Last updated:
July 21, 2026

Terms and Conditions

OWNERSHIP

This website/service is owned and operated by Civitfun Tourism, S.L.U. (hereinafter “CIVITFUN”), with registered office at Complejo Mirall Balear, Camí De Son Fangos 100, 07007, Tower A, 5th Floor, Palma de Mallorca, Spain. Registered with the Commercial Registry of Palma de Mallorca.
NIF: B-76653088
Email: info@civitfun.com

ACCEPTANCE

The CLIENT is defined, for the purposes of these Terms and Conditions, as the hotel, hotel chain and/or apartments that make use of the website and have access to CIVITFUN’s services (hereinafter, the “Service”). By using the website, the CLIENT agrees to comply with these Terms and Conditions, as well as the Terms of Use and Privacy and the Cookie Policy that are always available and accessible at www.civitfun.com.

The CLIENT will use the Service for its own consumption, subject to the conditions mentioned in the previous paragraph. In no event will the CLIENT use the Service in a manner other than agreed, nor for illicit purposes or for other purposes not aligned with this document or in any of the conditions mentioned in the previous paragraph.

CLAUSES

1. PURPOSE

The Agreement sets forth the Terms and Conditions for the provision of the below services to be provided by CIVITFUN to the CLIENT, as indicated in the annexes specified below:

Annex A

Online Check-in

Annex B

Online Check-in Aggregator

Annex C

Paperless

Annex D

Group Check-in

Annex E

Payment Protection

Annex F

Room Assignment Functionality

Annex G

Door Opening

Annex H

Upselling

Annex I

Cross-selling

Annex J

Guestlink

Annex K

Guest Registration

Annex L

Online Check-out

Annex M

OCR Document Scanner

Annex N

Hotel Confirmation Number

Annex O

Invoice Automation

Annex P

VeriFactu Compliance Integration

Annex Q

Automated Booking Loading

(each individually a “Service” and jointly the “Services”)

2. SERVICE DESCRIPTION

Through the use of the CIVITFUN website www.civitfun.com (hereinafter the “Website”) and access to the Services contracted with CIVITFUN, CIVITFUN hereby grants the CLIENT a limited, revocable and non-exclusive license to use the CIVITFUN software (the “License” and the “Software”). The License enables the CLIENT to offer its guests various services options via a web interface integrated with the CLIENT’s Property Management System (hereinafter “PMS”). The Services may be accessed by the Hotel guests through the CLIENT’s website via a designated URL. The software also facilitates the exchange of data with third parties (including booking managers), allowing for process automation and enhanced collaboration.

By using the Services, the CLIENT agrees to comply with the Terms of Use and Privacy and the Cookie Policy that are always available and accessible at the Website www.civitfun.com.

The CLIENT hereby warrants that it will use the Services only for its own consumption, subject to the conditions foreseen under the Agreement. The CLIENT further warrant that it will not use the Services in a manner other than agreed, nor for illicit purposes or for other purposes which are not aligned with this Agreement or in any of the conditions mentioned in the previous paragraph.

3. CLIENT’S OBLIGATIONS

3.1 Customer Service Platform:

  • Within seventy-two (72) hours of signing this Agreement, CIVITFUN shall register the CLIENT on its Customer Service Platform, accessible via the CIVITFUN dashboard. The CLIENT hereby agrees to use this platform for all post-sale communications to ensure proper delivery of the Services. CIVITFUN and HBX Group shall not be held liable for any delays or issues resulting from communications made through other channels.

3.2 Custom Developments:

  • The CLIENT hereby acknowledges that CIVITFUN is a standardized software solution and does not offer any custom developments for individual clients. Any requests for improvements of the Software must be submitted via the “Wish-list” section of the customer service platform. If deemed feasible, CIVITFUN may include such requests in its general development roadmap, to be scheduled at its discretion based on internal priorities and workload.

  • If the CLIENT requires urgent or customized developments, CIVITFUN’s post-sales team will provide a quote based on the estimated development hours.

  • HTML template developments for check-in records are not included in the standard CIVITFUN software package. If requested, CIVITFUN’s post-sales team will also provide a quote for these developments.

Any enhancement, improvement, modification, or new feature of the Software (the "Software Modifications") that may result from or be inspired by any request, suggestion, or feedback provided by the CLIENT shall not in any way confer any ownership, intellectual property rights, or other entitlements over Software Modifications to the CLIENT. All intellectual property rights, including but not limited to copyrights, know-how, and any related proprietary rights arising from the Software Modifications, shall vest exclusively in CIVITFUN and may be used by CIVITFUN’s at its sole discretion.

3.3 Onboarding process:

  • The onboarding process shall begin upon execution of this Agreement and continue in force until the agreed date between the Parties, depending on the Services contracted.

  • The CLIENT agrees to maintain clear, proactive, and timely communication with CIVITFUN throughout the onboarding and implementation process to meet the agreed deadlines.

  • The CLIENT shall provide all information requested by CIVITFUN’s onboarding team within the specified timeframes. If the CLIENT fails to provide the necessary information, complete configuration steps, or respond to onboarding notifications within the agreed deadlines, the onboarding process will be automatically postponed by one (1) month from the original start date, without any liability to CIVITFUN.

  • Delays caused by third parties (e.g., PMS providers, gateways, or other external vendors) are outside CIVITFUN’s control, and CIVITFUN shall not be held responsible for any such delays.

  • Go-Live: If the CLIENT does not complete the required customization actions within the agreed timeframe, CIVITFUN may proceed with the go-live using the available information and standard services settings.

  • The license validity and renewal date shall begin on the execution date of this Agreement, regardless of when the Services is implemented or used by the CLIENT.

4. After Sales Support and Warranty Plan

Incidents may be reported at any time via the digital support ticketing system available in the CIVITFUN back office. CIVITFUN will address incidents during Spanish working hours (GMT+1), Monday to Friday, from 8:00 a.m. to 8:00 p.m. If an incident is reported outside these hours, the response time will begin at the start of the next working day.

CIVITFUN will assist the CLIENT in identifying and resolving issues once contacted through the designated support channels.

Service response times shall not apply in case of (i) Force majeure events (as described below), planned outages, virus infections or server attacks, or (ii)Periods during which security updates or virus definitions are being applied.

In such cases, CIVITFUN will (i) to the extent possible, cooperate with the CLIENT to identify and resolve the issue, (ii) agree with the CLIENT on any planned Service suspension and (iii) notify the CLIENT promptly upon becoming aware of any system or network failure.

CIVITFUN will perform maintenance on the Services. Except in cases requiring immediate intervention, CIVITFUN shall provide at least twenty-four (24) hours’ notice prior to planned maintenance. Planned maintenance shall not exceed:

  • Eight (8) hours per month.

  • Eight (8) consecutive hours per maintenance event.

5. Term and termination

5.1. Term

This Agreement shall have the term stated in the commercial proposal from the acceptance of these Terms and Conditions, automatically renewable for successive annual periods, unless expressly stated otherwise.

Either party may notify the other Party of its intention not to extend the Agreement:

  • CLIENT: By serving prior written notice to CIVITFUN of at least thirty (30) days prior to the expiration of the Initial Term or any of its renewals.

  • CIVITFUN: By serving prior written notice to the CLIENT of at least ninety (90) days prior to the expiration of the Initial Term or any of its renewals.

In the event that the CLIENT wishes to terminate the Agreement under the conditions indicated in the previous paragraph, it may not claim from CIVITFUN or HBX Group any amount of the fully paid annual fee.

Once the Agreement is terminated for any reason, its purpose will be extinguished, without prejudice to the legal actions that may correspond to each of the Parties in the event of breach.

5.2.- Causes for Termination

The Agreement may be terminated for the following reasons:

  1. By either Party unilaterally and with immediate effect in the event that the other Party materially breaches any of the obligations of this Agreement, which is not cured within fifteen (15) days following notification of such material breach by the non-breaching Party.

