新機能SympleHost アカウントを Claude、ChatGPT などあらゆる AI アシスタントに接続。MCP を見る

Data Processing Agreement

How we handle personal data on your behalf, and the responsibilities we share in keeping it protected.

Version: · Singapore

Need a DPA for your organization?

Contact our privacy team to arrange execution, request the applicable subprocessor list, or discuss transfer safeguards. Include your organization’s legal name and SympleHost account email.

Contact privacy@symplehost.ai

1. Parties and scope

This Data Processing Agreement (“DPA”) is between ALPHA GAMMA PTE LTD, a Singapore company (UEN: 202505375R), trading as SympleHost (“SympleHost”, “we”, or “us”), and the customer identified in the applicable service agreement or order (“Customer” or “you”). It applies to personal data we process on your behalf to provide the SympleHost services (“Customer Personal Data”).

This DPA takes effect when incorporated into a service agreement or otherwise agreed in writing by both parties. Publication of this page alone does not execute an agreement. It supplements the applicable service agreement, including the Terms of Service, and remains in effect for as long as we process Customer Personal Data.

Under Singapore’s Personal Data Protection Act 2012 (“PDPA”), you act as the organization responsible for the data and we act as a data intermediary when processing it on your behalf and for your purposes. Where the EU or UK GDPR applies, you act as controller and we act as processor. If you process data for another controller, we act as your subprocessor and you must have authority to instruct us on that controller’s behalf.

Processing for which we independently determine the purposes, such as managing our own billing and business contacts, is described in our Privacy Policy.

2. Applicable law and definitions

“Applicable Data Protection Law” means the privacy and data protection laws applicable to the processing under this DPA, including the Singapore PDPA and, where applicable, the EU General Data Protection Regulation (“GDPR”) and UK GDPR and Data Protection Act 2018, as amended. Terms such as “personal data”, “controller”, “processor”, and “data subject” have the meanings given in the applicable law. A “personal data breach” is a security breach resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. A “subprocessor” processes that data on our behalf.

3. Your instructions and responsibilities

We will process Customer Personal Data only on your documented instructions to deliver the agreed services, including instructions concerning transfers. Those instructions comprise the service agreement, this DPA, your configuration and use of enabled features, and additional written instructions agreed with us. Schedule 1 describes the processing.

You are responsible for lawful collection and use of the data, required notices, a valid legal basis or consent where required, and ensuring your instructions comply with Applicable Data Protection Law. You control who can access your account and which integrations and features you enable.

We will tell you immediately if, in our opinion, an instruction infringes Applicable Data Protection Law and may suspend the affected processing while the parties resolve it. If applicable law requires processing outside your instructions, we will inform you before processing unless the law prohibits that notice.

4. Confidentiality and security

We will ensure that people authorized to process Customer Personal Data are bound by contractual or statutory confidentiality duties and may access it only as necessary for their authorized work.

We will implement and maintain reasonable security arrangements and technical and organizational measures appropriate to the processing risks, including Schedule 2. These must meet applicable PDPA protection obligations and, where applicable, Article 32 of the GDPR or UK GDPR. We will consider the nature and sensitivity of the data, available technology, implementation costs, and risks to individuals. Changes must not materially reduce the protection of Customer Personal Data.

5. Subprocessors

You authorize the subprocessors identified in the list supplied to you when this DPA is agreed. We will provide their identities, processing functions, and processing locations before authorization. Contact our privacy team for the list applicable to your services.

We will notify you in writing at least 30 days before adding or replacing a subprocessor, giving you the opportunity to object on reasonable data protection grounds before it processes your data. If you object, we will work with you on an alternative. If no reasonable solution is available, either party may terminate the affected service before the proposed subprocessor receives the data, with a proportionate refund of unused prepaid fees for that service.

We will assess each subprocessor and bind it by written obligations providing equivalent protection for Customer Personal Data. We remain responsible to you for its performance of those obligations. A service you contract with directly, such as a booking channel or payment provider, may have a separate role under its own agreement; connecting it does not automatically make it our subprocessor.

6. Data rights and compliance assistance

Taking account of the processing and information available to us, we will assist you with appropriate measures to respond to requests to exercise rights under Applicable Data Protection Law, including access, correction, and withdrawal of consent, and deletion, restriction, portability, or objection where applicable. If a request concerning your data reaches us directly, we will promptly refer it to you and will not respond substantively without your instructions unless legally required.

We will assist with your obligations concerning security, breach assessment and notification, data protection impact assessments, and consultation with supervisory authorities, including Articles 32–36 of the GDPR or UK GDPR where applicable. You remain responsible for decisions about requests and required regulatory submissions.

7. Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data and, where the PDPA applies, without undue delay after we have credible grounds to believe such a breach has occurred. Notice will be sent to your designated contact or account administrator, whose details you must keep current.

As information becomes available, we will describe the breach, affected categories and approximate numbers of individuals and records, likely consequences, measures taken or proposed to address it, and a follow-up contact. We may provide information in stages without undue further delay. We will investigate, take reasonable steps to limit harm, and cooperate with your assessment, response, and notification obligations.

