Data Processing Agreement under Article 28 GDPR
This Agreement governs how Web Trade EOOD processes personal data ON BEHALF OF the hotel that uses SayFIXED — the guests' reports, the photographs and the staff accounts. The Hotel is the controller of that data and Web Trade EOOD is the processor. The Agreement is required by Article 28 of Regulation (EU) 2016/679 and is accepted together with the General Terms and Conditions, upon the creation of the hotel account.
Subject matter, scope and relationship with the General Terms and Conditions
This Data Processing Agreement (the “Agreement”) is concluded between:
- the natural or legal person who, in the course of its trade or professional activity, operates a hotel, guest house or other accommodation establishment and creates an account for it in SayFIXED, hereinafter referred to as the “Hotel” or the “Controller”; and
- Web Trade EOOD, UIC 175311817, VAT number BG175311817, with registered seat and address of management: Sofia, Druzhba residential district, block 84, apartment 34, office: Sofia, 101A Slatinska Street, e-mail: office@say-fixed.com, telephone: +359 2 488 17 34, hereinafter referred to as the “Provider” or the “Processor”.
The Hotel and the Provider are referred to jointly as the “Parties”.
The person who creates the Hotel's account and accepts the Agreement confirms that he or she is of full age, acts on behalf of the Controller and is entitled to bind it. The data by which the Controller is identified upon the creation of the account is supplemented with the full contractual and invoicing data before a paid plan is activated, without this altering the date on which the Agreement enters into force.
1.1. The Agreement governs the processing by the Provider of personal data on behalf of the Hotel in the provision of SayFIXED and constitutes a contract within the meaning of Article 28, paragraphs 3 and 9 of Regulation (EU) 2016/679 (“GDPR”).
1.2. The Agreement applies to the data contained in the reports, the photographs, the feedback contact details, the accounts of the Hotel's users and the other data which the Hotel and its users enter or generate when using the platform, where the Provider processes it for the purposes determined by the Hotel.
1.3. The data which the Provider processes as an independent controller — including the data from the public enquiry form, the contractual and invoicing correspondence, the evidence of acceptance and its own security logs — is governed by the Privacy Policy and by the applicable law, and not by this Agreement.
1.4. The Agreement forms an integral part of the contract for SayFIXED and is accepted together with the General Terms and Conditions. In the event of a conflict on a matter relating to the processing of personal data on behalf of the Hotel, this Agreement shall prevail over the General Terms and Conditions. In the event of a conflict with a mandatory provision of the applicable law, the law shall apply.
1.5. The data does not become the property of the Provider. The Hotel retains control over the data and determines the purposes, the legal bases, the permitted access and the retention periods, in so far as the platform supports them and the law permits.
Roles and documented instructions
2.1. For the processing under this Agreement, the Hotel is the controller and the Provider is the processor of personal data.
2.2. The Provider processes the personal data solely:
- for the provision, maintenance, protection and technical support of SayFIXED;
- in accordance with this Agreement, the General Terms and Conditions, the settings in the account and other documented instructions of the Hotel;
- where this is required by the applicable law, in which case it shall inform the Hotel of the legal requirement before the processing, unless the law prohibits such information on important grounds of public interest.
2.3. Documented instructions shall also include the actions of duly authorised administrators of the Hotel through the settings of the platform, as well as written requests sent through the announced support channels following appropriate authentication.
2.4. If, in the Provider's opinion, an instruction of the Hotel infringes the GDPR or another applicable data protection law, the Provider shall inform the Hotel without undue delay and may suspend the execution of the particular instruction until it is confirmed, amended or withdrawn.
2.5. The Provider shall not be entitled to use the Hotel's data for its own marketing, for the sale of data, for the creation of user profiles for third-party purposes or for the training of general-purpose models, save under a separate, lawful and express written agreement.
