ProductPricing
Book a demo→
— Legal
Privacy PolicyCookie PolicyTerms of UseLegal NoticeData Processing AgreementSubprocessorsAcceptable Use Policy

Data Processing Agreement

The Article 28 GDPR terms under which Artidal processes personal data on behalf of its customers, including the processing details, security measures, subprocessors, and international-transfer safeguards.

Last updated: September 1, 2026

This Data Processing Agreement ("DPA") forms part of the service agreement (the "Agreement") between Artidal OÜ ("Processor", "Artidal") and the customer ("Controller") and governs the processing of personal data that Artidal carries out on the Controller's behalf under Article 28 of the GDPR.

Note: this is a starting-point template for review by legal counsel before it is offered for signature. Where the Agreement and this DPA conflict on data-protection matters, this DPA prevails.

1. Definitions

"GDPR" means Regulation (EU) 2016/679. "Personal data", "processing", "controller", "processor", "data subject", and "personal data breach" have the meanings given in the GDPR. "Subprocessor" means any processor engaged by Artidal to process personal data on the Controller's behalf.

2. Roles and scope

The Controller determines the purposes and means of processing personal data it uploads to, or generates within, the Artidal platform. Artidal acts solely as a processor and processes personal data only to provide the services and on the Controller's documented instructions, including those set out in the Agreement and this DPA. Details of the processing are set out in Annex 1.

3. Processor obligations

In line with Article 28(3) GDPR, Artidal shall:

  • process personal data only on the Controller's documented instructions, including regarding international transfers, unless required to act otherwise by EU or Estonian law (in which case it will inform the Controller unless legally prohibited);
  • ensure that persons authorised to process the personal data are bound by an appropriate obligation of confidentiality;
  • implement the technical and organisational security measures described in Annex 2, appropriate to the risk, in accordance with Article 32 GDPR;
  • respect the conditions in Section 4 for engaging subprocessors;
  • assist the Controller, by appropriate measures, in responding to requests from data subjects exercising their rights under Chapter III of the GDPR;
  • assist the Controller in ensuring compliance with its obligations regarding security, breach notification, data protection impact assessments, and prior consultation (Articles 32-36 GDPR), taking into account the nature of the processing and the information available to Artidal;
  • at the Controller's choice, delete or return all personal data at the end of the services, and delete existing copies unless retention is required by law; and
  • make available to the Controller all information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits and inspections as set out in Section 6.

4. Subprocessors

The Controller grants Artidal general authorisation to engage subprocessors to provide the services. A current list of subprocessors is maintained in our Subprocessors document.

Artidal will inform the Controller of any intended addition or replacement of a subprocessor, giving the Controller a reasonable opportunity to object on reasonable data-protection grounds. Artidal will impose data-protection obligations on each subprocessor that are no less protective than those in this DPA, and remains fully liable to the Controller for its subprocessors' performance.

5. Personal data breaches

Artidal will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's personal data, and will provide the information reasonably available to help the Controller meet its own breach-notification obligations.

6. Audits

Artidal will make available information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates. The parties will agree reasonable scope, timing, and confidentiality in advance, and audits will be conducted so as to minimise disruption to Artidal's operations.

7. International transfers

Where Artidal or a subprocessor transfers personal data outside the EEA, it will ensure an appropriate safeguard under Chapter V GDPR is in place — such as an adequacy decision, the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914) with any additional measures required, or the EU-U.S. Data Privacy Framework where the recipient is certified.

8. Duration

This DPA takes effect alongside the Agreement and continues for as long as Artidal processes personal data on the Controller's behalf.

Annex 1 — Details of processing

  • Subject matter: provision of the Artidal hospitality-management platform and related services.
  • Duration: the term of the Agreement, plus any period until data is deleted or returned.
  • Nature and purpose: hosting and processing of data to deliver bookings, property and operations management, payments, guest communication, marketing, analytics, and related features.
  • Types of personal data: names, contact details, booking and stay details, transaction and payment-related data, communications and message content, and account and usage data. The Controller must not upload special-category data unless agreed and lawful.
  • Categories of data subjects: the Controller's guests and customers, staff and authorised users, and business contacts.

Annex 2 — Technical and organisational measures

Artidal maintains the measures below, appropriate to the risk. «Important: this annex must describe measures you actually have in place — not aspirations. Confirm each item and remove any you do not yet meet. Do not list a certification (e.g. ISO 27001, SOC 2) unless it has genuinely been obtained.»

  • Access control — role-based access, unique accounts, and the principle of least privilege for systems processing personal data.
  • Authentication — enforced strong credentials and multi-factor authentication for administrative access.
  • Encryption — encryption of personal data in transit (TLS); «confirm whether data is also encrypted at rest and state it here».
  • Network and application security — firewalls, segregation of environments, and regular patching.
  • Logging and monitoring — logging of access and key events to detect and investigate incidents.
  • Backups and resilience — regular backups with tested restoration and measures to maintain availability.
  • Personnel — confidentiality obligations and data-protection awareness for staff with access.
  • Incident response — a documented process for handling and reporting personal data breaches.
  • Supplier management — due diligence and data-protection terms with subprocessors.

Artidal may update these measures from time to time, provided the level of protection is not reduced, and may replace any measure with one that is functionally equivalent or more protective.

Annex 3 — Subprocessors

The current list of authorised subprocessors is maintained in our Subprocessors document, which forms part of this DPA.

Requesting a signed DPA

Customers who require a countersigned copy of this DPA can request one at privacy@artidal.com.

The operating system for travel & hospitality.

hello@artidal.com
+372 623 7035
— Platform
Bookings & ReservationsOperationsGuest ExperienceCommunicationRevenue & PaymentsMarketing & GrowthAll Modules
— Solutions
Surf CampsYoga & Wellness RetreatsAdventure LodgesBoutique Eco-ResortsMulti-Location Operators
— Resources
BlogPricingRSS Feed
— Legal
Privacy PolicyCookie PolicyTerms of UseLegal NoticeData Processing AgreementSubprocessorsAcceptable Use Policy
artidal.
© 2026 Artidal OÜ · all rights reservedPrivacy Policy · Cookie Policy · Terms of Use · Legal Notice · Data Processing Agreement · Subprocessors · Acceptable Use Policy