Data Processing Agreement · GDPR Art. 28

Data Processing Agreement.

Standard Data Processing Agreement between Rmsclaud Retail d.o.o. (Processor) and the customer (Controller), aligned with GDPR Article 28 and the Montenegro Personal Data Protection Act.

01 · Subject matter

Subject matter of the processing

Rmsclaud processes personal data on behalf of the Customer for the sole purpose of operating the Rmsclaud modules the Customer has activated. The scope is limited to the reservation and rate data accessible under the OAuth token granted from the Customer’s SiteMinder login.

02 · Duration

Duration

The Agreement is effective for the duration of any active Rmsclaud module subscription, plus 30 days for data return / deletion.

03 · Nature and purpose

Nature and purpose

  • Reading of reservation, rate, and availability data via the SiteMinder API
  • Writing of rate changes, notes, or availability updates as required by the specific module
  • Storage of scoped OAuth tokens
  • Aggregation for reporting and analytics
04 · Sub-processors

Sub-processors

  • Hetzner Online GmbH — hosting (Frankfurt)
  • OVHcloud SAS — failover hosting (Warsaw)
  • Backblaze Inc. — encrypted backup (Helsinki EU cluster)
  • Stripe Payments Europe Ltd — payments (Dublin)
  • Mailjet SAS — email delivery (Paris)

Sub-processor changes announced 30 days in advance by email.

05 · Security

Technical and organisational measures

See the Security page for full detail. Highlights: TLS 1.3, AES-256 at rest, Argon2id password hashing, hardware key MFA on production access, quarterly restore drills.

06 · Data return

Return or deletion at end of term

At the end of the module subscription, Rmsclaud returns or deletes all personal data within 30 days, at the Customer’s choice. Written confirmation of deletion is provided on request.