Data Processing Agreement
This agreement forms part of the Terms of Service between TIOO and its customers, and governs the processing of personal data on behalf of the customer under UK GDPR Article 28.
Last updated: July 2026 (v1.0)1. Parties and Scope
This Data Processing Agreement ("DPA") is entered into between:
- TIOO (the "Processor"), operator of the TIOO property management platform at tioo.com; and
- the customer identified in the associated Terms of Service (the "Controller"), typically a property manager, hotelier, or short-let operator.
This DPA applies to all personal data that the Processor processes on behalf of the Controller in connection with the TIOO platform. It supplements, and is incorporated by reference into, the Terms of Service.
In case of conflict between this DPA and the Terms of Service, this DPA prevails on matters of data protection.
2. Definitions and Applicable Law
Terms used but not defined in this DPA have the meanings given in the applicable data protection law. Depending on the Controller's location and where its data subjects reside, that may include:
- the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018;
- the EU General Data Protection Regulation ("EU GDPR");
- the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA") — under which TIOO acts as a "service provider" and the Controller acts as a "business";
- the Brazilian General Data Protection Law ("LGPD");
- the Canadian Personal Information Protection and Electronic Documents Act ("PIPEDA") and Quebec Law 25;
- the Australian Privacy Act 1988 and Australian Privacy Principles ("APPs");
- the New Zealand Privacy Act 2020;
- the South African Protection of Personal Information Act ("POPIA");
- the Nigerian Data Protection Act 2023;
- the Singapore Personal Data Protection Act ("PDPA"); and
- any other applicable data protection, privacy, or information-security law in force in the jurisdictions where the Controller processes personal data through the platform.
Where those laws use different labels (e.g. CCPA's "business" and "service provider", PIPEDA's "organization"), those terms map to "Controller" and "Processor" in this DPA respectively. "Personal data" includes "personal information" (US laws), "personal data" (GDPR family), and any equivalent term in other applicable laws.
3. Subject Matter, Nature, Purpose, and Duration
- Subject matter: the operation of the TIOO platform for the Controller, including reservation management, guest communications, check-in workflows, ID document handling (where enabled), smart-lock integration (where enabled), billing, cleaning schedules, and website hosting.
- Nature and purpose: providing the software services described in the Terms of Service and following the Controller's documented instructions.
- Duration: for the duration of the Terms of Service, plus any period during which data is retained pursuant to Section 12 (Return and Deletion).
4. Categories of Personal Data and Data Subjects
Categories of personal data processed on behalf of the Controller (as applicable to the Controller's use of the platform):
- Contact details: guest name, email address, phone number, and, where collected, postal address.
- Reservation data: booking references, dates, room assignments, prices, arrival times, special requests, vehicle registration.
- Identity documents: passport, driving licence, or national ID scans and derived metadata, where the Controller has enabled the ID collection feature. Where the Controller has enabled the optional automated ID verification, associated biometric-derived confidence scores.
- Communications: message content and delivery metadata across email, SMS, and WhatsApp channels operated through the platform.
- Access data: smart-lock PIN codes, first-access timestamps, and access method, where smart-lock integration is enabled.
- Financial data: payment amounts and status. TIOO does not store full card numbers on its own infrastructure; card data is handled by the payment sub-processors named in Section 7.
- Security and usage data: IP addresses, user-agent strings, page visits, and audit-log entries relating to significant account actions.
Categories of data subjects: the Controller's guests; the Controller's staff members and cleaners with platform accounts; the Controller's account users.
5. Controller Obligations
The Controller warrants that:
- It has a lawful basis under UK GDPR Article 6 (and, where applicable, Article 9) for the processing it instructs the Processor to carry out;
- It has provided all required notices to data subjects and, where required, obtained their consent;
- Its instructions to the Processor comply with applicable data protection law.
The Controller retains full responsibility for the accuracy, quality, legality, and appropriateness of the personal data it enters into the platform and the instructions it gives to the Processor.
6. Processor Obligations
The Processor shall:
- Documented instructions. Process personal data only on the Controller's documented instructions, including with respect to transfers to a third country. The Terms of Service, this DPA, and the Controller's use of the platform's features constitute the Controller's initial documented instructions.
- Confidentiality. Ensure that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Security. Implement and maintain appropriate technical and organisational measures under UK GDPR Article 32, as described in Section 8 (Security Measures) below.
- Sub-processors. Engage sub-processors only in accordance with Section 7 (Sub-processors) below.
- Data subject rights. Taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising data subject rights under UK GDPR Chapter III.
- Security and DPIA assistance. Assist the Controller in ensuring compliance with the obligations under UK GDPR Articles 32 to 36, taking into account the nature of processing and the information available to the Processor.