Failure to comply may result in compensation, by the breaching Party, for damages caused.

  1. By CIVITFUN, at any time for any other reason, via written notice to the CLIENT with thirty (30) calendar days in advance.

6. Price and Taxes

Service prices are listed in euros (€) and are subject to applicable taxes at the time of purchase.

The VAT on the provision of the agreed Service, with taxes excluded, will be applied according to current Spanish legislation. VAT may be charged on the invoice, or it may be the CLIENT’s obligation to apply the passive taxpayer inversion clause in the recipient´s location.

While CIVITFUN makes every effort to ensure pricing accuracy on its Website, if a pricing error is identified in a Service ordered by the CLIENT, CIVITFUN will promptly inform the CLIENT and offer the option to confirm the order at the correct price or cancel it. If CIVITFUN is unable to reach the CLIENT, the order will be cancelled and any payments made will be fully refunded. CIVITFUN is not obliged to provide the Services if the pricing error is obvious and could reasonably have been recognized by the CLIENT as incorrect, even if the order has been confirmed.

Prices may change over time, but such changes will not affect confirmed orders for which a shipping confirmation has already been issued.

The CLIENT hereby undertakes to use the Services diligently and in good faith, to pay the agreed price, and to ensure the accuracy of the data provided for the transaction. CIVITFUN and HBX Group shall not be held liable for any issues arising from incorrect or incomplete data provided by the CLIENT.

For any clarification, incident or complaint, the CLIENT may contact CIVITFUN at: info@civitfun.com

7. Payment

7.1.- Payment Terms

The CLIENT shall pay for the Services in advance, within thirty (30) days following the invoice issuance by CIVITFUN. Accepted payment methods include:

  • Credit and debit cards (from back office)

  • SEPA direct debit

  • Wire transfer to one of the Civitfun accounts

Invoices must be paid in full. No deductions or partial payments are permitted. Any disputes regarding an invoice must be communicated to CIVITFUN within twenty (20) days as of issue thereof. Disputes raised after this period will not be considered.

The CLIENT authorises CIVITFUN to automatically charge the payments to the bank account or card provided.

If the Parties agree to deferred payment terms, CIVITFUN may assign its collection rights to third parties through factoring or equivalent financial arrangements.

7.2.- Consequences of Late Payments

  • In case of late payment, CIVITFUN may charge interest on the overdue amount at the rate applied by the European Central Bank to its last main refinancing operation plus eight (8) percentage points. CIVITFUN expressly reserves the right to pursue additional claims.

  • If payment is delayed by more than fifteen (15) days after the due date, CIVITFUN may restrict, suspend, or cancel the provision of Services until full payment is received.

  • CIVITFUN may report unpaid debts to the relevant credit or debtor registries, in accordance with applicable law.

8. Intellectual and Industrial Property

8.1. Content

The Parties agree that CIVITFUN shall be the sole and legitimate owner of any intellectual, industrial or similar property rights in each and every one of the works developed or created under this Agreement, including, but not limited to, the software, usage and operation manuals, any inventions, know-how, designs, documentation, secrets and/or source code (hereinafter, the “Materials”). In this regard, CIVITFUN grants the CLIENT a non-exclusive, non-assignable, revocable, non-transferable, royalty-free license to use the Services and software provided by CIVITFUN during the term of this Agreement. Any right other than that of mere access and use of the Services and Materials is expressly excluded from the terms of this license, particularly excluding the rights of transformation, public communication, distribution, reproduction, modification or performance of derivative works of the Services or Materials provided under this Agreement. Notwithstanding the foregoing, CIVITFUN may modify, lease, license, sell, transfer, distribute, publicly communicate, particularly in the manner it wishes, or reproduce the software and Materials at its sole discretion, without any requirement other than to reasonably ensure the maintenance of the rights and obligations assumed under this Agreement in favour of the CLIENT. The CLIENT hereby grants CIVITFUN a non-exclusive right to use the name, photographs, images, designs, text, logos, trademarks and other distinctive signs that CLIENT may have in its name for the sole purpose of ensuring the proper performance of the Services set forth herein. All design elements may only be used with the brand that the CLIENT has contracted, unless otherwise expressly agreed to in writing. Such uses may not extend to other brands, company names or any other items naming third parties. The CLIENT shall be liable for any defamatory or immoral information, for the veracity and accuracy of the content provided to CIVITFUN by any means and, therefore, guarantees that said content does not infringe any third-party intellectual and/or industrial property rights. The CLIENT at all times, during and after the termination of this Agreement, shall defend and hold harmless CIVITFUN from any claim or suit that could be directed against it as a result of any alleged infringement of intellectual or industrial property rights resulting from the information it may have provided to CIVITFUN for the execution of this agreement.

CIVITFUN trademarks and logos cannot be reproduced by the CLIENT without the express written permission of CIVITFUN. If that reproduction is authorised, the CLIENT must only use them under the parameters set by CIVITFUN and ensure that the copyright and trademark text is displayed. The CLIENT accepts the use of its logo in CIVITFUN’s presentations, case analyses and customer portfolios. CIVITFUN undertakes to comply with the specific obligations relating to image, resolution and use of copyright and trademark.

9. Data Protection and Security

Both Parties undertake to comply with the applicable regulations on personal data protection, in particular Regulation (EU) 2016/679 (General Data Protection Regulation or “GDPR”) and Organic Law 3/2018, on the Protection of Personal Data and Guarantee of Digital Rights.

The CLIENT will be responsible for obtaining the express and informed consent of the data subjects (guests, users, etc.) for the processing of their personal data through the services offered by CIVITFUN, if necessary. In any case, the CLIENT guarantees that it has the sufficient legal basis for the collection and processing of such data.

CIVITFUN will act as data processor in those cases in which it accesses or processes personal data on behalf of the CLIENT, limiting its use to what is strictly necessary for the provision of the contracted services. In these cases, both parties will sign the corresponding Data Processing Agreement (DPA) including as an Annex R to these T&Cs, in accordance with Article 28 of the GDPR, and with the applicable regulations.

The CLIENT expressly authorises CIVITFUN to share strictly necessary personal data with third-party subcontracted technology providers or collaborators, provided that it is essential for the correct execution of the Services and provided that the application of appropriate technical and organisational measures is guaranteed.

Both Parties undertake to adopt the necessary technical and organisational measures to ensure the security, integrity and confidentiality of personal data, as well as to report any data security breach within the deadlines and manners established by current legislation.

For further information on how we process personal data, please refer to our privacy policy, our DPA or sending an email to dataprotection@civitfun.com

As noted above, the entire purchasing procedure, as well as the transmission of personal data and payment systems, is performed on a secure and encrypted page via TLS protocol.

CIVITFUN ensures the security of the Services, in accordance with this technological knowledge. However, the complete future security of the Services cannot be guaranteed. In any case, CIVITFUN commits to remedying and implementing appropriate corrective measures to correct a potential security breach as soon as possible.

The CLIENT undertakes to notify CIVITFUN, immediately and through the email info@civitfun.com, of any situation that could lead to the identity theft of one of its users or any other possible security incident.

10. Liability and Disclaimer of Warranties

THE SERVICES AND SOFTWARE ARE PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT ANY WARRANTIES OF ANY KIND, WHETHER EXPRESS OR IMPLIED. All warranties are disclaimed to the fullest extent permissible by applicable law, including but not limited to implied warranties of merchantability, fitness for a particular purpose, non-infringement, and any warranties arising out of course of dealing or usage of trade. Neither the Services nor the Software is warranted to be uninterrupted, error-free, secure, or free of harmful components. The CLIENT understands that the Services and Software may contain errors and omissions that will be resolved as soon as they are detected or notified. In any case, CIVITFUN will seek to provide sufficient notice of any interruptions that occur in the operation of the Services or Software.

