HospiX · Legal
Data Processing Agreement
Last updated 6 August 2026
This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the Terms of Service between you (the "Customer") and The Trap Limited (company no. C108490, VAT MT31026127), trading as HospiX ("HospiX", "we", "us"). It applies whenever we process personal data on your behalf, and reflects Article 28 of the UK GDPR / EU GDPR.
1. Roles
For personal data about your guests and your staff that you enter into or generate through the Service (for example guest contacts in Guest Intelligence, loyalty and bookings, or staff names, pay and PINs in the staff tools), you are the Controller and we are your Processor. For your own account data (your name, email and billing details) we are the Controller, as described in our Privacy Policy.
2. Subject matter, duration, nature and purpose
- Subject matter and duration: our processing of Customer personal data for the duration of your subscription, plus the limited retention described in clause 8.
- Nature and purpose: hosting, storing, organising and displaying the data so we can provide the Service you have subscribed to, and to support you.
- Types of personal data: guest contact details (name, email, phone, birthday), guest visit and spend history, staff names and contact details, staff pay and hours, and any other personal data you choose to enter.
- Categories of data subjects: your guests and customers, and your staff and team members.
3. Our obligations as Processor
- Instructions: we process Customer personal data only on your documented instructions, which include using the Service and its settings, unless law requires otherwise (in which case we will tell you, unless the law forbids it).
- Confidentiality: anyone we authorise to process the data is bound by confidentiality.
- Security: we implement appropriate technical and organisational measures under Article 32, including encryption in transit, hashed passwords and staff PINs, access controls, server-side redaction of financial and personal data from users who are not entitled to see it, rate limiting, and separation of each customer's data.
- Assistance: taking into account the nature of the processing, we assist you with responding to data-subject requests, and with your obligations on security, breach notification, data protection impact assessments and prior consultation.
- Data-subject tools: the Service provides export and deletion tools so you can fulfil access, portability and erasure requests yourself.
4. Sub-processors
You give general authorisation for us to engage the sub-processors listed on our Sub-processors page to help provide the Service (hosting, database, payments, email and AI features). Each sub-processor is bound by data-protection terms no less protective than this DPA. We will give you a way to be notified of any intended change so you can object on reasonable data-protection grounds.
5. International transfers
Where a sub-processor processes personal data outside the EU/EEA, we rely on an adequacy decision or on Standard Contractual Clauses (or an equivalent safeguard). See the Sub-processors page for where each provider processes data.
6. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting Customer personal data, and will provide the information you reasonably need to meet your own notification duties (which, for a qualifying breach, is within 72 hours to your supervisory authority).
7. Audits
We make available the information necessary to demonstrate compliance with Article 28 and, on reasonable prior notice and subject to confidentiality, allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
8. Return and deletion
On termination, and at your choice, we delete or return Customer personal data, and delete existing copies, within a reasonable period, except where law requires us to keep limited records (for example invoices). Deleting your account deletes your personal data and content within 30 days, save for those limited legal-retention records.
9. Liability and precedence
The liability provisions of the Terms of Service apply to this DPA. Where this DPA conflicts with the Terms on the processing of Customer personal data, this DPA prevails.
10. Contact
Data-protection queries or to exercise audit rights: emanportelliwork@gmail.com.
Questions? emanportelliwork@gmail.com
Back to topThis is a general template provided for convenience. Have it reviewed by a qualified solicitor and tailored to your registered company details, jurisdiction and payment provider before relying on it commercially.