RatePulse Data Processing Agreement
Status: Last updated 2026-08-25 · v0.4.
This document (“DPA”) forms part of, and is incorporated into, the RatePulse Software as a Service Agreement (together, “the Agreement”) between the Customer and RATEPULSE LTD (company number 17408208), trading as RatePulse, whose registered office is at 176 Mytchett Road, Mytchett, Camberley, England GU16 6AE. Where this DPA and the rest of the Agreement disagree on a matter of data protection, this DPA prevails.
1. Parties and role
The Customer is the controller of the personal data described in Section 3. RatePulse is the processor, processing that data on the Customer’s behalf and on the Customer’s instructions. This split follows directly from what RatePulse does with the data: the Customer decides which guests it markets to and what its rates should be; RatePulse pulls the reservation data that makes those decisions possible and, where the Customer switches it on, sends the emails.
2. Subject matter, duration, nature and purpose of the processing
Subject matter. Guest reservation data that RatePulse’s connection to the Customer’s property management system (“PMS”) retrieves on a recurring schedule, for the Customer’s property or properties registered to the Service.
Nature. Automated retrieval, storage and analysis of that reservation data — computing occupancy, pace and demand signals from it — and, only where the Customer has enabled the relevant feature, sending marketing email on the Customer’s behalf to guests who have already stayed at the Customer’s property.
Purpose. To produce the occupancy analytics, pace and pickup detection, and rate recommendations the Customer sees in the Service, and to run the Customer’s own past-guest email campaigns (“direct recovery” / the Demand Engine) where the Customer has opted into that feature.
Duration. For the term of the Agreement. On termination, RatePulse’s handling of the data that was processed under this DPA is governed by Section 12 (Deletion or return).
3. Categories of personal data
RatePulse’s PMS connection retrieves, for each reservation: the guest’s name, email address and telephone number (where the PMS holds and exposes them), arrival and departure dates, the booking channel the reservation came through, the room type and rate booked, and the amount spent or outstanding on the reservation. This is the whole of what is retrieved — RatePulse does not request or retain any other guest personal data from the PMS, and does not receive payment card details, passport or ID numbers, or any special category data.
4. Categories of data subject
The Customer’s guests and prospective guests whose reservations are held in the PMS the Customer connects to the Service.
5. Documented instructions
RatePulse processes personal data only on the Customer’s documented instructions — this DPA, the rest of the Agreement, and the configuration choices the Customer makes within the Service (for example, enabling or disabling direct recovery) are the whole of those instructions, unless RatePulse is required to do otherwise by UK or EU law. If RatePulse is asked to do something with the data that appears to breach UK GDPR or another applicable data protection law, RatePulse will say so and will not proceed until the point is resolved.
6. Confidentiality
RatePulse personnel who can access personal data processed under this DPA are bound by confidentiality obligations, whether contractual or by virtue of their employment, that cover that data.
7. Security measures (Article 32)
RatePulse applies the following measures to personal data processed under this DPA:
- Encryption in transit. All traffic to and from the Service travels over TLS.
- Encryption at rest for PMS credentials. The credentials that grant RatePulse access to the Customer’s PMS are encrypted before storage (Fernet: AES-128-CBC with HMAC-SHA256 authentication) and are never held in plain text. The underlying cloud storage that holds reservation data is encrypted at rest by the cloud provider as a platform default.
- Access control. Administrative access to customer data is restricted to a named, limited set of RatePulse administrators.
- Audit logging. Administrative actions taken through RatePulse’s admin tools are written to an audit log.
- Tenant partitioning. Reservation data is partitioned by hotel; a connection made for one property does not expose another property’s data.
RatePulse has not obtained a third-party security certification (such as ISO 27001) or commissioned an independent penetration test as of the date of this DPA. If the Customer requires either as a condition of using the Service, RatePulse should be told before signing.
