Data Processing Agreement (DPA)
Version of 2026-08-05
This data processing agreement ("DPA") is entered into between the Customer (as defined in the terms of service, of which it constitutes Annex 1 and forms an integral part) and Saubeo SRL (Rue Rafhay 198, 4630 Soumagne, CBE 0704.742.612). In accordance with Article 28 GDPR, it governs the processing of personal data that Saubeo carries out on behalf of the Customer in connection with the Hoteo service.
1. Roles
For personal data contained in the Customer Data — in particular the data of the Customer's end clients (private individuals or business contacts: identity, addresses, contact details, service-call data, billing data) — the Customer is the data controller and Saubeo is the data processor.
For data relating to the Customer's own Account (users, subscription billing, support), Saubeo is the data controller: this processing is described in the privacy policy and does not fall within the scope of this DPA.
2. Subject matter, duration, nature and purpose of the processing
- Subject matter: hosting and processing of the Customer Data necessary for the operation of the Hoteo service.
- Duration: the term of the contract, plus the data retrieval period (60 days).
- Nature: collection, recording, structuring, storage, consultation, use, transmission (Peppol, e-mail/SMS), erasure.
- Purpose: providing the features of the Service (management of clients/sites/boilers, calendar, quotes/invoices, sending, reminders, bank reconciliation, AI assistant).
- Data subjects: end clients and contacts of the Customer, users of the Account.
- Categories of data: identity, contact details, service addresses, contractual and billing data, technical equipment data, communications. The Service is not intended for the processing of special categories of data (Art. 9 GDPR); the Customer undertakes not to enter any.
3. Customer instructions
Saubeo processes the Customer Data only on documented instructions from the Customer — the configuration and use of the Service's features constituting such instructions — unless required to do so by a legal obligation, in which case Saubeo informs the Customer before processing (unless prohibited by law). Saubeo informs the Customer if it considers an instruction to infringe the GDPR.
4. Confidentiality
Saubeo ensures that the persons authorised to process the Customer Data are bound by an appropriate obligation of confidentiality (contractual or statutory) and access it only to the extent necessary (least-privilege principle; support access is subject to the Customer's explicit authorisation in the application and is logged).
5. Security
Saubeo implements appropriate technical and organisational measures (Art. 32 GDPR), including: encryption of communications (TLS), strict segregation of data per organisation (multi-tenant isolation), role-based access control, logging of write operations, regular backups, hosting in the European Union, security updates. The main measures are summarised in the privacy policy.
6. Sub-processors
The Customer grants Saubeo a general authorisation to engage sub-processors for the performance of the Service. The up-to-date list is published at /legal/sous-traitants. Saubeo informs the Customer of any addition or replacement at least 14 days before it takes effect (e-mail and/or in-app message); the Customer may object in writing on reasonable grounds — failing agreement, it may terminate the contract free of charge before the change takes effect.
By way of exception, where a replacement is made urgent by reasons of security or continuity of the Service (in particular the failure or compromise of a sub-processor), Saubeo may proceed without prior notice; the Customer is then informed without undue delay and retains the objection and termination rights set out above.
Saubeo imposes on its sub-processors obligations equivalent to this DPA and remains liable for their performance.
7. Transfers outside the European Union
The Customer Data is hosted in the European Union. Where a sub-processor involves a transfer outside the EU (see the published list), the transfer is governed by an adequacy decision (in particular the EU-U.S. Data Privacy Framework) or by standard contractual clauses of the European Commission.
8. Assistance to the Customer
Taking into account the nature of the processing, Saubeo assists the Customer, by appropriate measures:
- in responding to requests to exercise the rights of data subjects (the export, rectification and deletion features of the application being the primary means);
- with its obligations regarding security, breach notification and, where applicable, data protection impact assessments (Art. 32 to 36 GDPR).
In the event of a personal data breach affecting the Customer Data, Saubeo notifies the Customer without undue delay after becoming aware of it, with the information necessary for the Customer's own notification obligations.
9. Fate of the data at the end of the contract
Closure of the Account means its definitive closure, whatever the cause. Three situations must be distinguished:
- Termination of the paid subscription: the Account switches to the free plan; the Customer Data is retained and this DPA continues to apply — there is no closure.
- Deletion of the Account at the Customer's initiative: the application requires a prior export of the Customer Data; deletion is then immediate and irreversible.
- Closure at Saubeo's initiative (in particular termination for breach or discontinuation of the Service): the Customer has 60 days from the notification to export the Customer Data.
Following the deletion or the end of the export period, Saubeo deletes or anonymises all Customer Data; residual copies in backups are purged within the period stated in the privacy policy (thirty days at most). Retaining the Customer's accounting documents (invoices, quotes, etc.) beyond closure is the sole responsibility of the Customer, who must export them beforehand. Saubeo's own accounting documents (subscription billing) do not fall within the scope of this DPA (Section 1) and follow the retention periods stated in the privacy policy.
10. Audits
Saubeo makes available to the Customer the information necessary to demonstrate compliance with this DPA. The Customer may, at most once a year and subject to reasonable prior notice of 30 days, conduct (or have conducted by an independent auditor who is not a competitor of Saubeo and is bound by confidentiality) an audit limited to the processing covered by this DPA, during business hours, without disrupting the Service, and at its own expense.
11. Miscellaneous
Liability under this DPA is governed by Section 15 of the terms of service. In the event of a conflict between this DPA and the terms of service, the DPA prevails with respect to data protection matters. The governing law and jurisdiction are those of the terms of service.