- Deletion or return. At the choice of the Controller, delete or return all personal data to the Controller after the end of the provision of services relating to processing, and delete existing copies unless applicable law requires storage of the personal data — as further described in Section 12 (Return and Deletion).
- Audits. Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28, and allow for and contribute to audits, as described in Section 11 (Audits).
- Instruction breach notice. Immediately inform the Controller if, in its opinion, an instruction from the Controller infringes UK GDPR, EU GDPR, CCPA/CPRA, or other applicable data protection law.
- CCPA/CPRA service-provider commitments. Where the Controller is a "business" under CCPA/CPRA, the Processor certifies that it acts as a "service provider" and shall not (i) sell or share the personal information; (ii) retain, use, or disclose the personal information for any purpose other than the specific business purpose of providing the platform services (or as otherwise permitted by CCPA/CPRA §1798.140(ag)(1) and §1798.140(ah)); (iii) retain, use, or disclose the personal information outside the direct business relationship with the Controller; or (iv) combine the personal information received from the Controller with personal information received from other sources except as permitted by CCPA/CPRA regulations.
- No sale, no share, no cross-context behavioural advertising. The Processor does not sell personal data (as "sale" is defined under CCPA/CPRA §1798.140(ad) or any equivalent term in other applicable law), does not "share" personal data for cross-context behavioural advertising (as "share" is defined under CCPA/CPRA §1798.140(ah)), and does not use personal data received from Controllers for its own marketing purposes. The Processor's business model is the subscription fee paid by the Controller — not monetisation of personal data.
7. Sub-processors
The Controller grants the Processor general authorisation to engage sub-processors, subject to the conditions set out in this Section. The Processor shall maintain an up-to-date list of sub-processors below and shall notify the Controller of intended changes at least 30 days in advance by email and via the platform. The Controller may object to a new sub-processor on reasonable data-protection grounds by written notice within 30 days; where an objection cannot be resolved, either party may terminate the Terms of Service without penalty limited to the affected service.
The Processor shall enter into a written contract with each sub-processor imposing data-protection obligations no less protective than those in this DPA, in accordance with UK GDPR Article 28(4). The Processor remains fully liable to the Controller for the performance of each sub-processor's obligations.
7.1 Current Sub-processor List
The sub-processors currently engaged in providing the platform, as of the "Last updated" date above:
| Sub-processor | Purpose | Data location | Transfer mechanism |
|---|---|---|---|
| DigitalOcean, LLC | Cloud compute + managed PostgreSQL database hosting the platform and all Controller data at rest | United Kingdom (LON1 region) | Within UK |
| DigitalOcean Spaces | Object storage for guest ID documents, invoices, exports, gallery images, and message attachments | United Kingdom (LON1 region) | Within UK |
| Cloudflare, Inc. | CDN + edge network + DDoS protection; Turnstile bot verification on public forms; custom-domain hostname management API | Global edge (metadata routed via nearest region) | UK IDTA + EU SCCs (Cloudflare DPA) |
| Stripe Payments UK, Ltd. / Stripe, Inc. | Subscription billing; Stripe Connect for tenant payment collection; Stripe Checkout / Elements for guest card handling (PCI SAQ A scope) | United Kingdom / European Union / United States | UK IDTA + EU SCCs (Stripe DPA) |
| PayPal (Europe) S.à r.l. et Cie, S.C.A. | Alternative payment gateway (where enabled by the Controller) | European Union / United States | UK IDTA + EU SCCs (PayPal DPA) |
| Paystack Payments Limited | Payment gateway for African markets (Nigeria, Ghana, Kenya, South Africa) — cards, bank transfer, mobile money, USSD, where enabled by the Controller | Nigeria | UK IDTA (Paystack DPA) |
| Mailgun (Sinch Email UK Ltd.) | Transactional email delivery, tenant email aliases, and inbound email webhook processing | European Union | UK IDTA (Mailgun DPA) |
| Twilio Ireland Limited | SMS delivery and phone-number verification (where enabled by the Controller) | Ireland / United States | UK IDTA + EU SCCs (Twilio DPA) |
| Meta Platforms Ireland Limited (WhatsApp Business API) | WhatsApp messaging to guests (where enabled by the Controller) | Ireland / United States | UK IDTA + EU SCCs (Meta DPA) |
| Amazon Web Services EMEA SARL (AWS Rekognition) | Automated ID document face-match confidence scoring (where the Controller has enabled ID verification) | Ireland (eu-west-1 region) | UK IDTA (AWS DPA) |
| Sciener (TTLock) | Smart-lock integration: PIN provisioning, revocation, and access logs on the physical lock (where the Controller has enabled smart-lock integration) | People's Republic of China | Explicit Controller instruction on enabling integration; UK GDPR Article 49(1)(b) — transfer necessary for the performance of a contract between the data subject and the Controller. Controllers using TTLock should include this transfer in their guest privacy notice. |
