Developing personalize our customer journeys to increase satisfaction & loyalty of our expansion recognized by industry leaders.

Search Now!
Contact Info
LocationKingsbridge Avenue
Newcastle, United Kingdom.
Follow Us
Contact Info
LocationKingsbridge Avenue
Newcastle, United Kingdom.
Follow Us
EU GDPR (2016/679) ePrivacy Directive UK Data Protection Act

Privacy Policy & EU Consent

Comprehensive transparency regarding how HotelMate Ltd processes personal data, protects privacy rights, and guarantees uncompromised, freely revocable consent across the European Economic Area (EEA), the United Kingdom, and globally.

Effective Date: September 2026· Version: 3.2 (EU Consent Aligned)· Jurisdiction: EEA & UK
Manage EU Consent
01

Overview & EU Legal Framework

Welcome to the official EU Privacy and Data Protection Policy for HotelMate Ltd ("HotelMate", "we", "us", or "our"). HotelMate delivers an all-in-one, AI-powered hospitality management ecosystem, comprising our Property Management System (PMS), Booking Engine, Channel Manager, Point of Sale (POS), Guest Self-Service portal, Housekeeping coordination, Accounting, and Customer Relationship Management (CRM).

We operate in strict adherence with European privacy standards, notably:

EU General Data Protection Regulation

Regulation (EU) 2016/679 (GDPR) enforcing data subject rights, strict legal bases, transparency, and accountability.

ePrivacy Directive & EDPB Guidelines

Directive 2002/58/EC (amended by 2009/136/EC) and EDPB Guidelines 05/2020 on active, opt-in consent for non-essential cookies.

UK GDPR & Data Protection Act 2018

Retained UK privacy legislation overseen by the Information Commissioner's Office (ICO).

03

Data Controller & Data Protection Officer (DPO)

For the personal data collected through this corporate website and for account administrative contacts of subscribing hotels, the designated Data Controller is:

Legal Entity:
HotelMate Ltd
Corporate Address:
Kingsbridge Avenue, Newcastle, United Kingdom
Data Protection Officer:
R&D Center:
241/1, Pipe Road, Koswatta, Battaramulla, Sri Lanka

Our Data Protection Officer monitors ongoing GDPR compliance, conducts Data Protection Impact Assessments (DPIAs) for new AI feature releases, and serves as the primary contact for EU data subjects and European supervisory authorities.

04

Dual Role Architecture: Controller vs. Processor

To maintain absolute transparency under GDPR Article 28, HotelMate distinguishes between two distinct capacities in which personal data is processed:

HotelMate as Data Controller
  • Whose data: Website visitors, hotel property owners creating trial accounts, newsletter subscribers, webinar attendees, and prospective business partners.
  • Purposes: Invoicing, billing, license management, platform security, client support communications, and legal compliance.
  • Governing terms: This Privacy Policy and our Terms of Service.
HotelMate as Data Processor
  • Whose data: Hotel guests whose booking records, room assignments, folios, and POS orders are inputted into HotelMate by our subscribing hotel clients.
  • Role of the Hotel: The hotel or resort is the Data Controller who determines why and how guest data is processed.
  • Our Commitment: We process guest data solely on the documented instructions of the hotel under a binding Data Processing Addendum (DPA) meeting GDPR Article 28 standards.
07

Categories of Personal Data Collected

We collect only the minimum personal data necessary to achieve the designated purposes:

  • Identity & Contact Data: First name, last name, hotel/property name, job title, corporate email address, telephone number, and communication records when inquiring via our contact forms.
  • Technical & Telemetry Data: Internet Protocol (IP) address, browser family and version, operating system, screen resolution, referral URLs, request timestamps, and anonymized user interaction events.
  • Financial & Transaction Data: Invoices, payment confirmation IDs, and billing addresses.Note: Payment card details are processed directly by certified PCI-DSS Level 1 payment processors and are never stored on HotelMate servers.
  • Guest Data (Processed on Behalf of Hotels): Names, stay dates, passport/ID details where mandated by local hospitality laws, room choices, and meal preferences. This data is subject to the hotel's own privacy notice and our Processor DPA.
09

Third-Party Service Providers & Sub-processors

To deliver high availability and enterprise-grade reliability, HotelMate engages carefully vetted third-party sub-processors bound by strict confidentiality and data protection agreements under GDPR Article 28:

Amazon Web Services (AWS)
EU-West (Ireland & London)

Encrypted primary database storage, cloud infrastructure, and backup management.

Vercel Inc.
Global Edge Network

Frontend hosting, serverless compute execution, and edge content delivery.