8. International transfers

SympleHost is based in Singapore. Providing the services may involve processing in Singapore and other countries. We will disclose relevant processing locations and comply with applicable transfer restrictions, including the PDPA’s requirements for overseas transfers where applicable. We will ensure that transferred data receives the protection required by Applicable Data Protection Law.

We will not make a restricted transfer unless a valid transfer mechanism and any necessary supplementary safeguards are in place. Where required for EEA transfers, the parties must complete and enter into the applicable European Commission Standard Contractual Clauses, including the appropriate module and annexes. UK restricted transfers require an applicable UK International Data Transfer Agreement or UK Addendum, unless another valid mechanism applies.

We will assist with necessary transfer assessments. This page alone does not execute those instruments or establish that they are already in place.

9. AI features and connected services

When you enable AI features, processing Customer Personal Data for summaries, suggested replies, and other requested outputs is subject to the same instructions, security, subprocessor, and transfer obligations as other processing under this DPA. This DPA does not authorize use of Customer Personal Data to train general-purpose AI models. You are responsible for reviewing outputs and for lawful instructions and disclosures through integrations you enable. An AI provider processing data on our behalf must be covered by Section 5.

10. Return and deletion

At the end of the relevant services, we will, at your choice, return or delete Customer Personal Data and delete remaining copies, unless applicable law requires retention. Please give export instructions within the 30-day export request window in the Terms of Service. That window does not remove our obligation to return or delete data under this DPA.

We will confirm the applicable return and deletion schedule with you. Data retained under a legal obligation must be limited to that purpose and remain protected. Backup copies awaiting deletion must be isolated from ordinary use and deleted through the applicable backup lifecycle; if restored for recovery, deletion instructions must be reapplied. On request, we will confirm completion and identify any legally required retention. This DPA continues to protect retained data.

11. Information and audits

We will make available information necessary to demonstrate compliance with this DPA and applicable data intermediary or processor obligations, and allow and contribute to audits and inspections by you or your appointed independent auditor. The parties will agree reasonable arrangements for notice, scope, confidentiality, and security, protecting other customers’ data and limiting unnecessary disruption. These arrangements must not prevent a legally required audit, an urgent investigation, or a supervisory authority from exercising its powers.

12. Relationship to other terms

This DPA takes precedence over conflicting service terms for processing Customer Personal Data. Mandatory transfer clauses prevail where they conflict with this DPA. Otherwise, the service agreement’s liability and dispute provisions apply, including Singapore governing law, subject to mandatory law. Nothing in this DPA limits individuals’ statutory rights or either party’s direct legal responsibilities. Changes to an agreed DPA must be agreed in writing; updating this webpage alone does not amend an executed version.

Schedule 1. Processing details

Subject matter and purpose
Providing the SympleHost services selected by the Customer: managing properties, reservations, guest communications, operational tasks, and connected services, together with requested support and AI assistance.
Nature of processing
Receiving, organizing, storing, retrieving, updating, analyzing, transmitting, exporting, and deleting data to carry out the Customer’s instructions.
Duration and frequency
Processing on an ongoing basis during the service term and for the limited period needed to return or delete data, subject to legally required retention under Section 10.
People whose data is processed
The Customer’s guests, prospective guests, property owners, staff, contractors, and other contacts whose data the Customer supplies or directs us to process.
Categories of personal data
Names and contact details; reservation and stay information; guest messages and preferences; property and task records linked to individuals; payment references and transaction status; and technical records associated with service use. The actual data depends on selected features and integrations.
Sensitive data
Special-category data and criminal-offence data are outside the intended scope unless specifically agreed in writing with appropriate safeguards. The Customer must avoid submitting unnecessary sensitive information, including in messages or free-text fields.
Customer rights and obligations
As set out in this DPA and the service agreement, including determining lawful purposes, providing instructions, managing access, and choosing return or deletion.

Schedule 2. Security measures

The following are the security obligations under this DPA. Specific implementation details and evidence applicable to your services can be requested from our privacy team.

  • Access and confidentiality. Limit access to authorized people according to their duties, use secure authentication, review access rights, and remove access when no longer needed.
  • Data protection. Protect data in transit with HTTPS/TLS and sensitive data at rest with encryption; manage access to credentials and secrets.
  • Service resilience. Maintain measures for availability, recovery, and restoration of access after an incident, including protected backups and recovery procedures appropriate to the service.
  • Operational security. Assess risks, address vulnerabilities, maintain relevant security records, and regularly evaluate the effectiveness of safeguards.
  • People and suppliers. Maintain confidentiality obligations, data protection awareness, and review of providers entrusted with Customer Personal Data.
  • Incident handling and disposal. Maintain procedures to investigate and respond to incidents and to return or securely delete data in accordance with this DPA.

Contact

ALPHA GAMMA PTE LTD · Singapore
Privacy enquiries: privacy@symplehost.ai