This Data Processing Agreement (“DPA”) applies when you use Villanote (https://villanote.com) to process the personal data of your guests - for example by keeping a guest list, recording their contact details or stay, or sending them a message. For that guest data you are the data controller and Jedro Labs LLC (“we”, “us”), a Wyoming limited liability company, act as your data processor. This DPA forms part of, and is governed by, our Terms of Service. Words defined in the EU General Data Protection Regulation (“GDPR”) have the same meaning here.
It does not cover your own host-account data (your email, guides and billing) - for that processing we are the controller, as described in our Privacy Policy.
1. Roles and subject-matter
You are the controller of the guest personal data you process with Villanote; we are your processor and process it only to provide the Service to you. The subject-matter, nature, purpose, duration, data categories and categories of data subject are set out in Annex 1.
2. Our processing on your instructions
We process guest personal data only on your documented instructions - which are: this DPA, the ordinary operation of the Service and its features, and the settings and actions you choose in your account (for example marking a guest as consented, or sending a message). We will tell you if, in our opinion, an instruction infringes data-protection law. We do not use your guests' personal data for our own purposes and we never sell it.
3. Duration
This DPA applies for as long as we process guest personal data on your behalf. On termination, Section 9 applies.
4. Confidentiality
We ensure that people authorised to process guest personal data are bound by an appropriate duty of confidentiality.
5. Security
We implement appropriate technical and organisational measures to protect guest personal data, taking into account the state of the art and the risk of the processing, as required by GDPR Article 32. Those measures are described in Annex 2.
6. Sub-processors
You give us general authorisation to engage the sub-processors listed in Annex 3 to help us provide the Service. We impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible to you for their performance. If we add or replace a sub-processor we will update this page and, where you have asked us to, give you notice so that you can object on reasonable data-protection grounds.
7. Assistance to you
Taking into account the nature of the processing and the information available to us, we will assist you, as far as reasonably possible, to:
- respond to requests from your guests to exercise their rights (access, rectification, erasure, restriction, portability and objection) - you can view, edit, export and delete individual guests, and delete your whole account, from within the Service;
- meet your own obligations to keep the processing secure, to notify personal-data breaches, and to carry out data-protection impact assessments and prior consultations (GDPR Articles 32-36).
8. Personal-data breaches
We will notify you without undue delay after becoming aware of a personal-data breach affecting guest data we process for you, with the information you reasonably need to meet your own notification duties.
9. Return or deletion on termination
When you stop using the guest features, or close your account, the guest personal data we hold for you is deleted within a reasonable period - deleting your account erases your guests, guides and files. Before then you can export or delete guest data yourself at any time. We may retain data only where and for as long as the law requires.
10. Records and audits
We make available the information reasonably necessary to demonstrate compliance with this DPA - including this page, Annex 2 and the sub-processor list - and will contribute to audits mandated by you, conducted on reasonable prior notice, no more than once a year unless required by a supervisory authority, and subject to confidentiality. A completed security questionnaire will ordinarily satisfy an audit request.
11. International transfers
The Service and its database are hosted in Frankfurt, Germany (EU). Some sub-processors process data in the United States; where guest personal data is transferred outside the EEA we rely on an appropriate transfer mechanism (such as the EU Standard Contractual Clauses or the EU-US Data Privacy Framework).
12. General
This DPA forms part of the Terms of Service. If there is a conflict between this DPA and the rest of the Terms about the processing of guest personal data, this DPA prevails. Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms. This DPA is governed by the law and venue stated in the Terms.
Annex 1 - Description of the processing
- Subject-matter: managing a host's guest contacts and stays, and sending host-initiated messages to those guests, within Villanote.
- Duration: for as long as you use the guest features and keep the data, subject to Section 9.
- Nature and purpose: storage, organisation, retrieval, export and deletion of guest records, and delivery of messages you initiate - all to provide the Service to you.
- Categories of personal data: a guest's name; email address and/or phone number (where you record them); preferred language; stay dates; marketing-consent status and its basis; and any tags or notes you add. Please do not record special categories of data (such as health) in free-text notes.
- Categories of data subject: your guests and prospective guests.
Annex 2 - Technical and organisational measures
- Encryption in transit: all traffic is served over HTTPS/TLS.
- Encryption at rest: the database and file storage are encrypted at rest by our infrastructure providers.
- Access control: production access is limited to authorised personnel; within the Service every host can reach only their own account's data, and that isolation is covered by our automated tests.
- Authentication: host passwords are stored only as bcrypt hashes; an emailed sign-in code can be required for every sign-in; sessions can be reviewed and revoked.
- Accountability: administrative actions on an account are recorded in an audit log.
- Resilience: the managed database keeps regular, encrypted backups with point-in-time recovery.
- Data minimisation and deletion: we collect only what the guest features need, and delete guest data on account closure or on your request.
- Sub-processor diligence: sub-processors are engaged under contract with equivalent data-protection obligations.
Annex 3 - Sub-processors
- Render - application hosting (Frankfurt, Germany)
- Neon - managed PostgreSQL database (Frankfurt, Germany)
- Brevo - transactional and host-initiated email
- Cloudinary - storage and delivery of guide images
- Stripe - payments and billing (host billing data only)
- Anthropic and Google (Gemini) - AI drafting and translation of guide content (not used to profile guests)
Contact
Questions about this DPA, or a signed counterpart for your records? Email hello@villanote.com.