Last updated 21 August 2026.
This Data Processing Agreement (the “DPA”) forms part of the agreement governing the customer’s use of Salisea (the “Agreement”). It applies when Samir Caus, trading as SaliSea, at c/o POSTFLEX PFX-744-129, Emsdettener Straße 10, 48268 Greven, Germany (“Salisea”), processes Customer Personal Data on behalf of the customer.
By entering into the Agreement, the customer enters into this DPA on its own behalf and, where applicable, on behalf of the controllers it is authorized to represent. Capitalized terms not defined here have the meanings given in the Agreement or applicable Data Protection Law.
“Customer Personal Data” means personal data submitted to, stored in, sent through, or otherwise processed by Salisea on the customer’s behalf in connection with the service.
“Data Protection Law” means the GDPR and other data protection law applicable to the processing under the Agreement.
The customer is the controller and Salisea is the processor of Customer Personal Data. If the customer processes data for another controller, the customer is a processor and Salisea is its subprocessor. Each party will comply with the obligations applicable to its role.
Salisea remains a separate controller for personal data it processes for its own purposes, including account administration, security, service communications, and the establishment or defence of legal claims, as described in the Privacy policy.
Salisea will process Customer Personal Data only:
The customer instructs Salisea to make the transfers and engage the subprocessors described in this DPA. Salisea will promptly inform the customer if, in its opinion, an instruction infringes Data Protection Law. Salisea may suspend the affected processing while the parties resolve the issue.
The customer is responsible for the lawfulness, accuracy, and scope of its instructions and Customer Personal Data, including providing required notices and establishing a valid legal basis.
The subject matter, nature, purpose, duration, data subjects, and categories of personal data are described in Annex 1.
Processing continues for the term of the Agreement and the deletion period described in section 10, unless Data Protection Law requires otherwise.
Salisea will ensure that persons authorized to process Customer Personal Data are bound by confidentiality and access the data only as necessary for their duties. Salisea will apply role-based and least-privilege access where supported by the service.
Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, Salisea will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The current measures are described in Annex 2.
The customer is responsible for securely configuring its accounts, permissions, forwarding rules, integrations, and devices, and for keeping its own legally required records and backups.
The customer gives Salisea general authorization to use the subprocessors listed in Annex 3 and to appoint replacements or additional subprocessors.
Salisea will impose data protection obligations on each subprocessor that are no less protective in substance than the obligations applicable to Salisea under this DPA, to the extent relevant to the subprocessor’s services. Salisea remains responsible to the customer for the performance of those obligations.
Salisea will give the customer at least 15 days’ notice before a new subprocessor begins processing Customer Personal Data, normally by email or an in-service notice. The customer may object during that period on reasonable data protection grounds. The parties will work in good faith on a commercially reasonable solution. If none is available, the customer may discontinue the affected feature or terminate the affected service without penalty before the new subprocessor begins processing.
User-directed integrations are enabled by the customer. Where an integration provider processes data directly for the customer under the customer’s account or instructions, that provider may act as the customer’s independent processor rather than Salisea’s subprocessor.
Salisea may process Customer Personal Data in the European Economic Area and wherever an authorized subprocessor operates. Salisea will ensure that a transfer subject to Chapter V GDPR relies on a lawful transfer mechanism.
Where an adequacy decision applies, the transfer may rely on that decision, including the EU–US Data Privacy Framework where applicable. Where no adequacy decision applies, Salisea will use the European Commission’s Standard Contractual Clauses or another lawful safeguard and will implement supplementary measures where required by Data Protection Law.
If Customer Personal Data is transferred by the customer in the EEA to Salisea in a country not recognized as adequate and no other lawful mechanism applies, the controller-to-processor module of the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 is incorporated into this DPA. The information in this DPA and its annexes completes the relevant annexes to those clauses. The optional docking clause applies; the optional independent-dispute-resolution language does not apply; and the competent supervisory authority and governing Member State law are determined under clauses 13 and 17 of the Standard Contractual Clauses.
