Named in Grant Thornton's 100 Ones to Watch 2026, their list of hospitality, retail and travel technology companies. See the list

Your guests' data stays your guests' data.

You are the data controller. We are your processor.

We run your guest journeys on your instructions, and do nothing else with what we learn.

Published in full

A current sub-processor list is available on request and under the DPA.

The relationship

We act on your instructions, for the purposes you set.

Under UK and EU data protection law you are the controller of your guests' personal data, and Biteluxe is your processor. Our Data Processing Agreement is published in full alongside our terms.

It covers processing scope and legal bases, help with data subject rights, sub-processor management, your audit rights, and the return or deletion of data when we stop working together.

What we send, and on what basis

We are stricter about messaging than the law requires.

Service messages relate to the guest's stay: check-in details, in-hotel reservations, stay updates. They are sent under contractual necessity and do not need separate opt-in.

Anything beyond service needs consent, and we cap it at two non-service messages from the point of booking. The cap is our own limit, because guest messaging goes wrong when guests feel pursued, and protecting your reputation matters more to us than the extra message.

Security

Named controls.

Access

  • Two-step verification on every staff inbox
  • Least-privilege, role-based access
  • Audit logs of who opened which conversation
  • Documented offboarding with access revoked

Data

  • Encryption in transit and at rest
  • Tested backups
  • Transfers outside the EEA only under Standard Contractual Clauses or an equivalent safeguard

Practice

  • Regular security audits, vulnerability assessments and penetration testing
  • A written incident response plan
  • Staff bound by confidentiality and trained on data protection
Card payments

Card details never reach your front desk or our systems.

Guests pay on their own phone, through the payment provider: yours if you already have one, or ours, which is PCI DSS Level 1 certified. The card details go from your guest to the payment provider and nowhere else.

The mobile inbox

The same inbox, under the same controls.

The app on iPhone and Android follows the same access rules, and accounts are revoked centrally when someone leaves. Where your policy does not allow guest data on personal phones, we can supply managed devices.

When something goes wrong

We tell you without undue delay.

If there is a breach we notify you promptly, with enough information for you to meet your own regulatory obligations. We carry cyber insurance, so the cost of a breach is covered.

An independent check

A certified compliance partner reviews how we handle your guests' data.

We work with a CIPP/E certified data compliance partner whose job is to find fault with how we handle guest data. The review covers our hotels too, so your obligations are looked at as well as ours.

Running a security review?

Send us your questionnaire.

We will answer it, and walk your IT or data protection lead through anything that needs a conversation.