Data Processing Agreement

Last updated 21 August 2026.

This Data Processing Agreement (the “DPA”) forms part of the agreement governing the customer’s use of Salisea (the “Agreement”). It applies when Samir Caus, trading as SaliSea, at c/o POSTFLEX PFX-744-129, Emsdettener Straße 10, 48268 Greven, Germany (“Salisea”), processes Customer Personal Data on behalf of the customer.

By entering into the Agreement, the customer enters into this DPA on its own behalf and, where applicable, on behalf of the controllers it is authorized to represent. Capitalized terms not defined here have the meanings given in the Agreement or applicable Data Protection Law.

1. Definitions and roles

“Customer Personal Data” means personal data submitted to, stored in, sent through, or otherwise processed by Salisea on the customer’s behalf in connection with the service.

“Data Protection Law” means the GDPR and other data protection law applicable to the processing under the Agreement.

The customer is the controller and Salisea is the processor of Customer Personal Data. If the customer processes data for another controller, the customer is a processor and Salisea is its subprocessor. Each party will comply with the obligations applicable to its role.

Salisea remains a separate controller for personal data it processes for its own purposes, including account administration, security, service communications, and the establishment or defence of legal claims, as described in the Privacy policy.

2. Customer instructions

Salisea will process Customer Personal Data only:

  • to provide, secure, maintain, and support the service under the Agreement;
  • through features, settings, integrations, and actions configured or initiated by the customer or its authorized users;
  • as further documented in this DPA or another written instruction agreed by the parties; or
  • where Union or Member State law requires processing, in which case Salisea will inform the customer before processing unless the law prohibits that notice.

The customer instructs Salisea to make the transfers and engage the subprocessors described in this DPA. Salisea will promptly inform the customer if, in its opinion, an instruction infringes Data Protection Law. Salisea may suspend the affected processing while the parties resolve the issue.

The customer is responsible for the lawfulness, accuracy, and scope of its instructions and Customer Personal Data, including providing required notices and establishing a valid legal basis.

3. Processing details

The subject matter, nature, purpose, duration, data subjects, and categories of personal data are described in Annex 1.

Processing continues for the term of the Agreement and the deletion period described in section 10, unless Data Protection Law requires otherwise.

4. Confidentiality and access

Salisea will ensure that persons authorized to process Customer Personal Data are bound by confidentiality and access the data only as necessary for their duties. Salisea will apply role-based and least-privilege access where supported by the service.

5. Security

Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, Salisea will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The current measures are described in Annex 2.

The customer is responsible for securely configuring its accounts, permissions, forwarding rules, integrations, and devices, and for keeping its own legally required records and backups.

6. Subprocessors

The customer gives Salisea general authorization to use the subprocessors listed in Annex 3 and to appoint replacements or additional subprocessors.

Salisea will impose data protection obligations on each subprocessor that are no less protective in substance than the obligations applicable to Salisea under this DPA, to the extent relevant to the subprocessor’s services. Salisea remains responsible to the customer for the performance of those obligations.

Salisea will give the customer at least 15 days’ notice before a new subprocessor begins processing Customer Personal Data, normally by email or an in-service notice. The customer may object during that period on reasonable data protection grounds. The parties will work in good faith on a commercially reasonable solution. If none is available, the customer may discontinue the affected feature or terminate the affected service without penalty before the new subprocessor begins processing.

User-directed integrations are enabled by the customer. Where an integration provider processes data directly for the customer under the customer’s account or instructions, that provider may act as the customer’s independent processor rather than Salisea’s subprocessor.

7. International transfers

Salisea may process Customer Personal Data in the European Economic Area and wherever an authorized subprocessor operates. Salisea will ensure that a transfer subject to Chapter V GDPR relies on a lawful transfer mechanism.

Where an adequacy decision applies, the transfer may rely on that decision, including the EU–US Data Privacy Framework where applicable. Where no adequacy decision applies, Salisea will use the European Commission’s Standard Contractual Clauses or another lawful safeguard and will implement supplementary measures where required by Data Protection Law.

If Customer Personal Data is transferred by the customer in the EEA to Salisea in a country not recognized as adequate and no other lawful mechanism applies, the controller-to-processor module of the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 is incorporated into this DPA. The information in this DPA and its annexes completes the relevant annexes to those clauses. The optional docking clause applies; the optional independent-dispute-resolution language does not apply; and the competent supervisory authority and governing Member State law are determined under clauses 13 and 17 of the Standard Contractual Clauses.

8. Assistance and rights requests

Taking into account the nature of processing and the information available to it, Salisea will provide reasonable assistance with:

  • requests by data subjects to exercise their rights;
  • security, breach notification, data protection impact assessments, and prior consultation obligations under Articles 32–36 GDPR; and
  • information reasonably needed to demonstrate compliance with Article 28 GDPR.

