DATA PROTECTION ADDENDUM

Version 1.0 | Effective September 25, 2026

‍

‍

This Data Protection Addendum (this “DPA”) supplements the Participating Property Service Provider Agreement between Guestbook Rewards, Inc. (“The Guestbook”) and Participating Property (the “Agreement”). This DPA applies in either of the following circumstances: (i) it is attached to the Agreement as Exhibit C, in which case it is incorporated into the Agreement and takes effect as of the Effective Date; or (ii) the parties execute it separately at a later date, including in connection with a Connected System integration, in which case it is incorporated into the Agreement and takes effect as of the date of the later signature set out in Section 13. In either case, that date is the “DPA Effective Date.”

‍

Where this DPA is executed separately, it applies to all processing of Personal Data carried out under the Agreement from the Effective Date onward, including processing that occurred before the DPA Effective Date, and it supersedes any prior data protection terms agreed between the to the same subject matter. Capitalized terms used but not defined in this DPA have the meanings given to them in the Agreement.

‍

‍

‍

1.  Purpose and Roles of the Parties:

‍

The Services operate as a consumer loyalty program that The Guestbook offers directly to individuals. Guests enroll with The Guestbook under the Terms of Use and the Privacy Policy, establish a direct relationship with The Guestbook, and may earn and redeem Rewards across all participating properties. Accordingly, the parties acknowledge and agree as follows:

‍

(a) The Guestbook is the controller (and, under U.S. Privacy Laws, the “business”) with respect to Member Data. The Guestbook determines the purposes and means of the processing of Member Data and is responsible for providing notice to, and for honoring the rights of, the individuals who register for the Services.

‍

(b) Participating Property is the controller (and “business”) with respect to Property Guest Data, including its own reservation, folio, guest profile, and property management system records.

‍

(c) Except as expressly provided in Section 7 (Connected System Data), each party acts as an independent and separate controller with respect to Personal Data it receives from the other. Except as provided in Section 7, neither party is a processor, sub-processor, or “service provider” of the other in connection with the Services, and the parties are not joint controllers within the meaning of Article 26 of the GDPR. Each party independently determines the purposes and means of its own processing and is independently responsible for its own compliance with Privacy Laws.

‍

(d) This DPA applies to each Affiliate that participates in the Services under the Agreement, and references to Participating Property include that Affiliate in respect of its own participation. Participating Property represents that it has authority to enter into this DPA on behalf of each such Affiliate and to give the instructions and make the commitments set out in this DPA in respect of Personal Data relating to that Affiliate’s guests. Participating Property will procure that each such Affiliate complies with this DPA and remains responsible for their acts and omissions as if they were its own. An Affiliate may, but need not, execute a joinder in a form reasonably acceptable to The Guestbook in order to become a party in its own right. Any notice, election, or opt-out given by Participating Property under this DPA applies to its participating Affiliates unless it states otherwise.

‍

‍

‍

‍

2.  Definitions:

‍

“Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with Participating Property, and any hotel property that Participating Property or such an entity owns, leases, manages, or operates. For this purpose, “control” means ownership of more than fifty percent (50%) of the voting interests, or the power to direct the management and policies of an entity or property, whether through ownership, contract, or a management agreement.

‍

“Extranet” means RewardsDash, The Guestbook’s partner extranet, or any successor partner portal that The Guestbook makes available to Participating Property.

‍

“Member Data” means Personal Data of individuals who register for the Services with The Guestbook, including registration and account details, birth month and day, stated hotel preferences, Rewards balances, redemption activity, Eligible Bill and Eligible Charges information associated with a registered account, and other information an individual provides to The Guestbook to enable a Reward or Benefit offered from time to time.

“Property Guest Data” means Personal Data relating to Participating Property’s guests that Participating Property holds in its own systems.

‍

“Shared Member Data” has the meaning given in Section 4.

‍

“Privacy Laws” means all data protection and privacy laws applicable to a party’s processing under this DPA, including the California Consumer Privacy Act as amended by the California Privacy Rights Act and comparable U.S. state privacy laws (collectively, “U.S. Privacy Laws”) and the EU General Data Protection Regulation, the UK GDPR, and the UK Data Protection Act 2018 (collectively, “European Privacy Laws”).

‍

“Personal Data,” “controller,” “processor,” “process,” “sell,” “share,” “business,” and “Sensitive Personal Information” have the meanings given to them under the applicable Privacy Laws.

‍

“Security Incident” means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Personal Data processed by a party.

