Data Processing Agreement
under Art. 28 of the General Data Protection Regulation (GDPR)
Effective Date: September 29, 2026
This Data Processing Agreement ("DPA") applies between the hotel or hotel group that uses LobbyFlight under our Terms of Service ("Hotel", controller) and RiFa Holding & Advertising GmbH ("LobbyFlight", processor) whenever LobbyFlight processes personal data on the Hotel's behalf.
The DPA forms part of the Terms of Service and is concluded when the Hotel accepts the Terms. It takes precedence over the Terms in all matters of data protection. Terms not defined here have the meaning given in the GDPR.
Parties
Controller
The Hotel as identified in its LobbyFlight account
Processor
RiFa Holding & Advertising GmbH
E.v. Behringstraße 14, 9500 Villach, Austria
Commercial register: Landesgericht Klagenfurt, FN611770m · VAT ID: ATU82970947
1. Subject and Duration
LobbyFlight processes personal data on behalf of the Hotel in order to provide the Service, in particular the Flight Concierge (tracking of individual guest flights, guest notifications, guest page and transport requests).
The DPA runs for as long as LobbyFlight processes personal data for the Hotel under the Terms of Service. It ends automatically when that processing has ended and the data has been deleted in accordance with section 9.
2. Nature and Purpose of the Processing
The processing comprises collecting, storing, organising, retrieving, using, transmitting and deleting personal data (Art. 4(2) GDPR), exclusively for the following purposes:
- Tracking the flights of individual guests that the Hotel (or the guest via an invitation from the Hotel) has entered
- Notifying the Hotel's staff and, where the Hotel has switched this on, the guest about flight status changes by email and web push
- Providing the guest's personal guest page with flight status, weather and departure recommendations
- Forwarding transport requests (taxi, shuttle) made by the guest to the Hotel and to the transport partners chosen by the Hotel
- Sending invitations with which the guest can enter their own flight
- Storing and, where the Hotel requests it, automatically translating content the Hotel uploads (for example info slides)
3. Types of Personal Data
Depending on how the Hotel uses the Service:
- Guest name and room number
- Guest email address and preferred language
- Flight number, flight date, direction (arrival or departure), airline, origin and destination airport, and the resulting flight status
- Transport requests: pickup time and address, number of passengers, the guest's optional note and internal notes of the Hotel
- Free-text notes the Hotel's staff add to a trip
- Time and number of visits to the guest page and the delivery status of emails to the guest (for example bounces)
- Web push subscription of the guest's browser (push service address and keys), only if the guest turns on notifications
- IP addresses of visitors to the guest page, used briefly for rate limiting
The Service is not intended for special categories of personal data (Art. 9 GDPR). The Hotel shall not enter such data, for example in free-text notes.
4. Categories of Data Subjects
- Guests of the Hotel whose flights are tracked
- Persons the Hotel invites to enter their flight
- Other persons whose data the Hotel enters into the Service (for example in notes or content)
5. Rights and Obligations of the Hotel
- The Hotel is responsible for the lawfulness of the processing, including the legal basis for tracking guest flights and for sending guest notifications, and for informing guests under Art. 13 and 14 GDPR.
- The Hotel issues its instructions primarily through the settings and functions of the Service. Further instructions shall be given in text form (for example by email to info@lobbyflight.com). Instructions that go beyond the agreed scope of the Service may be charged separately.
- Guests exercise their rights with the Hotel. The Hotel can view, correct and delete guest data itself in the portal.
- The Hotel informs LobbyFlight without undue delay if it finds errors or irregularities in the processing.
6. Obligations of LobbyFlight
- LobbyFlight processes personal data only on documented instructions from the Hotel, including with regard to transfers to third countries, unless Union or Member State law requires otherwise; in that case LobbyFlight informs the Hotel beforehand unless the law prohibits this.
- LobbyFlight informs the Hotel without undue delay if, in its opinion, an instruction infringes data protection law.
- Persons authorised to process the data are committed to confidentiality or are under an appropriate statutory obligation of confidentiality.
- LobbyFlight takes the technical and organisational measures required by Art. 32 GDPR (Annex 1). It may develop them further, provided the level of protection is not reduced.
- Taking into account the nature of the processing, LobbyFlight assists the Hotel with appropriate measures in responding to requests from data subjects (Art. 12 to 22 GDPR).
- LobbyFlight assists the Hotel in complying with its obligations under Art. 32 to 36 GDPR (security, breach notifications, data protection impact assessments, prior consultation), taking into account the information available to it.
- LobbyFlight notifies the Hotel without undue delay after becoming aware of a personal data breach affecting the Hotel's data, with the information the Hotel needs for its own notifications.
- LobbyFlight does not use the data for its own purposes and does not sell it. Aggregated usage figures without personal reference (for example the number of trips counted for billing) are not personal data within the meaning of this DPA.
7. Sub-processors
The Hotel grants LobbyFlight general authorisation to engage sub-processors. The sub-processors engaged when this DPA took effect are listed in Annex 2.
LobbyFlight informs the Hotel of any intended addition or replacement of a sub-processor at least 30 days in advance, by email or by a notice in the portal. The Hotel may object on reasonable data protection grounds within that period; if no solution can be found, either party may terminate the affected part of the Service.
LobbyFlight imposes on each sub-processor data protection obligations that offer the same level of protection as this DPA, and remains responsible to the Hotel for the sub-processor's performance.
8. Transfers to Third Countries
Some sub-processors are based in the USA or may process data there. LobbyFlight transfers personal data to a third country only if the requirements of Art. 44 et seq. GDPR are met, in particular on the basis of the EU-US Data Privacy Framework where the recipient is certified, or otherwise on the basis of the Standard Contractual Clauses of the European Commission.
