Legal

Data Processing Agreement

Governing Recal's processing of personal data on your behalf, under Article 28 GDPR

Last updated: July 2026

This Data Processing Agreement ('DPA') forms part of the Terms of Use between you (the 'Customer', acting as data controller) and Maud Naett, trading as Recal ('Recal', acting as data processor), and applies whenever Recal processes personal data on your behalf in providing the platform. By using Recal to record data about other people — guests, owners, contractors, and contacts — you accept this DPA.

1. Roles of the Parties

For the operational data you enter about third parties (for example guest and contact details, booking records, and documents), you are the data controller and Recal is your data processor: Recal processes that data only to provide the platform and only on your documented instructions, which are given through your configuration and use of the platform and through this DPA.

For data Recal processes about you as its own customer (your account, billing, and usage), Recal is an independent controller and that processing is governed by the Privacy Policy, not this DPA.

2. Subject Matter and Details of Processing

The processing Recal carries out on your behalf is as follows:

  • Subject matter and duration: provision of the Recal platform for the duration of your account; processing ends when your account is deleted, subject to the return-and-deletion terms below.
  • Nature and purpose: storing, organising, displaying, and otherwise processing your operational data so you can manage your property operations, including AI-assisted features you choose to use.
  • Categories of data subject: your guests, property owners, staff, co-hosts, contractors, and other contacts whose data you enter.
  • Categories of personal data: names and contact details; booking and stay information; notes and documents you upload, which may include identity documents (e.g. ID scans required by local registration rules); and any other data you choose to record. You must not enter special-category data unless you have a lawful basis to do so.

3. Recal's Obligations

Recal processes your operational data only on your documented instructions; keeps it confidential and ensures personnel with access are bound by confidentiality; implements the technical and organisational security measures described in the Privacy Policy; and does not use your operational data for its own purposes, never sells it, and does not use it to train AI models.

Recal assists you, taking into account the nature of the processing, with your obligations to respond to data-subject requests, to keep data secure, to notify personal-data breaches, and to carry out data-protection impact assessments. Recal notifies you without undue delay after becoming aware of a personal-data breach affecting your data.

4. Data Subject Rights and Assistance

The platform gives you direct tools to meet most controller obligations yourself:

  • access and rectification — you can view and edit the operational data you have entered at any time;
  • erasure — you can delete individual records, and deleting your account deletes your operational data (see the Privacy Policy for retention detail);
  • portability — you can export your calendars (iCal), files, and statistics, and may request a fuller export from info@recal.co;
  • restriction and objection — you control what is processed through your configuration of the platform;
  • where you need help beyond these tools to answer a data-subject request, Recal will provide reasonable assistance on request.

5. Sub-processors

You authorise Recal to engage the sub-processors needed to run the platform (hosting, storage, authentication, payments, communications, analytics, and AI infrastructure). Recal imposes data-protection obligations on each sub-processor equivalent to those in this DPA and remains responsible to you for their performance.

The current list of sub-processors is maintained on our Sub-processors page. Recal will give advance notice of any intended addition or replacement of a sub-processor so you have the opportunity to object on reasonable data-protection grounds.

6. International Transfers

Some sub-processors process data outside the European Economic Area. Where they do, transfers are safeguarded by European Commission Standard Contractual Clauses and, where the provider is certified, the EU-U.S. Data Privacy Framework. Recal's primary data storage (database, files, authentication) is located in the European Union.

7. Security

Recal implements appropriate technical and organisational measures to protect personal data, including encryption in transit, private file storage served only to authorised users, role-based access controls, and managed authentication. These measures are described in more detail in the Privacy Policy and are kept under review.

8. Return and Deletion

On termination of your account, Recal deletes your operational data (and instructs its sub-processors to do the same), except where retention is required by law, as described in the Privacy Policy. You may export the data you wish to keep before deletion.

9. Audit

Recal makes available the information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior written request and subject to confidentiality, will respond to a data-protection audit or questionnaire. This provision, and the allocation of liability between the parties, is governed by the Terms of Use and is subject to review by the parties' legal advisers.

10. Contact

For any questions about this DPA or Recal's processing of personal data on your behalf, contact:

Processor: Maud Naett (trading as Recal)

Email: info@recal.co

Postal address: Cami des Fornas s/n, Poligono 20, Parcela 124, 07820 Sant Antoni de Portmany, Islas Baleares, Spain

See also: Terms of Use, Privacy Policy, Sub-processors.