‍

“Termination Date” has the meaning given in the Agreement or, if not defined there, means the date on which the Agreement expires or terminates.

‍

‍

‍

‍

3.  Personal Data Disclosed by Participating Property:

‍

Participating Property will disclose to The Guestbook only the Personal Data reasonably necessary to (i) validate Eligible Bills and Eligible Charges, (ii) calculate, issue, and reconcile Rewards, the Member Reward Reimbursement, and Fees, and (iii) support Guests in connection with the Services (collectively, the “Permitted Purposes”). Where Participating Property provides a guest folio or equivalent record to evidence that a stay occurred and its final cost, that record may contain line items other than Rooms Charges. The Guestbook will use any such non-Rooms Charges line items solely to validate the Eligible Bill and the Eligible Charges, and will not use them to build guest profiles, to make inferences about a Guest, or for marketing. The Guestbook will not use Personal Data received from Participating Property for any purpose that is incompatible with the Permitted Purposes and the operation of the Services as described in the Privacy Policy.

‍

‍

‍

‍

4.  Personal Data Disclosed by The Guestbook:

‍

Where a Guest holds a reservation with Participating Property, The Guestbook may disclose to Participating Property the Member Data reasonably necessary for Participating Property to recognize that Guest and to deliver the Services, the Guest’s stay, and any applicable Benefits, including the Guest’s name, membership status, stay and room charge spend history at Participating Property, stated accommodation and service preferences, reservation identifiers, birth month and day, and other information the Guest has provided to The Guestbook to enable a Reward or Benefit offered from time to time (“Shared Member Data”). Shared Member Data does not include any special category of Personal Data or Sensitive Personal Information, which are addressed in Section 5. The Guestbook makes this disclosure as controller and in reliance on the notice given to members in the Privacy Policy, which states that The Guestbook may share Personal Data with its business partners who are members of The Guestbook program in order to provide services to the member. With respect to Shared Member Data, Participating Property will:

‍

(a) use it solely to service and fulfill the Guest’s reservation and stay and to deliver Rewards and Benefits under the Agreement;

‍

(b) except as expressly permitted under the paragraph titled “Consented Marketing Data” below, not use it for its own or any third party’s marketing or promotional purposes, not add it to any marketing list, loyalty program, or guest-profile database maintained for marketing purposes, and not disclose it to any third party other than its own service providers acting on its behalf under written contract;

‍

(c) not sell or share it (as those terms are defined under U.S. Privacy Laws) and not use it for cross-context behavioral advertising;

‍

(d) retain it only for so long as necessary for the Guest’s reservation and stay and for applicable legal, tax, and audit requirements, and thereafter delete or de-identify it; and

‍

(e) apply to it at least the same level of protection required of The Guestbook under this DPA. The parties intend the restrictions in this Section 4 to satisfy the Accountability for Onward Transfer Principle under any DPF Program certification referenced in Section 10 with respect to Shared Member Data originating in the European Economic Area, the United Kingdom, or Switzerland.

‍

Nothing in this Section 4 restricts Participating Property’s use of Personal Data that it collects directly from a Guest, or that it otherwise holds, independently of the Services. Where Participating Property obtains a Guest’s consent for marketing independently of the Services, that consent governs Participating Property’s use of the Personal Data it collected under it.

‍

Consented Marketing Data. Where an individual has given affirmative, opt-in consent at the time of enrollment in the Services to receive marketing communications from the specific Participating Property at which that individual enrolled, The Guestbook may disclose that individual’s name and e-mail address to that Participating Property for that ParticipatingProperty’s own marketing and promotional purposes (“Consented Marketing Data”). The Guestbook will disclose Consented Marketing Data to Participating Property only for individuals who enrolled in the Services at Participating Property, and will not disclose to Participating Property the Consented Marketing Data of any individual who enrolled elsewhere. The Guestbook will obtain and record that consent before any such disclosure and will forward to Participating Property any withdrawal of consent it receives. Consented Marketing Data is not Shared Member Data, and Sections 4(a) through (d) do not apply to it. With respect to Consented Marketing Data, Participating Property:

‍

(i) acts as an independent controller and “business” for its own marketing purposes and is solely responsible for its own compliance with Privacy Laws and with any other law applicable to it as sender, including the CAN-SPAM Act and the Telephone Consumer Protection Act;

‍

(ii) will maintain its own unsubscribe mechanism in every marketing communication and will honor any withdrawal of consent communicated by the individual or forwarded by The Guestbook, in each case no later than ten (10) business days after receipt;