9. Deletion and Return
LobbyFlight deletes personal data automatically as follows:
- Tracked flights, together with their transport requests, status history and push subscriptions: 30 days after the tracking is completed or cancelled
- Unused guest invitations: 30 days after the invitation link expires; cancelled invitations: 30 days after the cancellation
- When a trial ends without a plan, active trackings stop; the data is then deleted under the rule above
- When the Hotel closes its account: all data of its hotels, including guest data, 30 days after the closure
Before the account is closed, the Hotel may request the guest data still stored in a common machine-readable format. Data in backups of the database provider is overwritten in the provider's regular backup cycle. Statutory retention obligations remain unaffected.
10. Information and Audits
LobbyFlight makes available to the Hotel on request the information necessary to demonstrate compliance with Art. 28 GDPR, in particular this DPA, its annexes and current information on the sub-processors. The Hotel may carry out audits, or have them carried out by an auditor bound to confidentiality, after giving reasonable notice, as a rule no more than once a year, during normal business hours and without disrupting operations. LobbyFlight may charge reasonable costs for audits that go beyond the provision of documents, unless the audit reveals a material breach of this DPA.
11. Liability
Liability towards data subjects is governed by Art. 82 GDPR. Between the parties, the liability provisions of the Terms of Service apply, unless mandatory law provides otherwise.
12. Final Provisions
Amendments to this DPA are announced like amendments to the Terms of Service. Should any provision be invalid, the remaining provisions remain unaffected. This DPA is governed by the law of Austria; the place of jurisdiction is the one agreed in the Terms of Service.
Annex 1 – Technical and Organisational Measures (Art. 32 GDPR)
LobbyFlight operates no servers or data centres of its own; the Service runs on the managed infrastructure of the sub-processors listed in Annex 2. The following measures apply:
Confidentiality
- Physical access: the data centres are operated by the hosting and database providers, whose physical access controls apply.
- System access: personal user accounts; passwords are stored only as bcrypt hashes; password reset and email verification use time-limited links; LobbyFlight staff use separate administrator accounts.
- Data access: role-based permissions (organisation owner, manager, concierge); managers and concierges only have access to the hotels assigned to them; guest data is visible only to users with the flight tracking permission for that hotel.
- Guest page: reachable only through an unguessable personal link; only a SHA-256 hash of the link token is stored for lookup, plus a copy encrypted with AES-256-GCM whose key is derived from an application secret that is not stored in the database; links expire and the Hotel can renew them.
- Database: the public database API is closed (row-level security enabled on all tables, no privileges for anonymous roles); the application accesses the database only server-side.
- Separation: each record is stored with the identifiers of its hotel and organisation, and the application scopes its queries to the hotels a user may access.
- Data minimisation: flight, weather and map providers receive only flight numbers, dates, airport codes or coordinates, never guest names or contact details.
Integrity
- All connections to the Service are encrypted with TLS (HTTPS).
- Incoming payment and email delivery events are accepted only with a valid signature.
- Scheduled jobs can only be triggered with a secret token, and every run is recorded.
- Relevant actions of users in the portal are recorded in an activity log.
Availability and Resilience
- The application runs on Vercel's managed serverless infrastructure.
- The database is operated as a managed PostgreSQL service by Supabase, including the provider's automated backups.
- Automated health checks and an hourly operations watchdog monitor the flight data pipeline and the scheduled jobs.
- Rate limiting protects public endpoints, including the actions on the guest page, against abuse.
Privacy by Default and Regular Review
- Guest email notifications are off by default and are switched on by the Hotel per trip; web push requires the guest's own permission in the browser.
- The retention periods of section 9 are enforced by a daily automated deletion job.
- Changes to the Service are reviewed before deployment, and dependencies are kept up to date.
Annex 2 – Sub-processors
The following sub-processors process personal data on behalf of the Hotel:
| Sub-processor | Purpose | Data | Location / safeguard |
|---|---|---|---|
| Vercel Inc. | Hosting of the application, serverless functions and file storage | All data processed by the Service | USA · SCCs |
| Supabase Inc. | Managed PostgreSQL database incl. backups | All stored data, incl. guest data | USA (provider); database region as configured for the project · SCCs |
| Resend | Sending emails (guest notifications, invitations, transport confirmations, staff alerts) | Name and email address of the recipient, email content (flight details, link to the guest page) | USA · SCCs |
| Upstash (via Vercel KV) | Caching and rate limiting | IP addresses (only for the rate-limit window), cached flight data without guest reference | USA · SCCs |
| Anthropic | Automatic translation of info-slide texts, only if the Hotel uses this function | Slide texts entered by the Hotel; no guest data | USA · SCCs |
Web push notifications are delivered through the push service of the guest's browser vendor (for example Google, Apple, Mozilla or Microsoft). The notification content is end-to-end encrypted; the push service only receives the subscription address. The guest chooses this service by choosing the browser.
Transport partners (for example taxi companies) are chosen by the Hotel and receive the guest's name, room number, flight and requested pickup time when the guest makes a request. They are recipients on the Hotel's behalf, not sub-processors of LobbyFlight.
The following providers receive no personal data and are therefore not sub-processors: AviationStack and AeroDataBox via RapidAPI (flight data: flight numbers, dates, airport codes), OpenWeatherMap (weather: locations) and Google Maps Platform (travel times: coordinates of the hotel and the airport). Stripe processes payment data of the Hotel as part of LobbyFlight's own billing, not on behalf of the Hotel.
Contact
For questions about this DPA or about the processing of guest data, please contact us at:
RiFa Holding & Advertising GmbH
E.v. Behringstraße 14
9500 Villach, Austria
Email: info@lobbyflight.com