全国56自治体の宿泊税(現状全て)が利用可能になりました。回収も自動、月計表出力も自動です。

QuickGuestbook Data Processing Agreement

 

This Data Processing Agreement (the “DPA”) is entered into between Kabushiki Kaisha Quick Shukuzeicho (株式会社クイック宿税帳) (the “Company”) and the lodging business operator using QuickGuestbook / クイック宿税帳 (the “Customer”). This DPA applies where the Company processes Personal Data on behalf of the Customer in connection with the Service.

1. Purpose and Relationship with Main Agreement

  1. This DPA sets forth the terms and conditions under which the Company processes Personal Data on behalf of the Customer in connection with the Service.
  2. This DPA forms part of the Terms of Service, order forms, application forms, and other related agreements between the parties (collectively, the “Main Agreement”).
  3. In the event of any inconsistency between this DPA and the Main Agreement with respect to Personal Data processing, this DPA shall prevail.

2. Definitions

For purposes of this DPA:

  1. Personal Data” means personal information, personal data, or equivalent information regulated under applicable law.
  2. Customer Personal Data” means Personal Data provided by, through, or on behalf of the Customer and processed by the Company in connection with the Service.
  3. Data Subject” means an identified or identifiable individual to whom Customer Personal Data relates.
  4. Third-Party Payment Service” means any external payment processor, gateway, acquiring service, settlement provider, or similar third-party service, including Stripe by way of example only.
  5. Connected Account” means an account designated by the Customer and connected to a Third-Party Payment Service.
  6. Subprocessor” means any third party engaged by the Company to process Customer Personal Data.

3. Roles of the Parties

  1. The Customer acts as the business operator, controller, or equivalent primary party responsible for Customer Personal Data.
  2. The Company acts as a processor, contractor, or equivalent service provider processing Customer Personal Data on behalf of the Customer.
  3. Information processed by the Company in its own capacity for contract administration, billing, support, security, legal compliance, and its own business operations is governed by the Company’s Privacy Policy rather than this DPA.

4. Subject Matter, Purpose, and Scope of Processing

  1. The Company shall process Customer Personal Data only for the following purposes:
    (a) providing, operating, maintaining, and improving the Service;
    (b) supporting lodging tax, reservation, billing, notification, and stay-related workflows;
    (c) enabling integrations with Third-Party Payment Services, including payment UI, billing flow, and status synchronization;
    (d) troubleshooting, security management, fraud prevention, audit logging, and incident response;
    (e) customer support, onboarding, setup, migration, and related services; and
    (f) compliance with applicable law and lawful instructions of the Customer.
  2. The Company shall process Customer Personal Data in accordance with the Customer’s documented instructions, including instructions reflected in the Main Agreement, configuration settings, API connections, and use of the Service.
  3. The Company shall not process Customer Personal Data for its own independent purposes, except as permitted by law or expressly authorized under the Main Agreement and this DPA.
  4. If the Company reasonably believes an instruction violates applicable law, it may notify the Customer and suspend or refuse such processing to the extent reasonably necessary.

5. Customer Warranties

The Customer represents and warrants that:

  1. it has all necessary rights, authority, legal bases, notices, and consents required to provide Customer Personal Data to the Company and to instruct the Company to process it;
  2. it has lawfully informed relevant individuals, where required, regarding the use of the Service, Third-Party Payment Services, possible international processing, and other required matters;
  3. it remains solely responsible for compliance with lodging tax, lodging regulation, identity verification, consumer law, and other legal obligations applicable to its business; and
  4. Customer Personal Data submitted to the Service is, to the extent reasonably practicable, accurate and up to date.

6. Company Obligations

  1. The Company shall process Customer Personal Data with due care and in accordance with this DPA.
  2. The Company shall limit access to Customer Personal Data to personnel who need such access for authorized purposes.
  3. The Company does not guarantee the accuracy, completeness, or lawfulness of Customer Personal Data provided by the Customer.

7. Security Measures

The Company shall implement reasonable and appropriate technical, organizational, physical, and personnel security measures designed to protect Customer Personal Data against unauthorized access, leakage, loss, destruction, alteration, or misuse. Such measures may include:

  1. access control and authentication;
  2. role-based permissions;
  3. logging and monitoring;
  4. secure transmission and storage protections;
  5. employee confidentiality obligations and training;
  6. vendor management and incident response procedures; and
  7. appropriate risk assessment for international or outsourced environments.

8. Personnel Supervision

The Company shall ensure that personnel authorized to process Customer Personal Data are subject to confidentiality obligations and appropriate supervision.