To the maximum extent permitted by applicable law, there is no liability for any direct, indirect, incidental, special, consequential, or punitive damages arising out of or in connection with the Services or Software, this Agreement, or the use or inability to use the Services or Software, whether based on contract, tort (including negligence), strict liability, loss of profit, lack of accuracy, validity or authenticity of the information or any other legal theory, even if advised of the possibility of such damages. In particular, CIVITFUN hereby excludes any liability for damages of any nature that may be due to the impersonation of the identity of a third party, made by a user in any kind of communication made through CIVITFUN. The CLIENT is solely responsible for use of the Services or Software and for any content uploaded or stored using the Services or Software. CIVITFUN has no responsibility for any loss or corruption of data or for any damages arising from the CLIENT’s use of the Services or Software.

Subject to the above, CIVITFUN total liability for any claim arising out of or in connection with the Services or Software or this Agreement shall not exceed the amount paid by the CLIENT for the Services in the twelve (12) months preceding the event giving rise to the claim.

The Parties hereby acknowledge and agree that the exclusions of, and limitations on, liability set out in this Agreement are fair and reasonable.

11. Force Majeure

Neither Party shall be liable for breach of its duties and obligations under this Agreement if the execution of such obligations is affected, at origin and/or destination, delayed, prevented, hindered or frustrated by a “Force Majeure Event”.

For the purposes of this Agreement, a Force Majeure Event is understood as acts, unforeseeable events or cases that are unavoidable, unintentional and/or unforeseen beyond the will and actions of the Parties, including, but not limited to: acts of nature (such as earthquakes, tsunami, flooding, storms, cyclones, hurricanes, hurricane winds or tornadoes) or adverse and extraordinary weather conditions that are beyond the reasonable control of the Parties and substantially affect their operability and their ability to comply with their obligations with respect to this Agreement; civil conflicts like war, acts of war (whether or not declared), guerrillas, invasion, armed conflict or acts of a foreign enemy, military operations, acts of terrorism, disturbances, public demonstrations or other civil unrest of any kind, blockages, embargoes, revolution, mutiny, insurrection, civil unrest, civil disobedience, acts or campaigns of terrorism or sabotage; strikes; interventions of national or municipal authorities or authorities of any other type; declaration of a national emergency; forces of nature or any other natural disaster, fire, wildfire, explosion or chemical contamination; health-related crises, such as viruses, disease, fatal disease, pandemic or epidemics, outbreak of infectious diseases or pestilences that are beyond the reasonable control of the Parties and substantially affect their operability or their ability to comply with their obligations with respect to this Agreement; an event that arises or occurs by contribution of any cause, condition or other reason that adversely affects international or domestic travel, including but not limited to the city or country where the hotel is located or the country of origin of guests or others; any law, proclamation, regulation, statement, ordinance, order or similar issued by any public health or government authority, on an international, state, municipal or regional level; emergency on an international, national, state, municipal/regional or local level (whether de facto or de jure); or other acts, orders or actions from a government, court or regulatory agency or authority, including issuing recommendations or restricting movement of persons to avoid travel to the country where the hotels are located, to a particular area of the country where the hotels are located, to a neighbouring country, or a recommendation or restriction for nationals or residents of a certain country or region not to leave it; or if any government or public health authority imposes restrictive measures on travel or the concentration of persons, or otherwise restricts the normal functioning of the activity of the state, region or locality where the hotel is located, provided that said affected Party notifies the other Party in writing of the Force Majeure Event. If the Parties cannot agree whether an event should be interpreted as a Force Majeure Event, CIVITFUN shall have the maximum discretion to determine such event.

If one of these events occurs, the affected party will be exempted from executing its obligation or liability under this Agreement without any penalty, until said event has ceased, in accordance with the following terms:

  • In the event of a Force Majeure Event that results in the breach of obligations, the affected party invoking the Force Majeure Event will make all commercially reasonable efforts to eliminate or mitigate the consequent delay or breach so as not to be considered a breach of the Agreement.

  • The affected Party shall notify the other Party of the Force Majeure Event as soon as practicable, but - in any case - no later than forty-eight (48) hours from the date the affected Party becomes aware of said Force Majeure Event or twenty-four (24) hours after any means of providing notices between the Parties is resumed.

Such notice shall contain: (a) a preliminary assessment of the affected obligations; and (b) a preliminary estimate of the period of time in which the affected Party will be unable to comply with such obligations, as well as other relevant matters, a period that may not be greater than thirty (30) calendar days and successive days, counted from the occurrence of the Force Majeure Event

  • If the period of breach is extended for a period greater than thirty (30) calendar days, either Party may: (i) notify the other of its intention to terminate this Agreement without incurring any liability and without the need for judicial intervention; or (ii) suspend the effects of the agreement until compliance with it can be resumed, subject to agreement between the Parties of the term of the suspension of the agreement. In the absence of written agreement regarding the suspension period, this agreement shall be terminated without the need for any judicial intervention.

  • The affected Party must initiate compliance with its obligations after the agreed term has elapsed. Otherwise, the breach will be considered a contractual breach, causing the corresponding Party to incur the applicable legal consequences.

  • No failure, delay or interruption by CIVITFUN in exercising any right, power or privilege under this clause shall be deemed a waiver of similar or different provisions or conditions at that time or any time before or after; such failure, delay or interruption shall not prevent CIVITFUN from invoking this clause on a similar or different condition.

12. Confidentiality

At any time during the term of this Agreement, either Party may acquire confidential or proprietary information of the other Party’s business. For the purposes of this clause, “Confidential Information” shall be considered all information that is non-public, confidential or proprietary in nature, disclosed during or after the term of the agreement by the Party providing Confidential Information (the “Disclosing Party”) to the other party (the “Receiving Party”) or its affiliates, or any of its affiliates or their respective employees, directors, partners, shareholders, agents, lawyers, accountants or advisers (collectively, "Representatives"). This is whether disclosed orally or disclosed or accessed in writing, electronic or other form, whether or not such information is marked, designated or in any form identified as “Confidential.” Confidential Information may be contained in documents, drawings, schemes, digital ? ?or any other format, and may be sent orally, in writing, electronically or by visual observation and by any other means. Confidential Information includes, but is not limited to:

  • All information related to past, present and future matters, business plans and methods, of the Disclosing Party and its affiliates; its guests, customers, suppliers and other third parties, including but not limited to finances, rates, information on natural persons, complete or partial, supplier information, products, services, organisational structure and internal practices; images captured by cameras, scanners or through other means, including but not limited to computer applications and programs, forecasts, sales, hiring, rates, room categories and specifications and other financial results, records and budgets, and business strategies and other sales strategies;

  • Ideas, methods, trade secrets, know-how and other confidential intellectual property of the Disclosing Party and its affiliates.

  • All designs, specifications, documentation, components, schematics, drawings, protocols, processes and other visual representations, in whole or in part, of any of the foregoing.

  • All third-party Confidential Information contained in or incorporated into any information provided by the Disclosing Party to the Receiving Party or its Representatives.

  • Other information that would reasonably be considered non-public, confidential or proprietary, due to the nature of the Disclosing Party’s information and business.

  • All Work Product and Intellectual Property Rights.

  • All notes, analyses, compilations, reports, forecasts, studies, data, statistics, summaries, interpretations and other materials (the “Notes”) prepared by or for the Receiving Party or its Representatives that contain, are based upon, or otherwise reflect or are derived from, in whole or in part, any of the foregoing.

  • In addition, any other information of a confidential nature sent to the Receiving Party and labelled as confidential by the Disclosing Party (or which could be reasonably deduced to be confidential by the Receiving Party) is included under the definition of Confidential Information.

