Winter offer — choose annual and your year begins March 1.See plans

Data processing agreement

Last updated 21 August 2026

This Data Processing Agreement (“DPA”) forms part of, and is incorporated by reference into, the Terms of Service between Shushko Ltd (“Shushko”, “we”, “us”, or “our”) and the Host or Customer that has agreed to those Terms (the “Customer”, “you”, or “your”) (together, the “Agreement”). This DPA applies automatically when the Agreement takes effect, and no separate signature is required — though Shushko will provide a signed or countersigned copy on reasonable written request.

Capitalized terms not defined in this DPA have the meaning given to them in Shushko’s Privacy policy or the Agreement.

1. Definitions

  • GDPR” means Regulation (EU) 2016/679.
  • Personal Data“, “Processing“, “Controller“, “Processor“, “Data Subject“, “Personal Data Breach“, and “Special Categories of Personal Data” have the meanings given to them in the GDPR.
  • Customer Data” means the Personal Data described in Annex I, processed by Shushko on the Customer’s behalf in connection with the Service.
  • Sub-processor” means any processor engaged by Shushko to process Customer Data on the Customer’s behalf.

2. Scope and roles

2.1 This DPA applies where Shushko processes Personal Data on the Customer’s behalf as a Processor, specifically:

(a) Guest data collected through a Host Site, or otherwise through the Service, in connection with bookings and payments; and

(b) identity, travel document, or registration data collected on the Customer’s behalf for the purpose of complying with local tourism, hospitality, or public-security registration laws, where the Customer has enabled this functionality, and, where available and enabled, transmitted to the relevant authority on the Customer’s instructions.

2.2 As between the Parties, the Customer is the Controller and Shushko is the Processor with respect to the Personal Data described in 2.1. Shushko acts as an independent Controller with respect to its own account, billing, and marketing data as described in its Privacy Policy, and this DPA does not apply to that processing.

2.3 The subject matter, duration, nature, purpose, and categories of data and data subjects covered by this DPA are set out in Annex I.

3. Processor obligations

Shushko shall:

(a) process Personal Data only on the Customer’s documented instructions, including with regard to international transfers, unless required to do otherwise by EU or Member State law — in which case Shushko will inform the Customer of that legal requirement before processing, unless the law prohibits this;

(b) ensure that personnel authorized to process Personal Data are subject to a duty of confidentiality;

(c) implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Annex II;

(d) not engage a Sub-processor without the Customer’s prior authorization, as set out in Section 4;

(e) assist the Customer by appropriate technical and organizational measures, insofar as this is possible, in fulfilling the Customer’s obligation to respond to requests from Data Subjects seeking to exercise their rights under Chapter III of the GDPR;

(f) assist the Customer, taking into account the nature of processing and the information available to Shushko, in meeting its obligations under Articles 32 to 36 GDPR (security, breach notification, and data protection impact assessments);

(g) at the Customer’s choice, delete or return all Personal Data after the end of the provision of the relevant Services, and delete existing copies, unless applicable law requires continued storage — see Section 8;

(h) make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR, and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to reasonable advance notice and confidentiality.

The Agreement, this DPA, and the Customer’s configuration and use of the Service together constitute the Customer’s complete documented instructions to Shushko in respect of the processing of Customer Data. Any further or different instruction must be agreed in writing.

4. Sub-processors

4.1 The Customer provides Shushko with general written authorization to engage Sub-processors to help provide the Service (meaning the Customer does not need to separately approve each new Sub-processor — the Customer is instead notified of changes and may object, as set out in Section 4.2), provided that Shushko:

(a) imposes data protection obligations on each Sub-processor that are substantially similar to those in this DPA; and

(b) remains fully liable to the Customer for each Sub-processor’s performance of those obligations.

4.2 Shushko will give the Customer reasonable advance notice of any intended addition or replacement of a Sub-processor, giving the Customer the opportunity to object on reasonable data-protection grounds. If the Parties cannot resolve an objection, the Customer may terminate the affected part of the Service in accordance with the Agreement.

5. International data transfers

Shushko and its Sub-processors are primarily located within the European Economic Area (EEA). Where Personal Data is transferred to a Sub-processor located outside the EEA, Shushko will ensure an appropriate transfer mechanism is in place beforehand, such as the European Commission’s Standard Contractual Clauses, consistent with the approach described in our Privacy policy. Transmission of Personal Data to a public authority under Section 2.1(b) is made on the Customer’s instructions to a recipient acting in its own capacity, and is not a transfer to a Sub-processor.

6. Personal data breach

Shushko will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Data, and will provide reasonably requested information to help the Customer meet its own notification obligations under Articles 33 and 34 GDPR.

