MyaGuide Data Processing Addendum (DPA)
Document: Data Processing Addendum
Version: 1.1
Effective Date: 1 June 2026
Last Updated: 12 August 2026
1. Purpose and Status
1.1. This Data Processing Addendum ("DPA") forms part of the Terms of Service entered into between Van Riemsdijk & Karman S.L. (trading as MyaGuide) ("Company," "Processor") and the Customer ("Controller") and applies to the extent the Company processes Personal Data on Customer's behalf in connection with the Service.
1.2. This DPA reflects the requirements of Article 28 of Regulation (EU) 2016/679 ("GDPR") and, where applicable, equivalent provisions of UK data protection law and other applicable Data Protection Laws.
1.3. Capitalized terms not defined in this DPA have the meaning given in the Privacy Policy or the Terms of Service, including "Data Protection Laws" as defined in the Terms of Service. For purposes of this DPA, "Data Protection Laws" also includes applicable Spanish implementing legislation (including Ley Orgánica 3/2018), any other mandatory data protection law that applies to the relevant processing, and, where applicable, UK data protection law.
2. Roles of the Parties
2.1. For Personal Data of End Users (Guests) processed through the Approved Property Guide, the Digital Guest Guide, and Mya, Customer is the Controller and the Company is the Processor.
2.2. For Customer's own account and billing data, the Company is the Controller, and the Privacy Policy (not this DPA) governs that processing.
2.3. Where the Company engages a Sub-processor, that Sub-processor acts as a sub-processor to the Company in accordance with Section 5.
2.4. Customer, as Controller, is responsible for ensuring that it has a lawful basis for, and where required has obtained all necessary consents in connection with, the Personal Data it submits to, or causes End Users to submit to, the Service, including Personal Data within the Approved Property Guide and Personal Data collected directly from End Users.
3. Subject Matter, Duration, and Nature of Processing
3.1. Subject matter. The provision of the Service, including the Digital Guest Guide, Mya, multilingual guest communication, analytics, and related functionality.
3.2. Duration. For the duration of the Agreement, and thereafter only as necessary to comply with Section 9 (Deletion and Return of Data).
3.3. Nature and purpose of processing. Hosting, storage, retrieval, transmission, formulation of AI Concierge responses, translation, and analytics, all as necessary to provide the Service described in the Terms of Service.
3.4. Categories of data subjects. End Users (Guests); Customer's authorized users to the extent relevant.
3.5. Categories of Personal Data. As described in Section 3.3 of the Privacy Policy, including identification and contact data, stay-related data, PIN-protected information, and chat/voice interaction data with Mya. The parties agree that no special category data (Art. 9 GDPR) should knowingly be submitted to the Platform.
4. Processor Obligations
The Company will:
4.1. process Personal Data only on documented instructions from Customer, including with regard to international transfers, unless required to do otherwise by applicable law (in which case the Company will inform Customer of that legal requirement before processing, unless the law prohibits such notice); and will promptly inform Customer if, in the Company's reasonable opinion, an instruction from Customer infringes applicable Data Protection Laws, without obligation to act on that instruction pending resolution of the matter between the parties;
4.2. ensure that persons authorized to process Personal Data are subject to a duty of confidentiality;
4.3. implement appropriate technical and organizational measures as described in the Security Policy;
4.4. taking into account the nature of the processing, assist Customer, by appropriate technical and organizational measures, in responding to requests to exercise data subject rights;
4.5. assist Customer in ensuring compliance with security, breach notification, and data protection impact assessment obligations under Data Protection Laws, taking into account the nature of processing and information available to the Company;
4.6. at Customer's election, delete or return all Personal Data after the end of the provision of the Service, in accordance with Section 9, except where applicable law requires storage; and
4.7. make available to Customer information reasonably necessary to demonstrate compliance with this DPA and allow for, and contribute to, audits, including inspections, conducted by Customer or an auditor mandated by Customer, subject to Section 7.
5. Sub-processors
5.1. Customer authorizes the Company to engage Sub-processors to process Personal Data in connection with the Service, including hosting/infrastructure providers, AI model providers used to formulate Mya's responses, and Stripe for payment processing.
