Data Processing Agreement

pursuant to Art. 28 of Regulation (EU) 2016/679 ("GDPR")

Version 1.0 of 06/10/2026
Permanent text of this version: plutonios.com/en/data-processing-agreement/v1-0
This is a translation. In case of discrepancy, the Italian version prevails.

This agreement ("Agreement") forms an integral part of the contract for the supply of the Plutonios services, consisting of the commercial offer ("Offer") and the General Terms and Conditions for the Supply of Services ("GTC") (jointly, the "Contract"), and is accepted by signing the Offer. The parties to the Agreement are:

  • the Company indicated in the Offer, as data controller ("Controller");
  • Plutonios S.r.l., with registered office at Via Giuseppe Frua 15, 20146 Milan, Italy, tax code/VAT 13788200965, as data processor ("Processor").

Terms not defined in this Agreement have the meaning given to them by the GDPR.

1. Subject matter and duration

1.1

The Controller entrusts the Processor with the processing of the personal data necessary to provide the Services described in the Contract. This Agreement supplements and, in case of conflict, prevails over the GTC.

1.2

The Agreement has the same duration as the Contract and remains in effect until the data are returned or erased under Art. 10.

2. Nature and purposes of the processing

2.1

The Processor processes personal data exclusively to:

  1. a)manage, also through the artificial intelligence assistant, conversations with guests and prospective guests on the channels activated by the Controller;
  2. b)generate quotes and check availability through the connection to the Controller’s booking engine and PMS;
  3. c)synchronise bookings from the PMS or channel manager and provide the inbox, back office, conversation history and dashboards;
  4. d)run the automations configured by the Controller and, where requested by the Controller, guest analysis and segmentation;
  5. e)provide technical support, maintenance, security and the quality checks provided for in Art. 9.3 of the GTC.
2.2

Processing is carried out by electronic means, including through artificial intelligence models made available by sub-processors under Art. 7.

3. Categories of data subjects and data

3.1

Data subjects: guests, prospective guests and users who contact the Controller through the channels of the Services; persons named in bookings, including companions and minors limited to their number and age; the Controller’s staff using the back office.

3.2

Data: identification and contact data (name, telephone, email, language, nationality); booking and stay data (dates, rooms, rates, quotes, number and age of guests, requests); content of conversations (messages, voice messages and their transcripts, call recordings where activated); technical identifiers (WhatsApp identifier, browser identifier, IP address); preferences and attributes inferred from conversations; data transmitted by the Controller’s PMS or channel manager.

3.3

The Services are not intended for processing special categories of personal data (Art. 9 GDPR) or identity document data. The Processor limits the data acquired from the PMS to those necessary to provide the Services and does not use health data for segmentation or promotional purposes. Where such data are spontaneously provided by guests in conversations, they are processed solely to handle the related request.

4. Controller’s instructions

4.1

The Processor processes personal data only on documented instructions from the Controller, consisting of the Contract, this Agreement and the settings configured by the Controller in the back office, including with regard to transfers to third countries, unless required to do so by Union or Member State law; in such a case the Processor informs the Controller before processing, unless the law prohibits it.

4.2

The Processor immediately informs the Controller if, in its opinion, an instruction infringes the GDPR or other data protection provisions.

4.3

The Processor keeps the Controller’s data logically separate from data processed on behalf of other customers and does not combine them.

5. Authorised persons

5.1

The Processor ensures that persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, have received instructions under Art. 29 GDPR and access the data only to the extent necessary for support, maintenance, security and quality control of the Services.

6. Security

6.1

The Processor implements appropriate technical and organisational measures under Art. 32 GDPR, taking into account the state of the art, the costs of implementation and the risks, including: (a) encryption of data in transit; (b) encryption of credentials for access to third-party systems; (c) role-based access control and individual credentials; (d) logging of access and relevant events; (e) periodic backups; (f) storage of the main data on servers located in the European Union; (g) incident management procedures; (h) periodic review and update of the measures.

6.2

The Processor assists the Controller in ensuring compliance with Arts. 32-36 GDPR, including data protection impact assessments and prior consultation, taking into account the nature of processing and the information available to it.

7. Sub-processors

7.1

The Controller grants general written authorisation to engage sub-processors belonging to the categories set out in Annex 1. The list of sub-processors, with name, registered office, activity and place of processing, is provided to the Controller on request at info@plutonios.com, including before the Contract is signed.

7.2

The Processor notifies the Controller in writing, including by email, of any intended addition or replacement of sub-processors at least 15 (fifteen) days in advance. The Controller may object on reasonable and documented data protection grounds within 10 (ten) days of the notice. In case of objection the Parties seek a solution in good faith; failing that, the Controller may withdraw from the affected Services without penalty, including the penalty under Art. 6.3 of the GTC, with a refund of the unused portion of the fee.