‍

(iii) will not sell or share Consented Marketing Data (as those terms are defined under U.S. Privacy Laws), and will not disclose it to any third party other than its own service providers acting on its behalf under written contract;

‍

(iv) will not use Consented Marketing Data to identify, profile, or target any person other than the individual to whom it relates, and will not use it to determine whether any other person is enrolled in the Services;

‍

(v) may continue to use Consented Marketing Data it received while a Participating Property, including after the Termination Date, until the individual withdraws consent or opts out of Participating Property’s marketing communications; and

‍

(vi) will indemnify and hold harmless The Guestbook from third-party claims, and fines or penalties imposed by a supervisory authority, to the extent arising out of Participating Property’s use of Consented Marketing Data, whether arising before or after the Termination Date. This indemnity is subject to the limitations of liability set forth in the Agreement.

‍

The Guestbook will not disclose additional Consented Marketing Data to Participating Property after the Termination Date, and will forward to Participating Property any withdrawal of consent it receives, whether before or after the Termination Date, to the last notice address Participating Property provided. Participating Property’s obligations under clauses (i) through (iv) and (vi) above, and its obligation to honor withdrawals of consent, survive the expiration or termination of the Agreement for so long as Participating Property retains or uses any Consented Marketing Data, and end once Participating Property has deleted or de-identified all Consented Marketing Data and confirmed that in writing to The Guestbook. Until then, Participating Property will keep a current notice address on file with The Guestbook for this purpose.

‍

The parties intend the restrictions in this paragraph to satisfy the Accountability for Onward Transfer Principle with respect to Consented Marketing Data originating in the European Economic Area, the United Kingdom, or Switzerland. For individuals in those regions, The Guestbook will obtain opt-in consent meeting the requirements of the DPF Choice Principle and European Privacy Laws before any such disclosure.

‍

‍

‍

‍

5.  Payment Data and Special Categories:

‍

Participating Property will not include payment card numbers or other payment instrument details in any folio or other record it provides to The Guestbook, consistent with The Guestbook’s published practice that credit card information is never seen nor stored by The Guestbook. Neither party will disclose to the other any special category of Personal Data within the meaning of Article 9 of the GDPR or any Sensitive Personal Information, and the preferences exchanged under this DPA are limited to accommodation and service preferences that do not reveal health, religious, or similar information. Where Participating Property requires dietary, accessibility, medical, or similar information in order to serve a Guest, it will collect that information directly from the Guest under its own privacy notice, and such information is not Shared Member Data. If either party becomes aware that it has received such information from the other, it will notify the other party and delete the information unless retention is required by law.

‍

‍

‍

6.  Integrated Rewards Analytics Data:

‍

The Guestbook may capture de-identified event data from the websites, booking engines, and mobile or web applications on which the Integrated Rewards Functionality is deployed, other than a Connected System (together, “Property Digital Channels”) — such as whether the rewards offer was displayed, whether a visitor interacted with it, the stage of the booking flow reached, and the value of the reward displayed (“Integrated Rewards Analytics Data”) — for the purpose of reporting on, measuring, and enhancing the Services for Participating Property.

‍

Exclusions. Integrated Rewards Analytics Data does not include any name, e-mail address, telephone number, postal address, payment information, or other information that identifies an individual, and The Guestbook does not use any persistent device identifier for analytics purposes. Integrated Rewards Analytics Data is keyed to an identifier generated for the visitor’s browsing session, is not retained after that session ends, and is not linked to any individual.

‍

Member recognition. To recognize members, the Integrated Rewards Functionality transmits to The Guestbook the name, e-mail address, and reservation details that a guest enters in or receives from a Property Digital Channel. Where the guest is or becomes enrolled in the Services, The Guestbook processes that information as Member Data under Sections 1 and 2. Where the guest is not enrolled, The Guestbook uses the guest’s name and e-mail address solely to determine whether the guest is enrolled and does not retain them. The Guestbook retains the associated reservation record in pseudonymized form — including the confirmation number but excluding the guest’s name, e-mail address, and other direct identifiers — in order to report enrollment rates to Participating Property, to recalculate Rewards, the Member Reward Reimbursement, and Fees, and to maintain an audit trail, and retains it only for as long as necessary for those purposes and for applicable legal, tax, and audit requirements. A pseudonymized reservation record is not Integrated Rewards Analytics Data. The Guestbook will not attempt to reidentify any individual from a pseudonymized reservation record and will not combine it with other information in order to do so. The Guestbook does not use information about guests who are not enrolled for marketing, for profiling, or to solicit enrollment.

