Data Processing Addendum

Gearco

Last Updated: September 13, 2026


This Data Processing Addendum ("DPA") forms part of the Terms of Service, customer agreement, order, statement of work, or other agreement between Gearco, Inc. ("Gearco," "we," "us," or "our") and the customer ("Customer," "you," or "your") under which Gearco provides software, services, applications, hosting, support, or related services (collectively, the "Services").

This DPA applies only to the extent Gearco processes Personal Data on behalf of Customer and applicable data protection law requires the parties to enter into a data processing agreement.


1. Scope and Applicability


1.1 This DPA governs the Processing of Personal Data by Gearco on behalf of Customer in connection with the Services.


1.2 This DPA supplements Gearco's Terms of Service and Privacy Policy and applies only to Processing activities for which Gearco acts as a processor, service provider, or similar role under applicable data protection law.


1.3 Nothing in this DPA changes the ownership of Customer Content. Customer retains ownership of its underlying Content in accordance with Gearco's Terms of Service.


1.4 To the extent Gearco independently determines the purposes and means of Processing Personal Data for its own legitimate business purposes, Gearco may act as a controller or business under applicable law and such Processing will be governed by Gearco's Privacy Policy and applicable law.


2. Definitions


For purposes of this DPA:

  • "Applicable Data Protection Law" means privacy and data protection laws applicable to the Processing covered by this DPA.
  • "Customer Data" means Personal Data submitted to, stored in, transmitted through, or otherwise Processed by the Services on behalf of Customer.
  • "Data Subject" means an identified or identifiable individual to whom Personal Data relates.
  • "Personal Data" means information relating to an identified or reasonably identifiable individual and includes equivalent terms such as "personal information" where defined by applicable law.
  • "Process" or "Processing" means any operation performed on Personal Data, including collection, storage, access, use, transmission, alteration, retrieval, disclosure, deletion, or destruction.
  • "Subprocessor" means a third party engaged by Gearco to Process Personal Data on behalf of Customer in connection with the Services.


3. Roles of the Parties


3.1 Where Customer determines the purposes and means of Processing Personal Data and Gearco Processes such Personal Data on Customer's behalf, Customer acts as the controller and Gearco acts as the processor.


3.2 Where applicable privacy law uses different terminology, the parties will be treated in the substantially equivalent roles provided by that law.


3.3 Customer is responsible for ensuring that it has a lawful basis, appropriate notices, permissions, consents, and other authority necessary to collect and provide Personal Data to Gearco for Processing through the Services.


4. Processing Instructions


4.1 Gearco will Process Personal Data only:

  • as reasonably necessary to provide, operate, maintain, secure, support, and improve the Services;
  • in accordance with Customer's documented instructions;
  • as otherwise permitted by the parties' agreement; or
  • as required by applicable law.


4.2 Customer's use and configuration of the Services constitute documented instructions for purposes of this DPA.


4.3 If Gearco reasonably believes that a Customer instruction violates applicable law, Gearco may suspend the affected Processing and notify Customer where legally permitted.


5. Confidentiality


5.1 Gearco will ensure that personnel authorized to Process Customer Personal Data are subject to appropriate confidentiality obligations.


5.2 Access to Personal Data will be limited to personnel and service providers with a legitimate need to access such information in connection with the Services.


6. Security


6.1 Gearco maintains administrative, technical, and organizational safeguards designed to protect the confidentiality, integrity, and availability of Customer Data.


6.2 Gearco's security program includes controls and practices relating to areas such as:

  • identity and access management;
  • authentication and authorization;
  • system and network security;
  • encryption where appropriate;
  • monitoring and logging;
  • vulnerability and patch management;
  • change management;
  • incident response;
  • backup and recovery;
  • business continuity and disaster recovery;
  • vendor and Subprocessor management; and
  • employee security awareness.


6.3 Gearco maintains applicable Payment Card Industry Data Security Standard ("PCI DSS") compliance for systems and processes within its applicable cardholder data environment.


6.4 Gearco also undergoes independent SOC 2 Type II examination of applicable systems, controls, and operational practices.


6.5 SOC 2 Type II reports, PCI documentation, security questionnaires, or other relevant compliance information may be made available to qualified customers or prospective customers upon request and, where appropriate, subject to confidentiality requirements.


7. Subprocessors


7.1 Customer authorizes Gearco to engage Subprocessors as reasonably necessary to provide the Services.


7.2 Gearco will require its Subprocessors to maintain appropriate contractual obligations regarding confidentiality, security, and Processing of Personal Data consistent with the nature of the services they provide.


7.3 Gearco remains responsible for the performance of its Subprocessors to the extent required by applicable law.


7.4 Information regarding Gearco's then-current Subprocessors may be made available to Customer upon request or through a published Subprocessor list maintained by Gearco.


