Data Processing Addendum
Last updated: 14 November 2026 · Version 3.2
On this page
- Incorporation and parties
- Definitions
- Subject matter and duration
- Nature, purpose and categories
- Roles and instructions
- Confidentiality of personnel
- Security of processing
- Subprocessors
- International transfers and SCCs
- Data subject requests
- Assistance to the controller
- Personal data breaches
- Audit rights
- Return and deletion
- Liability and precedence
- Annex I — details of processing
- Annex II — technical and organisational measures
- Annex III — approved subprocessors
1. Incorporation and parties
This Data Processing Addendum ("DPA") is entered into between the Customer identified in the order form (the "Controller") and Talk with Guest, Lda ("Talk with Guest", "Talkguest" or the "Processor"), a Portuguese limited liability company registered under NIPC 516 842 397 with registered office at Rua Rodrigo da Fonseca 123, 1.º Esq, 1250-190 Lisboa. It is incorporated by reference into and forms an integral part of the Terms of Service governing the Customer's use of the Talkguest platform, and satisfies the requirements of Article 28(3) of Regulation (EU) 2016/679 (GDPR).
2. Definitions
Terms not defined in this DPA have the meaning assigned to them in the GDPR or in the Terms of Service. "Personal Data" means personal data that Talkguest processes on behalf of the Controller in the course of providing the Service. "Processing", "Data Subject", "Personal Data Breach" and related terms have the meaning set out in Article 4 GDPR. "SCCs" means the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, including their Portuguese translation. "Sub-processor" means any entity engaged by the Processor to process Personal Data on behalf of the Controller.
3. Subject matter and duration
The subject matter of the processing is the delivery of the Talkguest Software-as-a-Service platform in accordance with the Terms of Service. The processing lasts for the duration of the Subscription Term and any post-termination assistance period necessary for the return or deletion of Personal Data. The details of the processing are set out in Annex I. The Controller is entitled to modify the scope of processing only through documented instructions issued through the operator console or through a written amendment signed by both parties.
4. Nature, purpose and categories
The nature of the processing is described in Annex I and comprises collection, structuring, storage, retrieval, consultation, transmission by messaging channels, erasure and destruction. The purpose is to enable the Controller to deliver messaging, upsell, verification and reporting functions to its hotel guests. Categories of Data Subjects include hotel guests, prospective guests, personnel of the Controller and, where applicable, agents authorised by the Controller. Categories of Personal Data include contact identifiers, reservation records, communication content, identity documents where the verification module is enabled, and product usage telemetry.
5. Roles and instructions
The Controller determines the purposes and means of the processing and remains responsible for the lawfulness of the collection of Personal Data. Talk with Guest processes Personal Data only on documented instructions from the Controller. The Terms of Service, this DPA, the order form and the configuration choices made by the Controller through the operator console together constitute the initial documented instructions. If Talkguest considers that an instruction infringes the GDPR or Lei n.º 58/2019, it will inform the Controller in writing without undue delay and may suspend the affected instruction until it is corrected.
6. Confidentiality of personnel
Talk with Guest ensures that any person authorised to process Personal Data is bound by contractual obligations of confidentiality that survive the termination of the employment or engagement, and has received training on data protection and on the specific security requirements applicable to the Service. Access to Personal Data is restricted to personnel who need access to perform their duties, on a need-to-know basis, and is logged and periodically reviewed.
7. Security of processing
Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing as well as the risk of varying likelihood and severity for the rights and freedoms of Data Subjects, Talk with Guest implements the technical and organisational measures set out in Annex II. Talkguest reviews these measures at least once per year and updates them as necessary to maintain an appropriate level of security. Material changes that reduce the level of security require the prior written consent of the Controller.
8. Subprocessors
The Controller grants Talk with Guest general written authorisation to engage the Sub-processors listed in Annex III. Talkguest maintains an updated list on talk.mindbery.org/legal/subprocessors. Any addition or replacement of a Sub-processor is notified to the Controller at least thirty days in advance through email to the primary billing contact and through an in-product banner. The Controller may object on reasonable data-protection grounds within fifteen days. If the objection cannot be resolved, the Controller may terminate the affected part of the Service with a pro-rata refund of any prepaid fees corresponding to the terminated portion.
Talk with Guest enters into a written contract with each Sub-processor that imposes obligations no less protective than those in this DPA, in particular concerning security, confidentiality and assistance with Data Subject rights, and remains fully liable to the Controller for the performance of each Sub-processor's obligations.
9. International transfers and SCCs
Personal Data is hosted within the European Economic Area under normal operating conditions, as described in the Privacy Policy. Where a transfer to a third country is necessary, Talk with Guest relies on the SCCs (Module Two, controller-to-processor, and Module Three, processor-to-processor as applicable), which are hereby incorporated by reference and completed with the details set out in Annex I and Annex III. Talkguest also implements the supplementary measures identified through a transfer impact assessment for each concerned recipient, including end-to-end encryption, pseudonymisation and access logging. Where applicable law requires the execution of the UK Addendum to the SCCs or the Swiss adaptations issued by the FDPIC, those instruments are executed automatically as part of this DPA.
