Tenant as controller / IAN X as processor
For guest data entered by a tenant, the tenant generally decides the purpose and content of processing. IAN X generally provides software and infrastructure to process that data on the tenant's instructions.
This controller/processor language is a draft and must be reviewed for the applicable jurisdiction and customer agreement.
Processing instructions
IAN X processes tenant data to provide, secure, support, maintain, and improve the service, and to follow documented tenant instructions where technically and legally feasible.
Data types
Data may include tenant account data, staff records, guest records, stay and room data, payment records, invoices, support tickets, logs, audit trails, marketplace records, API data, and uploaded files where enabled.
Security safeguards
IAN X uses reasonable technical and organizational safeguards designed to protect data, such as tenant separation, access controls, backups, monitoring, and logging where configured.
Subprocessors placeholder
Hosting, email, payment, storage, monitoring, and support providers may act as subprocessors. A final subprocessor list should be reviewed and approved before launch.
Data export and delete requests
IAN X includes privacy request foundations for exports, anonymization, document deletion, and workspace export. Some actions may require approval to preserve accounting, reporting, security, and operational integrity.
Incident notification
IAN X is designed to support incident management and notices. Timing, content, and legal notification duties must be confirmed in the final customer agreement.
Return or deletion of data
Data return or deletion after termination may depend on tenant request, backups, legal retention, accounting records, and technical feasibility.
Contact
Data processing questions should be sent to the privacy or DPO contact shown on this page if configured.