Staysi legal
Data Processing Addendum
Data-processing terms for customer personal data handled by Staysi.
For Staysi host customers acting as controllers/businesses.
Effective and version date: August 25, 2026 · Version 2026-08-25
1. Scope and roles
This Data Processing Addendum (DPA) forms part of the agreement between the Staysi customer (Customer) and Staysi for use of the services. It applies when Staysi processes personal data on behalf of Customer (Customer Personal Data).
Customer is the controller/business or other party determining the purposes and means of processing Customer Personal Data, and Staysi is the processor/service provider, except where applicable law assigns different terminology. Each party is independently responsible for processing it performs as its own controller/business.
2. Customer instructions
Staysi will process Customer Personal Data only on documented Customer instructions, including the agreement and Customer configuration/use of the service, unless law requires otherwise. If legally permitted, Staysi will notify Customer before processing required by law.
3. Processing details
- Subject matter: operating Staysi guest communication, property/stay information, smart-home scenes, notifications, support, security, and related services configured by Customer.
- Duration: for the term of the agreement plus limited retention/deletion periods, subject to legal retention requirements.
- Data subjects: Customer users, property owners/managers where applicable, booking guests, travel-party members whose data Customer provides, and persons communicating about a stay.
- Data categories: identity/contact information, reservation/stay information, property and access information, communications and requests, support content, device/session identifiers, integration metadata, and other information Customer submits to the service.
- Sensitive data: Staysi is not designed for Customer to intentionally submit special-category or highly sensitive data unless necessary for a supported stay/safety workflow. Customer should minimize such data.
4. Confidentiality and security
Staysi will ensure personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations and will maintain reasonable technical and organizational measures appropriate to the risk, including access controls, encryption in transit, protected credentials/tokens, logging, backups, vulnerability/dependency management, and incident-response procedures.
5. Subprocessors
Customer gives Staysi general authorization to engage subprocessors. Staysi will impose data-protection obligations appropriate to the services each subprocessor performs and remains responsible for its subprocessor obligations as required by applicable law and the agreement. The current list is in the Subprocessor Register.
Where applicable law or Customer’s order requires advance notice of a new subprocessor, Staysi will provide reasonable notice through the account email or another documented channel. Customer may object on reasonable data-protection grounds through Host Support.
6. Data-subject requests
Taking into account the nature of processing, Staysi will provide reasonable assistance to Customer with data-subject requests concerning Customer Personal Data. Hosts can use the Privacy & data controls to request access, correction, or deletion. Staysi may require reasonable verification and may preserve records that law permits or requires it to retain.
7. Security incidents
Staysi will notify Customer without undue delay after becoming aware of a confirmed personal-data breach affecting Customer Personal Data where notification is required by applicable law. Notification will include information reasonably available concerning the nature of the incident, affected data, likely consequences, mitigation, and a contact route. Notification is not an admission of fault or liability.
8. Deletion and return
At the end of the service, Staysi will delete or return Customer Personal Data in accordance with Customer instructions, available product controls, the retention schedule, and applicable law. Backup copies may persist until overwritten under the applicable backup lifecycle and remain protected while retained.
9. International transfers
Where Customer Personal Data is transferred internationally and applicable law requires a transfer mechanism, the parties will use an appropriate lawful mechanism and supplementary safeguards as required.
10. Audits and information
Staysi will make information reasonably necessary to demonstrate compliance with applicable processor obligations available to Customer and will support reasonable audits where legally required, subject to confidentiality, security, scope, frequency, and cost protections appropriate to the service.
11. California service-provider restrictions
Where the California Consumer Privacy Act applies and Staysi acts as a service provider or contractor, Staysi will not sell or share Customer Personal Data, retain/use/disclose it outside the business purposes specified by the agreement except as permitted by law, or combine it with personal information from other sources except as legally permitted. Customer may take reasonable steps required by law to help ensure compliant use.
12. Precedence and contact
If this DPA conflicts with the agreement on processing Customer Personal Data, this DPA controls to the extent of the conflict. Customers can use Privacy & data for formal privacy requests and Host Support for DPA or security questions.