‍

Safeguards. With respect to Integrated Rewards Analytics Data, The Guestbook will: (a) implement technical safeguards and business processes that prohibit reidentification; (b) not attempt to reidentify any individual, and not permit any recipient to do so; and (c) not combine it with other data in a manner that would reidentify an individual. Integrated Rewards Analytics Data is not Personal Data and is “deidentified” within the meaning of U.S. Privacy Laws.

‍

Deletion on termination. Upon expiration or termination of the Agreement, The Guestbook will delete Integrated Rewards Analytics Data that identifies Participating Property within ninety (90) days after the Termination Date. This does not apply to data that has been aggregated with data of other participating properties in a form that does not identify Participating Property, which The Guestbook may retain and use for benchmarking, research, and improvement of the Services.

‍

Limits on cross-property use. The Guestbook will not disclose to any other participating property, or to any third party, any data that identifies Participating Property or Participating Property’s individual performance, without Participating Property’s prior written consent. The Guestbook will make available benchmarking outputs derived from the aggregated pool only where the output reflects at least five (5) participating properties, and will suppress any figure from which a single property’s contribution could reasonably be derived. The Guestbook will not construct a comparison about Participating Property for the benefit of a named competitor, and will not use Participating Property’s performance data in sales or marketing materials without its prior written consent. For the avoidance of doubt, data contributed to the aggregated pool informs industry-level benchmarks and improvements to the Services that are available to participating properties generally.

‍

Benchmarking opt-out. Participating Property may opt out of the inclusion of its data in aggregated datasets used for cross-property benchmarking by giving written notice to The Guestbook at contact@theguestbook.com or through the Extranet. The opt-out takes effect within thirty (30) days after receipt, is given at no charge, and applies prospectively to both Integrated Rewards Analytics Data under this Section and Connected System Data under Section 7. Because an aggregated dataset cannot be disaggregated, the opt-out does not require The Guestbook to alter, withdraw, or reconstruct any aggregated dataset created before it takes effect. The opt-out does not affect The Guestbook’s use of data to report on, measure, and enhance the Services for Participating Property itself. Where Participating Property opts out, The Guestbook may exclude Participating Property from cross-property benchmarking reports and comparative insights derived from the aggregated pool.

‍

‍

‍

7.  Connected System Data:

‍

If Participating Property elects to connect its property management system (PMS), central reservation system (CRS), customer relationship management system (CRM), content management system (CMS), or any similar system to the Services (each, a “Connected System”), The Guestbook will ingest and process the Personal Data made available through that Connected System and accepted by The Guestbook in accordance with the field mapping it establishes during integration (“Connected System Data”) solely in order to provide the Services to Participating Property. A Connected System may transmit a fixed set of fields that Participating Property cannot vary or suppress; The Guestbook accepts into its systems only the mapped fields, and disregards any other field at ingestion without storing it. With

‍

(a) process it only for the purposes of providing the Services and on Participating Property’s documented instructions. The parties agree that this DPA, the Agreement, and Participating Property’s election to connect a Connected System and to receive the Services, together constitute Participating Property’s complete documented instructions for the processing of Connected System Data, including with respect to international transfers, and that no separate or further instruction is required. The Guestbook establishes the field mapping during integration, limited to the fields reasonably necessary to provide the Services, and will make the then-current mapping available to Participating Property on request. Participating Property may issue additional instructions only in writing, and where an additional instruction falls outside the scope of the Services The Guestbook may decline it or condition it on agreement as to scope, timing, and fees. Participating Property’s instructions may not require The Guestbook to ingest, map, or otherwise process any special category of Personal Data or Sensitive Personal Information, and any instruction or field mapping that would do so is outside the scope of this DPA and will be disregarded. The Guestbook will not process Connected System Data otherwise unless required by applicable law, in which case it will inform Participating Property of that requirement before processing unless the law prohibits it;

‍

(b) not retain, use, or disclose it for any purpose other than performing the Services and the purposes expressly permitted in this Section, not sell or share it, and not retain, use, or disclose it outside the direct business relationship between the parties, except that The Guestbook may use it internally to build and improve the quality of the Services as permitted under U.S. Privacy Laws, provided that such use does not include building or modifying profiles of individual consumers for use outside the Services, or cleaning or augmenting data acquired from another source;

‍

(c) not combine it with Personal Data that The Guestbook receives from or on behalf of any other person, or collects from its own interactions with individuals, except as necessary to perform the Services or as otherwise permitted by U.S. Privacy Laws;

