HostHub

Data Processing Addendum

数据处理附录

Effective August 1, 2026 · 生效日期 August 1, 2026

For customers who need a signed processor agreement — typically anyone handling guests from the EEA or the UK. It takes effect automatically with the Terms of Service; no signature is required, but we will sign a copy on request.

适用于需要签署处理者协议的客户,通常是接待来自欧洲经济区或英国房客的经营者。本附录随《服务条款》自动生效,无需签署;如需签署版本,我们可应请求提供。

  1. 1. Roles角色

    This addendum forms part of the Terms of Service between PLATINUM TRAVEL INC. ("Processor") and the Customer ("Controller"). It applies whenever we process personal data on the Customer's behalf, and prevails over the Terms of Service on that subject if the two conflict.
    本附录构成 PLATINUM TRAVEL INC.(“处理者”)与客户(“控制者”)之间《服务条款》的一部分。凡我们代表客户处理个人信息,即适用本附录;就该事项与《服务条款》冲突的,以本附录为准。

    The Controller determines the purposes and means of processing. The Processor processes only on documented instructions, which are: the Terms of Service, this addendum, and the Controller's use of the features in the product.
    控制者决定处理的目的与方式。处理者仅按书面指示处理,该等指示包括:《服务条款》、本附录,以及控制者对产品功能的使用行为。

    If we believe an instruction breaches applicable data protection law, we will tell the Controller and may pause that processing.
    若我们认为某项指示违反适用的数据保护法,我们将告知控制者,并可暂停该项处理。

  2. 2. Annex I — details of the processing附件一 — 处理详情

    • Subject matter: provision of the HostHub property management service.
      处理事项:提供 HostHub 房产管理服务。
    • Duration: for as long as the Controller's account is open, plus the 30-day export window after termination.
      处理期限:控制者账号存续期间,以及终止后 30 天的导出期。
    • Nature and purpose: storing, organising, transmitting, displaying, synchronising with connected channels, generating documents from, and deleting the data, in order to run the Controller's rental operation.
      处理性质与目的:为运行控制者的租赁业务,对数据进行存储、整理、传输、展示、与所接入渠道同步、据以生成文件以及删除。
    • Categories of data subject: guests and tenants, prospective guests, the Controller's staff and cleaners, and owners in profit-sharing arrangements.
      数据主体类别:房客与租客、潜在房客、控制者的员工与清洁人员,以及分成业主。
    • Categories of personal data: names, email addresses, phone numbers, messaging identifiers, stay dates and party size, payment and deposit amounts, free-text notes, identity-verification status, photographs, signed contracts and handwritten signature images, and message content.
      个人信息类别:姓名、邮箱、电话、通讯标识、入住日期与人数、付款与押金金额、自由文本备注、身份验证状态、照片、已签署合同与手写签名图像,以及消息内容。
    • Special category data: none is required by the product. If a Controller enters it in a free-text field, they do so on their own instruction and remain responsible for its lawfulness.
      特殊类别数据:产品本身不要求提供。若控制者在自由文本字段中录入,属其自行指示,并由其对合法性负责。
    • Frequency: continuous, for as long as the service is in use.
      处理频率:服务使用期间持续进行。
  3. 3. Confidentiality保密

    Everyone we authorise to access personal data is bound by a duty of confidentiality, and access is limited to those who need it to run or support the service.
    我们授权访问个人信息的所有人员均负有保密义务,且访问权限仅限于为运行或支持服务所必需的人员。

