Guest data processing terms

Last updated: 2026-09-15

These terms govern the processing ALocal carries out, on the host’s behalf, of the guest data collected through the platform, as required by Article 28(3) GDPR. They apply to every management account that uses guest intake and SIBA files, and they supplement the Terms of Use.

These terms are drafted in Portuguese and also made available in English and Spanish. In the event of any discrepancy between versions, the Portuguese version prevails.

The provider’s full legal identity (name, tax number and address) is still to be published on the legal pages. Until then, these pages refer to the service as the Gestão de Alojamento Local platform.

Parties

  • Controller: the host who holds the management account, runs the accommodation and is required to report stays by foreign nationals (articles 15 and 16 of Portuguese Law 23/2007).
  • Processor: the provider of the Gestão de Alojamento Local platform (ALocal), whose full legal identity is still to be published.

Subject matter and duration

  • Subject matter: collecting, storing and organising guests’ identity data, generating the accommodation bulletin files and keeping the host’s evidence of compliance.
  • Duration: for as long as the management account exists, until the data are erased as described under “End of processing”.

Nature and purpose

  • Collection through a private link the host sends to the guest, with field validation.
  • Encrypted storage of identity fields, and viewing by account users.
  • Generation of the .DAT file for SIBA, with guests of foreign nationality only, and of an internal CSV register with every guest on the stay.
  • Erasure at the end of the retention period.
  • Sole purpose: enabling the host to report guests and to show that they did. ALocal does not file the bulletin on SIBA, does not send data to authorities, does not use the data for marketing and does not sell them.

Categories of data

  • For each guest: first name, last name, date of birth, gender, nationality, country of residence, and identity document type, number and issuing country.
  • For the stay: arrival and departure dates and the accommodation.
  • The form does not collect images or copies of documents.

Categories of data subjects

  • Guests of the accommodation: the main guest and up to four accompanying guests per form.

Host obligations

  • Process the data on a lawful basis and within the purposes of these terms.
  • Inform guests; the form shows a notice and the Privacy Policy has a section on guest data.
  • Send the link only to the guests of the stay, and give account access only to those who need it.
  • File the bulletin on the SIBA portal within the legal deadlines and keep what the law requires to be kept.
  • Answer guests’ requests about their data.

ALocal obligations

  • Instructions: process the data only on the host’s documented instructions, which are these terms and the host’s use of the platform, and tell the host if it considers an instruction infringes data protection law.
  • Confidentiality: ensure that anyone with access to the data has committed to confidentiality or is under a statutory obligation of confidentiality.
  • Security: apply the measures described under “Security measures”.
  • Processors: the host gives general authorisation for the processors listed below. ALocal announces any addition or replacement on this page before it takes effect, and the host may object. Each processor is bound by equivalent data protection obligations.
  • Data subject requests: forward to the host, without undue delay, any request it receives, and help the host answer it; the account data export is under Account › Your data (GDPR).
  • Assistance: help the host comply with Articles 32 to 36 GDPR, taking into account the information available to ALocal.
  • Personal data breaches: notify the host without undue delay after becoming aware of a personal data breach, with the information available so the host can meet its own notification duties.
  • Demonstration and audits: make available the information needed to demonstrate compliance with these terms, and allow audits, including inspections, by the host or an auditor it mandates, on reasonable prior notice.

Security measures

  • Identity fields encrypted in the database with AES-256-GCM, using per-field keys derived with HKDF-SHA256 from a master key set in the server configuration.
  • SIBA files and backups written to object storage with server-side encryption.
  • Access by account and role: only members of the management account reach the data; exporting all data requires the owner or administrator role.
  • Audit log of identity reads, exports, downloads and erasures.
  • Single-use, time-limited intake links, stored only as a cryptographic fingerprint.
  • Daily database backups.
  • Daily automatic erasure at the end of the retention period.

End of processing

  • While the account exists, identity data and the .DAT and CSV files are erased once 365 days have passed since the departure date, the default period. The export record remains, with no identity data.
  • When the service ends, and at the host’s choice, ALocal erases the guest data or first returns them through the account data export, unless the law requires them to be kept.
  • Backups are deleted from the server after 14 days; in them, identity fields remain encrypted.
  • To ask for the account to be deleted, use the data deletion page.

Authorised processors

The providers involved in the service, and what each one receives.

ProviderServiceData receivedLocation
OVHcloudApplication and database server; object storage for SIBA files and backups.All guest data stored by the platform (in the database, identity fields are encrypted).Object storage and backups in the GRA region (Gravelines, France). Server location still to be confirmed.
BrevoSending platform emails to account users.Address and content of sign-in and reminder emails; no guest identity data.Still to be confirmed.
ImprovMXForwarding messages sent to the support address.Only what someone writes to that address; it does not receive form data.United States company. It states that it receives email in France (AWS, Paris), deletes it once delivered and may deliver it from infrastructure in the United States, under standard contractual clauses.

Stripe processes subscription payments and receives no guest data, so it is not on this list.

Information for guests is in the “Guest data” section of the Privacy Policy.

For questions about these terms, write to the support address. Suggested subject line: Acordo de tratamento. support@alocal.pt