zentrumhub_logo-removebg-preview Main Header

simplifying Travel Technology

Zentrumhub-blackfont-SVG 2 RateHawk Hotel API

ZentrumHub Data Processing Agreement

1. Parties and Definitions

This Data Processing Agreement ("DPA") is entered into between the client identified in the applicable Order Form or Master Services Agreement ("Controller") and ZentrumHub Private Limited ("Processor", "ZentrumHub"), and forms part of, and is incorporated by reference into, the Master Services Agreement ("Agreement") governing Controller's use of the ZentrumHub white-label hotel booking platform. In the event of conflict between this DPA and the Agreement on data protection matters, this DPA prevails.

Definitions (as defined in Art. 4 GDPR unless stated otherwise):

  • Personal Data — any information relating to an identified or identifiable natural person processed under the Agreement (e.g., guest booking PII).
  • Data Subject — the individual to whom Personal Data relates (typically Controller's end guests/travelers).
  • Controller — determines the purposes and means of processing; here, ZentrumHub's B2B client.
  • Processor — ZentrumHub, processing Personal Data on Controller's documented instructions.
  • Sub-processor — any third party engaged by ZentrumHub to process Personal Data in furtherance of the Agreement.
  • Applicable Data Protection Law — GDPR (Regulation (EU) 2016/679), UK GDPR, and, where the Controller or its end guests are India-nexused, the DPDP Act 2023.
  • TOMs — Technical and Organisational Measures per Art. 32 GDPR.

2. Subject Matter, Duration, Nature and Purpose of Processing

FieldDetail
Subject matterProvision of a white-label hotel booking aggregation platform (search, booking, payment facilitation, guest account management)
DurationFor the term of the Agreement, plus the deletion/return period in Section 10
Nature of processingCollection, storage, retrieval, transmission, and structured querying of booking and guest data across ~100 connector microservices on AWS EKS (ap-south-1, us-east-1, eu-west-1), Elasticsearch, DynamoDB and Aerospike
PurposeProcessing occurs solely to deliver the booking platform functionality per Controller's documented instructions in the Agreement, applicable Order Forms, and this DPA — see full detail in Annex I
Categories of Data SubjectsController's end guests/travelers; Controller's authorized platform users/administrators
Categories of Personal DataSee Annex I

3. Processor Obligations (Art. 28(3) GDPR)

ZentrumHub shall:

  1. Process only on documented instructions from Controller, including regarding international transfers, unless required otherwise by EU/member state/India law — in which case ZentrumHub will inform Controller before processing, unless prohibited from doing so (Art. 28(3)(a)).
  2. Ensure confidentiality — all personnel authorized to process Personal Data are bound by confidentiality obligations, whether contractual or statutory (Art. 28(3)(b)).
  3. Implement Art. 32 security measures — see Section 5 and Annex II (Art. 28(3)(c)).
  4. Respect sub-processor conditions — no Sub-processor is engaged without Controller's prior general or specific written authorization; sub-processor obligations are equivalent to those in this DPA (Art. 28(3)(d); see Section 4).
  5. Assist with data subject rights — taking into account the nature of processing, ZentrumHub will assist Controller in responding to Data Subject requests (access, rectification, erasure, restriction, portability, objection) via appropriate technical and organizational measures (Art. 28(3)(e); see Section 6).
  6. Assist with Art. 32–36 obligations — security, breach notification, DPIAs and prior consultation, taking into account the nature of processing and information available to ZentrumHub (Art. 28(3)(f)).
  7. Delete or return all Personal Data at Controller's choice on termination, and delete existing copies unless retention is required by law (Art. 28(3)(g); see Section 10).
  8. Provide compliance information and permit audits — ZentrumHub will make available all information necessary to demonstrate compliance with this Article and allow for, and contribute to, audits including inspections conducted by Controller or an authorized auditor (Art. 28(3)(h); see Section 9).

ZentrumHub will immediately inform Controller if, in its opinion, an instruction infringes GDPR, the DPDP Act, or other applicable data protection law.

4. Sub-processors

Controller grants ZentrumHub general written authorization to engage the Sub-processors listed in Annex III. ZentrumHub will:

  • Notify Controller of any intended addition or replacement of Sub-processors with at least 30 days' prior notice, giving Controller the opportunity to object on reasonable data-protection grounds.
  • Impose data protection obligations on each Sub-processor that are no less protective than those in this DPA, by way of a written contract.
  • Remain fully liable to Controller for a Sub-processor's performance of its obligations.

If Controller objects to a new Sub-processor and the objection is not resolved within 30 days, either party may terminate the affected Services without penalty.

