This Data Processing Agreement ("DPA") is entered into between the client identified in the applicable Order Form or Master Services Agreement ("Controller") and ZentrumHub Private Limited ("Processor", "ZentrumHub"), and forms part of, and is incorporated by reference into, the Master Services Agreement ("Agreement") governing Controller's use of the ZentrumHub white-label hotel booking platform. In the event of conflict between this DPA and the Agreement on data protection matters, this DPA prevails.
Definitions (as defined in Art. 4 GDPR unless stated otherwise):
| Field | Detail |
|---|---|
| Subject matter | Provision of a white-label hotel booking aggregation platform (search, booking, payment facilitation, guest account management) |
| Duration | For the term of the Agreement, plus the deletion/return period in Section 10 |
| Nature of processing | Collection, storage, retrieval, transmission, and structured querying of booking and guest data across ~100 connector microservices on AWS EKS (ap-south-1, us-east-1, eu-west-1), Elasticsearch, DynamoDB and Aerospike |
| Purpose | Processing occurs solely to deliver the booking platform functionality per Controller's documented instructions in the Agreement, applicable Order Forms, and this DPA — see full detail in Annex I |
| Categories of Data Subjects | Controller's end guests/travelers; Controller's authorized platform users/administrators |
| Categories of Personal Data | See Annex I |
ZentrumHub shall:
ZentrumHub will immediately inform Controller if, in its opinion, an instruction infringes GDPR, the DPDP Act, or other applicable data protection law.
Controller grants ZentrumHub general written authorization to engage the Sub-processors listed in Annex III. ZentrumHub will:
If Controller objects to a new Sub-processor and the objection is not resolved within 30 days, either party may terminate the affected Services without penalty.
ZentrumHub maintains the TOMs summarized below (full detail in Annex II), assessed against the risk of the processing per Art. 32(1):
Where ZentrumHub receives a request directly from a Data Subject relating to Controller's Personal Data, it will not respond directly (unless legally required) and will instead forward the request to Controller without undue delay, and in any event within 5 business days. ZentrumHub will provide reasonable technical assistance (e.g., data extraction from Elasticsearch/DynamoDB, account deletion via Auth0) to enable Controller to fulfil Access, Rectification, Erasure, Restriction, Portability and Objection requests within Controller's own statutory deadlines.
ZentrumHub will notify Controller without undue delay, and in any event within 24 hours of becoming aware of a Personal Data Breach affecting Controller's Personal Data — a shorter internal SLA than the 72-hour Art. 33 regulator deadline, to give Controller adequate time to assess and notify.
Notification will include, to the extent then known (with supplementary information provided as it becomes available):
ZentrumHub will cooperate with Controller and provide reasonable assistance for any regulator or Data Subject notifications Controller is required to make.
Personal Data is primarily processed in the AWS region matching Controller's contracted deployment region, with multi-region failover across ap-south-1 (India), us-east-1 (United States) and eu-west-1 (Ireland) as set out in Annex I.
Where Personal Data originating in the EEA/UK is transferred to a country without an EU adequacy decision (including India and the United States):
ZentrumHub will provide a completed Transfer Impact Assessment on Controller's reasonable request.
ZentrumHub will make available all information reasonably necessary to demonstrate compliance with this DPA, including:
Controllers with a documented regulatory or contractual need may request an on-site or remote audit, on 30 days' written notice, no more than once per 12-month period (absent a Personal Data Breach or regulator directive), conducted during business hours, subject to confidentiality obligations and without compromising the security or confidentiality of other clients' data. Audit costs are borne by the requesting Controller unless the audit identifies a material non-compliance, in which case ZentrumHub bears its own costs of remediation.
On termination or expiry of the Agreement, ZentrumHub will, at Controller's written election made within 30 days of termination:
Absent an election within 30 days, ZentrumHub will delete the Personal Data. ZentrumHub may retain Personal Data to the extent required by Applicable Data Protection Law or other legal obligation (e.g., statutory financial record-keeping), solely for that purpose, and will continue to protect it under this DPA's TOMs until deletion.