| Sentry (Functional Software, Inc.) | Application error monitoring — request metadata and stack traces. Personal data scrubbing enabled at the SDK layer; no guest personal data is transmitted intentionally. | United States | UK IDTA + EU SCCs (Sentry DPA) |
| Ticketmaster Discovery API | Public event data for the Smart Pricing feature. No personal or guest data is shared; only aggregate location queries are transmitted. | United States | Not applicable (no personal data) |
| Nominatim (OpenStreetMap Foundation) | Address geocoding for the Controller's business address and Smart Pricing venue lookups. Only address strings are transmitted. | Germany | Within EEA (adequacy decision) |
| Google Places API | Google Reviews sync for the Controller's website builder (where the Controller has enabled this integration) | United States | UK IDTA + EU SCCs (Google Cloud DPA) |
| TheSportsDB, AIMS Race Directors' Meeting, Wikidata | Public sporting-event, marathon, and cultural-event data for the Smart Pricing feature. No personal data is shared. | Various | Not applicable (no personal data) |
| Unsplash Inc., Pexels GmbH | Stock photography search for the website builder. Only search queries are transmitted; no personal data. | Canada / Germany | Adequacy decision (Canada, Germany) |
The Controller may verify the current sub-processor list at any time at tioo.com/dpa and by contacting [email protected] for material updates.
8. Security Measures
The Processor implements and maintains the following technical and organisational measures, in line with UK GDPR Article 32:
8.1 Technical measures
- Encryption in transit: TLS 1.2+ enforced across all HTTP endpoints, SMTP submission, database connections, and object storage.
- Encryption at rest: sensitive fields (integration credentials, TOTP secrets, payment gateway keys) encrypted at the application layer using Fernet (AES-128-CBC + HMAC-SHA256) via
django-encrypted-model-fields. Database and object-storage volumes encrypted at rest by the infrastructure provider. - Private object storage: guest ID documents, invoices, and data exports stored in a private DigitalOcean Spaces bucket. Read access via time-limited signed URLs (1-hour TTL). Access-Control-Allow-Origin restricted.
- Access controls: role-based access via
OrganizationMemberroles (owner, admin, manager, receptionist, cleaner) with per-property scoping. Two-factor authentication (TOTP) available to all users on all plans. Optional email-code login layer available. Sudo-mode re-authentication required for high-privilege actions (ID disclosure, permanent deletion). - Multi-tenant isolation: tenant data scoped by
organizationforeign key with sweep tests preventing cross-tenant leakage. Silent-investigation impersonation writes to a walled-off audit log that never appears on tenant-facing surfaces. - Rate limiting: applied to login, signup, password reset, cross-domain token, TC login, shop checkout, guest ID download, and all other authentication and enumeration-prone endpoints. IP source normalised through Cloudflare's verified visitor IP header to prevent spoofing bypass.
- Automated account protection: five failed login attempts in five minutes triggers a fifteen-minute lockout. Subdomain-probe auto-blocking after twenty unknown-subdomain hits in five minutes.
- Audit logging: every mutating action recorded in
TenantAuditLogwith actor, timestamp, IP, and structured details. Sensitive disclosures (ID document downloads) retained for six years under the UK Limitation Act 1980; other entries retained for twelve months. - Dependency management: Dependabot enabled on GitHub. Security advisories from the django-security mailing list actioned.
- Backups: PostgreSQL point-in-time recovery via the managed database provider. Object storage backed up daily. Backups encrypted at rest.
8.2 Organisational measures
- Least-privilege administrator access to production infrastructure.
- Staff impersonation of tenant accounts requires an explicit reason and is fully audited; the two impersonation modes (transparent tier-1 and silent investigative tier-2) have distinct authentication and audit paths, with tier-2 gated behind a superuser-only platform feature flag.
- Written incident-response plan; tenants notified as required under UK GDPR Article 33 within seventy-two hours of the Processor becoming aware of a personal data breach.
- Written vulnerability-management process; external audit programme documented and phased to launch, penetration testing, and — where triggered by a customer requirement — SOC 2 Type I preparation.
The Processor may update these measures over time provided that the overall level of security is not reduced.
9. Personal Data Breach Notification
The Processor shall notify the Controller without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting the Controller's data. The notification shall include, to the extent known:
- the nature of the breach, including the categories and approximate number of data subjects and records affected;
- the likely consequences of the breach;
- the measures taken or proposed to address the breach and mitigate its adverse effects;
- the name and contact details of the Processor's contact point for further information.
Notifications will be sent to the Controller's registered account owner email address. The Controller is responsible for keeping that address current.
