Data Processing Agreement
Version 2026-09-30
For customers who accepted an earlier version, this version applies from 30 October 2026.
This Data Processing Agreement ("DPA") is between the Customer (the "Controller") and Amiqa Tech AB, org. nr 559492-5744 ("Amiqa", the "Processor"). It applies automatically when the Customer accepts the Terms of Service, and meets the requirements of Article 28 of the GDPR and the Swedish Data Protection Act (dataskyddslagen, 2018:218).
1. Scope and roles
1.1 This DPA covers personal data that Amiqa processes on the Controller's behalf when providing the Services ("Customer Personal Data"). Annex 1 describes that processing.
1.2 The Controller decides why and how Customer Personal Data is processed and is responsible for having a lawful basis for it. Amiqa processes it only as the Controller's processor.
1.3 This DPA does not cover data Amiqa processes as a controller for its own purposes, such as account and billing data. The Privacy Policy covers that.
1.4 If this DPA and the Terms of Service conflict on data protection, this DPA prevails.
2. Instructions
2.1 Amiqa processes Customer Personal Data only on the Controller's documented instructions. The Terms, this DPA and the Controller's use and configuration of the Services are those instructions.
2.2 Amiqa will tell the Controller if it believes an instruction infringes data protection law.
2.3 If the law requires Amiqa to process Customer Personal Data otherwise, Amiqa will inform the Controller first, unless the law forbids it.
3. Anonymised data and AI
3.1 The Controller instructs Amiqa to anonymise Customer Personal Data where needed to produce aggregated statistics. Anonymised data cannot identify the Controller, its property or any individual, is not personal data, and Amiqa may use it to improve its products.
3.2 Amiqa does not use Customer Personal Data to train machine-learning or AI models, and does not use it to provide or improve services for any other customer.
3.3 Where an AI feature needs to send data to a third-party model provider, Amiqa sends only what the feature needs, removes personal fields where it can, and uses only providers listed as subprocessors that do not train on the data.
4. Confidentiality
Amiqa ensures that everyone authorised to process Customer Personal Data is bound by confidentiality, and gives access only to staff who need it for the Services or for support the Controller has asked for.
5. Security
5.1 Amiqa implements the technical and organisational measures in Annex 2, taking into account the state of the art, the cost and the risks to data subjects.
5.2 Amiqa may update these measures, provided the overall level of protection does not decrease.
6. Personal data breaches
6.1 Amiqa notifies the Controller without undue delay, and where possible within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data.
6.2 The notice describes, as far as known: what happened, the categories and approximate number of data subjects and records, the likely consequences, and the measures taken or proposed. Amiqa adds information as it becomes available.
6.3 Amiqa helps the Controller meet its own duty to notify the supervisory authority and data subjects. Notifying a breach is not an admission of fault.
7. Subprocessors
7.1 The Controller gives Amiqa general authorisation to use subprocessors. The current list is at amiqa.io/subprocessors.
7.2 Amiqa gives the Controller's account owner at least 30 days' email notice before adding or replacing a subprocessor.
7.3 The Controller may object on reasonable data protection grounds within those 30 days. The parties will then discuss it in good faith. If no solution is found, the Controller may terminate the affected Services with a pro-rata refund of prepaid fees.
7.4 Amiqa imposes data protection obligations on each subprocessor that are no less protective than this DPA, and remains liable for its subprocessors.
8. Transfers outside the EEA
Amiqa transfers Customer Personal Data outside the EEA only to a country with an EU adequacy decision, or under the EU Standard Contractual Clauses with any supplementary measures required. The subprocessor list states the safeguard for each transfer.
9. Assistance
9.1 Amiqa helps the Controller, as far as it reasonably can, to answer requests from data subjects exercising their rights. The Services let the Controller find, correct and export guest data itself. To delete a guest's data, the Controller asks Amiqa at support@amiqa.io, and Amiqa deletes it without undue delay, so that the Controller can meet its own deadlines under the GDPR. If a data subject contacts Amiqa directly, Amiqa forwards the request to the Controller and does not answer it itself.
9.2 Amiqa gives the Controller the information it reasonably needs for data protection impact assessments and prior consultations with a supervisory authority.
10. Deletion and return
10.1 While the subscription is active, and for 30 days after it ends, the Controller can export its bookings from the Services. When the subscription ends, Amiqa provides, on request made within those 30 days, a copy of Customer Personal Data in a common machine-readable format such as CSV.
10.2 After those 30 days, Amiqa deletes Customer Personal Data from its active systems within 30 days, unless the law requires it to be kept. Copies in backups are overwritten on the normal backup cycle, within 30 days, and are not restored in the meantime except to recover from an incident.
10.3 On request, Amiqa confirms the deletion in writing.
11. Audits
11.1 On request, Amiqa provides the information needed to show compliance with this DPA, including a description of its security measures and any available audit reports.
11.2 If that is not enough, the Controller, or an independent auditor bound by confidentiality, may audit Amiqa once a year with 30 days' notice, during business hours and at the Controller's cost. More often only after a personal data breach or where a supervisory authority requires it.
12. Term and liability
12.1 This DPA applies as long as Amiqa processes Customer Personal Data.
12.2 Liability under this DPA follows the Terms of Service, section 13, including its limits.
12.3 Swedish law governs this DPA, and the Stockholm District Court (Stockholms tingsrätt) has jurisdiction as first instance. This does not affect the Controller's right to complain to a supervisory authority, or the EU Standard Contractual Clauses where they apply.
Annex 1: Description of the processing
| Item | Description |
|---|---|
| Data subjects | The Controller's guests and bookers; the Controller's staff who use the Services; people who review the Controller's property |
| Categories of data | Name and contact details; booking details (dates, rooms, rates, number of guests, special requests); identity document details where the Controller records them for guest registration; invoices; guest messages sent through online travel agencies; reviews and the Controller's replies; staff account details and activity logs |
| Payment data | Card payments for direct bookings are handled by the payment subprocessor. Amiqa stores payment references, not full card numbers |
| Special categories | Not intended. The Controller should not enter them. Free text such as messages and reviews may contain them incidentally |
| Nature and purpose | Hosting and operating the property management system, channel connections, booking engine, revenue management and review tools for the Controller |
| Duration | The subscription, plus the export and deletion periods in section 10 |
| Location | EU (Stockholm and Frankfurt), plus the transfers listed at amiqa.io/subprocessors |
Annex 2: Technical and organisational measures
| Area | Measure |
|---|---|
| Hosting | Production databases and servers in AWS EU regions (Stockholm and Frankfurt) |
| Encryption | TLS for all traffic between users, the Services and subprocessors; encryption at rest for all databases, their backups and file storage |
| Separation between hotels | Every request is checked against the property the user belongs to. An identifier from another hotel is treated as not found |
| Access control | Role-based permissions per property, set by the Controller. Amiqa staff access to production is limited to named people |
| Network protection | Web application firewall on the public entry points; databases not reachable from the internet |
| Monitoring | Automated alarms on errors and unusual activity, reviewed by the engineering team |
| Backups | Automated database backups in the same EU region, kept 30 days (property management system) and 7 days (revenue management) |
| Secure development | Code review before release; security review is part of every change; dependency vulnerability scanning in the build pipeline |
| People | Confidentiality obligations for all staff and contractors; access removed when someone leaves |
| Incident response | Documented incident procedures; breach notice to Controllers under section 6 |
Amiqa Tech AB · Fatburs Kvarngata 24, 118 64 Stockholm, Sweden · support@amiqa.io