When you put personal data on a guest page, GuestPorta processes that data on your behalf. The General Data Protection Regulation (GDPR) requires an agreement for this. This data processing agreement is that agreement. It forms part of our terms and conditions and applies automatically to every host who uses GuestPorta; you do not need to sign anything separately.
1. Parties and scope
This agreement is made between:
- the host, the person or company that has an account with GuestPorta, as the controller; and
- GuestPorta, Lange Kleiweg 62 d, 2288 GK Rijswijk, The Netherlands, registered with the Dutch Chamber of Commerce under number 99260034, as the processor.
It covers the personal data that the host adds to the service, mainly as content of guest pages, and that GuestPorta processes on the host's behalf. It does not cover the data that GuestPorta processes as a controller for its own purposes, such as account details, billing and form submissions on our website. That processing is described in our privacy policy.
2. Definitions
Terms such as personal data, processing, controller, processor, data subject, personal data breach and supervisory authority have the meaning given to them in the GDPR. Service, host, guest page, guest and content have the meaning given in our terms and conditions.
3. Subject and purpose
GuestPorta processes the personal data only to provide the service: to store the content, show it to guests who open a guest page, make backups, keep the service secure and support the host. Annex 1 describes the processing in more detail. GuestPorta does not use the personal data for its own purposes, does not sell it and does not use it to build profiles.
The host is responsible for the content of its guest pages, and guarantees that it has a legal basis to publish the personal data it adds, and that it informs the people concerned where the law requires it.
4. Instructions
GuestPorta processes the personal data only on the documented instructions of the host. The host gives these instructions by using the service, through its settings and through this agreement. If GuestPorta believes an instruction infringes the GDPR or other data protection law, it will tell the host and may suspend that instruction until the host confirms or changes it.
If the law requires GuestPorta to process personal data in another way, for example on the order of a competent authority, GuestPorta will inform the host first, unless the law forbids this.
5. Confidentiality
GuestPorta keeps the personal data confidential. Only people who need access to perform their work have it, and they are bound by a duty of confidentiality.
6. Security
GuestPorta takes appropriate technical and organisational measures to protect the personal data against loss and unlawful processing, taking into account the state of the art, the costs, and the nature of the data and the risks. Annex 2 describes these measures. GuestPorta may change them, as long as the level of protection does not decrease.
Guest pages are available to anyone who has the link. The host decides what it publishes on them and should not put information on a guest page that must stay private, such as copies of identity documents, payment details or special categories of personal data.
7. Sub-processors
The host gives GuestPorta general permission to engage sub-processors, such as providers of hosting, database and file storage, email delivery and support tools. GuestPorta imposes the same data protection obligations on them as those in this agreement, and remains responsible towards the host for their work.
A current list of sub-processors is available on request at hello@guestporta.com. GuestPorta informs the host at least 30 days before it adds or replaces a sub-processor. The host can object on reasonable data protection grounds within that period. If we cannot resolve the objection together, the host may cancel its subscription before the change takes effect.
8. Transfers outside the EEA
GuestPorta transfers personal data outside the European Economic Area only when an adequate level of protection is ensured, through an adequacy decision of the European Commission, such as the EU-US Data Privacy Framework, or through the standard contractual clauses approved by the European Commission, with additional measures where needed.
9. Assistance
Most requests from data subjects can be handled by the host itself, because it can change or delete the content of its guest pages at any time. If a data subject contacts GuestPorta directly, we forward the request to the host without undue delay and do not answer it ourselves, unless the host asks us to.
Where reasonable, GuestPorta helps the host to meet its obligations regarding the security of processing, personal data breaches, data protection impact assessments and prior consultation with a supervisory authority, taking into account the nature of the processing and the information available to us. If this assistance takes considerable time, we may charge reasonable costs, after agreeing them with the host in advance.
10. Personal data breaches
GuestPorta informs the host without undue delay, and where possible within 48 hours, after becoming aware of a personal data breach that affects the host's personal data. We provide the information the host needs to assess the breach and, where required, to report it to the supervisory authority and the people concerned: what happened, which data and how many people are likely affected, the likely consequences, and the measures taken or proposed.
GuestPorta takes the measures that can reasonably be expected to limit the consequences and to prevent a repeat. Reporting a breach to the supervisory authority or to data subjects is the responsibility of the host, as the controller.
11. Audits and information
On request, GuestPorta provides the host with the information needed to show that it complies with this agreement. If that information is not sufficient, the host may have an audit carried out by an independent expert bound by confidentiality, no more than once a year and with at least 30 days' notice. The audit must not unreasonably disrupt our work. The host bears the costs of the audit, unless it shows that GuestPorta seriously failed to comply with this agreement.
12. Term, return and deletion
This agreement applies for as long as GuestPorta processes personal data for the host under the terms and conditions. It ends automatically when that processing ends.
When the host's subscription ends, its guest pages go offline. For 30 days the host can ask for a copy of its content. After that period GuestPorta deletes the personal data, unless the law requires us to keep it. Backups are overwritten within a further 90 days. The obligations that by their nature continue after the end of this agreement, such as confidentiality, remain in force.
13. Liability
The liability of GuestPorta under this agreement is subject to the limitations in the liability section of our terms and conditions, insofar as the law allows.
14. Final provisions
If this agreement and the terms and conditions conflict, this agreement prevails for everything related to the processing of personal data. GuestPorta may change this agreement in the same way as the terms and conditions, with at least 30 days' notice, and never in a way that lowers the protection of the personal data. This agreement is governed by Dutch law, and disputes are submitted to the court named in the terms and conditions.
Would you like a signed copy for your records? Mail hello@guestporta.com and we will send you one.
Annex 1. Description of the processing
Nature and purpose
Storing, displaying and delivering the content of guest pages to guests, making backups, securing the service and providing support, as described in section 3.
Categories of data subjects
- the host itself, and its team members, co-hosts and staff named on a guest page;
- contact persons such as cleaners, caretakers, neighbours and emergency contacts;
- guests who open a guest page.
Categories of personal data
- names, roles, phone numbers, email addresses and messaging links;
- photos and other content that the host adds and that may show people;
- technical data of guests who open a guest page, such as IP address, browser type and the time of the visit, needed to deliver the page and keep it secure.
The service is not intended for special categories of personal data, such as health data, or for identity documents or payment details. The host does not add such data to a guest page.
Duration
For the duration of the subscription, and afterwards as set out in section 12.
Annex 2. Security measures
- All connections to the website and the service are encrypted with TLS.
- Personal data is stored with providers that encrypt data at rest.
- Access to accounts is protected by login credentials, and each host can only see and change its own content.
- Access to production systems is limited to the people who need it, uses personal accounts and is protected by two-factor authentication where the provider offers it.
- Regular backups are made so data can be restored after an incident.
- Forms and endpoints are protected against abuse, for example with rate limiting.
- Software and dependencies are kept up to date, and security updates are applied promptly.
- Incidents are handled following a fixed procedure, including the notification described in section 10.