HotelO — owned and operated by Dwoing
This DPA is between:
HotelO is owned and operated by Dwoing.
This DPA forms part of the agreement between HotelO and the Customer for use of the HotelO platform. It applies to personal data processed by HotelO on the Customer’s behalf through the service.
If there is a conflict between this DPA and another agreement concerning the processing of personal data, this DPA will control to the extent of that conflict, unless the parties have expressly agreed otherwise in writing.
For personal data that the Customer enters into HotelO for its hotel operations, the Customer generally determines why the information is collected and how it is used. HotelO processes that information to provide, secure, maintain and support the contracted HotelO services.
Accordingly, the Customer is responsible for determining the lawful basis and appropriate purpose for collecting guest, employee, vendor and other personal information, while HotelO acts as the service provider/processor for those processing activities to the extent applicable under law.
HotelO may act as an independent Data Fiduciary/controller-type entity for information it collects directly for its own legitimate business purposes, such as account administration, billing, security, fraud prevention, support and legal compliance. Such processing is governed primarily by the HotelO Privacy Policy.
“Personal Data” means information relating to an identified or identifiable individual, to the extent protected by applicable law.
“Processing” includes collection, recording, organisation, storage, retrieval, use, disclosure, transmission, restriction, deletion or other handling of Personal Data.
“Data Principal”, “Data Fiduciary”, “Data Processor” and similar terms have the meanings assigned by applicable data-protection law, including the Digital Personal Data Protection Act, 2023 and applicable rules, when those provisions apply.
The subject matter of processing is the provision of the HotelO hotel-management and CRM services, including account management, customer/guest records, reservations or operational records where enabled, billing-related records, housekeeping or property-management workflows, reports, support and related platform functions.
Processing continues for the duration of the Customer’s active subscription and for any limited period thereafter necessary for lawful retention, backup, security, dispute resolution or compliance, subject to the Customer’s deletion/export rights and applicable law.
Depending on the Customer’s configuration and use of the platform, Personal Data may include:
The Customer should not upload information to HotelO unless it is reasonably necessary for its lawful hotel operations and the Customer has an appropriate legal basis and safeguards for doing so.
Where identity documents, government identifiers, financial information or other sensitive/high-risk information are processed, the Customer is responsible for determining whether collection, storage and use are legally permitted and for providing any required notice or consent.
HotelO does not require Customers to use the platform as a general-purpose repository for sensitive information and may restrict particular uses where necessary for security, legal or operational reasons.
HotelO will process Customer-controlled Personal Data primarily to:
HotelO will not intentionally use Customer-controlled Personal Data for unrelated advertising or sell it as a standalone data-broker product.
The Customer is responsible for:
HotelO will maintain reasonable technical and organisational safeguards appropriate to the nature of the processing and risks involved. Measures may include access controls, authentication mechanisms, least-privilege access, application-level protections, secure server configuration, backups, monitoring, logging and measures designed to protect data against unauthorised access, alteration, loss or disclosure.
No internet-based system can be guaranteed to be completely secure. The Customer is responsible for maintaining secure passwords, authorised-user controls and secure devices used to access HotelO.
HotelO will limit access to Customer Personal Data to personnel, contractors and service providers who need such access to provide or support the services, subject to appropriate confidentiality obligations and access controls.
HotelO may use hosting providers, infrastructure providers, payment providers, email or notification providers, analytics/security services and other technology suppliers necessary to operate the platform.
Where a third party processes Customer Personal Data on HotelO’s behalf, HotelO will seek to impose contractual or equivalent obligations appropriate to the nature of the processing and will remain responsible for its processing activities as required by applicable law.
Depending on the infrastructure and service providers used, Personal Data may be processed or stored outside the Customer’s state or country. Where applicable law imposes requirements or restrictions on such transfers or processing, HotelO will take steps required of it under that law.
Where the Customer is the responsible Data Fiduciary/controller, the Customer generally handles requests from individuals concerning their Personal Data, including requests for access, correction, updating, erasure or other rights available under applicable law.
Where HotelO receives a request that appears to concern Customer-controlled data, HotelO may direct the requester to the relevant Customer unless applicable law requires HotelO to respond directly.
HotelO will provide reasonable assistance, where technically feasible and legally required, to help the Customer respond to valid data-subject/Data Principal requests.
