Data Processing Agreement
Last updated 26 September 2026
The short version
The hotel decides what guest data is collected and why. We only handle it on the hotel’s instructions, keep it secure, use only the sub-processors listed here, tell the hotel quickly if something goes wrong, and delete or return the data when the hotel leaves.
1. Scope and roles
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Consulaw Tech Services (“Processor”, “we”) and the hotel that uses Alejo OS (“Controller”, “Hotel”). It applies whenever we process personal data on the Hotel’s behalf in providing the Service, and it takes effect when the Hotel accepts the Terms. It is drafted to meet Section 29 of the Nigeria Data Protection Act 2023 (“NDPA”) and the NDPC’s implementing rules, and, where the GDPR applies, Article 28 GDPR. A countersigned copy is available on request.
The Hotel is the controller of its guests’ and staff members’ personal data. We are the processor. For the account data of the Hotel’s users, and for data we use for our own security and billing, we are a controller in our own right, as our Privacy Policy explains.
2. Details of the processing
| Item | Detail |
|---|---|
| Subject matter | Providing the Alejo OS hotel operations platform to the Hotel. |
| Duration | For as long as the Hotel uses the Service, plus the deletion period in section 9. |
| Nature and purpose | Hosting, storing, organising, retrieving, displaying, transmitting and deleting data to run reservations, check-in and check-out, folios and payments, housekeeping, maintenance, guest requests, orders, events, staff access, NFC and door access, notifications and reporting. |
| Types of personal data | Guest identity and contact details (name, email, phone), ID type and number, nationality, stay and booking details, special requests and notes, orders and service requests, folio and payment records (no full card numbers), NFC and door-access credentials and activity, guest session tokens; staff name, email, role, sign-in and audit records. |
| Data subjects | The Hotel’s guests and prospective guests, the Hotel’s staff and users, and other people the Hotel records. |
| Special categories | None intended. The Hotel must not put special-category data (such as health or biometric data) into free-text fields unless it has a lawful basis and a genuine need. |
3. Our obligations
We will:
- process personal data only on the Hotel’s documented instructions, which are the Terms, this DPA and the Hotel’s use and configuration of the Service, unless the law requires otherwise (in which case we tell the Hotel first, if lawful);
- tell the Hotel if we believe an instruction breaches data protection law;
- make sure everyone with access to the data is bound by confidentiality and is given access only as needed;
- apply the security measures in Annex A;
- not sell the data, and not use it for our own purposes other than those the Hotel has authorised, and aggregated, anonymised analytics that cannot identify anyone;
- keep records of our processing as the law requires.
4. Sub-processors
The Hotel gives general authorisation for the sub-processors in Annex B. We will bind each of them to obligations no less protective than this DPA, and remain responsible for their performance. We will tell the Hotel of any intended addition or replacement at least 30 days before it takes effect, by email or in the app. The Hotel may object on reasonable data protection grounds within that period. If we cannot resolve the objection, the Hotel may end the affected part of the Service without penalty.
5. Helping the Hotel with data subject requests
Guests and staff exercise their rights against the Hotel. The Service lets the Hotel view and correct the data it holds, and we provide an export on request. If a person contacts us directly about data we process for the Hotel, we will not respond on the merits and will redirect them to the Hotel and tell the Hotel promptly. We will give the Hotel reasonable help, on request, in responding to requests for access, correction, deletion, restriction, portability and objection.
6. Personal data breaches
We will tell the Hotel without undue delay, and where possible within 48 hours, after becoming aware of a personal data breach affecting its data. Our notice will describe, as far as we then know, the nature of the breach, the data and people affected, the likely consequences and the measures taken or proposed, and we will update it as we learn more.
The Hotel decides whether and how to notify the Nigeria Data Protection Commission (within 72 hours where the breach is likely to put people’s rights at risk) and affected individuals, and we will give the help it reasonably needs to do so.
7. Impact assessments and prior consultation
On request we will give the Hotel the information it reasonably needs about how the Service processes data so it can carry out data protection impact assessments and any consultation with the NDPC.
8. International transfers
The Hotel authorises us to process and transfer data to the locations in Annex B, including outside Nigeria. We will make sure each transfer has a lawful basis under the NDPA and, where it applies, Chapter V GDPR: an adequacy finding, Standard Contractual Clauses or an equivalent binding safeguard, and appropriate technical measures. The Hotel is responsible for any additional transfer requirements that apply specifically to it.
9. Return and deletion
While the agreement runs the Hotel can ask us for an export at any time. After it ends, on the Hotel’s written request we will export the data to the Hotel in a common format, and then delete or anonymise it within 90 days, unless the law requires us to keep some of it (for example accounting records), in which case we keep it securely and only for that purpose. Backups are overwritten in their normal cycle. On request we will confirm deletion in writing.
10. Information and audits
We will provide the information needed to show compliance with this DPA, including written answers to reasonable security and privacy questionnaires. Where that is not enough, and no more than once a year (or after a breach), the Hotel may audit our relevant practices on 30 days’ notice, during business hours, subject to confidentiality and without unreasonable disruption to other customers. The Hotel pays the cost of an audit it initiates unless it reveals a material breach by us.
11. The Hotel’s obligations
- The Hotel has a lawful basis for the data it puts into Alejo OS and gives the required notices to guests and staff.
- The Hotel’s instructions comply with the law, and the Hotel keeps its accounts and staff access secure.
- The Hotel records only the guest data it genuinely needs, and sets sensible retention for it.
- The Hotel tells us promptly if it receives a request or complaint that affects our processing.
12. Liability and order of precedence
The liability terms of the Terms of Service apply to this DPA. If this DPA conflicts with the Terms on the processing of personal data, this DPA prevails. Nothing here limits a data subject’s rights or either party’s liability where the law does not allow it to be limited.
13. Annex A - Security measures
- Encryption in transit (HTTPS/TLS) for all traffic; provider-managed encryption at rest for hosted databases.
- Passwords hashed with bcrypt; never stored or logged in plain text.
- Optional two-factor authentication (TOTP) with hashed single-use backup codes; session tokens signed, HTTP-only and short-lived, revocable on password change or sign-out everywhere.
- Role-based access control enforced on every server action, not just in the interface; separate authentication for guest sessions, which end at check-out.
- Sign-in, reset and public-form rate limiting; one-time, expiring tokens for password reset, email verification and staff invitations.
- Third-party payment credentials that hotels provide are encrypted at rest with a separate key; payment webhooks are signature-verified.
- Audit logging of sensitive actions; security headers and a content security policy on the application.
- Separation of each hotel’s data by hotel identifier in every query; least-privilege access for our own staff; dependency vulnerability scanning.
- Backups and recovery through our database provider; incident response and breach procedure as in section 6.
14. Annex B - Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase (Amazon Web Services) | Managed database hosting | European Union (Frankfurt) |
| Vercel | Application hosting, serverless compute, delivery | United States, with global edge delivery |
| Paystack | Payment processing and payouts (Nigeria) | Nigeria and other regions Paystack operates in |
| Stripe | Payment processing for hotels that connect Stripe | United States and European Union |
| Resend | Transactional email delivery | United States |
| Tappa | NFC card, tag and access services | As described in Tappa’s own notices |
| Sentry | Application error monitoring, where enabled | United States |
Questions about this DPA or a request for a countersigned copy: consulawtech@gmail.com.
