Version: DPA v1.0, Effective date: 15 January 2026
Master Data Processing Agreement
This Master Data Processing Agreement ("DPA") is between Grand Systems ApS, CVR no. 42289086, Højbro Plads 10, 1200 Copenhagen, Denmark ("GRAND") and the Customer identified in the applicable Partner Agreement ("Customer"), together the "Parties". It forms part of, and is incorporated into, the Agreement between GRAND and Customer for the use of GRAND's property management system and related services. Capitalised terms not defined in this DPA have the meaning given in the Agreement, including the Master Terms & Conditions ("MTC").
1. Roles, subject matter and duration
1.1 Roles.
- Where Customer is the hotel / venue (or a similar organisation using GRAND PMS to manage its own operations), Customer is the Controller and GRAND is the Processor for personal data processed in the Service on Customer's instructions (for example guest and attendee data).
- Where Customer itself acts as a Processor for its own client (for example a management company acting for a hotel chain), GRAND acts as Customer's Sub-processor. In that scenario, references in this DPA to "Controller" mean Customer's client, and Customer remains responsible for passing down the Controller's instructions to GRAND.
- GRAND is an independent Controller for its own business and relationship data, including sales and marketing data, contracting and billing, telemetry, security logging, analytics, fraud and abuse prevention and similar purposes. Those Controller-lane activities are not governed by this DPA and will be described in GRAND's privacy notice.
1.2 Subject matter. The subject matter of this DPA is GRAND's processing of personal data as Processor or Sub-processor on behalf of Customer in connection with providing the Service.
1.3 Duration. This DPA applies for as long as GRAND processes personal data on behalf of Customer under the Agreement and continues until deletion or anonymisation of such data in accordance with clause 9.
1.4 Description of processing. The nature, purpose, categories of data and data subjects and processing operations are described in Annex A.
2. Instructions and processing on behalf of Customer
2.1 Documented instructions. GRAND shall process personal data only on documented instructions from Customer, including with respect to transfers of personal data to a third country, unless required to do so by EU or Member State law to which GRAND is subject. In such a case, GRAND shall inform Customer of that legal requirement before processing, unless the law prohibits such information.
2.2 Agreement and configuration as instructions. The Agreement, this DPA, and Customer's normal use and configuration of the Service (including through APIs and integrations that Customer enables) constitute Customer's documented instructions.
2.3 Notification of unlawful instructions. If GRAND considers that an instruction from Customer infringes the GDPR or other EU/Member State data protection law, GRAND shall promptly inform Customer and may suspend the relevant processing until the instruction is clarified or changed.
2.4 Restrictions on special category data. The Service is not designed to store special categories of personal data (for example detailed health data, religious or political information) or other highly sensitive data. Customer must not use free-text fields for such data and must only use structured fields where strictly necessary (for example for simple accessibility needs) and where Customer has an appropriate legal basis. This restriction is part of Customer's instructions to GRAND.
3. GRAND's obligations as Processor / Sub-processor
3.1 Confidentiality. GRAND shall ensure that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
3.2 Security measures. GRAND shall implement and maintain appropriate technical and organisational measures to protect personal data, taking into account the nature, scope, context and purposes of processing and the risks to data subjects. A description of GRAND's baseline security measures is set out in Annex C and may be updated from time to time without reducing the overall level of protection.
3.3 Sub-processors.
- Customer authorises GRAND to engage Sub-processors to provide the Service, as listed in Annex B.
- GRAND shall impose on each Sub-processor data protection obligations that are at least as protective as those in this DPA, including appropriate security measures.
- GRAND remains responsible to Customer for the performance of its Sub-processors.
3.4 Assistance with data subject rights. Taking into account the nature of the processing, GRAND shall assist Customer, by appropriate technical and organisational measures, in fulfilling Customer's obligations to respond to requests from data subjects under Chapter III of the GDPR, to the extent such requests relate to personal data in the Service.
3.5 Assistance with security and DPIA. GRAND shall, upon Customer's request and taking into account the nature of processing and the information available to GRAND, provide reasonable assistance to Customer in relation to:
- security of processing;
- notification of personal data breaches to supervisory authorities and communication of such breaches to data subjects; and
- where required, data protection impact assessments and prior consultations with supervisory authorities.
3.6 Data breach notification. GRAND shall notify Customer without undue delay after becoming aware of a personal data breach affecting personal data processed on behalf of Customer. The notification shall at least:
- describe the nature of the breach, including, where possible, the categories and approximate number of data subjects and data records concerned;
- describe the likely consequences of the breach; and
- describe the measures taken or proposed to address the breach and mitigate its possible adverse effects.
