Back to home

Data Processing Agreement (DPA)

Public version aligned with Annex 2 of the signed SaaS Agreement. Compliant with GDPR Article 28.

Data Protection Contact

HITECH GROUP SASU — Ms Olesea PANCIUC, President

Registered office: 2323 Chemin de Saint-Bernard, 06220 Vallauris, France

SIREN 101 382 752 — RCS Antibes — VAT FR15101382752

privacy@nexo-hotel.com · +33 7 55 84 13 20

Compliant with Regulation (EU) 2016/679 (GDPR) Article 28. Last updated: May 2026

1. Role of the parties

This Data Processing Agreement ("DPA") governs the processing of personal data carried out by HITECH GROUP in connection with the provision of the NEXO solution.

The hotel establishment (the Client) acts as data controller (Art. 4(7) GDPR); HITECH GROUP acts as processor (Art. 4(8) GDPR). HITECH GROUP processes data only on documented instructions from the Client. Contact: privacy@nexo-hotel.com.

2. Description of processing

ElementDescription
NatureHosting, collection, automated analysis (AI), translation, transmission and storage of conversational data
PurposeProvision of an AI concierge service to hotel guests (assistance, information, recommendations, request handling, translation)
Categories of dataIdentification (name if provided), contact (email/phone if provided), conversation content, session metadata, language, timestamps. Data relating to bookings and hotel stays when provided by the Client (room number, stay dates, specific requests).
Data subjectsHotel guests (end users); hotel staff using the interface
Sensitive dataThe Service is not designed to process special categories of data under Article 9 GDPR. If such data is voluntarily provided by an end user (allergy, disability, pregnancy, religious conviction for dining or service needs), it is processed solely to deliver the requested service, without profiling or further processing.
Primary hostingOVHcloud — datacenters located in France (European Union)

3. Retention periods

Data categoryDuration
Guest conversations (chat, messaging, voice)24 months from the last interaction
Technical and access logs12 months
Backups90 days, rotating
Billing and contractual data10 years (legal obligation, French Commercial Code)

At the end of these periods, data is securely deleted or anonymized, unless a contrary legal obligation applies.

4. Processor obligations

  • Process data only on documented instructions from the Client, and inform the Client if an instruction appears to breach the GDPR.
  • Ensure confidentiality of persons authorized to process data, bound by a contractual duty of confidentiality surviving the relationship.
  • Implement the security measures set out in Section 5.
  • Assist the Client with data subject requests, impact assessments (Art. 35) and breach notifications.
  • At the end of the Agreement, return or delete data according to the Client’s choice.

5. Security (Article 32 GDPR)

  • Encryption in transit (TLS 1.2+) and at rest (AES-256).
  • Primary hosting on OVHcloud, datacenters located in France (EU).
  • Individual access control, role-based rights management, strengthened authentication, logging.
  • Regular backups (90-day rotation) with tested restoration procedures.
  • Documented incident management; staff awareness and confidentiality commitments.

6. Sub-processors

Sub-processorPurposeLocation
OVHcloudHosting, infrastructure, AI agents, databaseFrance (EU)
OpenAI (API — Zero Data Retention or Enterprise where applicable)Conversational AI model — contractual exclusion of training on Client dataUnited States — SCCs
AnthropicAlternative AI modelUnited States — SCCs
Mistral AIEuropean AI modelEU — France
DeepLMachine translationEU — Germany
ElevenLabsVoice synthesis (Phone AI option)United States — SCCs
TwilioTelephony and SMS (Phone AI option)United States — SCCs
BrevoTransactional emailEU — France

The Client grants general authorization to use the sub-processors listed below. HITECH GROUP imposes the same protection obligations on them and notifies any change with fifteen (15) days’ notice.

An up-to-date list is available to the Client on request at privacy@nexo-hotel.com.

7. Transfers outside the European Union

Primary infrastructure (hosting, processing, AI agents, database) is located in France with OVHcloud. However, certain artificial intelligence processing may be carried out by sub-processors outside the EEA (notably the United States: OpenAI, Anthropic, ElevenLabs, Twilio), under European Commission Standard Contractual Clauses (SCCs) (Implementing Decision 2021/914), modules 2 and 3 as applicable, together with appropriate supplementary measures (encryption, data minimization, Zero Data Retention options where available), in accordance with GDPR Chapter V.

8. Data subject rights

HITECH GROUP provides features to respond to data subject requests (access, rectification, erasure, restriction, portability, objection) and assists the Client within fifteen (15) business days. Any request received directly from a data subject is forwarded to the Client without delay. Contact: privacy@nexo-hotel.com.

9. Automated decisions and AI model training

Automated processing by AI models does not produce legal effects concerning data subjects within the meaning of Article 22 GDPR. The Solution is an assistance tool; operational decisions remain with hotel staff.

Client data is not used to train the general artificial intelligence models of HITECH GROUP or its sub-processors, unless the Client gives express written consent. Client-specific content remains isolated and does not contribute to shared model learning.

10. Personal data breaches (Article 33 GDPR)

HITECH GROUP notifies the Client of any data breach of which it becomes aware within a maximum of seventy-two (72) hours, with the required information (nature, scope, categories and number of data subjects affected, consequences, measures taken), and cooperates on notifications to the CNIL and data subjects. Incident contact: privacy@nexo-hotel.com · +33 7 55 84 13 20.

11. Audit

The Client may exercise an audit right once per year, with thirty (30) days’ notice. HITECH GROUP may meet this obligation by providing its reports or certifications. HITECH GROUP may share any certification obtained subsequently (ISO 27001, SOC 2, or equivalent) at the Client’s request.

12. Return or deletion of data

At the end of the service, at the Client’s choice expressed within thirty (30) days, HITECH GROUP returns data in a structured format or securely deletes it, subject to legal retention obligations.

13. Scope — exclusion of payment services

This DPA covers only processing related to the NEXO AI concierge. It does not cover regulated payment services (PSD2/DSP2), which where applicable will be subject to separate specific agreements.

Data protection contact: privacy@nexo-hotel.com · +33 7 55 84 13 20

Supervisory authority: CNIL — 3 Place de Fontenoy, TSA 80715, 75334 PARIS CEDEX 07 — www.cnil.fr