Data Processing Agreement (template)
Version 1.0 · 2026-07-12 · Art. 28(3) GDPR · executed as part of the operator subscription.
Parties. The campground operator (Controller) and Camp44 (Processor).
1. Subject matter & duration. Processing of guest and booking personal
data for the operation of the Controller's reservation system, for the term
of the subscription.
2. Nature & purpose. Storage, organisation, transmission of booking,
payment-status, communication and statutory-registration data; automated
transactional messaging; report generation.
3. Categories of data & data subjects. Guests and their party members:
identity, contact, stay, party composition, travel-document data where
statutory registration requires it, payment references (never card data —
those flow directly to the Controller's own PSP account).
4. Controller instructions. The Processor processes only on documented
instructions, including the configuration the Controller sets in the product
(retention classes, registration authorities, tax postures). Product
configuration constitutes a documented instruction.
5. Confidentiality. Persons authorised to process are bound to
confidentiality.
6. Security (Art. 32). Encryption in transit; authority credentials
encrypted at rest (AES-256-GCM with keys held outside the database);
immutable financial ledger; role-based, per-property access control; audit
events on booking changes.
7. Subprocessors. General authorisation with the published subprocessor
list; 30 days' notice of changes with a right to object on reasonable
grounds.
8. Data-subject rights. The Processor provides the tooling (machine-
readable subject export; erasure that anonymises everything not under a
statutory retention duty) and assists the Controller without undue delay.
9. Breach notification. Without undue delay after becoming aware, with
the information Art. 33(3) requires.
10. Deletion/return. On termination the Controller takes the full-data
export; the Processor then deletes personal data except where retention is
legally required (bookkeeping records).
11. Audits. The Processor makes available the information necessary to
demonstrate compliance and allows audits, normally satisfied by
documentation and the claims-vs-code checklist.