GRAND may provide information in phases as it becomes available. Customer remains responsible for any required notifications to authorities or data subjects, unless the Parties agree otherwise in writing.
3.7 Records of processing. GRAND shall maintain records of processing activities carried out on behalf of Customer as required by Article 30(2) GDPR and make them available to Customer upon request, to the extent necessary to demonstrate compliance.
3.8 No sale or unrelated use. GRAND shall not sell personal data or use it for purposes other than providing the Service, fulfilling its legal obligations, or its own independent Controller purposes described in its privacy notice.
4. Customer's obligations
4.1 Controller responsibilities. Customer is responsible for complying with its obligations as Controller (or as Processor vis-à-vis its own Controller) under applicable data protection law, including:
- ensuring that it has a valid legal basis for the processing of personal data in the Service;
- providing appropriate privacy notices to data subjects;
- configuring the Service in a way that supports compliance (for example retention settings, access permissions); and
- avoiding the entry of unnecessary special category data or other sensitive data.
4.2 Accuracy, minimisation and retention. Customer is responsible for the accuracy of personal data and for defining and implementing appropriate retention periods in the Service that align with Customer's legal obligations and policies.
4.3 Instructions. Customer shall provide instructions that are lawful, documented and compatible with the functionality and technical limitations of the Service.
4.4 Informing data subjects. Where required by law, Customer shall inform data subjects that their personal data is processed in GRAND PMS and that it may be transferred to GRAND and its Sub-processors as described in this DPA and the MTC.
5. Sub-processors and changes
5.1 Current Sub-processors. The Sub-processors engaged by GRAND as of the effective date are listed in Annex B.
5.2 Additions and replacements. GRAND may add or replace Sub-processors provided that:
- GRAND updates the live sub-processor list; and
- GRAND gives Customer at least thirty (30) days' prior notice, for example by email to the notice contact in clause 8.1 or via the Service.
5.3 Right to object. Customer may object in writing to a new Sub-processor on reasonable grounds relating to data protection within the notice period. If Customer objects, the Parties shall work together in good faith to find a reasonable solution. If no solution is found within thirty (30) days, Customer may terminate the affected part of the Service (or, if no separation is technically feasible, the Agreement) with effect from the date the new Sub-processor is scheduled to start, without penalty. This is Customer's sole remedy for objections to Sub-processors.
6. International transfers
6.1 EU/EEA processing only. As of the Effective Date, Grand and its Sub-processors process Customer personal data for the Service only in the EU/EEA. Grand will not intentionally transfer Customer personal data (including PMS guest and admin data) to a country outside the EU/EEA in connection with the Service, unless: (a) Customer explicitly enables an integration or data flow that requires such a transfer; or (b) the Parties agree otherwise in writing.
6.2 Transfers to third countries. Should GRAND intend to engage a Sub-processor or introduce any data flow that results in Customer Personal Data being processed in or from a third country, GRAND shall (a) ensure appropriate safeguards under Chapter V GDPR (such as in relation to Standard Contractual Clauses, supplemented, where necessary, by additional technical and organisational measures); and (b) update this DPA and the Sub-processor list before such processing starts, giving Customer the right to object under clause 5.3.
6.3 Customer-configured integrations. Where Customer connects the Service to third-party systems under Customer's own control (for example by connecting its own payment provider or marketing tools), Customer is responsible for ensuring that any resulting transfers outside the EU/EEA comply with applicable law. In such cases, GRAND's role is limited to executing Customer's configuration.
7. Audits and information
7.1 Information and reports. GRAND shall make available to Customer all information reasonably necessary to demonstrate compliance with this DPA, for example security summaries, audit reports or certifications, subject to confidentiality.
7.2 Audit right. Customer (or its independent auditor bound by confidentiality) may, no more than once per year and with at least thirty (30) days' prior written notice, carry out a reasonable audit of GRAND's compliance with this DPA, to the extent such audit cannot reasonably be satisfied by the information provided under clause 7.1. Audits shall:
- be conducted during normal business hours and in a manner that minimises disruption;
- respect GRAND's security, confidentiality and safety rules; and
- be limited to systems and processes relevant to the Service.
7.3 Costs. Customer shall bear its own costs of any audit. If an on-site audit requires material time or expense for GRAND, Customer shall reimburse GRAND's reasonable costs, unless the audit reveals a material breach of this DPA.
8. Notices and contacts
8.1 Notice contact at GRAND. All notices under this DPA (including data protection notices, sub-processor change notices, security incident notifications and data subject requests addressed to GRAND) shall be sent to mads@grandsystems.com, or to any updated contact details notified by GRAND.