9. Subprocessing

  1. The Company may engage Subprocessors as reasonably necessary to provide the Service.
  2. The Company shall impose data protection obligations on Subprocessors that are substantially similar to those set forth in this DPA.
  3. The Company shall exercise appropriate oversight over Subprocessors as required by applicable law.
  4. Categories of Subprocessors may include hosting providers, cloud infrastructure providers, monitoring providers, support providers, email or communication vendors, analytics providers, and payment integration support providers.

10. Third-Party Payment Services

  1. The Service may integrate with Third-Party Payment Services.
  2. Even where transaction proceeds are received by the Customer or a Customer-designated Connected Account, the Company may process transaction-related Personal Data to the extent necessary to provide payment UI, billing flow, status synchronization, error handling, and operational support.
  3. The Company is not intended to be the primary holder of full payment instrument data such as full card numbers where such data is directly collected and stored by the Third-Party Payment Service.
  4. Processing by Third-Party Payment Services is also subject to the terms and privacy policies of those providers.
  5. The Company does not guarantee availability, compliance decisions, payout timing, settlement outcomes, or identity verification outcomes of any Third-Party Payment Service.

11. International Processing

  1. The Company may process Customer Personal Data outside Japan or allow access from outside Japan in connection with hosting, support operations, infrastructure, or Subprocessors.
  2. The Company shall take reasonable measures required under applicable law with respect to such international processing.
  3. The Customer acknowledges that the use of global cloud or external service providers may involve cross-border processing.

12. Data Subject Requests

  1. The Customer shall be primarily responsible for responding to requests, complaints, or inquiries from Data Subjects.
  2. Upon the Customer’s reasonable request, the Company shall provide reasonable assistance to the extent legally permitted and technically feasible.

13. Personal Data Incidents

  1. If the Company becomes aware of unauthorized access, leakage, loss, destruction, or other incidents affecting Customer Personal Data, it shall notify the Customer without undue delay to the extent legally permitted.
  2. The Company shall take reasonable steps to investigate, mitigate, remediate, and help prevent recurrence.
  3. The Customer remains primarily responsible for any legally required notifications to Data Subjects or regulators, unless otherwise required by law.

14. Audit and Information Rights

  1. The Customer may request reasonable information regarding the Company’s processing of Customer Personal Data where necessary for legal compliance or reasonable oversight.
  2. The Company may satisfy such requests through documentation, written responses, summaries, certifications, or other reasonable means that protect confidentiality, security, trade secrets, and the rights of other customers.
  3. Any onsite audit shall be subject to prior agreement on scope, timing, method, confidentiality, security safeguards, and allocation of reasonable costs.

15. Return and Deletion

  1. Upon termination of the Main Agreement, the Company shall return, delete, or anonymize Customer Personal Data, except to the extent retention is required by law, backup cycles, fraud prevention, dispute handling, audit needs, or other legitimate reasons.
  2. The format, timing, and method of return shall be subject to the Company’s then-current technical capabilities and the Main Agreement.
  3. Residual copies in backups may remain until overwritten in the ordinary course.

16. Aggregated and Anonymized Information

  1. Subject to applicable law and the Main Agreement, the Company may generate and use aggregated, statistical, anonymized, or de-identified information derived from Customer Personal Data for service improvement, analytics, benchmarking, product development, research, sales, and marketing.
  2. The Company shall comply with legal requirements applicable to anonymization, publication, security handling, and prohibitions on re-identification.

17. Confidentiality

The Company shall treat Customer Personal Data as confidential and shall not disclose it to third parties except as permitted by the Main Agreement, this DPA, or applicable law.

18. Liability

  1. The Company’s liability under this DPA shall be subject to the liability limitations set forth in the Main Agreement.
  2. Nothing in this DPA limits liability that cannot be limited under applicable law.

19. Term

  1. This DPA shall remain effective for the duration of the Main Agreement.
  2. Provisions that by their nature should survive termination shall survive, including those relating to confidentiality, deletion, liability, and applicable law.

20. Governing Law and Language

  1. This DPA shall be governed by the laws of Japan.
  2. Jurisdiction shall follow the forum agreed in the Main Agreement.
  3. This DPA may be prepared in Japanese and English, and both language versions shall have equal effect. Any discrepancy shall be resolved in good faith in light of the parties’ common intent and the structure of the Main Agreement.

Schedule 1 – Processing Details

  • Data Subjects: guests, reservers, companions, customer personnel, facility contacts, inquiry contacts
  • Data Types: name, address, phone number, email address, date of birth, nationality, ID-related information, reservation details, stay details, billing data, tax-related data, payment status data, communications, logs
  • Processing Operations: collection, receipt, recording, storage, access, retrieval, editing, transmission, export, deletion, anonymization, aggregation
  • Retention: during the term of the Main Agreement and for a reasonable period thereafter as necessary for law, backups, audit, dispute handling, and security.