8. Sub-processors
RatePulse uses the following sub-processors to deliver the Service. Each processes personal data only for the purpose stated, under a contract with RatePulse.
| Sub-processor | Purpose | Location | Status |
|---|---|---|---|
| Hetzner Online GmbH | Hosting of the RatePulse application servers, background workers and web tier — every request and every scheduled job runs on this infrastructure | Germany (company); servers in Helsinki, Finland | Live |
| Google Cloud / Firebase | The Firestore database, authentication, and file storage | Firestore data is held at rest in the eur3 European multi-region (Netherlands and Belgium); Google administrative and support access may originate outside the EEA | Live |
| GoCardless | Subscription payment processing | UK | Live |
| Brevo | Transactional and marketing email delivery, including direct-recovery guest email | EU | Live |
| Mailgun | Transactional email delivery | EU/US | Live |
| Groq | AI model inference for the AI Revenue Assistant, proactive suggestions and generated narratives | US | Live |
| OpenAI | AI model inference, used as the fallback when the primary inference provider is unavailable, and speech-to-text transcription of voice messages spoken to the AI Revenue Assistant | US | Live |
| Sentry | Error monitoring and diagnostics | EU/US | Live |
| Zoho | Electronic signature of, and custody of, executed agreements between the Customer and RatePulse, including this DPA once signed. Processes the signatory’s name, email address and, in the completion certificate, IP address and signing timestamp | EU | Live |
No AI model inference provider listed above is permitted to train models on Customer Personal Data, and RatePulse does not itself train, fine-tune or evaluate any model on it.
RatePulse will give the Customer notice before appointing a new sub-processor, and the Customer may object on reasonable data-protection grounds within a reasonable period of that notice. RatePulse remains responsible to the Customer for each sub-processor’s performance of its data protection obligations to the same standard as if RatePulse were carrying out that processing itself.
9. International transfers
Where a sub-processor listed in Section 8 is located outside the UK, the transfer of personal data to it is made under the UK International Data Transfer Agreement (IDTA), or the EU Standard Contractual Clauses together with the UK Addendum, as applicable to that transfer.
10. Data subject rights
Taking into account the nature of the processing, RatePulse will assist the Customer, by appropriate technical and organisational measures, to respond to a data subject exercising their rights under UK GDPR (access, rectification, erasure, restriction, portability and objection). If a guest contacts RatePulse directly to exercise one of these rights, RatePulse will not action the request itself beyond confirming receipt, and will forward it to the Customer without undue delay, since the Customer as controller is best placed to verify the guest’s identity and decide the response.
11. Personal data breach
RatePulse will notify the Customer without undue delay, and in any event within 48 hours of becoming aware, of any personal data breach affecting data processed under this DPA. That notification will include what the Customer needs to meet its own notification duty under Article 33 UK GDPR: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures RatePulse has taken or proposes to take in response.
12. Deletion or return
On termination of the Agreement, RatePulse will delete the Customer’s personal data processed under this DPA within 30 days, unless UK or EU law requires RatePulse to keep it, and will confirm deletion in writing on request. The Customer may instead request return of its data before that window closes, using the export provided for in the Agreement.
13. Audit and information rights
RatePulse will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA, and will permit and contribute to audits — including inspections — carried out by the Customer or an auditor the Customer mandates, once per year on reasonable written notice, or more often if a supervisory authority requires it or following a personal data breach affecting the Customer’s data.
14. Liability
Liability arising under this DPA is subject to the limitation of liability set out in the Agreement. This DPA does not create an additional or separate cap.
15. Contact
Questions about this DPA, or a request to exercise a right under Sections 10-13: privacy@ratepulse.io
Effective date
This DPA takes effect once executed alongside the Agreement it forms part of.
Version history
- 2026-08-25 — v0.4, completed the sub-processor schedule: added Hetzner Online GmbH, which hosts the application servers, and OpenAI, used for fallback inference and speech-to-text; corrected the Google Cloud entry, which credited that provider with application hosting it does not perform, and stated the Firestore data region; and recorded that no inference provider may train on Customer Personal Data.
- 2026-08-19 — v0.3, identified RATEPULSE LTD as the legal processor and aligned references with the Software as a Service Agreement.
- 2026-08-08 — v0.2, updated the sub-processor schedule and execution terms for the live electronic-signature flow.
- 2026-08-06 — v0.1, initial draft (pending legal review)
Draft pending legal review. This document was prepared with care but has not been reviewed by counsel. Before it is presented to a customer for signature, this document should be reviewed by a UK-qualified data protection lawyer. The draft label flips to “v1.0” on review.