8.2 Customer contact. Customer shall designate a contact point for data protection matters in the Partner Agreement or by notice to GRAND, and keep the contact details up to date.
9. Return and deletion of data
9.1 Export before deletion. Customer may request a standard export of Customer Content (including personal data) at any time during the Subscription Term and within thirty (30) days after termination of the Agreement, as set out in the MTC. GRAND shall provide the export in a commonly used machine-readable format (such as CSV or JSON) within thirty (30) days after receiving the request.
9.2 Deletion / anonymisation. GRAND shall delete or irreversibly anonymise personal data processed on behalf of Customer within thirty (30) days after the earlier of:
- providing the final export under clause 9.1; or
- the expiry of the thirty (30) day request window after termination,
subject to clause 9.3 and to the technical retention periods in backup systems described in Annex C.
9.3 Retention for legal reasons. GRAND may retain personal data beyond the periods in clause 9.2 where required by EU or Member State law (for example for bookkeeping) or where necessary to establish, exercise or defend legal claims. In such cases, GRAND shall continue to protect the data in accordance with this DPA and applicable law.
9.4 Backups. Personal data in backups will be overwritten in line with GRAND's backup rotation cycles described in Annex C and will not be restored except where necessary for security, availability or integrity reasons.
10. Allocation of responsibility and liability
10.1 Allocation of responsibilities. The Parties acknowledge that:
- GRAND is responsible for complying with its obligations as Processor/Sub-processor under this DPA and Article 28 GDPR; and
- Customer is responsible for complying with its obligations as Controller (or Processor towards its own Controller), including obtaining necessary consents or ensuring another lawful basis, providing privacy information to data subjects and configuring the Service appropriately.
10.2 Liability between the Parties. The limitations and exclusions of liability set out in clause 16 of the MTC apply also to this DPA and to any claims between the Parties arising out of or in connection with this DPA, except where such limitations are not permitted by mandatory law.
10.3 GDPR Article 82. Nothing in this DPA limits the rights of data subjects under Article 82 GDPR or the ability of a supervisory authority to impose administrative fines on either Party. Each Party is responsible for its own administrative fines, unless the Parties explicitly agree otherwise in the Agreement.
11. Order of precedence and changes
11.1 Precedence. In case of conflict between this DPA and other parts of the Agreement regarding processing of personal data, this DPA prevails.
11.2 Updates to annexes and URLs. GRAND may update the annexes and URLs referenced in this DPA (for example to reflect new Sub-processors, security measures or data categories), provided that such updates do not materially reduce the level of protection for personal data. Material changes shall be notified in advance in accordance with the MTC.
11.3 Governing law and venue. This DPA is governed by the same law and venue as the Agreement (Danish law and the City Court of Copenhagen).
Annex A: Description of processing
A.1 Data subjects
- Guests and attendees of Customer's hotels, venues and events.
- Customer's staff and administrators who use the Service.
- Where Customer is a Processor, data subjects defined by Customer's own Controller.
A.2 Categories of personal data
- Guest and attendee data (PMS data)
- Identification and contact details: name, email, phone number, nationality, date of birth, gender.
- Booking and stay details: reservation ID, check-in and check-out dates, room type, event booking details, participation status.
- Billing information: company name, VAT/EAN/EHF identifiers, invoicing address, billing email, payment reference, PO or project numbers.
- Optional structured fields: dietary needs, accessibility requirements or similar where supported by the Service as structured fields.
- Optional business metadata: department, internal reference numbers and similar.
- Address information where entered.
- Customer staff / admin data
- Identification and contact details: name, job title, work email, work phone.
- Authentication and account data: username, encrypted password, two-factor authentication data where enabled, last login timestamps.
- Configuration and preferences: language settings, role/permissions, profile photo (if uploaded).
- Usage and audit data: access logs, changes made in the system, feature usage, support tickets relating to the individual user.
- Future data categories: passport data
- For guests, where required by law or Customer processes: passport number, expiry date, issuing country, place of birth and similar identification information.
- Free-text data
- Free-text fields exist in the Service but are not intended for special category or highly sensitive data. Customer is contractually instructed not to store such data, except where strictly necessary and where the Service provides appropriate structured fields.
A.3 Special categories of data
- The Service is not designed for special category data. Customer is expressly discouraged from entering any special category data (Article 9 GDPR) or other highly sensitive information in free-text fields.
- If Customer nonetheless chooses to do so, Customer remains solely responsible for ensuring a lawful basis, compliance with Article 5 GDPR (including data minimisation), and any additional safeguards.
