Ultra Guest
Data Processing Agreement
The Data Processing Agreement template (controller-to-processor). Hotel-specific fields show neutral placeholders here and are completed per hotel in the signed agreement; the sub-processor table renders from the live register.
AI-authored draft, published live per operator instruction; a legal-counsel review is running in parallel.
This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Ultra Guest Platform Services Agreement, order form, or other master commercial agreement (the "Main Agreement") between:
- the hotel legal name, of the hotel address, the property country (the "Controller", "Hotel", or "you"); and
- Ultra Hospitality, of 14 Syria St., Mohandessin, Giza, Egypt (the "Processor", "Ultra Guest", or "we"),
each a "Party" and together the "Parties".
This DPA records the terms on which Ultra Guest processes Personal Data on behalf of the Hotel in connection with the Ultra Guest multi-tenant guest-commerce and AI-concierge platform (the "Platform"). It is entered into to satisfy the obligations of the Hotel as a data controller and Ultra Guest as a data processor under Applicable Data Protection Law, including Egypt's Personal Data Protection Law (Law No. 151 of 2020) and its Executive Regulations ("PDPL") and, where applicable to guests or processing in the GCC, the data protection laws of the relevant jurisdiction.
This DPA takes effect on the effective date or, if later, on the effective date of the Main Agreement.
1. Definitions
1.1. Terms used but not defined in this DPA have the meaning given in the Main Agreement. Where a term is defined both here and in the Main Agreement, the definition in this DPA controls for the purposes of this DPA.
1.2. For the purposes of this DPA:
- "Applicable Data Protection Law" means all laws and regulations relating to the processing and protection of Personal Data that apply to a Party, including the PDPL, the rules and decisions of the Egyptian Data Protection Center, the Consumer Protection Law (Law No. 181 of 2018) to the extent it governs guest data and communications, and any equivalent or successor data protection law in the property country or any GCC jurisdiction in which the Hotel operates or in which Data Subjects are located.
- "Controller", "Processor", "Data Subject", "Personal Data", "Sensitive Personal Data", "Processing" (and "Process" / "Processed"), and "Personal Data Breach" have the meanings given to them (or their nearest equivalents) under the PDPL, and references to a "controller" / "processor" are to be read as references to the "data controller" / "data holder/processor" roles recognised under the PDPL.
- "Data Subject Request" means a request from, or on behalf of, a Data Subject to exercise rights under Applicable Data Protection Law, including rights of access, rectification, erasure, restriction, objection, withdrawal of consent, and data portability.
- "Sub-processor" means any third party engaged by Ultra Guest (or by another Sub-processor) to Process Personal Data on the Hotel's behalf under this DPA.
- "Services" means the Platform and related services provided by Ultra Guest under the Main Agreement.
2. Roles of the Parties; relationship to the Main Agreement
2.1. Roles. With respect to the Personal Data Processed under the Services, the Hotel is the Controller and Ultra Guest is the Processor. The Hotel determines the purposes and means of the Processing; Ultra Guest Processes Personal Data only on the Hotel's behalf and on its documented instructions, except where Ultra Guest is required to Process by a law to which it is subject (in which case it will inform the Hotel of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest).
2.2. Merchant of record. The Parties acknowledge that, in the underlying commercial relationship, the Hotel is the merchant-of-record and the provider of the hospitality goods and services sold through the Platform, and Ultra Guest acts as a technology platform and disclosed commercial agent earning a net commission of the agreed. This allocation does not change the data-protection roles set out in clause 2.1.
2.3. Independent controller activities. Ultra Guest acts as an independent controller (and not as the Hotel's Processor) only for the limited activities for which it determines purposes and means in its own right, namely: platform account and access management for Hotel personnel; security, fraud-prevention, abuse-prevention, and audit logging at the platform layer; billing, commission reconciliation, and tax records between the Parties; and aggregated or de-identified analytics that do not identify any Data Subject. Such activities are governed by Ultra Guest's own privacy notice and are outside the scope of this DPA except as expressly stated.
2.4. Order of precedence. In the event of any conflict or inconsistency between the documents forming the agreement between the Parties, the following order of precedence applies, from highest to lowest: (a) this DPA, solely with respect to the subject matter of the Processing of Personal Data; (b) the Main Agreement; and (c) any order form, schedule, or policy referenced by either. Except as expressly modified by this DPA, the Main Agreement remains in full force and effect, and nothing in this DPA reduces any obligation Ultra Guest owes the Hotel under the Main Agreement in relation to data protection or security.