‍

(d) ensure that persons authorized to process it are bound by written confidentiality obligations;

‍

(e) implement and maintain the technical and organizational measures described in Annex 2;

‍

(f) engage sub-processors only under written contracts imposing obligations materially equivalent to those in this Section, and give Participating Property at least thirty (30) days’ notice before authorizing any new sub-processor, which Participating Property may object to on reasonable data protection grounds. If the parties do not resolve an objection within a reasonable period, Participating Property may discontinue the affected Connected System integration without penalty;

‍

(g) taking into account the nature of the processing, assist Participating Property by appropriate technical and organizational measures in responding to requests from individuals exercising their rights, and promptly forward to Participating Property any such request it receives directly;

‍

(h) assist Participating Property in ensuring compliance with its obligations relating to security, Security Incident notification, data protection impact assessments, and prior consultation, taking into account the nature of the processing and the information available to The Guestbook;

‍

(i) notify Participating Property without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Security Incident affecting Connected System Data. This period is shorter than the period in Section 8(d) because The Guestbook acts as a processor of Connected System Data, and Participating Property, as controller of that data, must in turn notify its supervisory authority within seventy-two (72) hours of becoming aware of the incident;

‍

(j) make available to Participating Property the information necessary to demonstrate compliance with this Section and allow for and contribute to audits, including inspections, by Participating Property or an auditor it mandates. Such audits will be satisfied in the first instance by The Guestbook’s then-current security documentation and its responses to a reasonable security questionnaire. Where Participating Property reasonably demonstrates that those are insufficient, it may conduct an on-site audit no more than once in any twelve (12) month period, on at least thirty (30) days’ written notice, during normal business hours, subject to confidentiality obligations and at its own cost; and

‍

(k) promptly inform Participating Property if, in The Guestbook’s opinion, an instruction infringes Privacy Laws, and notify Participating Property if The Guestbook determines that it can no longer meet its obligations under this Section.

‍

Aggregated and deidentified data. Participating Property instructs The Guestbook to create aggregated and deidentified datasets from Connected System Data. The Guestbook will produce those datasets so that they do not identify, relate to, describe, or become reasonably linkable, directly or indirectly, to any individual or to Participating Property, and will apply to them the reidentification safeguards described in Section 6. Datasets produced in accordance with this paragraph are not Personal Data and are not Connected System Data, and The Guestbook may retain and use them, including after the Termination Date, for benchmarking, research, reporting, and improvement of the Services. This paragraph is subject to the benchmarking opt-out in Section 6.

‍

Deletion and return. Upon expiration or termination of the Agreement, or at any time upon Participating Property’s written request, The Guestbook will delete Connected System Data or, at Participating Property’s election made within thirty (30) days after the Termination Date, return it in a commonly used machine-readable format and then delete it. The Guestbook will complete deletion within sixty (60) days after the Termination Date or the date of the request, except that (i) it may retain Connected System Data to the extent required by applicable law, (ii) copies held in routine backups will be deleted in accordance with its standard backup cycle and remain subject to this Section until deleted, and (iii) aggregated and deidentified datasets produced in accordance with the paragraph above are not Connected System Data and are not subject to deletion, return, or the retention limits in this paragraph.

‍

Boundary with The Guestbook’s own processing. Where Personal Data made available through a Connected System is also used by The Guestbook for the Permitted Purposes described in Section 3 — including validating Eligible Bills and Eligible Charges and calculating Rewards, the Member Reward Reimbursement, and Fees — The Guestbook acts as an independent controller with respect to that use and the records it creates for those purposes, as described in Sections 1 and 3, and this Section 7 does not apply to them. The parties acknowledge that the same underlying information may therefore be processed by The Guestbook in both capacities, for different purposes. Data deidentified in accordance with Section 6 is not Connected System Data.