  • The terms of this Agreement

12.1 Exceptions to Confidential Information

The following information shall not be considered Confidential Information:

a) information that is public knowledge at the time of its receipt by the Receiving Party;

b) information that, after receipt thereof by the Receiving Party, is published or is in the public domain for any reason not attributable to the Receiving Party or to anyone to whom the Recipient has sent the information;

c) information that has been required by law or by any governmental or regulatory authority having jurisdiction over the Receiving Party to be disclosed in order to comply with any valid judicial or administrative order.

d) information disclosed by either Party, in the event that it is a publicly listed company or has issued financial instruments on a stock market, in order to comply with the appropriate legal requirements, even if such disclosure has been made without the consent of the other Party; e) Published/Public Information or in the Public Domain: Information relating to the Issuer that is publicly known as a result of its disclosure, in the absence of any act of the Receiving Party, through communication that is national, massive and concentrated.

The Parties’ obligation of Confidentiality shall survive the Term of this Agreement.

12.2.- Confidentiality Limitations

The CLIENT authorises CIVITFUN to assign or exchange information and data necessary for the provision of the Services to the other clients, suppliers, processors or sub-processors that the CLIENT expressly designates for this purpose.

The CLIENT expressly authorises CIVITFUN to share data with third parties about its operations, provided that they are aggregated and anonymised.

In addition, the CLIENT expressly authorises CIVITFUN to share data relating to the CLIENT with any of its subsidiaries or holding companies or any subsidiary of its parent company.

13. Assignment, Modifications and SEVERABILITY

The CLIENT may not assign, transfer, subrogate, or delegate this Agreement or any of its obligations without prior written consent from CIVITFUN, requested at least thirty (30) calendar days in advance.

CIVITFUN may assign its rights and/or obligations under this Agreement, in whole or in part, to any subsidiary, affiliate, holding company, or any subsidiary thereof.

The CLIENT shall promptly notify CIVITFUN of any change in ownership.

If any provision of this Agreement is declared null, void, or unenforceable, the remaining provisions shall remain valid and binding on the Parties.

14. Claims and Actions Arising from the Agreement

This Agreement and any non-contractual obligations arising out of or in connection with it, shall be governed by the laws of Spain.

In case of judicial dispute, each Party agrees that the governing law shall be the one of the domicile of the defendant.

Each party agrees that courts of the country of domicile of the defendant of the relevant action shall have exclusive jurisdiction to determine any dispute arising out of or in connection with this Agreement (including in relation to any non-contractual obligations). Any counterclaims shall be ignored in deciding who the defendant is. Where there are separate but related actions the courts with jurisdiction shall be decided by the first of such actions to be issued. Each party irrevocably waive any right that it may have to object to an action being brought in such courts, to claim that the action has been brought in an inconvenient forum, or to claim that such courts do not have jurisdiction.

15. General Compliance with Anti-Bribery, Anti-Money Laundering, Trade Restrictions and Business Ethics Regulations

CIVITFUN takes a zero-tolerance approach to violations of international trade sanctions laws, including but not limited to anti-bribery and anti-corruption legislation and applicable restrictions on trade, cash flow and terrorist financing.

The CLIENT hereby warrants that it does so and will comply with them, and that its Associated Parties do and will comply with all requirements of supranational and international legislation and related procedures, restrictions and sanctions related to bribery, corruption, corporate crimes, international trade, cash flow and terrorist financing, to which the CLIENT and/or CIVITFUN may be subject from time to time.

The CLIENT warrants that, to the best of its knowledge, each person who owns interests (directly or indirectly) in it or its Associated Parties: (a) is not currently identified on any sanctions list; and (b) is not in any way prohibited from engaging in transactions due to trade embargoes, economic penalties or other prohibitions.

The CLIENT warrants that, to the best of its knowledge, neither it nor its Associated Parties have been convicted of, or have been or are the subject of, any investigation by any governmental, administrative or regulatory body into crimes involving, for example, trade sanctions, bribery or corruption in connection with fraud or dishonesty.

The CLIENT warrants that, in its monetary transactions with CIVITFUN, it will not use any financial or payment institution that is in any way prohibited from engaging in transactions, due to trade embargoes, economic penalties or other prohibitions.

The CLIENT will provide supporting evidence of such compliance, if reasonably required by CIVITFUN.

Any violation by the CLIENT of any section of this Clause shall be deemed a material breach of this Agreement and may result in the immediate termination of this Agreement by CIVITFUN or legal action.

The CLIENT agrees that if, at any time after the date of formation of the Agreement, it or any of its Associated Parties is subject to any Sanction, whether or not this occurs before or after the signing of this agreement, prohibiting or restricting its performance or rights under the Agreement, or the execution of the Agreement exposes it, or creates an exposure risk, to any Sanctions, including but not limited to foreign or secondary Sanctions, CIVITFUN may suspend or terminate the Agreement once such Sanctions become effective.

CIVITFUN shall not be liable in any way for damages incurred by the CLIENT or its Associated Parties arising from activities performed by CLIENT or its Associated Parties and in violation of any international trade sanctions regulations. This includes but is not limited to anti-bribery and anti-corruption laws and restrictions applicable to trade, cash flow and terrorist financing.

For the purposes of this clause:

• “Associated Parties” means any person (including a director, employee, shareholder, representative, agent, contractor, subcontractor or subsidiary) or any other third party related to a Party by virtue of the measures taken to comply with the obligations of this Agreement.

• “Sanctions” means any law, regulation, order or license relating to financial sanctions or trade embargoes, or related to restrictive measures that have been imposed, administered or applied at any time by any international authority. These could be, for example, those imposed by the United States, the European Union, the United Kingdom on countries such as the regions of Afghanistan, Crimea Region and other Ukraine Regions (Donetsk, Kherson, Luhansk, Zaporizhzhia), Cuba, Iran, North Korea, Sudan and Syria.

16. Customer Service and Contact

For any clarification, incident or complaint, the CLIENT may contact CIVITFUN via:

Email: info@civitfun.com
Mailing Address: Complejo Mirall Balear, Camí De Son Fangos 100, 07007, Tower A, 5th Floor, Palma De Mallorca, Spain.

17. Non-Return Policy

Once the Services are contracted, the CLIENT acknowledges and accepts that no returns or refunds will be issued, regardless of the level of use or satisfaction.

IN WITNESS WHEREOF, the Parties have hereby caused this Agreement to be duly executed by their respective authorized representatives as of the undersigned dates.

Annex A

Online Check-in Product

  • The CLIENT will define the operation of the online check-in process through the options offered by the CIVITFUN back-office.

  • The CLIENT may define what personal or commercial data guests must provide by choosing from the list of fields defined in the back office.

  • The CLIENT may enable the use of an “Optical Character Recognition” document scanner (hereinafter “OCR”) that collects the image of guests’ documents and extracts the data, making it easier for them to complete the form.

  • Also, the CLIENT may enable the contract signing process for the contract(s) it wants the guest to sign through a valid signature, compliant with Regulation (EU) No. 910/2014.

  • CIVITFUN will be responsible for retrieving, presenting to the guest and updating the information to and from the PMS.

  • The Basic Check-In Online product can include data integration into the PMS. In order to provide this product, it will be necessary to integrate/certify with the CLIENT’s PMS in the event that the CLIENT’s PMS does not fall into the CIVITFUN integration catalogue.

Annex B

ONLINE CHECK-IN AGGREGATOR

The Online Check-in Aggregator is a product developed by CIVITFUN in collaboration with other entities of the HBX Group, designed to centralise and simplify access of the CLIENT’s guests to their bookings brokered by the HBX Group and to the digital check-in process, regardless of the provider or platform used by each CLIENT.

This system allows any company that offers an online hotel check-in service – whether it is a third-party vendor such as CIVITFUN or a hotel chain with its own internally developed system – to integrate with HBX Group clients to facilitate access to bookings and the start of the check-in process.