5.2. The Company will maintain a current list of Sub-processors, by category and, where reasonably feasible, by name, in Annex 2 to this DPA, or in an equivalent location made available to Customer, and will provide notice of the addition or replacement of a Sub-processor with material processing responsibilities. Customer may object to a new Sub-processor on reasonable data protection grounds within fourteen (14) days of notice; if the parties cannot resolve the objection, Customer's exclusive remedy is to terminate the affected portion of the Service.
5.3. The Company will impose data protection terms on each Sub-processor that are no less protective than those set out in this DPA, and remains liable to Customer for the Sub-processor's performance of its data protection obligations.
6. International Transfers
6.1. Where Personal Data is transferred outside the EEA (including to a Sub-processor located outside the EEA), the Company will ensure that the transfer is subject to an appropriate safeguard recognized under Data Protection Laws, such as: (a) an adequacy decision of the European Commission; (b) the European Commission's Standard Contractual Clauses (incorporated by reference into this DPA as Annex 3, where applicable); or (c) another lawful transfer mechanism.
6.2. Customer, as Controller, authorizes the Company to enter into Standard Contractual Clauses or rely on another valid transfer mechanism with Sub-processors on Customer's behalf where necessary to give effect to this Section.
7. Audits
7.1. The Company will make available information necessary to demonstrate compliance with this DPA, which may, at the Company's discretion, be satisfied through the provision of relevant certifications, audit reports, or completed security questionnaires.
7.2. Where such information is not sufficient, Customer may request an on-site or remote audit, on reasonable prior written notice, no more than once per year (except following a confirmed security incident), conducted in a manner that minimizes disruption to the Company's business and subject to confidentiality obligations. Customer bears its own costs of an audit; the Company may charge reasonable costs of facilitating an audit beyond standard information provision.
8. Personal Data Breach
8.1. The Company will notify Customer without undue delay after becoming aware of a Personal Data breach affecting Personal Data processed on Customer's behalf, providing information reasonably available to assist Customer in meeting its own notification obligations under Data Protection Laws.
8.2. The Company will take reasonable steps to identify, contain, and remediate the cause of a confirmed breach, consistent with the Security Policy.
9. Deletion and Return of Data
9.1. Upon termination or expiry of the Agreement, and upon Customer's written request made within thirty (30) days of termination, the Company will, at Customer's election, delete or return Personal Data processed on Customer's behalf, except to the extent applicable law requires continued storage, in which case the Company will isolate and protect that data from further processing other than as required by that law.
9.2. If no election is made within the thirty (30) day period referenced in Section 9.1, the Company may proceed to delete the relevant Personal Data in accordance with its standard retention practices described in the Privacy Policy.
10. Liability
10.1. Liability under this DPA is subject to the limitations of liability set out in Section 13 of the Terms of Service, except to the extent such limitation is not permitted under applicable Data Protection Laws with respect to claims brought by data subjects or supervisory authorities.
11. Order of Precedence
In the event of a conflict between this DPA and the Terms of Service with respect to the processing of Personal Data, this DPA prevails.
12. Annex 1 — Description of Processing
See Section 3 of this DPA.
13. Annex 2 — Sub-processors
Sub-processor category | Purpose | Location of processing (general) |
|---|---|---|
Cloud hosting / infrastructure provider | Hosting of the Platform and stored data | EEA / United States (subject to an appropriate transfer mechanism) |
AI model provider | Formulation of Mya's natural-language responses | EEA / United States (subject to an appropriate transfer mechanism) |
Payment processor (Stripe) | Subscription billing and payment processing | EEA / United States (subject to an appropriate transfer mechanism) |
Email/communications provider | Renewal reminders and transactional notices | EEA / United States (subject to an appropriate transfer mechanism) |
Analytics provider | Aggregated usage analytics | EEA / United States (subject to an appropriate transfer mechanism) |
A specific, named, and currently maintained version of this Annex, including precise sub-processor identities and processing locations, is maintained internally and made available to Customer on request, consistent with Section 5.2. This table is for general reference and is to be completed and kept current by the Company's data protection function.
14. Annex 3 — Technical and Organizational Measures
See the Security Policy, which is incorporated into this DPA by reference and describes the technical and organizational measures implemented by the Company.
15. Contact
Van Riemsdijk & Karman S.L. (trading as MyaGuide)
Established in Jávea/Xàbia, Spain · NIF/VAT: ESB21983580
Legal email: mya@myaguide.com
