1. Scope
This Data Processing Addendum (“DPA”) applies where a business customer uses LeisureOS to process personal information for which that business determines the purposes and means of processing and LeisureOS processes the information on the business’s behalf.
In this DPA, the business customer is referred to as the “Customer” and LeisureOS / Aiby Technologies as the “Processor”.
2. Processing instructions
The Processor will process Customer-controlled personal information only to provide LeisureOS, maintain and secure the service, comply with documented Customer instructions, and meet applicable legal obligations.
The normal use of LeisureOS, the Customer’s configuration choices and support requests constitute documented instructions for the processing necessary to provide the service.
3. Processing details
| Subject matter | Operation of the LeisureOS hospitality and leisure management platform |
|---|---|
| Duration | For the Customer’s authorized use of LeisureOS and any reasonable retention/backup period required after termination |
| Nature | Collection, recording, organization, retrieval, display, use, updating, storage, protection, deletion and related processing required to provide the service |
| Purposes | Account access, Staff workflows, customer ordering, bookings, pool admissions, payment-status recording, reporting, security, support and service operation |
| Data subjects | Customer personnel, venue Staff, venue customers, booking guests and other individuals whose information the Customer chooses to record |
| Data types | Names, contact details, account/role data, order and service activity, booking details, pool admission data, payment metadata, audit/security data and other operational information entered by the Customer |
4. Confidentiality
The Processor will take reasonable steps to ensure that people authorized to access Customer-controlled personal information are subject to confidentiality obligations and access the information only as required for their role.
5. Security measures
The Processor will maintain appropriate technical and organizational measures designed to protect personal information against unauthorized access, alteration, disclosure or destruction.
Current LeisureOS controls include, where applicable, password hashing, authenticated sessions, server-side permissions, tenant and branch separation, CSRF protections, signed QR links, rate limiting, audit records, prepared database statements, transaction locking and HTTPS in production.
6. Service providers and subprocessors
The Processor may use infrastructure and service providers to operate LeisureOS, such as hosting, backup, email, monitoring or security providers.
Before commercial launch, LeisureOS should maintain a current list of subprocessors and ensure appropriate contractual safeguards are in place where required.
7. Data subject requests
Where the Customer receives a valid request relating to personal information processed in LeisureOS, the Processor will provide reasonable assistance, taking into account the nature of the processing and the functionality available in the platform.
8. Security incidents
If the Processor becomes aware of a confirmed personal-data breach affecting Customer-controlled data, the Processor will notify the affected Customer without undue delay where required by applicable law and will provide reasonably available information needed for the Customer’s response.
9. Return and deletion
On termination of the service, Customer data should be returned or deleted in accordance with the final commercial agreement, applicable law and reasonable backup-retention procedures.
The production launch should define a clear export and deletion process before paid contracts rely on this clause.
10. International transfers
Where Customer personal information is transferred across borders and applicable law requires transfer safeguards, the parties will use an appropriate lawful transfer mechanism.
11. Compliance information
On reasonable request and subject to confidentiality and security restrictions, the Processor will provide information reasonably necessary to demonstrate compliance with its processor obligations.
Any on-site audit rights, frequency limits, costs and independent audit-report process should be finalized in the commercial version of this DPA.
12. Relationship with other terms
If there is a conflict between this DPA and the general Terms concerning the processing of Customer-controlled personal information, the DPA should control to the extent of that conflict once formally incorporated into the Customer agreement.
13. Contact
Questions about data processing can be raised through the LeisureOS contact page until dedicated legal/privacy contact information is published.