Legal

Data Processing Agreement (DPA)

How ResortConcierge AI processes personal data on behalf of hotels and resorts as their processor, and the data-protection commitments that govern it.

This Data Processing Agreement ("DPA") forms part of the agreement between Anchor Point Agency, LLC, a limited liability company organized under the laws of the State of South Carolina, United States, doing business as ResortConcierge AI ("ResortConcierge," "we," "us," or "our"), and the hotel, resort, portfolio, or organization that subscribes to or uses the Service (the "Customer," "you," or "your"), and governs our processing of personal data on your behalf. It applies where, in providing the ResortConcierge AI websites, applications, dashboards, APIs, integrations, documentation, and related services (the "Service"), we process personal data subject to applicable data protection laws — including the EU General Data Protection Regulation (GDPR), the UK GDPR, and U.S. state privacy laws such as the CCPA/CPRA. Under this DPA you act as the controller (or processor on behalf of your own controller) and we act as your processor (or subprocessor). This DPA supplements our Terms of Service and Privacy Policy; where a separately signed DPA or Order conflicts with this DPA for the subject it covers, that signed document controls. Capitalized terms not defined here have the meanings given in the Terms of Service or applicable data protection law.

1. Definitions

The following terms apply throughout this DPA, in addition to the definitions in our Terms of Service.

  • "Personal Data" — any information relating to an identified or identifiable natural person that we process on your behalf in providing the Service.
  • "Processing" — any operation performed on Personal Data, such as collection, storage, use, disclosure, or deletion.
  • "Controller," "Processor," "Data Subject," and "Supervisory Authority" — have the meanings given in applicable data protection law.
  • "Subprocessor" — a third party engaged by us to process Personal Data in connection with the Service.
  • "Data Protection Laws" — all laws and regulations applicable to the processing of Personal Data under this DPA, including the GDPR, UK GDPR, and applicable U.S. state privacy laws.
  • "Customer Data" — has the meaning given in the Terms of Service and includes any Personal Data contained within it.

2. Roles & scope of processing

This DPA sets out how we process Personal Data contained in Customer Data on your instructions. It determines each party's responsibilities under Data Protection Laws.

  • You are the Controller (or a Processor acting for another controller) and determine the purposes and means of processing the Personal Data you load into or generate through the Service.
  • We are your Processor (or Subprocessor) and process Personal Data only to provide the Service and on your documented instructions, including those given through the Service's configuration.
  • Your instructions are reflected in the Terms of Service, this DPA, your Order, and your use and configuration of the Service; additional instructions must be agreed in writing.
  • We will inform you if, in our opinion, an instruction infringes Data Protection Laws, unless legally prohibited from doing so.
  • You are responsible for the accuracy, quality, and legality of the Personal Data and for having an appropriate legal basis and required notices and consents for the processing.

3. Details of processing

The subject matter, nature, and purpose of the processing, and the categories of data subjects and Personal Data, are described below and further specified by your use of the Service.

  • Subject matter — provision of the ResortConcierge AI guest-experience platform and its AI features to the Customer.
  • Duration — the term of your subscription, plus the period until Personal Data is deleted or returned under this DPA.
  • Nature & purpose — hosting, storing, processing, transmitting, and generating content (including AI Output) to deliver, secure, support, and improve the Service on your instructions.
  • Categories of data subjects — the Customer's guests, prospective guests, Authorized Users, and staff whose data is processed through the Service.
  • Categories of Personal Data — contact and profile details, communications and conversation history, service requests and preferences, and usage and device data; you control whether any special-category data is submitted.
  • Special-category data — the Service is not designed to process special categories of Personal Data, and you should not submit such data except as expressly agreed and lawfully permitted.

4. Processor obligations

When processing Personal Data on your behalf, we commit to the following obligations.

  • Process Personal Data only on your documented instructions, including for international transfers, unless required to do otherwise by law (in which case we will notify you where permitted).
  • Ensure that personnel authorized to process Personal Data are bound by appropriate confidentiality obligations.
  • Implement and maintain the technical and organizational security measures described in Section 5.
  • Engage Subprocessors only in accordance with Section 6.
  • Assist you, taking into account the nature of the processing, in fulfilling your obligations to respond to Data Subject requests and to maintain security, breach notification, and data protection impact assessments.
  • At your choice, delete or return Personal Data at the end of the engagement as described in Section 12, and make available information necessary to demonstrate compliance.

