Data Processing Agreement
Last updated · 1 May 2026
How AURI processes personal data on your behalf under GDPR Article 28 and UAE / Saudi PDPL.
This Data Processing Agreement ("DPA") forms part of the Service Agreement between Maciej Adamski Sp. z o.o. ("Processor", "AURI") and the Customer ("Controller"). It governs the processing of personal data by AURI on behalf of the Customer in connection with the AURI hotel SPA management system. The DPA is automatically incorporated when the Service Agreement is signed — no separate signature required.
Scope of processing
The Customer remains the data controller and is responsible for establishing the lawful basis for processing.
Categories of personal data
— Guest personal data — name, contact details (email, phone), date of birth, language preference, room number where applicable.
— Treatment-related data — selections, scheduling preferences, allergies and contraindications (medical SPA tier), staff notes.
— Payment data — processor tokens only. Full card numbers are never stored by AURI (handled by Stripe / Tap).
— Marketing consent flags.
— Booking history and operational records.
Exact data categories depend on the modules each Customer enables.
Purposes of processing
— Operate the booking and resource management system as configured by the Customer.
— Send transactional notifications (booking confirmations, reminders, cancellation notices) per Customer configuration.
— Generate reports and analytics for the Customer's own use.
— Support the Customer's own GDPR / PDPL obligations (data-subject access requests, erasure requests, exports).
Security measures
— Data isolation — each Customer receives a dedicated database and dedicated Google Cloud project.
— Encryption — data encrypted at rest (Google Cloud default disk encryption, AES-256, plus application-level AES-256-GCM on VIP guest PII) and in transit (TLS 1.2+).
— Authentication — bcrypt password hashing (cost 12), server-side sessions, configurable timeouts, optional MFA.
— API security — bearer-token authentication with constant-time comparison to prevent timing attacks.
— Audit logging — all administrative actions logged for traceability.
— Backups — daily automated snapshots, 30-day retention, point-in-time recovery.
— Network — HTTPS enforced in production, HTTP redirected to encrypted connections.
Full security documentation lives at /legal/security.
Sub-processors
AURI uses the following sub-processors to deliver the Service. Each operates under their own DPA and applicable data-transfer mechanisms.
| Sub-processor | Purpose | Data category | Region |
|---|---|---|---|
| Google Cloud Platform | Infrastructure hosting | All processed data | EU (Frankfurt) or GCC (Doha / Dammam), per Customer config |
| Stripe | Payment processing (EU / global) | Payment tokens, transaction metadata | EU + US (under SCCs) |
| Tap Payments | Payment processing (GCC / MENA) | Payment tokens, transaction metadata | UAE (regional) |
| Twilio | SMS and WhatsApp notifications | Phone numbers, message content | US (under SCCs) |
| Resend | Email notifications | Email addresses, message content | US (under SCCs) |
AURI gives 30 days' notice of any new or changed sub-processor via the privacy@auri-system.com mailing list. Customers may object within 30 days, in which case AURI will either replace the sub-processor or allow the Customer to terminate the affected Service without penalty.
International data transfers
For GCC Customers requiring data-localisation, AURI configures the GCP region to a GCC region (Doha,
me-central1, or Dammam, me-central2).Breach notification
— Nature of the breach.
— Categories and approximate number of data subjects affected.
— Likely consequences.
— Measures taken or proposed to address the breach and mitigate harm.
The Customer, as controller, remains responsible for notifying the supervisory authority within 72 hours where required (GDPR Art. 33) — AURI assists with the technical detail and scope assessment.