Hotel Manager Matrix
Last updated: 13 September 2026 · Part of the Terms of Service
The content of the hotel — the checks, the day's numbers, the register, the duty rota, the reports, and the team members it names — belongs to the hotel. For that content the hotel is the controller and Hotel Consult Ltd, Company No. 204073745, Sofia 1415, Bulgaria, is the processor. This agreement sets the terms of that role, as Article 28 GDPR requires. It takes effect together with the Terms of Service; on request we also provide it as a signed document.
It does not cover the data for which we are ourselves the controller — your account with us, the invoices, our own security log. That processing is described in the Privacy Policy.
| Subject matter | Provision of the Hotel Manager Matrix application |
|---|---|
| Duration | The hotel's subscription, plus the deletion window in section 9 |
| Nature and purpose | Hosting and storage of the hotel's content; task notifications by email; display of checks, registers, rotas, statistics and reports to the people the manager has authorised |
| Data | Team members: first and last name, email address, phone if given, position and department, the tasks, entries and reports that carry their name, duty shifts |
| Data subjects | The hotel's team — the people the manager invites |
| Special categories | None. The application neither asks for them nor needs them — do not enter them. |
We process this data only on the hotel's documented instructions — the Terms of Service, this agreement, and what the manager does in the application's settings are those instructions, complete. If the law of the EU or of a Member State obliges us to process beyond them, we tell the hotel before we do, unless that law forbids it. If an instruction would, in our view, break the GDPR, we say so immediately.
Access is limited to the people who need it to run the service, and each of them is bound to confidentiality by contract or by law.
Everything encrypted in transit and at rest. Passwords only as bcrypt hashes. The database and files in Frankfurt, in the EU. Each hotel sees only its own data — the rule is kept in the database itself, not on the screen, and rights follow the position. Actions that affect people and money go to a log customers cannot alter. Error reports reach Sentry with addresses scrubbed. Backups run automatically, several times a day. We review these measures regularly, and we help the hotel meet its own duties under Articles 32–36 with the information we hold.
The hotel authorises these sub-processors for its content:
| Who | What for | Where |
|---|---|---|
| Supabase | Database, sign-in and files | European Union (Frankfurt) |
| Vercel | Delivers the application to the browser | USA — EU–US Data Privacy Framework |
| Sentry | Technical errors, scrubbed before they leave | EU region |
Task emails go out from our own mail server; payments go through Stripe, for which we are the controller — both are outside this list. Each sub-processor is bound to obligations equivalent to this agreement, and we remain fully answerable to the hotel for their work. A new or replaced sub-processor is announced 30 days in advance by email or in the application; the hotel may object on reasonable data protection grounds, and if we cannot offer a way through, it may cancel the affected subscription without penalty.
Most requests the manager can answer alone: the full archive downloads from Settings, and content and accounts can be corrected or deleted in the application. Where that is not enough, we help on request. If a team member writes to us directly, we pass the request to the hotel without delay and do not answer on the merits unless the hotel asks us to.
We tell the hotel about a personal data breach affecting its content without undue delay, and no later than 48 hours after we become aware of it — what happened, whose data and roughly how much, the likely consequences, and what we have done or propose to do. That is what the hotel needs for its own duties under Articles 33–34. We document every breach and cooperate in its investigation.
The mechanics are already in the product: the archive downloads from Settings at any time, and the owner deletes the hotel whenever they choose — the application stops immediately, the data is erased at most 30 days later, and until that date one click undoes it. After the date there is no recovery, backups included, within their regular rotation. Where the law requires longer storage — the ten years for invoices — only that survives.
We provide the information needed to show this agreement is kept, and answer a reasonable written questionnaire within 30 days. An audit or inspection — by the hotel or an auditor it appoints who is not our competitor — can happen once a year, with 30 days' notice, in working hours, without disrupting the service, at the hotel's cost and under confidentiality.
The data lives in the EU. Where a sub-processor involves a transfer outside it, the transfer stands on Chapter V GDPR — an adequacy decision such as the EU–US Data Privacy Framework, or the European Commission's standard contractual clauses — as section 6 lists.
This agreement lasts as long as we process the hotel's content, and the liability rules of the Terms of Service apply to it, except where the GDPR itself says otherwise (Article 82). Bulgarian law governs. Where this agreement and the Terms of Service differ on data protection, this agreement wins. It exists in Bulgarian and English; if the versions differ, the English one prevails.
Hotel Consult Ltd · Sofia 1415, Bulgaria · matrix@hotelconsult.bg — write to us with your company details to receive this agreement countersigned.