Nature, purpose and duration of the processing
3.1. The subject matter of the processing is the data relating to the reports of issues at the Hotel's establishment. Its nature is storage, structuring, display to authorised users, transmission within the scope of the permitted access, retrieval, archiving and erasure. The purposes are the receipt and handling of the reports, notification, management of accounts and rights, reporting and export, and the maintenance and protection of the service.
The categories of data subjects are: guests who submit a report or are mentioned in one; users of the Hotel; contact persons and authorised persons of the Hotel; persons who may incidentally appear in a photograph or in free text.
The types of personal data are: the description of the report and the related data on place and time; contact details voluntarily provided by a guest; attached photographs; data concerning the accounts of the Hotel's users; technical data necessary for authentication, security and accountability.
The service is not intended for the deliberate processing of special categories of data under Article 9 GDPR, health information, identity documents, payment data or data relating to convictions and offences.
3.2. The processing begins upon the successful creation of the Hotel's account and the acceptance of this Agreement. It continues for as long as the Provider provides the service, as well as throughout the agreed period of view-only access, export and subsequent erasure.
3.3. After the end of the trial or paid period, where there is no active paid plan, the submission of new reports ceases on the day of expiry, and the Hotel's users retain access for viewing and export for a further 14 calendar days. After that period, access to the platform is terminated. The Hotel's data is retained and is not erased automatically; erasure is carried out at the Hotel's request within 30 calendar days or in accordance with section 5 of the General Terms and Conditions.
3.4. Erasure covers the active system. Copies may remain in the backup archives until they lapse through the ordinary backup cycle. If a backup copy is restored for disaster recovery purposes, the applicable rules on the restriction of access and on erasure shall apply again.
Obligations of the Hotel as controller
4.1. The Hotel:
- determines the purposes and means of the processing and is responsible for its lawfulness;
- ensures an applicable legal basis and provides the necessary information to guests, employees and other data subjects;
- sets appropriate retention periods and access rights;
- gives only lawful, specific and reasonably feasible instructions;
- ensures that the persons who use its administrator account are duly authorised;
- does not require or encourage the entry of data which is not necessary for the management of the reports;
- does not use SayFIXED as a system for emergency calls, medical assistance, security or any other life-saving activity;
- informs the Provider in good time of incorrect settings, unauthorised access or any other circumstance which may affect the security of the data.
4.2. The Hotel must not knowingly enter, or instruct the entry of, special categories of personal data under Article 9 GDPR, data relating to convictions and offences, identity documents, payment data or health information. Should such data be entered unintentionally in free text or in a photograph, the Hotel shall review and erase it without undue delay, and the Provider shall provide reasonable technical assistance.
4.3. The Hotel is responsible for assessing whether and to what extent names, telephone numbers, e-mail addresses, photographs, free text and internal comments are necessary for the particular purpose.
Obligations of the Provider as processor
5.1. The Provider:
- processes the data only on documented instructions and only for the agreed purposes;
- ensures that the persons authorised to process the data have undertaken an obligation of confidentiality or are under an appropriate statutory obligation of confidentiality;
- implements appropriate technical and organisational measures in accordance with Article 32 GDPR;
- complies with the conditions for engaging other processors under section 9;
- assists the Hotel in responding to requests from data subjects in accordance with section 7;
- assists the Hotel in complying with the obligations under Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available to it;
- maintains the applicable records of processing activities and cooperates with the competent supervisory authority where the law so requires;
- makes available to the Hotel the information necessary to demonstrate compliance with Article 28 GDPR and allows for inspections under the conditions of section 12;
- upon termination, returns or erases the data in accordance with section 13.
5.2. The Provider does not independently determine new purposes for the processing of the data under this Agreement. Where it processes certain data for its own statutory obligation, for security, for evidencing contractual relations or for the defence of legal claims as an independent controller, it clearly distinguishes those activities and applies the relevant Privacy Policy.
