Effective date: August 30, 2026
Last updated: August 30, 2026
This Data Processing Addendum ("DPA") forms part of the ResvPro Terms of Service or other written agreement between ResvPro LLC, a Florida limited liability company ("ResvPro," "we," "us"), and the customer identified in the applicable Order ("Customer," "you") governing Customer's use of the Services (the "Agreement"). It applies to ResvPro's processing of Personal Data contained in Operator Data on Customer's behalf.
If a term is defined in the Agreement and not here, the Agreement's definition applies. Where this DPA conflicts with the rest of the Agreement, this DPA controls as to the processing of Personal Data.
| Customer | ResvPro | |
|---|---|---|
| Under U.S. state law | Business / Controller | Service Provider / Processor |
| Under GDPR (where it applies) | Controller | Processor |
Customer determines the purposes and means of processing Operator Data. ResvPro processes it only to provide, secure, and support the Services and for the other Business Purposes described in Annex 1.
ResvPro is an independent Controller of, and this DPA does not apply to, data ResvPro collects for its own purposes — Customer account and billing records, Site visitor data, and support correspondence with Customer's own personnel. The ResvPro Privacy Policy governs that data.
Customer will:
Customer's instructions are the Agreement, this DPA, Customer's configuration of the Services, and any further written instructions the parties agree to. Customer represents that its instructions are lawful.
ResvPro processes Personal Data only on Customer's documented instructions, including for international transfers, unless a law it is subject to requires otherwise — in which case ResvPro will notify Customer before processing, unless that law prohibits the notice. ResvPro will notify Customer if, in its opinion, an instruction infringes Applicable Data Protection Law, and may suspend that instruction until resolved.
ResvPro is a Service Provider with respect to Personal Data it processes for Customer. ResvPro:
The parties acknowledge that Customer's disclosure of Personal Data to ResvPro under the Agreement is not a Sale or Share, and that no monetary or other valuable consideration is exchanged for it.
Where ResvPro creates Deidentified or aggregated data from Operator Data as the Agreement permits, ResvPro will take reasonable measures to ensure the data cannot be associated with an individual or household, will publicly commit to maintaining it in deidentified form, will not attempt to reidentify it, and will contractually obligate any recipient to the same.
ResvPro limits access to Personal Data to personnel who need it to perform the Agreement, and binds them to written confidentiality obligations that survive the end of their engagement.
Personal Data may be processed by automated systems, including large language models, to deliver the Services. ResvPro does not use Operator Data to train general-purpose AI models, and contractually prohibits its AI Subprocessors from training their models on Operator Data. Model providers listed in Annex 3 process Operator Data as Subprocessors on a zero-retention or limited-retention basis as noted there.
ResvPro maintains the technical and organizational measures set out in Annex 2, appropriate to the risk. ResvPro may update them, provided it does not materially reduce overall security during the term.
ResvPro will notify Customer without undue delay and no later than 72 hours after confirming a Security Incident affecting Customer's Personal Data. The notice will describe, to the extent known: the nature of the incident and the categories and approximate number of records affected, the likely consequences, the measures taken or proposed, and a contact point for more information. ResvPro will provide updates as they become available, and will reasonably assist Customer in meeting Customer's own breach-notification obligations.
Notification is not an acknowledgment of fault or liability. Customer is responsible for notifying End Customers and regulators where it is the Controller, unless the parties agree otherwise in writing.
Customer gives ResvPro general written authorization to engage Subprocessors. The Subprocessors in use as of the effective date are listed in Annex 3.
ResvPro will give Customer at least 30 days' notice before a new Subprocessor begins processing Personal Data, by email to the account's administrative contact and by updating our subprocessor page at resvpro.com/subprocessors. Customer may object on reasonable data-protection grounds within that period. The parties will work in good faith to resolve the objection; if they cannot, Customer may terminate the affected Services and receive a pro-rata refund of prepaid unused fees as its sole remedy.
ResvPro imposes data protection obligations on each Subprocessor that are no less protective than this DPA, and remains liable to Customer for its Subprocessors' acts and omissions to the same extent it would be liable for its own.
