Oasis Guest Lab logo Oasis Guest Lab
Back to site

Legal

Data Processing Addendum

Version 1.0 · Effective 1 September 2026

The legal documents for this service

  • Terms of ServiceThe contract itself: what you buy, what we owe you, liability and termination.
  • Privacy PolicyWhat we do with your data, and what we do with your guests' data. Two separate roles.
  • Data Processing AddendumThe Article 28 terms. Part of your contract. Hand this to your lawyer.You are here
  • Sub-processorsEvery third party that touches guest data, and where each one processes it.
  • Acceptable Use PolicyWhat the platform may not be used for, including Meta and WhatsApp rules passed to you.
  • Cookie PolicyWhat this website stores on your device.

Each document is versioned and updated separately, so a change to one does not silently rewrite the others. Together they are the whole agreement.

Permanent URL of this version: https://www.oasisguestlab.ai/legal/dpa/v1.0/ Current version always at: https://www.oasisguestlab.ai/legal/dpa/

This Addendum is incorporated by reference into the Oasis Guest Lab Terms of Service and forms part of the agreement between us. Where this Addendum and the Terms of Service conflict on a matter of personal data, this Addendum governs.


1. Parties and roles

Processor: Lux Oasis Advisory & Services LLC, a company registered in the Sharjah Free Zone (SHAMS), United Arab Emirates, licence number 2645909, TRN 104722180700003 ("we", "us", "our").

Controller: the client identified on the Order Form ("you", "your").

For guest personal data processed through the Service, you are the controller and we are your processor. You decide the purposes and the means. You decide the legal basis. You answer data subject requests. We act only on your documented instructions.

We are a controller in our own right only for the data described in Part A of our Privacy Policy: website visitors, enquiries and the account records of the individuals at your business who use the Service. That data is outside this Addendum.

Where you are yourself a processor for someone else, for example where you manage units for owners who are the true controllers, you confirm that you have the authority to give us the instructions in this Addendum, and this Addendum applies as between us as if you were the controller.

2. Which law applies

This Addendum is written to be capable of satisfying:

  • the UAE Personal Data Protection Law, Federal Decree-Law No. 45 of 2021, which applies to our processing as a UAE-established company; and
  • Articles 28 and 32 to 36 of the EU General Data Protection Regulation, and the equivalent provisions of the UK GDPR, where you determine that either applies to your processing.

We do not determine whether the GDPR or the UK GDPR applies to you. You do, and you tell us on the Order Form. Where you say it applies, clauses 8.3, 9, 10 and 12 operate on GDPR timings and terminology, and the standard contractual clauses referred to in clause 8.3 are incorporated.

We make no claim of compliance with any other data protection regulation.

3. Subject matter and duration

Subject matter: the processing of personal data necessary to provide the Oasis Guest Lab guest communication service to you, as described in the Terms of Service and the Order Form.

Duration: from the Service Start Date until the deletion or return of all personal data under clause 11. Our obligations under clauses 5, 6, 9, 11 and 12 survive termination for as long as we hold any of your personal data.

4. Nature and purpose of the processing

We process personal data in order to:

  1. receive guest messages from a WhatsApp number connected to your account, and match each message to the correct unit and, where you connect a property management system, to the correct booking;
  2. generate a reply using the knowledge layer built from the unit data you supply, by submitting the message and relevant unit context to an AI provider;
  3. apply the escalation rules configured for your account and flag conversations to your team;
  4. present conversations in the Chatwoot operator dashboard so your team can read, take over and continue them, and label what was AI and what was human;
  5. retain conversation history so context survives a handover;
  6. host, back up, secure, monitor and support the Service;
  7. produce Aggregated and De-identified Data as permitted by clause 6.4;
  8. comply with law.

Processing operations include collection, recording, organisation, structuring, storage, retrieval, consultation, use, disclosure by transmission to the sub-processors listed in the Sub-processor List, restriction, erasure and destruction.

