← Back to MentoCore

Data Processing Agreement

This DPA supplements the Terms of Service between the customer ("Controller") and Hospitality Mentors Inc ("Processor") and applies whenever we process personal data on the customer's behalf. A countersigned copy is available on request from legal@hospitalitymentors.net.

1. Subject matter and duration

We process personal data solely to provide MentoCore for the duration of the subscription, plus the deletion grace period described in clause 8.

2. Nature and purpose

Hosting, storage, transmission, retrieval, analysis and deletion of customer content entered into inspections, actions, incidents, SOPs, training, scheduling, traceability and notification features, plus AI-assisted drafting where the Controller enables it.

3. Categories of data and data subjects

Data subjects: the Controller's employees, contractors, and named contacts.

Data categories: identity and contact details, employment role and site, training and certification records, activity and audit metadata, and any content the Controller chooses to upload (including photographs). Special-category data is not requested and should not be uploaded.

4. Controller instructions

We process personal data only on documented instructions from the Controller, including use of the product's features. We tell the Controller if an instruction appears to infringe applicable data protection law, and we do not use customer personal data for our own purposes or to train third-party AI models.

5. Confidentiality and personnel

Personnel with access to personal data are bound by confidentiality obligations, receive security training, and are granted least-privilege access that is reviewed periodically.

6. Security measures (Art. 32)

  • TLS encryption in transit; encryption at rest on managed storage.
  • Row-level security enforcing tenant isolation on every table.
  • Role-based access control validated server-side, with roles held in a dedicated table.
  • Immutable audit events for privileged and record-changing operations.
  • Optional two-factor authentication for all users; recommended for owners and admins.
  • Automated dependency vulnerability scanning and database security linting.
  • Backups with point-in-time recovery; recovery objectives stated on the security page.

7. Sub-processors

The Controller authorises the sub-processors listed on our sub-processor page. We give at least 30 days' notice before adding or replacing a sub-processor; the Controller may object on reasonable data-protection grounds and, if we cannot resolve the objection, terminate the affected service without penalty.

8. Deletion and return

On termination, or on request, we delete customer personal data from active systems within 30 days; backups age out within 35 days. Export is available at any time in-app (Settings → Privacy & data) or via API.

9. Personal data breach

We notify the Controller without undue delay and in any case within 72 hours of becoming aware of a personal data breach affecting their data, with the nature of the breach, likely consequences, and remediation steps taken. Notifications go to the workspace owner's email address.

10. Assistance, audits and transfers

We assist the Controller with data subject requests, DPIAs, and regulator enquiries. We make available the information needed to demonstrate compliance and will respond to a reasonable annual security questionnaire; on-site audits require 30 days' notice and a confidentiality agreement. International transfers rely on the EU Standard Contractual Clauses and the UK Addendum, incorporated by reference.

11. Contact

Data protection contact: privacy@hospitalitymentors.net · Hospitality Mentors Inc, New York, NY, United States

Last updated 2 September 2026. Hospitality Mentors Inc · Hospitality Mentors Inc, New York, NY, United States