  4. 4. Annex II — security measures附件二 — 安全措施

    • Encryption of data in transit (TLS) and at rest by our infrastructure providers.
      传输过程加密(TLS),基础设施服务商提供静态加密。
    • Passwords stored only as bcrypt hashes; sessions carried in signed, http-only cookies; password reset and email verification tokens stored hashed, single-use and time-limited.
      密码仅以 bcrypt 哈希存储;会话使用签名的 http-only Cookie;密码重置与邮箱验证令牌以哈希形式存储,一次性且限时有效。
    • Tenant isolation: every query is scoped to the owning account, enforced by a central tenant map and verified by an automated suite that runs one tenant's requests against another's data and asserts they are refused.
      租户隔离:每次查询均限定于所属账号,由集中的租户映射强制执行,并通过自动化测试套件验证——以一个租户的请求访问另一租户的数据并断言被拒绝。
    • Role-based access within an account, so staff accounts see only the pages the Controller grants them.
      账号内基于角色的访问控制,员工账号仅能看到控制者授予的页面。
    • Error reports scrubbed of request bodies, cookies, query strings and sensitive headers before leaving our servers.
      错误报告在离开服务器前已剔除请求体、Cookie、查询串与敏感请求头。
    • An in-account activity log of actions taken, and a recycle bin so a deletion can be reversed rather than being immediately final.
      账号内操作活动日志,以及回收站机制,使删除可撤销而非立即不可逆。
    • Managed, point-in-time-recoverable database backups held by our database provider.
      由数据库服务商提供的托管式、可按时间点恢复的数据库备份。
  5. 5. Annex III — subprocessors附件三 — 次级处理者

    The Controller authorises the following subprocessors. Those marked optional are engaged only if the Controller enables that feature.
    控制者授权使用以下次级处理者。标注“可选”的仅在控制者启用相应功能时使用。

    • Vercel Inc. — Application hosting and file storage (Vercel Blob). All data in transit; uploaded photos, documents and signed contract PDFs at rest.
      Vercel Inc. — 应用托管与文件存储(Vercel Blob)。全部传输中的数据;上传的照片、文件与已签署合同 PDF。
    • Neon Inc. — Managed PostgreSQL database. All account, property, booking, guest and message records.
      Neon Inc. — 托管 PostgreSQL 数据库。全部账号、房源、订单、房客与消息记录。
    • Stripe, Inc. — Subscription billing, and guest payments where the customer connects their own Stripe account. Billing contact and payment details. Card numbers are entered on Stripe's own forms and never reach our servers..
      Stripe, Inc. — 订阅计费;若客户接入自有 Stripe 账户,则用于收取房客款项。账单联系人与支付信息。卡号在 Stripe 页面输入,不经过我们的服务器。。
    • Anthropic PBC (optional) — The AI assistant, note parsing, message drafting and pricing suggestions. Only the text sent to a given feature — typically a booking note, a guest message or a pricing question.
      Anthropic PBC(可选) — AI 助理、备注解析、消息草拟与定价建议。仅限该功能所发送的文本,通常为订单备注、房客消息或定价问题。
    • Hostex (optional) — Channel management: calendars, reservations and guest messages. Reservation and guest data for the customer's own Hostex account, using the customer's own API key.
      Hostex(可选) — 渠道管理:日历、预订与房客消息。客户自有 Hostex 账户的预订与房客数据,使用客户自己的 API 密钥。
    • The customer's chosen SMTP provider (optional) — Outbound email: contracts, invoices, reminders and confirmations. Recipient address and message content, including attached PDFs.
      The customer's chosen SMTP provider(可选) — 外发邮件:合同、发票、提醒与确认。收件地址与邮件内容,包括附件 PDF。
    • Functional Software, Inc. (Sentry) (optional) — Error monitoring. Error reports with request bodies, cookies and query strings stripped, and the user reduced to an account id.
      Functional Software, Inc. (Sentry)(可选) — 错误监控。错误报告;请求体、Cookie 与查询串已剔除,用户仅保留账号 ID。

    We impose data protection obligations on each subprocessor no less protective than those in this addendum, and remain liable for their performance. We will give at least 30 days' notice before adding or replacing one; the Controller may object on reasonable data protection grounds, and if we cannot resolve the objection they may terminate the affected service without penalty for the unused period.
    我们对每一次级处理者施加不低于本附录的数据保护义务,并对其履约承担责任。新增或更换次级处理者前,我们将至少提前 30 天通知;控制者可基于合理的数据保护理由提出异议,如无法解决,控制者可就受影响的服务终止合作,未使用期间不承担违约责任。