3. Subject-matter, duration, nature, and purpose of Processing
3.1. Subject-matter. The subject-matter of the Processing is the Personal Data of the Hotel's guests, prospective guests, and other Data Subjects, Processed by Ultra Guest to provide the Services.
3.2. Duration. Ultra Guest will Process Personal Data for the term of the Main Agreement and for any period thereafter during which Ultra Guest is required or permitted to retain Personal Data under clause 11 (Return and deletion) or under Applicable Data Protection Law.
3.3. Nature and purpose. The nature and purpose of the Processing is to operate the multi-tenant guest-commerce and in-stay concierge/booking Platform on behalf of the Hotel, including: presenting offers and ancillary products; operating the cart, session, order, and AI-concierge conversation thread; recording guest acceptance of room upsell, stay-extension, discounted-room, and in-room add-on offers and routing confirmation to the Hotel's booking/PMS workflow; processing payments through enabled gateways; hosting hotel-branded operational guest communications; maintaining a double-entry ledger and reconciling commission; providing multilingual (Arabic and English first) content and AI-assisted concierge responses grounded in Hotel-provided facts; and providing related support, security, and analytics.
3.4. Processing operations. The Processing may include collection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission to enabled Sub-processors and to the Hotel's booking/PMS and payment systems, restriction, erasure, and destruction.
4. Categories of Data Subjects and Personal Data
4.1. Categories of Data Subjects. The Personal Data Processed under this DPA concerns the following categories of Data Subjects:
- Hotel guests and prospective/booking guests (including the named booker and accompanying guests on a pre-arrival guest list);
- Individuals who interact with the Platform's explore site or AI concierge without completing a booking; and
- The Hotel's authorised users and staff to the extent their data passes through the Services (in which case clause 2.3 may apply).
4.2. Categories of Personal Data. The Personal Data Processed may include:
- Identity and contact data: name, email address, telephone number, country of residence, language preference, and loyalty or membership identifiers;
- Booking and stay data: reservation reference, property, room type, arrival/departure dates, occupancy, and pre-arrival guest-list entries;
- Transaction data: order and cart contents, offers accepted, amounts, currency, commission allocation, payment status, and partial card or wallet metadata (Ultra Guest does not store full primary account numbers; these are handled by PCI-compliant payment Sub-processors);
- Communications and interaction data: AI-concierge conversation threads, support messages, consent and preference records, and device, log, and usage metadata; and
- Guest-preference data and, where the guest provides it, special-requirement data such as dietary preferences and allergen information, which the Parties treat with elevated care under clause 6.
4.3. Sensitive Personal Data. The Services are not designed to collect Sensitive Personal Data within the meaning of the PDPL except for allergen and dietary special-requirement data voluntarily provided by guests for service-safety purposes. The Hotel must not instruct Ultra Guest to Process any other category of Sensitive Personal Data through the Services without a prior written agreement specifying the additional safeguards required.
5. Hotel (Controller) obligations and instructions
5.1. Lawful instructions. The Hotel warrants that it has a valid legal basis under Applicable Data Protection Law (including, where required, freely given, specific, informed, and unambiguous consent) for the Processing it instructs, and that its instructions to Ultra Guest comply with Applicable Data Protection Law. The Hotel is responsible for the accuracy, quality, and legality of the Personal Data it or its guests provide and for the means by which it acquired that data.
5.2. Documented instructions. The Hotel's documented instructions are set out in this DPA, the Main Agreement, the configuration choices the Hotel makes in the Platform admin console (including enabled payment gateways, languages, retention settings, and communication templates), and any further written instructions the Parties agree. Ultra Guest will notify the Hotel if, in its opinion, an instruction infringes Applicable Data Protection Law.
5.3. Guest-facing transparency and consent. The Hotel is responsible for providing required privacy notices to its guests and for obtaining and recording any consent required for the Processing, including for hotel-branded marketing communications and for loyalty/booking-incentive participation. Ultra Guest will provide platform features to support consent capture and record-keeping.
