← Back to Privacy Policy

Data Processing Agreement

Effective: June 9, 2026

This Data Processing Agreement (“DPA”) forms part of the FieldStay Terms of Service between FieldStay, Inc.(“Processor” or “FieldStay”) and the organization using the FieldStay platform (“Controller”). It governs the processing of personal data by FieldStay on behalf of the Controller in connection with the FieldStay service.

1. Definitions

“GDPR”
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (“General Data Protection Regulation”) and, where applicable, the UK GDPR as retained in UK law under the European Union (Withdrawal) Act 2018.
“Personal Data,” “Processing,” “Controller,” “Processor,” “Data Subject,” “Supervisory Authority”
Have the meanings given in Article 4 of the GDPR.
“Sub-Processor”
Any third party engaged by FieldStay to process Personal Data on behalf of the Controller in connection with the Service.
“Service”
The FieldStay property operations platform and all associated features made available to the Controller under the Terms of Service.
“Security Incident”
Any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed by FieldStay.

2. Scope and Role of the Parties

The Controller is the FieldStay customer (the property management organization) that determines the purposes and means of Processing Personal Data entered into and managed through the Service — including data about crew members, vendors, property owners, guests, and bookings (“Controller Personal Data”).

FieldStay acts as a Processor of Controller Personal Data and processes that data only on behalf of and at the direction of the Controller, in accordance with this DPA and the Terms of Service.

FieldStay is an independent Controller of data about its own users (account holders, platform administrators) for the purposes of managing accounts and subscriptions. That processing is governed by the FieldStay Privacy Policy, not this DPA.

3. Details of Processing

As required by GDPR Article 28(3), the subject matter and details of the Processing are:

Subject Matter
The provision of the FieldStay property operations platform to the Controller.
Duration
For the term of the Controller's subscription to the Service, plus any retention periods required by applicable law following termination.
Nature and Purpose of Processing
Storage, retrieval, transmission, and display of Controller Personal Data to operate features including: crew scheduling and dispatch, vendor work order management, inventory tracking, booking management, owner reporting, and communications.
Type of Personal Data
Names, email addresses, phone numbers, and role information of crew members, vendors, and property owners entered by the Controller. Guest names, email addresses, and arrival/departure dates from connected booking platforms. Property addresses and operational notes.
Categories of Data Subjects
Crew members, vendors, property owners, and guests whose data the Controller enters or imports into the Service.

4. Processor Obligations (GDPR Article 28(3))

4.1 Processing on Instructions Only

FieldStay will process Controller Personal Data only on documented instructions from the Controller. The Controller's use of the Service (including configuration, integrations, and API calls) constitutes documented instructions. If FieldStay is required by applicable law to process Controller Personal Data in a manner not covered by those instructions, it will notify the Controller before processing (unless prohibited by law on grounds of public interest). If FieldStay reasonably believes an instruction infringes applicable data protection law, it will promptly notify the Controller.

4.2 Confidentiality

FieldStay will ensure that personnel authorized to process Controller Personal Data are subject to appropriate confidentiality obligations — whether by employment contract, statutory duty, or equivalent binding obligation — and are informed of the confidential nature of the data.

4.3 Security Measures (GDPR Article 32)

FieldStay will implement and maintain appropriate technical and organizational security measures to protect Controller Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures currently include:

  • Encryption of data in transit using TLS 1.2 or higher.
  • Encryption of sensitive credentials and OAuth tokens at rest (AES-256 via Supabase Vault).
  • Row-Level Security enforced at the database layer to prevent cross-tenant data access.
  • Role-based access controls limiting personnel access to data needed to perform their role.
  • Append-only audit logs for all security-relevant operations.
  • Regular review of access permissions and security configurations.

FieldStay will take steps to ensure that any natural person acting under its authority who has access to Controller Personal Data processes it only in accordance with this DPA, unless required to do so by applicable law.

4.4 Sub-Processors

The Controller provides general authorization for FieldStay to engage Sub-Processors. The current list of Sub-Processors is published in the Privacy Policy (Section 5).

Before engaging a new Sub-Processor or replacing an existing one, FieldStay will notify the Controller (by updating the Privacy Policy and, for material changes, by email to the Controller's account holder) at least 30 days in advance. The Controller may object in writing within that 30-day period on data protection grounds; if FieldStay cannot accommodate the objection, the Controller may terminate the affected portion of the Service.

FieldStay will impose data protection obligations on all Sub-Processors equivalent to those in this DPA, as required by GDPR Article 28(4). FieldStay remains liable to the Controller for the performance of Sub-Processors' obligations.

