ResvPro
Get on the list

ResvPro Data Processing Addendum

Effective date: August 30, 2026
Last updated: August 30, 2026

This Data Processing Addendum ("DPA") forms part of the ResvPro Terms of Service or other written agreement between ResvPro LLC, a Florida limited liability company ("ResvPro," "we," "us"), and the customer identified in the applicable Order ("Customer," "you") governing Customer's use of the Services (the "Agreement"). It applies to ResvPro's processing of Personal Data contained in Operator Data on Customer's behalf.

If a term is defined in the Agreement and not here, the Agreement's definition applies. Where this DPA conflicts with the rest of the Agreement, this DPA controls as to the processing of Personal Data.


1. Definitions

  • "Applicable Data Protection Law" — every privacy, data protection, and communications law that applies to a party's processing under this DPA, including the California Consumer Privacy Act as amended by the CPRA and its implementing regulations ("CCPA"), the comprehensive privacy statutes of other U.S. states, and, where applicable, the EU General Data Protection Regulation and the UK GDPR ("GDPR").
  • "Business," "Business Purpose," "Consumer," "Sell," "Share," "Service Provider," "Contractor," and "Deidentified" — as defined in the CCPA.
  • "Controller," "Processor," "Data Subject," "Personal Data," "Processing," and "Supervisory Authority" — as defined in the GDPR, with "Personal Data" also covering "personal information" and "personal data" as defined in U.S. state law.
  • "End Customer" — a guest, rider, passenger, renter, or other customer of Customer's business.
  • "Operator Data" — as defined in the Agreement: data Customer or its End Customers submit to, or that ResvPro collects through, the Services on Customer's behalf.
  • "Security Incident" — a confirmed breach of ResvPro's security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data that ResvPro processes under this DPA. Unsuccessful attempts and events with no impact on Personal Data — pings, port scans, failed logins, denied access attempts — are not Security Incidents.
  • "Sensitive Data" — Personal Data that Applicable Data Protection Law treats as sensitive or special-category, including government identifiers, precise geolocation, health data, biometric data, and data revealing protected characteristics.
  • "Subprocessor" — any third party ResvPro engages to process Personal Data under this DPA.

2. Roles of the parties

CustomerResvPro
Under U.S. state lawBusiness / ControllerService Provider / Processor
Under GDPR (where it applies)ControllerProcessor

Customer determines the purposes and means of processing Operator Data. ResvPro processes it only to provide, secure, and support the Services and for the other Business Purposes described in Annex 1.

ResvPro is an independent Controller of, and this DPA does not apply to, data ResvPro collects for its own purposes — Customer account and billing records, Site visitor data, and support correspondence with Customer's own personnel. The ResvPro Privacy Policy governs that data.


3. Customer's obligations

Customer will:

  1. comply with Applicable Data Protection Law in its use of the Services and in the instructions it gives ResvPro;
  2. provide the notices and obtain the consents and permissions required for ResvPro to process Operator Data as contemplated by the Agreement — including for messaging, telephone calls, and call recording, and including all-party recording consent where a jurisdiction requires it;
  3. maintain the accuracy and quality of Operator Data and of its configured policies;
  4. respond to End Customer privacy requests as the Controller, using the export, correction, and deletion functions of the Services; and
  5. not submit Sensitive Data or data about children under 13 to the Services except through fields designed for it and with the legal basis required.

Customer's instructions are the Agreement, this DPA, Customer's configuration of the Services, and any further written instructions the parties agree to. Customer represents that its instructions are lawful.


4. ResvPro's processing obligations

4.1 Instructions

ResvPro processes Personal Data only on Customer's documented instructions, including for international transfers, unless a law it is subject to requires otherwise — in which case ResvPro will notify Customer before processing, unless that law prohibits the notice. ResvPro will notify Customer if, in its opinion, an instruction infringes Applicable Data Protection Law, and may suspend that instruction until resolved.