Confidentiality and access
6.1. The Provider grants access to the personal data only to persons for whom such access is necessary for the performance of specific job functions, for maintenance, for security or for carrying out a lawful instruction.
6.2. Access rights are granted on the principle of least privilege, are reviewed periodically and are revoked when they are no longer necessary.
6.3. The Provider ensures that the authorised persons are informed of the confidential nature of the data and are bound by confidentiality also after the end of their involvement.
6.4. Access by the Provider's staff for support purposes is limited to what is necessary in the particular case and, where practicable, is traceable through appropriate technical records.
Data subject requests and rights
7.1. Where the Provider receives a request from a guest, an employee or another data subject concerning data which it processes on behalf of the Hotel, it shall not respond on the merits on behalf of the Hotel, unless it is expressly authorised to do so or the law requires otherwise.
7.2. The Provider forwards the request to the Hotel without undue delay, where the identity of the relevant Hotel can reasonably be established.
7.3. Taking into account the nature of the processing, the Provider assists the Hotel by means of the available functionality and appropriate technical measures in relation to requests for access, rectification, erasure, restriction, portability, objection and other applicable rights.
7.4. The Hotel is responsible for verifying the identity of the applicant, for assessing the request and for responding within the statutory period. If the request requires extraordinary technical work beyond the standard functionality, the Parties may agree reasonable costs in advance, save where the assistance is necessary as a result of a breach by the Provider.
Security and personal data breaches
8.1. The Provider implements and maintains appropriate technical and organisational measures commensurate with the risk and with the nature, scope, context and purposes of the processing. The Provider documents the measures implemented and provides a description to the Hotel upon a reasoned request, in accordance with section 12 and subject to an obligation of confidentiality.
8.2. The Provider periodically reviews the effectiveness of the measures and updates them where changes in the risk, in the service or in the applicable law so require. Such an update must not materially diminish the overall level of protection.
8.3. In the event of a personal data breach, the Provider shall notify the Hotel without undue delay after becoming aware of it. The notification shall contain, in so far as the information is available:
- a description of the nature of the breach;
- the categories and approximate number of data subjects and records concerned;
- contact details for further communication;
- the likely consequences;
- the measures taken or proposed in order to address the breach and to mitigate its possible adverse effects.
8.4. Where the information cannot be provided at the same time, it may be provided in phases without further undue delay. The Provider documents the facts, the effects and the action taken.
8.5. The Provider provides reasonable assistance to the Hotel in assessing whether notification of a supervisory authority or of the data subjects is required. The decision and the content of the notification on behalf of the Controller are the responsibility of the Hotel, unless the law provides otherwise.
8.6. Notification of an incident does not constitute an admission of fault or liability.
Other processors
9.1. The Hotel grants the Provider a general written authorisation to engage other processors (“sub-processors”) solely for the provision and protection of SayFIXED under the conditions of this section.
9.2. The current list of the sub-processors, their functions, the places of processing and the applicable international transfer mechanisms is set out in Annex 1 and is published in a place accessible to the Hotel.
9.3. Before adding or replacing a sub-processor which will process the Hotel's personal data, the Provider shall inform the Hotel and give it a reasonable opportunity to object on reasoned grounds relating to the protection of personal data.
9.4. In the event of an objection, the Parties shall use good-faith efforts to find a reasonable solution. If no such solution is possible and the change is essential for the provision of the service, the Hotel may terminate the affected service under the conditions of the General Terms and Conditions, without prejudice to amounts already due.
9.5. The Provider imposes on each sub-processor, by way of a written contract, substantially the same data protection obligations as those applicable to it under this Agreement. The Provider remains liable to the Hotel for the performance of the sub-processor's obligations in accordance with Article 28, paragraph 4 GDPR.
9.6. The Provider shall, upon a reasoned request, make available the information necessary to demonstrate compliance with this section, and may redact confidential information, trade secrets and data of other clients which is not necessary for the verification.