6. Ultra Guest (Processor) obligations
6.1. Process only on instructions. Ultra Guest will Process Personal Data only on the Hotel's documented instructions, including with regard to international transfers, unless required to Process by a law to which Ultra Guest is subject, in which case clause 2.1 applies. Ultra Guest will not sell Personal Data and will not Process it for its own purposes except as permitted under clause 2.3.
6.2. Confidentiality. Ultra Guest will ensure that persons authorised to Process the Personal Data are bound by an appropriate obligation of confidentiality (whether contractual or statutory), are made aware of the confidential nature of the data, and Process it only as necessary to perform the Services. Access is granted on a least-privilege, need-to-know basis.
6.3. Security measures. Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing as well as the risk to Data Subjects, Ultra Guest will implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including, as appropriate:
- strict tenant isolation so that each Hotel's Personal Data is logically segregated and a tenant is re-validated against the authenticated token on every request (fail-closed);
- encryption of Personal Data in transit (TLS) and at rest;
- a separate, self-hosted database and identity stack dedicated to the Platform, isolated from any other Ultra product environment;
- access controls, role-based authorisation, secure authentication, and audit logging that is append-only;
- pseudonymisation or minimisation where practicable, and exclusion of structured pricing, availability, and tax facts and of unverified allergen content from any translation or AI caching path;
- regular testing, assessment, and evaluation of the effectiveness of these measures; and
- measures to restore availability and access to Personal Data in a timely manner after an incident, including backups.
6.4. Allergen and safety-critical handling. Allergen and dietary special-requirement data is never auto-published to guests in a translated form without a human review gate per language, and such data is treated as a structured safety fact rather than free-text routed through the AI translation cache. Ultra Guest will surface this data to the Hotel's fulfilment workflow so that the Hotel, as the service provider, can act on it.
6.5. Assistance — Data Subject Requests. Taking into account the nature of the Processing, Ultra Guest will assist the Hotel by appropriate technical and organisational measures, insofar as possible, to fulfil the Hotel's obligation to respond to Data Subject Requests. Where Ultra Guest receives a Data Subject Request directly, it will not respond on its own (other than to confirm receipt and direct the Data Subject to the Hotel) and will, without undue delay and within the dsr forwarding days business days, forward the request to the Hotel at the controller contact email.
6.6. Assistance — compliance, DPIA, and prior consultation. Ultra Guest will provide the Hotel with reasonable assistance, taking into account the nature of the Processing and the information available to Ultra Guest, with: the Hotel's obligations to keep Personal Data secure (clause 6.3); Personal Data Breach notification and communication (clause 7); the carrying out of data protection impact assessments ("DPIA") where the Processing is likely to result in a high risk; and any prior consultation with the supervisory authority that the DPIA indicates is required.
6.7. Records. Ultra Guest will maintain records of the categories of Processing carried out on the Hotel's behalf as required by Applicable Data Protection Law and will make them available to the Hotel and, where required, to the supervisory authority on request.
7. Personal Data Breach notification
7.1. Ultra Guest will notify the Hotel without undue delay, and in any event within seventy-two (72) hours of becoming aware of a Personal Data Breach affecting the Hotel's Personal Data.
7.2. The notification will, to the extent then known and as it becomes available, describe: the nature of the breach including, where possible, the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures taken or proposed to address the breach and mitigate its effects; and a contact point for further information.
7.3. Ultra Guest will cooperate with the Hotel and take reasonable steps as directed by the Hotel to assist in the Hotel's investigation, mitigation, and remediation of the breach. The Hotel is responsible for any notification to the supervisory authority and to affected Data Subjects required of it as Controller; Ultra Guest will not make such external notifications identifying the Hotel without the Hotel's prior written approval, except where independently required of Ultra Guest by law.
8. Sub-processors
8.1. General authorisation. The Hotel grants Ultra Guest general written authorisation to engage Sub-processors to Process Personal Data, subject to this clause 8.