5. Categories of data and data subjects

5.1 Data subjects

  • Guests and prospective guests who message a WhatsApp number connected to the Service.
  • Individuals mentioned by a guest in a message, such as fellow travellers.
  • Members of your team who use the Chatwoot dashboard.

5.2 Categories of personal data

  • WhatsApp phone number and WhatsApp profile display name.
  • Message content sent to and from the connected number, which is free text and may contain anything the guest chooses to write.
  • Conversation metadata: timestamps, delivery and read status, direction, detected language, AI or human attribution, escalation labels and tags.
  • Booking data received from your property management system where you connect one: guest name, phone number, unit, check-in and check-out dates, booking source and booking reference.
  • Your team's dashboard user names, email addresses and action logs.

5.3 Special categories

The Service is not designed for, and you must not configure it to solicit, data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation.

A guest may volunteer such data in free text, most commonly health or dietary information. Where that happens it is processed incidentally, as part of the message, under the same protections as the rest of the conversation. You are responsible for accounting for that possibility in your own privacy notice, your own legal basis analysis and, where required, your own data protection impact assessment.

5.4 Children

The Service is not directed at children. Data about children may appear where a booking includes them or a guest mentions them.

6. Your instructions

6.1 The instruction

We process personal data only on your documented instructions, including on transfers, unless we are required to process by law that applies to us, in which case we will tell you before processing unless that law forbids it on important grounds of public interest.

6.2 What counts as your instruction

Your documented instructions are:

  1. this Addendum;
  2. the Terms of Service and the Order Form;
  3. the configuration you set or ask us to set in the platform, including unit data, escalation rules, retention period and team access;
  4. any further written instruction you give us, by email to info@luxoasisadvisory.com, which we accept in writing.

We may charge for a further instruction that requires material development work, at a rate agreed in advance. We will not charge for an instruction needed to make our processing lawful.

6.3 If an instruction looks unlawful

We will tell you immediately if, in our opinion, an instruction infringes applicable data protection law. We may suspend the affected processing until the instruction is withdrawn, confirmed or amended.

6.4 The one thing we may do with the data beyond your instructions

We may produce and use Aggregated and De-identified Data as defined in clause 11.3 of the Terms of Service: data from which names, phone numbers, email addresses, booking references, unit and building identifiers and your identity have been removed or irreversibly obscured, so that neither a guest, nor a member of your team, nor a unit, nor you can reasonably be identified. We may use it to improve and train our models and prompts, to benchmark and measure service quality, and for product analytics, during and after the term.

Aggregated and De-identified Data produced to that standard is not personal data. We will not attempt to re-identify it and will not permit anyone else to.

6.5 The prohibition that goes with it

We will not use identifiable guest personal data, or guest conversation content in any form from which an individual can reasonably be re-identified, to train, fine-tune, evaluate or improve any model, for benchmarking, or for product analytics.

To be plain about why: that would be processing for our own purposes, which would make us a controller of guest personal data rather than your processor. It would put us outside this Addendum, would require its own legal basis and its own transparency to guests, and would expose both of us. It is prohibited under this agreement and we do not do it.

We will only engage AI sub-processors on terms that do not permit the provider to use content submitted through the Service to train the provider's own models. If that ever ceases to be true of a provider we use, we will say so in the Sub-processor List and treat it as a change requiring notice under clause 7.

7. Confidentiality

We ensure that every person authorised to process personal data under this Addendum:

  • is bound by a written obligation of confidentiality, or is under an appropriate statutory obligation of confidentiality;
  • is given access only to the personal data they need for their role, under individual credentials;
  • has been informed of the confidential nature of the data and of their obligations;
  • remains bound after their engagement with us ends.

Access to guest conversation content by our personnel is limited to support, security and fault diagnosis, and to what you ask us to look at.

8. Security

8.1 The obligation

We implement and maintain appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of processing, as well as the risk to individuals.

