Effective date: 14 September 2026. Version 1.1.

Enterprise customers may request a countersigned copy for their records; the online version at /dpa remains the operative text unless a written amendment is executed.

1. Binding effect and incorporation

This Data Processing Agreement ("DPA") forms part of the contract between the Host ("Controller") and Josef Pechar, IČO 24005169 ("Processor"), for the UbyHost service ("Service") described in the Terms of Service at /terms. By creating an account, logging in, or using the Service, the Controller agrees to this DPA on behalf of itself and any legal entities it configures in the Service. If the Controller signs a separate written data processing agreement with the Processor that expressly supersedes this DPA, that signed agreement prevails to the extent of conflict.

2. Definitions

Capitalised terms not defined here have the meaning in the Terms or GDPR. "Guest Data" means personal data relating to Guests processed by the Processor on behalf of the Controller through the Service. "Personal Data Breach" has the meaning in GDPR Article 4(12). "Subprocessor" means a third party engaged by the Processor to process Guest Data. "Applicable Data Protection Law" means GDPR, Act No. 110/2019 Coll., and other laws binding the Controller or Processor.

3. Roles of the parties

For Guest Data, the Controller is the data controller and determines the purposes and means of processing vis-à-vis Guests. The Processor processes Guest Data only on documented instructions from the Controller (including configuration in the Service, submissions to UbyPort when enabled, and support requests) and does not process Guest Data for its own marketing or unrelated purposes. The Processor is an independent contractor, not an agent of the Controller for accommodation or regulatory filings.

4. Subject matter, duration, and nature of processing

Subject matter: provision of hosted software for house books, guest forms, stay management, and optional police reporting integrations. Duration: for the term of the Controller's use of the Service and until Guest Data is deleted or returned per Section 15. Nature of processing: collection, storage, organisation, retrieval, transmission, encryption of credentials, display to authorised Controller users, formatting for export, and transmission toward UbyPort or related endpoints when the Controller enables such features.

5. Details of processing (Annex summary)

Categories of data subjects: Guests, and occasionally third parties named on travel documents. Types of personal data: identity and contact details, nationality, dates of birth and stay, travel document numbers and types, addresses, signatures, accommodation metadata, and optional passport photographs or PDFs uploaded for verification. Special categories: the Service may process document images that could reveal ethnic origin or health only where the Controller instructs such upload and has a lawful basis; the Controller is responsible for necessity and proportionality. Controller personnel data is outside this DPA except where listed in the Privacy Policy.

6. Controller obligations

The Controller shall: (a) comply with Applicable Data Protection Law; (b) provide lawful instructions and ensure a valid legal basis for processing; (c) maintain accurate guest privacy notices naming the Controller entity and contact; (d) not instruct processing that violates law; (e) ensure Host Users are authorised and trained; (f) respond to data subject requests from Guests unless the Processor assists as stated below; (g) notify the Processor without undue delay if a Guest objects to processing that affects the Service.

7. Processor obligations

The Processor shall: process Guest Data only on documented instructions unless required by EU or Member State law (in which case the Processor informs the Controller unless prohibited); ensure persons authorised to process Guest Data are bound by confidentiality; implement appropriate technical and organisational measures per Section 10; engage Subprocessors per Section 11; assist the Controller as set out in Sections 12–14; and make available information necessary to demonstrate compliance with Article 28 obligations.

8. Documented instructions

Instructions include: this DPA, the Terms, the Privacy Policy, the Controller's in-app configuration (properties, legal entities, reporting settings), actions taken through the user interface, and written requests to operator contact on /legal. If the Processor believes an instruction infringes Applicable Data Protection Law, it will inform the Controller without undue delay. The Processor may suspend processing of the infringing instruction where legally required or where continuing would expose the Processor to substantial risk, after reasonable notice where practicable.

9. Confidentiality

The Processor ensures that persons processing Guest Data are subject to confidentiality obligations (contractual or statutory). The Processor will not disclose Guest Data to third parties except as permitted in this DPA, the Privacy Policy, or with the Controller's instructions, or as required by law with notice to the Controller where allowed.

10. Security measures (Article 32)

Taking into account the state of the art, costs, and risks, the Processor implements measures including: access controls and authentication for Host accounts; mandatory two-factor authentication (TOTP) in production; encryption of sensitive integration credentials and TOTP secrets at rest; HTTPS for data in transit; Cloudflare Turnstile where configured; logical separation of customer data; rate limiting on authentication; backup and recovery procedures (including optional off-site copies to Google Drive and Amazon S3 when configured by the Operator); restriction of production access to authorised personnel; and security updates to dependencies. The Controller is responsible for password strength, device security, recovery codes, and sharing guest links only with intended recipients. A summary is also in the Privacy Policy.

