Data Processing Agreement (DPA)

Updated on 2026-08-24

This Data Processing Agreement ("DPA") forms an integral part of the Terms of Service of BedFlow (art. 11) and applies by operation of law to every subscription. Customers who wish to receive a signed copy can request one via info@fades-management.com.

1. Parties and subject matter

This DPA is concluded between:

  • The Customer, as identified in the subscription, hereinafter the "Controller" (art. 4.7 GDPR); and
  • Fades Management EOOD ("BedFlow"), established at Plovdiv 4000, Bulgaria, UIC/VAT BG208 607 050, hereinafter the "Processor" (art. 4.8 GDPR).

In accordance with art. 28.3 GDPR, it governs the processing of personal data of end-guests that the Processor carries out on behalf of the Controller in the context of the Service.

For the data of the Customer's own account (contact details, billing, logins), BedFlow itself acts as controller; that processing is covered by the Privacy policy and not by this DPA.

2. Duration

This DPA applies for as long as the subscription runs, extended by the 30-day export period after termination (Terms of Service, art. 10), and ends once all personal data has been erased or returned in accordance with art. 11 of this DPA.

3. Nature, purpose and scope of the processing

| Element | Description | |---|---| | Nature of the processing | Hosting, storage, structuring, consultation, transmission and erasure via the SaaS application BedFlow | | Purpose | Management of reservations, guest communication, invoicing and statutory guest registration for the Customer's properties | | Categories of data subjects | The Customer's end-guests and their fellow travellers | | Categories of personal data | Identification data (name, e-mail, phone), booking data (dates, room, price, remarks), address and billing data, communication with the Customer, legally required registration data | | Special categories | None; the Customer undertakes not to process special categories of personal data (art. 9 GDPR) through the Service |

The Processor processes this data solely on the basis of documented instructions from the Controller, as laid down in the subscription, this DPA and the configuration the Customer sets up in the Service. The Processor shall immediately inform the Customer if, in its opinion, an instruction infringes the GDPR.

4. Obligations of the Processor

The Processor:

  • processes the personal data exclusively for the purposes described in art. 3 and never for its own purposes;
  • ensures that all persons authorised to access the data under its authority are bound by a duty of confidentiality;
  • implements the technical and organisational measures described in art. 5;
  • assists the Controller, taking into account the nature of the processing, in responding to requests from data subjects (art. 12–23 GDPR) and in complying with the obligations under art. 32–36 GDPR (security, breach notification, DPIAs);
  • makes available to the Controller all information necessary to demonstrate compliance with art. 28 GDPR (art. 10 of this DPA);
  • erases or returns the data after the end of the provision of services (art. 11 of this DPA).

5. Security (art. 32 GDPR)

The Processor implements at least the following measures:

  • TLS encryption for all connections (HTTPS)
  • Encryption at rest for databases and backups
  • Role-based access control and two-factor authentication for staff
  • Daily backups, retained for 30 days
  • Logging and audit trail of access and changes
  • Regular security audits and updates
  • A documented incident-response procedure

6. Sub-processors

  • The Controller grants a general written authorisation for the engagement of sub-processors.
  • The current list of sub-processors is set out in the Privacy policy (section 6).
  • Changes (addition or replacement) are announced at least 30 days in advance by e-mail or through the Service. The Controller may object in writing, stating its reasons, within that period; if consultation does not lead to a solution, the Controller may terminate the subscription free of charge before the change takes effect.
  • The Processor imposes on every sub-processor the same data protection obligations as set out in this DPA and remains fully liable towards the Controller for their performance.

7. Processing location and international transfers

  • The application and the production database are hosted with Hostinger International on servers in Paris, France (EU).
  • Certain sub-processors process data in the United States. Those transfers are covered by Standard Contractual Clauses (SCCs), adequacy decisions where applicable (including the EU-US Data Privacy Framework) and supplementary technical and organisational measures, as described in the Privacy policy (section 7).
  • Beyond these cases, no personal data is transferred to countries outside the EEA without appropriate safeguards.

8. Personal data breaches

  • The Processor notifies a personal data breach affecting the Controller's data without undue delay and at the latest within 48 hours of becoming aware of it, to the e-mail address provided by the Customer.
  • The notification contains at least the information referred to in art. 33.3 GDPR: the nature of the breach, the categories and numbers concerned, the likely consequences and the measures taken or proposed. Information not yet available is provided in phases.
  • The Processor provides reasonable assistance with the notification to the supervisory authority (the Controller's 72-hour deadline, art. 33 GDPR) and, where required, to the data subjects (art. 34 GDPR).
  • The Processor documents every breach and the measures taken.

9. Rights of data subjects

If the Processor receives a request directly from an end-guest (access, rectification, erasure, restriction, data portability, objection), it forwards it to the Controller without delay and does not answer it itself, unless instructed to do so by the Controller. The Service provides the Controller with the functionality to handle such requests itself (access, correction, export and deletion of guest data).

10. Verification and audit

  • On request, the Processor makes available all information reasonably necessary to demonstrate compliance with this DPA.
  • The Controller may conduct (or commission) an audit at most once every twelve months, subject to 30 days' prior written notice, during office hours, without disrupting the service and at its own expense. The auditor is bound by confidentiality and may not be a competitor of the Processor.
  • Available audit reports or certifications may be submitted in place of an on-site audit.

11. Return and erasure

  • The Controller can at any time export all of its data itself in structured formats (CSV, JSON).
  • After termination of the subscription, the Controller retains 30 days of access for export. Thereafter all personal data is permanently erased; backups rotate out within the following 30 days.
  • Data subject to a statutory retention obligation (including billing data) is retained for the duration of that obligation and erased afterwards.

12. Liability

Liability under this DPA is governed by art. 8 of the Terms of Service, without prejudice to the mandatory provisions of the GDPR, including art. 82.

13. Governing law and jurisdiction

This DPA is governed by Bulgarian law, without prejudice to the directly applicable provisions of the GDPR. The courts of Plovdiv, Bulgaria have jurisdiction (Terms of Service, art. 13).


  • Version: 1.0
  • Date: 24 August 2026
  • Contact: info@fades-management.com