Taking into account the nature of the processing and the information available to it, ResvPro will provide reasonable assistance to Customer with:
Assistance beyond what is reasonably required, or requested at a volume or frequency that is unreasonable, may be charged at ResvPro's then-current professional-services rates on prior written notice.
On Customer's written request no more than once every 12 months (and additionally after a Security Incident affecting Customer):
Customer will not have access to other customers' data, and ResvPro may redact or withhold information that would compromise its security, confidentiality obligations, or legal privilege.
On termination or expiry of the Agreement, ResvPro will make Operator Data available for export for 30 days, and will then delete or deidentify it in accordance with its standard schedule. Copies in backups are purged on a rolling basis. ResvPro may retain Personal Data where Applicable Data Protection Law requires, and will keep it protected and limit further processing to the purpose of that retention. On written request, ResvPro will certify deletion.
ResvPro processes Personal Data in the United States. Customer is responsible for ensuring that any transfer of Personal Data to ResvPro complies with Applicable Data Protection Law.
Where GDPR applies to Customer's Personal Data and ResvPro is not certified under an applicable adequacy mechanism, the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (Controller to Processor) or Module Three (Processor to Processor), are incorporated into this DPA by reference, with:
For UK transfers, the UK International Data Transfer Addendum (version B1.0) is incorporated, with the Clauses above as the Approved EU SCCs and Tables 1–4 populated from this DPA. For Swiss transfers, references to the GDPR are read as references to the Swiss FADP and the Swiss Federal Data Protection and Information Commissioner is the competent authority.
Each party's liability under this DPA is subject to the exclusions and limitations of liability in the Agreement. Nothing in this DPA limits any liability that Applicable Data Protection Law does not permit to be limited, including a Data Subject's rights under the Standard Contractual Clauses.
Where Customer requires a signed copy, this DPA is executed by the parties' authorized representatives below. Otherwise it is incorporated into the Agreement by reference and accepted when Customer accepts the Agreement.
| ResvPro LLC | Customer |
|---|---|
| Signature: | Signature: |
| Name: | Name: |
| Title: | Title: |
| Date: | Date: |
| Entity: | |
| Notice email: |
Data exporter / Business / Controller: Customer, as identified in the Order. Contact: the administrative contact on the account.
Data importer / Service Provider / Processor: ResvPro LLC, 3750 Gunn Highway, Suite 306J, PMB 1165, Tampa, FL 33618. Contact: privacy@resvpro.com.
Subject matter. Provision of the ResvPro reservation and operations platform.
Duration. The term of the Agreement, plus the retention period in Section 9.
Nature and purpose of processing — the Business Purposes for which ResvPro is permitted to process Personal Data:
Frequency. Continuous, for the duration of the Agreement.
Categories of Data Subjects: Customer's End Customers and prospective End Customers; Customer's personnel and authorized users; and other individuals whose details appear in a booking, waiver, call, or message (for example, additional passengers or emergency contacts).
Categories of Personal Data:
| Category | Examples |
|---|---|
| Identifiers and contact data | Name, email address, postal address, telephone number, account or booking reference |
| Booking and transaction data | Activity booked, date and time, party size, pricing, status, cancellation and refund history, notes |
| Communications data | Call audio and recordings where enabled, transcripts, SMS and chat message content, email content, delivery status, consent and opt-out records |
| Waiver and eligibility data | Waiver status and signature records, age or date of birth where the activity requires it, certification or license status, stated restrictions relevant to eligibility |
| Emergency and third-party contact data | Names and phone numbers of emergency contacts where Customer collects them |
| Technical data | IP address, device and browser data, timestamps, and log data associated with use of the Services |
Sensitive Data. ResvPro does not require Sensitive Data. Where Customer's activity lawfully requires a limited eligibility datum — such as age, a boating-safety certification, or a stated physical restriction relevant to safety — Customer is responsible for its legal basis, and ResvPro applies the restrictions and safeguards in this DPA and Annex 2. ResvPro does not knowingly process government identification numbers, payment card numbers, or health records.
