This page summarizes the Data Processing Addendum (DPA) that forms part of our Terms of Service when a customer uses Sixto to process personal data of its guests, staff and contacts. The full DPA, including the signable version and the standard contractual clauses where needed, is available on request at [email protected].
Roles and scope
The customer is the data controller (Responsable del Tratamiento) and [Sixto legal entity, S.A.S.] is the data processor (Encargado del Tratamiento) for personal data the customer or its guests put into Sixto. The DPA covers the subject matter (providing Sixto), duration (the subscription plus the deletion period), nature and purpose (hosting and processing for reservations, guest communication, compliance filings, accounting and operations), the types of data (identification and contact data, travel data, identity document data, payment records, messages, team records) and the categories of people (guests, team members, owners, contacts).
For data about website visitors and account holders, Sixto acts as controller, as described in the Privacy Policy.
Processor obligations
Sixto will:
- process personal data only on the customer's documented instructions, which are the Terms, the DPA and the customer's use of the product, and tell the customer if an instruction appears to break the law;
- make sure people who access personal data are bound by confidentiality;
- not sell the data, not use it for advertising or profiling, and not use it to train AI models;
- keep records of its processing activities and cooperate with the customer's authorities when the law requires;
- process data in line with Ley 1581 de 2012 and its regulations, and the GDPR where it applies.
Subprocessors
The customer gives a general authorization for Sixto to use subprocessors. Each one is bound by a written agreement with data protection obligations no less protective than the DPA, and Sixto remains responsible for them. The categories and purposes are on the Subprocessors page and the current named list is available on request.
We notify customers before adding or replacing a subprocessor that processes customer personal data, by email or in the app, normally at least 30 days ahead. The customer may object on reasonable data protection grounds, and we will work with them on a solution or, failing that, they may terminate the affected service.
Security measures
Sixto maintains technical and organizational measures appropriate to the risk, including:
- encryption of data in transit;
- logical separation of each customer's data, enforced in the application;
- role-based permissions, with scoped API keys and connected agents never receiving more permission than the person who set them up;
- audit logs of sensitive actions;
- a credential vault for integration secrets;
- redaction of sensitive details before text is sent to AI providers, and guest identity documents read by AI only with the guest's consent;
- support access to a customer account only with the customer's consent, read-only by default and audited;
- regular backups and access controls on production systems.
Details are on the Security page and the full DPA.
Personal data breach
If Sixto becomes aware of a breach of security that leads to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to customer personal data, it will notify the customer without undue delay and, where feasible, within 72 hours of becoming aware. The notice will describe what is known about the nature of the breach, the data and people affected, likely consequences and the measures taken or proposed, and will be updated as we learn more. The customer decides whether to notify the SIC (Superintendencia de Industria y Comercio), other authorities or the affected people, and Sixto will help.
Assistance to the customer
Taking into account the nature of the processing, Sixto will help the customer to respond to requests from people exercising their rights (access, update, rectification, deletion, revocation, portability and objection), to carry out impact assessments and to consult authorities. The product includes export and deletion tools. If a person writes to Sixto directly about customer data, we pass the request to the customer and do not answer it ourselves unless the law requires.
International transfers
Customer personal data may be processed outside Colombia. Sixto will make sure transfers rely on a lawful mechanism, such as the standards and safeguards recognized by the SIC or, for GDPR data, standard contractual clauses, and will include them in the full DPA where needed.
Return and deletion
The customer can export its data while the account is active. After termination, Sixto keeps the data available for export for 30 days, then deletes it from active systems and from backups as they roll off, unless the law requires it to keep some records. On request, Sixto confirms the deletion in writing.
Audits and information
Sixto will give the customer the information needed to show compliance with the DPA, for example answers to a reasonable security questionnaire and a summary of its measures. If that is not enough, the customer may carry out an audit, not more than once a year unless there has been a breach, with reasonable notice, during business hours, under confidentiality and without exposing other customers' data. The audit's reasonable costs are the customer's.
Request the full DPA
To get the full DPA, a signable copy, the current subprocessor list or to ask a question, write to [email protected]. Please include your company name and the account owner's email.