Data Processing Agreement (template)

Version 1.0 · 2026-07-12 · Art. 28(3) GDPR · executed as part of the operator subscription.

Parties. The campground operator (Controller) and Camp44 (Processor).

1. Subject matter & duration. Processing of guest and booking personal

data for the operation of the Controller's reservation system, for the term

of the subscription.

2. Nature & purpose. Storage, organisation, transmission of booking,

payment-status, communication and statutory-registration data; automated

transactional messaging; report generation.

3. Categories of data & data subjects. Guests and their party members:

identity, contact, stay, party composition, travel-document data where

statutory registration requires it, payment references (never card data —

those flow directly to the Controller's own PSP account).

4. Controller instructions. The Processor processes only on documented

instructions, including the configuration the Controller sets in the product

(retention classes, registration authorities, tax postures). Product

configuration constitutes a documented instruction.

5. Confidentiality. Persons authorised to process are bound to

confidentiality.

6. Security (Art. 32). Encryption in transit; authority credentials

encrypted at rest (AES-256-GCM with keys held outside the database);

immutable financial ledger; role-based, per-property access control; audit

events on booking changes.

7. Subprocessors. General authorisation with the published subprocessor

list; 30 days' notice of changes with a right to object on reasonable

grounds.

8. Data-subject rights. The Processor provides the tooling (machine-

readable subject export; erasure that anonymises everything not under a

statutory retention duty) and assists the Controller without undue delay.

9. Breach notification. Without undue delay after becoming aware, with

the information Art. 33(3) requires.

10. Deletion/return. On termination the Controller takes the full-data

export; the Processor then deletes personal data except where retention is

legally required (bookkeeping records).

11. Audits. The Processor makes available the information necessary to

demonstrate compliance and allows audits, normally satisfied by

documentation and the claims-vs-code checklist.

privacytermscookiesdpasubprocessorsaccessibilitysecurity