Integration between CIVITFUN and the HBX Group technology environment creates a unique dynamic URL that HBX Group shares with its B2B customers. When guests access this URL for check-in, the Online Check-in Aggregator identifies whether the CLIENT has its own system or uses a third-party vendor. If it does, it automatically redirects guests to the appropriate system, ensuring the process is performed according to the standards and preferences defined by the CLIENT.

Key benefits of this Product include:

  • Unification of online check-in access, regardless of the technology used by each hotel.

  • Improving guests experience by facilitating access to the digital process, directly and without friction.

  • Alignment with the hotel’s operational preferences, ensuring that the desired system is used.

  • Optimisation of the booking and check-in ecosystem of HBX Group and its B2B customers.


Important: This Product serves as a redirection channel and does not involve the Aggregator’s direct processing of personal data. Guests’ information, where applicable, is managed only by the check-in system to which it is redirected, in accordance with its own privacy and data processing policies.

Annex C

Paperless and Push Paperless

T-Paperless or Push Paperless is the CIVITFUN solution designed to optimise the capture of data from the documents of the CLIENT’s guests at its hotels by retrieving them:

  • With push notifications sent to an Android tablet (advised option).

  • By searching for reservations via an Android tablet after inserting the data into PMS.

  • Manual insertion using the Android tablet keyboard.

  • Document capture with Optical Character Recognition (“OCR”) technology via the Android tablet’s camera.

1. Service Description

T-Paperless / Push Paperless makes it easy to capture document data using OCR technology through an Android tablet’s camera. This Service is designed to enable fast and efficient digitisation without the need for a traditional document scanner. The effectiveness of this technology depends directly on the quality of the captured image, the condition of the document, the lighting conditions of the place where the capture is taken, the use of brackets to avoid involuntary movements, the use of a recommended tablet and the use of backgrounds to improve contrast.

Below, the minimum requirements that the Android Tablet must have to install the T-Paperless / Push Paperless Product are the following:

  • 4GB of RAM memory

  • Android version 13 or higher

  • Camera resolution: 8MP or higher

Failure to meet the points listed above may influence the quantity and quality of the data captured. Thus, neither CIVITFUN nor HBX Group are responsible for such capture if the tablet does not meet the minimum requirements mentioned.

2. CLIENT Responsibilities

Implementation: The CLIENT is responsible for the implementation of the T-Paperless / Push Paperless service in its hotels, including ensuring that the necessary hardware and software are correctly configured and operational and they meet the minimum requirements mentioned in the previous section.

Training: It is the obligation of the CLIENT to provide adequate training to its reception staff and any other staff involved, ensuring that they fully understand how to effectively and safely use the Service, since the use of the document scanner involves the alteration of the receptionist’s operations.

3. Nature of the Service

CLIENT acknowledges and agrees that T-Paperless / Push Paperless is not a document scanner, but a camera-based solution on an Android tablet. The CLIENT understands the nature and limitations of the Service and undertakes to use it in accordance with the purpose for which it has been designed.

Annex D

Group check-in

The Group Check-In product is a solution developed by CIVITFUN to facilitate the digital management of group reservations and the check-in process for guests associated with such reservations.

This functionality allows the CLIENT and users authorized by the CLIENT, including travel agencies and group organizers, to manage guest information and complete certain tasks related to guest arrivals in advance. Group Check-In helps optimize front desk operations, reduce administrative workload, and improve the guest arrival experience.

For the proper provision of the Service, integration with the CLIENT's PMS may be required. In cases where the PMS is not included in CIVITFUN's integration catalog, a specific integration or certification with such system will be required.

The CLIENT shall be responsible for any access granted to authorized third-party users and for complying with all legal obligations related to the identification, registration, or communication of guest information to the competent authorities. CIVITFUN acts solely as the provider of the technology platform and assumes no responsibility in relation to such obligations.

Annex E

Payment Protection

During the online check-in process, the CLIENT may enable a service to pay for bookings or storing the credit card details. CIVITFUN sets the guest’s booking as paid or saves the card data via a token that is sent to the CLIENT’s PMS. Guests’ payment will be made via a payment gateway selected by the CLIENT. This process is secure. In order to provide this Service, in the event that the CLIENT’s payment gateway provider is not included under the CIVITFUN’s integration catalogue, it will be necessary to integrate/certify with the CLIENT’s own provider. CIVITFUN will be responsible for retrieving, presenting to the guest and updating the information to and from the PMS.

Annex F

Room Assignment Functionality

The CLIENT may enable a room assignment service to be provided the online check-in process. This Room Assignment functionality allows the CLIENT’s guest to choose from the available rooms for their booking. This information must be accessible in the CLIENT’s PMS. CIVITFUN will be responsible for retrieving, presenting to guests and updating the information to and from the PMS. In order to provide this Service, in the event that the CLIENT’s PMS does not fall into the CIVITFUN integration catalogue, it will be necessary to integrate/certify with the CLIENT’s PMS.

Annex G

Door Opening

The CLIENT may enable a Door Opening Product to be provided during the online check-in process. The Door Opening Product creates and sends an electronic key or digitised information (BLE or Pincode) that allows guests to access their room. In order to provide this service, it will be necessary to carry out the integration/certification with the CLIENT’s lock provider. CIVITFUN will be responsible for retrieving, presenting to guests and updating the information to and from the PMS. In order to provide this Service, in the event that the CLIENT’s PMS does not fall into the CIVITFUN integration catalogue, it will be necessary to integrate/certify with the CLIENT’s PMS.

Annex H

Upselling

The CLIENT may enable an Upselling service to be provided during the online check-in process for the assigned room during the booking process. The Upselling Product allows the CLIENT to update the charge pending collection in the PMS. The updated charge pending collection may be charged by activating the “Booking Payment” service. CIVITFUN will be responsible for retrieving, presenting to guests and updating the information to and from the PMS. In order to provide this Service, in the event that the CLIENT’s PMS does not fall into the CIVITFUN integration catalogue, it will be necessary to integrate/certify with the CLIENT’s PMS.

Annex I

Cross-selling

The CLIENT may enable a service for Cross-Selling goods or services to be provided during the online check-in process. The Cross-Selling product allows updates to be made to the outstanding charge in the PMS. The updated charge pending collection may be charged by activating the “Booking Payment” service. CIVITFUN will be responsible for retrieving, presenting to guests and updating the information to and from the PMS. In order to provide this Service, in the event that the CLIENT’s PMS does not fall into the CIVITFUN integration catalogue, it will be necessary to integrate/certify with the CLIENT’s PMS.

Annex J

Guestlink

The Guestlink Product is a guest communication tool and allows emails to be configured and sent prior to arrival at the hotel (24, 48 and 72 hours prior to arrival), during and after guests’ stay. Guestlink allows the CLIENT to set up and edit online check-in notification and confirmation emails, as well as other types of emails, including Upselling and Cross-selling offers, interesting information for the guests’ stay and post-stay service surveys. In order to provide this Service, in the event that the CLIENT’s PMS does not fall into the CIVITFUN integration catalogue, it will be necessary to integrate/certify with the CLIENT’s PMS.

Annex K

Guest Registration

The Guest Registration Product collects guests’ information and then automatically sends it to the competent body in those countries that legally requires the communication of guests’ data to the authorities. The CLIENT may define what personal or commercial data guests must provide by choosing them from the list of fields defined in the back office. In order to provide this Service, in the event that the CLIENT’s PMS does not fall into the CIVITFUN integration catalogue, it will be necessary to integrate/certify with the CLIENT’s PMS.

In addition, during the purchase process, the CLIENT may be able to modify certain items such as addresses, billing details or payment methods. To do this, the CLIENT must go back to the relevant button, when possible, and before the final acceptance of the purchase.

Once the purchase is made, it will be confirmed through an email sent within twenty-four (24) hours to the address stated therein. It will indicate the service purchased, the amount, applicable taxes and the applicable Terms and Conditions.

