Xentra

    Data Processing Agreement (DPA)

    This Data Processing Agreement ("DPA") forms part of the contract for services between Stellar Tourism Innovations GmbH ("Processor") and its customers ("Controller") and governs the processing of personal data in accordance with Art. 28 GDPR.

    Last updated: 5 September 2026

    Preamble

    This Data Processing Agreement (DPA) governs the processing of personal data by Stellar Tourism Innovations GmbH ("Xentra", "Processor") on behalf of the Customer ("Controller").

    Xentra provides a SaaS platform for managing short-term rentals, within which personal data of guests and contacts of the Customer is processed.

    §1 Subject and Duration

    The Processor processes personal data on behalf of the Controller in the context of the following services:

    • Booking management and guest check-in
    • Guest communication (SMS, email, messaging)
    • Smart lock and access management
    • AI-assisted text generation and analysis
    • Payment processing (via Stripe)
    • Identity verification and registration

    §2 Categories of Data Subjects and Data

    .h3DataSubjects

    • Guests / travelers of the Controller
    • Contacts and business partners of the Controller
    • Owners and managers of the properties administered by the controller
    • Employees and service providers of the controller with access to the platform

    .h3DataTypes

    • Master data (name, address, date of birth)
    • Contact data (email, phone)
    • Booking data (arrival, departure, price, apartment)
    • Identity documents (for check-in with ID verification)
    • Payment data (processed by Stripe)
    • Communication content (messages, emails)
    • Access data for properties (access codes, key assignments) and access logs
    • Signatures, uploaded ID images and task photos
    • Voice messages and transcripts generated from them
    • Scheduling, working time and remuneration data of the controller's service providers

    §3 Obligations of the Processor

    • Processing data exclusively based on documented instructions of the Controller
    • Ensuring confidentiality of all persons entrusted with data processing
    • Taking all necessary technical and organizational measures pursuant to Art. 32 GDPR
    • Supporting the Controller in fulfilling obligations towards data subjects
    • Immediate notification of the Controller in case of data breaches

    §4 Sub-processors

    The Controller agrees to the use of the following sub-processors:

    ProviderPurposeServer location
    Supabase Inc..subSupabaseAWS eu-central-1 (Frankfurt)
    Vercel Inc..subVercelUSA (SCC)
    Google Cloud (Cloud Run).subGcloudEU (Frankfurt)
    Functional Software Inc. (Sentry).subSentryEU / USA (SCC)
    Digital Shift OÜ (Capgo).subCapgoEU (Estland)
    Google LLC (Gemini API).subGeminiUSA (SCC)
    Anthropic PBC.subAnthropicUSA (SCC)
    Stripe Inc. / Stripe Payments Europe Ltd..subStripeEU / USA (SCC)
    Chargebee Inc..subChargebeeUSA (SCC)
    Haufe-Lexware GmbH & Co. KG.subLexwareEU (Deutschland)
    Fatture in Cloud S.p.A..subFattureincloudEU (Italien)
    Resend Inc..subResendUSA (SCC)
    Twilio Inc..subTwilioUSA (SCC)
    Meta Platforms Ireland Ltd..subMetaEU / USA (SCC)
    HostU.subHostuEU (DE/AT)
    Apple Distribution International Ltd..subApnsEU / USA
    Google Ireland Ltd. (FCM).subFcmEU / USA (SCC)
    Chekin S.L..subChekinEU (Spanien)
    AVS GmbH.subAvsEU (Deutschland)
    Feratel Media Technologies AG.subFeratelEU (Österreich)
    WINTOP Software.subWintopEU (DE/AT)
    Nuki Home Solutions GmbH.subNukiEU (Österreich)
    Seam Labs Inc..subSeamUSA (SCC)
    Salto Systems S.L..subSaltoEU (Spanien)
    Ring LLC (Amazon.com Inc.).subRingUSA (SCC)
    Tedee sp. z o.o..subTedeeEU (Polen)
    Sciener / TTLock.subTtlockChina (SCC)
    igloocompany Pte Ltd.subIgloohomeSingapur (SCC)
    Wonderlabs (SwitchBot).subSwitchbotHongkong (SCC)
    Channex Ltd..subChannexEU
    Smoobu GmbH.subSmoobuEU (Deutschland)
    iLoca Services GmbH.subIlocaEU (Deutschland)
    V-Office (Ferienhausmiete GmbH).subVofficeEU (Deutschland)
    Beds24 (Cousins Online Ltd.).subBeds24EU / UK
    Lodgify S.L..subLodgifyEU (Spanien)
    Octorate S.r.l..subOctorateEU (Italien)
    Smily (BookingSync S.A.S.).subSmilyEU (Frankreich)
    Hostfully Inc..subHostfullyUSA (SCC)
    Hospitable Inc..subHospitableUSA (SCC)
    Hostaway Pty Ltd.subHostawayUSA (SCC)
    Guesty Inc..subGuestyUSA (SCC)
    PriceLabs.subPricelabsUSA / Indien (SCC)
    Google LLC (Drive).subGoogleDriveUSA (SCC)
    Google LLC (OAuth).subGoogleOauthUSA (SCC)
    Google LLC (Maps Geocoding).subGmapsUSA (SCC)

    .subprocessorsScc

    .subprocessorsChange

    .supportAccess

    §5 Technical and Organizational Measures

    The Processor has implemented the following measures:

    • Encryption of all data in transit (TLS 1.2+) and at rest (AES-256)
    • Row-Level Security (RLS) — each user can only see their own data
    • Anonymization of personal data before transmission to AI services (Google Gemini)
    • Audit logging of all AI processing operations (without PII in logs)
    • Multi-factor authentication for administrative access
    • Regular security reviews and updates
    • API key encryption with pgcrypto for all external integrations

    §6 Deletion and Return

    After the contractual relationship ends, the processor deletes the controller's personal data unless a statutory retention obligation applies. Certain data sets are subject to their own periods already during the term: registration data in the transmission logs to registration portals is deleted 30 days after confirmed transmission, support recordings after 30 days, and technical access and interface logs after 7 to 30 days.

    The Controller may request the export of their data in machine-readable format at any time.

    §7 Audit Rights

    The Controller has the right to verify compliance with this DPA through appropriate measures, including inspections.

    The Processor shall provide the Controller with all necessary information to demonstrate compliance upon request.

    §8 Contact

    For questions regarding data processing, please contact:

    Stellar Tourism Innovations GmbH
    Torstrasse 105-107
    10119 Berlin
    E-Mail: datenschutz@myxentra.com

    We use cookies

    This website uses cookies and similar technologies for analytics and to improve your experience. Learn more in our Privacy Policy.