11. Subprocessors

The Controller provides general written authorisation for the Processor to engage Subprocessors listed or described in the Privacy Policy at /privacy (including infrastructure hosting such as AWS Lightsail, Render.com, Cloudflare including Turnstile, Google Drive and Amazon S3 for configured backups, and, where used, DNS/CDN or e-mail providers). The Processor will impose data protection terms on Subprocessors substantially similar to this DPA. The Processor remains liable to the Controller for Subprocessor performance to the extent required by Article 28(4). The Processor will inform the Controller of intended changes to Subprocessors (e.g. by updating the Privacy Policy) and allow the Controller to object on reasonable data-protection grounds; if unresolved, the Controller may terminate the affected Service as per the Terms.

12. Assistance with data subject rights

Taking into account the nature of processing, the Processor assists the Controller by appropriate technical measures to fulfil obligations to respond to Guest requests (access, rectification, erasure, restriction, portability, objection) where feasible and only on the Controller's instruction. Guests must contact the Controller as named in the guest privacy notice. The Processor may charge reasonable fees for manifestly excessive or repetitive requests unless prohibited by law.

13. DPIA and prior consultation

Where required under Articles 35–36 GDPR, the Controller conducts data protection impact assessments and prior consultations. The Processor provides available information about the Service and security measures upon reasonable written request to assist the Controller.

14. Personal data breach

The Processor notifies the Controller without undue delay after becoming aware of a Personal Data Breach affecting Guest Data, with information available to allow the Controller to meet Articles 33–34 obligations. Notification may be by e-mail to the account contact or in-app where practicable. The Processor will cooperate with reasonable remediation and documentation requests.

15. Return and deletion of Guest Data

Upon termination of the Service or on the Controller's documented request, the Processor will delete or return Guest Data within a reasonable period, except where storage is required by law or retained in encrypted backups for a limited disaster-recovery window before automatic purging. Export tools in the Service should be used before termination. Anonymised or aggregated data that cannot identify individuals may be retained.

16. Audits and information

The Processor makes available information necessary to demonstrate compliance with Article 28 and allows for audits no more than once per twelve (12) months on thirty (30) days' notice, during business hours, without disrupting other customers, subject to confidentiality and security restrictions. The Controller bears its own audit costs unless an audit reveals material non-compliance attributable to the Processor. The Processor may satisfy audit requests through current certifications or third-party reports where they cover the Service.

17. International transfers

The Processor processes data primarily in the EEA. Where a Subprocessor transfers Guest Data outside the EEA, the Processor ensures appropriate safeguards under Chapter V GDPR (including Standard Contractual Clauses or adequacy decisions). Details are in the Privacy Policy. The Controller authorises such transfers as part of this DPA unless the Controller objects in writing on valid legal grounds.

18. Liability

Liability between the parties for Guest Data processing is governed by the Terms of Service (including limitations and indemnities). Each party remains liable to data subjects and supervisory authorities under Applicable Data Protection Law for its own violations. Nothing in this DPA limits either party's liability where limitation is not permitted by law.

19. Processor contact for data protection

Data protection queries and instructions regarding Guest Data processing should be sent to Josef Pechar using contact details on /legal (e-mail if published). The Controller should include account identification and a clear description of the requested action.

20. Changes to this DPA

The Processor may update this DPA to reflect legal, technical, or Subprocessor changes. Material changes will be posted at /dpa with an updated effective date and, where practicable, notified at least thirty (30) days before taking effect. Continued use of the Service after the effective date constitutes acceptance where permitted by law. The Controller may terminate if it reasonably objects to a material change that materially weakens protection and no alternative is offered.

21. Order of precedence

For Guest Data processing: this DPA prevails over conflicting Terms provisions. The Privacy Policy describes broader processing (including Controller account data) and does not limit Processor obligations here. Guest-facing notices are the Controller's responsibility. Mandatory law prevails over all contractual documents.

22. Governing law

This DPA is governed by the laws of the Czech Republic. Courts in Prague have exclusive jurisdiction for business users as in the Terms, subject to mandatory consumer or data subject rules that cannot be waived.

23. Severability

If a provision of this DPA is invalid, the remainder remains effective. The parties will replace the invalid provision with a valid one that best reflects the original intent.

24. Entire agreement on processing

Together with the Terms and Privacy Policy, this DPA constitutes the complete agreement on the Processor's processing of Guest Data, superseding prior oral or written understandings on that subject unless a later signed writing expressly amends it.

Professional review

This DPA follows common SaaS practice under GDPR and Czech law. It does not replace your own privacy programme, records of processing, or guest notices. Seek qualified counsel for high-risk processing or group-wide compliance programmes.

Legal notice · Terms of Service · Privacy Policy · Back to login

Export CSV

Choose the date range to include in the export.

Search or jump to…

Keyboard shortcuts

g d
Go to Overview
g s
Go to Stays
g r
Go to Reports
g h
Go to House book
⌘/Ctrl K
Open search
j / k
Select next row / Select previous row
Enter
Open selected row