Data protection frameworkAnotherPillow index
The hotel controls guest data. AnotherPillow follows its instructions.
This page explains the intended GDPR roles and production controls. It is not, by itself, the signed data-processing agreement required for a live hotel.
DPA required before productionRoles and instructions
The hotel determines why guest data is used for the stay, payment and communication. AnotherPillow processes that information only to operate the approved booking service, under documented instructions and a signed Article 28 agreement.
- Hotel-specific purpose and scope
- Authorised personnel only
- Confidentiality obligations
Subprocessors and transfers
Infrastructure, email, payment, AI and hotel-system providers are recorded by purpose and location before activation. A new subprocessor requires the agreed notice and objection process. Any transfer outside the EEA needs an adequacy decision or another documented safeguard.
- Current provider register
- Equivalent contractual duties
- Transfer mechanism recorded
Rights, retention and deletion
The hotel receives guest requests and AnotherPillow supplies the technical help needed to search, correct, export, restrict or delete processor data. The production schedule sets retention, legal exceptions, export and deletion after termination.
- Identity verification
- Hotel-approved retention
- Documented backup expiry
Incidents and assurance
AnotherPillow records, contains and investigates suspected personal-data incidents and informs the hotel without undue delay. The hotel remains responsible for any authority or guest notification required of the controller.
- Named incident contacts
- Evidence preservation
- Security and audit documentation
Data protection framework · AnotherPillow