Legal

Data Processing Agreement (DPA)

Last updated: 3 July 2026

The short version: your guests' data belongs to you. Here is the legal framework that guarantees it.

This Data Processing Agreement is incorporated by reference into the Valiris Terms of Service and forms part of the contract between the operator and Valiris SAS. It is accepted automatically when an operator accepts the Terms of Service at signup, and no further signature is required for it to take effect.

Print this page for your records.

1. Parties and roles

This Agreement is entered into between the operator using Valiris to manage guest communications ("the operator", acting as data controller for its guests' and its own team members' personal data) and Valiris SAS ("Valiris", acting as data processor). Together, the operator and Valiris are "the Parties".

  • Company: Valiris SAS
  • Legal form: Société par actions simplifiée (SAS) with share capital of €200.00
  • SIREN: 101 335 990
  • SIRET (head office): 101 335 990 00012
  • RCS: Paris 101 335 990
  • Intra-community VAT number: FR88101335990
  • Registered office: 25 rue de Ponthieu, 75008 Paris, France
  • Contact: contact@valiris.io

2. Subject matter, duration, nature and purpose

Subject matter: the processing of personal data by Valiris on the operator's documented instructions, in order to deliver AI-assisted guest message handling and related platform features (Knowledge Base retrieval, Extras and payment flows, escalations and approvals, analytics).

Duration: this Agreement applies for as long as Valiris processes personal data on the operator's behalf, that is, for the duration of the underlying service agreement between the Parties, and it terminates automatically when that agreement ends, subject to the deletion and return provisions in clause 10.

Nature of the processing: automated and, where applicable, manual operations, including collection, storage, retrieval, organisation, use, transmission, and deletion of personal data through the Valiris platform.

Purpose: to enable the operator to automate and manage communications with its guests, including AI-generated replies, and to operate the associated features it has configured on the platform.

3. Categories of data subjects and personal data

Guests (data subjects)

Name, contact details (email, phone), booking dates and references, message content exchanged with the AI or the operator's team, requested Extras and payment status.

Operator staff (data subjects)

Name, email address, and role or permission level within the operator's Valiris account.

Valiris does not knowingly process special categories of personal data (Article 9 GDPR). The operator agrees not to include such data in its Knowledge Base documents, instructions, or other content it provides to the Service.

4. Processing on documented instructions only

Valiris processes personal data only on the operator's documented instructions. Those instructions consist of this Agreement, the Terms of Service, and, critically, the configuration the operator sets on the platform itself: AI Settings, Knowledge Base content, Extras, the approval workflow, and per-property configuration. The operator's own settings ARE its instructions to Valiris.

If Valiris considers that an instruction infringes the GDPR or another applicable data protection provision, it will inform the operator without delay.

5. Confidentiality

Valiris ensures that any person it authorises to process personal data under this Agreement, employees and contractors alike, is bound by an appropriate confidentiality obligation, whether contractual or statutory, and processes that data only as instructed.

6. Security measures

Valiris implements appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, or damage, appropriate to the risk presented by the processing. The measures currently in place are set out in full in the Annex to this Agreement, Technical and Organisational Measures (TOMs), which forms an integral part of this Agreement. Valiris may update these measures over time, provided any update does not materially decrease the overall level of protection.

7. Sub-processors

The operator gives Valiris a general written authorisation to engage sub-processors to help deliver the service. The current list of sub-processors, together with the purpose of each engagement, the categories of personal data involved, and their location, is published and kept up to date in our Privacy Policy. This Agreement does not repeat that list, so the Privacy Policy is the authoritative reference.

Before engaging a new sub-processor, or replacing an existing one, Valiris will give the operator at least 30 days' notice by email or in-app notification. If the operator has a reasonable, documented objection grounded in data protection law, it may raise it within that period; the Parties will discuss the objection in good faith and, if it cannot be resolved, the operator may terminate the affected part of the service without penalty.

Valiris imposes on every sub-processor data protection obligations that are at least equivalent to those set out in this Agreement, and remains fully liable to the operator for each sub-processor's performance of those obligations.

