Your guests' data stays your guests' data.
You are the data controller. We are your processor.
We run your guest journeys on your instructions, and do nothing else with what we learn.
Published in full
A current sub-processor list is available on request and under the DPA.
We act on your instructions, for the purposes you set.
Under UK and EU data protection law you are the controller of your guests' personal data, and Biteluxe is your processor. Our Data Processing Agreement is published in full alongside our terms.
It covers processing scope and legal bases, help with data subject rights, sub-processor management, your audit rights, and the return or deletion of data when we stop working together.
We are stricter about messaging than the law requires.
Service messages relate to the guest's stay: check-in details, in-hotel reservations, stay updates. They are sent under contractual necessity and do not need separate opt-in.
Anything beyond service needs consent, and we cap it at two non-service messages from the point of booking. The cap is our own limit, because guest messaging goes wrong when guests feel pursued, and protecting your reputation matters more to us than the extra message.
Named controls.
Access
- Two-step verification on every staff inbox
- Least-privilege, role-based access
- Audit logs of who opened which conversation
- Documented offboarding with access revoked
Data
- Encryption in transit and at rest
- Tested backups
- Transfers outside the EEA only under Standard Contractual Clauses or an equivalent safeguard
Practice
- Regular security audits, vulnerability assessments and penetration testing
- A written incident response plan
- Staff bound by confidentiality and trained on data protection
Card details never reach your front desk or our systems.
Guests pay on their own phone, through the payment provider: yours if you already have one, or ours, which is PCI DSS Level 1 certified. The card details go from your guest to the payment provider and nowhere else.
The same inbox, under the same controls.
The app on iPhone and Android follows the same access rules, and accounts are revoked centrally when someone leaves. Where your policy does not allow guest data on personal phones, we can supply managed devices.
We tell you without undue delay.
If there is a breach we notify you promptly, with enough information for you to meet your own regulatory obligations. We carry cyber insurance, so the cost of a breach is covered.
A certified compliance partner reviews how we handle your guests' data.
We work with a CIPP/E certified data compliance partner whose job is to find fault with how we handle guest data. The review covers our hotels too, so your obligations are looked at as well as ours.
Send us your questionnaire.
We will answer it, and walk your IT or data protection lead through anything that needs a conversation.