Back to home

Data processing agreement (DPA)

Last updated: 30/09/2026

This binding electronic annex to the Terms governs processing on the host's behalf under Article 28 GDPR. The host accepting the Terms is the controller; MYLAE DIGITAL DI DAVIDE MERENDA, Piazzale Europa n. 2, int. 1 — 98057 Milazzo (ME), Italia; C.F. MRNDVD91D18F158T — P.IVA 03878780836; hello@pronto-host.com is the processor. For guest-data processing, this DPA takes precedence over conflicting Terms.

Subject, duration and categories

Data is used to identify guests and make the mandatory report to the public-security authority through Alloggiati Web (Article 109 of Italy's TULPS). The legal basis is the operator's legal obligation, Article 6(1)(c) GDPR. Consent is not requested for this report; acknowledging this notice is not consent. Without the required data, the operator cannot complete the legal requirements for accommodation. Contact them if you need another collection method.

We process first and last name, sex, date and place of birth, citizenship, stay dates, family or group composition and, when required for the guest category, document type, number and place of issue. Booking references may also be included. When you upload a document, its image or PDF and extracted fields are processed temporarily. Uploading a document for every family or group member is not necessary where the law does not require their document details.

Host accounts are for adults. Check-in may include child guests whose data is supplied by a family member or accompanying adult for applicable registration obligations; it is not used for marketing.

Processing lasts as necessary for service delivery and the specific retention periods below. At termination, at the controller's choice, the processor returns still-lawfully available data or deletes it and existing copies unless its own legal obligation requires retention. It does not restore deleted data to create an export. Receipts can be downloaded during the service; request return before account deletion. Provider technical copies must be unavailable for ordinary use and deleted under applicable contractual cycles.

Instructions and controller obligations

Documented instructions are the Terms, this DPA and the host's authorized service operations: temporary collection, reading and review, reporting to the authority, deletion of reported data and retention of the receipt only. Independent uses, advertising and model training by Pronto Host using guest documents are not authorized. The processor promptly informs the host of instructions it considers unlawful. Legally required processing is communicated beforehand unless the law prohibits this. The controller determines lawfulness, informs guests and issues instructions consistent with deletion obligations.

The service includes collection and review of check-in data and submission to Alloggiati Web when configured. The host remains responsible for identification, data accuracy, reporting deadlines and checking results and receipts; online upload does not replace checks required by law. The host must provide guests with a complete notice before collection, authorize only necessary personnel and retain no document copies after fulfilling the reporting obligation. The data processing agreement (DPA), published at /en/legal/dpa, forms an integral part of these Terms: accepting them appoints MYLAE DIGITAL under Article 28 GDPR on the DPA's instructions. Download receipts before deleting the account to meet the five-year retention requirement.

Confidentiality and security

The processor binds authorized personnel to confidentiality and limits access to operational need. Measures include authorization and accommodation-ownership checks, expiring access and upload links, a private document bucket, credential protection, minimized logs, automatic deletion and retries. It maintains risk-appropriate measures under Article 32 GDPR and checks access, availability and restoration capability without returning expired data to ordinary use.

Subprocessors and transfers

The operator and authorized personnel can access the data, which is reported to the public-security authority. Technical providers involved are Google Cloud Storage for temporary uploads in a private bucket and Google Vertex AI for configured reading, Convex for the database, backend and receipt archive, and Vercel for the application. Subprocessors and their activities are described in the data processing agreement attached to the Terms.

The host gives general authorization to the providers listed under Recipients for their specified activities. The processor undertakes to impose equivalent Article 28 obligations, remains responsible for their performance and emails the host before additions or replacements, allowing a reasoned objection before new processing starts. If unresolved, the parties stop the affected processing. Transfers outside the EEA require instructions and Chapter V safeguards; provider and safeguard information is available on request.

The EU reading endpoint does not mean that every operation by all providers takes place in the EU. Any transfer outside the EEA must comply with Chapter V GDPR, using an adequacy decision or other applicable safeguards. Ask the operator for information and a copy of the safeguards, or contact hello@pronto-host.com for assistance.

Assistance and breaches

Considering the processing and available information, the processor assists the controller with guest-rights requests, security, impact assessments and prior consultation (Articles 32–36 GDPR). It forwards requests received without responding for the controller unless instructed. Hosts can send requests to hello@pronto-host.com.

The processor informs the controller of any personal-data breach without undue delay after becoming aware, using account contact details, providing its nature, affected data and people where known, likely consequences and measures taken or proposed, with further updates as information becomes available. It assists containment and documentation. The controller assesses authority and guest notifications; the controller's 72-hour notification deadline is not a deadline for the processor to notify the controller.

Return, deletion and audits

Following Alloggiati Web's confirmation of acceptance, Pronto Host automatically starts deleting accepted guests' uploaded documents, OCR readings and transmitted personal data. For partial submissions, deletion covers explicitly accepted guests; rejected data or data with an uncertain result remains temporarily available to resolve the result, for at most 7 days after the attempt. We do not retain an archive of transmitted named guest records. The official receipt and technical metadata needed to identify it are retained for 5 years after submission, without adding document copies or named guest lists.

Drafts and unsubmitted check-ins expire two days after the arrival date, counted from 00:00 UTC, or 7 days after creation when no arrival date is set. Automatic jobs perform deletion and retry technical failures. The operator can delete data earlier when it is no longer needed. Account deletion also removes the receipt archive: the operator must download and retain receipts beforehand. These rules apply to data managed by the service; the authorities apply their own retention periods.

The processor provides information necessary to demonstrate compliance with the DPA and allows and contributes to audits and inspections by the controller or its appointed auditor, using proportionate arrangements that protect other customers. Send notices, additional instructions and audit requests to hello@pronto-host.com.