5. Technical and Organizational Measures

ZentrumHub maintains the TOMs summarized below (full detail in Annex II), assessed against the risk of the processing per Art. 32(1):

  • Encryption — TLS 1.3 in transit across all service-to-service (Istio mTLS) and external traffic; AES-256 at rest across DynamoDB, Elasticsearch and Aerospike stores.
  • Access control — RBAC scoped per microservice, mandatory MFA for administrative and production access, least-privilege IAM policies, Auth0-brokered authentication.
  • Network security — WAF layer at ingress, Istio service mesh for east-west traffic policy enforcement and mTLS, network segmentation per environment/region.
  • Logging and monitoring — centralized audit logging, anomaly detection, retained per the Retention Schedule.
  • Resilience — multi-region deployment (ap-south-1, us-east-1, eu-west-1) with documented RTO/RPO targets for disaster recovery.
  • Testing — annual penetration testing plus testing on material infrastructure change (Section 9), regular vulnerability scanning.
  • Data minimization and pseudonymization — applied where consistent with platform functionality, particularly for analytics use cases.

6. Assistance with Data Subject Rights

Where ZentrumHub receives a request directly from a Data Subject relating to Controller's Personal Data, it will not respond directly (unless legally required) and will instead forward the request to Controller without undue delay, and in any event within 5 business days. ZentrumHub will provide reasonable technical assistance (e.g., data extraction from Elasticsearch/DynamoDB, account deletion via Auth0) to enable Controller to fulfil Access, Rectification, Erasure, Restriction, Portability and Objection requests within Controller's own statutory deadlines.

7. Personal Data Breach Notification

ZentrumHub will notify Controller without undue delay, and in any event within 24 hours of becoming aware of a Personal Data Breach affecting Controller's Personal Data — a shorter internal SLA than the 72-hour Art. 33 regulator deadline, to give Controller adequate time to assess and notify.

Notification will include, to the extent then known (with supplementary information provided as it becomes available):

  • Nature of the breach, including categories and approximate number of Data Subjects and records affected
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach and mitigate its effects
  • Contact point for further information (dpo@zentrumhub.com)

ZentrumHub will cooperate with Controller and provide reasonable assistance for any regulator or Data Subject notifications Controller is required to make.

8. International Transfers

Personal Data is primarily processed in the AWS region matching Controller's contracted deployment region, with multi-region failover across ap-south-1 (India), us-east-1 (United States) and eu-west-1 (Ireland) as set out in Annex I.

Where Personal Data originating in the EEA/UK is transferred to a country without an EU adequacy decision (including India and the United States):

  • EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) are incorporated by reference — Module 2 (Controller-to-Processor) governs the Controller-to-ZentrumHub transfer, and Module 3 (Processor-to-Processor) governs onward transfers from ZentrumHub to Sub-processors, per Annex III.
  • Supplementary measures apply per Section 5 (encryption in transit/at rest, access controls) to address Schrems II risk.
  • Transfers to AWS eu-west-1 or under the EU-US Data Privacy Framework (where the receiving Sub-processor is DPF-certified) rely on that adequacy mechanism instead of SCCs, where applicable.

ZentrumHub will provide a completed Transfer Impact Assessment on Controller's reasonable request.

9. Audit Rights and Penetration Testing

ZentrumHub will make available all information reasonably necessary to demonstrate compliance with this DPA, including:

  • Annual third-party penetration test summary reports, and results of any material-change-triggered re-test
  • Relevant SOC 2 Type II report sections and ISO 27001 certification status (where held)
  • Responses to a reasonable annual security/compliance questionnaire

Controllers with a documented regulatory or contractual need may request an on-site or remote audit, on 30 days' written notice, no more than once per 12-month period (absent a Personal Data Breach or regulator directive), conducted during business hours, subject to confidentiality obligations and without compromising the security or confidentiality of other clients' data. Audit costs are borne by the requesting Controller unless the audit identifies a material non-compliance, in which case ZentrumHub bears its own costs of remediation.

10. Data Return and Deletion on Termination

On termination or expiry of the Agreement, ZentrumHub will, at Controller's written election made within 30 days of termination:

  • Return all Personal Data to Controller in a structured, commonly used, machine-readable format (e.g., encrypted export from Elasticsearch/DynamoDB), or
  • Delete all Personal Data, including from backups, within 90 days, and certify deletion in writing on request.

Absent an election within 30 days, ZentrumHub will delete the Personal Data. ZentrumHub may retain Personal Data to the extent required by Applicable Data Protection Law or other legal obligation (e.g., statutory financial record-keeping), solely for that purpose, and will continue to protect it under this DPA's TOMs until deletion.