International transfers
10.1. The Provider does not transfer personal data outside the European Economic Area and does not allow access to it from a third country, save on the documented instruction of the Hotel or where there is a valid basis under Chapter V GDPR.
10.2. Where a transfer is based on an adequacy decision, standard contractual clauses, binding corporate rules or another permissible mechanism, the mechanism and the applicable supplementary measures shall be specified in Annex 1.
10.3. If the applicable law or the circumstances of the transfer change, the Provider shall inform the Hotel and take the measures reasonably necessary to preserve lawfulness, or shall suspend the affected transfer.
Requests from public authorities
11.1. The Provider does not voluntarily disclose data to a public authority, save on the documented instruction of the Hotel or where the law so requires.
11.2. Where it receives a binding request, the Provider shall, in so far as the law permits:
- verify the competence, the scope and the formal regularity of the request;
- disclose only the minimum data necessary;
- inform the Hotel in advance or without undue delay after the disclosure;
- document the request and the response.
Information, inspections and audit
12.1. The Provider makes available to the Hotel the information reasonably necessary to demonstrate compliance with the obligations under Article 28 GDPR, including applicable policies, summaries of inspections, certifications or security questionnaires, where available.
12.2. If the information provided is not sufficient, the Hotel may carry out an inspection itself or through an independent auditor who is bound by confidentiality and is not a competitor of the Provider.
12.3. The inspection shall be carried out following reasonable prior notice, during normal working hours, without unjustified interruption of the service and without access to data of other clients, source code, vulnerabilities or trade secrets beyond what is necessary for the inspection. In the event of an incident, a reasonable suspicion of a breach or a request from a supervisory authority, a shorter period may apply.
12.4. The Hotel shall bear the reasonable costs of an extraordinary audit, unless the audit establishes a material breach by the Provider or is necessary as a result of such a breach.
12.5. The Provider shall immediately inform the Hotel if, in its opinion, the requested inspection or instruction infringes the applicable law or the security of another client.
Return and erasure of the data
13.1. During the term of the active contract, the Hotel may use the available export tools or request an export in a commonly used machine-readable format, in so far as the relevant data and formats are supported by the platform.
13.2. Upon expiry or termination of the service, the Hotel's standard documented instruction is:
- that the submission of new reports be ceased on the day of expiry or termination;
- that access for viewing and export be retained for a further 14 calendar days, after which it be terminated;
- that the data be retained and erased at the Hotel's request within 30 calendar days or in accordance with section 5 of the General Terms and Conditions;
- that residual copies in the backup archives lapse through the ordinary backup cycle.
13.3. Until the final erasure begins, the Hotel may request an earlier return and/or erasure. The request shall be carried out following appropriate authentication, unless the law requires retention.
13.4. Following erasure, the Provider shall confirm its completion upon request. Technical data which has been irreversibly anonymised and no longer constitutes personal data is not subject to return or erasure under this section.
13.5. Contractual, accounting, payment, audit and evidentiary records which the Provider processes as an independent controller may be kept separately for the applicable statutory periods or for the establishment, exercise and defence of legal claims. They may not be used for any other incompatible purpose.
Assistance with impact assessment and prior consultation
14.1. Taking into account the nature of the processing and the information available to it, the Provider shall provide reasonably necessary assistance to the Hotel in carrying out a data protection impact assessment and in the prior consultation of a supervisory authority under Articles 35 and 36 GDPR.
14.2. The Hotel remains responsible for assessing whether such an assessment or consultation is necessary and for determining its scope.
Liability
15.1. Liability as between the Parties is governed by the General Terms and Conditions to the maximum extent permitted by law.
15.2. Nothing in this Agreement excludes or limits any liability or rights which cannot be excluded or limited under the GDPR or another mandatory provision, including the rights of data subjects and the powers of the supervisory authorities.
15.3. Each Party is liable for its own infringements of the applicable law and for the performance of the obligations assigned to it according to its role.
