Guest Data Is the Most
Sensitive Thing You Hold.
Identity documents, payment tokens, addresses, stay history. HotPilot is built so that data stays encrypted, stays inside your property boundary, and leaves a record every time somebody touches it.
The Problem
"We Take Security Seriously" Is Not an Answer
A hotel system holds identity documents, payment tokens and the movements of every guest who ever stayed. When a DPO, a bank or a corporate client asks how that data is protected, "it's in the cloud" does not survive the follow-up question — and under GDPR it is the hotel, not the vendor, that is the controller on the hook.
The Solution
Answers You Can Forward to Your DPO
Encryption at rest on every sensitive column, a property boundary enforced in the data layer rather than in each query, permissions defined across 153 discrete operations, and an audit trail that records who read what. Every claim on this page maps to a mechanism you can ask us to demonstrate.
PLATFORM SECURITY
What Actually Protects the Data
Encryption at Rest
Identity documents, payment credentials and integration secrets are encrypted in the database, not just on the disk underneath it.
Property Isolation
Every property is a hard boundary applied in the data layer, so one hotel's queries cannot reach another's rows even by mistake.
Role-Based Access
153 discrete operations, six preset roles and custom roles on top — staff see the screens their job needs and nothing else.
Audit Trail
Logins, PII reads, price changes, refunds and permission edits are recorded with the user, the timestamp and the IP.
No Card Numbers Stored
Card details go straight to your payment gateway. HotPilot keeps a token and a last-four, never a number that could leak.
EU Infrastructure
Data is hosted in the European Union on managed infrastructure, with transport encryption on every connection.
Backups & Recovery
Automated backups with point-in-time recovery, so an accident is an inconvenience rather than an incident.
Scoped AI Access
AI assistants act through the same permission system as a person — an AI cannot read what the signed-in role cannot read.
GDPR & PRIVACY
The Paperwork, Already Done
Lawful Basis Mapped
Every category of personal data we process is documented with its purpose and legal basis in our data inventory.
Data Processing Agreement
You are the controller, HotPilot is the processor. A DPA is available and forms part of the contract.
Consent & Cookies
A consent banner on every tenant site gates analytics and marketing tags per category until the visitor agrees.
Right to Erasure
Guest data can be deleted or anonymised on request, including in the systems it was synced into.
Retention Schedule
Each data category has a defined retention period, applied automatically rather than left to somebody's diary.
Subprocessor Register
Every third party that touches data is listed publicly, with what it does and where it operates.
Statutory Guest Registers
Bulgarian, Greek and Turkish guest-registration exports are generated from the same data, in the format each authority expects.
Breach Procedure
A defined notification path, so a 72-hour regulatory clock is met by a process rather than by improvisation.
Features
See It — Don't Take Our Word for It
Housekeeping Should Not See Revenue
Six preset roles cover the usual hotel structure, and each grants a precise subset of 153 operations. Duplicate a preset, adjust it, assign it — a receptionist gets 32 operations, housekeeping gets 10, and nobody has to be trusted not to click the wrong screen.
Who Read That Guest's Record, and When
Logins, booking-list views, price changes, discounts and refunds are written to a log with the user, timestamp, IP and a structured record of what changed. When a guest asks who accessed their data, the answer is a filter rather than an investigation.
An AI Assistant With the Same Permissions as a Person
HotPilot's assistants connect through a scoped endpoint where every action is limited to what the signed-in role may do in the admin. Tokens are minted per client and revocable in one click, and AI actions land in the same audit trail as human ones.
Housekeeping Should Not See Revenue
Six preset roles cover the usual hotel structure, and each grants a precise subset of 153 operations. Duplicate a preset, adjust it, assign it — a receptionist gets 32 operations, housekeeping gets 10, and nobody has to be trusted not to click the wrong screen.
Who Read That Guest's Record, and When
Logins, booking-list views, price changes, discounts and refunds are written to a log with the user, timestamp, IP and a structured record of what changed. When a guest asks who accessed their data, the answer is a filter rather than an investigation.
An AI Assistant With the Same Permissions as a Person
HotPilot's assistants connect through a scoped endpoint where every action is limited to what the signed-in role may do in the admin. Tokens are minted per client and revocable in one click, and AI actions land in the same audit trail as human ones.
THE DOCUMENTS
Privacy Policy, Terms, Cookies and Subprocessors
The full legal set is public — including the list of every subprocessor that touches data and what each one is used for.
FAQ
Frequently Asked Questions
Everything you need to know about security and compliance at HotPilot.
Online
On managed infrastructure in the European Union, with encryption in transit on every connection and encryption at rest for sensitive fields. If you need the specific region or provider named for a due-diligence questionnaire, ask and we will put it in writing.
Online
Yes. You remain the data controller and HotPilot acts as processor under a DPA. We maintain a data inventory mapping every category of personal data to its purpose, legal basis and retention period, plus a public subprocessor register.
Online
No. Card details are captured by your payment gateway and never reach our database. We keep a gateway token and the last four digits so staff can identify a card — there is no card number in our systems to lose.
Online
No. The property boundary is enforced in the data layer, so it applies to every query in the platform instead of depending on each developer remembering to add a filter. Multi-property groups can be given deliberate cross-property access; nothing is shared by default.
Online
Logins, reads of personal data such as the booking list, price changes, discounts, refunds, permission edits and integration changes — each with the user, timestamp, IP and a structured record of what changed. Entries are filterable by user, action and date.
Online
Guest records can be exported or erased on request, including anonymisation where a booking has to remain for accounting purposes. Retention rules also run automatically, so data does not linger past its defined period while somebody waits for a request.
Online
Yes. We are happy to complete vendor questionnaires, walk your team through the architecture, and provide the data inventory, the DPA and the subprocessor list. Get in touch and we will start with whatever your process needs.
Ready to Answer
the Hard Questions?
Get the data inventory, the DPA and the subprocessor list — plus a walkthrough of how the platform protects your guests.