11. Liability, Term and Termination

This DPA takes effect on the effective date of the Agreement and remains in force for as long as ZentrumHub processes Personal Data on Controller's behalf. Liability of each party arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement, except that such limitations do not apply to a party's indemnification obligations for regulatory fines caused by its own breach of Applicable Data Protection Law or of this DPA.

Either party may terminate this DPA together with the Agreement in accordance with the Agreement's termination provisions. Sections 7 (Breach Notification), 9 (Audit), 10 (Return/Deletion) and 11 (Liability) survive termination to the extent necessary for their purpose.


Annex I — Details of Processing

FieldDetail
Categories of Data SubjectsGuests/travelers booking via Controller's white-label platform; Controller's authorized administrative/support users
Categories of Personal DataName, contact details (email, phone), booking dates and itinerary, payment tokenization data (not raw card data — handled by PCI-scoped payment processor), passport/ID number where required by destination property, loyalty/account identifiers, IP address, device data
Special category dataNone processed by ZentrumHub under this DPA unless separately agreed in writing (e.g., dietary/accessibility data disclosed voluntarily by guests, which is minimized and not used for profiling)
Processing operationsCollection at booking, storage, transmission to hotel/supplier systems, retrieval for itinerary management, retention per Section 10 and the client contract, deletion/anonymization at end of retention
FrequencyContinuous, transaction-driven
Processing locationsAWS ap-south-1 (primary), us-east-1, eu-west-1 — per Controller's contracted deployment region and DR configuration
DurationFor the term of the Agreement, plus retention/deletion periods in Section 10 and the client contract (max. 5 years per Section 8 of the ZentrumHub retention schedule, unless a longer period is contractually agreed)

Annex II — Technical and Organizational Measures

DomainMeasure
Encryption in transitTLS 1.3 for external traffic; Istio mTLS for all east-west service-to-service traffic across ~100 connector microservices
Encryption at restAES-256 across DynamoDB, Elasticsearch, Aerospike
Access controlRBAC per microservice; mandatory MFA for production/admin access; least-privilege IAM; Auth0-brokered authentication and session management
Network securityWAF at ingress; Istio service mesh policy enforcement; per-environment network segmentation
Logical segregationMulti-tenant data logically isolated per client at the application and query layer
Logging and monitoringCentralized audit logging via Prometheus/Grafana/Elastic APM; anomaly and intrusion detection; Alertmanager-driven incident response
Vulnerability managementRegular vulnerability scanning; annual third-party penetration test plus re-test on material infrastructure change
Business continuity / DRMulti-region active deployment (ap-south-1, us-east-1, eu-west-1) with defined RTO/RPO targets
Change managementGitLab CI/CD with mandatory review gates; infrastructure changes via Helm/Kubernetes manifests under version control
Personnel securityConfidentiality agreements for all personnel with data access; role-based least-privilege provisioning; access revocation on offboarding
Physical securityInherited from AWS data center controls (SOC 2 Type II, ISO 27001) — no ZentrumHub-operated physical data centers

Annex III — List of Sub-processors

Sub-processorLocationPurposeTransfer Mechanism
Amazon Web Services, Inc. India (ap-south-1), United States (us-east-1), Ireland (eu-west-1) Cloud infrastructure hosting — compute (EKS), storage (DynamoDB), networking SCCs Module 3; eu-west-1 transfers stay within EEA
Auth0 (Okta, Inc.) United States Identity and access management, authentication SCCs Module 3 / EU-US DPF where certified
Elastic (self-hosted on AWS infrastructure) Per AWS region above Search and content indexing Inherits AWS transfer mechanism above

ZentrumHub will update this Annex and provide the 30-day notice required by Section 4 before adding or replacing any Sub-processor. This list reflects infrastructure-level sub-processors only; client-specific payment processors or third-party suppliers integrated at Controller's instruction are addressed in the applicable Order Form.

Free ebook download

Wait — something's for you 👋

Built for travel agencies
The 5 Hidden
Costs
of Adding a New Hotel Supplier
$
$215K+integration cost
6–9 monthsper supplier
2–7% bookingsfail silently
10–15% devcapacity drain
"What CTOs and CEOs miss when they say, 'let's just integrate one more.'"
12-page report · 2026 edition

The real cost most OTAs never calculate.

Drop your work email and we’ll send you the 12-page report that breaks down where 6–9 months and $215K+ quietly disappear — free.

Your email is safe. Unsubscribe anytime.