Data Processing Addendum (DPA) - Auctores Technologies OÜ
Version: 2026-07-11 (last updated 11 July 2026)
Applies to: Auctores service and any integrations (incl. PMS connections) where Auctores processes personal data on behalf of a business customer.
0) Parties and incorporation into the Agreement
This Data Processing Addendum ("DPA") is entered into between:
- Controller (Customer): the legal entity that accepts the Auctores Terms of Service (the "Customer"), and
- Processor: Auctores Technologies OÜ, registry code 17394351, Harju maakond, Tallinn, Kesklinna linnaosa, Ahtri tn 12, 15551, Estonia ("Auctores").
This DPA forms part of and is incorporated into the contract between the parties governing the Customer's use of the Service (the "Agreement", typically the Auctores Terms of Service).
Effective Date: the date the Customer accepts the Agreement (or, if signed separately, the signature date of this DPA).
Order of precedence: If there is a conflict between this DPA and the Agreement regarding personal data processing, this DPA prevails.
1) Definitions
Applicable Data Protection Law means GDPR and any applicable implementing laws in EU/EEA Member States, and (where applicable) UK GDPR.
Controller, Processor, Personal Data, Processing,Data Subject have the meanings given in GDPR.
Customer Personal Data means Personal Data processed by Auctores on behalf of Customer in connection with the Service.
Subprocessor means a Processor engaged by Auctores to process Customer Personal Data.
Security Incident means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data (a "personal data breach" under GDPR).
2) Scope of processing
2.1 Subject matter, nature, purpose, and duration
Auctores processes Customer Personal Data to provide the Service, including (as applicable) ingesting operational data from connected systems (e.g., PMS/CRS) to generate analytics and recommendations (including smart overbooking recommendations and optional write-back actions if enabled by Customer).
Auto Apply is disabled by default. Customer must affirmatively enable it and grant the necessary permissions before Auctores is instructed to write a recommended setting to a connected system.
Processing details (categories of data subjects, data types, and processing operations) are described in Annex 1.
Duration: for the term of the Agreement, plus limited retention as described in this DPA and Annex 1.
2.2 Customer as Controller
Customer is responsible for:
- determining the lawful basis for processing Customer Personal Data;
- providing required notices to Data Subjects;
- ensuring any necessary permissions/authorisations are obtained for Customer's connected data sources.
3) Processing on documented instructions
Auctores shall:
- process Customer Personal Data only on documented instructions from Customer, including as set out in the Agreement, this DPA, and Customer's configuration choices in the Service;
- inform Customer if Auctores believes an instruction violates Applicable Data Protection Law (unless prohibited by law).
Customer's use of Service features (e.g., enabling/disabling "Auto-Apply", selecting properties/room categories, setting risk caps, choosing sync scopes) constitutes documented instructions.
4) Confidentiality
Auctores ensures that persons authorised to process Customer Personal Data:
- are bound by confidentiality obligations; and
- access Customer Personal Data only as needed to provide the Service.
5) Security (Art. 32 GDPR)
Auctores implements appropriate technical and organisational measures to protect Customer Personal Data, taking into account the state of the art, costs of implementation, and risks.
Baseline measures include (non-exhaustive):
- encryption in transit (TLS) and encryption at rest where supported;
- encrypted storage of connector secrets/tokens and restricted access;
- role-based access control, least privilege, logging/monitoring.
Further detail is provided in Annex 2 (TOMs).
6) Subprocessors
6.1 Authorisation
Customer provides general authorisation for Auctores to engage Subprocessors to deliver the Service.
6.2 List and notifications
Auctores maintains a list of Subprocessors in Annex 3 (and may also maintain an online subprocessor list).
Auctores will provide notice of intended changes (addition or replacement of Subprocessors) by updating Annex 3 / the online list and (where reasonable) via in-product or email notice. Customer may object to a new Subprocessor on reasonable data protection grounds.
6.3 Flow-down obligations and liability
Auctores will:
- impose data protection obligations on Subprocessors that are no less protective than this DPA; and
- remain responsible for Subprocessors' performance of their obligations related to Customer Personal Data.
7) Assistance to Customer
Taking into account the nature of processing, Auctores will provide reasonable assistance to Customer with:
7.1 Data Subject requests
Responding to Data Subject requests (access, deletion, etc.) to the extent Customer cannot fulfil such requests independently through the Service.
7.2 Compliance obligations
Supporting Customer with:
- security and breach notification obligations;
- data protection impact assessments (DPIAs) and consultations with supervisory authorities, where applicable.
8) Security Incidents (personal data breaches)
Auctores will:
- notify Customer without undue delay after becoming aware of a Security Incident involving Customer Personal Data;
- provide available information reasonably required for Customer to meet breach reporting obligations; and
- take reasonable steps to mitigate and remediate the incident.
