Data Processing Agreement
This Data Processing Agreement forms part of the SereneDeck Terms where SereneDeck processes personal data on behalf of a customer.
Effective 31 August 2026
Document version 2026-08-31
1. Parties and roles
The SereneDeck customer is the controller and ADNorden, CVR 27802753, is the processor for personal data submitted to the service on the customer's behalf. Each party remains responsible for its own obligations under applicable data-protection law.
2. Subject matter and duration
Processing covers the hosting and operation of SereneDeck's station, reservation, Guest Pass, room, import, reporting and audit functions. Processing lasts for the customer relationship and any limited return, deletion or legally required retention period after termination.
3. Data subjects, data and purposes
Data subjects may include hotel guests, customer employees, contractors and invited users. Data may include names, work emails, roles, room numbers, stay dates, party size, booking details, notes, identifiers from connected hotel systems, audit events and support information. SereneDeck processes this data only to provide, secure, support and maintain the service under the customer's documented instructions.
4. Customer instructions
The Terms, the customer's use and configuration of the service, and written support requests constitute documented instructions. SereneDeck will notify the customer if an instruction appears to infringe applicable data-protection law, unless prohibited from doing so.
5. Confidentiality and security
Persons authorised to process customer data are bound by confidentiality. SereneDeck maintains measures appropriate to the risk, including encrypted transport, password and token hashing, role-based access, tenant scoping, auditability, restricted administrative access, environment-managed secrets, recovery procedures and regular verification of security-relevant changes.
6. Subprocessors and transfers
The customer gives general authorisation for the providers on the Subprocessors page. SereneDeck will provide reasonable advance notice of a new subprocessor that will handle customer personal data. The customer may raise a documented data-protection objection. Equivalent contractual protections and lawful transfer safeguards are required throughout the provider chain.
7. Assistance
Taking account of the nature of processing, SereneDeck will reasonably assist the customer with data-subject requests, security obligations, breach assessment, supervisory-authority enquiries and data-protection impact assessments. The customer remains responsible for verifying requests and communicating with data subjects unless otherwise agreed.
8. Personal-data breaches
SereneDeck will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer data and will provide available information reasonably required for the customer's assessment and notifications. SereneDeck will take reasonable steps to contain, investigate and remediate the incident.
9. Return, deletion and audits
On termination and written request, SereneDeck will make customer data available for export and then delete or anonymise it, subject to legal retention duties and normal backup-expiry cycles. SereneDeck will provide information reasonably necessary to demonstrate compliance and permit proportionate audits under appropriate confidentiality, security and cost arrangements.
10. Contact and priority
Data-processing questions can be sent to contact@serenedeck.com. If this DPA conflicts with the Terms on processing of customer personal data, this DPA controls.