4.2 Service Provider commitments under the CCPA

ResvPro is a Service Provider with respect to Personal Data it processes for Customer. ResvPro:

  1. will not sell or share Personal Data as those terms are defined in the CCPA;
  2. will not retain, use, or disclose Personal Data for any purpose other than the specific Business Purposes set out in Annex 1, including not for its own commercial purpose, and not outside the direct business relationship with Customer, except as the CCPA permits;
  3. will not combine Personal Data received from Customer with Personal Data it receives from, or on behalf of, another person, or collects from its own interactions with a Consumer, except as the CCPA and its regulations permit (for example, to detect security incidents or resist malicious or illegal activity);
  4. will comply with the CCPA's obligations applicable to Service Providers and will provide the same level of privacy protection the CCPA requires of Customer;
  5. will notify Customer promptly, and in any event within five business days, if it determines it can no longer meet its obligations under the CCPA;
  6. grants Customer the right to take reasonable and appropriate steps to ensure ResvPro uses Personal Data in a manner consistent with Customer's CCPA obligations, including through the assessments described in Section 8, and to stop and remediate unauthorized use of Personal Data on notice; and
  7. will assist Customer in responding to verifiable Consumer requests as described in Section 7.

The parties acknowledge that Customer's disclosure of Personal Data to ResvPro under the Agreement is not a Sale or Share, and that no monetary or other valuable consideration is exchanged for it.

4.3 Deidentified data

Where ResvPro creates Deidentified or aggregated data from Operator Data as the Agreement permits, ResvPro will take reasonable measures to ensure the data cannot be associated with an individual or household, will publicly commit to maintaining it in deidentified form, will not attempt to reidentify it, and will contractually obligate any recipient to the same.

4.4 Confidentiality

ResvPro limits access to Personal Data to personnel who need it to perform the Agreement, and binds them to written confidentiality obligations that survive the end of their engagement.

4.5 AI processing

Personal Data may be processed by automated systems, including large language models, to deliver the Services. ResvPro does not use Operator Data to train general-purpose AI models, and contractually prohibits its AI Subprocessors from training their models on Operator Data. Model providers listed in Annex 3 process Operator Data as Subprocessors on a zero-retention or limited-retention basis as noted there.


5. Security and Security Incidents

5.1 Security measures

ResvPro maintains the technical and organizational measures set out in Annex 2, appropriate to the risk. ResvPro may update them, provided it does not materially reduce overall security during the term.

5.2 Incident notification

ResvPro will notify Customer without undue delay and no later than 72 hours after confirming a Security Incident affecting Customer's Personal Data. The notice will describe, to the extent known: the nature of the incident and the categories and approximate number of records affected, the likely consequences, the measures taken or proposed, and a contact point for more information. ResvPro will provide updates as they become available, and will reasonably assist Customer in meeting Customer's own breach-notification obligations.

Notification is not an acknowledgment of fault or liability. Customer is responsible for notifying End Customers and regulators where it is the Controller, unless the parties agree otherwise in writing.


6. Subprocessors

6.1 Authorization

Customer gives ResvPro general written authorization to engage Subprocessors. The Subprocessors in use as of the effective date are listed in Annex 3.

6.2 New Subprocessors

ResvPro will give Customer at least 30 days' notice before a new Subprocessor begins processing Personal Data, by email to the account's administrative contact and by updating our subprocessor page at resvpro.com/subprocessors. Customer may object on reasonable data-protection grounds within that period. The parties will work in good faith to resolve the objection; if they cannot, Customer may terminate the affected Services and receive a pro-rata refund of prepaid unused fees as its sole remedy.

6.3 Flow-down and liability

ResvPro imposes data protection obligations on each Subprocessor that are no less protective than this DPA, and remains liable to Customer for its Subprocessors' acts and omissions to the same extent it would be liable for its own.