8.2 What those measures are

Annex 2 sets out the measures we actually have in place, and identifies those that are planned but not yet implemented. We do not describe a measure we do not have.

We hold no security certification, and we do not claim ISO 27001, SOC 2, or any equivalent. If we obtain one, we will say so in Annex 2 and name the certifying body and the scope.

8.3 Sub-processing

We may engage sub-processors. Each one:

  • is engaged under a written contract imposing data protection obligations that are, in substance, no less protective than those in this Addendum;
  • is used only for the purpose described in the Sub-processor List;
  • remains our responsibility, and we remain fully liable to you for their performance of their data protection obligations.

Where the GDPR applies and a sub-processor is outside the EEA or the UK without an adequacy decision, we put in place the standard contractual clauses adopted by the European Commission in the module appropriate to the relationship, and, where we are the data exporter for onward transfer, the UK International Data Transfer Addendum, together with the transfer risk assessment those instruments require. Where a recipient is certified under the EU-US Data Privacy Framework and the transfer falls within its scope, we may rely on that instead. We do not assert that any particular provider is so certified; the position for each is stated in the Sub-processor List.

Where the UAE PDPL applies to the transfer out of the UAE, we rely on written contractual commitments with each provider carrying obligations equivalent in substance to those we owe you. The PDPL's own transfer instruments depend on executive regulations that we do not treat as settled as at the effective date of this Addendum. We will re-paper on those instruments when they are available in usable form, and we will notify you when we do. This is a known open point, not an oversight.

8.4 Notice of change to sub-processors

The current Sub-processor List is at https://www.oasisguestlab.ai/legal/sub-processors/. It is a separate document with its own version number so that it can change without reopening this Addendum.

We give you at least 30 days' written notice by email before adding or replacing a sub-processor. You may object within those 30 days on reasonable data protection grounds, in writing, saying what the grounds are. We will work with you to find a solution, which may include not using that sub-processor for your data or offering a different configuration.

If we cannot resolve your objection within 30 days of receiving it, you may terminate the affected part of the Service, or the whole agreement, on written notice and without penalty, and we will refund fees you have paid for any period after termination. This is an express exception to the no-refund rule in clause 6 of the Terms of Service.

Where a change is urgent and necessary to keep the Service secure or lawful, we may make it with shorter notice, and we will tell you as soon as we can and explain why. Your objection right is unaffected.

9. Assistance with data subject rights

9.1 We do not answer for you

If a guest, a member of your team, or anyone else contacts us directly to exercise a right over data we process for you, we will not respond to the substance. We will forward the request to your nominated contact without undue delay, and in any event within three business days, and tell the individual that we have done so and that you are the controller.

9.2 What we do for you

Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, so far as this is possible, in fulfilling your obligation to respond to requests for access, rectification, erasure, restriction, portability and objection, and to any objection to automated decision-making.

In practice this means we will, on your written request and within seven business days unless the request is exceptionally large:

  • search for and provide a copy of the personal data we hold about a named individual;
  • correct data at your instruction;
  • delete data at your instruction;
  • restrict processing of a conversation or a data subject at your instruction;
  • export a conversation or a set of conversations in a structured, commonly used, machine-readable format;
  • confirm in writing what we have done.

We will not charge for reasonable assistance of this kind. If the volume of requests becomes disproportionate to your subscription, we will agree a fair charge with you in advance.

9.3 Automated decision-making

The Service generates message replies automatically. It does not make decisions producing legal effects or similarly significant effects concerning individuals, and it must not be configured to. It does not price, screen, approve, refuse, rank or profile guests. If you want to use output from the Service as an input to a decision of that kind, that is your processing, under your own legal basis, and you must tell us first.

10. Assistance with your other obligations

Taking into account the nature of the processing and the information available to us, we assist you with:

  • security of processing;
  • notification of personal data breaches to a supervisory authority and communication to data subjects;
  • data protection impact assessments;
  • prior consultation with a supervisory authority.

