Data Processing Agreement (Template)

Template version 2026-07-06. This is the standard Data Processing Agreement between the Milatos booking platform and its suppliers. An executed copy for your business is available on request: [email protected].

1. Parties and roles

This Agreement is made between the accommodation or car-rental supplier named in the Supplier Agreement (the Controller) and Vagelis Filippakis, operator of the Milatos booking platform, book.milatos.com, Greece (the Processor). It supplements the Supplier Agreement and applies for as long as the Processor processes personal data on the Controller’s behalf.

2. Subject matter and purpose

The Processor operates the online booking system through which guests book the Controller’s accommodation or vehicles. Processing is limited to what is necessary to provide the booking service: receiving reservations, facilitating payment to the Controller, sending booking confirmations and related transactional email, and maintaining booking records for the Controller’s dashboard and monthly fee statements.

3. Categories of data and data subjects

  • Data subjects: guests and customers who book with the Controller.
  • Data categories: name, email address, phone number, country, booking dates and details, payment status (payment card data is processed directly by Stripe or PayPal and never stored by the Processor).

4. Obligations of the Processor (Art. 28(3) GDPR)

  • Process personal data only on the Controller’s documented instructions, as embodied in the platform’s booking functionality.
  • Ensure persons authorised to process the data are bound by confidentiality.
  • Implement appropriate technical and organisational measures (TLS in transit, access-controlled servers in the EU, role-based admin access, off-docroot document storage, daily off-server backups).
  • Not engage another processor without the Controller being informed (see §5).
  • Assist the Controller in responding to data-subject requests (access, erasure, rectification, portability).
  • Notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s guest data.
  • At termination of the Supplier Agreement, delete or return the Controller’s guest data, unless EU or Greek law requires retention (e.g. tax records).
  • Make available information necessary to demonstrate compliance and allow audits reasonably requested by the Controller.

5. Sub-processors

The Controller authorises the following sub-processors: Stripe Payments Europe (card payments), PayPal (Europe) S.à r.l. (payments), the platform’s transactional email provider, and the platform’s EU hosting provider. The Processor will inform Controllers of intended changes to this list, giving the opportunity to object.

6. International transfers

Guest data is stored in the EU. Where a sub-processor transfers data outside the EEA (e.g. payment networks), the transfer is covered by an adequacy decision or Standard Contractual Clauses maintained by that sub-processor.

7. Liability and governing law

Liability follows the Supplier Agreement. This DPA is governed by Greek law; place of jurisdiction is Heraklion, Greece.

Note: this template is provided for transparency. It has not yet been individually reviewed by counsel for every jurisdiction; suppliers are welcome to have it reviewed by their own advisers before signing.