PCI-DSS Payment Gateways
Stripe / PayHere / Adyen

Tokenized payment processing conforming to Level 1 PCI-DSS security standards.

Tawk.to Live Chat
Customer Support

Real-time conversational messaging and inquiry ticket generation.

10

International Data Transfers & Standard Contractual Clauses

HotelMate operates its primary European infrastructure within EEA data centers (such as AWS Frankfurt and AWS Ireland). Where personal data is accessed or transferred outside the European Economic Area (for instance, to our specialized R&D center in Sri Lanka or cloud vendor personnel), we ensure an equivalent standard of protection through:

European Commission Standard Contractual Clauses (SCCs): Module 1 (Controller to Controller) and Module 2 (Controller to Processor) execution pursuant to Commission Implementing Decision (EU) 2021/914.
UK International Data Transfer Addendum (IDTA): For data transfers subject to UK GDPR.
Supplementary Technical Safeguards: Mandatory TLS 1.3 transit encryption, AES-256 data-at-rest encryption, and strict role-based access control preventing unapproved surveillance access.
11

Your GDPR Data Subject Rights (Articles 15–22)

Under Chapter III of the GDPR, European and UK residents possess powerful, enforceable legal rights:

Art. 15 Right of Access

Obtain confirmation as to whether your data is being processed, and receive a complete copy in an intelligible format.

Art. 16 Right to Rectification

Demand immediate correction of inaccurate or incomplete personal records without undue delay.

Art. 17 Right to Erasure

Also known as the "Right to be Forgotten". Request complete deletion when data is no longer necessary or consent is revoked.

Art. 18 Restriction of Processing

Temporarily pause active processing while data accuracy or legitimate grounds are contested.

Art. 20 Data Portability

Receive your personal data in a structured, commonly used, machine-readable format (e.g. JSON/CSV) to transmit to another vendor.

Art. 21 Right to Object

Object to processing based on legitimate interests or direct marketing at any time. We will cease processing immediately.

12

Exercise Your Rights (Data Subject Request Portal)

We respond to all verified requests within one calendar month as mandated by GDPR Article 12(3). You may submit a request directly through this form or email us at privacy@hotelmate.co.uk.

13

Technical & Organizational Security Measures (Art. 32)

In accordance with GDPR Article 32, HotelMate implements comprehensive state-of-the-art security mechanisms calibrated to risk levels:

TLS 1.3 & AES-256

End-to-end encryption in transit and AES-256 for persistent database storage.

Role-Based Access Control

Principle of least privilege (PoLP) with multi-factor authentication (MFA) enforcement.

Vulnerability Audits

Continuous automated code scanning, dependency monitoring, and independent pentesting.

Daily Geo-Replicated Backups

Disaster recovery testing with encrypted snapshots isolated from production.

14

Data Retention & Erasure Schedules

We do not retain personal data longer than necessary for the purposes for which it was gathered. Typical schedules include:

  • Website Consent Preferences: Retained in your local browser storage for 12 months, after which re-confirmation is requested.
  • Sales & Demo Inquiries: Retained for 24 months following the last active communication, unless a customer contract is signed or deletion is requested earlier.
  • Client Contract & Billing Records: Retained for 7 years post-contract termination pursuant to statutory tax and financial audit requirements.
  • Server Security & Access Logs: Retained on rolling 90-day automated purge cycles.
15

Lodging a Complaint with a Supervisory Authority

If you believe that our processing of your personal data infringes European or UK privacy regulations, you have the statutory right under GDPR Article 77 to lodge a formal complaint with a competent Data Protection Authority (DPA), in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement:

European Data Protection Board (EDPB)

Provides access to all 27 EU National Data Protection Authorities.

Visit EDPB Directory
United Kingdom Information Commissioner's Office (ICO)

Supervisory authority for HotelMate Ltd corporate operations in the UK.

ico.org.uk
Direct Resolution with HotelMate

We invite you to reach out to our dedicated privacy desk first so we can resolve any concern promptly.

privacy@hotelmate.co.uk
16

Policy Amendments & Version History

We review this Privacy Policy periodically to reflect technological advances, new HotelMate module launches, and evolving European case law. Any material change will be announced via an update banner on our site or by direct notification to active account administrators prior to taking effect.

Version 3.2 (Current): September 2026 — Enhanced interactive EU Consent Management Center, re-aligned EDPB guidelines, and explicit dual-role disclosures.
Version 3.1: March 2025 — Updated AWS Frankfurt data transfer documentation and SCC references.
Version 3.0: January 2024 — Comprehensive GDPR compliance overhaul for multi-module PMS platform.