Guest ID Processing Agreement>
Villario · a trading name of Cyridium Ltd · DPA Version: 2026-07-10
This Data Processing Agreement (“DPA”) is entered into between Cyridium Ltd, trading as Villario, a company registered in England and Wales (registered office: 19 Brambles Crescent, Blythe Valley, Solihull, B90 8DJ) (“Processor” or “Villario”), and the Host who accepts it in their Host dashboard (“Controller” or “Host”).
When this DPA applies: Certain jurisdictions legally require accommodation providers to collect and retain identification details from every guest before check-in. Where a Host's Property is in such a jurisdiction, Villario can collect this data from Guests on the Host's behalf. Villario will not enable guest ID collection, and will not send guest ID collection emails, for any Property until the Host has accepted the current version of this DPA. Acceptance is recorded against the specific DPA version accepted; if this DPA is later revised, the Host must accept the new version before collection can continue.
1. Definitions
Personal Data, Data Subject, Processing, Controller, Processor — have the meanings given in UK GDPR.
Guest ID Data — the identity information and document scan described in Schedule A, submitted by a Guest via Villario's one-time collection link in connection with a Booking on the Host's Property.
Instructions — the Host's documented instructions for processing Guest ID Data, as set out in this DPA and enacted through the collection, retention, and access-control mechanisms described below.
Security Incident — any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Guest ID Data.
2. Roles of the parties
For Guest ID Data, the Host is the Controller: the legal duty to collect and retain this information for statutory guest-registration purposes belongs to the Host as the accommodation provider registered in the relevant jurisdiction. Villario is the Processor, acting only on the Host's documented Instructions, as implemented by the collection, storage, access, and retention mechanism described in this DPA.
3. Subject matter, nature, and purpose of processing
Schedule A — Processing details
Item | Details |
|---|---|
Subject matter | Collection, storage, and time-boxed disclosure of guest identification data required for statutory guest registration |
Duration | For as long as the Host's account processes Bookings for Properties in a jurisdiction requiring guest ID collection, subject to the automatic retention and purge schedule in Section 7 |
Nature of processing | Collection via a one-time secure link; encryption at rest; time-boxed, field-limited disclosure to the Host; automatic deletion once the statutory retention period expires |
Purpose | To meet the Host's statutory guest-registration obligations in the Property's jurisdiction |
Types of personal data | Full name, date of birth, nationality, document number, document expiry date, issuing country, address, place of birth, and a scan of the identity document |
Categories of data subjects | Guests who have made a Booking on the Host's Property in a jurisdiction that requires guest ID collection |
Special category data | Not anticipated. Guests should not include special category data (e.g. health information) in any free-text field submitted through the collection flow. |
4. How Villario processes Guest ID Data (the Instructions)
Collection: Villario emails the Guest a one-time submission link (30-day validity) once collection is triggered ahead of check-in. The Guest submits the required fields, and where applicable a document scan, directly to Villario — never to the Host.
Encryption: Submitted data is encrypted at rest (AES-256-GCM). Document scans are stored separately in access-controlled storage.
Host-visible fields only: The Host's view is limited to first name, last name, date of birth, and nationality. Document number, expiry date, issuing country, address, place of birth, and the document scan itself are never disclosed to the Host under this DPA; they are accessible only to Villario personnel, and only where necessary to respond to a lawful request from a competent authority.
Host access window: The Host's limited view is available only until a fixed number of days after the Guest's check-out (14 days by default). After that point, the Host's access is withdrawn automatically and entirely, independent of whether the underlying record has yet reached its statutory retention deadline.
Audit log: Every attempt to view a Guest ID Data record — whether it succeeds, is denied because the host-access window has closed, or is denied because the record has already been purged — is logged immutably.
Fail-closed default: If the host-access expiry cannot be determined for a record, it is treated as already expired and withheld from the Host, rather than disclosed by default.
