Skip to content
RoomAnchorPMS

Data processing agreement

How we process guest and staff personal data on behalf of your organisation.

Last updated

Draft for review. Have your legal adviser review this page before relying on it.

This data processing agreement ("DPA") forms part of the RoomAnchor terms of service between [company legal name], of [registered address] ("we", the processor), and the organisation using RoomAnchor ("you", the controller).

1. Roles

You decide why and how personal data about your guests, staff and contacts is processed in RoomAnchor. You are the controller. We process that data only on your behalf and on your documented instructions, which are these terms, this DPA and your use of the service.

2. Data covered

Category of people Typical data
Guests Name, email, phone, address, nationality, identification numbers, stay history, preferences, requests, folio charges and payments, loyalty points, marketing consent
Staff Name, email, role, property access, shifts, clock times, leave, and pay rates where you record them
Business contacts Company accounts, suppliers, event organisers

We do not ask for special category data. If you choose to record it, for example in notes, you are responsible for having a lawful basis.

3. Our obligations

We will:

  • process personal data only to provide, secure and support the service;
  • make sure our staff with access are bound by confidentiality;
  • keep appropriate technical and organisational security measures (section 5);
  • help you respond to requests from people exercising their rights, using the tools in the service where possible;
  • tell you without undue delay, and within 72 hours where we can, after becoming aware of a personal data breach affecting your data;
  • delete or return your data at the end of the service, as set out in section 8;
  • give you the information reasonably needed to show compliance with this DPA.

4. Your obligations

You will:

  • have a lawful basis for the data you collect, including marketing consent for campaigns and guest messages that need it;
  • give guests and staff the privacy information the law requires;
  • control who in your team can see what, using roles and property access;
  • keep your own account credentials and API keys secure.

5. Security measures

  • Hosting in a managed environment with access limited to authorised staff.
  • HTTPS for every connection, encrypted sessions and security headers.
  • Each organisation's data is separated in the application, and every request is checked against the organisation it belongs to.
  • Guest identification numbers, and payment gateway and SMS credentials, are encrypted at rest.
  • Two-factor authentication for users, which an organisation can require.
  • An activity log of changes with user, time, IP address and browser.
  • Scheduled database backups with monitoring and cleanup.
  • Support sign-ins to your organisation are bannered and logged.

6. Sub-processors

You authorise us to use sub-processors for hosting, email delivery and, when you turn them on, payment gateways (such as Stripe, SSLCommerz and bKash), SMS providers (such as SSL Wireless and BulkSMS BD) and channel providers. We will keep a current list available on request and give notice before adding a new sub-processor, so you can object on reasonable grounds.

Some providers you connect, such as a payment gateway using your own merchant account, act under their own agreement with you rather than as our sub-processor.

7. Transfers

Where data is processed outside Bangladesh, we take reasonable steps to keep it protected to the standard required by the applicable law of Bangladesh.

8. End of the service

When your subscription ends, your organisation stays available in read-only form for at least 30 days so you can export your data. After that we delete it from the live service, unless the law requires us to keep it. Copies in backups are overwritten on their normal cycle.

9. Liability and precedence

The liability terms in the terms of service apply to this DPA. If this DPA and the terms of service conflict about personal data, this DPA wins.

10. Contact

[company legal name], [registered address]. Questions about this DPA can be sent to the support email shown on our website.