7.3

The Processor imposes on sub-processors, by contract, data protection obligations substantially equivalent to those in this Agreement and remains liable to the Controller for the performance of their obligations (Art. 28(4) GDPR).

7.4

Where the WhatsApp channel is activated on a WhatsApp Business account in the Controller’s name, the WhatsApp service provider processes the data under its direct contractual relationship with the Controller; the Processor accesses it as a technology provider authorised by the Controller.

8. Transfers to third countries

8.1

Transfers of personal data outside the European Economic Area take place only to sub-processors authorised under Art. 7 and on the basis of the safeguards under Chapter V GDPR: an adequacy decision, including the EU-U.S. Data Privacy Framework for certified recipients, or standard contractual clauses adopted by the European Commission.

9. Data subject rights and personal data breaches

9.1

The Processor informs the Controller without undue delay, and in any case within 5 (five) working days, of requests received directly from data subjects and does not respond to them without the Controller’s instructions. At the Controller’s request, it carries out within 15 (fifteen) days the operations needed to handle requests for access, rectification, erasure, restriction and portability.

9.2

The Processor notifies the Controller of any personal data breach without undue delay and in any case within 48 (forty-eight) hours of becoming aware of it, providing, to the extent available, the information referred to in Art. 33(3) GDPR, and cooperates with the Controller for the obligations under Arts. 33 and 34 GDPR.

10. Retention, return and erasure

10.1

Data are retained for the duration of the Contract. The Controller may at any time request the early erasure of individual conversations or of the data of individual guests.

10.2

Technical logs, which may contain conversation data, are retained for no more than 120 (one hundred and twenty) days. Call recordings, where the telephone channel is activated, are retained for the period set by the Controller and in any case for no more than 90 (ninety) days.

10.3

Upon termination of the Contract the Processor, at the Controller’s choice, returns the data as provided by Art. 6.3 of the GTC and erases them within 30 (thirty) days; backup copies are erased within 90 (ninety) days of termination, unless Union or Member State law requires their retention. On request, the Processor confirms the erasure in writing.

11. Information and audits

11.1

The Processor makes available to the Controller all information necessary to demonstrate compliance with Art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or by an auditor mandated by it and bound by confidentiality.

11.2

Except in case of a personal data breach or a request from a supervisory authority, audits are agreed with at least 30 (thirty) days’ notice, no more than once a year, during business hours, in a manner that does not compromise the security of other customers’ data, and at the Controller’s expense.

12. Further obligations

12.1

The Processor keeps the record of processing activities under Art. 30(2) GDPR.

12.2

The Controller guarantees the lawfulness of the processing entrusted, including the existence of an appropriate legal basis, the information provided to data subjects and, where necessary, the collection of consent, as well as the lawfulness of the instructions given.

12.3

The liability of the Parties towards data subjects is governed by Art. 82 GDPR.

13. Artificial intelligence

13.1

Neither the Processor nor its sub-processors use the personal data processed on behalf of the Controller to train artificial intelligence models. The Processor uses third-party artificial intelligence services only under contractual terms that exclude such use.

13.2

The Processor configures the Services so that data subjects are clearly informed, at the latest at the time of the first interaction, that they are interacting with an artificial intelligence system and, where enabled, that the call is recorded (Art. 50 Regulation (EU) 2024/1689).

13.3

Content generated by artificial intelligence models may be inaccurate or incomplete. The Controller monitors the functioning of the Services through the back office, ensures that data subjects can be put in contact with its staff and does not use the Services to take decisions based solely on automated processing that produce legal effects concerning data subjects or similarly significantly affect them (Art. 22 GDPR).

13.4

On request, the Processor provides the Controller with the information on the functioning of the artificial intelligence systems needed for the information to data subjects and for any data protection impact assessment.

Annex 1. Categories of sub-processors

Category
Hosting and infrastructure (application servers, databases, backups, logs)
Location
Germany
Transfer safeguards
No transfer outside the EEA
Category
Cloud services (file storage, email, translation, technical support services)
Location
EU / USA
Transfer safeguards
Data Privacy Framework; standard contractual clauses
Category
Artificial intelligence models (reply generation, translation, classification, speech transcription and synthesis) and knowledge base services
Location
EU / USA
Transfer safeguards
Standard contractual clauses; Data Privacy Framework where certified
Category
Artificial intelligence tools for technical support and quality control
Location
USA
Transfer safeguards
Standard contractual clauses; Data Privacy Framework where certified
Category
Technical monitoring of the services
Location
EU
Transfer safeguards
No transfer outside the EEA
Category
Messaging (WhatsApp Business Platform), for numbers provided by Plutonios (Art. 9.4 of the GTC)
Location
EU / USA
Transfer safeguards
Data Privacy Framework; standard contractual clauses