Henora GuestLegal

Henora Guest

Data Processing Agreement

Last updated · 26 June 2026

This Data Processing Agreement (“DPA”) supplements the Terms of Service between you (the “Customer”) and SC BROKEN HEART WEAR S.R.L. (operating Henora Guest, the “Processor”). It applies whenever the Processor processes personal data on behalf of the Customer in the course of providing the Service, and is intended to satisfy Article 28 of Regulation (EU) 2016/679 (GDPR).

1. Roles

  • The Customer is the Controller of any personal data it places into a guide (e.g. host contact details, emergency numbers, third-party contact information, guest names if it chooses to record them).
  • The Processor processes that personal data only on the Customer’s documented instructions, as set out in this DPA and the Terms of Service.
  • Guest analytics displayed to the Customer are aggregated and not personal data; the Processor acts as Controller for technical operation logs and for the Customer’s own account data, as described in the Privacy Policy.

2. Subject matter, duration, nature and purpose

Subject matterProvision of the Henora Guest platform (digital guest guides, QR sharing, recommendations, optional video instructions, optional team accounts).
DurationFor the duration of the subscription, plus the retention periods set out in the Privacy Policy.
Nature and purposeHosting, storage, transmission, display and retrieval of personal data the Customer enters into guides, so that guests can view that data via a link or QR code.
Types of personal dataContact data (name, phone, email, WhatsApp), property addresses, free-text notes that may incidentally contain personal data, account email and authentication credentials.
Categories of data subjectsThe Customer, the Customer's hosts / staff / co-hosts, third parties added by the Customer (e.g. emergency contacts), guests who voluntarily open a guide.

3. Processor obligations

The Processor will:

  • process personal data only on the Customer’s documented instructions (the Terms and this DPA), including with regard to transfers, unless required by EU or Member State law;
  • ensure that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation;
  • take all measures required pursuant to Art. 32 GDPR (security of processing);
  • respect the conditions for engaging sub-processors set out in Section 5;
  • assist the Customer, taking into account the nature of processing, by appropriate technical and organisational measures, in fulfilling its obligations to respond to data-subject requests;
  • assist the Customer in ensuring compliance with Art. 32–36 GDPR (security, breach notification, DPIA, prior consultation);
  • at the Customer’s choice, delete or return all personal data after the end of the provision of services and delete existing copies unless EU or Member State law requires storage;
  • make available to the Customer all information necessary to demonstrate compliance with this DPA and allow for, and contribute to, audits.

4. Security measures (Art. 32 GDPR)

The Processor maintains, at minimum:

  • encryption of personal data in transit (TLS) and at rest, where supported by the underlying infrastructure;
  • role-based access control, least-privilege principle, secure credential management;
  • multi-factor authentication for administrative access to infrastructure providers;
  • logging and monitoring of administrative access and security-relevant events;
  • regular backups managed by the underlying database provider, with point-in-time recovery available on supported plans;
  • a documented incident-response process and the ability to restore availability and access in a timely manner;
  • regular review of effectiveness of these measures.

5. Sub-processors

The Customer provides a general authorisation for the Processor to engage sub-processors. The current list of sub-processors is published in Section 5 of the Privacy Policy and includes Supabase, Vercel Inc., Bunny.net, Stripe, Resend, Inc. and OpenAI, Inc. (the latter only for Premium and Hotel plans, for automatic translation of guide content).

The Processor will inform the Customer of any intended addition or replacement of sub-processors by updating the Privacy Policy. The Customer has the right to object to any new sub-processor on reasonable data-protection grounds within 30 days, in which case the parties will work together in good faith; if no resolution is reached, the Customer may terminate the affected portion of the Service.

The Processor remains fully liable to the Customer for the performance of each sub-processor’s obligations.

6. International transfers

Some sub-processors (e.g. Vercel, Resend) are established in the United States. Transfers outside the EEA are governed by the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914), in their controller-to-processor or processor-to-processor module as applicable, together with any supplementary measures the Processor or sub-processor implements following its transfer impact assessment.

7. Data-subject requests

If the Processor receives a request from a data subject regarding personal data processed on behalf of the Customer, it will refer the data subject to the Customer and, where appropriate, notify the Customer without undue delay so the Customer can respond as Controller.

8. Personal-data breaches

The Processor will notify the Customer of any personal-data breach affecting Customer data without undue delay after becoming aware of it, providing the information reasonably available to enable the Customer to meet its own obligations under Art. 33–34 GDPR.

9. Return or deletion at end of services

On termination of the subscription, the Customer may export its data from Settings → Privacy & data → Download my data or by using Delete account to permanently erase everything immediately. Backups will be overwritten in the normal course of business by the underlying infrastructure providers.

10. Liability and audits

Each party’s liability under this DPA is subject to the limitations of liability in the Terms of Service. The Customer may audit the Processor’s compliance with this DPA by reviewing publicly available certifications and reports of the sub-processors, and by submitting reasonable written questions to support@henoraguest.com; on-site audits may be agreed where strictly necessary, with reasonable notice and protection of confidential information.

11. Governing law

This DPA is governed by Romanian law and forms an integral part of the Terms of Service. In case of conflict between the Terms and this DPA on data-protection matters, this DPA prevails.

12. Acceptance

By using the Service in a Controller capacity (notably by entering third-party personal data into a guide or by adding team members), the Customer accepts this DPA. A countersigned PDF version is available on request at support@henoraguest.com.