GENERAL TERMS AND CONDITIONS AND DATA PROCESSING AGREEMENT

PMSPilot (Koban Management LLC) Effective from: 08.08.2026 Operator: Koban Management LLC, Wyoming, USA Contact: [email protected]


PREAMBLE

These terms govern use of the PMSPilot platform by hoteliers, hospitality businesses and other commercial operators (each a "Customer"). PMSPilot is a cloud-based management system for reservations, guest data and business processes.

The following terms are binding. By registering/using the platform, the Customer accepts them. If the Customer objects, the platform must not be used.


1. SCOPE OF SERVICES

1.1 Service definition

PMSPilot provides the following core services:

  • Cloud-based hotel management system (SaaS)
  • Reservation management
  • Guest data storage
  • API connections to channel managers, OTAs and other platforms
  • Reporting and analytics
  • Technical support (see section 8)

1.2 Availability

We guarantee 99.0% availability measured monthly (excluding planned maintenance and force majeure).

Planned maintenance: max. 4 hours/month, outside 06:00–22:00 CET where possible.

If availability falls below the guarantee, the Customer receives a service credit (see section 1.3).

1.3 Service credits

If the availability guarantee is not met:

  • 98.5–99.0% availability: 5% monthly fee credit
  • 98.0–98.5% availability: 10% monthly fee credit
  • <98.0% availability: 25% monthly fee credit

Service credits are the sole remedy for availability issues.

1.4 What is NOT guaranteed

  • 100% uptime (no SLA is realistically absolute)
  • Compatibility with all third-party applications
  • That the platform meets your specific business requirements
  • Forecasts (data-driven recommendations are indicative only)

2. CUSTOMER OBLIGATIONS & DATA BACKUP

2.1 Customer obligations

The Customer agrees to:

a) Backup strategy: Regularly (at least daily) perform independent backups of all critical data (reservations, guest data, invoices, rates). PMSPilot provides an export API for this purpose.

b) Password security: Protect login credentials and share them only with authorised staff. The Customer is responsible for all activity under the account.

c) Legal compliance: Guarantee lawful operation in all applicable jurisdictions and that use of PMSPilot is lawful.

d) Correct data entry: Remain responsible for accuracy of all entered data (rates, availability, descriptions, guest information).

e) OTA data updates: Regularly verify that automatic price updates to Booking.com, Airbnb, etc. work correctly. PMSPilot does not guarantee complete synchronisation with all platforms (see section 2.2).

2.2 Price synchronisation & availability management

IMPORTANT: PMSPilot synchronises prices/availability with third parties (Booking.com, Airbnb, Expedia, etc.). Delays or errors may occur:

  • OTA API errors: OTAs may occasionally reject updates (technical faults on their side)
  • Delays: updates may take 15 minutes to 2 hours
  • Double bookings: despite synchronisation, double bookings can theoretically occur (very rare)

Customer duty: Check OTA channels daily (Booking.com dashboard, Airbnb calendar, etc.) and correct errors immediately.

PMSPilot is NOT liable for:

  • Financial losses from pricing errors (e.g. €50 instead of €150)
  • Lost bookings due to availability errors
  • OTA fines or penalties (e.g. Booking.com penalties for many cancellations)

The Customer bears full responsibility for price checks and availability corrections.


3. LIMITATION OF LIABILITY

3.1 Exclusion of indirect damages

Neither PMSPilot nor Koban Management LLC is liable for:

  • Lost profits / lost revenue
  • Lost savings
  • Reputational or image damage
  • Indirect, consequential, punitive or exemplary damages
  • Data loss or corruption where the Customer failed to maintain backups
  • Errors of third parties (OTAs, channel managers, payment providers)

3.2 Liability cap

Under NO circumstances shall PMSPilot/Koban Management LLC be liable for more than:

The sum of all fees paid by the Customer in the 3 months preceding the claim.

Example: €50/month paid = €150 maximum liability. Example: €200/month paid = €600 maximum liability.

