HospitalityOS

Privacy Policy

Last updated: Pending legal configuration

This is a structural legal template. Professional legal review is required before commercial launch. Jurisdiction-specific details, legal entity information, and registered addresses must be confirmed by qualified counsel.

1. Controller

Pending legal configuration: The legal entity acting as data controller, its registered address, and jurisdiction must be confirmed by qualified counsel before commercial launch.

2. Contact

Contact information for privacy enquiries must be confirmed before commercial launch. Until then, please use the contact form on our website.

3. Scope

This Privacy Policy explains how HospitalityOS collects, processes, and protects personal data across our website, demo/contact requests, and the HospitalityOS platform.

4. Website Data

We collect minimal data when you visit our website — necessary for the website to function, and optionally analytics data subject to your consent. See our Cookie Policy for details.

5. Account Data

When you create a HospitalityOS account, we process your name, email address, and role information necessary to provide the service.

6. Demo and Contact Requests

When you submit a demo or contact request, we process the information you provide — name, business email, company, property type, and your message — to respond to your enquiry.

7. HospitalityOS Platform Data

The HospitalityOS platform processes operational data — properties, reservations, guests, operations, commercial, and intelligence data — on behalf of the organizations that use the platform. We act as a processor for this data. See our DPA for details.

8. Guest Data Roles

Hospitality properties that use HospitalityOS may process guest data. The property organization is the controller for guest data. HospitalityOS provides tools to help properties manage guest data in compliance with applicable privacy laws.

9. Cookies

We use cookies for essential functionality and optional analytics. See our Cookie Policy for details and your choices.

10. Analytics

We use Google Analytics to understand website usage. Analytics are only activated with your consent — we do not activate analytics or marketing trackers before applicable consent. See our Cookie Policy for how to manage this choice.

11. Integrations

Where HospitalityOS connects to external systems (PMS, booking sources, providers), data may be shared with those systems. You authorize such connections. We enforce fail-closed behavior for unknown credentials.

12. Xperio3D

Xperio3D spatial data may include physical property measurements, layout, and materials. This data does not contain guest PII. Spatial facts are presented with appropriate provenance and confidence.

13. AI Processing

HospitalityOS may use AI-assisted features for recommendations and concierge functions. AI output may be incomplete or incorrect. Material decisions remain subject to human review. See our AI Policy for details.

14. Cross-Vertical Processing

Cross-vertical cooperation (with Y MarineOS, DestinationOS, VenueOS) requires explicit consent and defaults to OFF. Only the minimum necessary intent is shared — not customer databases.

15. Legal Bases

We process personal data based on: contract performance, legitimate interests, consent, and legal obligations where applicable. Specific legal bases are confirmed during legal review.

16. Retention

We retain personal data only as long as necessary for the purposes described, or as required by law. Specific retention periods are confirmed during legal review.

17. Recipients and Processors

We may use subprocessors to provide the service, including Google (Google Analytics) for website analytics, activated only with your consent. A full subprocessor list is maintained and available upon request. See our DPA for details.

18. International Transfers

Where data is transferred internationally, appropriate safeguards are applied. Specific mechanisms are confirmed during legal review.

19. Security

We implement appropriate technical and organizational measures to protect personal data. See our Security page for details.

20. Data Subject Rights

You have rights regarding your personal data — access, rectification, erasure, restriction, portability, and objection. Contact us to exercise these rights.

21. Deletion

You can request deletion of your data. See our Data Deletion page for details.

22. Complaints

You have the right to lodge a complaint with the competent data protection authority.

23. Policy Changes

We may update this Privacy Policy from time to time. Material changes will be communicated through appropriate channels.