4.5 Assistance with Data Subject Rights

FieldStay will, to the extent technically possible and taking into account the nature of the Processing, assist the Controller in fulfilling its obligations to respond to Data Subject rights requests (access, rectification, erasure, restriction, portability, objection) under GDPR Chapter III. Given the nature of the Service, the Controller can directly fulfill most Data Subject rights requests using the Service's built-in tools (data export, account deletion). Where built-in tools are insufficient, FieldStay will provide reasonable assistance upon written request.

4.6 Assistance with Compliance Obligations

FieldStay will assist the Controller in ensuring compliance with the obligations under GDPR Articles 32–36, taking into account the nature of the Processing and the information available to FieldStay, including with respect to:

  • Security (Article 32):Providing information about FieldStay's technical and organizational security measures on request.
  • Breach Notification (Articles 33–34): Notifying the Controller of any Security Incident without undue delay and, where feasible, within 72 hours of FieldStay becoming aware of it, to enable the Controller to meet its own notification obligations to the Supervisory Authority and affected Data Subjects.
  • Data Protection Impact Assessment (Article 35): Providing reasonable information and cooperation to assist the Controller in conducting any required DPIA relating to Processing performed by FieldStay.
  • Prior Consultation (Article 36): Providing reasonable assistance where a DPIA indicates a high risk requiring consultation with a Supervisory Authority.

4.7 Return or Deletion of Data

Upon termination or expiry of the Service subscription, FieldStay will, at the Controller's election (communicated by email within 30 days of termination):

  • Return: Provide the Controller with an export of Controller Personal Data in a structured, machine-readable format (JSON).
  • Delete:Securely delete Controller Personal Data from FieldStay's production systems within 30 days of the termination date, except where retention is required by applicable law (e.g., financial records subject to a 7-year statutory retention period).

If the Controller does not elect within 30 days of termination, FieldStay will delete Controller Personal Data per its standard retention schedule. FieldStay will certify deletion in writing upon request.

4.8 Audit and Compliance Demonstration

FieldStay will make available to the Controller all information necessary to demonstrate compliance with GDPR Article 28, and will allow for and contribute to audits and inspections conducted by the Controller or an auditor mandated by the Controller. FieldStay may satisfy this obligation by providing:

  • Relevant certifications, security attestations (e.g., SOC 2 Type II reports), or penetration test summaries, subject to confidentiality obligations.
  • Written responses to Controller security questionnaires.
  • Where required, participation in on-site or remote audits on reasonable notice (at least 30 days), during normal business hours, and subject to a confidentiality agreement.

5. Controller Obligations

The Controller represents and warrants that:

  • It has a lawful basis to collect and transfer Controller Personal Data to FieldStay for processing under this DPA (e.g., it has obtained appropriate consent from crew members for operational processing, or relies on legitimate interest or employment contract).
  • It has provided all required privacy notices to Data Subjects whose data is entered into the Service, informing them that their data may be processed by FieldStay as a Processor.
  • It will comply with applicable data protection law in its own use of the Service, including the accuracy of the data it enters and the lawfulness of any instructions given to FieldStay.
  • It will not instruct FieldStay to process Personal Data in a way that would infringe applicable data protection law.

6. International Data Transfers

FieldStay processes Controller Personal Data in the United States. To the extent that Controller Personal Data originates from the EEA, UK, or Switzerland, the transfer is governed by the applicable transfer mechanism described in the Privacy Policy (Section 6), which is incorporated by reference into this DPA.

If Standard Contractual Clauses (SCCs) are required to legitimize a transfer, the Controller and FieldStay agree that the EU Commission's 2021 SCCs (Module 2: Controller-to-Processor) are incorporated into this DPA by reference and apply to such transfers. The SCCs are available at ec.europa.eu. The Parties agree that Annex I (description of transfers) is fulfilled by Section 3 (Details of Processing) of this DPA, and Annex II (technical/organizational measures) is fulfilled by Section 4.3 above.

7. Liability

Each Party's liability under this DPA is subject to the limitations and exclusions set out in the FieldStay Terms of Service. To the extent permitted by applicable law, FieldStay's liability for breaches of this DPA is limited to direct damages and does not include indirect, consequential, or punitive damages. Nothing in this DPA limits liability that cannot be excluded or limited under applicable law (including GDPR Article 82).

8. Term and Termination

This DPA is effective from the date the Controller accepts the Terms of Service (or the effective date above, whichever is later) and continues for as long as FieldStay processes Controller Personal Data under the Terms of Service. Termination of the Terms of Service automatically terminates this DPA, subject to Section 4.7 (data return/deletion).

9. Order of Precedence

In the event of a conflict between this DPA and the Terms of Service with respect to the processing of Controller Personal Data, the terms of this DPA prevail. In the event of a conflict between this DPA and the SCCs, the SCCs prevail.

10. Contact

To exercise rights under this DPA, request a signed copy, or raise a data protection concern, contact:

FieldStay, Inc. — Data Privacy

Email: privacy@fieldstay.app