This agreement is drafted from the CNIL's standard controller–processor clauses and states what HoteFlow actually does. It forms part of the Terms and is accepted when you create an organisation.
Data processing agreement
Version 2026-09-06
This agreement governs HoteFlow's processing of personal data on your behalf. It applies whenever you use HoteFlow to run your business — your properties, your staff, your cleaners, your missions.
1. Who is who
Your organisation is the data controller. HoteFlow is the processor, acting only on your instructions. This is not a formality: it means you decide what is processed and why, and we do not use your organisation's data for any purpose of our own. For your own account details — your email and display name — HoteFlow is itself the controller, and the privacy policy governs that.
2. Subject matter, duration, nature and purpose
Subject matter: coordinating short-term-rental cleaning. Nature and purpose: storing and organising your properties, checklists and access details; scheduling turnovers from your calendars; assigning and tracking missions; recording evidence of work done; and sending the notifications those require. Duration: for as long as your organisation has an account, and thereafter only as section 9 permits.
3. What personal data, and whose
Categories of data subjects: your organisation's members (owners, admins, managers, dispatchers and cleaners), and the members of any cleaning agency you engage or host you work for. Categories of personal data: names, email addresses, roles and memberships; work records including missions, timings, checklist responses and messages; photographs taken as evidence of completed work; and, where an organisation applies for verification, identity documents, company-registration extracts and professional-liability insurance certificates, together with the declared legal name, SIREN, SIRET and VAT number. Verification data is collected only from organisations that apply, is held in private storage, and every access to a document by HoteFlow staff is recorded in the audit trail. HoteFlow does not process guest personal data: the calendar import reads arrival and departure times and an opaque event identifier, and no field for a guest's name or contact details exists anywhere in the system.
4. We process only on your documented instructions
HoteFlow processes personal data only on your documented instructions, including as to transfers outside the EU. Your instructions are: this agreement, the Terms, and the actions you and your members take in the product. If we believe an instruction breaches data protection law we will tell you and may suspend that processing. We will not process your organisation's data for our own purposes, and we will never sell it.
5. Confidentiality
Everyone we authorise to process your data is bound by an obligation of confidentiality, and access is limited to those who need it to run or support the service. Access to production data is restricted and audited.
6. Security (article 32)
We implement appropriate technical and organisational measures, including: row-level security isolating every organisation's data in the database; encryption of property access secrets with AES-256-GCM using a key held outside the database; evidence photographs stored in private buckets and served only through short-lived signed links; encryption in transit; audited access to sensitive records; and daily backups. Access codes are revealed only to the worker assigned to an active mission, and every reveal is logged.
7. Other processors
You give general authorisation for HoteFlow to engage sub-processors. We will provide the current list — each one's name, purpose and location — in writing on request. We impose data-protection obligations on each of them no less protective than those in this agreement, and we remain fully liable to you for their performance. We will give you at least 30 days' notice before adding or replacing a sub-processor, and you may object on reasonable data-protection grounds; if we cannot resolve your objection you may terminate.
8. Helping you meet your own obligations
We assist you in responding to requests from data subjects — access, rectification, erasure, portability, objection — taking into account the nature of the processing. The product provides self-service export and account erasure, which will usually satisfy a request without our involvement. We also assist you with your obligations under articles 32 to 36: security, notification of breaches, and impact assessments. We notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need for your own notification to the CNIL.
9. Deleting or returning your data
On termination, and at your choice, we delete or return all personal data processed on your behalf, and delete existing copies unless retention is required by law. Each member can export their own personal data at any time from their account. An export of your whole organisation's data is available on request while the account is active — there is no self-service control for it yet, and we will not pretend otherwise.
10. Demonstrating compliance, and audits
We make available to you the information necessary to demonstrate compliance with article 28, and allow and contribute to audits, including inspections, conducted by you or an auditor you mandate. Audits are at reasonable intervals and on reasonable notice, and must not compromise the confidentiality of other customers' data.
11. Transfers outside the EU
The database and file storage are in the EU. Two categories of recipient are not: billing data is processed in the United States by our payment processor, and web push notifications are delivered by the recipient's own browser vendor, which may route outside the EU. Those transfers rely on the safeguards in each provider's own data-processing terms. The specific mechanism for each — standard contractual clauses or an adequacy decision — has not yet been confirmed by us and is not asserted here; it will be stated in the list we provide on request. We will not transfer your data outside the EU other than as described above without informing you.
12. Precedence and changes
Where this agreement conflicts with the Terms on the processing of personal data, this agreement prevails. We record which version your organisation accepted, and an owner or admin can accept a new version from the organisation's own screens. If we change it materially we will ask you to accept the new version, and tell you what changed. A managed client record — one created by an agency for a client who has no account — is covered by the agreement the managing agency accepted. It is not a separate party to this one: it has no account, no plan and no relationship with us of its own, and the agency is the party that engaged us.