Legal

Data Processing Agreement

Last updated:

This data processing agreement (the “DPA”) is intended to govern personal-data processing carried out in connection with the ACL Voice service, in accordance with Article 28 of the GDPR where that regulation applies. It is a professional model intended to be reviewed, completed and, where applicable, signed in the context of the B2B contract. The exact role of each party (controller or processor) may vary according to the processing activity; this document does not lock in a single role for all processing.

Parties

This DPA is entered into between:

  • The professional customer, generally the hotel entity or its group, identified in the commercial contract (the “Customer”).
  • ACL GESTION, whose registered office is at 22 Avenue de Châlons, 93150 Le Blanc-Mesnil, France, registered under number 845 388 222 (“ACL Voice”).

Where the Customer designates properties, users or affiliates that benefit from the service, it warrants that they will comply with this DPA, to the extent applicable.

Definitions

The terms “personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach” and “supervisory authority” have the meaning given to them by the GDPR.

The “Service” means the AI-powered voice receptionist SaaS platform and the associated features provided by ACL Voice. “Instructions” means the controller’s documented instructions, including the contract, account settings and this DPA.

Controller and processor roles

The parties acknowledge that the applicable role depends on the purpose and means of each processing activity:

  • For caller data, hotel-guest data, reservations and hotel-operations content processed in order to provide the Service according to the Customer’s settings, the Customer generally acts as controller and ACL Voice as processor.
  • For account, billing, platform-security, B2B prospecting and improvement data determined by ACL Voice, ACL Voice may act as controller.
  • In particular cases, the parties could act as joint controllers; such a qualification will be retained only if it clearly results from the contract or an amendment.

This DPA must not be read as a definitive and universal legal qualification. Signed contractual annexes, where they exist, prevail to determine the role applicable to a given processing activity.

Subject matter, duration, nature and purpose

Subject matter: the processing of personal data necessary to provide the Service, including answering calls, speech recognition and synthesis, generating responses, assisting with reservations via a connected PMS, transferring to staff, presenting results in the dashboard, support and security.

Duration: that of the service contract, plus the retention, return or deletion periods provided below.

Nature: collection, recording, organisation, storage, retrieval, consultation, use, disclosure, restriction, erasure. The processing includes AI-assisted processing, which may produce transcripts, summaries and automated actions, without any warranty of accuracy.

Purpose: to provide the Service in accordance with the contract and the Instructions, and to ensure ACL Voice’s security, support and legal obligations.

Categories of data and data subjects

Categories of data subjects, depending on use of the Service:

  • The hotel’s guests, prospects and callers.
  • The Customer’s staff, receptionists and users.
  • The Customer’s professional contacts.

Categories of personal data, depending on the features enabled: identity and contact details; reservation data; telephone numbers; call content, call metadata, transcripts, recordings if enabled; AI-assisted conversation data; account data and technical / security logs; any other data spontaneously communicated during a call.

The Customer must not use the Service to intentionally process special categories of data (Article 9 GDPR) or data relating to convictions, except where necessary, with a legal basis and specific documented instructions.

Documented instructions

Where ACL Voice acts as processor, it processes data only on the Customer’s documented instructions, including as regards transfers, unless otherwise required by law. This DPA, the contract, account settings and written support requests constitute Instructions.

ACL Voice will inform the Customer if, in its opinion, an Instruction infringes the GDPR or other applicable provisions, to the extent it is in a position to ascertain this.

Confidentiality

ACL Voice ensures that persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

Security measures, access control and minimisation

ACL Voice implements appropriate technical and organisational measures, taking into account the state of the art, costs, the nature of the processing and the risks. Those measures may include:

  • Access control and privilege management.
  • Authentication, including enhanced measures where the service so provides.
  • Encryption of traffic where applicable.
  • Logging and incident monitoring.
  • Separation of environments and the principle of least privilege.
  • Minimisation: the Service is designed to process the data needed to handle the call and the functions enabled by the Customer.

The Customer is responsible for configuring the Service so as to limit the data collected, authorising only the relevant users, and issuing clear Instructions.

Sub-processors

The Customer authorises ACL Voice to engage sub-processors (technology providers, hosting, telephony, AI and technical-support providers) to provide the Service, provided that:

  • ACL Voice imposes on those sub-processors data-protection obligations substantially equivalent to those of this DPA.
  • ACL Voice remains responsible vis-à-vis the Customer for the performance of those obligations by the sub-processors, within the limits of the contract.