Taking into account the nature of processing and the information available to it, Salisea will provide reasonable assistance with:
If Salisea receives a request from a data subject concerning Customer Personal Data, it will direct the person to the customer and will not respond on the customer’s behalf unless instructed or legally required. The customer remains responsible for responding to the request.
Salisea will notify the customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notice will include the information reasonably available to Salisea that the customer needs to meet its notification obligations. Salisea may provide information in phases and will take reasonable steps to contain, investigate, and mitigate the breach.
A notice under this section is not an admission of fault or liability.
During the term, the customer may retrieve Customer Personal Data through available service features. The customer should export data it wishes to retain before closing the account.
After termination, Salisea will delete or anonymize account data within 30 days and Customer Personal Data in the workspace within 90 days, unless the customer requests earlier deletion where technically available or Union or Member State law requires retention. Original email files and attachments are deleted no later than 90 days after receipt.
Salisea does not promise a backup archive. Data remaining temporarily in deletion queues or storage systems will be isolated from ordinary use and deleted according to the applicable deletion cycle.
On written request, Salisea will provide information reasonably necessary to demonstrate compliance with this DPA, including relevant third-party audit reports or certifications available to it.
If that information is insufficient, the customer may conduct one audit in any 12-month period, and additional audits where required by a supervisory authority or following a substantiated personal data breach. Audits must be conducted on reasonable advance notice, during normal business hours, by a qualified independent auditor bound by confidentiality, and without unreasonable disruption or access to another customer’s data. The customer bears its audit costs unless the audit identifies a material breach by Salisea.
If this DPA conflicts with the Agreement on the processing of Customer Personal Data, this DPA prevails. The Standard Contractual Clauses prevail over both where they apply and conflict.
Liability arising from this DPA is subject to the liability provisions of the Agreement to the extent permitted by Data Protection Law. Changes to this DPA will follow the change process in the Agreement, except that Salisea may make changes required by Data Protection Law or changes that do not materially reduce protection for Customer Personal Data.
Questions about this DPA may be sent to privacy@salisea.com.
Subject matter and purpose: Providing the Salisea accommodation-management service, including property and unit administration, availability and calendar workflows, inquiry intake, email routing, bookings, guest communications, operational workflows, optional notifications and integrations, and optional AI-assisted extraction, language detection, translation, and reply drafting.
Nature of processing: Collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, transmission, alignment, restriction, deletion, and other processing initiated through the service.
Duration: The term of the Agreement plus the deletion periods in section 10.
Data subjects: The customer’s owners, staff, contractors, and authorized users; prospective, current, and former guests; inquiry senders and message recipients; property contacts, service providers, and other persons whose data the customer submits.
Personal data: Names, contact details, authentication and account identifiers, roles and permissions, inquiry and message content, stay dates, party composition, booking and property information, availability, calendar records, payment-request and transaction-reference information, communication history, email headers and routing data, technical and security data, integration identifiers, AI inputs and results, review actions, and support information.
Sensitive data: The service is not intended for special-category data, criminal-conviction data, identity documents, or payment-card data. The customer must not submit such data unless a specific Salisea feature expressly requests it and the parties have confirmed appropriate safeguards.
Frequency: Continuous or as initiated by the customer and its authorized users during the term.
| Subprocessor | Service and processing | Processing location |
|---|---|---|
| Cloudflare, Inc. and its affiliates | Hosting, content delivery, security, Workers, D1, R2, KV, Queues, Email Routing and Email Service, operational logs, and optional Workers AI | Cloudflare’s global network and service locations under its applicable data processing terms |
| Google LLC and its affiliates | Optional Google authentication and Google Places address search | Locations described in Google’s applicable service and data processing terms |
| Telegram Messenger Inc. and relevant affiliates | Optional owner notifications initiated when the customer connects the Salisea bot | Locations described in Telegram’s applicable terms and privacy documentation |