This applies to:

  • Downtime and data loss
  • Faulty price synchronisation
  • Any kind of damage

3.3 Exceptions to the liability cap

The liability cap does NOT apply in cases of:

a) Gross negligence or wilful misconduct by PMSPilot (e.g. intentional deletion of your data) b) Data protection claims (GDPR/CCPA): damages under Art. 82 GDPR remain intact c) Consumer protection laws: statutory protection in Germany/Austria/Switzerland remains intact d) Breach of this agreement by PMSPilot (but only up to the liability cap)


4. DATA PROTECTION AND PROCESSING (GDPR ART. 28)

4.1 Roles

  • Controller: The Customer (you as hotelier)
  • Processor: PMSPilot / Koban Management LLC
  • Sub-processors: See section 4.3

4.2 Scope of processing

PMSPilot processes the following personal data solely to provide PMS services:

Guest data:

  • Name, email, phone
  • Address
  • Payment information (stored encrypted)
  • Reservation history
  • Special needs (allergies, mobility aids)
  • Passport data (stored in R2)

Business data:

  • Customer account information
  • Usage logs (anonymised)
  • Payment history

Purpose: reservation management, payment processing, guest service, compliance

Duration: while the service is active + statutory retention (3–10 years depending on jurisdiction for invoices/compliance)

4.3 Sub-processors

PMSPilot uses the following sub-processors:

Sub-processorPurposeData protection agreement
Stripe (USA/EU)Payment processing (cards)DPA under Standard Contractual Clauses
PayPal (USA/EU)Payment processing (PayPal accounts)DPA under Standard Contractual Clauses
Channex (USA/EU)Channel manager integration (OTA sync)DPA under Standard Contractual Clauses
Cloudflare (USA/EU)CDN, DDoS protection, backupsDPA under Standard Contractual Clauses
AWS (USA/EU/Others)Server infrastructure, storageDPA under Standard Contractual Clauses
SendGrid (USA)Email deliveryDPA under Standard Contractual Clauses

Objection right: The Customer may object in writing to a new sub-processor within 30 days ([email protected]). On a justified objection, the Customer may terminate without penalty.

We notify about new sub-processors by email at least 30 days before implementation.

4.4 Technical and organisational measures (TOMs)

PMSPilot implements the following security measures:

Technical measures:

  • AES-256 encryption for data at rest
  • TLS 1.3 encryption for data in transit
  • WAF (Web Application Firewall) against attacks
  • Automated backup systems (daily)
  • Intrusion Detection System (IDS)
  • Regular security patches (within 7 days for critical vulnerabilities)

Organisational measures:

  • Role-based access control (RBAC)
  • Two-factor authentication (2FA) for all accounts
  • Staff data-protection training (annual)
  • Confidentiality obligations for all staff
  • Audit logs for data access
  • Incident response plan (72-hour notification duty, see 4.5)

The Customer receives a current security report on request.

4.5 Personal data breaches & notification

PMSPilot obligation: If a personal data breach occurs (unauthorised access, data leak), PMSPilot will:

  1. Notify the Customer without undue delay (max. 72 hours)
  2. Inform about nature of the breach, affected data/persons, likely consequences and measures taken
  3. Support the Customer in notifying data subjects and authorities

Customer obligation: The Customer is responsible for notifying the supervisory authority and data subjects where required.

4.6 Data portability & deletion

Export: The Customer may export all data at any time (API or batch export). Formats: CSV, Excel.

Deletion after end of contract:

  • Live data: deleted immediately
  • Backups: deleted within 7 days (recovery window)
  • Invoices/audit logs: retained 7 years (legal requirement)
  • Guest names (GDPR Art. 17): deleted on Customer request (unless statutory retention applies)

The Customer receives deletion confirmation by email.

4.7 Data locations (jurisdiction)

  • Primary storage: Europe (Cloudflare)
  • Backups: Europe
  • Processing: where required for service operation

For EU customers: transfers are protected by Standard Contractual Clauses (SCCs).


5. PAYMENTS & BILLING

5.1 14-day trial

PMSPilot offers every new Customer a 14-day free trial. During the trial:

  • The service is fully functional
  • All core features may be used (reservations, guest data, API, etc.)
  • No payment required for base features
  • The Customer may cancel anytime without cause

EXCEPTION — paid modules: The following premium modules are not free during trial and must be paid immediately:

  • Channel Manager (OTA integration)
  • OTA Live Chat
  • Guest reviews
  • Fiskaly (fiscal/POS integration)

These modules are non-refundable, including during the trial.

