Data Processing Agreement
Last updated: September 14, 2026
This Data Processing Agreement (“DPA”) is part of the Terms of Use between the customer who holds a WonderGuest account (the “Customer”) and SEEDFLOW, a French simplified joint-stock company (SAS) with its registered office at 24 rue Lombard, 33300 Bordeaux, France, SIREN 989 468 426 (“WonderGuest”). It applies to every processing of personal data that WonderGuest carries out on the Customer’s behalf while providing the Service. It is accepted by creating an account or continuing to use the Service. A countersigned copy is available on request at support@wonderguest.app.
Capitalized terms not defined here have the meaning given in the Terms of Use. “Guest Data” means the personal data of the Customer’s guests and prospective guests that WonderGuest processes for the Customer. “Data Protection Laws” means Regulation (EU) 2016/679 (GDPR), the French Data Protection Act (loi Informatique et Libertés) and, where they apply to the Customer, United States state privacy laws such as the California Consumer Privacy Act (CCPA).
1. Roles
For Guest Data, the Customer is the controller (or “business” under the CCPA) and WonderGuest is the processor (or “service provider”). For the Customer’s own account data, WonderGuest is the controller and the Privacy Policy applies.
2. Description of the processing
| Subject matter | Storage and display of the Customer’s guidebooks; collection of guest answers through check-in forms; processing of guest orders placed in the Customer’s extras store; sending of emails to guests at the Customer’s instruction; statistics on guidebook views. |
| Purpose | Enabling the Customer to inform, welcome and sell services to its guests. |
| Duration | The term of the Customer’s account, plus the deletion period in section 9. |
| Data subjects | Guests and prospective guests of the Customer’s properties; members of the Customer’s team who use the account. |
| Categories of personal data | Identity (first and last name); contact details (email address, telephone number, postal address entered with an extras order); stay details (arrival and departure dates, arrival time, number of adults and children, means of transport, pets, language, occasion, special requests); answers to custom questions configured by the Customer; extras orders (items, amounts, requested date and time, comments); technical data when a guest opens a guidebook (IP address, device type, pages viewed, QR code scans). |
| Special categories | None intended. The Customer agrees not to use custom questions to collect health data, government identification numbers, payment card numbers or other special categories of data; WonderGuest is not designed to process them. If a guest volunteers such information in a free-text field, the Customer remains responsible for it. |
3. Customer instructions
WonderGuest processes Guest Data only on the Customer’s documented instructions: the Terms of Use, this DPA, the settings the Customer chooses in the Service (which questions to ask, which extras to sell, which emails to send) and any further written instruction agreed by both parties. WonderGuest informs the Customer if it considers that an instruction infringes Data Protection Laws.
The Customer is responsible for having a lawful basis to collect Guest Data, for informing its guests about the processing (a notice in the guidebook or in the booking confirmation is usually enough) and for the content of the questions it asks.
4. WonderGuest’s obligations
- Confidentiality: only the people who need access to operate or support the Service have it, and they are bound by confidentiality obligations.
- Security: WonderGuest implements the measures described in section 7 and on the Security page.
- Assistance: taking into account the nature of the processing, WonderGuest assists the Customer in responding to guests who exercise their rights and in meeting its obligations on security, breach notification and data protection impact assessments.
- Requests received directly: if a guest contacts WonderGuest about Guest Data, WonderGuest forwards the request to the Customer and does not answer it on the Customer’s behalf unless the Customer asks.
- Records and audits: WonderGuest makes available the information necessary to demonstrate compliance with Article 28 GDPR. The Customer may audit that compliance once a year, on 30 days’ written notice, during business hours and at its own cost, by reviewing WonderGuest’s documentation and, where necessary, through an independent auditor bound by confidentiality. For sub-processors, WonderGuest provides their reports and certifications instead of on-site audits.