8.2. Current Sub-processors. At the effective date, the authorised Sub-processors are those set out in the Platform Sub-processor Register, which Ultra Guest maintains as the single source of truth and publishes in the Ultra Guest Trust Center:
| Sub-processor | Service provided | Location / region | Personal Data categories |
|---|---|---|---|
| Amazon Web Services, Inc. — Amazon Bedrock | AI/LLM inference for the AI concierge, content translation, and grounding (Claude and Titan models). | AWS us-east-1 (United States) | Concierge conversation content, prompt context, and grounding facts (excludes stored payment card numbers). |
| Amazon Web Services, Inc. — Amazon SES | Delivery of transactional and operational hotel-branded guest email. | AWS us-east-1 (United States) | Recipient name, email address, and message content. |
| Amazon Web Services, Inc. — EC2 / managed hosting | Hosting of the self-hosted Platform database, application, and identity stack (PostgreSQL + GoTrue run on this infrastructure). | AWS us-east-1 (United States) | All personal-data categories, at rest, within the tenant-isolated Platform database. |
| Open-Meteo (weather data) | Local weather for the in-stay destination guide. | Open-Meteo (EU-based) | Approximate property coordinates only — no guest personal data is sent. |
Any additional Hotel-specific Sub-processors agreed with the Hotel are: the additional subprocessors.
8.3. Flow-down. Ultra Guest will impose on each Sub-processor, by a written contract, data-protection obligations no less protective than those in this DPA, in particular sufficient guarantees to implement appropriate technical and organisational measures. Where a Sub-processor fails to fulfil its data-protection obligations, Ultra Guest remains fully liable to the Hotel for that Sub-processor's performance.
8.4. Notice of changes. Ultra Guest will give the Hotel at least the subprocessor notice days days' prior notice (by email to the Hotel's nominated contact and/or via the Platform admin console) of any intended addition or replacement of a Sub-processor, so as to give the Hotel an opportunity to object on reasonable data-protection grounds before the new Sub-processor begins Processing.
8.5. Objection. If the Hotel reasonably objects within the notice period, the Parties will work in good faith to resolve the objection. If they cannot, the Hotel may, as its sole remedy, suspend or terminate the affected Services without penalty for that affected portion, subject to the termination terms of the Main Agreement.
9. International transfers
9.1. The Hotel acknowledges and instructs that providing the Services involves the transfer of Personal Data to, and Processing in, jurisdictions outside the property country, including the United States (for AWS Bedrock inference in us-east-1 and other AWS-hosted Sub-processor services).
9.2. Ultra Guest will only transfer Personal Data across borders where: (a) the transfer is necessary to provide the Services and is consistent with the Hotel's instructions; and (b) the transfer is made subject to an appropriate safeguard recognised under Applicable Data Protection Law, which may include the Data Subject's explicit consent obtained by the Hotel, the necessity of the transfer for performance of the contract with the Data Subject, an adequacy or licensing determination by the competent authority, or contractual data-transfer clauses imposed on the recipient. The PDPL's cross-border transfer requirements (including any licence or approval required from the competent authority) apply, and Ultra Guest will support the Hotel in meeting them.
9.3. Ultra Guest will implement supplementary technical measures, such as encryption in transit and at rest and data minimisation in the prompt context sent for AI inference, to protect Personal Data during international transfer.
9.4. EEA / UK / Switzerland transfers. Where the Hotel or its guests are located in the European Economic Area, the United Kingdom, or Switzerland, and Personal Data is transferred to Ultra Guest or a Sub-processor outside those territories without an adequacy decision, the transfer is made subject to the EU Standard Contractual Clauses (Module Two: Controller-to-Processor) approved by Commission Implementing Decision (EU) 2021/914 (and, for the United Kingdom, the UK International Data Transfer Addendum), supplemented by the technical and organisational measures in clauses 6.3 and 9.3 and by the transfer-impact considerations Ultra Guest documents in its Trust Center. The Parties will execute, or incorporate by reference into the Main Agreement, the applicable Standard Contractual Clause modules and complete their annexes from the Main Agreement and the Platform Sub-processor Register. In the event of conflict, the Standard Contractual Clauses prevail over this DPA in respect of such transfers.
9.5. Representative and supervisory contacts. Where Ultra Guest is required to designate a representative under Article 27 GDPR (or its United Kingdom equivalent), the current appointee is published in the Trust Center: the representative Ultra Guest appoints under Article 27 GDPR where required (published in the Trust Center). This clause records the transfer-safeguard mechanism the Parties rely on; it does not, by itself, render either Party established in the EEA or the United Kingdom.