The CLIENT is hereby notified that, for legal reasons, CIVITFUN stores the electronic documents to formalise the purchases in the CLIENT’s profile. The CLIENT may access such documents at any time in its account or by requesting it from: info@civitfun.com

The Parties understand that CIVITFUN does not subrogate the CLIENT in its legal obligations, and the CIVITFUN Service is intended solely to facilitate the automation process necessary for reporting to the authorities. Consequently, the CLIENT expressly accepts that neither CIVITFUN nor HBX Group assume any responsibility with respect to the CLIENT’s obligations to report information to the authorities.

Annex L

Online Check-out

The “Online Check-Out” service allows guests to complete their check-out digitally, including updating their status in the CLIENT’s PMS, processing any pending payments, issuing invoices, and optionally completing a survey.

To provide the service, the CLIENT’s PMS must be integrated with CIVITFUN. If it is not listed in CIVITFUN’s integration catalog, a specific integration or certification will be required.

During the process, guests may review certain information, such as billing details, before confirming their check-out. Once completed, a confirmation email will be sent including the service details and applicable amounts.

For legal reasons, CIVITFUN stores electronic records of check-out operations in the CLIENT’s profile, accessible at any time via the account or by requesting them atinfo@civitfun.com.

The Parties acknowledge that CIVITFUN does not assume the CLIENT’s legal obligations and solely facilitates the automated check-out process. The CLIENT expressly accepts that CIVITFUN bears no responsibility for the CLIENT’s compliance with legal requirements toward authorities.

Annex M

OCR Document Scanner

The “OCR Document Scanner” service allows automatic reading of guest identification documents (ID cards, passports, or similar) using AI technology. Unlike standard MRZ-based scanners, the system extracts necessary data directly from the document content.

The OCR service can be used as a complement to the Online Check-In or Paperless Check-In products, or as a standalone, modular solution.

To operate, the service requires any device with a camera. The document images may be stored and transmitted to the hotel's PMS when so determined by the CLIENT. Such storage is intended to improve scanning quality, facilitate the resolution of technical incidents, and enable retry attempts in the event of errors during the processing or transmission of the extracted data. The images shall be retained only for the period defined in the applicable retention policy.

The Parties acknowledge that CIVITFUN provides this service solely to facilitate data capture, and does not assume any legal responsibility for the CLIENT’s compliance with local regulations regarding guest data or identity verification.

Annex N

Hotel Confirmation Number Product

The Hotel Confirmation Number (hereinafter “HCN”) Product has been developed by CIVITFUN in the context of a partnership with HBX Group and its objective is to automate the receipt of the booking confirmation number (HCN) directly from the PMS for all bookings intermediated by HBX Group.

Through a technical integration between HBX Group and CIVITFUN, specific calls are enabled allowing automated querying of the unique identifier assigned by the PMS to each booking. This functionality ensures that HBX Group receives the confirmation number (HCN) for each booking and effectively sends it to its B2B clients and their guests.

This process avoids common incidents related to the inability to locate a booking in the CLIENT’s system by reception staff or by guests and significantly reduces the number of interactions between the CLIENT’s and HBX Group’s operational teams or the HBX Group’s B2B clients to obtain the confirmation number upon request from HBX Group’s B2B customers or guests.

This Product has been designed to improve operational efficiency between the CLIENT and its distributors. It is always compliant with current data protection regulations and does not compromise the privacy of guests.

Annex O

Invoice Automation

The Invoice Automation Product has been developed by CIVITFUN in the context of a partnership with HBX Group with the aim of automating the invoice sending process by the CLIENT to HBX Group, relating to the bookings generated through the latter and paid by virtual credit card (hereinafter “VCC”).

Through direct integration with the PMS, CIVITFUN provides HBX Group with access to the calls necessary to automatically request and download invoices associated with the CLIENT’s VCC bookings.

This functionality eliminates the need for the CLIENT to manually send invoices to HBX Group, significantly reducing the management times needed to obtain the specific invoice for each booking under current legislation.

Automating invoice submission:

  • Ensures the timely and accurate receipt of invoices by HBX Group.

  • Minimises incidents associated with the non-receipt or late receipt of invoices.

  • Avoids service interruptions caused by administrative delays.

  • Significantly reduces operational burdens and interactions between the CLIENT and HBX Group teams.

The invoice obtained through this Product will be considered the only tax-valid invoice issued by the CLIENT to HBX Group.

Annex P

verifactu compliance integration

The VeriFactu Compliance Integration product is a solution developed by CIVITFUN to automate the retrieval, processing, and transmission of invoicing information generated by the CLIENT's PMS, facilitating its integration with the systems and processes associated with the VeriFactu regulatory framework in Spain.

This service enables the connection between the CLIENT's PMS and the CIVITFUN platform to automate invoicing-related information workflows, reducing manual administrative tasks and improving process traceability.

The main benefits of this product include:

  • Automation of invoicing information processing.

  • Reduction of administrative workload and manual tasks.

  • Improved operational efficiency through PMS integration.

  • Traceability and monitoring of processed records.

  • Adaptation to the technical requirements applicable to the VeriFactu framework.

To provide this Service, integration with the CLIENT's PMS will be required. In cases where the PMS is not included in CIVITFUN's integration catalog, a specific integration or certification with such system will be required.

The CLIENT acknowledges and agrees that CIVITFUN acts solely as a technology provider responsible for processing and transmitting the information supplied by the PMS. The CLIENT shall remain solely responsible for the issuance of invoices, the accuracy and legality of the fiscal and commercial information contained therein, and compliance with any applicable tax, accounting, regulatory, or legal obligations. CIVITFUN does not provide tax or legal advice and assumes no responsibility for the content of invoices or records processed through the Service.

Annex Q

AUTOMATED BOOKING LOADING PRODUCT

The Automated Booking Loading product has been developed by CIVITFUN in the context of a partnership with HBX Group with the aim of automating the loading of FIT bookings into the CLIENT’s Property Management System (PMS), eliminating the need to manually enter guest data received from compatible distribution channels.

Through direct integration with the PMS, CIVITFUN provides the necessary connections for such bookings to be automatically synchronized, ensuring the correct transmission of the booking information.

Automating this process:

Eliminates manual booking entry and transcription errors.

Reduces management times and avoids delays or administrative incidents.

Ensures that booking information is available in the PMS according to agreed standards.

CLIENT Responsibilities

Bookings managed through this Product shall be deemed valid for all contractual purposes between the CLIENT and CIVITFUN. The CLIENT shall remain responsible for the accuracy of the original booking data and for compliance with applicable regulations regarding data protection, tourism, and other relevant legislation.

Annex R

Data Protection Agreement

THE PARTIES

This processing contract (hereinafter, the “Contract”) regulates the processing of personal data within the framework of the provision of services in accordance with the contract signed between the Parties (hereinafter, the “Main Contract”).

Both Parties agree that they have sufficient legal capacity and the capacity to act to be bound by the terms of this Contract,

THE PARTIES HEREBY STATE

  1. That, by virtue of the corresponding Main Contract signed between the Parties, the Processor has undertaken to provide the Controller with the services described therein (hereinafter, the “Services”).

  2. For the performance of such Services, the Processor needs to process the personal data on behalf of the Controller.

IT IS HEREBY AGREED as follows:

  1. Definitions

    1. The following terms shall have the meaning set forth below.

Applicable Law” or “Data Protection Regulation” means any applicable law and regulation in any relevant jurisdiction in relation to the use or processing of personal data, including: (i) the California Consumer Privacy Act (“CCPA”), (ii) the General Data Protection Regulation (Regulation (EU) 2016/679) (“EU GDPR” or “GDPR”), (iii) the Swiss Federal Act on Data Protection (“FADP”), (iv) the EU GDPR as part of the law of England and Wales under section 3 of the 2018 European Union Act (Withdrawn), (the “United Kingdom GDPR”) or any other applicable data protection regulations; in each case, as it is updated, modified or replaced from time to time.

