DATA PROCESSING
Data Processing Agreement
Article 28 processing terms for organizations using the StayMission free pilot. Effective 15 September 2026.
Roles and scope
The customer organization is controller and Lyuben Doykin, trading as StayMission, is processor for personal data the customer enters about owners, workers, contacts and property operations. Processing lasts while the pilot workspace is active plus the agreed deletion period and is limited to hosting, organizing, securing, backing up and transmitting records according to the customer’s use of the service.
Instructions and confidentiality
The customer instructs processing through these terms, account settings and documented support requests. StayMission will process customer data only on documented instructions unless Bulgarian or EU law requires otherwise, and will notify the customer where legally permitted. Anyone authorized to process the data must be bound to confidentiality.
Security
Current measures include encrypted transport, secure session cookies, password hashing, expiring tokens, role and owner authorization, separate operational databases per organization, authenticated file delivery, firewalling, key-based administration, security updates and rolling backups. Customers must configure roles carefully and avoid unnecessary sensitive data.
Subprocessors
The customer gives general authorization for the published subprocessors. StayMission will give reasonable advance notice of a material new subprocessor where practical, allowing the customer to raise a reasoned data-protection objection. StayMission remains responsible for imposing appropriate data-protection obligations on subprocessors.
Assistance and incidents
Taking account of the processing, StayMission will reasonably assist with data-subject requests, security assessments, breach response and legally required impact assessments. Suspected customer-data breaches will be communicated without undue delay with available information needed for the customer’s duties.
Return, deletion and audit
On a verified request at the end of service, permitted data can be exported using available exports and operational data will be scheduled for deletion within 30 days, with rolling backups expiring within up to seven further days, unless law requires retention. Reasonable compliance information will be provided; audits must protect other customers and avoid unnecessary disruption.
Customer obligations
The customer is responsible for lawful instructions, transparency to data subjects, an appropriate legal basis, data accuracy, role assignments and responding as controller. The customer must not instruct processing that violates applicable law and must not upload prohibited sensitive information.
Run your portfolio
from one place.
Start your workspace14-day Starter trial · No card required