ACL Voice does not list named sub-processors here, in order to avoid inaccurate information. An up-to-date list may be provided to the Customer on request at contact.voice@acl-gestion.com or in accordance with [SUBPROCESSOR NOTICE MECHANISM].

Changes of sub-processors

ACL Voice will inform the Customer of additions or replacements of sub-processors involved in essential processing of the Service, in accordance with: [SUBPROCESSOR NOTICE MECHANISM], and subject to a notice period of: [SUBPROCESSOR NOTICE PERIOD].

The Customer may object on a reasonable data-protection ground within [SUBPROCESSOR OBJECTION PERIOD]. If the objection cannot be resolved, the parties will discuss in good faith a solution, including, where applicable, termination of the affected part of the Service in accordance with the commercial contract.

International transfers

Where ACL Voice or a sub-processor transfers data outside the EU/EEA, a recognised transfer mechanism is put in place (adequacy decision, standard contractual clauses, and additional measures where applicable).

The Customer authorises those transfers to the extent necessary to provide the Service. Operational details (countries, providers) are communicated in the contractual framework and not on this public page, in order to avoid any inaccurate list.

Assistance with data-subject rights

Where ACL Voice acts as processor, it assists the Customer, by appropriate technical and organisational measures, in fulfilling its obligation to respond to requests to exercise rights (access, rectification, erasure, restriction, objection, portability, withdrawal of consent), to the extent the Service so permits.

If a data subject contacts ACL Voice directly in respect of data processed on the Customer’s behalf, ACL Voice will inform the Customer and will not respond itself, except on instruction or where legally required.

Notification of personal data breaches

ACL Voice will notify the Customer, without undue delay, of any personal data breach of which it becomes aware and which concerns data processed on the Customer’s behalf. The internal target timeframe is: [BREACH NOTICE PERIOD], without that timeframe constituting a warranty that it will never be exceeded in the event of a complex incident.

The notification describes, to the extent available, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed.

The Customer remains responsible for notifications to authorities and data subjects where it is the controller, unless applicable law imposes a direct obligation on ACL Voice.

DPIA, records and compliance assistance

ACL Voice assists the Customer, taking into account the nature of the processing and the information available to it, with data protection impact assessments (DPIAs) and prior consultations, where the Customer is required to carry them out.

ACL Voice maintains the records of processing required when it acts as processor, and provides the Customer with the information reasonably necessary to demonstrate compliance with Article 28 obligations, subject to secrets, security and the rights of other customers.

Audits

The Customer may, no more than once per [AUDIT FREQUENCY] period except in the event of a confirmed incident, request audit information (reports, questionnaires, attestations) and, if that remains insufficient, an on-site or remote audit, subject to reasonable notice, during business hours, without disrupting the Service or compromising the security or confidentiality of other customers.

Audits may be carried out by the Customer or an independent auditor bound by confidentiality, excluding competitors of ACL Voice. Costs are: [AUDIT COST ALLOCATION].

Retention, deletion and return

Operational retention periods depend on configuration, the Instructions and legal obligations. They must be specified operationally: [RETENTION PERIODS].

At the end of the Service, ACL Voice will delete or return, at the Customer’s choice and using reasonably available means, the personal data processed as processor, and will then delete existing copies, except where a legal obligation of retention applies or a limited secure retention need (backups, evidence, security) for a period of [POST-TERMINATION RETENTION].

Liability

The parties’ liability under this DPA is subject to the limitations of the commercial contract, without prejudice to mandatory provisions of the GDPR and applicable law. Each party is liable for damage caused by processing where it has not complied with the obligations specifically incumbent on it under the GDPR.

Order of precedence

In the event of a conflict, the following order of precedence applies, unless expressly stated otherwise: (1) the signed commercial contract and its specific data-related annexes; (2) this DPA; (3) the Terms & Conditions of Sale; (4) the Terms of Use; (5) the Privacy Policy.

The public version of this DPA on the website does not replace a signed DPA. In the event of a difference, the signed DPA prevails.

Contact

Contact: contact.voice@acl-gestion.com. Address: 22 Avenue de Châlons, 93150 Le Blanc-Mesnil, France.