8. Assistance

Valiris assists the operator, insofar as reasonably possible given the nature of the processing, in responding to requests from data subjects, guests or team members, exercising their rights under the GDPR. This includes tools available directly on the platform, such as data export and deletion, and forwarding to the operator any request Valiris receives directly from a data subject.

Valiris also assists the operator in meeting its obligations under Articles 32 to 36 of the GDPR: the security of processing, notification of personal data breaches, data protection impact assessments, and prior consultation with the CNIL or another competent supervisory authority, where required, taking into account the information available to Valiris and the nature of the processing.

9. Personal data breaches

Valiris notifies the operator without undue delay after becoming aware of a personal data breach affecting personal data processed under this Agreement. The notification includes, to the extent known at the time: the nature of the breach; the categories and approximate number of data subjects and personal data records concerned; the likely consequences of the breach; and the measures taken or proposed to address it and mitigate its effects, in line with Article 33(3) of the GDPR. Valiris cooperates with the operator and provides further information as it becomes available, to support any notification the operator is required to make to a supervisory authority or to affected data subjects.

10. Deletion and return

On termination of the service agreement between the operator and Valiris, the operator has 30 days to export its data, including guest message history, booking records, and Knowledge Base documents, using the platform's export tools or by written request to contact@valiris.io. Once that 30-day window has passed, Valiris permanently deletes all personal data processed under this Agreement from its production systems and instructs its sub-processors to do the same, except to the extent EU or French law requires Valiris to retain specific data, for example billing and accounting records.

11. Audits

Valiris makes available to the operator all information reasonably necessary to demonstrate compliance with this Agreement, including this DPA, its Annex, and relevant security documentation and certifications. Where that documentation does not sufficiently address the operator's concerns, the operator, or an independent auditor it appoints who is itself bound by confidentiality, may conduct an on-site audit of Valiris's relevant processing activities. Such audits are limited to once per calendar year, unless triggered by a personal data breach or a binding request from a supervisory authority, require at least 30 days' prior written notice, must take place during normal business hours without disrupting Valiris's operations or other customers' data, and are carried out at the operator's cost.

12. International transfers

Some Valiris sub-processors are established outside the European Economic Area, principally in the United States. Where personal data is transferred to such a sub-processor, Valiris relies on a valid transfer mechanism recognised under the GDPR: the European Commission's Standard Contractual Clauses and, where the recipient participates, the EU-US Data Privacy Framework, together with supplementary technical and organisational measures such as encryption in transit and at rest. The transfer mechanism relied on for each sub-processor is listed alongside it in our Privacy Policy.

13. AI transparency responsibilities and governing law

Where the operator uses Valiris to communicate with guests through an AI system, the operator is the deployer of that AI system for the purposes of Regulation (EU) 2024/1689 (the AI Act) and is responsible for configuring guest-facing AI transparency in line with its obligations, which apply from 2 August 2026 under Article 50 of that Regulation. Valiris provides Transparency Mode, including an automatic first-message notice informing guests they are communicating with an automated assistant, to help the operator meet this obligation. The operator remains responsible for selecting the transparency configuration appropriate to its guests and jurisdiction.

This Agreement is governed by French law. Any dispute arising from or in connection with this Agreement is submitted to the exclusive jurisdiction of the courts of Paris, France.

Annex: Technical and organisational measures (TOMs)

These are the measures Valiris has in place at the date of this Agreement, referenced in clause 6.

Encryption at rest Stored credentials, such as PMS API keys and property access codes, are encrypted using AES-256-GCM.
Encryption in transit All data in transit between the operator, Valiris, and its sub-processors is encrypted using TLS.
Data isolation Row-level security (RLS) scopes every database query to the operator's own organisation, so operators cannot access one another's data.
Access control Role-based access control governs what team members can see and do, with owner, admin, manager, and viewer roles.
Two-factor authentication Optional TOTP-based two-factor authentication is available for operator accounts.
Rate limiting API rate limiting protects the platform and its data against abuse and automated attacks.
Webhook integrity Incoming PMS webhooks are verified by signature before their data is accepted and processed.
Data location The primary database is hosted in the EU (Frankfurt, Germany).
Breach response A documented breach-response procedure is in place, with readiness to notify the CNIL within 72 hours where required.

Questions about this agreement?

We're a small team and we read every email. Reach out directly.

contact@valiris.io