Legal
Data processing agreement
How POLARGATE S.L. handles the personal data in reviews on the hotel's behalf.
Last updated:
Version 2026-10-11.3.
Parties
This is the data processing agreement under Article 28 of the GDPR between the hotel that signs up for PolarPuffin, as controller, and POLARGATE S.L. (tax ID B24895005), as processor. It is part of the terms of service and is accepted with them, on payment. Anything it does not cover is governed by those terms.
Purpose and duration
The processor handles the data only to provide the service the hotel signed up for: bringing together its Google, TripAdvisor and Booking reviews, analysing them, preparing the reports, alerts, measurements and draft replies, and emailing them. The agreement lasts as long as the subscription.
What data and whose
The personal data in the hotel's reviews and in what is prepared from them for the hotel (reports, alerts and draft replies). The reviews are public.
Before analysis, the reviewer's name and profile link are removed (pseudonymisation). The text may still contain personal data, such as the name of a member of staff or another guest; the reports replace it with "[name]".
Data subjects: the people who write the reviews (the hotel's guests) and the people named in them, such as staff.
Special categories of data are not sought. If a review contains any, it is not used.
What is not covered
POLARGATE S.L. processes the hotel's contact, account and billing data as a controller in its own right, under the privacy policy, not under this agreement. The same goes for the free report and the free trial, before signing up: to provide them, POLARGATE S.L. processes the reviews as a controller, on the legitimate interest of giving the hotel what it asked for.
Instructions
The processor handles the data only on the hotel's documented instructions: this agreement, the terms of service and whatever the hotel asks for in writing. If a law requires otherwise, it tells the hotel first, unless that law forbids it. If it believes an instruction infringes the GDPR or another data protection rule, it says so immediately.
Confidentiality
Polargate staff who handle the data are bound by confidentiality, which continues after they stop doing so.
Security measures
- Data is encrypted in transit.
- Access is limited to Polargate staff who need it to provide the service.
- Data is processed on Polargate's own equipment and by the sub-processors listed below, nowhere else.
- The reviewer's name and profile link are removed before analysis.
Sub-processors
The hotel gives general written authorisation for the processor to use sub-processors. Today they are:
- Anthropic, PBC
- United States. Analyses the review text with Claude. It does not train its models on data received through its commercial API.
- Google Ireland Limited
- Ireland. Google Workspace, used to email the reports.
Changes of sub-processor
Before adding or replacing one, the processor emails the hotel 30 days in advance. The hotel may object and, if no agreement is reached, cancel before the change applies. Each sub-processor is bound by the same obligations as this agreement.
International transfers
When a sub-processor handles data outside the European Economic Area, the transfer relies on the European Commission's standard contractual clauses and, where the provider is certified, the EU-US Data Privacy Framework.
Data subject rights
If someone asks the processor to access, rectify or erase their data, to object, or to exercise any other right, the processor passes the request to the hotel without delay. It helps the hotel answer such requests with the technical and organisational measures available to it.
Security breaches
If the processor becomes aware of a breach affecting the data, it notifies the hotel without undue delay and within 48 hours at most, with what it knows: what happened, which data and people may be affected, its likely consequences and what has been done. It then helps the hotel notify the supervisory authority and the people affected where needed.
Impact assessments
The processor helps the hotel with any data protection impact assessments and prior consultations with the supervisory authority it needs to carry out, with the information available to it.
When the agreement ends
When the subscription ends, the processor deletes the data or, if the hotel asks beforehand, returns it, within the following 30 days. It keeps only what a law requires it to keep, and only for as long as required.
Audits
The processor gives the hotel the information needed to show that it complies with this agreement, starting with documentation. If that is not enough, the hotel may carry out an audit, itself or through an auditor of its choice, with reasonable notice and at its own cost.
Other legal texts
Terms of service · Privacy policy · Cookie policy · Legal notice
For any question about this page, write to hello@polargate.ai.