Data processing agreement (DPA)
Current version: 2026-09-12-r2. This document can be accepted from your account (the "Data processing agreement" section). Real guest-data processing (submission to SES Hospedajes) is not activated until you accept the current version.
Parties
The Controller: the Owner/Agency holding the CheckinSecure account, as the holder/manager of the hospitality activity under RD 933/2021 (where applicable). The Processor: CheckinSecure's operator identified in the Legal notice. For an already-registered acceptance of this DPA, the contractually bound Processor is whichever operator was in effect on that acceptance's date -- never the operator currently in effect, if it has since changed.
Purpose
To govern the processing of guests' personal data that CheckinSecure carries out on behalf of the Owner/Agency, solely to comply with the legal obligation to communicate traveller data to SES Hospedajes under RD 933/2021.
Duration
This agreement remains in force while the Owner/Agency has an active account, and automatically extends during the applicable retention period for data already communicated (see Retention).
Documented instructions
CheckinSecure processes data only in accordance with: this agreement, the configuration entered by the Owner/Agency on the platform, and any additional written instructions the Owner/Agency issues through the available contact channel.
Confidentiality and security
Anyone authorized to process the data is bound by a duty of confidentiality. Security measures applied: encryption of SES credentials at rest, hashed passwords, server-side revocable opaque session tokens, strict multi-tenant isolation, no-store headers on private pages and APIs, and idempotent retries on technical failure.
Subprocessors and international transfers
The Owner/Agency generally authorizes CheckinSecure to engage the subprocessors listed below, subject to data-protection obligations equivalent to those in this agreement. CheckinSecure will notify the Owner/Agency of any addition or replacement of a subprocessor with reasonable notice, giving the opportunity to object on justified grounds. These subprocessors may process data outside the European Economic Area, relying on the transfer mechanisms (EU Standard Contractual Clauses or equivalent) they have published.
| Subprocessor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Application and database infrastructure (Workers, D1, queues) | EE. UU. / UE (según configuración de Cloudflare) |
| Resend | Transactional and operational email delivery (never to guests) | EE. UU. |
Retention
Legal guest data is kept for 3 years from the end of the stay/contract, under article 5.3 of RD 933/2021. This obligation falls on the obligated party (the Owner/Agency, where applicable); CheckinSecure, as processor, retains and processes that data according to the Owner/Agency's documented instructions, including this period.
Security breach notification
CheckinSecure will notify the Owner/Agency without undue delay and, in any case, within 72 hours of becoming aware of a security breach affecting the data covered by this agreement.
Assistance and data subject rights
CheckinSecure will assist the Owner/Agency in responding to data subject rights requests and in reasonable impact assessments related to this processing.
Deletion or return of data
Upon termination of the relationship, CheckinSecure will delete or export the personal data processed, at the Owner/Agency's choice, unless a law requires longer retention.
Liability
See the liability section of the Terms and conditions, also applicable to this agreement.
Termination
This agreement automatically terminates when the Owner/Agency's account is closed, without prejudice to any subsisting legal retention obligations.