A.4 Nature and purpose of processing
GRAND processes personal data on behalf of Customer for the following purposes:
- providing, operating and maintaining the PMS and related modules;
- enabling Customer to manage bookings, events, guests and attendees;
- enabling billing, invoicing and payment flows;
- providing customer support, troubleshooting and incident management;
- implementing Customer's configuration of the Service (for example roles, permissions, templates);
- performing backups, disaster recovery and security monitoring;
- generating logs and audit trails needed for security and operational purposes;
- where Customer requests, performing data migration services and exports.
A.5 Processing operations
Typical processing operations include:
- collection, storage, organisation, structuring and hosting;
- consultation, retrieval and use via the PMS interfaces;
- disclosure by transmission to Sub-processors as needed to provide the Service;
- alignment or combination with other Customer Content within the same Customer environment;
- restriction, deletion and anonymisation in line with the Agreement and this DPA;
- backup and restoration (e.g. from snapshots) as necessary for availability and security.
A.6 Duration of processing
For the Subscription Term and the deletion/retention periods described in clause 9 of the DPA, subject to any longer legal retention obligations.
Annex B: Sub-processors
This annex describes GRAND's core Sub-processors as of the effective date.
| # | Sub-processor | Role / service | Hosting location(s) | Transfer mechanism (if outside EU/EEA) |
|---|---|---|---|---|
| 1 | Amazon Web Services EMEA SARL (AWS) | Primary cloud hosting provider for GRAND PMS (application servers, databases, storage, images, backups) | EU (Ireland, eu-west-1) | Not applicable (EEA) |
| 2 | Sentry | Error tracking and application monitoring (stores error logs that may include hotel/venue names and staff identifiers) | EU (Frankfurt, EU data region) | See clause 6 (no intentional transfers of Customer Content outside EU/EEA) |
| 5 | Sproom | E-invoicing / PEPPOL and EAN invoicing for public-sector and other customers | EU | Not applicable (EEA) |
GRAND may use additional Sub-processors for ancillary services (for example secure cloud storage of internal documents, ticketing systems) that may, in limited cases, contain personal data relating to Customer staff. Such providers will be listed on the live sub-processor list where relevant.
Annex C: Technical and organisational measures and transfers
C.1 General security standard
GRAND shall maintain and implement reasonable and appropriate technical and organisational measures aimed at protecting Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, in accordance with Article 32 GDPR and other applicable data protection law.
In determining such measures, GRAND is entitled to take into account:
- the state of the art and current standard practice for SaaS providers,
- the costs of implementation, and
- the nature, scope, context and purposes of the Processing and the risks of varying likelihood and severity for the rights and freedoms of natural persons.
C.2 Categories of measures
Without limiting clause C.1, GRAND's security framework includes measures in the following areas:
- Network and transmission security: protection of data in transit using industry-standard encryption (such as HTTPS/TLS or successor protocols) and secure administration interfaces.
- Access control and authentication: access to production systems limited to authorised personnel on a need-to-know basis, with role-based access controls and appropriate authentication measures for privileged accounts, and timely revocation of access when roles change.
- Logical segregation and environment management: logical separation of Customer environments in the multi-tenant platform and use of non-production or appropriately anonymised data for test and development where feasible.
- Backup, availability and recovery: regular backups of production data and documented procedures for restoring availability and access to Personal Data in a timely manner in the event of a physical or technical incident.
- Logging and monitoring: collection of technical logs and alerts to support performance monitoring, troubleshooting and security incident detection and response.
- Physical and cloud infrastructure security: reliance on reputable cloud infrastructure providers with industry-standard physical and environmental security measures for data centres.
- Organisational measures and training: internal policies on information security, access management and incident response, confidentiality obligations for staff and regular security/privacy awareness for relevant personnel.
- Data protection by design and by default: product decisions that support data minimisation, avoidance of unnecessary special category data in free-text fields and configuration options that help Customers use the Service in a privacy-friendly way.
C.3 Changes to measures
GRAND may update or modify the technical and organisational measures from time to time, provided that such updates do not result in a material reduction of the overall level of protection for Personal Data as compared to the level in place at the Effective Date of this DPA. Changes to the measures do not require an amendment to this DPA.
C.4 International transfers and supplementary measures
- As described in clause 6, Grand and its Sub-processors process Customer personal data for the Service only in the EU/EEA as of the Effective Date.
- If Grand at any time intends to process Customer personal data in or from a third country without an adequacy decision, Grand shall ensure that an appropriate transfer mechanism under Chapter V GDPR is in place (such as the EU Standard Contractual Clauses), supplemented where necessary by additional technical and/or organisational safeguards.
