Production Gateway Active • Mews Certified Partner Node Layer
Back to the security pack
Draft for legal review
Download PDF

Data Processing Agreement

Schedule to the 60-Day Read-Only Shadow Pilot — SwiftInvoicePro Apex Flow Technology Ltd · natromrich@googlemail.com · swiftinvoicepro.com

DRAFT for legal review. Not legal advice. Names, dates and any Controller-specific requirements are completed before signature. Version 1.1 · 8 September 2026.

1. Parties and status

ItemDetail
Controller[Hotel group legal entity, registered address, company number]
ProcessorApex Flow Technology Ltd (England & Wales), natromrich@googlemail.com
AgreementSchedule to the 60-day read-only shadow pilot scope dated [date]
Term60 calendar days from first data access, unless ended earlier under clause 9
Governing lawEngland & Wales, subject to the Controller's requirement

The Controller determines the purposes and means of processing. The Processor processes personal data only on the Controller's documented instructions, of which this Schedule and the pilot scope are the complete set for the pilot term.

2. Subject matter, nature and purpose

Automated consolidation of corporate billing data read from the Controller's property management system, to produce one reconciled invoice per corporate account per period in shadow mode. The Processor's output is compared against the Controller's existing process; the Controller's process remains authoritative throughout.

  • Read-only. No writes back to the PMS, no schema changes, no property-side agent.
  • Single property or single franchise cluster. Not the portfolio.
  • No automated decision-making with legal or similarly significant effect.
  • No use of the data for training models, benchmarking, or any Processor purpose.

3. Categories of data subject and personal data

CategoryData
Corporate guestsName, reservation reference, folio number, stay dates, room number
Corporate account contactsEmployer / corporate account name, billing contact name, business email
Hotel staff (pilot users)Name, business email, role, audit log of actions taken in the pilot tenant
Transaction dataFolio transaction lines, rates, taxes, currency, payment method type (no PAN)

Excluded by design: no special category data, no criminal offence data, no cardholder data (no PAN, CVV or track data), no loyalty passwords or credentials, no free-text guest preference notes. If the Controller's extract would include any of these, it is filtered at source before transmission.

4. Security measures

ControlImplementation
Tenant isolationRow-level security on every table; each pilot is a single isolated tenant
EncryptionTLS 1.2+ in transit; AES-256 at rest
AuthenticationSigned webhooks (HMAC) for ingestion; scoped tokens for API reads; MFA on admin access
Access controlLeast privilege; named individuals only; access list supplied on request
IdempotencyReplay-safe keys; duplicate submissions rejected and logged
LoggingAppend-only audit log of access and processing events, retained for the pilot term
BackupsEncrypted, tenant-scoped, deleted with the tenant
TestingLoad and failure-injection testing evidenced in the security pack

5. Sub-processors

The Controller gives general authorisation for the sub-processors listed below. The Processor gives at least 30 days' written notice of any addition or replacement, and the Controller may object on reasonable data protection grounds, in which case the pilot may be ended under clause 9 without penalty.

Sub-processorPurposeLocation
Managed Postgres platform (Lovable Cloud)Pilot tenant database and storageEU / region selected at provisioning
CloudflareApplication hosting, TLS termination, DDoS protectionEU edge
ResendTransactional email (pilot notifications and reports)EU / US

6. International transfers

Pilot data is provisioned in an EU region by default. Where a sub-processor processes data outside the UK/EEA, transfers are made under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, with a transfer risk assessment supplied on request. The Controller may require EU-only processing, in which case any sub-processor that cannot meet it is not used for the pilot.

7. Assistance to the Controller

  • Data subject requests: the Processor forwards any request received directly to the Controller within 2 working days and assists with access, rectification, erasure and portability within 5 working days.
  • Personal data breach: the Processor notifies the Controller without undue delay and in any event within 24 hours of becoming aware, with the facts known, likely consequences and remediation.
  • DPIA and prior consultation: the Processor supplies architecture, data flow and security documentation on request.
  • Records: the Processor maintains Article 30(2) records for the pilot and provides them on request.

8. Audit

The Processor makes available the security architecture pack, RLS policy appendix, penetration and load test evidence, and the pilot audit log. The Controller may carry out one remote audit or security questionnaire during the pilot term on 10 working days' notice, at no cost. On-site audit is available on reasonable notice where required by the Controller's policy.

9. Duration, return and deletion

  • Either party may end the pilot on 5 working days' written notice, for any reason, at no cost.
  • On expiry or termination, the Processor deletes all Controller personal data — including backups — within 5 working days and confirms deletion in writing.
  • Where deletion is not immediately possible for a backup cycle, the data remains encrypted, isolated and unprocessed until the cycle expires, and the Controller is told the exact date.
  • No data is retained after the pilot for any Processor purpose. There is no automatic conversion to a paid service and no auto-renew.

10. Liability and cost

The pilot is provided at no cost. Each party remains liable under UK GDPR for its own compliance. Nothing in this Schedule limits liability that cannot be limited at law. Commercial liability terms are agreed separately if and when the pilot converts to a paid service.

11. Signature

ControllerProcessor
NameRichard Romero
PositionDirector, Apex Flow Technology Ltd
Signature
Date

Apex Flow Technology Ltd is a private limited company registered in England & Wales. Company No. 17347345. Registered office: 29 Railway Road, Rhoose, Barry, Wales, CF62 3FE.