Skip to content
verified_user SECURITY & COMPLIANCE

Guest Data Is the Most
Sensitive Thing You Hold.

Identity documents, payment tokens, addresses, stay history. HotPilot is built so that data stays encrypted, stays inside your property boundary, and leaves a record every time somebody touches it.

GDPR compliant EU hosting 100% PII access logged

The Problem

"We Take Security Seriously" Is Not an Answer

A hotel system holds identity documents, payment tokens and the movements of every guest who ever stayed. When a DPO, a bank or a corporate client asks how that data is protected, "it's in the cloud" does not survive the follow-up question — and under GDPR it is the hotel, not the vendor, that is the controller on the hook.

shield

The Solution

Answers You Can Forward to Your DPO

Encryption at rest on every sensitive column, a property boundary enforced in the data layer rather than in each query, permissions defined across 153 discrete operations, and an audit trail that records who read what. Every claim on this page maps to a mechanism you can ask us to demonstrate.

check_circle Sensitive fields encrypted at rest
check_circle Property isolation enforced platform-wide
check_circle Role-based access across 153 operations
check_circle Audit trail on PII reads and money changes

PLATFORM SECURITY

What Actually Protects the Data

lock

Encryption at Rest

Identity documents, payment credentials and integration secrets are encrypted in the database, not just on the disk underneath it.

domain_disabled

Property Isolation

Every property is a hard boundary applied in the data layer, so one hotel's queries cannot reach another's rows even by mistake.

admin_panel_settings

Role-Based Access

153 discrete operations, six preset roles and custom roles on top — staff see the screens their job needs and nothing else.

history

Audit Trail

Logins, PII reads, price changes, refunds and permission edits are recorded with the user, the timestamp and the IP.

credit_card_off

No Card Numbers Stored

Card details go straight to your payment gateway. HotPilot keeps a token and a last-four, never a number that could leak.

cloud_done

EU Infrastructure

Data is hosted in the European Union on managed infrastructure, with transport encryption on every connection.

settings_backup_restore

Backups & Recovery

Automated backups with point-in-time recovery, so an accident is an inconvenience rather than an incident.

smart_toy

Scoped AI Access

AI assistants act through the same permission system as a person — an AI cannot read what the signed-in role cannot read.

GDPR & PRIVACY

The Paperwork, Already Done

gavel

Lawful Basis Mapped

Every category of personal data we process is documented with its purpose and legal basis in our data inventory.

handshake

Data Processing Agreement

You are the controller, HotPilot is the processor. A DPA is available and forms part of the contract.

cookie

Consent & Cookies

A consent banner on every tenant site gates analytics and marketing tags per category until the visitor agrees.

person_off

Right to Erasure

Guest data can be deleted or anonymised on request, including in the systems it was synced into.

schedule

Retention Schedule

Each data category has a defined retention period, applied automatically rather than left to somebody's diary.

groups

Subprocessor Register

Every third party that touches data is listed publicly, with what it does and where it operates.

assured_workload

Statutory Guest Registers

Bulgarian, Greek and Turkish guest-registration exports are generated from the same data, in the format each authority expects.

travel_explore

Breach Procedure

A defined notification path, so a 72-hour regulatory clock is met by a process rather than by improvisation.

Features

See It — Don't Take Our Word for It

01 Role-Based Access Control

Housekeeping Should Not See Revenue

Six preset roles cover the usual hotel structure, and each grants a precise subset of 153 operations. Duplicate a preset, adjust it, assign it — a receptionist gets 32 operations, housekeeping gets 10, and nobody has to be trusted not to click the wrong screen.

Six presets plus unlimited custom roles
153 individually grantable operations
The same permissions applied to AI assistants
HotPilot Role-Based Access Control
02 Audit Trail

Who Read That Guest's Record, and When

Logins, booking-list views, price changes, discounts and refunds are written to a log with the user, timestamp, IP and a structured record of what changed. When a guest asks who accessed their data, the answer is a filter rather than an investigation.

PII reads logged, not only writes
Every money movement recorded
Filter by user, action and date range
HotPilot Audit Trail
03 AI Boundaries

An AI Assistant With the Same Permissions as a Person

HotPilot's assistants connect through a scoped endpoint where every action is limited to what the signed-in role may do in the admin. Tokens are minted per client and revocable in one click, and AI actions land in the same audit trail as human ones.

AI actions bounded by the user's role
Per-client tokens, revocable instantly
AI activity in the same audit trail
HotPilot AI Boundaries
policy

THE DOCUMENTS

Privacy Policy, Terms, Cookies and Subprocessors

The full legal set is public — including the list of every subprocessor that touches data and what each one is used for.

FAQ

Frequently Asked Questions

Everything you need to know about security and compliance at HotPilot.

On managed infrastructure in the European Union, with encryption in transit on every connection and encryption at rest for sensitive fields. If you need the specific region or provider named for a due-diligence questionnaire, ask and we will put it in writing.

Yes. You remain the data controller and HotPilot acts as processor under a DPA. We maintain a data inventory mapping every category of personal data to its purpose, legal basis and retention period, plus a public subprocessor register.

No. Card details are captured by your payment gateway and never reach our database. We keep a gateway token and the last four digits so staff can identify a card — there is no card number in our systems to lose.

No. The property boundary is enforced in the data layer, so it applies to every query in the platform instead of depending on each developer remembering to add a filter. Multi-property groups can be given deliberate cross-property access; nothing is shared by default.

Logins, reads of personal data such as the booking list, price changes, discounts, refunds, permission edits and integration changes — each with the user, timestamp, IP and a structured record of what changed. Entries are filterable by user, action and date.

Guest records can be exported or erased on request, including anonymisation where a booking has to remain for accounting purposes. Retention rules also run automatically, so data does not linger past its defined period while somebody waits for a request.

Yes. We are happy to complete vendor questionnaires, walk your team through the architecture, and provide the data inventory, the DPA and the subprocessor list. Get in touch and we will start with whatever your process needs.

Ready to Answer
the Hard Questions?

Get the data inventory, the DPA and the subprocessor list — plus a walkthrough of how the platform protects your guests.