- Grand shall perform and document transfer assessments where required by law and will take into account the nature of the data, the services provided, the legal environment of the third country and any relevant guidance from supervisory authorities.
1. Roles, subject matter and duration
1.1 Roles.
- Where Customer is the hotel / venue (or a similar organisation using GRAND PMS to manage its own operations), Customer is the Controller and GRAND is the Processor for personal data processed in the Service on Customer's instructions (for example guest and attendee data).
- Where Customer itself acts as a Processor for its own client (for example a management company acting for a hotel chain), GRAND acts as Customer's Sub-processor. In that scenario, references in this DPA to "Controller" mean Customer's client, and Customer remains responsible for passing down the Controller's instructions to GRAND.
- GRAND is an independent Controller for its own business and relationship data, including sales and marketing data, contracting and billing, telemetry, security logging, analytics, fraud and abuse prevention and similar purposes. Those Controller-lane activities are not governed by this DPA and will be described in GRAND's privacy notice.
1.2 Subject matter. The subject matter of this DPA is GRAND's processing of personal data as Processor or Sub-processor on behalf of Customer in connection with providing the Service.
1.3 Duration. This DPA applies for as long as GRAND processes personal data on behalf of Customer under the Agreement and continues until deletion or anonymisation of such data in accordance with clause 9.
1.4 Description of processing. The nature, purpose, categories of data and data subjects and processing operations are described in Annex A.
2. Instructions and processing on behalf of Customer
2.1 Documented instructions. GRAND shall process personal data only on documented instructions from Customer, including with respect to transfers of personal data to a third country, unless required to do so by EU or Member State law to which GRAND is subject. In such a case, GRAND shall inform Customer of that legal requirement before processing, unless the law prohibits such information.
2.2 Agreement and configuration as instructions. The Agreement, this DPA, and Customer's normal use and configuration of the Service (including through APIs and integrations that Customer enables) constitute Customer's documented instructions.
2.3 Notification of unlawful instructions. If GRAND considers that an instruction from Customer infringes the GDPR or other EU/Member State data protection law, GRAND shall promptly inform Customer and may suspend the relevant processing until the instruction is clarified or changed.
2.4 Restrictions on special category data. The Service is not designed to store special categories of personal data (for example detailed health data, religious or political information) or other highly sensitive data. Customer must not use free-text fields for such data and must only use structured fields where strictly necessary (for example for simple accessibility needs) and where Customer has an appropriate legal basis. This restriction is part of Customer's instructions to GRAND.
3. GRAND's obligations as Processor / Sub-processor
3.1 Confidentiality. GRAND shall ensure that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
3.2 Security measures. GRAND shall implement and maintain appropriate technical and organisational measures to protect personal data, taking into account the nature, scope, context and purposes of processing and the risks to data subjects. A description of GRAND's baseline security measures is set out in Annex C and may be updated from time to time without reducing the overall level of protection.
3.3 Sub-processors.
- Customer authorises GRAND to engage Sub-processors to provide the Service, as listed in Annex B.
- GRAND shall impose on each Sub-processor data protection obligations that are at least as protective as those in this DPA, including appropriate security measures.
- GRAND remains responsible to Customer for the performance of its Sub-processors.
3.4 Assistance with data subject rights. Taking into account the nature of the processing, GRAND shall assist Customer, by appropriate technical and organisational measures, in fulfilling Customer's obligations to respond to requests from data subjects under Chapter III of the GDPR, to the extent such requests relate to personal data in the Service.
3.5 Assistance with security and DPIA. GRAND shall, upon Customer's request and taking into account the nature of processing and the information available to GRAND, provide reasonable assistance to Customer in relation to:
- security of processing;
- notification of personal data breaches to supervisory authorities and communication of such breaches to data subjects; and
- where required, data protection impact assessments and prior consultations with supervisory authorities.
3.6 Data breach notification. GRAND shall notify Customer without undue delay after becoming aware of a personal data breach affecting personal data processed on behalf of Customer. The notification shall at least:
- describe the nature of the breach, including, where possible, the categories and approximate number of data subjects and data records concerned;
- describe the likely consequences of the breach; and
- describe the measures taken or proposed to address the breach and mitigate its possible adverse effects.
GRAND may provide information in phases as it becomes available. Customer remains responsible for any required notifications to authorities or data subjects, unless the Parties agree otherwise in writing.
3.7 Records of processing. GRAND shall maintain records of processing activities carried out on behalf of Customer as required by Article 30(2) GDPR and make them available to Customer upon request, to the extent necessary to demonstrate compliance.
