Data Processing Addendum (DPA)
Between: Processor: Bizr Single-Member P.C., operating HERMES PMS, with registered office in Athens, Greece (“Bizr”). Controller: the entity named in the HERMES tenant signup (“Customer”).
Effective from: the date the Customer signs up for HERMES PMS through hermespms.com and clicks to accept these terms.
Version: 1.0 — 2026-05-29.
This DPA forms part of, and is incorporated into, the Master Services Agreement between Bizr and the Customer (the MSA; embodied in our Terms of Service). In case of conflict between this DPA and the MSA, this DPA prevails for all matters relating to processing of personal data. It reflects the requirements of GDPR Art. 28.
1. Subject matter, duration, nature and purpose
| Field | Value |
|---|---|
| Subject matter | Provision of HERMES PMS — a SaaS property management system, including reservation handling, channel-manager bridge, ledger / invoicing, mailbox + calendar hosting, and AI-assisted drafting. |
| Duration | For the term of the MSA, plus the post-termination retention window described in §9. |
| Nature | Storage, organisation, structuring, retrieval, transmission, deletion. |
| Purpose | Enabling the Customer to operate its hotel business — accepting reservations, billing guests, communicating with guests, complying with Greek tax law. |
2. Types of personal data and categories of data subjects
Categories of data subjects: the Customer’s hotel guests (current, past, prospective); the Customer’s staff users; counterparties on the Customer’s invoices.
Types of personal data:
| Data subject | Personal data |
|---|---|
| Guests | Name, contact email, phone, postal address, country, language, date of birth (optional), passport / ID number (when collected for the Δελτίο Άφιξης under Greek Police Order 8/1999), nationality, reservation details, payment-related metadata (transaction reference only — never card data), mailbox messages where the guest is sender or recipient |
| Staff users | Name, work email, hashed password, role, last-login timestamp, IP of last login |
| Invoice counterparties | Name / company name, VAT / AFM, address, line-item descriptions |
Article 9 (special categories) and Article 10 (criminal convictions) data are out of scope. The Customer must not knowingly input such data into HERMES.
3. Customer warranties
The Customer warrants that:
- it has all lawful bases required under GDPR Art. 6 (and Art. 9 where applicable) for the personal data it provides;
- it has provided the necessary information to data subjects under Art. 13 and 14;
- the personal data shared with Bizr is accurate, necessary, and not excessive for the stated purposes;
- it will not use HERMES outside the scope of the MSA.
4. Processor obligations
Bizr undertakes that:
- (a) it will process personal data only on the Customer’s documented instructions, the primary instruction being the use of HERMES;
- (b) authorised persons are bound by confidentiality;
- (c) it will implement the security measures described in §5;
- (d) it will engage sub-processors only under §6;
- (e) it will assist the Customer with data-subject requests (see §7);
- (f) it will assist with GDPR Art. 32–36 obligations;
- (g) at the Customer’s choice, Bizr will delete or return all personal data after termination (see §9);
- (h) it will make available information necessary to demonstrate compliance and contribute to audits (§10).
5. Security of processing
Bizr implements the controls described in our Information Security Policy. At minimum:
- production data hosted within the EEA (Hetzner, Falkenstein);
- TLS 1.3 in transit for all external endpoints (Let’s Encrypt via Traefik);
- AES-256 encryption at rest for the production database and Backblaze B2 backups;
- mailbox passwords and Elorus API tokens encrypted in the database at the application layer;
- card data never received or stored (PCI SAQ-A scope — tokenization client-side via Stripe / Viva);
- access to administrative interfaces restricted to a WireGuard tunnel + key-only SSH;
- role-based access control inside HERMES (tenant scoping via Sanctum tokens + global Eloquent scope);
- daily automated database snapshots + daily encrypted off-site backups, 35-day retention;
- continuous error monitoring (Sentry) with PII scrubbed at source;
- documented Incident Response Plan, tabletop-tested at least annually.
The list is reviewed at least annually and may be updated; the level of protection will not be reduced.
6. Sub-processors
The Customer provides general written authorisation for Bizr to engage the sub-processors listed in the live sub-processor register. Each sub-processor is bound by terms imposing data-protection obligations no less protective than this DPA.
Notice of new sub-processors. Bizr will notify the Customer at least 14 days before any new sub-processor begins processing, by email and by updating the register. The Customer may object in writing within 14 days, giving reasonable grounds. If the objection cannot be resolved, the Customer may terminate the affected service.
7. Data-subject requests
Bizr will, where technically feasible, assist the Customer in fulfilling its obligations under Chapter III of GDPR. Direct requests received by Bizr will be forwarded to the Customer without undue delay.
8. Personal data breach
Bizr will notify the Customer without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting the Customer’s data. The notification will, to the extent then known, describe: nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, measures taken or proposed.
9. Return and deletion
On termination of the MSA, the Customer may within 30 days request export of personal data via the HERMES export API (JSON + SQL dump). After the 30-day grace period, Bizr will delete all production copies within 30 days, except that:
- backups may persist up to 35 days under the standard rolling-backup schedule;
- records legally required to be retained (e.g. invoices subject to Greek tax law) will be retained for the legally required period and not used for any other purpose.
10. Audits
Bizr will make available, on request: this DPA + sub-processor register, the Information Security Policy, the Incident Response Plan, and pen-test summaries / SOC reports of sub-processors where Bizr is permitted to share them.
The Customer (or an independent auditor mandated by the Customer, bound by confidentiality and not a Bizr competitor) may once per year, on at least 30 days’ written notice, audit Bizr’s compliance with this DPA. Audits will be conducted during normal business hours and not unreasonably interfere with Bizr’s operations.
11. International transfers
Data is processed within the EEA wherever the architecture permits. Where transfers outside the EEA occur (Cloudflare, US-side Stripe payment metadata, Anthropic for opted-in AI drafting, Sentry, Channex UK), they are performed under the European Commission’s Standard Contractual Clauses (Module 2 — Controller-to-Processor) and the supplementary measures described in the sub-processor register.
12. Governing law
This DPA is governed by the laws of Greece. Disputes are subject to the exclusive jurisdiction of the courts of Athens.
13. Order of precedence
Order: (1) SCCs where they apply, (2) this DPA, (3) the MSA / Terms of Service.
14. Acceptance
By signing up for HERMES PMS, completing the signup form on hermespms.com, and continuing to use the service, the Customer is deemed to have signed this DPA in the name of the entity identified on the signup form. The acceptance event is recorded with the timestamp, IP address, and user agent of the submitting browser.
The Customer may at any time request a counter-signed PDF copy by emailing [email protected].