10. International Data Transfers
Personal data is primarily processed in the United Kingdom (DigitalOcean LON1 region). Where the Processor or a sub-processor transfers personal data across borders, the Processor ensures one of the following lawful mechanisms applies, chosen to match the applicable legal regime and the destination:
- Adequacy decisions. Transfers to countries recognised as offering adequate protection by the UK Secretary of State (e.g. EEA, Canada for commercial organisations, Israel, South Korea, Switzerland, Japan) or the European Commission (equivalent adequacy list), or under equivalent adequacy mechanisms recognised by other applicable jurisdictions.
- Standard contractual clauses. The UK International Data Transfer Addendum ("UK IDTA"), the EU Commission Standard Contractual Clauses ("EU SCCs"), the Swiss revised SCCs, and equivalent standard contract mechanisms recognised under other applicable data protection laws — each accompanied, where required, by a transfer-impact assessment.
- EU-US and UK-US Data Privacy Framework ("DPF"). Where a sub-processor is DPF-certified, transfers to the United States may rely on the EU-US DPF, the UK Extension to the EU-US DPF, or the Swiss-US DPF as appropriate.
- Approved certifications or codes of conduct. Where a sub-processor holds an approved GDPR Article 42 certification or adheres to an approved Article 40 code of conduct with binding and enforceable commitments.
- Derogations for specific situations. UK GDPR / EU GDPR Article 49 derogations (or equivalent under other laws) where no other mechanism applies. The primary case is the TTLock smart-lock integration: the transfer to the People's Republic of China is authorised by the Controller when enabling the integration and is necessary for the performance of the contract between the Controller and the data subject (Article 49(1)(b)).
For Controllers subject to laws other than UK/EU GDPR (e.g. CCPA/CPRA in California, LGPD in Brazil, PIPEDA in Canada, APA in Australia, PDPA in Singapore), TIOO applies the strictest of the safeguards required by any applicable law. The applicable mechanism for each sub-processor is set out in the table in Section 7.1.
11. Audits
The Processor shall make available to the Controller, on request, information reasonably necessary to demonstrate compliance with its obligations under this DPA and Article 28 UK GDPR, including:
- a summary of its security measures (as set out in Section 8);
- the up-to-date sub-processor list (Section 7);
- copies of relevant third-party audit reports where held (e.g. SOC 2 or ISO 27001 reports of sub-processors) subject to any confidentiality requirements imposed by those third parties.
Where the above is insufficient to demonstrate compliance, the Controller may request an on-site audit no more than once per calendar year, subject to reasonable advance notice (at least 30 days), reasonable scope, and reimbursement of the Processor's reasonable costs. The Controller shall bear the Controller's own costs. The Processor may propose an independent third-party auditor as an alternative.
12. Return and Deletion of Data
Upon termination or expiry of the Terms of Service, the Controller may request return or deletion of the personal data processed on its behalf. Unless the Controller instructs otherwise:
- the Processor shall, within thirty (30) days, delete or return all personal data and delete existing copies from active systems;
- backups containing the personal data will be purged in the ordinary course of the Processor's backup rotation, and no later than ninety (90) days;
- the Processor may retain personal data to the extent required by applicable law (e.g. financial records under UK HMRC rules) or in an aggregated / anonymised form.
ID disclosure audit-log entries and other statutorily retained records are subject to their respective retention periods as set out in the Privacy Policy.
13. Liability
Each party's liability under this DPA is subject to the exclusions and limitations of liability set out in the Terms of Service. Nothing in this DPA limits either party's liability for damages that cannot be limited under applicable law.
14. Order of Precedence, Term, and Governing Law
This DPA is effective from the Controller's acceptance of the Terms of Service or, if later, the "Last updated" date at the top of this page, and continues until the end of the Processor's provision of services to the Controller. In case of any conflict between this DPA, the Terms of Service, or any other agreement between the parties on the subject matter of data protection, this DPA prevails.
This DPA is governed by the laws of England and Wales, and each party submits to the exclusive jurisdiction of the courts of England and Wales for any dispute arising out of or in connection with this DPA. Nothing in this DPA excludes or limits mandatory rights, remedies, or protections available to the Controller or to data subjects under the mandatory rules of their local law, including consumer protection, data protection, and privacy laws in the Controller's or data subject's jurisdiction. Where local mandatory rules require a different transfer mechanism, supervisory authority, or dispute forum, those local rules apply to the extent of the mandatory requirement.
15. Contact
For questions about this DPA, to request a countersigned copy, to raise a sub-processor objection, or to invoke your audit right, contact [email protected].
Need a countersigned copy?
Email us and we'll return a signed PDF with your organisation's name and effective date within two business days.
[email protected]