Hotel data-processing agreement
Effective 28 September 2026. Business contact presentation updated 29 September 2026. Keep this version with your account records.
1. Parties, scope and duration
This agreement forms part of the WorkRoom service terms between the hotel business identified on the account (controller) and ArdanShield (processor), whose business contact details are shown below. It applies for the service and any necessary return, restricted retention and deletion period. ArdanShield's own account/security processing is described separately in the privacy notice.
ArdanShieldTechnology House, 9 Newton Place, Glasgow, G3 7PR
Email: workroom@ardanshield.com
Contact: 07469458428
Subject matter and purpose: providing hotel coordination, authorised support, storage, retrieval, audit, backup and agreed return/deletion. Nature: collecting, recording, organising, storing, retrieving, displaying to authorised users, exporting, correcting and deleting information. Data subjects: hotel staff, authorised users, contractor contacts and people incidentally present in approved operational records. Data types: names, work contacts, job/reporting structures, permissions, rota assignments, work/activity records, approved documents and photographs. Special-category data, criminal-offence records, guest identity/payment data and disciplinary/medical files are outside the intended service and must not be uploaded.
2. Documented instructions and confidentiality
The controller determines the purposes and lawful basis of its processing and provides required notices. Authorised account settings, use within the agreed service and verified written support requests are documented instructions. ArdanShield processes only on those instructions, including transfers, unless law requires otherwise; in that case it informs the controller before processing unless prohibited by law. It will promptly inform the controller if an instruction appears to infringe applicable data-protection law. Authorised personnel must be bound by appropriate confidentiality obligations.
3. Security measures
Measures include HTTPS transport, password hashing, server-side tenant and object permission checks, department access controls, login throttling, private object storage with authorised file access, upload limits and validation, material-action audit records, secrets outside source control, restricted deployment access, independent backups and restore checks. Access is limited by role and purpose. Measures are maintained and reviewed with regard to the risks. No security certification or guarantee against all incidents is made. Customers remain responsible for their own devices and staff access decisions.
4. Subprocessors and international transfers
The controller generally authorises Render (hosting and database), Cloudflare R2 (private files and backups) and Namecheap PrivateEmail (service email) for their stated purposes, subject to applicable processing terms and lawful transfer arrangements. ArdanShield will impose equivalent applicable data-protection obligations on subprocessors and remains responsible for their performance of those obligations.
ArdanShield will provide at least 14 days' advance written notice of a proposed new or replacement subprocessor receiving hotel personal data. The controller may raise a reasonable data-protection objection during that period. The parties will seek a suitable alternative or orderly termination and data return if the objection cannot be resolved. A restricted international transfer will take place only with an applicable lawful transfer mechanism and any required assessment or supplementary safeguards. A selected hosting region alone is not such a mechanism.
5. Assistance, incidents and assurance
Taking account of the nature of processing and information available, ArdanShield will assist with data-subject requests, security obligations, personal-data breach assessment and notifications, impact assessments and prior consultation. It will notify the controller without undue delay after becoming aware of a breach affecting its personal data, providing available information on its nature, affected records/people, likely consequences, mitigation and a contact, with updates as facts become available. Ordinary support targets do not delay breach notification.
ArdanShield will make information reasonably necessary to demonstrate these obligations available and allow and contribute to audits or inspections by the controller or its mandated auditor. Practical arrangements must protect other customers and service security and must not remove mandatory rights.
6. Return, deletion and records
At service end, ArdanShield will, at the controller's choice, return or delete operational personal data and delete existing copies unless law requires retention. The controller may request an assisted export including original uploads. At least 30 days of read access after expiry are available to arrange this. Verified deletion instructions are normally completed within 30 days. Shared user identities and separately required provider billing/legal records are handled according to their distinct purposes; this does not permit retention of unnecessary hotel operational records.
Backup copies awaiting controlled expiry remain restricted from ordinary use and ordinarily expire within 35 days. A documented legal hold or recovery incident may justify limited longer retention. Before any restoration is returned to service, completed deletion instructions must be reapplied. ArdanShield records completion and any retention exception and will provide confirmation on request. The controller can contact workroom@ardanshield.com about retention instructions, rights requests, security or closure.
Questions or requests: workroom@ardanshield.com.