8. Data Subject Requests


8.1 Taking into account the nature of the Processing, Gearco will provide reasonable assistance to Customer in responding to valid requests from Data Subjects exercising rights available under applicable law.


8.2 If Gearco receives a Data Subject request relating primarily to Personal Data Processed on behalf of Customer, Gearco may direct the request to Customer unless applicable law requires Gearco to respond directly.


8.3 Customer remains responsible for determining whether a Data Subject request is valid and for providing instructions regarding the appropriate response.


9. Security Incidents


9.1 Gearco maintains procedures designed to identify, assess, and respond to security incidents.


9.2 Gearco will notify Customer without undue delay after becoming aware of a confirmed breach of security involving Customer Personal Data where notification is required by applicable law.


9.3 Where reasonably available, Gearco will provide information concerning:

  • the nature of the incident;
  • the categories of affected information;
  • actions taken or planned to contain or remediate the incident; and
  • information reasonably necessary for Customer to satisfy applicable legal obligations.


9.4 Notification of a security incident does not constitute an admission of fault or liability by Gearco.


10. Assistance with Privacy Compliance


10.1 Taking into account the nature of the Processing and information reasonably available to Gearco, Gearco will provide reasonable assistance to Customer with applicable obligations relating to:

  • security of Processing;
  • Personal Data breach response;
  • privacy impact assessments;
  • regulatory consultation; and
  • Data Subject rights.


10.2 Customer remains responsible for its own compliance obligations under applicable law.


11. Return, Retention, and Deletion


11.1 Upon termination of the applicable Services, Customer Personal Data will be retained and deleted in accordance with Gearco's Terms of Service and applicable customer agreement.


11.2 Unless otherwise required by law, permitted under the agreement, or covered by a separate retention arrangement, Customer Content is subject to Gearco's standard post-termination retention period.


11.3 Gearco offers a paid extended data storage and retention service for customers requiring Customer Content to be preserved beyond the standard retention period. The scope, duration, pricing, access rights, and other terms of extended retention will be governed by the applicable customer agreement, order, or written arrangement.


11.4 Where required by applicable law, Gearco will delete or return Personal Data following termination of the applicable Processing services, subject to legal retention obligations and applicable contractual rights.


12. Aggregated, Anonymized, De-identified, and Derived Information


12.1 Nothing in this DPA prevents Gearco from creating, retaining, or using aggregated, anonymized, de-identified, or derived information in accordance with the Terms of Service, provided such information is processed so that it does not reasonably identify an individual, customer, property, guest, or user.


12.2 Gearco's use of aggregated, anonymized, de-identified, or derived information for analytics, benchmarks, indexes, research, statistics, market intelligence, performance measures, and other analytical products is governed by Sections 9.7 and 9.8 of Gearco's Terms of Service.


12.3 Information that no longer constitutes Personal Data under applicable law is outside the scope of this DPA.


13. Audits and Compliance Information


13.1 Gearco will make available information reasonably necessary to demonstrate compliance with its obligations under this DPA.


13.2 Where appropriate, Gearco may satisfy audit or compliance requests by providing available third-party assurance reports, certifications, attestations, security documentation, questionnaire responses, or similar materials.


13.3 If applicable law requires an additional audit and existing documentation is reasonably insufficient, the parties will cooperate in good faith regarding the scope, timing, confidentiality, security, and cost of such audit.


13.4 Audits must not unreasonably interfere with Gearco's operations, compromise the security or confidentiality of other customers, or require disclosure of Gearco trade secrets except to the extent legally required.


14. International Data Transfers


14.1 Gearco operates primarily within the United States.


14.2 If Personal Data subject to international transfer restrictions is Processed under the Services, the parties will implement an appropriate lawful transfer mechanism where required by applicable law.


14.3 Where required, such mechanisms may include approved Standard Contractual Clauses or another legally recognized transfer mechanism.


15. European Union and European Economic Area Processing


15.1 Gearco does not intentionally market, offer, or provide its Services directly to individuals located in the European Union or European Economic Area, nor does Gearco intentionally monitor the behavior of individuals located within those jurisdictions.


15.2 If Customer processes Personal Data of individuals located in the European Union or European Economic Area through the Services and applicable law requires Gearco to act as a processor on Customer's behalf, this DPA is intended to address the applicable processor obligations, including those required under Article 28 of the General Data Protection Regulation ("GDPR").


15.3 The parties will cooperate in good faith to execute any additional legally required data protection terms that are reasonably necessary for a particular Processing activity.


16. U.S. Privacy Laws


16.1 To the extent applicable U.S. privacy law treats Gearco as a processor, service provider, contractor, or equivalent party with respect to Customer Personal Data, Gearco will Process such information in accordance with Customer's instructions, this DPA, the parties' agreement, and applicable law.