  6. 6. Assistance with data subject requests协助数据主体请求

    The product lets the Controller find, correct, export and delete records themselves, which is how most requests are answered. Where that is not enough, we will provide reasonable assistance, taking into account the nature of the processing.
    产品允许控制者自行查找、更正、导出与删除记录,多数请求可由此处理。若不足以应对,我们将结合处理性质提供合理协助。

    If a data subject contacts us directly, we will not respond on the Controller's behalf beyond telling them to contact the Controller, and we will forward the request.
    若数据主体直接联系我们,除告知其联系控制者外,我们不会代表控制者作出答复,并会转交该请求。

    We will also assist, so far as we reasonably can, with data protection impact assessments and prior consultations relating to the service.
    在合理范围内,我们亦将协助与本服务相关的数据保护影响评估与事前咨询。

  7. 7. Personal data breaches个人信息泄露

    We will notify the Controller without undue delay after becoming aware of a personal data breach affecting their data, and in any event within 72 hours, with the information we hold at the time and updates as we learn more.
    在知悉涉及控制者数据的个人信息泄露后,我们将不无故迟延地通知控制者,并在任何情况下于 72 小时内通知,说明届时掌握的信息,并随进展持续更新。

    Notifying supervisory authorities and data subjects is the Controller's responsibility, since they hold the relationship. We will support it.
    向监管机构与数据主体报告由控制者负责,因其为关系主体。我们将提供支持。

  8. 8. Return and deletion返还与删除

    The Controller may export their data at any time while the account is open, and for 30 days after termination. After that we delete it, other than backups that expire on their own cycle and anything we must retain by law.
    账号存续期间及终止后 30 天内,控制者可随时导出数据。此后我们将删除数据,但按自身周期自然过期的备份及法律要求保留的内容除外。

  9. 9. Audits审计

    On reasonable written request, and no more than once a year unless a regulator requires otherwise, we will provide the information needed to demonstrate compliance with this addendum. On-site audits are by prior agreement, at the Controller's cost, and must not disrupt the service or expose another customer's data.
    在合理书面请求下,且除监管机构另有要求外每年不超过一次,我们将提供证明遵守本附录所需的信息。现场审计须事先约定,费用由控制者承担,且不得干扰服务运行或暴露其他客户的数据。

  10. 10. International transfers跨境传输

    Where personal data originating in the EEA, the UK or Switzerland is transferred to a country without an adequacy decision, the parties agree the applicable Standard Contractual Clauses apply, with the Controller as data exporter and the Processor as data importer, and Annexes I to III above completing them.
    凡源自欧洲经济区、英国或瑞士的个人信息传输至无充分性认定的国家,双方同意适用相应的标准合同条款,控制者为数据出口方、处理者为数据进口方,并以上述附件一至三作为其附录内容。

  11. 11. Liability责任

    The limitations of liability in the Terms of Service apply to this addendum, except where applicable data protection law does not allow them to.
    《服务条款》中的责任限制适用于本附录,但适用的数据保护法不允许的除外。

  12. 12. Contact联系方式

    Data protection enquiries: platinumtravelca@gmail.com. PLATINUM TRAVEL INC., 2980 Number 3 Rd, Richmond, BC V6X 2B3.
    数据保护相关咨询:platinumtravelca@gmail.com。PLATINUM TRAVEL INC.,2980 Number 3 Rd, Richmond, BC V6X 2B3。

The English text is the governing version; the Chinese is provided for convenience. 中文译文仅供参考,以英文版为准。
PLATINUM TRAVEL INC. · 2980 Number 3 Rd, Richmond, BC V6X 2B3 · platinumtravelca@gmail.com