3.8 No sale or unrelated use. GRAND shall not sell personal data or use it for purposes other than providing the Service, fulfilling its legal obligations, or its own independent Controller purposes described in its privacy notice.
4. Customer's obligations
4.1 Controller responsibilities. Customer is responsible for complying with its obligations as Controller (or as Processor vis-à-vis its own Controller) under applicable data protection law, including:
- ensuring that it has a valid legal basis for the processing of personal data in the Service;
- providing appropriate privacy notices to data subjects;
- configuring the Service in a way that supports compliance (for example retention settings, access permissions); and
- avoiding the entry of unnecessary special category data or other sensitive data.
4.2 Accuracy, minimisation and retention. Customer is responsible for the accuracy of personal data and for defining and implementing appropriate retention periods in the Service that align with Customer's legal obligations and policies.
4.3 Instructions. Customer shall provide instructions that are lawful, documented and compatible with the functionality and technical limitations of the Service.
4.4 Informing data subjects. Where required by law, Customer shall inform data subjects that their personal data is processed in GRAND PMS and that it may be transferred to GRAND and its Sub-processors as described in this DPA and the MTC.
5. Sub-processors and changes
5.1 Current Sub-processors. The Sub-processors engaged by GRAND as of the effective date are listed in Annex B.
5.2 Additions and replacements. GRAND may add or replace Sub-processors provided that:
- GRAND updates the live sub-processor list; and
- GRAND gives Customer at least thirty (30) days' prior notice, for example by email to the notice contact in clause 8.1 or via the Service.
5.3 Right to object. Customer may object in writing to a new Sub-processor on reasonable grounds relating to data protection within the notice period. If Customer objects, the Parties shall work together in good faith to find a reasonable solution. If no solution is found within thirty (30) days, Customer may terminate the affected part of the Service (or, if no separation is technically feasible, the Agreement) with effect from the date the new Sub-processor is scheduled to start, without penalty. This is Customer's sole remedy for objections to Sub-processors.
6. International transfers
6.1 EU/EEA processing only. As of the Effective Date, Grand and its Sub-processors process Customer personal data for the Service only in the EU/EEA. Grand will not intentionally transfer Customer personal data (including PMS guest and admin data) to a country outside the EU/EEA in connection with the Service, unless: (a) Customer explicitly enables an integration or data flow that requires such a transfer; or (b) the Parties agree otherwise in writing.
6.2 Transfers to third countries. Should GRAND intend to engage a Sub-processor or introduce any data flow that results in Customer Personal Data being processed in or from a third country, GRAND shall (a) ensure appropriate safeguards under Chapter V GDPR (such as in relation to Standard Contractual Clauses, supplemented, where necessary, by additional technical and organisational measures); and (b) update this DPA and the Sub-processor list before such processing starts, giving Customer the right to object under clause 5.3.
6.3 Customer-configured integrations. Where Customer connects the Service to third-party systems under Customer's own control (for example by connecting its own payment provider or marketing tools), Customer is responsible for ensuring that any resulting transfers outside the EU/EEA comply with applicable law. In such cases, GRAND's role is limited to executing Customer's configuration.
7. Audits and information
7.1 Information and reports. GRAND shall make available to Customer all information reasonably necessary to demonstrate compliance with this DPA, for example security summaries, audit reports or certifications, subject to confidentiality.
7.2 Audit right. Customer (or its independent auditor bound by confidentiality) may, no more than once per year and with at least thirty (30) days' prior written notice, carry out a reasonable audit of GRAND's compliance with this DPA, to the extent such audit cannot reasonably be satisfied by the information provided under clause 7.1. Audits shall:
- be conducted during normal business hours and in a manner that minimises disruption;
- respect GRAND's security, confidentiality and safety rules; and
- be limited to systems and processes relevant to the Service.
7.3 Costs. Customer shall bear its own costs of any audit. If an on-site audit requires material time or expense for GRAND, Customer shall reimburse GRAND's reasonable costs, unless the audit reveals a material breach of this DPA.
8. Notices and contacts
8.1 Notice contact at GRAND. All notices under this DPA (including data protection notices, sub-processor change notices, security incident notifications and data subject requests addressed to GRAND) shall be sent to mads@grandsystems.com, or to any updated contact details notified by GRAND.
8.2 Customer contact. Customer shall designate a contact point for data protection matters in the Partner Agreement or by notice to GRAND, and keep the contact details up to date.