5. Security measures

We maintain appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing.

  • Encryption of Personal Data in transit and, where appropriate, at rest.
  • Role-based access controls, least-privilege access, and approval workflows for sensitive actions.
  • IP masking, network protections, logging, and monitoring of the Service.
  • Measures to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems.
  • Regular testing, assessment, and evaluation of the effectiveness of these measures, and processes to restore availability after an incident.
  • You are responsible for configuring the security controls the Service makes available to you and for safeguarding your credentials.

6. Subprocessors

You provide general authorization for us to engage Subprocessors to process Personal Data in connection with the Service, subject to the conditions below.

  • We use vetted Subprocessors, such as cloud infrastructure, hosting, communications, and AI model providers, to deliver the Service.
  • We impose data protection obligations on each Subprocessor that are no less protective than those in this DPA, and we remain responsible for their performance of those obligations.
  • We maintain a current list of Subprocessors, available to you on request, and provide a mechanism for notice of intended changes.
  • You may object to a new Subprocessor on reasonable data-protection grounds; if we cannot reasonably accommodate the objection, you may terminate the affected Service as your remedy.

7. Assistance with data subject requests

Taking into account the nature of the processing, we will assist you by appropriate technical and organizational measures, insofar as possible, to fulfill your obligation to respond to requests from Data Subjects exercising their rights — such as access, rectification, erasure, restriction, portability, and objection. If we receive a request directly from a Data Subject relating to Personal Data we process for you, we will, where permitted, direct the individual to you and will not respond except on your instructions or as required by law. The Service also provides controls that allow you to access, correct, export, and delete Personal Data directly.

8. Personal data breach notification

We maintain processes to detect and respond to Personal Data breaches affecting Personal Data we process on your behalf. We will notify you without undue delay after becoming aware of such a breach and will provide information reasonably available to us to help you meet your own notification obligations, including the nature of the breach, the categories and approximate number of data subjects and records affected where known, likely consequences, and the measures taken or proposed to address it. We will cooperate with you and take reasonable steps to mitigate and remediate the breach.

9. Data protection impact assessments

Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance to help you carry out data protection impact assessments and, where required, prior consultations with Supervisory Authorities in relation to your use of the Service.

10. International data transfers

We may process and store Personal Data in the United States and other countries where we or our Subprocessors operate. Where this DPA involves a transfer of Personal Data from the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, the transfer is governed by the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), which are incorporated into this DPA by reference, together with supplementary measures where appropriate. You can contact us through our contact page for further information about the safeguards in place.

11. Audits & demonstrating compliance

We will make available to you information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. To minimize disruption and protect the confidentiality and security of other customers, audits are subject to reasonable notice, scope, frequency, and confidentiality conditions, and may, where appropriate, be satisfied through up-to-date certifications, third-party audit reports, or completed security questionnaires that we make available.

12. Return & deletion of personal data

Upon termination or expiry of the Service, and at your choice, we will delete or return Personal Data we process on your behalf and delete existing copies, unless retention is required by applicable law. You should export any Personal Data you wish to retain before the end of the engagement using the Service's export controls. Residual copies in routine, secure backups will be deleted in accordance with our backup-rotation schedule, and such copies remain subject to the confidentiality and security obligations of this DPA until deleted.

13. Liability & order of precedence

Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service or your Order. This DPA forms part of, and is subject to, the Terms of Service and any applicable Order. In the event of a conflict between this DPA and the Terms of Service regarding the processing of Personal Data, this DPA controls; a separately signed DPA or Order controls over this DPA for the subject it covers.

14. Contact & effective date

This DPA is entered into with Anchor Point Agency, LLC, a South Carolina limited liability company doing business as ResortConcierge AI. To put a signed DPA in place, request our current Subprocessor list, or ask questions about our data-processing commitments, contact Anchor Point Agency, LLC through our contact page. Last updated: June 14, 2026.

Frequently Asked Questions

Need to execute a DPA?

Contact our team and we'll get the agreement in place for your account.