‍

‍

‍

8.  The Guestbook Commitments:

‍

The Guestbook will:

‍

(a) Security. maintain a written information security program with appropriate technical and organizational measures, no less protective than those summarized in Annex 2 to this DPA, designed to protect Personal Data against Security Incidents;

‍

(b) Personnel. ensure that personnel authorized to access Personal Data are bound by written confidentiality obligations and receive appropriate privacy and security training;

‍

(c) Service Providers. engage service providers that process Personal Data in connection with the Services (including hosting, analytics, communications, and payment providers) only under written contracts imposing data protection obligations materially no less protective than those in this DPA, and remain responsible for their performance in connection with the Services; a current list of the categories of such service providers is available to Participating Property upon written request;

‍

(d) Security Incident Notification. notify Participating Property without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Security Incident affecting Personal Data that Participating Property disclosed to The Guestbook or that The Guestbook disclosed to Participating Property, and provide the information then reasonably available to The Guestbook to assist Participating Property in meeting its own notification obligations. This period corresponds to the seventy-two (72) hour period in Article 33(1) of the GDPR, which applies to each party as controller of the Personal Data it holds; the shorter period in Section 7(i) applies instead where The Guestbook acts as a processor of Connected System Data;

‍

(e) Individual Rights. maintain a process by which individuals may exercise the rights of access, correction, deletion, portability, opt-out, and limitation available to them under Privacy Laws, through the account pages of the Services and at contact@theguestbook.com, and respond to such requests as controller of Member Data;

‍

(f) No Sale or Sharing. not sell or share (as those terms are defined under U.S. Privacy Laws) Personal Data disclosed to it by Participating Property, and not use such Personal Data for cross-context behavioral advertising;

‍

(g) Retention. retain Personal Data only for as long as necessary for the Permitted Purposes, the operation of members’ accounts, and applicable legal, tax, and audit requirements, and thereafter delete or de-identify it in accordance with its retention schedule and the Privacy Policy; and

‍

(h) Records and Assistance. maintain records of its processing as required by Privacy Laws and, upon reasonable written request no more than once in any twelve (12) month period, provide Participating Property with a summary of its then-current security practices and responses to a reasonable security questionnaire, which the parties agree will satisfy Participating Property’s audit rights in the first instance. Where Participating Property reasonably demonstrates that those are insufficient, or where a supervisory authority requires more, the parties will agree a proportionate alternative. This clause does not apply to Connected System Data, for which the audit rights in Section 7(j) govern.

‍

‍

‍

9.  Participating Property Commitments:

‍

Participating Property will:

‍

(a) provide its guests with any notice, and obtain any consent, required under Privacy Laws for the disclosure of Personal Data to The Guestbook and for their participation in the Services, and maintain a lawful basis for each such disclosure;

‍

(b) disclose only accurate Personal Data that is necessary for the Permitted Purposes;

‍

(c) implement appropriate technical and organizational measures to protect Personal Data in its possession or control, including Shared Member Data;

‍

(d) notify The Guestbook without undue delay of any Security Incident affecting Personal Data exchanged under the Agreement;

‍

(e) promptly inform The Guestbook if it receives a request from an individual that relates to Member Data or Shared Member Data, so that The Guestbook may respond to that request as controller; and

‍

(f) be responsible for the content, operation, and legal compliance of its own websites, booking engines, and other Property Digital Channels, including any notice or consent required from its site visitors.

‍

‍

‍

10.  International Data Transfers:

‍

The Guestbook participates in, and maintains an active self-certification under, the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework (each, a “DPF Program”), in each case covering non-human-resources personal data, as reflected in the certification record listed under the name “The Guestbook” on the Data Privacy Framework List published at www.dataprivacyframework.gov. For so long as a certification remains active, The Guestbook adheres to the applicable DPF Principles with respect to Personal Data received from the region that certification covers, including the Notice, Choice, and Accountability for Onward Transfer Principles and the independent recourse mechanism identified in its certification, and remains subject to the investigatory and enforcement authority of the U.S. Federal Trade Commission. Participating Property may rely on the applicable certification as the transfer mechanism for Personal Data it transfers to The Guestbook from a region that certification covers.

‍

Where The Guestbook does not hold an active certification covering the relevant region, or where such a certification lapses, is suspended, is withdrawn, or is invalidated, or where Participating Property is otherwise required by European Privacy Laws to put an alternative transfer mechanism in place, then Module One (controller to controller) of the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914, and, for transfers subject to UK law, the UK International Data Transfer Addendum to those clauses, are incorporated into this DPA by reference and apply automatically to that transfer without further action by the parties, with Participating Property as data exporter and The Guestbook as data importer. For purposes of those clauses, Annex I is completed by Annex 1 to this DPA, Annex II is completed by Annex 2 to this DPA, the optional docking clause does not apply, and the governing law and forum are those of Ireland. For Connected System Data, Module Two (controller to processor) of those Standard Contractual Clauses applies in place of Module One, with Participating Property as data exporter and The Guestbook as data importer, and the obligations in Section 7 of this DPA constitute the description of the processing and of the technical and organizational measures required by those clauses. Upon Participating Property’s reasonable request, the parties will execute a standalone copy of the applicable clauses.