We will provide the information reasonably necessary for those purposes on written request. We are a small company and we will say so if a request is beyond what we can reasonably do; we will not simply not answer.

11. Personal data breaches

We notify you of a personal data breach affecting personal data processed under this Addendum without undue delay after becoming aware of it, and in any event within 72 hours of becoming aware.

The notification goes to your nominated contact by email and by WhatsApp, and includes, so far as we know it at the time:

  1. the nature of the breach, including the categories and approximate number of data subjects and records affected;
  2. the likely consequences;
  3. the measures we have taken or propose to take, including measures to mitigate adverse effects;
  4. a point of contact at our end.

Where we cannot provide all of it at once, we provide it in phases without undue further delay. We record every breach, its effects and the remedial action taken, and we make that record available to you.

You decide whether to notify a supervisory authority or the affected individuals. We will not notify a supervisory authority or a data subject about a breach affecting your data unless you ask us to or the law requires us to, and if the law requires us to we will tell you first where we lawfully can.

We will not delay notifying you while we investigate. An incomplete notification within the deadline is better than a complete one after it.

12. Deletion and return on exit

  1. On termination, and at your choice, we delete or return all personal data processed under this Addendum.
  2. Export. You may request an export at any time during the term and for 30 days after termination. We provide it within 14 days of the request, in a structured, commonly used, machine-readable format, at no charge for the first export following termination.
  3. Deletion. We delete all personal data processed under this Addendum within 30 days of the effective date of termination, or within 30 days of delivering a requested export, whichever is later.
  4. Retention position during the term. Conversation data is retained for twelve months from the date of the last message in that conversation and then deleted, unless you instruct a shorter period. You may instruct a shorter period at any time. This is the single retention period for the Service.
  5. What survives. We retain only what applicable law requires us to retain, principally invoices and accounting records under UAE tax and accounting law, for the period required and for that purpose only. Those records are not guest conversation data.
  6. Backups. Copies held in routine system backups are isolated from live processing on the deletion date and are deleted when those backups are overwritten in the ordinary cycle. That cycle is stated in Annex 2.
  7. Confirmation. We confirm deletion in writing on request.

13. Audit

  1. We make available to you the information necessary to demonstrate compliance with this Addendum, and we allow for and contribute to audits, including inspections, conducted by you or by an auditor you mandate.
  2. In the ordinary case, we satisfy this by answering a written information request, including a security questionnaire, once in any twelve-month period, within 30 days.
  3. An on-site or systems audit may be conducted where it is required by a supervisory authority, where you are required to conduct one by law, or following a personal data breach affecting your data. It is subject to: 30 days' written notice; a scope agreed in advance; no more than once in any twelve-month period unless a breach or a regulator requires more; conduct during business hours in a way that does not disrupt the Service or other clients; the auditor being bound by confidentiality and not being our competitor; and no access to another client's data, to our source code, or to information whose disclosure would breach an obligation we owe someone else.
  4. Cost. You bear the cost of an audit under paragraph 3, and our reasonable costs of supporting it, unless the audit finds a material breach of this Addendum by us, in which case we bear our own costs and reimburse yours.
  5. We hold no third-party audit report or certification to offer in place of an audit, and we say so rather than implying otherwise.

14. Liability

Liability under this Addendum is subject to the limitations and exclusions in clause 16 of the Terms of Service, except to the extent that a limitation is not permitted by applicable data protection law.

Nothing in this Addendum limits a data subject's rights, or a supervisory authority's powers, against either of us.

15. Order of precedence and general

This Addendum prevails over the Terms of Service on any matter of personal data. Where the standard contractual clauses are incorporated under clause 8.3, they prevail over this Addendum to the extent of any conflict.

Language. These documents are written in English. English is the governing language. If they are translated, the English version prevails.