5.2 After the trial (subscription activation)

After 14 days the free trial ends. To continue, the Customer must:

  1. Manually activate a subscription → Dashboard button "Activate subscription"
  2. Be redirected to Stripe → enter payment details
  3. Confirm payment → paid subscription begins

By confirming payment at Stripe, the Customer implicitly accepts:

  • That the 14-day trial constituted performance of a service (Art. 16(m) Directive 2011/83/EU)
  • That the right of withdrawal thereby expires
  • That the subscription is billed immediately
  • That there is no refund after the first payment

No automatic activation: The subscription is NOT activated automatically. Active payment is the Customer's express consent.

5.3 Payment terms

  • First payment: after the 14-day trial (day 15)
  • Billing cycle: monthly or yearly (depending on plan)
  • Payment method: Stripe payment methods offered
  • Collection: automatically every 30 days via Stripe
  • Due: immediately upon invoicing

5.4 Invoices

Invoices are sent digitally and available via Stripe. The Customer can retrieve them anytime in the PMS dashboard under "Billing & Subscription" → "View invoices".

5.5 Price changes

Price increases:

  • Notified by email 30 days in advance
  • Apply from the next billing cycle
  • Give the Customer a right to terminate without penalty (within 14 days)

5.6 Refunds

No refund after trial:

After the free trial, once a paid subscription is activated, there is no refund, including on cancellation of an annual plan.

This is valid because during the trial the Customer:

  • Could use full platform functionality
  • Could make an informed decision
  • Explicitly accepted that the trial constitutes performance of a service

Exception for total outage: If PMSPilot is completely unavailable for more than 24 hours after subscription activation (>99% downtime), the Customer receives a pro-rata credit for the outage period (calculated in days).


6. TERMINATION

6.1 Customer termination

During the 14-day trial: Cancel anytime without cause or fees. Immediate effect. No subscription is activated.

After the trial (paid subscription): Cancel anytime via the dashboard. Effective at the end of the current billing cycle (e.g. end of month).

No further fees after the termination date.

6.2 Termination by PMSPilot

PMSPilot may terminate if:

a) The Customer is 7+ days overdue b) The Customer materially breaches these terms (e.g. selling data, hacking attempts) c) The Customer violates laws (e.g. fraud, money laundering) d) Technical/operational reasons (force majeure, e.g. critical security vulnerability)

Where possible, PMSPilot gives 7 days' notice to export data. For security breaches or illegal activity, notice may be shortened to 24–48 hours.

6.3 Consequences after termination

  • Account and all data deleted after 90 days
  • No further fees
  • Customer may export data (free, via API or download)

7. INTELLECTUAL PROPERTY

7.1 PMSPilot IP

All software, designs, logos, trademarks and content of the PMSPilot platform are owned by Koban Management LLC and protected by copyright. Use is limited to private, non-commercial use as a hotelier.

Prohibited:

  • Reverse engineering, decompilation
  • Commercial reuse
  • Sale or transfer to third parties
  • Plagiarism of UI/code

7.2 Customer data

The Customer remains owner of all uploaded data (guest data, reservations, etc.). PMSPilot has a usage right only to operate the service.

PMSPilot will not use Customer data for other purposes (e.g. marketing, sale to third parties) unless the Customer expressly consents.


8. SUPPORT & SERVICE LEVEL

8.1 Support channels

8.2 Support offering

Standard support for all Customers:

  • Response time: 24 hours (weekdays), 48 hours (weekend)
  • Email ticketing system
  • Knowledge base & self-service

8.3 Support scope

PMSPilot helps with:

  • Technical issues and bugs
  • Platform functionality
  • API integration
  • Security questions
  • Custom software development related to PMSPilot – chargeable

PMSPilot does NOT help with:

  • Business strategy consulting
  • Third-party tools (e.g. Booking.com support)

9. DISCLAIMER & PROHIBITED USE

9.1 No warranty

PMSPilot is provided "AS IS" without warranties of any kind (including implied). The Customer uses the platform at their own risk.

This excludes in particular:

  • Fitness for a particular purpose
  • Freedom from errors
  • Uninterrupted availability

9.2 Prohibited activities

The Customer must not use the platform for:

  • Illegal activities (money laundering, fraud, human trafficking)
  • Hacking or unauthorised access
  • Distribution of malware
  • Harassment, bullying or discrimination
  • Spam or phishing
  • Sale or sharing of access credentials
  • Automated scraping (except with API permission)
  • DDoS attacks

Consequences: Immediate suspension without refund.

