Effective: June 9, 2026
This Data Processing Agreement (“DPA”) forms part of the FieldStay Terms of Service between FieldStay, Inc.(“Processor” or “FieldStay”) and the organization using the FieldStay platform (“Controller”). It governs the processing of personal data by FieldStay on behalf of the Controller in connection with the FieldStay service.
The Controller is the FieldStay customer (the property management organization) that determines the purposes and means of Processing Personal Data entered into and managed through the Service — including data about crew members, vendors, property owners, guests, and bookings (“Controller Personal Data”).
FieldStay acts as a Processor of Controller Personal Data and processes that data only on behalf of and at the direction of the Controller, in accordance with this DPA and the Terms of Service.
FieldStay is an independent Controller of data about its own users (account holders, platform administrators) for the purposes of managing accounts and subscriptions. That processing is governed by the FieldStay Privacy Policy, not this DPA.
As required by GDPR Article 28(3), the subject matter and details of the Processing are:
FieldStay will process Controller Personal Data only on documented instructions from the Controller. The Controller's use of the Service (including configuration, integrations, and API calls) constitutes documented instructions. If FieldStay is required by applicable law to process Controller Personal Data in a manner not covered by those instructions, it will notify the Controller before processing (unless prohibited by law on grounds of public interest). If FieldStay reasonably believes an instruction infringes applicable data protection law, it will promptly notify the Controller.
FieldStay will ensure that personnel authorized to process Controller Personal Data are subject to appropriate confidentiality obligations — whether by employment contract, statutory duty, or equivalent binding obligation — and are informed of the confidential nature of the data.
FieldStay will implement and maintain appropriate technical and organizational security measures to protect Controller Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures currently include:
FieldStay will take steps to ensure that any natural person acting under its authority who has access to Controller Personal Data processes it only in accordance with this DPA, unless required to do so by applicable law.
The Controller provides general authorization for FieldStay to engage Sub-Processors. The current list of Sub-Processors is published in the Privacy Policy (Section 5).
Before engaging a new Sub-Processor or replacing an existing one, FieldStay will notify the Controller (by updating the Privacy Policy and, for material changes, by email to the Controller's account holder) at least 30 days in advance. The Controller may object in writing within that 30-day period on data protection grounds; if FieldStay cannot accommodate the objection, the Controller may terminate the affected portion of the Service.
FieldStay will impose data protection obligations on all Sub-Processors equivalent to those in this DPA, as required by GDPR Article 28(4). FieldStay remains liable to the Controller for the performance of Sub-Processors' obligations.
FieldStay will, to the extent technically possible and taking into account the nature of the Processing, assist the Controller in fulfilling its obligations to respond to Data Subject rights requests (access, rectification, erasure, restriction, portability, objection) under GDPR Chapter III. Given the nature of the Service, the Controller can directly fulfill most Data Subject rights requests using the Service's built-in tools (data export, account deletion). Where built-in tools are insufficient, FieldStay will provide reasonable assistance upon written request.
FieldStay will assist the Controller in ensuring compliance with the obligations under GDPR Articles 32–36, taking into account the nature of the Processing and the information available to FieldStay, including with respect to:
Upon termination or expiry of the Service subscription, FieldStay will, at the Controller's election (communicated by email within 30 days of termination):
If the Controller does not elect within 30 days of termination, FieldStay will delete Controller Personal Data per its standard retention schedule. FieldStay will certify deletion in writing upon request.
FieldStay will make available to the Controller all information necessary to demonstrate compliance with GDPR Article 28, and will allow for and contribute to audits and inspections conducted by the Controller or an auditor mandated by the Controller. FieldStay may satisfy this obligation by providing:
The Controller represents and warrants that:
FieldStay processes Controller Personal Data in the United States. To the extent that Controller Personal Data originates from the EEA, UK, or Switzerland, the transfer is governed by the applicable transfer mechanism described in the Privacy Policy (Section 6), which is incorporated by reference into this DPA.
If Standard Contractual Clauses (SCCs) are required to legitimize a transfer, the Controller and FieldStay agree that the EU Commission's 2021 SCCs (Module 2: Controller-to-Processor) are incorporated into this DPA by reference and apply to such transfers. The SCCs are available at ec.europa.eu. The Parties agree that Annex I (description of transfers) is fulfilled by Section 3 (Details of Processing) of this DPA, and Annex II (technical/organizational measures) is fulfilled by Section 4.3 above.
Each Party's liability under this DPA is subject to the limitations and exclusions set out in the FieldStay Terms of Service. To the extent permitted by applicable law, FieldStay's liability for breaches of this DPA is limited to direct damages and does not include indirect, consequential, or punitive damages. Nothing in this DPA limits liability that cannot be excluded or limited under applicable law (including GDPR Article 82).
This DPA is effective from the date the Controller accepts the Terms of Service (or the effective date above, whichever is later) and continues for as long as FieldStay processes Controller Personal Data under the Terms of Service. Termination of the Terms of Service automatically terminates this DPA, subject to Section 4.7 (data return/deletion).
In the event of a conflict between this DPA and the Terms of Service with respect to the processing of Controller Personal Data, the terms of this DPA prevail. In the event of a conflict between this DPA and the SCCs, the SCCs prevail.
To exercise rights under this DPA, request a signed copy, or raise a data protection concern, contact:
FieldStay, Inc. — Data Privacy
Email: privacy@fieldstay.app