Legal
FortySix Data Processing Agreement
Draft for legal review Last updated 6 October 2026
This agreement is between the property using FortySix (the "controller", in Mexico the "responsable") and FortySix Technologies Ltd, a company registered in England and Wales (number 17487825), registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom (the "processor", in Mexico the "encargado"). It forms part of the FortySix Terms of Service and applies whenever FortySix processes personal data on the property's behalf. It is written to meet UK and EU data protection law (UK GDPR and GDPR, Article 28) and Mexico's federal law on the protection of personal data.
1. What FortySix processes, and why
- Purpose: providing FortySix to the property, as described in the Terms of Service, for as long as the agreement lasts.
- Guests: names, contact details, stay dates, rooms and beds, prices and payments, notes and requests, booking references from OTAs, and, where the property switches on guest records, nationality and passport or ID details (no document photos).
- Staff: names, roles, email and phone if given, work records such as shifts, sales and till counts; PINs are stored only in a form that can't be read back.
2. FortySix's commitments
- To process the data only on the property's documented instructions, which are these terms and how the property uses FortySix, unless the law requires otherwise (and then to tell the property first, where allowed).
- That everyone at FortySix with access to the data is bound to keep it confidential.
- To keep the data secure (section 3).
- To use other companies (subprocessors) only as set out in section 4.
- To help the property answer requests from guests and staff exercising their rights (access, correction, deletion and others), mainly through FortySix's own tools: search, edit and export.
- To tell the property about a personal data breach [within 48 hours] of becoming aware of it, with what's known, and to help it meet its own obligations.
- To give the property the information it reasonably needs to check these commitments are kept.
3. Security
- Data is stored in the EU (Ireland), encrypted in transit and at rest.
- Each property's data is kept apart at the database level; one property can't reach another's.
- Staff PINs are stored only as one-way hashes, with lockouts after repeated wrong attempts. Sensitive actions need a manager's approval.
- Bookkeeping, audit and till records can only be added to, not changed.
- Access by FortySix's own team is limited to what's needed to run and support the service.
4. Subprocessors
The property agrees to FortySix using the subprocessors listed on the Account & Data page (Supabase, Cloudflare, Channex, Resend and Google Workspace), each under a written agreement with data protection terms at least as protective as these. FortySix will give at least 30 days' notice of a new subprocessor; the property can object for good reason, and if no solution is found it can end the agreement.
Where a subprocessor processes data outside the UK or EEA, FortySix ensures an approved transfer safeguard is in place, such as the UK International Data Transfer Agreement or the EU Standard Contractual Clauses.
5. How long data is kept
- Guest and staff data: as long as the property keeps it in FortySix.
- Guests' nationality and passport details: deleted 13 months after the stay.
- Connection logs: 180 days. App error reports: 30 days.
- When the agreement ends, the property has 90 days to export its data. FortySix then deletes it, including from backups within [their normal cycle], unless the law requires FortySix to keep some of it.
6. Mexico
For properties in Mexico, FortySix acts as encargado: it processes guests' and staff's data only for the property, following its instructions and its aviso de privacidad, doesn't use the data for its own purposes, and keeps it confidential and secure as set out above.