9.3 Compliance & illegal use

The Customer guarantees that:

  • Their business is lawful in all countries of operation
  • They comply with local laws (labour, tax, environment, data protection)
  • They do not use PMSPilot for illegal purposes

PMSPilot may suspend accounts on suspicion of legal violations.


10. INDEMNIFICATION

The Customer agrees to indemnify PMSPilot and Koban Management LLC against claims arising from:

a) The Customer's use of PMSPilot b) Breach of these terms c) Guest complaints about data security (where PMSPilot is not at fault) d) Local law violations (e.g. labour law, tax fraud)

Exception: PMSPilot remains liable for claims caused by its own negligence or legal violations.


11. GOVERNING LAW & JURISDICTION

11.1 Applicable law

These terms are governed by the laws of Wyoming, USA, with the following priority:

  1. GDPR (data protection): if the Customer is in the EU, GDPR rules apply (Art. 3 GDPR)
  2. Local consumer protection laws: apply in addition to Wyoming law
  3. Otherwise: Wyoming law

11.2 Jurisdiction & arbitration

Customers in the EU/EEA (Germany, Austria, Switzerland, UK, etc.):

  • Venue: place of the Customer's business seat
  • Or arbitration under ICC Rules (London), one arbitrator
  • Costs: PMSPilot bears arbitrator fees
  • Language: German or English (Customer choice)

Customers outside EU/EEA:

  • Venue: Sheridan County, Wyoming, USA
  • Or arbitration under AAA Rules (English)

11.3 Mediation before litigation

Before any lawsuit, the parties agree to a 30-day mediation period. A neutral mediator attempts to resolve the dispute. Costs are shared.


12. MISCELLANEOUS

12.1 Entire agreement

This agreement is the complete agreement between Customer and PMSPilot and replaces all prior agreements.

12.2 Severability

If any section is invalid, the remaining sections remain valid. The parties replace the invalid clause with a lawful alternative.

12.3 Amendments

PMSPilot may amend these terms. Changes are notified by email 30 days in advance. Continued use after 30 days constitutes acceptance. The Customer may terminate if they disagree.

12.4 Contact

Legal/Complaints: [email protected] Support: [email protected] Data Protection Officer (DPO): [email protected]

12.5 Language

These terms are available in German and English. In case of conflict, the German version prevails for EU customers.


ANNEX A: DATA PROCESSING AGREEMENT (DPA) UNDER GDPR ART. 28

Between: Customer (Controller) and PMSPilot / Koban Management LLC (Processor)

A.1 Processing instructions

The Processor (PMSPilot) processes data only on documented instructions of the Customer. Automatic instructions include:

  • Store reservations
  • Process guest data
  • Process payments
  • Generate reports
  • Create automatic backups

Further instructions must be in writing ([email protected]).

A.2 Processing details

ParameterDetails
Data subject categoriesGuests, employees, managing directors
Categories of personal dataNames, email, phone, address, payment info, reservation history, special needs
PurposeHotel management, payment processing, customer service, compliance
DurationWhile account is active + 7 years retention (invoices)
Nature and scopeStorage, retrieval, reporting, deletion, export
LocationUSA (AWS) + EU backups

A.3 Authority requests

If an authority (e.g. court, data protection authority) requests Customer data:

  1. PMSPilot informs the Customer immediately (unless prohibited)
  2. Legal review: PMSPilot checks whether the request is lawful
  3. Minimal disclosure: only requested data is disclosed
  4. Documentation: PMSPilot documents all requests

ACCEPTANCE

By registering on PMSPilot, the Customer confirms that they have fully read and accepted these terms.

Special notes:

  • The 14-day trial is free
  • After day 14 the Customer must actively activate and pay for a subscription (Stripe)
  • By paying, the Customer confirms that the trial constituted performance of a service
  • There is no refund after the first payment

Acceptance date: [Captured automatically upon registration] Customer company: _______________ Authorised person/email: _______________


© August 2026 Koban Management LLC. All rights reserved.

Terms of Service | PMSPilot