Data processing
DPA
This DPA page describes Purnukka's role as a personal data processor when the service is used to process customer guest data.
Updated: 26.6.2026
This is not legal advice. The terms can be reviewed by a lawyer before final use.
Roles in personal data processing
Purnukka may act as a processor on behalf of the customer when the service processes the customer's guests or end customers' data. The customer is then the controller for their own guests and accommodation operations.
Purnukka acts as the controller for its own customer, sales, billing and support data.
Subject of processing
Processing may cover bookings, contact details, messages, traveller declarations, service orders, technical payment routing and other data needed for use of the service.
Processing is carried out to provide and maintain the service, provide customer support, protect security and handle statutory obligations.
Subprocessors
Purnukka may use subprocessors to provide the service. These may include Stripe, hosting providers, email services, domain services, analytics tools and other technical services.
Purnukka aims to choose providers with appropriate technical and organisational safeguards for the intended use.
Security measures
Security measures may include HTTPS connections, limiting access rights, technical logging, provider backups, routing payment data processing to a payment provider and limiting maintenance access as needed.
The exact implementation depends on the service version, the features used by the customer and third-party services.
Assistance with data subject rights
Purnukka reasonably assists the customer with requests related to data subject rights if the request concerns data that Purnukka processes on behalf of the customer.
The customer is primarily responsible for handling data subject requests in accordance with applicable data protection law.
Deletion or return at the end of the agreement
At the end of the agreement, Purnukka may delete or return personal data processed on behalf of the customer as agreed, unless there is a statutory, accounting or legal basis for retaining the data.
Data may remain in technical backups for a limited period in line with the provider's normal backup practices.