7. Assistance to Customer

Taking into account the nature of the processing and the information available to it, ResvPro will provide reasonable assistance to Customer with:

  • Individual rights requests — access, correction, deletion, portability, opt-out, and appeal — primarily by making self-service functions available in the Services. If ResvPro receives a request directly from an End Customer, it will not respond substantively; it will inform the individual to contact Customer and will forward the request to Customer without undue delay.
  • Data protection impact assessments, risk assessments, and prior consultation with a Supervisory Authority or state regulator, where required by Applicable Data Protection Law and relating to ResvPro's processing.
  • Security, breach notification, and regulator inquiries as described in Section 5.

Assistance beyond what is reasonably required, or requested at a volume or frequency that is unreasonable, may be charged at ResvPro's then-current professional-services rates on prior written notice.


8. Assessments, audits, and information

On Customer's written request no more than once every 12 months (and additionally after a Security Incident affecting Customer):

  1. ResvPro will make available the information reasonably necessary to demonstrate compliance with this DPA — including a completed security questionnaire and, when available, third-party audit reports or certifications;
  2. if that documentation is not sufficient, Customer or an independent auditor bound by confidentiality and not a competitor of ResvPro may conduct an assessment of ResvPro's relevant systems and controls, on at least 30 days' notice, during business hours, without unreasonably disrupting operations, and limited to information relevant to Customer's Personal Data; and
  3. Customer bears its own and the auditor's costs, unless the assessment reveals material non-compliance, in which case ResvPro bears the reasonable cost of the assessment and will remediate promptly.

Customer will not have access to other customers' data, and ResvPro may redact or withhold information that would compromise its security, confidentiality obligations, or legal privilege.


9. Deletion and return

On termination or expiry of the Agreement, ResvPro will make Operator Data available for export for 30 days, and will then delete or deidentify it in accordance with its standard schedule. Copies in backups are purged on a rolling basis. ResvPro may retain Personal Data where Applicable Data Protection Law requires, and will keep it protected and limit further processing to the purpose of that retention. On written request, ResvPro will certify deletion.


10. International transfers

ResvPro processes Personal Data in the United States. Customer is responsible for ensuring that any transfer of Personal Data to ResvPro complies with Applicable Data Protection Law.

Where GDPR applies to Customer's Personal Data and ResvPro is not certified under an applicable adequacy mechanism, the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (Controller to Processor) or Module Three (Processor to Processor), are incorporated into this DPA by reference, with:

  • Clause 7 (docking) — included;
  • Clause 9 — Option 2, general written authorization, with the 30-day notice period in Section 6.2;
  • Clause 11 — the optional independent dispute-resolution language is not included;
  • Clause 17 — governed by the law of Ireland;
  • Clause 18(b) — courts of Ireland;
  • Annexes I, II, and III of the Clauses — populated by Annexes 1, 2, and 3 of this DPA, with Customer as data exporter and ResvPro as data importer.

For UK transfers, the UK International Data Transfer Addendum (version B1.0) is incorporated, with the Clauses above as the Approved EU SCCs and Tables 1–4 populated from this DPA. For Swiss transfers, references to the GDPR are read as references to the Swiss FADP and the Swiss Federal Data Protection and Information Commissioner is the competent authority.


11. Liability

Each party's liability under this DPA is subject to the exclusions and limitations of liability in the Agreement. Nothing in this DPA limits any liability that Applicable Data Protection Law does not permit to be limited, including a Data Subject's rights under the Standard Contractual Clauses.


12. General

  • Term. This DPA takes effect on the effective date and continues until ResvPro has deleted or returned all Personal Data under Section 9.
  • Order of precedence. This DPA, then the Standard Contractual Clauses where they apply (which prevail over this DPA in the event of conflict), then the Agreement.
  • Changes. ResvPro may update this DPA where required by a change in Applicable Data Protection Law, on 30 days' notice, provided the update does not materially reduce Customer's protections.
  • Governing law. Except where the Standard Contractual Clauses provide otherwise, this DPA is governed by the law of the State of Florida, and the courts of Hillsborough County, Florida have jurisdiction, subject to any dispute-resolution provision in the Agreement.
  • Severability. If any provision is unenforceable, the rest of this DPA stands.