Voice cloning data. Where Customer enables the optional voice cloning feature, ResvPro processes voice recordings Customer supplies or authorizes, and the synthetic voice model derived from them, solely on Customer's documented instructions. Customer acknowledges that this data may constitute biometric identifier or biometric information under Applicable Data Protection Law, including the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifiers Act, and the Washington biometric privacy statute. Customer is the Controller of voice cloning data and is solely responsible for the legal basis, notices, written consents, retention schedule, and deletion obligations those laws impose. ResvPro processes voice cloning data only to generate and operate Customer's configured agent, does not use it for any other customer or purpose, and deletes it on the schedule in Section 9 or earlier on Customer's written instruction. Absent voice cloning, ResvPro does not knowingly process biometric data.
Health information. The Services are not HIPAA compliant and ResvPro is not a business associate. Customer will not configure the Services to solicit or store protected health information. Where an End Customer volunteers a medical or physical condition during a call, Customer determines whether it is retained and is responsible for the legal basis for retaining it.
Children. Where an End Customer is a minor, their details are provided by a parent or guardian through Customer's booking or waiver process. Customer is responsible for obtaining the required consent.
ResvPro maintains the following measures. Measures marked [Planned] are committed to but not yet fully implemented as of the effective date; ResvPro will implement them before processing production Personal Data for Customer.
| Area | Measures |
|---|---|
| Encryption | TLS 1.2 or higher for all data in transit, including to Subprocessors. Encryption at rest for databases, object storage, and backups. |
| Access control | Unique named accounts, no shared credentials; multi-factor authentication on all administrative and cloud accounts; least-privilege role-based access; access reviewed on role change and revoked on departure. |
| Environment separation | Production separated from development and test environments. Production Personal Data is not used in development or test. |
| Logging and monitoring | Application and infrastructure logs retained and monitored; administrative actions and access to Personal Data recorded in audit logs. [Planned] — centralized log aggregation and alerting. |
| Vulnerability management | Dependency scanning and prompt patching of known vulnerabilities. [Planned] — annual third-party penetration test. |
| Backup and recovery | Automated encrypted backups with defined retention; documented restore procedure tested periodically. [Planned] — documented RTO and RPO targets. |
| Secure development | Code review before merge; secrets held in a managed secret store, never in source control; change history retained. |
| Personnel | Written confidentiality obligations; security awareness training; background screening where lawful and appropriate to the role. |
| Subprocessor management | Security and privacy review before engagement; contractual flow-down of this DPA's obligations; periodic review. |
| Incident response | Documented incident response procedure with defined roles, severity levels, and the notification path in Section 5. [Planned] — annual tabletop exercise. |
| Data minimization and retention | Collection limited to what the Services require; retention per the ResvPro Privacy Policy and Customer's configured settings; deletion on the schedule in Section 9. |
| Physical security | Production infrastructure is hosted with cloud providers operating certified data centers; ResvPro maintains no on-premises production infrastructure. |
As of the effective date:
| Subprocessor | Role | Personal Data processed | Location |
|---|---|---|---|
| Twilio Inc. | Telephony and messaging — call connectivity, SMS delivery, delivery receipts | Phone numbers, call metadata and audio, message content, consent and opt-out records | United States |
| Google LLC (Google Workspace) | Business email and productivity for ResvPro personnel supporting Customer | Contact details and any Personal Data contained in support correspondence | United States |
| Webflow, Inc. | Hosting of resvpro.com and its forms | Contact details submitted through Site forms | United States |
To be added before production processing begins, on notice under Section 6.2: cloud infrastructure and managed database hosting; AI model providers for voice and text generation (engaged on a zero-retention or no-training basis); a voice synthesis and voice cloning provider, engaged only where Customer enables that optional feature; a payment processor for Customer billing; error monitoring and analytics.
No voice recording or voice model is transmitted to a voice cloning provider until that provider is named in this Annex and Customer has received notice under Section 6.2.
An up-to-date list, including planned subprocessors, is published at resvpro.com/subprocessors. To receive change notices by email, write to privacy@resvpro.com.
ResvPro LLC · 3750 Gunn Highway, Suite 306J, PMB 1165, Tampa, FL 33618
Privacy: privacy@resvpro.com · Legal: legal@resvpro.com