This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Customer", "you") and Pixhelm LTD ("Lobbix", "we", "us"), and governs our processing of personal data on your behalf when you use Lobbix. It supplements our Terms of Service and Privacy Policy. Where there is a conflict on data protection matters, this DPA prevails.
Roles and definitions
For personal data processed through your use of Lobbix, you act as the controller (or processor on behalf of your own customers) and Lobbix acts as the processor (or sub-processor). Terms such as "personal data", "processing", "controller", "processor", and "data subject" have the meanings given in applicable data protection law, including the GDPR.
Scope and subject matter
- Subject matter: our provision of the Lobbix platform to you.
- Duration: the term of your agreement with us, plus any wind-down period.
- Nature and purpose: hosting your property's reservations, guest records, folios and invoices, and syncing availability with the booking channels you connect.
- Types of data: account and contact data, guest identity and stay data (names, contact details, reservation history), and billing records.
- Data subjects: your personnel and your guests.
Processing instructions
We will process personal data only on your documented instructions — including this DPA, your configuration of the service, and your support requests — unless required to do otherwise by law, in which case we will inform you where legally permitted. We will notify you if, in our opinion, an instruction infringes applicable data protection law.
Confidentiality
We ensure that personnel authorised to process personal data are bound by appropriate obligations of confidentiality and are granted access only on a need-to-know basis.
Security measures
We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, or damage. These include encryption in transit, access controls, environment isolation, malware scanning of uploads, logging, and regular backups. A current description of our security measures is available at transport encryption (HTTPS only, HSTS), per-user accounts with optional two-factor authentication, password hashing, workspace-level tenant isolation enforced on every request, an append-only audit log, anti-virus scanning of uploaded files before they are stored, and access to production systems limited to the individuals who need it. We do not assert any specific certification in this draft; add any that apply once verified.
Sub-processors
You authorise us to engage sub-processors to help provide the service — for example, cloud hosting, payment processing, and email delivery. We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance. Our current list is available at Hetzner Online GmbH (application hosting, database and object storage; Nuremberg, Germany); Cloudflare, Inc. (DNS, and DNS/TLS automation for customer custom domains; global edge network); Paddle.com Market Ltd (merchant of record — payment processing, invoicing and tax; United Kingdom); Purelymail (transactional email delivery; United States); Google LLC (optional "Sign in with Google" authentication, only for accounts that choose it; United States). We will give you advance notice of any intended addition or replacement of a sub-processor and a reasonable opportunity to object.
Data-subject requests
Taking into account the nature of the processing, we will assist you with appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights. Where a data subject contacts us directly about data we process on your behalf, we will refer them to you unless legally required to respond.
Personal data breach notification
We will notify you without undue delay after becoming aware of a personal data breach affecting personal data we process for you, and we will provide information reasonably available to us to help you meet your own notification obligations.
Return and deletion of data
On termination or expiry of your agreement, we will, at your choice, delete or return the personal data we process on your behalf and delete existing copies, except where retention is required by law. Standard account data is handled as described in the Privacy Policy.
Audits
We will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable confidentiality, scheduling, and scope limitations set out in this section — no more than one audit in any 12-month period, on at least 30 days’ written notice, during normal business hours, at your expense, and satisfied in the first instance by our most recent security documentation where it reasonably answers the request.
International transfers
Where we transfer personal data to a country without an adequacy decision, we will rely on an appropriate transfer mechanism such as the Standard Contractual Clauses, which are incorporated by reference where applicable. Details of the mechanism we rely on are set out in the UK International Data Transfer Addendum (IDTA) together with appropriate technical and organisational safeguards.
Governing law and contact
This DPA is governed by the laws of the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction over any dispute. For data protection matters under this DPA, contact us at hello@lobbix.org. Our details: Pixhelm LTD, Suite 11114, 5 Brayford Square, London, United Kingdom, E1 0SG.
Questions? Contact hello@lobbix.org.
Last updated: August 13, 2026