10. Data subject requests
Taking into account the nature of the processing, Talk with Guest assists the Controller by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Controller's obligation to respond to requests for exercising Data Subjects' rights under Chapter III GDPR. Where a Data Subject contacts Talkguest directly, Talkguest forwards the request to the relevant Controller within seventy-two hours and provides operational assistance in retrieving, correcting, exporting or deleting the affected data through the operator console or, where required, through direct database action logged and countersigned by two Talkguest engineers.
11. Assistance to the controller
Talk with Guest assists the Controller in ensuring compliance with the obligations set out in Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available to Talkguest. This assistance includes providing information necessary for the maintenance of the Controller's records of processing, cooperating with data protection impact assessments where required, and, upon request, supplying the technical documentation necessary for prior consultation with the CNPD.
12. Personal data breaches
Talk with Guest notifies the Controller of any Personal Data Breach affecting Personal Data processed under this DPA without undue delay and, in any event, no later than forty-eight hours after becoming aware of the incident. The notification includes the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed to address the breach and to mitigate its adverse effects, and the contact point for further information. Talkguest maintains an internal register of incidents that is available to the Controller on request.
13. Audit rights
Talk with Guest makes available to the Controller all information necessary to demonstrate compliance with the obligations set out in Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Controller or an independent auditor mandated by the Controller. Audits are conducted with at least thirty days' prior written notice, no more than once per calendar year (except in the aftermath of a Personal Data Breach), during business hours and under strict confidentiality obligations. Talkguest may satisfy audit requests by providing recent independent assessment reports, including ISO/IEC 27001 certificates and SOC 2 Type II attestations, provided that these cover the scope of the request.
14. Return and deletion
Upon termination of the Subscription Term, and at the choice of the Controller, Talk with Guest either returns all Personal Data to the Controller or deletes it, unless retention is required by Union or Member State law. A structured export in JSON and CSV formats is made available through the operator console for thirty days following termination. Personal Data is deleted from active systems within a further sixty days and from backup systems within one hundred and eighty days. Talkguest certifies the completion of deletion in writing on request.
15. Liability and precedence
The liability of the parties under this DPA is subject to the limitations set out in the Terms of Service, without prejudice to the mandatory rules of the GDPR and the Portuguese Lei n.º 58/2019, in particular the joint liability of controller and processor towards Data Subjects. In the event of a conflict between this DPA and the Terms of Service on matters concerning the processing of Personal Data, this DPA prevails. In the event of a conflict between this DPA and the SCCs on transfers to third countries, the SCCs prevail.
16. Annex I — details of processing
Categories of Data Subjects: hotel guests and prospective guests of the Controller; personnel of the Controller with an operator account; agents authorised by the Controller. Categories of Personal Data: identifiers (name, contact details, reservation reference), communication content (messages exchanged through the platform), identity documents (only where the verification module is enabled and only for the strict duration of the verification workflow), transactional metadata (timestamps, channel, language). Special categories of Personal Data are not processed under the standard configuration; where the Controller enables health-related fields to record dietary or accessibility preferences, such data is processed under Article 9(2)(a) with the Data Subject's explicit consent obtained by the Controller. Nature and purpose: delivery of a hosted messaging and upsell platform for the hospitality sector. Duration: for the Subscription Term and up to one hundred and eighty days after termination for backup retention.
17. Annex II — technical and organisational measures
Encryption in transit using TLS 1.2 or higher on all endpoints, with modern cipher suites and Perfect Forward Secrecy. Encryption at rest using AES-256 for databases and object storage. Key management using a hardened key management service with regional isolation in Portugal and quarterly key rotation. Identity and access management with role-based access, mandatory multi-factor authentication for all Talkguest personnel, hardware security keys for privileged administrators, and session recording on production access.
Segregation of environments between development, staging and production with distinct credentials and network isolation. Network segmentation with default-deny egress and application-layer firewalls in front of every public endpoint. Vulnerability management including automated dependency scanning at each build, monthly infrastructure scans and quarterly independent penetration testing. Logging and monitoring with centralised log aggregation, real-time anomaly detection and a twenty-four seven security operations rota. Backup with encrypted, geographically redundant snapshots taken every six hours and retained for thirty days.
Business continuity with a documented plan tested at least annually, a recovery time objective of four hours and a recovery point objective of one hour. Physical security through provider-managed data centres certified ISO/IEC 27001 and, where applicable, ISO/IEC 27017 and ISO/IEC 27018. Personnel security including background checks compatible with Portuguese labour law, annual data-protection training and formal on-boarding and off-boarding procedures.
18. Annex III — approved subprocessors
OVHcloud SAS (Roubaix, France; Sines, Portugal; Limerick, Ireland) — production hosting and disaster recovery. Mailgun Technologies EU B.V. (Amsterdam, Netherlands) — transactional email delivery for password resets and system notifications. Intercom Ireland Limited (Dublin, Ireland) — support and in-product messaging suite, EU tenancy. Sentry.io GmbH (Frankfurt, Germany) — error monitoring and application performance measurement. Stripe Payments Europe Ltd. (Dublin, Ireland) — card-based settlement gateway used only when the Controller opts for card payment rather than SEPA direct debit. BetterStack Kft. (Prague, Czech Republic) — status page and uptime monitoring, EU region. This annex is updated as described in section eight, and the current authoritative version is always the one published at talk.mindbery.org/legal/subprocessors.