5. Sub-processors
The Customer authorizes the following sub-processors for Guest Data:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase, Inc. | Database, file storage and authentication | Switzerland (AWS, Zurich region) |
| Stripe | Payment of extras orders through Stripe payment links. WonderGuest never stores card numbers. | European Union and United States |
| Resend, Inc. | Sending of emails to guests (order confirmations, messages the Customer sends through the Service) | United States |
| PostHog, Inc. | Usage statistics on guidebooks (views, QR code scans) | European Union |
| Functional Software, Inc. (Sentry) | Error monitoring | European Union (Germany) |
WonderGuest keeps this list up to date on this page and informs Customers by email or in the Service at least 30 days before adding or replacing a sub-processor that processes Guest Data. The Customer may object on reasonable data protection grounds within that period; if the parties cannot find a solution, the Customer may terminate the affected part of the Service. WonderGuest remains responsible to the Customer for the performance of its sub-processors.
6. International transfers
Guest Data is stored in Switzerland, a country covered by a European Commission adequacy decision. Transfers to sub-processors in the United States rely on the EU-US Data Privacy Framework where the sub-processor is certified, and otherwise on the standard contractual clauses adopted by the European Commission, together with the sub-processor’s data processing terms. Customers established in the United States acknowledge that Guest Data is transferred to and stored in Europe.
7. Security measures
- Encryption in transit (TLS) and at rest.
- Row-level security policies in the database, so that each Customer only accesses its own properties, guidebooks, reservations and orders.
- Passwordless authentication for Customers (one-time code by email, Google or Apple sign-in).
- Guidebook URLs built on unguessable tokens; a guidebook can be unpublished at any time.
- Sensitive blocks (door codes, access instructions) hidden from guests until the time set by the Customer before arrival, with the unlock time decided on the server.
- Separate production and preview environments; secrets stored as environment variables on the hosting platforms.
- Daily backups managed by Supabase.
8. Personal data breach
WonderGuest notifies the Customer without undue delay, and at the latest 72 hours after becoming aware of a personal data breach affecting Guest Data, with the information available at that time: nature of the breach, categories and approximate number of guests and records concerned, likely consequences, measures taken or proposed and a contact point. Further information follows as it becomes available. WonderGuest does not notify guests or supervisory authorities on the Customer’s behalf unless the Customer asks in writing or the law requires it.
9. Deletion and return
During the term, the Customer manages Guest Data through the Service. When the Customer’s account is deleted, or on the Customer’s written request, WonderGuest deletes Guest Data within 30 days, except for data that must be kept to comply with a legal obligation (for example the accounting records of extras orders) and for copies held in backups, which expire within the backup retention period.
10. Data subject requests
The Customer answers requests from its guests (access, deletion, correction, portability, objection). WonderGuest assists the Customer with the features of the Service and, where a request cannot be handled with those features, on written request and without undue delay.
11. United States state privacy laws
Where the CCPA or another United States state privacy law applies to the Customer, WonderGuest acts as a service provider or processor and, for Guest Data:
- processes it only for the business purpose of providing the Service, as described in this DPA and the Terms of Use;
- does not sell it and does not share it for cross-context behavioral advertising;
- does not retain, use or disclose it outside the direct business relationship with the Customer or for any purpose other than providing the Service, except as permitted by law;
- does not combine it with personal data received from other customers or collected from its own interactions with the guest, except as permitted by law;
- notifies the Customer if it determines that it can no longer meet its obligations under those laws, and allows the Customer to take reasonable and appropriate steps to stop and remediate any unauthorized use of Guest Data;
- provides the level of privacy protection those laws require and cooperates with the Customer in responding to verifiable consumer requests.
WonderGuest certifies that it understands these restrictions and will comply with them.
12. Liability, precedence and governing law
The limitations of liability in the Terms of Use apply to this DPA. In case of conflict between this DPA and the Terms of Use on the processing of Guest Data, this DPA prevails. This DPA is governed by the law and jurisdiction clause of the Terms of Use. Nothing in it limits the rights that guests hold directly under Data Protection Laws.
13. Contact
Questions about this DPA, requests for a countersigned copy and objections to a sub-processor: support@wonderguest.app