13. Signature

Where Customer requires a signed copy, this DPA is executed by the parties' authorized representatives below. Otherwise it is incorporated into the Agreement by reference and accepted when Customer accepts the Agreement.

ResvPro LLCCustomer
Signature: Signature:
Name: Name:
Title: Title:
Date: Date:
Entity:
Notice email:

Annex 1 — Description of the processing

Data exporter / Business / Controller: Customer, as identified in the Order. Contact: the administrative contact on the account.

Data importer / Service Provider / Processor: ResvPro LLC, 3750 Gunn Highway, Suite 306J, PMB 1165, Tampa, FL 33618. Contact: privacy@resvpro.com.

Subject matter. Provision of the ResvPro reservation and operations platform.

Duration. The term of the Agreement, plus the retention period in Section 9.

Nature and purpose of processing — the Business Purposes for which ResvPro is permitted to process Personal Data:

  1. answering, placing, routing, and recording calls, and generating transcripts and call outcomes;
  2. taking, confirming, modifying, and cancelling bookings, and syncing them with Customer's connected platforms;
  3. sending and receiving messages across SMS, chat, and email, and maintaining consent and delivery records;
  4. running waiver, age, safety, certification, and eligibility checks and recording the results;
  5. maintaining customer records, reviews, and follow-up workflows;
  6. providing dashboards, reporting, and analytics to Customer about Customer's own operation;
  7. providing support, troubleshooting, and account administration to Customer;
  8. securing the Services, preventing fraud and abuse, and maintaining audit records; and
  9. complying with legal obligations applicable to ResvPro as a provider of the Services.

Frequency. Continuous, for the duration of the Agreement.

Categories of Data Subjects: Customer's End Customers and prospective End Customers; Customer's personnel and authorized users; and other individuals whose details appear in a booking, waiver, call, or message (for example, additional passengers or emergency contacts).

Categories of Personal Data:

CategoryExamples
Identifiers and contact dataName, email address, postal address, telephone number, account or booking reference
Booking and transaction dataActivity booked, date and time, party size, pricing, status, cancellation and refund history, notes
Communications dataCall audio and recordings where enabled, transcripts, SMS and chat message content, email content, delivery status, consent and opt-out records
Waiver and eligibility dataWaiver status and signature records, age or date of birth where the activity requires it, certification or license status, stated restrictions relevant to eligibility
Emergency and third-party contact dataNames and phone numbers of emergency contacts where Customer collects them
Technical dataIP address, device and browser data, timestamps, and log data associated with use of the Services

Sensitive Data. ResvPro does not require Sensitive Data. Where Customer's activity lawfully requires a limited eligibility datum — such as age, a boating-safety certification, or a stated physical restriction relevant to safety — Customer is responsible for its legal basis, and ResvPro applies the restrictions and safeguards in this DPA and Annex 2. ResvPro does not knowingly process government identification numbers, payment card numbers, or health records.

Voice cloning data. Where Customer enables the optional voice cloning feature, ResvPro processes voice recordings Customer supplies or authorizes, and the synthetic voice model derived from them, solely on Customer's documented instructions. Customer acknowledges that this data may constitute biometric identifier or biometric information under Applicable Data Protection Law, including the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifiers Act, and the Washington biometric privacy statute. Customer is the Controller of voice cloning data and is solely responsible for the legal basis, notices, written consents, retention schedule, and deletion obligations those laws impose. ResvPro processes voice cloning data only to generate and operate Customer's configured agent, does not use it for any other customer or purpose, and deletes it on the schedule in Section 9 or earlier on Customer's written instruction. Absent voice cloning, ResvPro does not knowingly process biometric data.