“Controller” means the natural or legal person, public authority, service or other body which, alone or together with others, determines the purposes and means of the processing;

Processor” means the natural or legal person, public authority, service or other body that processes personal data on behalf of the controller;

The terms “data subject”, “personal data”, “personal data breach”, “processing” and “supervisory authority” shall have the meanings set out in the GDPR.

  1. Purpose

    1. The purpose of this Contract is to define the conditions under which the Processor will process the personal data necessary for the correct provision of the Services.

    2. The Processor undertakes to process the personal data only in accordance with the documented instructions communicated to it by the Controller from time to time. The initial instructions from the Controller to the Processor in relation to the object and duration of the processing, the nature and purpose of the processing, the type of personal data and the categories of data subjects are described in Appendix I.

    3. In processing personal data under this Contract, the Processor shall comply with the Applicable Law and the applicable and mandatory recommendations of the competent Data Protection Authorities or other competent authorities, and shall be kept informed of and comply with any changes in such legislation and/or recommendations. The Parties shall agree to make such changes and modifications to this Contract as may be necessary under Applicable Data Protection Regulations.

  2. Term

    1. This Contract shall be in effect for the duration of the provision of the Services.

    2. If the services are modified during the term of this Contract and such modified services involve new or modified processing of personal data, or if the instructions of the Controller are modified or otherwise updated, the new modifications or instructions will be considered part of Appendix I, as applicable.

  3. Purpose of the Processing

    1. Personal data will be processed only for the purpose of providing the Services. Where the Processor considers it necessary to process the data for a different purpose, it must request the prior written authorisation of the Controller. In the absence of such authorisation, the Processor may not carry out such processing.

    2. If the Processor processes the data for a different purpose without the authorisation of the Controller, it shall be considered the Controller.

  4. Obligations of the Controller

    1. For the provision of the Service, the Controller undertakes to make available to the Processor the personal data and/or the information necessary so that the data can be adequately processed for the provision of the Services.

    2. The Controller shall ensure that personal data has been collected in accordance with the Applicable Law.

    3. The Controller shall ensure that data subjects have been informed of the processing of their personal data by the Processor on behalf of the Controller.

  5. Obligations of the Processor

The Processor agrees to comply with the following obligations:

    1. Process the personal data only for the purposes of the provision of the Services, complying with the instructions given in writing at any time by the Controller (unless there are regulations that require additional processing).

    2. The Processor shall immediately inform the Controller if it does not have sufficient instructions on how to process the personal data in a particular situation or if the instructions provided under this Contract, in the reasonable opinion of the Processor, violate the applicable Data Protection Regulation.

    3. Keep a record of all categories of the processing activities carried out on behalf of and in the name of the Controller.

    4. The Processor is obliged to adopt the appropriate technical and organisational measures to protect the personal data being processed and, therefore, must, among other things, comply with all the security measures set out in Appendix II, as well as with those communicated periodically by the Controller.

    5. The Processor shall maintain appropriate technical and organisational measures to ensure the security of the personal data and shall continuously review and improve the effectiveness of its security measures. Personal data will be protected against any other unlawful form of processing. Taking into account the state of the art and the costs of application, as well as the nature, scope, context and purposes of the processing and the risk of varying probability and severity for the rights and freedoms of individuals, the technical and organisational measures to be applied by the controller shall include at least those specified in Appendix II and as appropriate:

      1. pseudonymisation and encryption of personal data;

      2. the ability to ensure the ongoing confidentiality, integrity, availability and resilience of the systems and services that process personal data;

      3. the ability to restore promptly the availability and access to personal data in the event of a physical or technical incident; and

      4. a process to periodically check, assess and evaluate the effectiveness of technical and organisational measures to ensure the security of the processing.

    6. When the data is processed in the Processor’s systems, the latter undertakes to ensure, taking into account the technical progress, the costs of application and the nature, scope, context and purposes of the processing, as well as the risk of varying probability and severity in relation to the rights and freedoms of natural persons, the implementation of appropriate technical and organisational measures to ensure a level of security appropriate to the corresponding risk.

    7. The Controller shall have the right to take the necessary measures to verify that the Processor is in a position to comply with the obligations imposed on it by this Contract, and that the Processor has taken the necessary measures to ensure such compliance. The Processor undertakes to make available to the Controller all information and assistance necessary to demonstrate compliance with the obligations set out in this Contract and to allow and contribute to audits, including on-site inspections, carried out by the Controller or by another auditor commissioned by the Controller. Audits may only be conducted with prior notice and an explanation of the reasons for the audit. Audits shall take place during the Processor’s normal business hours and the costs associated with the audit shall be borne by the Controller.

    8. Notify the Controller, without undue delay and within a maximum period of 48 hours, of any personal data security breaches of which it becomes aware, supporting the Controller in notifying the competent Data Protection Authority, and where appropriate, the data subjects, of any security breaches that occur, as well as providing support to the Controller, when necessary, in carrying out privacy impact assessments and after consulting the competent Data Protection Authority.

    9. Assist the Controller in complying with its obligation to respond to any request made by a data subject who exercises its data protection rights. If the Processor receives an exercise of rights, it shall transfer it to the Controller as soon as it becomes aware of it.

    10. The Processor is authorised to anonymise the personal data processed under this Contract, ensuring that they can no longer be associated with or identify any individual. After anonymisation, the Processor may use such anonymised information for its own legitimate purposes, including but not limited to data analysis, research and service improvement, provided that said use complies with applicable data protection regulations and does not compromise the confidentiality obligations owed to the Controller.

    11. Return to the Controller all personal data once the provision of the Services is complete and delete existing copies, unless the retention of the data is required by law.

  1. Sub-Processors

    1. As a general rule, it is prohibited to subcontract with third parties the Services that involve the access and/or processing of personal data in whole or in part. However, in the event that the intervention of a Sub-Processor is necessary for the provision of the Services, the Processor is authorised to do so.

    2. A list of authorised Sub-Processors shall be made available to the Controller.

    3. The Processor undertakes to ensure that all Sub-Processors are bound by written agreements that require them to comply with the obligations corresponding to those contained in this Contract.

    4. In any case, access to the data is authorised to individuals who provide services to the Processor in the context of their organisation, under a commercial and non-labour relationship. In addition, access to the data is also authorised for companies and professionals hired by the Processor within its internal organisational scope for the provision of general or maintenance services (such as computer services, consulting, audits, etc.), provided that such tasks are not arranged by the Processor for the purpose of subcontracting with a third party all or part of the services it provides to the Controller.

  2. International Data Transfers

    1. The Processor shall not process personal data outside the European Economic Area (EEA) or in a country that does not have an adequate level of protection, unless it can ensure an adequate protection framework in accordance with the applicable regulations, by applying binding corporate rules, the formalisation of standard contractual clauses adopted by the European Commission (“EU SCC”), or the Information Commissioner (“UK SCC”) or other similar applicable Standard Contractual Clauses approved by the competent data protection authority, if applicable, obtaining authorisation for the transfer by the competent authority.

    2. The Parties acknowledge and agree that, where the Standard Contractual Clauses apply, (a) Appendix I to this Contract serves as Appendix I to the UK SCC, (b) Appendix I to this Contract contains the information required in Appendix I to the EU SCC.

    3. For data transfers from Switzerland, where a data transfer requires a lawful transfer mechanism, the EU SCC will be amended in accordance with the following:

      1. The supervisory authority with respect to such Personal Data is the Swiss Federal Data Protection and Information Commissioner. References to a “Member State” shall be construed as references to Switzerland. Data subjects located in Switzerland may enforce their rights in Switzerland. References to the EU GDPR shall be understood to be made to the Swiss Federal Act on Data Protection (amended or replaced). In Clause 17 (Applicable Law), the laws of Switzerland shall apply. In Clause 18 (Choice of Forum and Jurisdiction): the parties agree that the disputes will be resolved by the courts of Switzerland.

