Shop Modules Pricing Integrations Features Guides Blog FAQ About Contact Account Access →

Your Cart

Your cart is empty.

Data Processing Agreement

Last updated: 1 August 2026 | CockpitShop d.o.o. — Data Processor | Customer — Data Controller

This Data Processing Agreement ("DPA") is entered into between CockpitShop d.o.o. ("Processor") and the customer entity identified in the CockpitShop account registration ("Controller"), collectively "the Parties". This DPA supplements the Terms of Service and applies where the Controller uses CockpitShop modules to process personal data of hotel guests or other third parties ("Data Subjects"). This DPA becomes effective upon acceptance of the Terms of Service and remains in force for the duration of the subscription.

1. Definitions

"Personal Data" means any information relating to an identified or identifiable natural person, as defined in Article 4(1) of Regulation (EU) 2016/679 (GDPR).

"Processing" means any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, erasure or destruction.

"Controller" means the natural or legal person (hotel or hotel group) that determines the purposes and means of processing Personal Data of hotel guests through the use of CockpitShop modules.

"Processor" means CockpitShop d.o.o., which processes Personal Data on behalf of the Controller through the operation of CockpitShop modules.

"Sub-processor" means any third party engaged by the Processor to process Personal Data in connection with the Service.

"Supervisory Authority" means the Agencija za zaštitu ličnih podataka (AZLP), Rimski trg 46, 81000 Podgorica, Montenegro, registration 05-030/26-1847.

2. Subject Matter, Nature and Purpose of Processing

The Processor processes Personal Data on behalf of the Controller for the sole purpose of providing the CockpitShop module services subscribed to by the Controller. The nature of processing includes: retrieval of reservation and guest data from the Controller's Dirs21 account via the Dirs21 API; transformation and formatting of this data for the purposes of the specific module function (e.g. OTA distribution, accounting export, guest messaging); storage of operational data required for module functionality; and deletion of data upon module cancellation or account closure.

Personal Data categories processed may include (depending on modules subscribed): guest full name; guest email address and telephone number; reservation dates and room type; payment status and amount; OTA source and booking reference; and guest nationality where provided by Dirs21.

Data Subjects: hotel guests whose reservation data is stored in the Controller's Dirs21 account.

3. Controller's Obligations

The Controller warrants that it has a lawful basis under GDPR for processing hotel guest personal data through its Dirs21 account and for sharing that data with CockpitShop via the Dirs21 API. The Controller is responsible for: (a) ensuring all required notifications and consents from Data Subjects are in place for the types of processing performed by each module; (b) providing accurate Dirs21 API credentials and updating them promptly when changed; (c) notifying CockpitShop immediately of any confirmed or suspected data breach on the Controller's systems that may affect data shared with the Processor; (d) ensuring that any instructions given to the Processor regarding the processing of Personal Data comply with applicable data protection law.

4. Processor's Obligations

The Processor agrees to: (a) process Personal Data only on documented instructions from the Controller, including instructions given through module configuration settings in the CockpitShop account portal; (b) ensure that all personnel with access to Personal Data are bound by appropriate confidentiality obligations; (c) implement and maintain the technical and organisational security measures described in Article 32 GDPR and set out in Section 6 of this DPA; (d) not engage any Sub-processor without prior specific or general written authorisation from the Controller (general authorisation is deemed given by acceptance of these Terms, covering the sub-processors listed in Section 7); (e) assist the Controller in responding to requests from Data Subjects exercising their rights under GDPR Articles 15–22; (f) assist the Controller in meeting its obligations under Articles 32–36 GDPR (security, breach notification, DPIA, prior consultation); (g) delete or return all Personal Data to the Controller upon termination of the Service, at the Controller's choice, and delete existing copies unless data retention is required by applicable law; (h) provide all information necessary to demonstrate compliance with this DPA and to allow and contribute to audits and inspections by the Controller or an authorised auditor.

5. International Transfers

The Processor stores and processes all Personal Data within the European Economic Area. The Processor will not transfer Personal Data to any third country outside the EEA without the Controller's prior written consent and the implementation of appropriate safeguards pursuant to GDPR Chapter V. Where any Sub-processor is located outside the EEA, the Processor will ensure Standard Contractual Clauses (SCCs) approved by the European Commission are in place prior to such transfer.

6. Technical and Organisational Security Measures

The Processor implements and maintains the following security measures: AES-256 encryption at rest for all stored Personal Data including API credentials; TLS 1.2 or higher for all data in transit; role-based access controls limiting staff access to Personal Data on a need-to-know basis; automatic session expiry and single-use access tokens; regular automated vulnerability scanning; incident response procedures with maximum 72-hour breach notification capability; access logging and audit trails retained for 12 months.

7. Sub-processors

The Controller grants general authorisation for the following categories of Sub-processors, subject to the Processor entering into GDPR-compliant data processing agreements with each: (a) EEA-based cloud hosting and infrastructure providers for data storage and compute; (b) EEA-based email delivery providers for transactional email (module alerts, connection notifications). The Processor will notify the Controller of any intended changes to the list of Sub-processors at least 14 days in advance, giving the Controller the opportunity to object.

8. Data Breach Notification

In the event of a Personal Data breach as defined in Article 4(12) GDPR that affects Personal Data processed under this DPA, the Processor will notify the Controller without undue delay and in any event within 72 hours of becoming aware of the breach. Notification will be sent to the Controller's registered email address and will include, to the extent known at the time: a description of the nature of the breach; categories and approximate number of Data Subjects and records affected; name and contact details of the data protection contact at the Processor; likely consequences of the breach; measures taken or proposed to address the breach and mitigate its effects.

9. Duration and Termination

This DPA remains in force for the duration of the Processor's provision of Services to the Controller. Upon termination of all module subscriptions, the Processor will, at the Controller's choice, securely delete or return all Personal Data processed under this DPA within 30 days of the termination date, and provide written confirmation of deletion. The Processor may retain Personal Data beyond this period only to the extent and for the duration required by applicable law, and will inform the Controller of any such retention.

10. Governing Law

This DPA is governed by the law of Montenegro. Disputes arising from this DPA shall be subject to the exclusive jurisdiction of the Osnovni sud u Podgorici. For EU Consumer Controllers, applicable mandatory consumer protection law of their member state may also apply.

11. Contact

For DPA enquiries or to request a signed copy: CockpitShop d.o.o., ul. Bulevar Sv. Petra Cetinjskog 22, 81000 Podgorica, Crna Gora. Email: support@cockpitshop.org. Phone: +382 20 245 110.