9) Return or deletion of Customer Personal Data
Upon termination or expiry of the Agreement, Auctores will, at Customer's choice (to the extent supported by the Service):
- return Customer Personal Data (export), and/or
- delete Customer Personal Data.
Auctores may retain limited data where required by law or for legitimate security/audit purposes (e.g., minimal operational logs) for a limited period, after which it is deleted or irreversibly anonymised according to Auctores retention practices.
10) International transfers
Auctores' primary production deployment uses Supabase in Frankfurt, Germany (eu-central-1) and Railway in Amsterdam, the Netherlands (europe-west4). Google Cloud encryption/key-management resources are configured in an Auctores-selected European location, and MailerSend's current DPA identifies a data centre in Belgium. The current public location, jurisdiction, and international-access safeguards disclosure is maintained in Sections 6 and 7 of the Privacy Policy.
If Customer Personal Data is transferred outside the EU/EEA (and where applicable the UK), Auctores will use an applicable lawful transfer mechanism, including the European Commission's Standard Contractual Clauses where required, and supplementary technical, organisational, and contractual measures appropriate to the transfer. Those measures include encryption, least-privilege access, confidentiality, logging/monitoring, data minimisation, and provider contractual controls.
11) Liability
Liability under this DPA follows the liability provisions of the Agreement, to the extent permitted by Applicable Data Protection Law.
13) Contact
Data protection contact: leo@auctores.ai or valentin@auctores.ai (or the contact address listed in the Privacy Policy).
Annex 1 - Details of Processing (Art. 28(3))
A. Categories of Data Subjects
- Customer's authorised users/admins (hotel staff)
- Guests/individuals referenced in reservation records (to the extent included in PMS data)
B. Categories of Personal Data (typical)
Reservation / operational data (depending on the PMS and Customer configuration), such as:
- reservation identifier(s), status (booked/modified/cancelled/no-show), booking timestamps
- stay dates (arrival/departure), room category/type, rate plan, channel/source
- number of guests, optional flags (e.g., guarantee indicator)
- cancellation timestamp and reason (if available)
Important exclusions (intended):
- No payment card numbers/CVV (PCI data) is required or intended to be processed by Auctores.
C. Special categories (Art. 9)
Not intended to be processed.
D. Processing operations (nature)
Collection from connected systems, storage, organisation, analysis/modeling to generate recommendations, display in dashboards, and (if enabled) write-back of configuration/limits to connected systems.
E. Purpose
Provide overbooking/cancellation analytics and recommendations; support automation actions when explicitly enabled by Customer.
F. Duration / retention
- Account-related data: for duration of the Customer account.
- Connector credentials: stored while the connection is active; deleted on disconnection or account deletion.
- Minimal operational logs: typically retained up to 180 days for security and troubleshooting (unless law requires longer).
- Provider-managed backup/disaster-recovery copies: isolated from ordinary processing and overwritten or expired under the applicable provider backup cycle; completed deletion requests are reapplied if a backup is restored.
- Billing, tax, contract, consent, and security evidence: only for the applicable legal or claims period.
- The latest public retention criteria are maintained in the Privacy Policy.
Annex 2 - Technical & Organisational Measures (TOMs)
Auctores maintains a security program appropriate to the nature of the Service and the risks.
Access control
- Role-based access control (RBAC) and least-privilege access
- Restricted production access; logging/monitoring of privileged access
Encryption
- Encryption in transit via TLS
- Encryption at rest where supported by providers
- Connector secrets/tokens stored encrypted; accessed only for authorised API calls
Operational security
- Logging/monitoring for production systems
- Incident response procedures (detect, contain, remediate, post-incident review)
Data minimisation
- Only data needed for forecasting/recommendations is processed
- Configurable scopes (properties/room categories/time windows) where applicable
Availability & resilience
- Backups and restore processes (as supported by infrastructure providers)
- Measures to maintain service continuity
Vendor management
- Use of Subprocessors under contractual controls
- Periodic review of Subprocessor security posture (reasonable effort)
Annex 3 - Subprocessors (as of version date)
Auctores uses the following Subprocessors (may change over time; see Subprocessor notice process in Section 6):
| Subprocessor | Purpose | Primary location used |
|---|---|---|
| Supabase | Database, authentication, and storage | Frankfurt, Germany (eu-central-1) |
| Google Cloud Platform (GCP) | Encryption / key management | Auctores-selected European location |
| Railway | Application hosting and backend execution | Amsterdam, the Netherlands (europe-west4) |
| MailerSend | Transactional email delivery | Belgium (documented data centre) |