Legal
Data Processing Addendum
Archived at /legal/dpa/v1.0/. This version is never overwritten in place.
01Parties and status
This addendum is between you, the client named on the Order Form ("you", "the Controller"), and Lux Oasis Advisory & Services LLC, a company registered in the Sharjah Free Zone (SHAMS), United Arab Emirates, licence number 2645909, TRN 104722180700003 ("we", "us", "our", "the Processor").
It forms part of the Terms of Service and applies wherever we process personal data on your behalf. Where we process personal data as controller in our own right, for example the contact details of your staff who use the service, this addendum does not apply and the Privacy Policy does.
02Why this addendum exists
The main personal data that reaches us from your side is guest and reservation data visible in your property management system. We do not need it to price a listing and we limit what we take, but where we do handle it we handle it as your processor and on your instructions. This addendum sets out those instructions and our obligations.
03Roles
3.1 You are the controller of the personal data described in the Annex. You decide why and how it is processed. You are responsible for having a lawful basis for it, for the notices given to the individuals concerned, and for the accuracy of the data you give us.
3.2 We are your processor for that data. We do not select a lawful basis for it, we do not decide the purposes of processing it, and we do not answer data subject requests about it in our own name.
3.3 We are not a joint controller with you and nothing in this addendum makes us one.
04Our instructions
4.1 We process personal data only on your documented instructions. Your instructions are the Terms of Service, the Order Form and this addendum, including the Annex, plus any further written instruction you give us.
4.2 If we think an instruction breaches applicable data protection law, we will tell you and may pause that processing until it is resolved.
4.3 If we are required by law to process personal data other than on your instructions, we will tell you first unless the law forbids it.
4.4 We will not use the personal data we process for you for any purpose of our own, including improving our services, except in aggregated and anonymised form that cannot identify any individual, you, your properties or your building.
4.5 We will not sell the data, will not use it for advertising, and will not disclose it to any other client of ours.
05Confidentiality
Everyone we allow to process the data is bound by a duty of confidence, is told what they may and may not do with it, and has access only to what they need for the work.
06Security
6.1 We apply appropriate technical and organisational measures, taking account of the state of the art, the cost of implementation and the risk to individuals. Those measures are: encrypted cloud infrastructure; authenticated access with individual credentials; access limited to named personnel who need it; logging of access to client systems; and secure handling and deletion of connected account credentials.
6.2 We hold no security certification and we do not claim to meet any named security standard. If that changes we will say so.
6.3 We do not commit to any availability or uptime level in this addendum. Availability is dealt with, and expressly not warranted, in the Terms of Service.
07Sub-processors
7.1 You give us general written authorisation to appoint the sub-processors listed in the Sub-processor List published at /legal/sub-processors/, which is incorporated into this addendum.
7.2 Before adding or replacing a sub-processor we will give you at least 30 days' written notice. If you object on reasonable data protection grounds within that period, we will discuss it with you. If we cannot resolve it, you may terminate the affected service on written notice without penalty and we will refund fees paid for the period after termination.
7.3 We impose data protection obligations on each sub-processor that are no less protective than those in this addendum, and we remain responsible to you for their performance.
7.4 Some of the platforms you connect to, in particular your PriceLabs account, your property management system and your booking channels, are yours. Where we access them under your account, they are not our sub-processors. They are your own suppliers, on your own contracts, and you remain the controller in your relationship with them. The Sub-processor List distinguishes the two cases.
08Assisting you
We will, at your cost where the work is more than trivial:
- help you respond to requests from individuals exercising their rights, and pass on to you without undue delay any request we receive that relates to your data;
- help you with data protection impact assessments and any consultation with a supervisory authority, so far as the information is ours to give;
- give you the information you reasonably need to demonstrate compliance with this addendum.
09Personal data breach
If we become aware of a breach affecting personal data we process for you, we will tell you without undue delay and in any event within 48 hours of becoming aware. We will describe what happened, the categories and approximate number of records affected, the likely consequences and the measures taken or proposed. We will keep you updated as we learn more, and we will not make any public statement about a breach affecting your data without telling you first.
10International transfers
10.1 Personal data may be processed outside the UAE by the sub-processors named in the Sub-processor List, which states where each one processes.
10.2 For each transfer we rely on contractual protections in our agreement with the recipient and, where the recipient offers them, on that recipient's standard data protection clauses. Where you are subject to the EU or UK GDPR, we will enter into the relevant standard contractual clauses with you, with us as data importer or exporter as the case requires.
10.3 We do not claim to hold, and do not rely on, any adequacy decision or certification. The transfer regime under UAE Federal Decree-Law No. 45 of 2021 depends on executive regulations, and we do not assert certainty about their content or effect. We will update this clause when the position is settled.
11Deletion and return
11.1 On termination of the services, or on your earlier written request, we will delete or return the personal data we process for you, at your election, within 30 days.
11.2 We will delete existing copies unless we are required by law to keep them, in which case we will tell you what we are keeping and why, and we will keep it only for as long as required and only for that purpose.
11.3 Backups are overwritten on their normal cycle. Data in a backup is not restored into live use after a deletion request.
11.4 Credentials and access to your connected accounts are dealt with in clause 7 of the Terms of Service. Deleting a credential is not the same as your revoking our access, and you should do both.
12Audit
12.1 We will make available the information reasonably necessary to demonstrate compliance with this addendum, and will respond to a reasonable written audit questionnaire once in any twelve months.
12.2 Where a written response is genuinely not sufficient, you may audit us, or appoint an independent auditor who is not a competitor of ours, on 30 days' written notice, no more than once in any twelve months, during business hours, without disrupting our operations, and subject to confidentiality. You bear the cost unless the audit reveals a material breach by us.
13Liability
Liability under this addendum is subject to clause 15 of the Terms of Service. Nothing in this addendum increases or reduces the cap in that clause, and nothing in it limits any liability that cannot lawfully be limited.
14Order of precedence
If this addendum conflicts with the Terms of Service on a data protection matter, this addendum governs. On any other matter, the Terms of Service govern. The Order Form governs over both.
15Governing law
This addendum is governed by the same law and subject to the same jurisdiction as the Terms of Service. See clause 18 of those terms, which carries a placeholder pending selection.
16Annex: description of the processing
Complete this Annex for each client on the Order Form. Do not leave it generic.
Subject matter. Provision of revenue management services and an advisory AI agent for the Listings named on the Order Form.
Duration. The term of the Order Form, plus the deletion period in clause 11.
Nature and purpose of processing. Reading data from the Controller's connected accounts; analysing it; generating written briefings, alerts and recommendations; answering the Controller's questions; and, where the Order Form so provides, changing configuration settings inside the Controller's connected accounts.
Types of personal data.
- Contact and identification data of the Controller's personnel who use the service.
- Reservation records that may contain guest name, guest contact details, stay dates, rate paid and booking channel, where these are visible in the connected property management system.
- [PLACEHOLDER: delete or add rows to match the integration actually configured for this client. If guest identity fields are excluded from the integration, say so here in terms.]
Categories of data subject.
- The Controller's personnel.
- Guests of the Controller's properties, where reservation records are visible.
Special category data. None is requested, required or knowingly processed. Do not put special category data into the service.
Sub-processors. As listed in the Sub-processor List at the date of the Order Form.
This document has been prepared for review and requires sign-off by a qualified UAE lawyer before publication. It is not legal advice.