7. Data protection impact assessments

Shushko will provide reasonable assistance to the Customer, at the Customer’s cost, with data protection impact assessments and any related consultations with supervisory authorities that the Customer reasonably considers necessary, taking into account the nature of the processing and the information available to Shushko.

8. Retention, return and deletion of data

8.1 Retention during the term. Guest identity and travel document details processed under Section 2.1(b) are deleted 12 months after the departure date of the booking to which they relate, unless the Customer instructs Shushko otherwise in writing and Shushko agrees. Reservation and payment records are retained for the duration of the Agreement and thereafter in accordance with Section 8.2.

8.2 On termination or expiry of the Agreement. This Section governs Customer Data remaining at the point the Agreement ends. Shushko will retain reservation and payment data — guest identity and travel document details having been deleted in accordance with Section 8.1 — for the period the Customer is required to retain such records under the tourism, hospitality, tax, and accounting laws applicable to it. The Customer is responsible for determining that period. Where the Customer has not notified Shushko of a different period in writing, Shushko will retain that data for ten years from the end of the Agreement and then delete it. Other Customer Data will be retained for up to 12 months before deletion, to accommodate the seasonal nature of short-term rental businesses. During the applicable retention period, the Customer may request return of some or all of that Customer Data, which Shushko may condition on reactivation of the Customer’s account or payment of a reasonable fee. After the applicable period, or at any time following the Customer’s request, Shushko will delete Customer Data and existing copies, unless:

(a) applicable law requires Shushko to retain some or all of it — for example, for accounting, tax, or regulatory purposes as described in our Privacy policy; or

(b) the Customer has instructed Shushko in writing to retain specified Customer Data for a longer period — for example, to meet the Customer’s own record-keeping obligations under local tourism, hospitality, or public-security law.

The Customer is responsible for determining what data retention obligations apply to it under the laws of the jurisdictions in which it operates.

9. Special categories of data

The Customer shall not submit, and shall not instruct Shushko to process, special categories of personal data (as defined in Article 9 GDPR) through the Service, except to the extent expressly required by applicable law for the purpose described in Section 2.1(b), and shall notify Shushko in writing before doing so. For the avoidance of doubt, identity and travel document details collected under Section 2.1(b) are not special categories of personal data, and the notification requirement in this Section does not apply to them.

10. Liability

Each Party’s liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement.

11. Term

This DPA takes effect when the Customer first accepts the Agreement and remains in effect for as long as Shushko processes Customer Data under the Agreement, subject to Section 8.

12. Governing law and order of precedence

This DPA is governed by the same governing law as the Agreement. In the event of a conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA prevails.

This DPA is published in English. Where we provide a translated version, it is for convenience only, and the English version shall prevail in the event of any inconsistency or conflict.


Annex I — Details of processing

Subject matter: The provision of the Service by Shushko to the Customer, including operation of the Customer’s Host Site, booking and payment facilitation, and guest registration functionality where enabled.

Duration: As set out in Section 8 of this DPA.

Nature and purpose of processing: Hosting, storage, transmission, and processing of Personal Data as necessary to operate the Host Site, process bookings and payments, and — where enabled by the Customer — collect, store, and make available to the Customer the guest identity or registration information the Customer requires in order to meet its own reporting obligations under local tourism, hospitality, or public-security laws, and, where such functionality is available for the relevant jurisdiction and enabled by the Customer, transmit that information to the relevant authority on the Customer’s instructions.

Categories of data subjects: Guests booking accommodation through a Host Site or whose details are otherwise collected through the Service, and, where applicable, other individuals whose data is submitted by the Customer or a Guest in connection with a booking or a registration requirement.

Types of personal data: Contact details (name, email, phone); booking details (dates, property, price); payment-related data, including confirmation data for online card payments (processed via Stripe; full card data is not held by Shushko) and records of payments settled outside the Platform, such as cash or bank transfer; and, where enabled by the Customer, identity or travel document details required for local registration purposes (such as passport or ID number, nationality, or date of birth).

Annex II — Technical and organizational security measures

Shushko implements measures including, but not limited to:

  • Encryption of Personal Data in transit (HTTPS/TLS).
  • Encryption of Personal Data at rest at the infrastructure level, using a managed cloud database service with built-in encryption at rest.
  • Additional field-level encryption applied to specific sensitive data, such as identity or travel document numbers (where collected). Authentication is passwordless: users sign in via a single-use, time-limited code sent to their registered email address. No user passwords are stored.
  • Continuous backup of production data with point-in-time recovery, retained for 35 days.
  • Access to production systems limited to authorized personnel using individually assigned, permission-scoped credentials; shared or administrative credentials are not used for routine access.