Entry into force, amendment and termination
16.1. The Agreement enters into force at the moment when the Hotel's account is successfully created and the authorised person accepts its version by means of the separate contractual checkbox. Clicking the link in the confirmation e-mail does not in itself constitute acceptance.
16.2. In the event of a material amendment, the Provider shall publish a new version and require a fresh acceptance where this is necessary in view of the nature of the change and the applicable law. No acceptances are created with retroactive effect.
16.3. The Agreement remains in force for as long as the Provider processes personal data on behalf of the Hotel. The sections on confidentiality, audit, liability and erasure shall continue to apply in so far as necessary after termination.
Governing law, language and contact
17.1. The Agreement is governed by Bulgarian law, without prejudice to the directly applicable provisions of the law of the European Union and to the jurisdiction of the supervisory authorities and the courts determined by the applicable law.
17.2. The Agreement may be made available in several languages. In the event of a discrepancy between a translation and the Bulgarian version, the Bulgarian version shall prevail, in so far as the law permits.
17.3. Notices under the Agreement shall be sent through the account in SayFIXED or to the contractual addresses of the Parties. The Provider's contact for questions concerning the processing and for incidents is:
Web Trade EOOD
UIC (Bulgarian company ID): 175311817
VAT number: BG175311817
Registered address: Druzhba residential district, block 84, apt. 34, Sofia, Bulgaria
Office: 101a Slatinska St, Sofia, Bulgaria
Email: office@say-fixed.com
Phone: +359 2 488 17 34
Annex 1 — Approved sub-processors
The list has been compiled following a review of the active infrastructure and of the configuration as at 16.08.2026.
| Supplier | Service and purpose | Categories of data | Location |
|---|---|---|---|
| SuperHosting.BG OOD | sending service messages by electronic mail — messages to the Hotel's users and, where the guest has provided contact details, notifications about the status of his or her report | name and e-mail address of the recipient; the content of the message, which may include the name of the hotel, the room number and the type of issue | Bulgaria |
As at the date of this Agreement, this is the only sub-processor. The processing is carried out in Bulgaria and no transfer of personal data outside the European Economic Area takes place.
Browser notifications. The platform supports notifications to the employee's browser which, when enabled, are delivered through the infrastructure of the relevant browser manufacturer. As at the date of this Agreement, this feature does not have a single active subscriber in production. When enabled, the browser provider receives solely the technical data necessary for delivery, without the content of the report, which is encrypted.
Tracking technologies on the public website. The public page say-fixed.com may load measurement and advertising technologies following the visitor's express consent. These concern data which the Provider processes as an independent controller and do not fall within the scope of this Agreement. They are governed by the Privacy Policy and the Cookie Policy.
If a given external service does not receive and has no access to personal data under this Agreement, it is not included as a sub-processor, but the decision is documented internally.
Annex 2 — Documented instructions of the Hotel
By accepting the Agreement, the Hotel instructs the Provider:
- to receive, store, structure and display the reports and the related data to the authorised users of the Hotel;
- to send the notifications permitted by the settings and by the selected contact details;
- to carry out the technical operations necessary for security, diagnostics, maintenance, backups and restoration;
- to apply the settings for roles, rights, periods, export and erasure;
- to engage the sub-processors listed in the current Annex 1;
- upon expiry or termination, to cease the submission of new reports, to retain access for viewing and export for a further 14 calendar days and thereafter to terminate it, erasing the data at the Hotel's request or in accordance with section 5 of the General Terms and Conditions, save where there is a valid instruction to the contrary or a statutory obligation.
Additional instructions may be given by an authorised administrator through the functions of SayFIXED or in writing through the announced channels following authentication. The Provider is not obliged to carry out an instruction which is unlawful, technically impossible or outside the agreed scope, unless the Parties agree the necessary change.
Terms and Conditions for the use of SayFIXED Privacy Policy Cookie Policy
Back to the home page