Health information. The Services are not HIPAA compliant and ResvPro is not a business associate. Customer will not configure the Services to solicit or store protected health information. Where an End Customer volunteers a medical or physical condition during a call, Customer determines whether it is retained and is responsible for the legal basis for retaining it.

Children. Where an End Customer is a minor, their details are provided by a parent or guardian through Customer's booking or waiver process. Customer is responsible for obtaining the required consent.


Annex 2 — Technical and organizational measures

ResvPro maintains the following measures. Measures marked [Planned] are committed to but not yet fully implemented as of the effective date; ResvPro will implement them before processing production Personal Data for Customer.

AreaMeasures
EncryptionTLS 1.2 or higher for all data in transit, including to Subprocessors. Encryption at rest for databases, object storage, and backups.
Access controlUnique named accounts, no shared credentials; multi-factor authentication on all administrative and cloud accounts; least-privilege role-based access; access reviewed on role change and revoked on departure.
Environment separationProduction separated from development and test environments. Production Personal Data is not used in development or test.
Logging and monitoringApplication and infrastructure logs retained and monitored; administrative actions and access to Personal Data recorded in audit logs. [Planned] — centralized log aggregation and alerting.
Vulnerability managementDependency scanning and prompt patching of known vulnerabilities. [Planned] — annual third-party penetration test.
Backup and recoveryAutomated encrypted backups with defined retention; documented restore procedure tested periodically. [Planned] — documented RTO and RPO targets.
Secure developmentCode review before merge; secrets held in a managed secret store, never in source control; change history retained.
PersonnelWritten confidentiality obligations; security awareness training; background screening where lawful and appropriate to the role.
Subprocessor managementSecurity and privacy review before engagement; contractual flow-down of this DPA's obligations; periodic review.
Incident responseDocumented incident response procedure with defined roles, severity levels, and the notification path in Section 5. [Planned] — annual tabletop exercise.
Data minimization and retentionCollection limited to what the Services require; retention per the ResvPro Privacy Policy and Customer's configured settings; deletion on the schedule in Section 9.
Physical securityProduction infrastructure is hosted with cloud providers operating certified data centers; ResvPro maintains no on-premises production infrastructure.

Annex 3 — Subprocessors

As of the effective date:

SubprocessorRolePersonal Data processedLocation
Twilio Inc.Telephony and messaging — call connectivity, SMS delivery, delivery receiptsPhone numbers, call metadata and audio, message content, consent and opt-out recordsUnited States
Google LLC (Google Workspace)Business email and productivity for ResvPro personnel supporting CustomerContact details and any Personal Data contained in support correspondenceUnited States
Webflow, Inc.Hosting of resvpro.com and its formsContact details submitted through Site formsUnited States

To be added before production processing begins, on notice under Section 6.2: cloud infrastructure and managed database hosting; AI model providers for voice and text generation (engaged on a zero-retention or no-training basis); a voice synthesis and voice cloning provider, engaged only where Customer enables that optional feature; a payment processor for Customer billing; error monitoring and analytics.

No voice recording or voice model is transmitted to a voice cloning provider until that provider is named in this Annex and Customer has received notice under Section 6.2.

An up-to-date list, including planned subprocessors, is published at resvpro.com/subprocessors. To receive change notices by email, write to privacy@resvpro.com.


ResvPro LLC · 3750 Gunn Highway, Suite 306J, PMB 1165, Tampa, FL 33618
Privacy: privacy@resvpro.com · Legal: legal@resvpro.com

ResvPro

AI front desk for watersports and adventure tours.

InstagramFacebook

© 2026 ResvPro LLC. All rights reserved.

ResvPro™ is a trademark of ResvPro LLC.

3750 Gunn Highway, Suite 306J, PMB 1165, Tampa, FL 33618

info@resvpro.com

Privacy PolicyTerms of ServiceData Processing AddendumSubprocessors