Legal
Data Processing Addendum (DPA)
Rendezvo (City Insider)
Effective date: July 23, 2026 (provisional - updated once reviewed and approved)
This Data Processing Addendum ("DPA") is incorporated into the Master Subscription Agreement between Rendezvo, [LEGAL ENTITY NAME] ("Rendezvo") and Customer (the "Agreement") and governs Rendezvo's processing of personal information contained in Guest Data.
1. Definitions
"Personal Information" (or "Personal Data"), "business" (or "controller"), "service provider" (or "processor"), "sell," "share," and "processing" have the meanings given in the California Consumer Privacy Act as amended by the CPRA ("CCPA"), other applicable US state privacy laws ("State Privacy Laws"), and, for guests located in the EU/UK, the General Data Protection Regulation ("GDPR"). "Guest Data" means Personal Information about Customer's hotel guests processed through the Service.
2. Roles and scope
Customer is the business/controller of Guest Data; Rendezvo is Customer's service provider/processor. Details of processing:
- Nature and purpose: delivering the City Insider service to Customer's guests over WhatsApp and SMS, including receiving guest messages, generating a night-out plan with the help of a third-party AI provider, and related hosting and support, as described in the Agreement.
- Categories of data subjects: Customer's hotel guests, and Customer's personnel who administer the Service.
- Categories of Personal Information: guest phone number; messages exchanged with the City Insider; stated preferences (mood, party size, budget, timing, cuisine); the generated plan; and any hotel- or stay-context Customer chooses to provide (such as dates of stay or room type).
- Duration: the term of the Agreement plus the deletion period in Section 9.
3. Service-provider obligations (CCPA)
Rendezvo certifies that it understands and will comply with the following. Rendezvo will NOT:
- Sell or share Personal Information.
- Retain, use, or disclose Personal Information for any purpose other than performing the services specified in the Agreement, or as permitted by the CCPA.
- Retain, use, or disclose Personal Information outside the direct business relationship with Customer.
- Combine Personal Information received from Customer with Personal Information from other sources, except as permitted by the CCPA.
Customer may take reasonable and appropriate steps to ensure Rendezvo uses Personal Information consistently with Customer's obligations, and Rendezvo will notify Customer if it determines it can no longer meet its obligations under State Privacy Laws, upon which Customer may take reasonable steps to stop and remediate unauthorized use.
4. Processor obligations (GDPR)
For Guest Data of guests located in the EU/UK, Rendezvo will: process Personal Data only on Customer's documented instructions, including regarding international transfers; ensure personnel are bound by confidentiality; implement the security measures in Section 8; assist Customer with data-subject requests and its Articles 32-36 obligations; delete or return Personal Data per Section 9; and make available information necessary to demonstrate compliance. [If Guest Data crosses from the EU/UK to the US, Standard Contractual Clauses or another valid transfer mechanism must be put in place; add as Exhibit B once executed.]
5. Instructions
Rendezvo processes Personal Information only on Customer's documented instructions: the Agreement, use of the Service's features, and other written instructions. Rendezvo will inform Customer if an instruction, in Rendezvo's opinion, violates State Privacy Laws or GDPR.
6. No AI training; automated processing
Rendezvo will not use Personal Information to train, fine-tune, or improve machine-learning models without Customer's prior written consent. Rendezvo's third-party LLM provider is bound by written terms prohibiting training on, and requiring non-retention of, Personal Information. The Service does not make solely automated decisions producing legal or similarly significant effects on data subjects; the AI generates plan text as content generation and decision support, as described further in the AI & Automated Processing Disclosure.
7. Confidentiality and personnel
Rendezvo limits access to Personal Information to personnel who need it to provide the Service and who are bound by confidentiality obligations, and trains such personnel on data handling.
8. Security
Rendezvo maintains a written security program including: encryption of Personal Information in transit (TLS 1.2+) and at rest (AES-256); role-based access controls and MFA for administrative access; logging and monitoring; secure development practices; vendor risk review; and periodic testing of safeguards. SOC 2 Type II is on Rendezvo's roadmap; Rendezvo is not yet certified. [List certifications once obtained.]
9. Deletion and return
Upon termination or expiration of the Agreement, upon Customer's written request, or upon a verified guest erasure request, Rendezvo will delete or return Personal Information within [30] days, and delete remaining copies within [90] days, except where retention is required by law. Rendezvo locates and erases a guest's data by phone number across its datastore. Deletion from backups occurs on backup-rotation cycles not exceeding [90] days.
10. Subprocessors
Customer generally authorizes Rendezvo to engage subprocessors for cloud hosting, LLM inference, SMS/WhatsApp messaging delivery, database hosting, and email/form handling. Exhibit A is an illustrative, non-exhaustive current list. Rendezvo will: maintain a current subprocessor list at [URL or Exhibit A]; bind each subprocessor to obligations no less protective than this DPA; give Customer [30] days' notice of new subprocessors, during which Customer may object on reasonable data-protection grounds (if unresolved, Customer may terminate the affected services with a pro-rata refund); and remain liable for subprocessor performance.
11. Consumer and data-subject rights requests
Rendezvo will promptly (within [5] business days) forward to Customer any request it receives directly from a guest and will not respond except to direct the person to Customer. Rendezvo will provide reasonable assistance, including access, deletion, and correction capabilities in the Service, to help Customer fulfill verified requests under State Privacy Laws and GDPR.
12. Security incidents
Rendezvo will notify Customer without undue delay, and no later than [72 hours], after confirming a breach of security resulting in unauthorized access to, or acquisition of, Personal Information, providing: the nature and scope of the incident, categories and approximate volume of affected records, mitigation taken, and a contact point. Rendezvo will cooperate with Customer's notification obligations under state breach-notification laws and GDPR. Notification is not an admission of fault.
13. Audits
No more than once annually (and after a confirmed incident), Customer may assess Rendezvo's compliance by written questionnaire and review of Rendezvo's then-current security documentation [and third-party audit reports, e.g. SOC 2, once available]. On-site audits require [30] days' notice, business hours, confidentiality, and Customer's cost.
14. Liability and order of precedence
Liability under this DPA is subject to the limitations in the Agreement [including any super-cap for data-protection claims]. If this DPA conflicts with the Agreement regarding Personal Information, this DPA controls.
Exhibit A: Subprocessors (illustrative current list, confirm real names and locations before publishing)
| Subprocessor | Purpose | Location |
|---|---|---|
| [cloud hosting provider] | Cloud hosting | [location] |
| [LLM inference provider] | AI-generated plan text | [location] |
| [SMS/WhatsApp messaging provider] | Guest messaging delivery | [location] |
| [database hosting provider] | Guest data storage | [location] |
| [email/form provider] | Marketing site forms and email | [location] |