‍

‍

‍

11.  Cooperation and Government Requests:  

‍

Each party will provide the other with reasonable cooperation and information necessary for the other to fulfill its obligations under Privacy Laws in connection with the Services, including in relation to data protection impact assessments and inquiries from supervisory authorities. If a party receives a legally binding request from a public authority for Personal Data it received from the other party, it will, to the extent legally permitted, notify the other party and challenge any request that appears unlawful or overbroad.

‍

‍

‍

12.  Precedence, Liability, and Term:  

‍

This DPA forms part of the Agreement. In the event of a conflict between this DPA and the body of the Agreement with respect to the processing of Personal Data, this DPA controls; with respect to all other matters, the Agreement controls. Nothing in this DPA is intended to vary or expand any limitation of liability set forth in the Agreement. This DPA takes effect on the DPA Effective Date and continues for so long as either party processes Personal Data received from the other under the Agreement. Sections 1, 2, 4 (including the paragraph titled “Consented Marketing Data” and the surviving obligations stated in it), 5, 6, 7, 8(f), 8(g), and 12 of this DPA survive the expiration or termination of the Agreement.

‍

‍

‍

13.  Execution:  

‍

Where this DPA is attached to the Agreement as Exhibit C, it is executed by the parties’ signature of the Agreement and no separate signature is required, and the signature block below may be left blank. Where the parties execute this DPA separately, it may be signed in counterparts, including by electronic signature or by an authorized representative of Participating Property accepting it in the Extranet, each of which is an original and all of which together constitute one instrument. Acceptance in the Extranet satisfies any requirement that this DPA be recorded in writing, including for the purposes of Article 28(9) of the GDPR. The Guestbook will record the identity of the individual who accepted, the date and time of acceptance, and the version accepted, and will make that record available to Participating Property on request.

‍

‍

‍

14.  Changes to this DPA:

‍

The Guestbook may update this DPA from time to time by publishing a revised version at https://theguestbook.com/hoteliers/data-protection-addendum and giving Participating Property at least thirty (30) days’ written notice by e-mail to the address Participating Property has provided, through the Extranet, or both. A revised version takes effect at the end of that notice period. Where a change would materially reduce the protections in this DPA, Participating Property may object in writing, including through the Extranet, before the change takes effect, in which case the version in effect immediately before the change continues to apply to Participating Property until the parties agree otherwise. The Guestbook will identify each version by version number and effective date, will publish each version at a stable address, and will make prior versions available on request. This Section does not apply to a copy of this DPA that the parties have negotiated and signed as a separate instrument, which may be amended only in writing signed by both parties. Participating Property’s acceptance of the published version of this DPA, including acceptance in the Extranet under Section 13, does not make this Section inapplicable.

‍

To be completed only if this DPA is executed separately from the Agreement:

‍

‍

THE GUESTBOOK:                                            PARTICIPATING PROPERTY:

‍

Guestbook Rewards, Inc.                                  __________________________

‍

By: _______________________________                    By: ____________________________

(Signature)                                                         (Signature)

‍

Name: _____________________________                  Name: __________________________

‍

Title: ______________________________                   Title: ___________________________

‍

Date:  _____________________________                   Date: ___________________________

‍

‍

‍

‍

ANNEX 1: DESCRIPTION OF THE DATA TRANSFERS

‍

Parties. Data exporter: Participating Property, at the address stated in the Agreement, acting as controller and, for Transfer E, as the controller instructing The Guestbook as processor. Data importer: Guestbook Rewards, Inc., 10785 W. Twain Ave, Suite 100, Las Vegas, NV 89135, USA, contact contact@theguestbook.com, acting as controller except for Transfer E, where it acts as processor. The activities relevant to the transfers are the Services described in the Agreement.

‍

Competent supervisory authority. Where the Standard Contractual Clauses apply under Section 10, the competent supervisory authority is determined in accordance with Clause 13 of those clauses.

‍

Categories of data subjects. For Transfers A, B, and C, guests of Participating Property who register for the Services with The Guestbook. For the pseudonymized reservation records described in Transfer D, guests of Participating Property who make a reservation through a Property Digital Channel, whether or not they register for the Services; Integrated Rewards Analytics Data itself does not relate to an identified or identifiable individual. For Transfer E, the individuals whose Personal Data Participating Property makes available through a Connected System, which may include guests, prospective guests, and Participating Property’s own booking contacts.