Governing law and jurisdiction. As stated in clause 17 of the Terms of Service, including the placeholder for the forum, which must be settled before publication.

Changes. This Addendum carries a version number and an effective date and is archived at a permanent URL. A material change is notified at least 30 days in advance by email and requires acceptance. The Sub-processor List changes under clause 8.4 and does not require a new version of this Addendum.


ANNEX 1: PROCESSING DETAILS

ItemDetail
ControllerThe client named on the Order Form
ProcessorLux Oasis Advisory & Services LLC
Subject matterProvision of the Oasis Guest Lab AI guest communication service
DurationFrom the Service Start Date until deletion or return under clause 12
Nature and purposeAs set out in clause 4
Categories of data subjectAs set out in clause 5.1
Categories of personal dataAs set out in clause 5.2
Special categoriesNot solicited; may appear incidentally in free text, see clause 5.3
Frequency of processingContinuous, for the duration of the agreement
RetentionTwelve months from the last message in a conversation; deletion within 30 days of termination; see clause 12
Sub-processorsAs listed at https://www.oasisguestlab.ai/legal/sub-processors/

ANNEX 2: TECHNICAL AND ORGANISATIONAL MEASURES

This Annex states measures actually in place as at the effective date. Measures marked [TO CONFIRM] are recorded as questions for the owner and must be either confirmed or removed before publication. Nothing in this Annex may be published as fact until it has been verified against the live environment.

In place

AreaMeasure
Encryption in transitAll traffic between guests, WhatsApp, our platform and the operator dashboard is protected with TLS
HostingGuest and unit data is held on servers operated by Hetzner in EU data centres. Physical and environmental security at those data centres is provided by Hetzner under its own controls
DashboardChatwoot is open-source software that we self-host on our own EU infrastructure. Guest conversation content is not sent to a third-party dashboard vendor
Access controlAccess is restricted to personnel who need it for their role, under individual named credentials. Shared accounts are not used for administrative access
ConfidentialityEveryone with access is under a written confidentiality obligation that survives the end of their engagement
SegregationEach client's units, knowledge layers and conversations are logically separated within the platform
Sub-processor controlEvery sub-processor is engaged under a written contract with data protection obligations, and is listed publicly with its role and processing location
Message attributionEvery message is labelled as AI generated or human sent, giving an audit trail of who said what
DeletionDocumented deletion process on termination and on instruction, with written confirmation on request

To confirm before publication

AreaQuestion
Encryption at rest[TO CONFIRM] Whether the database and file storage volumes are encrypted at rest, and by what mechanism
Backups[TO CONFIRM] Backup frequency, storage location, encryption, and the rotation period after which backups are overwritten. Clause 12.6 and clause 13 of the Terms of Service both refer to this figure
Multi-factor authentication[TO CONFIRM] Whether MFA is enforced on administrative access to the platform, to Hetzner, to 360dialog, to the Meta Business Manager and to the OpenAI account
Logging and monitoring[TO CONFIRM] What access and administrative actions are logged, how long logs are kept, and whether anything alerts
Business continuity[TO CONFIRM] Restore testing, recovery objectives, and what happens if the primary host is lost
Personnel[TO CONFIRM] Whether background checks and security training are carried out, and for whom
Vulnerability management[TO CONFIRM] Patching cadence, dependency updates, and whether any penetration test has been carried out
Incident response[TO CONFIRM] Whether a written incident response procedure exists, given the 72-hour commitment in clause 11
Sub-processor model training[TO CONFIRM] Written confirmation from the AI provider that content submitted through the API is not used to train its models, and confirmation of the processing region

This document has been prepared for review and requires sign-off by a qualified UAE lawyer before publication. It is not legal advice.

Copyright 2026 Oasis Guest Lab. All rights reserved.

Privacy Policy Terms of Service

Oasis Guest Lab is a product of Lux Oasis Advisory & Services LLC