This DPA takes effect on the effective date of the Agreement and remains in force for as long as ZentrumHub processes Personal Data on Controller's behalf. Liability of each party arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement, except that such limitations do not apply to a party's indemnification obligations for regulatory fines caused by its own breach of Applicable Data Protection Law or of this DPA.
Either party may terminate this DPA together with the Agreement in accordance with the Agreement's termination provisions. Sections 7 (Breach Notification), 9 (Audit), 10 (Return/Deletion) and 11 (Liability) survive termination to the extent necessary for their purpose.
| Field | Detail |
|---|---|
| Categories of Data Subjects | Guests/travelers booking via Controller's white-label platform; Controller's authorized administrative/support users |
| Categories of Personal Data | Name, contact details (email, phone), booking dates and itinerary, payment tokenization data (not raw card data — handled by PCI-scoped payment processor), passport/ID number where required by destination property, loyalty/account identifiers, IP address, device data |
| Special category data | None processed by ZentrumHub under this DPA unless separately agreed in writing (e.g., dietary/accessibility data disclosed voluntarily by guests, which is minimized and not used for profiling) |
| Processing operations | Collection at booking, storage, transmission to hotel/supplier systems, retrieval for itinerary management, retention per Section 10 and the client contract, deletion/anonymization at end of retention |
| Frequency | Continuous, transaction-driven |
| Processing locations | AWS ap-south-1 (primary), us-east-1, eu-west-1 — per Controller's contracted deployment region and DR configuration |
| Duration | For the term of the Agreement, plus retention/deletion periods in Section 10 and the client contract (max. 5 years per Section 8 of the ZentrumHub retention schedule, unless a longer period is contractually agreed) |
| Domain | Measure |
|---|---|
| Encryption in transit | TLS 1.3 for external traffic; Istio mTLS for all east-west service-to-service traffic across ~100 connector microservices |
| Encryption at rest | AES-256 across DynamoDB, Elasticsearch, Aerospike |
| Access control | RBAC per microservice; mandatory MFA for production/admin access; least-privilege IAM; Auth0-brokered authentication and session management |
| Network security | WAF at ingress; Istio service mesh policy enforcement; per-environment network segmentation |
| Logical segregation | Multi-tenant data logically isolated per client at the application and query layer |
| Logging and monitoring | Centralized audit logging via Prometheus/Grafana/Elastic APM; anomaly and intrusion detection; Alertmanager-driven incident response |
| Vulnerability management | Regular vulnerability scanning; annual third-party penetration test plus re-test on material infrastructure change |
| Business continuity / DR | Multi-region active deployment (ap-south-1, us-east-1, eu-west-1) with defined RTO/RPO targets |
| Change management | GitLab CI/CD with mandatory review gates; infrastructure changes via Helm/Kubernetes manifests under version control |
| Personnel security | Confidentiality agreements for all personnel with data access; role-based least-privilege provisioning; access revocation on offboarding |
| Physical security | Inherited from AWS data center controls (SOC 2 Type II, ISO 27001) — no ZentrumHub-operated physical data centers |
| Sub-processor | Location | Purpose | Transfer Mechanism |
|---|---|---|---|
| Amazon Web Services, Inc. | India (ap-south-1), United States (us-east-1), Ireland (eu-west-1) | Cloud infrastructure hosting — compute (EKS), storage (DynamoDB), networking | SCCs Module 3; eu-west-1 transfers stay within EEA |
| Auth0 (Okta, Inc.) | United States | Identity and access management, authentication | SCCs Module 3 / EU-US DPF where certified |
| Elastic (self-hosted on AWS infrastructure) | Per AWS region above | Search and content indexing | Inherits AWS transfer mechanism above |
ZentrumHub will update this Annex and provide the 30-day notice required by Section 4 before adding or replacing any Sub-processor. This list reflects infrastructure-level sub-processors only; client-specific payment processors or third-party suppliers integrated at Controller's instruction are addressed in the applicable Order Form.
Drop your work email and we’ll send you the 12-page report that breaks down where 6–9 months and $215K+ quietly disappear — free.