Hapi Terms of Use
For hotels and hotel companies using Hapi through a Technology Provider

These Terms of Use (“Terms”) apply between Data Travel, LLC d/b/a Hapi (“Hapi”) and any hotel, hotel company or management company (“Hotel”) whose technology provider (“Provider”) uses Hapi’s services to connect to the Hotel’s systems. The Hotel accepts these Terms through its agreement with the Provider, or by allowing Hapi to connect to its systems.
1. How this works
1.1 Hapi provides data connectivity services (the “Services”) to the Provider under a separate agreement between Hapi and the Provider. The Provider pays Hapi for the Services. The Hotel owes no fees to Hapi.
1.2 The Hotel’s commercial relationship, service levels and support are with the Provider. These Terms cover only Hapi’s access to and handling of the Hotel’s data.
2. Authorization to access and share Hotel Data
2.1 The Hotel authorizes Hapi to connect to its property management system (“PMS”) and any other system the Hotel or the Provider designates, and to access, extract, process and transmit data from those systems (“Hotel Data”) to the Provider, for the purpose of providing the Provider’s services to the Hotel.
2.2 The Hotel authorizes its PMS provider and other system vendors to give Hapi the access needed for this purpose, and will confirm this authorization to those vendors on request.
2.3 The Hotel (or the Provider, if agreed between them) is responsible for obtaining, at its own cost, any licenses, interfaces or fees required from its PMS provider or other vendors (for example Oracle OHIP, OXI or OWS).
2.4 The Hotel may withdraw this authorization at any time by notifying the Provider. Hapi will then stop accessing the Hotel’s systems.
3. Roles under privacy laws
3.1 For the purposes of the GDPR, UK GDPR, Swiss FADP, CCPA/CPRA and other applicable privacy laws (“Privacy Laws”):
(a) the Hotel is the controller of the personal data in the Hotel Data and the data exporter of that data from its systems to the Provider’s environment;
(b) the Provider is the Hotel’s processor; and
(c) Hapi is a sub-processor engaged by the Provider, and a “service provider” under the CCPA/CPRA.
3.2 Hapi does not decide why or how personal data is used. Hapi processes it only to provide the Services and on documented instructions, which the Hotel gives through its agreement with the Provider and these Terms. Once Hotel Data is delivered to the Provider, the Provider is responsible for its processing. The details of the processing are set out in Appendix A.
4. Hotel responsibilities as controller
4.1 The Hotel is solely responsible for having a lawful basis for the processing and transfers described in these Terms. This includes giving all required privacy notices to, and obtaining all required consents from, guests and other data subjects.
4.2 The Hotel represents that it has the right to authorize Hapi to access the Hotel Data and to send it to the Provider.
4.3 The Hotel will indemnify Hapi against third-party claims, fines and penalties arising from the Hotel’s failure to meet Section 4.1, 4.2, 4.4 or 4.5.
4.4 Communications. The Hotel will not include personal data of guests or other individuals, or any Sensitive Data (as defined in Section 4.5), in any communication with Hapi outside the Services, including support tickets, emails, Slack or other messaging channels, chats and attachments, except limited data that Hapi specifically requests to resolve an issue, provided through a secure channel Hapi designates. If such data is submitted, Hapi may delete it and will otherwise handle it under these Terms. To the extent permitted by law, Hapi is not responsible for data submitted in breach of this Section.
4.5 No Sensitive Data. The Services are not designed for, and the Hotel will not transmit to Hapi in the normal course of business, (a) special categories of personal data under Privacy Laws, including health data; (b) government identification or passport numbers; or (c) passwords or other access credentials (together, “Sensitive Data”). The Hotel, with the Provider, will configure its systems and data mappings so that Sensitive Data is excluded from the Hotel Data made available to Hapi. If Sensitive Data is nevertheless transmitted, the Hotel is solely responsible for it and Hapi may delete it.