5. Host's obligations as Controller
The Host warrants and undertakes that:
Guest ID collection is enabled only for Properties in jurisdictions that have a genuine legal basis requiring it;
The Host has, or will provide on request, a lawful basis and any required guest-facing notice for this collection beyond what Villario's own Privacy Policy already provides;
The Host will not attempt to request Guest ID Data directly from a Guest by message, email, or any channel outside the Villario collection link;
The Host will use the limited fields disclosed to it (Section 4) solely for the statutory guest-registration purpose, and not retain, copy, or export them beyond what its own record-keeping obligation strictly requires;
The Host will notify Villario promptly if it becomes aware of any inaccuracy in Guest ID Data or a request from a Guest that affects it.
6. Villario's obligations as Processor
Villario shall:
Process Guest ID Data only per the Instructions in Section 4, except where required to do so by law (in which case Villario will inform the Host unless legally prohibited);
Ensure personnel authorised to access Guest ID Data are bound by confidentiality obligations;
Implement and maintain the technical and organisational measures described in Schedule B;
Not engage a new sub-processor for Guest ID Data without informing the Host, as set out in Section 8;
Assist the Host, by appropriate technical and organisational measures, in responding to Guest data-subject requests relating to Guest ID Data;
Make available information reasonably necessary to demonstrate compliance with this DPA.
7. Retention and deletion
Guest ID Data is retained until the statutory retention period applicable to the Property's jurisdiction expires (by default, 3 years from submission, or longer where local law specifies a longer period), at which point it is automatically and permanently purged by Villario — this deletion clock runs independently of, and is not extended or shortened by, the separate host-access window described in Section 4. On termination of the Host's account, Guest ID Data already collected continues to be retained and purged strictly on this same statutory schedule; it is not deleted early merely because the Host account has closed.
8. Sub-processors
Schedule C — Approved sub-processors for Guest ID Data
Sub-processor | Role | Location |
|---|---|---|
Linode, LLC (Akamai Technologies) | Encrypted storage of Guest ID Data and document scans | UK/EU regions |
Postmark (Wildbit, LLC) | Delivery of the one-time collection link email | United States — UK/EU Standard Contractual Clauses in place |
Villario will notify Hosts of any change to this sub-processor list at least 14 days in advance by updating this Schedule and this DPA's version.
9. Security measures
Schedule B — Technical and organisational measures
Encryption at rest: AES-256-GCM, per record.
Encryption in transit: TLS 1.2 or higher for all submission and access paths.
One-time submission tokens: Guest submission links expire after 30 days and cannot be reused once submitted.
Field-level access control: The Host-facing view is limited to the minimal field set in Section 4, enforced server-side, not just hidden in the interface.
Time-boxed host access: Enforced server-side against the check-out date, independent of the statutory retention clock.
Immutable audit logging: Every access attempt (granted or denied) is logged.
Automatic purge: A scheduled process permanently deletes records once the statutory retention period expires.
Personnel: Staff with access to Guest ID Data are subject to confidentiality obligations and access is limited on a need-to-know basis.
10. Security incident notification
In the event of a Security Incident involving Guest ID Data, Villario will notify the Host without undue delay, and where feasible within 72 hours of becoming aware of it, including a description of the nature of the incident, categories and approximate number of data subjects affected, likely consequences, and remedial measures taken or proposed. The Host remains responsible for notifying the ICO and affected Guests as required by UK GDPR Articles 33 and 34, since the Host is the Controller for this data.
11. International transfers
Where Guest ID Data is transferred outside the UK or EEA to a sub-processor in a third country, Villario ensures an appropriate transfer mechanism is in place (UK International Data Transfer Agreement, UK Addendum to EU Standard Contractual Clauses, or an equivalent lawful mechanism).
12. Term and termination
This DPA continues for as long as Villario processes Guest ID Data on the Host's behalf. If the Host's account is closed, Villario continues to retain and, in due course, purge Guest ID Data already collected strictly in accordance with Section 7 — this DPA continues to apply to that residual processing until final deletion.
13. Governing law
This DPA is governed by the laws of England and Wales. The parties submit to the exclusive jurisdiction of the courts of England and Wales.
14. Contact
Cyridium Ltd, trading as Villario
19 Brambles Crescent, Blythe Valley, Solihull, B90 8DJ
Data protection queries: privacy@villario.com
ICO registration: ZC135949