BookNLink

Data Processing Agreement (Auftragsverarbeitungsvertrag)

This DPA governs the processing of personal data by BookNLink GmbH (Processor) on behalf of the customer (Controller) in connection with the BookNLink connectors and modules. It complies with Article 28 GDPR and § 62 BDSG.

1. Subject and duration

The Processor processes personal data on behalf of the Controller for the sole purpose of providing the modules listed in the order form. The DPA runs for the duration of the underlying service contract.

2. Nature and purpose of processing

Processing consists in the automated ingestion, normalisation, distribution and reconciliation of hotel-inventory-related data through the official BookNLink API. The purpose is the technical operation of the modules ordered by the Controller.

3. Categories of data subjects and data

Categories of data subjects: hotel guests, hotel staff, corporate customers of the Controller. Categories of data: contact data, reservation data, transaction identifiers, technical log data.

4. Technical and organisational measures

The Processor implements the TOMs described in Annex 1 (available on request), including: TLS 1.2+ in transit; encryption at rest; role-based access; two-factor authentication for production; ninety-day journalling; encrypted off-site backups in a second EU data centre.

5. Sub-processors

The Processor may engage the following sub-processors: EU-based cloud hosting provider (Hetzner Cloud, Germany); transactional email (Postmark, EU region); payment (Stripe Payments Europe Ltd, Ireland). New sub-processors are notified with at least thirty days notice; the Controller may object in text form within that period.

6. International transfers

No transfers outside the EEA occur under this DPA. Should a transfer become necessary, it will be based on an adequacy decision (Art. 45 GDPR) or on the EU Standard Contractual Clauses (Art. 46 GDPR).

7. Support for data-subject rights

The Processor supports the Controller in fulfilling data-subject requests (Art. 15–22 GDPR) within reasonable time and at no additional cost for standard requests.

8. Notification of personal-data breaches

The Processor notifies the Controller of any personal-data breach without undue delay, at the latest within 72 hours of becoming aware, providing the information listed in Art. 33 (3) GDPR.

9. Deletion or return

Upon termination of the underlying service contract, the Processor deletes all personal data processed on behalf of the Controller within thirty days, unless a statutory retention obligation applies.

10. Audit rights

The Controller may audit the Processor's compliance with this DPA once per calendar year, with thirty days notice, during business hours, at the Processor's premises in Berlin, and subject to reasonable confidentiality obligations.

11. Governing law and venue

German law applies. Exclusive venue is Berlin.

Annex 1 — Technical and organisational measures

Available on request in a separate document. Categories covered: confidentiality, integrity, availability and resilience, procedure for regular testing and evaluation.

Sign this DPA

Email dpo@booknlink.org with subject "DPA request" — we return a countersigned PDF within two business days.

Updated 17 August 2026 · BookNLink GmbH · Berlin