5. Hapi’s commitments
As a sub-processor, Hapi will:
(a) keep Hotel Data confidential and bind its personnel to confidentiality;
(b) maintain appropriate technical and organizational security measures, including those listed in Appendix A;
(c) not sell Hotel Data, not use it for its own purposes, and not use it to train publicly available AI models;
(d) use only the sub-processors listed in Appendix A (Amazon Web Services for hosting and Salesforce for support), give the Provider at least thirty (30) days’ notice before adding or replacing one, and bind each sub-processor to written terms at least as protective as these Terms;
(e) notify the Provider without undue delay after becoming aware of a security incident affecting Hotel Data (and the Hotel directly where required by law), and provide reasonable assistance;
(f) help the Provider and the Hotel respond to data subject requests and provide reasonable compliance information;
(g) notify the Provider of any legally binding government request for Hotel Data, unless prohibited, and disclose only the minimum required; and
(h) delete Hotel Data within sixty (60) days after Services for the Hotel end, unless the law requires otherwise, subject to standard backup cycles.
6. Data location and international transfers
6.1 Hosting region. Hapi hosts and processes Hotel Data in the region selected by the Provider: (a) the European Union, on Amazon Web Services in Germany; or (b) the United States, on Amazon Web Services. Providers located outside the United States are generally hosted in the EU region. The Provider is responsible for selecting a single region and informing the Hotel of it. Hapi will not change the region without the Provider’s instruction.
6.2 EU hosting. Where the Provider has selected EU hosting, Hapi stores and processes Hotel Data in the EU. Any limited remote access by Hapi personnel or sub-processors from outside the EEA (for example, for support or incident response) is covered by the safeguards in Section 6.4.
6.3 US hosting. Where the Provider has selected US hosting and Hotel Data includes personal data from the EEA, UK or Switzerland, the transfer of that data to Hapi in the United States is covered by the safeguards in Section 6.4.
6.4 Safeguards. For any transfer described in Sections 6.2 or 6.3, the Hotel (as data exporter) and Hapi (as data importer) agree to the EU Standard Contractual Clauses (Commission Decision 2021/914), [Module 2 / Module 3], which are incorporated by reference, together with the UK International Data Transfer Addendum and the Swiss adaptations as applicable. The Annexes are completed by Appendix A. In case of conflict, the Standard Contractual Clauses prevail over these Terms.
6.5 Delivery to the Provider. Hapi delivers Hotel Data to the Provider’s systems wherever the Provider has located them. Any transfer resulting from the Provider’s location is made on the Hotel’s instruction, and the Hotel and the Provider are responsible for putting an appropriate transfer mechanism in place for it.
7. Ownership
The Hotel owns its Hotel Data. Hapi owns the Services. Hapi may use aggregated and anonymized usage data that does not identify the Hotel or any individual to operate and improve the Services.
8. Disclaimers and liability
8.1 The Services are provided to the Provider. Hapi makes no warranty to the Hotel about the Services, including availability or data accuracy. The Hotel’s remedies for service performance lie with the Provider.
8.2 To the extent permitted by law, neither party is liable for indirect, consequential or punitive damages, or for lost profits. Hapi’s total liability to the Hotel is limited to the fees Hapi received from the Provider for Services to that Hotel in the twelve (12) months before the claim. These limits do not restrict any rights of data subjects under Privacy Laws.
9. Term
These Terms apply for as long as Hapi provides Services for the Hotel through a Provider. Sections 4, 5(h), 7 and 8 survive termination.
10. General
10.1 Hapi may update these Terms by posting a new version at this URL. Material changes affecting personal data take effect thirty (30) days after posting.
10.2 These Terms are governed by the laws of the State of Florida, without regard to conflict-of-law rules. Before starting any proceedings, the parties will try in good faith to resolve the dispute for thirty (30) days. The courts located in Miami-Dade County, Florida have jurisdiction over any dispute arising from these Terms. This Section does not apply to disputes under the Standard Contractual Clauses, which are governed and resolved as those Clauses provide, and does not limit any data subject’s right to bring a claim before a competent court or supervisory authority under Privacy Laws.
10.3 Privacy contact: legalcompliance@stayhapi.com.
Appendix A – Data Processing Details
This Appendix completes Annexes I to III of the Standard Contractual Clauses referred to in Section 6.4, and describes the processing under Section 3.
A.1 Parties and description of processing (SCC Annex I)
A.2 Technical and organizational measures (SCC Annex II)
Encryption in transit (TLS) and at rest; role-based access controls and least privilege; multi-factor authentication for administrative access; logging and monitoring; vulnerability management and patching; backups and disaster recovery; personnel confidentiality obligations; incident response procedures; deletion within sixty (60) days after the Services end.
A.3 Sub-processors (SCC Annex III)
Last updated: September 23, 2026.