‍

Transfer A — Participating Property to The Guestbook. Name and email address; reservation and stay details, including confirmation or folio number, property, arrival and departure dates, rate code, rate, rate with taxes and fees, and room type; the guest folio or equivalent record evidencing that the stay occurred and its final cost, which may contain line items other than Rooms Charges; and Eligible Bill and Eligible Charges amounts. Payment card numbers and payment instrument details are excluded under Section 5.

‍

Transfer B — The Guestbook to Participating Property (Shared Member Data). Categories such as Guest name, membership status, stay and room charge spend history at Participating Property, reservation identifiers, stated accommodation and service preferences, birth month and day, Rewards and Benefits applicable to the reservation, and other information the Guest has provided to enable a Reward or Benefit, excluding special categories of Personal Data and Sensitive Personal Information.

‍

Transfer C — The Guestbook to Participating Property (Consented Marketing Data). Name and e-mail address only, and only for individuals who enrolled in the Services at Participating Property and gave affirmative opt-in consent at enrollment, as described in Section 4.

‍

Transfer D — Integrated Rewards Analytics Data. Integrated Rewards Analytics Data consists of de-identified event data — offer displayed, visitor interaction, booking flow stage, reward value, and whether the guest was enrolled — recorded in accordance with Section 6, and is not Personal Data. Separately, The Guestbook retains reservation records in pseudonymized form, including the confirmation number and excluding the guest’s name, e-mail address, and other direct identifiers. Name and e-mail address transmitted for member recognition are processed as Member Data where the guest is enrolled and are not retained where the guest is not enrolled.

‍

Transfer E — Connected System Data. Personal Data made available through a Connected System that Participating Property elects to connect and accepted by The Guestbook under the field mapping it establishes, processed as processor under Section 7. A Connected System may transmit a fixed set of fields that Participating Property cannot vary or suppress; only the mapped fields are accepted into The Guestbook’s systems, and any other field is disregarded at ingestion and not stored. The mapped fields depend on the integration and typically include guest name and contact details, reservation and stay records, and guest profile and preference fields.

‍

Sensitive data. None. Under Section 5, neither party discloses special categories of Personal Data or Sensitive Personal Information to the other, and preferences are limited to accommodation and service preferences. Where a Connected System transmits fields that Participating Property cannot suppress, The Guestbook will not include special categories of Personal Data or Sensitive Personal Information in the field mapping, and will disregard any such field at ingestion.

‍

Frequency of the transfers. Continuous, for the duration of the Agreement. Transfer B occurs only in connection with a Guest reservation at Participating Property. Transfer C occurs only upon enrollment with consent. Transfer E occurs only if Participating Property elects to connect a Connected System.

‍

Nature and purpose of the processing. For Transfer A, the Permitted Purposes described in Section 3. For Transfers B and C, the purposes described in Section 4. For Transfer D, the analytics purposes described in Section 6. For Transfer E, provision of the Services on Participating Property’s documented instructions, as described in Section 7.

‍

Retention period. For Transfer A, as described in Section 8(g). For Transfer B, as described in Section 4(d). For Transfer C, until the individual withdraws consent or opts out, as described in the paragraph titled “Consented Marketing Data.” For Transfers D and E, as described in Sections 6 and 7 respectively.

‍

Recipients. The categories of service providers described in Section 8(c), and, for Transfer B, Participating Property’s own service providers acting on its behalf under written contract.

‍

‍

ANNEX 2: TECHNICAL AND ORGANIZATIONAL MEASURES

‍

The Guestbook maintains a written information security program that includes measures such as the following, implemented as appropriate to the risks presented by the processing:

‍

•   Encryption of Personal Data in transit using industry-standard TLS, and encryption of Personal Data at rest.

‍

•   Role-based access control, unique user credentials, and multi-factor authentication for administrative access to systems holding Personal Data.

‍

•   Logical separation of each Participating Property’s data within multi-tenant systems.

‍

•   Logging and monitoring of access to production systems holding Personal Data.

‍

•   Documented change management, vulnerability management, and patch management processes.

‍

•   Confidentiality agreements with personnel, background screening where permitted by applicable law, and periodic security awareness training.

‍

•   A documented incident response plan with defined escalation and notification procedures.

‍

•   Backup and business continuity procedures, including regular backups and periodic restoration testing.

‍

•   Secure disposal or de-identification of Personal Data at the end of the applicable retention period.

‍

•   Diligence over service providers, including contractual data protection commitments.

‍

‍