    4. However, the provisions of this section shall not apply to transfers to countries, or to individual recipients, or individual companies (including without limitation to recipients certified under the EU-U.S. Data Privacy Framework), which the European Commission has determined offer an adequate level of protection for personal data.

  3. Responsibility

    1. The Processor shall assume full liability for any damages caused and shall hold the Controller harmless from any claims arising from judicial and/or extrajudicial actions for direct non-compliance, solely attributable to the Processor, with the obligations contained in this Contract or the regulations applicable in its capacity as Processor.

    2. However, the Processor shall not be liable for damages or breaches arising from compliance with the instructions given by the Controller. In said cases, the Controller shall assume responsibility for and indemnify the Processor for any penalties, claims or damages that may arise from such instructions.

    3. If the breach by the Processor is a direct consequence of compliance with the instructions given by the Controller, the Controller shall be exempt from liability and shall be responsible for the consequences of such breach, including the monetary penalties imposed by the competent data protection authority or by any authority. In such case, the Controller shall indemnify the Processor for the damages caused.

  4. Personal Data of the Signing Parties

    1. Each of the Parties is informed that the contact details of its representatives and employees processed under this contract, as well as the others exchanged during the provision of the services, will be processed by the other Parties for the purpose of enabling development, compliance and control of the agreed service provision relationship, the basis of the processing being the fulfilment of the contractual relationship and the data being kept for the entire time that it is in force, and even after, until the possible responsibilities arising from it expire. Personal data may be communicated by the Parties to the competent Public Administrations and Bodies for the purposes of complying with their respective legal obligations, in accordance with current regulations, as well as, when necessary, to third parties involved in the management of the activities carried out.

    2. Data subjects may request access to personal data, its rectification, erasure, portability and limitation of its processing, as well as oppose it, at each Party’s domicile and/or lodge a complaint with the competent data protection authority.

  5. Applicable Law and Jurisdiction

    1. This Contract and all non-contractual obligations arising out of or in relation to it shall be governed by and construed in accordance with the laws set forth in the Main Contract.

    2. Each Party irrevocably submits to the exclusive jurisdiction of the courts provided for in the Main Contract on any claim or matter arising under or in connection with this Contract.

APPENDIX I

Processing Details

The information required in Appendices I and III of the EU SCC and Appendix 1 of the UK SCC is included below

  1. The Parties

Controller:the client

Contact details:[DATA PROTECTION CONTACT DETAILS]

Signature and date:By signing the Contract, it is considered that the Controller has signed these Standard Contractual Clauses incorporated therein, as of the Effective Date of the Main Contract.

Processor:Civitfun Tourism SL.

Contact details: dataprotection@civitfun.com

Signature and date:By signing the Contract, it is considered that the Processor has signed these Standard Contractual Clauses incorporated therein, as of the Effective Date of the Main Contract.

  1. Purpose of the processing:

In accordance with the main contract, the categories applicable to each purpose are described below:

Data Subjects

  • Guests of the Client

Categories of Personal Data

  • Identifying data

  • Personal characteristics data

  • Nationality data

  • Data on social circumstances and characteristics of the accommodation/housing.

  • Economic and financial data.

  • Data on goods and services transactions

Special-category personal data (if applicable)

  • Data on health or disability.

Nature and Purpose of the Processing

Provide the Services and/or comply with all other obligations provided for in the Main Contract and the Contract, including without limitation:

Data receipt, including collection, access, retrieval, recording, and input; Data retention, including storage, organisation, and structuring; Data use; Data updating; Data sharing, including disclosure, dissemination, authorisation of access, and any other form of making it available; Data return to the data exporter or data subject; Data erasure, including destruction and deletion. In each case, only to the extent strictly necessary for the specific Service contracted by the Controller.

Duration of the Processing

As described in the Master Contract

Transfer Frequency

Regular

Recipients of the Personal Data Transferred to the Data Importer

Each Party shall be responsible for maintaining a listing.

3. Competent Control Authority

The control authority shall be the Controller’s supervisory authority.

APPENDIX II

Minimum Safety Measures

HBX Group has implemented and maintains appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, in accordance with applicable data protection laws, and accepted information security standards. These measures operate within an Information Security Management System (ISMS) certified to ISO/IEC 27001:2022 standards, with regular reviews and updates to ensure its effectiveness.

The security measures are designed to protect Personal Data and to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services.

Without limitation, such measures include the following:

Information Security Governance and ISMS

HBX Group operates a formal, documented Information Security Management System aligned with ISO/IEC 27001:2022. The ISMS is supported by approved policies, procedures, and other governance documents, led by the Information Security Policy, governing security, acceptable use of IT resources, information classification, access control, password management, and workplace security practices. These documents define minimum security requirements and are reviewed and updated on a regular basis as part of the ISMS lifecycle.

Risk Management, Monitoring, and Incident Response

HBX Group applies a risk-based approach to information security, including the identification, assessment, and treatment of information security risks. Continuous security monitoring capabilities are in place to detect, analyze, and respond to security events and potential threats on a 24x7 basis. Formal incident management procedures ensure timely identification, containment, remediation, and recovery from security incidents, including escalation and notification processes where required by applicable law.

Business Continuity and Resilience

HBX Group maintains documented business continuity, disaster recovery, and crisis management arrangements designed to ensure the availability and resilience of systems and services. These measures support the continuity of critical business functions and the timely restoration of systems and data following a disruptive event.

These arrangements include regular backup processes designed to ensure the availability and integrity of Personal Data, as well as procedures for the secure restoration of data following an incident or system failure. In addition, Disaster Recovery Plan (DRP) is tested at least on a yearly basis.

Access Control and Identity Management

Access to systems and Personal Data is restricted in accordance with the principles of least privilege and need-to-know. Identity and access management controls are implemented to ensure that access rights are granted, reviewed, and revoked in a controlled manner. Strong authentication mechanisms and role-based authorization processes are applied to reduce the risk of unauthorized access.

Network, Endpoint, and Infrastructure Security

HBX Group implements technical and organizational safeguards to protect networks, endpoints, and infrastructure against unauthorized access, malware, and other security threats. Preventive and detective controls are applied to monitor system activity and restrict access to high-risk or malicious resources. Physical access to offices and other facilities is subject to appropriate security controls.

Vulnerability and Threat Management

HBX Group conducts regular vulnerability assessments and penetration testing to identify, assess, and remediate security weaknesses in a timely manner. Threat intelligence and monitoring activities are used to track emerging threats and inform the continuous improvement of security controls.

Secure Development and Change Management

All initiatives and developments follow “security by design” principle, where security requirements are integrated into the software development life cycle through secure development practices, including code analysis, testing, and controlled change management processes.

Data Protection and Information Handling Controls

Personal Data is protected through appropriate technical measures, including encryption of data in transit and controls designed to prevent unauthorized disclosure, alteration, or loss of information. Information is classified according to its sensitivity, and corresponding protection measures are applied in line with a defined information classification framework.

Logging, Audit, and Accountability

System and application activities are logged to support monitoring, incident investigation, and accountability. Access logs and relevant security logs are integrated in the security SIEM, being reviewed on a regular basis to detect anomalies and verify compliance with internal policies and security requirements.

Training and Awareness

HBX Group provides regular information security and data protection training and awareness programs for employees and relevant personnel.

Third-Party and Supplier Security

HBX Group maintains processes to assess and manage information security risks arising from third-party service providers and subprocessors. Where third parties process Personal Data on behalf of HBX Group, contractual obligations are in place to ensure appropriate technical and organizational security measures consistent with this section.