside the Agreement’s scope, unless prohibited by law.5.5 Security
- Maintain technical and organizational security measures to safeguard Personal Data from unauthorized access, loss, or alteration.
- Ensure the adequacy of security measures employed by personnel involved in data Processing and remain accountable for failures to meet security standards.
- Require all personnel involved in data Processing to adhere to this DPA’s confidentiality and security standards.
- Report Personal Data Breaches involving the processor, Subprocessors, or third parties within 48 hours of awareness.
5.6 Contacting Protectum
Questions or concerns related to this DPA should be directed to Protectum at hi@protectum.es.
5.7 Supervisory Authority Audit
If a Supervisory Authority requests an audit of the facilities where a data processor handles Personal Data to assess compliance with Data Protection Requirements, the data processor will cooperate fully with the audit. The data controller shall bear all costs and expenses associated with the audit, including any reasonable fees for time and resources the data processor dedicates to comply with the audit requirements.
6. Data Transfers
Each party agrees that it will only transfer Personal Data to the other party after implementing any additional measures required under applicable law, such as executing the Standard Contractual Clauses (SCCs) or other legally mandated agreements.
If Personal Data protected under the General Data Protection Regulation is transferred between the parties in a manner requiring SCCs without a prior explicit agreement, the parties agree that, by entering into this DPA, they are deemed to have executed the applicable SCCs, which are incorporated herein by reference.
7. Data Return and Deletion
Upon termination of data processing services or at the data controller's reasonable request, the data processor shall, at the controller’s discretion, either return all Personal Data (including copies) to the controller or securely destroy it. The data processor must ensure that any Subprocessors follow the same instructions and demonstrate compliance to the satisfaction of the data controller.
If Data Protection Requirements prevent the data processor from fully returning or destroying Personal Data, the data processor shall ensure the continued confidentiality of such retained data and limit its active Processing strictly to what is necessary to comply with legal obligations.
8. Term
This Data Processing Agreement (DPA) will remain in effect as long as either party is involved in processing Personal Data on behalf of the other party, or until the termination of the Protectum Contract, provided that all Personal Data has been returned or deleted in accordance with the provisions of this DPA.
9. Governing Law, Jurisdiction, and Venue
Notwithstanding any provisions in the Agreement to the contrary, this DPA shall be governed by the laws of Spain. Any legal action or proceeding related to this DPA, including disputes that arise outside the context of the contract, shall be brought in the jurisdiction of Comunidad Valenciana, Spain.