Data Processing Agreement
Terms under which Regi processes traveler personal data on behalf of lodging customers, in accordance with Article 28 GDPR.
Last updated: May 7, 2026
In case of conflict between language versions, the Spanish version of this Agreement prevails.
This Data Processing Agreement (the "DPA") forms part of the Terms and Conditions between Ignacio Lopezosa Serrano (trading as "Regi", "we", or the "Processor") and the lodging customer (the "Controller", "Customer", or "you") that subscribes to the Regi service. It governs the processing of personal data carried out by Regi on the Controller's behalf.
The DPA is automatically entered into when the Customer accepts the Terms and Conditions and the Privacy Policy and uses the Regi service for activities that involve personal data processing on the Customer's instructions, in particular the Spanish traveler registration obligation under Royal Decree 933/2021.
1. Parties and roles
The lodging customer acts as Controller for the personal data of travelers staying at its accommodations and for the data it submits to the Regi service. Regi acts as Processor on behalf of the Controller for the processing described in this DPA.
Each party is independently responsible for compliance with applicable data protection law in respect of its own role.
2. Subject matter, nature and duration
Subject matter: processing of traveler and lodging-account personal data necessary to deliver the Regi service, including collection of traveler check-in data, transmission of mandatory traveler reports to the Spanish Ministry of the Interior via SES.Hospedajes, generation of internal records, and customer support.
Duration: this DPA is in force for as long as the Customer holds an active Regi subscription, plus any post-termination period required to delete or return personal data as described in Section 12.
3. Categories of data subjects and data
Data subjects: travelers checking in to the Customer's accommodations; the Customer's authorized users (lodging managers, owners, employees who access the platform).
Categories of personal data: identification data (full name, surnames, ID/passport/residence-permit number, nationality, date of birth, sex, signature where required), contact data (address, phone, email), travel data (check-in/out dates, room or property reference, payment method as required by RD 933/2021, group composition), and account-administration data for the Customer's authorized users (name, email, role).
Special categories: Regi does not request special-category personal data. The Customer must not submit such data through the service unless and until specific written instructions from the Customer authorize it.
4. Controller's documented instructions
Regi processes personal data only on the documented instructions of the Controller. The Terms and Conditions, the Privacy Policy, this DPA, the configuration choices made through the Regi platform, and the Customer's use of platform features constitute the Controller's documented instructions.
If Regi is required by EU or Spanish law to process personal data outside those instructions, Regi will inform the Controller of that legal requirement before processing, unless the law prohibits doing so on important grounds of public interest.
Regi will inform the Controller without undue delay if, in its opinion, an instruction infringes applicable data protection law.
5. Confidentiality
Regi ensures that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is granted on a strict need-to-know basis.
6. Security of processing
Regi implements appropriate technical and organizational measures pursuant to Article 32 GDPR. These include, as appropriate to the risk: encryption of personal data in transit (TLS) and at rest, access controls based on role and least privilege, multi-factor authentication for administrative access, infrastructure isolation, secure software development practices, regular logging and monitoring, vulnerability management, periodic backups, and staff awareness procedures.
The list of measures may evolve over time to keep pace with the state of the art and the risk to data subjects.
7. Subprocessors
The Controller grants Regi general written authorization to engage subprocessors for the processing described in this DPA. The current list of subprocessors is published at /subprocessors and forms part of this DPA.
Regi will inform the Controller of any intended addition or replacement of a subprocessor before that change takes effect, by updating the public list and, where applicable, by direct communication. The Controller may object to such changes on reasonable, documented data-protection grounds within 30 days of notification. If the parties cannot reach a solution, the Controller may terminate the affected service.
Regi imposes on each subprocessor data-protection obligations consistent with this DPA by means of a written contract, and remains fully liable to the Controller for the performance of the subprocessor's obligations.
8. International transfers
Authoritative storage of traveler personal data takes place within the European Union (AWS regions eu-west-3 Paris and eu-south-2 Spain). Where a subprocessor located outside the EEA is engaged, Regi relies on a valid transfer mechanism under Chapter V GDPR (typically the European Commission's Standard Contractual Clauses, supplemented where necessary by additional safeguards).
The location of each subprocessor is published on the Subprocessors page.
9. Assistance with data-subject rights
Taking into account the nature of the processing, Regi assists the Controller by appropriate technical and organizational measures, insofar as possible, in fulfilling the Controller's obligation to respond to requests from data subjects exercising their rights under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection, automated decision-making).
Where a request is addressed to Regi directly, Regi will redirect the data subject to the Controller, unless and to the extent the law requires Regi to respond.
10. Personal data breaches
Regi notifies the Controller without undue delay after becoming aware of a personal data breach affecting Controller's data, providing the information required to enable the Controller to comply with its own obligations under Articles 33 and 34 GDPR (description of the breach, categories and approximate number of data subjects and records affected, likely consequences, measures taken or proposed).
Notifications are sent to the Customer's administrative contact on file.
11. Audits and information
Regi makes available to the Controller all information reasonably necessary to demonstrate compliance with this DPA and the obligations laid down in Article 28 GDPR.
On the Controller's reasonable written request, and no more than once per twelve-month period (except where required earlier by a supervisory authority or by a documented breach), Regi will respond to a written audit questionnaire and, where strictly necessary, allow for and contribute to audits conducted by the Controller or an auditor mandated by the Controller, subject to advance notice, confidentiality undertakings, and minimization of disruption to the service.
12. Return or deletion at end of service
On termination of the service, Regi will, at the Controller's choice, delete or return all personal data processed on behalf of the Controller, and delete existing copies, unless EU or Spanish law requires storage of the personal data. In particular, traveler records that must be retained pursuant to Royal Decree 933/2021 will be retained for the period mandated by that regulation, even after termination.
The Controller can request export of its data through the platform during the subscription term.
13. Liability
Each party's liability under this DPA is governed by the limitation of liability set out in the Terms and Conditions, except for liability that cannot be limited by law (in particular, claims by data subjects under Article 82 GDPR or sanctions imposed by a supervisory authority).
14. Governing law
This DPA is governed by Spanish law and applicable EU data-protection law. Disputes are subject to the jurisdiction set out in the Terms and Conditions.
15. Contact
Privacy-related communications under this DPA, including data-subject rights requests, breach notifications, and subprocessor objections, must be sent to privacy@regi.es.