Data Processing Agreement (DPA)
Public version aligned with Annex 2 of the signed SaaS Agreement. Compliant with GDPR Article 28.
Data Protection Contact
HITECH GROUP SASU — Ms Olesea PANCIUC, President
Registered office: 2323 Chemin de Saint-Bernard, 06220 Vallauris, France
SIREN 101 382 752 — RCS Antibes — VAT FR15101382752
privacy@nexo-hotel.com · +33 7 55 84 13 20
Compliant with Regulation (EU) 2016/679 (GDPR) Article 28. Last updated: May 2026
1. Role of the parties
This Data Processing Agreement ("DPA") governs the processing of personal data carried out by HITECH GROUP in connection with the provision of the NEXO solution.
The hotel establishment (the Client) acts as data controller (Art. 4(7) GDPR); HITECH GROUP acts as processor (Art. 4(8) GDPR). HITECH GROUP processes data only on documented instructions from the Client. Contact: privacy@nexo-hotel.com.
2. Description of processing
| Element | Description |
|---|---|
| Nature | Hosting, collection, automated analysis (AI), translation, transmission and storage of conversational data |
| Purpose | Provision of an AI concierge service to hotel guests (assistance, information, recommendations, request handling, translation) |
| Categories of data | Identification (name if provided), contact (email/phone if provided), conversation content, session metadata, language, timestamps. Data relating to bookings and hotel stays when provided by the Client (room number, stay dates, specific requests). |
| Data subjects | Hotel guests (end users); hotel staff using the interface |
| Sensitive data | The Service is not designed to process special categories of data under Article 9 GDPR. If such data is voluntarily provided by an end user (allergy, disability, pregnancy, religious conviction for dining or service needs), it is processed solely to deliver the requested service, without profiling or further processing. |
| Primary hosting | OVHcloud — datacenters located in France (European Union) |
3. Retention periods
| Data category | Duration |
|---|---|
| Guest conversations (chat, messaging, voice) | 24 months from the last interaction |
| Technical and access logs | 12 months |
| Backups | 90 days, rotating |
| Billing and contractual data | 10 years (legal obligation, French Commercial Code) |
At the end of these periods, data is securely deleted or anonymized, unless a contrary legal obligation applies.
4. Processor obligations
- Process data only on documented instructions from the Client, and inform the Client if an instruction appears to breach the GDPR.
- Ensure confidentiality of persons authorized to process data, bound by a contractual duty of confidentiality surviving the relationship.
- Implement the security measures set out in Section 5.
- Assist the Client with data subject requests, impact assessments (Art. 35) and breach notifications.
- At the end of the Agreement, return or delete data according to the Client’s choice.
5. Security (Article 32 GDPR)
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Primary hosting on OVHcloud, datacenters located in France (EU).
- Individual access control, role-based rights management, strengthened authentication, logging.
- Regular backups (90-day rotation) with tested restoration procedures.
- Documented incident management; staff awareness and confidentiality commitments.
6. Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| OVHcloud | Hosting, infrastructure, AI agents, database | France (EU) |
| OpenAI (API — Zero Data Retention or Enterprise where applicable) | Conversational AI model — contractual exclusion of training on Client data | United States — SCCs |
| Anthropic | Alternative AI model | United States — SCCs |
| Mistral AI | European AI model | EU — France |
| DeepL | Machine translation | EU — Germany |
| ElevenLabs | Voice synthesis (Phone AI option) | United States — SCCs |
| Twilio | Telephony and SMS (Phone AI option) | United States — SCCs |
| Brevo | Transactional email | EU — France |
The Client grants general authorization to use the sub-processors listed below. HITECH GROUP imposes the same protection obligations on them and notifies any change with fifteen (15) days’ notice.
An up-to-date list is available to the Client on request at privacy@nexo-hotel.com.
7. Transfers outside the European Union
Primary infrastructure (hosting, processing, AI agents, database) is located in France with OVHcloud. However, certain artificial intelligence processing may be carried out by sub-processors outside the EEA (notably the United States: OpenAI, Anthropic, ElevenLabs, Twilio), under European Commission Standard Contractual Clauses (SCCs) (Implementing Decision 2021/914), modules 2 and 3 as applicable, together with appropriate supplementary measures (encryption, data minimization, Zero Data Retention options where available), in accordance with GDPR Chapter V.
8. Data subject rights
HITECH GROUP provides features to respond to data subject requests (access, rectification, erasure, restriction, portability, objection) and assists the Client within fifteen (15) business days. Any request received directly from a data subject is forwarded to the Client without delay. Contact: privacy@nexo-hotel.com.
9. Automated decisions and AI model training
Automated processing by AI models does not produce legal effects concerning data subjects within the meaning of Article 22 GDPR. The Solution is an assistance tool; operational decisions remain with hotel staff.
Client data is not used to train the general artificial intelligence models of HITECH GROUP or its sub-processors, unless the Client gives express written consent. Client-specific content remains isolated and does not contribute to shared model learning.
10. Personal data breaches (Article 33 GDPR)
HITECH GROUP notifies the Client of any data breach of which it becomes aware within a maximum of seventy-two (72) hours, with the required information (nature, scope, categories and number of data subjects affected, consequences, measures taken), and cooperates on notifications to the CNIL and data subjects. Incident contact: privacy@nexo-hotel.com · +33 7 55 84 13 20.
11. Audit
The Client may exercise an audit right once per year, with thirty (30) days’ notice. HITECH GROUP may meet this obligation by providing its reports or certifications. HITECH GROUP may share any certification obtained subsequently (ISO 27001, SOC 2, or equivalent) at the Client’s request.
12. Return or deletion of data
At the end of the service, at the Client’s choice expressed within thirty (30) days, HITECH GROUP returns data in a structured format or securely deletes it, subject to legal retention obligations.
13. Scope — exclusion of payment services
This DPA covers only processing related to the NEXO AI concierge. It does not cover regulated payment services (PSD2/DSP2), which where applicable will be subject to separate specific agreements.
Data protection contact: privacy@nexo-hotel.com · +33 7 55 84 13 20
Supervisory authority: CNIL — 3 Place de Fontenoy, TSA 80715, 75334 PARIS CEDEX 07 — www.cnil.fr