If Salisea receives a request from a data subject concerning Customer Personal Data, it will direct the person to the customer and will not respond on the customer’s behalf unless instructed or legally required. The customer remains responsible for responding to the request.

9. Personal data breaches

Salisea will notify the customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notice will include the information reasonably available to Salisea that the customer needs to meet its notification obligations. Salisea may provide information in phases and will take reasonable steps to contain, investigate, and mitigate the breach.

A notice under this section is not an admission of fault or liability.

10. Return and deletion

During the term, the customer may retrieve Customer Personal Data through available service features. The customer should export data it wishes to retain before closing the account.

After termination, Salisea will delete or anonymize account data within 30 days and Customer Personal Data in the workspace within 90 days, unless the customer requests earlier deletion where technically available or Union or Member State law requires retention. Original email files and attachments are deleted no later than 90 days after receipt.

Salisea does not promise a backup archive. Data remaining temporarily in deletion queues or storage systems will be isolated from ordinary use and deleted according to the applicable deletion cycle.

11. Audits

On written request, Salisea will provide information reasonably necessary to demonstrate compliance with this DPA, including relevant third-party audit reports or certifications available to it.

If that information is insufficient, the customer may conduct one audit in any 12-month period, and additional audits where required by a supervisory authority or following a substantiated personal data breach. Audits must be conducted on reasonable advance notice, during normal business hours, by a qualified independent auditor bound by confidentiality, and without unreasonable disruption or access to another customer’s data. The customer bears its audit costs unless the audit identifies a material breach by Salisea.

12. General terms

If this DPA conflicts with the Agreement on the processing of Customer Personal Data, this DPA prevails. The Standard Contractual Clauses prevail over both where they apply and conflict.

Liability arising from this DPA is subject to the liability provisions of the Agreement to the extent permitted by Data Protection Law. Changes to this DPA will follow the change process in the Agreement, except that Salisea may make changes required by Data Protection Law or changes that do not materially reduce protection for Customer Personal Data.

Questions about this DPA may be sent to privacy@salisea.com.

Annex 1: Details of processing

Subject matter and purpose: Providing the Salisea accommodation-management service, including property and unit administration, availability and calendar workflows, inquiry intake, email routing, bookings, guest communications, operational workflows, optional notifications and integrations, and optional AI-assisted extraction, language detection, translation, and reply drafting.

Nature of processing: Collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, transmission, alignment, restriction, deletion, and other processing initiated through the service.

Duration: The term of the Agreement plus the deletion periods in section 10.

Data subjects: The customer’s owners, staff, contractors, and authorized users; prospective, current, and former guests; inquiry senders and message recipients; property contacts, service providers, and other persons whose data the customer submits.

Personal data: Names, contact details, authentication and account identifiers, roles and permissions, inquiry and message content, stay dates, party composition, booking and property information, availability, calendar records, payment-request and transaction-reference information, communication history, email headers and routing data, technical and security data, integration identifiers, AI inputs and results, review actions, and support information.

Sensitive data: The service is not intended for special-category data, criminal-conviction data, identity documents, or payment-card data. The customer must not submit such data unless a specific Salisea feature expressly requests it and the parties have confirmed appropriate safeguards.

Frequency: Continuous or as initiated by the customer and its authorized users during the term.

Annex 2: Technical and organizational measures

  • encrypted transport using HTTPS/TLS;
  • password hashing and secure, HTTP-only session cookies;
  • tenant-scoped authorization, role checks, scoped integration permissions, and short-lived access tokens where applicable;
  • CSRF protection, validation, rate limiting, and controls intended to prevent unauthorized or cross-workspace access;
  • restricted production credentials and environment-bound secrets;
  • logging and audit records for security-relevant and user-authorized actions;
  • retention timestamps and automated deletion for original email files and attachments;
  • human review before AI-generated replies are sent or booking-affecting actions are taken;
  • security and dependency updates, incident investigation, and access removal when no longer required; and
  • logical separation of customer workspaces within the shared service infrastructure.

Annex 3: Authorized subprocessors

SubprocessorService and processingProcessing location
Cloudflare, Inc. and its affiliatesHosting, content delivery, security, Workers, D1, R2, KV, Queues, Email Routing and Email Service, operational logs, and optional Workers AICloudflare’s global network and service locations under its applicable data processing terms
Google LLC and its affiliatesOptional Google authentication and Google Places address searchLocations described in Google’s applicable service and data processing terms
Telegram Messenger Inc. and relevant affiliatesOptional owner notifications initiated when the customer connects the Salisea botLocations described in Telegram’s applicable terms and privacy documentation