If HotelO becomes aware of a security incident affecting Customer-controlled Personal Data that requires notification under applicable law, HotelO will take reasonable steps to investigate, contain and remediate the incident and provide information to the Customer as required by applicable law and reasonably available to HotelO.
The Customer remains responsible for determining whether it has notification obligations to guests, authorities or other parties based on its role and applicable law, except to the extent a law places the obligation directly on HotelO.
HotelO may disclose Personal Data where required by law, court order, governmental authority or other legally binding process. Where legally permitted and reasonably practicable, HotelO may provide notice to the Customer so that the Customer can consider appropriate action.
HotelO will retain Customer-controlled Personal Data for as long as necessary to provide the service and, after termination, for limited periods where required for backups, security, accounting, legal compliance, dispute resolution or enforcement of agreements.
Retention periods may vary depending on the data type, service configuration and applicable legal requirements.
Subject to the capabilities of the applicable HotelO plan and reasonable technical limitations, the Customer may request or use available functionality to export Customer data during or following the subscription.
Following termination, HotelO may delete or anonymise Customer-controlled data in accordance with its retention practices, backup cycles and applicable legal obligations. Data in backups may remain for a limited period until those backups are securely overwritten or otherwise disposed of.
HotelO will provide reasonable information about its relevant privacy and security practices where necessary for the Customer to assess compliance obligations relating to the HotelO service, subject to confidentiality, security and protection of HotelO’s systems and other customers.
Any formal audit or security assessment requiring access to non-public systems, personnel or facilities may be subject to reasonable prior notice, scope, security requirements and cost arrangements.
HotelO is designed as a multi-customer SaaS platform. Customer accounts and records are intended to be logically separated so that one Customer cannot ordinarily access another Customer’s records through normal application functions.
The Customer must not attempt to bypass access controls, inspect another tenant’s records or use the service to obtain unauthorised information.
As between HotelO and the Customer, the Customer retains its rights in the Customer data it submits to the platform. The Customer grants HotelO the limited rights necessary to host, process, transmit, back up and otherwise handle that data to provide the contracted services.
HotelO may use technical, diagnostic and aggregated information that does not reasonably identify an individual or expose a Customer’s confidential business information for purposes such as service improvement, security, performance monitoring and analytics, subject to applicable law.
The Customer must not knowingly use HotelO to collect or process children’s Personal Data except where it is lawful and the Customer has complied with applicable requirements. Hotels should apply appropriate safeguards where minors are guests.
Where applicable law imposes additional requirements concerning children’s data, the parties will comply with those requirements according to their respective legal roles.
Where payments are handled through an external payment provider, payment-card processing may occur directly through that provider rather than being stored as full card information in HotelO. Customers should not enter full card numbers, CVVs, passwords, OTPs or other authentication secrets into ordinary HotelO notes or customer fields unless a specific feature expressly supports such information.
Each party will comply with applicable data-protection, cybersecurity and information-technology laws applicable to its role. The parties will reasonably cooperate where required to respond to lawful regulatory inquiries relating to processing performed under this DPA.
HotelO may restrict or suspend processing, accounts, features or access where reasonably necessary to protect the platform, prevent abuse, respond to a security threat, comply with law or enforce the Main Agreement.
Each party remains responsible for its own acts and omissions. Nothing in this DPA excludes liability that cannot lawfully be excluded or limited. Any contractual limitation of liability applicable to the HotelO service will apply to this DPA to the extent legally permissible.
HotelO may update this DPA when reasonably necessary to reflect changes to the service, technology, security practices or applicable law. Material changes will be communicated through the website, account interface or other reasonable means. Continued use of the service after the effective date of an updated DPA constitutes acceptance where permitted by applicable law and contract.
This DPA is governed by the laws applicable to the HotelO service and the parties’ underlying agreement, subject to any mandatory legal requirements applicable to data protection or privacy.
This DPA is intended to support compliance with applicable Indian data-protection and information-technology requirements, including the Digital Personal Data Protection Act, 2023 and applicable rules as and when their respective provisions come into force, together with other applicable laws and regulatory requirements.
The parties acknowledge that legal obligations may change and that this DPA does not remove any obligation imposed directly by applicable law.
For questions concerning this DPA, data processing, privacy or security matters:
Dwoing / HotelO
Email: hello@hotelo.in
Website: https://hotelo.in/
By subscribing to or using HotelO where this DPA is presented as part of the contractual documents, the Customer confirms that it has reviewed and agrees to this DPA to the extent applicable to its use of the service.