9. Return and deletion of data
9.1 Export before deletion. Customer may request a standard export of Customer Content (including personal data) at any time during the Subscription Term and within thirty (30) days after termination of the Agreement, as set out in the MTC. GRAND shall provide the export in a commonly used machine-readable format (such as CSV or JSON) within thirty (30) days after receiving the request.
9.2 Deletion / anonymisation. GRAND shall delete or irreversibly anonymise personal data processed on behalf of Customer within thirty (30) days after the earlier of:
- providing the final export under clause 9.1; or
- the expiry of the thirty (30) day request window after termination,
subject to clause 9.3 and to the technical retention periods in backup systems described in Annex C.
9.3 Retention for legal reasons. GRAND may retain personal data beyond the periods in clause 9.2 where required by EU or Member State law (for example for bookkeeping) or where necessary to establish, exercise or defend legal claims. In such cases, GRAND shall continue to protect the data in accordance with this DPA and applicable law.
9.4 Backups. Personal data in backups will be overwritten in line with GRAND's backup rotation cycles described in Annex C and will not be restored except where necessary for security, availability or integrity reasons.
10. Allocation of responsibility and liability
10.1 Allocation of responsibilities. The Parties acknowledge that:
- GRAND is responsible for complying with its obligations as Processor/Sub-processor under this DPA and Article 28 GDPR; and
- Customer is responsible for complying with its obligations as Controller (or Processor towards its own Controller), including obtaining necessary consents or ensuring another lawful basis, providing privacy information to data subjects and configuring the Service appropriately.
10.2 Liability between the Parties. The limitations and exclusions of liability set out in clause 16 of the MTC apply also to this DPA and to any claims between the Parties arising out of or in connection with this DPA, except where such limitations are not permitted by mandatory law.
10.3 GDPR Article 82. Nothing in this DPA limits the rights of data subjects under Article 82 GDPR or the ability of a supervisory authority to impose administrative fines on either Party. Each Party is responsible for its own administrative fines, unless the Parties explicitly agree otherwise in the Agreement.
11. Order of precedence and changes
11.1 Precedence. In case of conflict between this DPA and other parts of the Agreement regarding processing of personal data, this DPA prevails.
11.2 Updates to annexes and URLs. GRAND may update the annexes and URLs referenced in this DPA (for example to reflect new Sub-processors, security measures or data categories), provided that such updates do not materially reduce the level of protection for personal data. Material changes shall be notified in advance in accordance with the MTC.
11.3 Governing law and venue. This DPA is governed by the same law and venue as the Agreement (Danish law and the City Court of Copenhagen).
Annex A: Description of processing
A.1 Data subjects
- Guests and attendees of Customer's hotels, venues and events.
- Customer's staff and administrators who use the Service.
- Where Customer is a Processor, data subjects defined by Customer's own Controller.
A.2 Categories of personal data
- Guest and attendee data (PMS data)
- Identification and contact details: name, email, phone number, nationality, date of birth, gender.
- Booking and stay details: reservation ID, check-in and check-out dates, room type, event booking details, participation status.
- Billing information: company name, VAT/EAN/EHF identifiers, invoicing address, billing email, payment reference, PO or project numbers.
- Optional structured fields: dietary needs, accessibility requirements or similar where supported by the Service as structured fields.
- Optional business metadata: department, internal reference numbers and similar.
- Address information where entered.
- Customer staff / admin data
- Identification and contact details: name, job title, work email, work phone.
- Authentication and account data: username, encrypted password, two-factor authentication data where enabled, last login timestamps.
- Configuration and preferences: language settings, role/permissions, profile photo (if uploaded).
- Usage and audit data: access logs, changes made in the system, feature usage, support tickets relating to the individual user.
- Future data categories: passport data
- For guests, where required by law or Customer processes: passport number, expiry date, issuing country, place of birth and similar identification information.
- Free-text data
- Free-text fields exist in the Service but are not intended for special category or highly sensitive data. Customer is contractually instructed not to store such data, except where strictly necessary and where the Service provides appropriate structured fields.
A.3 Special categories of data
- The Service is not designed for special category data. Customer is expressly discouraged from entering any special category data (Article 9 GDPR) or other highly sensitive information in free-text fields.
- If Customer nonetheless chooses to do so, Customer remains solely responsible for ensuring a lawful basis, compliance with Article 5 GDPR (including data minimisation), and any additional safeguards.
A.4 Nature and purpose of processing
GRAND processes personal data on behalf of Customer for the following purposes:
- providing, operating and maintaining the PMS and related modules;
- enabling Customer to manage bookings, events, guests and attendees;
- enabling billing, invoicing and payment flows;
- providing customer support, troubleshooting and incident management;
- implementing Customer's configuration of the Service (for example roles, permissions, templates);
- performing backups, disaster recovery and security monitoring;
- generating logs and audit trails needed for security and operational purposes;
- where Customer requests, performing data migration services and exports.