10. Audit and inspection rights
10.1. Ultra Guest will make available to the Hotel all information reasonably necessary to demonstrate compliance with the obligations in this DPA and with Applicable Data Protection Law.
10.2. Ultra Guest will allow for and contribute to audits, including inspections, conducted by the Hotel or an independent auditor mandated by the Hotel and reasonably acceptable to Ultra Guest, subject to: reasonable prior written notice of at least the audit notice days days; conduct during normal business hours; no more than once in any twelve (12) month period unless required by the supervisory authority or following a Personal Data Breach; appropriate confidentiality undertakings; and no unsupervised access to systems, data, or premises of other tenants. Ultra Guest may satisfy an audit request by providing current third-party certifications, audit reports, or completed security questionnaires where these reasonably address the Hotel's request.
10.3. Each Party bears its own costs of an audit, save that the Hotel will reimburse Ultra Guest's reasonable costs for assistance exceeding the provision of standard documentation.
11. Return and deletion of Personal Data
11.1. On expiry or termination of the Main Agreement, or earlier on the Hotel's written request, Ultra Guest will, at the Hotel's choice, return to the Hotel and/or delete the Personal Data it Processes on the Hotel's behalf, and delete existing copies, unless Applicable Data Protection Law requires continued storage.
11.2. Ultra Guest may retain Personal Data to the extent and for the period required by Applicable Data Protection Law (including tax, accounting, double-entry ledger, and consumer-protection record-keeping obligations under Law No. 181 of 2018) or as necessary to resolve disputes or enforce agreements, in each case keeping the Personal Data confidential and Processing it only as required by that law.
11.3. Ultra Guest will, on request, certify in writing the deletion or return carried out under this clause. Return will be provided in a commonly used, machine-readable format within the return window days days of the request.
12. Liability and indemnity
12.1. Allocation. Each Party's aggregate liability arising out of or related to this DPA, whether in contract, tort (including negligence), or otherwise, is subject to the limitations and exclusions of liability set out in the Main Agreement, and any reference in the Main Agreement to that Party's aggregate liability applies to the combined liability under the Main Agreement and this DPA.
12.2. Apportionment. Where both Parties are responsible for any damage caused by Processing that infringes Applicable Data Protection Law, each Party is liable for the damage only to the part of the damage corresponding to its share of responsibility for the event giving rise to the damage. A Party that has paid full compensation may claim back from the other Party that part of the compensation corresponding to the other Party's share of responsibility.
12.3. Processor indemnity. Ultra Guest will indemnify the Hotel against direct losses, fines, and reasonable costs the Hotel actually incurs to the extent arising from Ultra Guest's breach of this DPA or its Processing of Personal Data otherwise than on the Hotel's documented instructions, subject to the liability caps in clause 12.1.
12.4. Controller indemnity. The Hotel will indemnify Ultra Guest against direct losses, fines, and reasonable costs Ultra Guest actually incurs to the extent arising from the Hotel's instructions, the Hotel's lack of a valid legal basis or consent for the Processing, the inaccuracy or unlawfulness of Personal Data provided by the Hotel or its guests, or the Hotel's breach of this DPA, subject to the liability caps in clause 12.1.
12.5. Nothing in this DPA limits or excludes either Party's liability where such limitation or exclusion is not permitted by Applicable Data Protection Law.
13. General
13.1. Governing law and venue. This DPA is governed by the laws of the property country and subject to the dispute-resolution and venue provisions of the Main Agreement, except where Applicable Data Protection Law mandates a different forum for Data-Subject or supervisory-authority matters.
13.2. Data protection contacts. Queries about this DPA or the Processing may be sent to the Hotel's controller contact at the controller contact email and, where appointed, the Hotel's data protection officer at the dpo contact. Complaints may be addressed to the complaint contact and, ultimately, to the competent supervisory authority.
13.3. Changes. Ultra Guest may update this DPA to reflect changes in Applicable Data Protection Law, Sub-processors, or the Services, giving the Hotel reasonable prior notice; changes that materially reduce the protection of Personal Data will not take effect over the Hotel's reasonable objection without the Hotel's right to terminate the affected Services.
13.4. Severance and survival. If any provision of this DPA is held invalid, the remainder continues in effect. Clauses that by their nature should survive termination (including clauses 6.2, 7, 11, and 12) survive.