16.2 Gearco does not acquire ownership of Customer Personal Data by virtue of Processing it on Customer's behalf.


17. Disclosure Required by Law


17.1 Gearco may disclose Customer Personal Data where required by applicable law, regulation, court order, subpoena, or other valid legal process.


17.2 Where legally permitted and reasonably practicable, Gearco will notify Customer before making a legally compelled disclosure relating specifically to Customer Personal Data.


17.3 Gearco may seek protective measures, confidential treatment, redaction, limitation of scope, or other reasonable protections where appropriate.


18. Order of Precedence


18.1 This DPA supplements the agreement between Gearco and Customer.


18.2 If there is a conflict between this DPA and the Terms of Service regarding Gearco's Processing of Personal Data on behalf of Customer, this DPA will control solely with respect to that Personal Data Processing issue.


18.3 Except as expressly modified by this DPA, the Terms of Service and applicable customer agreements remain in full force and effect.


19. Limitation of Liability


The liability of each party arising out of or relating to this DPA will be subject to the limitations and exclusions of liability contained in the applicable agreement between Gearco and Customer, except to the extent such limitations are prohibited by applicable law.


20. Changes to this DPA


Gearco may update this DPA from time to time to reflect changes in applicable law, technology, security practices, or the Services. Material changes will be reflected through an updated revision date and, where required by law or applicable agreement, appropriate notice will be provided.


21. Contact

Questions regarding this DPA or Gearco's data protection practices may be directed to:

Gearco, Inc.
6555 Sugarloaf Parkway
Suite 307-204
Duluth, GA 30097
United States

Email: privacy.officer@gearcoinc.com



Schedule 1 – Processing Details


  • Subject Matter
    Processing of Personal Data in connection with Gearco software, applications, hosting, support, property management, payment, reporting, analytical, and related Services.
  • Duration
    For the duration of the applicable customer relationship and any applicable retention period.
  • Nature of Processing
    Collection, hosting, storage, organization, access, retrieval, transmission, reporting, support, analysis, backup, deletion, and other Processing reasonably necessary to provide the Services.
  • Purpose of Processing
    Providing and supporting Gearco Services, including property operations, reservations, guest services, payments, reporting, customer support, security, and related functionality.
  • Categories of Data Subjects
    Guests, prospective guests, Customer employees, Customer users, authorized representatives, vendors, and other individuals whose Personal Data is submitted to or Processed through the Services.
  • Categories of Personal Data
    Contact information, account information, reservation and stay information, transaction-related information, user and employee information, communications, system usage information, and other Personal Data submitted by Customer through the Services.
  • Sensitive Data
    Gearco does not require Customer to submit sensitive Personal Data except where necessary for use of a specific Service. Customer is responsible for determining whether submission of sensitive information is appropriate and lawful.


Schedule 2 – Technical and Organizational Measures


Gearco maintains technical and organizational measures designed to protect Customer Personal Data, including controls appropriate to the nature of the Services and information Processed.


These measures include, where applicable:


Access Control

  • role-based access controls;
  • least-privilege principles;
  • authentication controls;
  • administrative access restrictions;
  • periodic access review.


Infrastructure and Network Security

  • network segmentation where appropriate;
  • firewall and perimeter controls;
  • system hardening;
  • secure configuration standards;
  • infrastructure monitoring.


Encryption and Data Protection

  • encryption in transit where appropriate;
  • encryption at rest where appropriate;
  • secure handling of credentials and secrets;
  • data access controls.


Logging and Monitoring

  • system and application logging;
  • security monitoring;
  • event review and escalation procedures.


Vulnerability and Change Management

  • vulnerability identification and remediation;
  • software and system patching;
  • controlled production changes;
  • development and deployment controls.


Incident Response

  • documented incident response procedures;
  • investigation and containment processes;
  • escalation and notification procedures;
  • post-incident review where appropriate.


Business Continuity

  • backups appropriate to the applicable Service;
  • recovery procedures;
  • business continuity planning;
  • disaster recovery planning and testing where appropriate.


Vendor Management

  • risk-based review of relevant vendors and Subprocessors;
  • confidentiality and security obligations;
  • ongoing vendor management where appropriate.
  • Customers may request additional information regarding Gearco’s current Subprocessors by contacting privacy.officer@gearcoinc.com.


Compliance

  • applicable PCI DSS compliance;
  • independent SOC 2 Type II examination of applicable systems and controls;
  • periodic review of security policies and practices.


Gearco may update its technical and organizational measures from time to time, provided that such updates do not materially reduce the overall level of security applicable to Customer Personal Data during the applicable Service term.