A.5 Processing operations
Typical processing operations include:
- collection, storage, organisation, structuring and hosting;
- consultation, retrieval and use via the PMS interfaces;
- disclosure by transmission to Sub-processors as needed to provide the Service;
- alignment or combination with other Customer Content within the same Customer environment;
- restriction, deletion and anonymisation in line with the Agreement and this DPA;
- backup and restoration (e.g. from snapshots) as necessary for availability and security.
A.6 Duration of processing
For the Subscription Term and the deletion/retention periods described in clause 9 of the DPA, subject to any longer legal retention obligations.
Annex B: Sub-processors
This annex describes GRAND's core Sub-processors as of the effective date.
| # | Sub-processor | Role / service | Hosting location(s) | Transfer mechanism (if outside EU/EEA) |
|---|---|---|---|---|
| 1 | Amazon Web Services EMEA SARL (AWS) | Primary cloud hosting provider for GRAND PMS (application servers, databases, storage, images, backups) | EU (Ireland, eu-west-1) | Not applicable (EEA) |
| 2 | Sentry | Error tracking and application monitoring (stores error logs that may include hotel/venue names and staff identifiers) | EU (Frankfurt, EU data region) | See clause 6 (no intentional transfers of Customer Content outside EU/EEA) |
| 5 | Sproom | E-invoicing / PEPPOL and EAN invoicing for public-sector and other customers | EU | Not applicable (EEA) |
GRAND may use additional Sub-processors for ancillary services (for example secure cloud storage of internal documents, ticketing systems) that may, in limited cases, contain personal data relating to Customer staff. Such providers will be listed on the live sub-processor list where relevant.
Annex C: Technical and organisational measures and transfers
C.1 General security standard
GRAND shall maintain and implement reasonable and appropriate technical and organisational measures aimed at protecting Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, in accordance with Article 32 GDPR and other applicable data protection law.
In determining such measures, GRAND is entitled to take into account:
- the state of the art and current standard practice for SaaS providers,
- the costs of implementation, and
- the nature, scope, context and purposes of the Processing and the risks of varying likelihood and severity for the rights and freedoms of natural persons.
C.2 Categories of measures
Without limiting clause C.1, GRAND's security framework includes measures in the following areas:
- Network and transmission security: protection of data in transit using industry-standard encryption (such as HTTPS/TLS or successor protocols) and secure administration interfaces.
- Access control and authentication: access to production systems limited to authorised personnel on a need-to-know basis, with role-based access controls and appropriate authentication measures for privileged accounts, and timely revocation of access when roles change.
- Logical segregation and environment management: logical separation of Customer environments in the multi-tenant platform and use of non-production or appropriately anonymised data for test and development where feasible.
- Backup, availability and recovery: regular backups of production data and documented procedures for restoring availability and access to Personal Data in a timely manner in the event of a physical or technical incident.
- Logging and monitoring: collection of technical logs and alerts to support performance monitoring, troubleshooting and security incident detection and response.
- Physical and cloud infrastructure security: reliance on reputable cloud infrastructure providers with industry-standard physical and environmental security measures for data centres.
- Organisational measures and training: internal policies on information security, access management and incident response, confidentiality obligations for staff and regular security/privacy awareness for relevant personnel.
- Data protection by design and by default: product decisions that support data minimisation, avoidance of unnecessary special category data in free-text fields and configuration options that help Customers use the Service in a privacy-friendly way.
C.3 Changes to measures
GRAND may update or modify the technical and organisational measures from time to time, provided that such updates do not result in a material reduction of the overall level of protection for Personal Data as compared to the level in place at the Effective Date of this DPA. Changes to the measures do not require an amendment to this DPA.
C.4 International transfers and supplementary measures
- As described in clause 6, Grand and its Sub-processors process Customer personal data for the Service only in the EU/EEA as of the Effective Date.
- If Grand at any time intends to process Customer personal data in or from a third country without an adequacy decision, Grand shall ensure that an appropriate transfer mechanism under Chapter V GDPR is in place (such as the EU Standard Contractual Clauses), supplemented where necessary by additional technical and/or organisational safeguards.
- Grand shall perform and document transfer assessments where required by law and will take into account the nature of the data, the services provided, the legal environment of the third country and any relevant guidance from supervisory authorities.
Get a glimpse of the future
We help you do more across all hospitality operations, delivering excellence in every guest interaction.
Book a demo