Hotel data security

Understand how Peaqplus
handles hotel data.

Review data location, access controls, AI data handling, external service categories, and incident commitments before procurement.

This is a public summary, not a certification. Contractual scope is set out in the DPA and order form; current technical details are supplied during the security review.

Data protection

Where hotel data lives
and how access is controlled.

European hosting

Production hotel data is hosted in European data centres.

The current provider, legal entity, and applicable terms are supplied during the security and DPA review.
Protected connections

Browser and application traffic uses HTTPS. The PMS delivery route depends on the supported integration.

We confirm the connection method for your PMS during onboarding or the security review.
Stored data protection

Stored data is protected through infrastructure controls and application access restrictions.

We confirm the current storage and encryption controls during the security review.
Backups and recovery

Operational backups form part of the service continuity process.

Current retention and restore procedures are available for an authorised security review.
Access control

Role-based permissions and per-property data isolation limit what each account can see.

Authorised multi-property accounts can access only the hotels assigned to them.
Monitoring

Application error monitoring and server logs support operational and security investigation.

Response and communication depend on the scope and severity of the event.
GDPR

The rights, the role, the document trail.

Peaqplus operates as a data processor for hotel data; the hotel is the data controller. You decide why and how the data is used. We process it on your behalf for the contracted service.

GDPR contact
Requests (DPA, sub-processor list, data subject requests routed through us) → security@peaqplus.com
WHAT THAT MEANS IN PRACTICE
Data Processing Agreement (DPA)
The current DPA is available for review and can be signed with the customer agreement.
Data Subject Rights
We support guest data rectification, erasure, and export requests routed through your hotel team.
External service disclosure
The current provider list, locations, and applicable transfer safeguards are available for procurement and DPA review.
Data location
Production hotel data is stored in Europe. The AI provider receives anonymised, non-personal business data as described below.
Investigation records
Application and server records support operational or security investigations. The evidence available for a specific review depends on its scope.
AI specifics

What the AI sees,
what it doesn't, where it runs.

Peaqplus currently uses Anthropic for AI features. The provider may change among the providers named in our terms. Data is anonymised before it is sent, and the AI remains an advisory layer within the platform.

The data path · with visible boundaries
01
Hotel context
PMS data and snapshots
02
Access scope
Account and assigned hotel
03
Anonymise
Remove identifiers
04
AI provider
Current: Anthropic
05
Advisory output
Not an automatic decision
06
Human review
Your team makes the decision
Removed before the AI sees anything
  • Hotel / property name and brand
  • Guest personal data
  • Booking identifiers
  • Staff names
  • Internal credentials, API tokens
Bounded by the platform
  • AI output is advisory and should be reviewed by a person
  • Pulse AI is optional and active only with the relevant subscription
  • The AI does not make commercial decisions on the hotel's behalf
Scoped to your access
  • Account and property access rules apply before data is prepared
  • Conversation history is tied to the authenticated account and property context
  • Multi-property users see only the hotels assigned to their account
What's NOT used
  • Customer data is not used to train AI models
  • The AI provider's enterprise terms include a no-training clause for our usage
External services

Public summary and contractual provider list.

This summary names the current AI provider and the service categories involved. Legal names, locations, and transfer safeguards are supplied in the current provider list for procurement and DPA review. New personal-data sub-processors are notified in line with the contractual notice period.

Service or categoryPurposeData involvedDisclosure
Hosting provider
Infrastructure hostingContracted operational dataCurrent provider list / DPA
Anthropic
(current AI provider; receives anonymised, non-personal data)
Optional AI featuresAnonymised business metricsNamed publicly
Email delivery provider
Transactional emailRecipient address and message contentCurrent provider list / DPA
Sentry
Application error monitoringApplication error metadataCurrent provider list / DPA
When something goes wrong

The incident protocol, in three steps.

Customer-side responsibilities
  • Notify us before major PMS upgrades or maintenance windows
  • Maintain accurate contact info for the customer success contact
01
Detection and assessment

Monitoring signals and customer reports are assessed to identify the affected services, customers, and severity.

The response is prioritised by impact and scope.
02
Communication

A security incident affecting customer data is notified without undue delay in line with the DPA.

Operational updates use the agreed contact path and a cadence appropriate to the incident.
03
Follow-up

We document the cause and remediation after the incident has been contained.

A customer-facing summary is provided when appropriate or contractually required.
Contact

Questions, audits, DPAs, security reviews.

For security or privacy matters — DPA requests, sub-processor list, security questionnaires, customer-side audits, GDPR data subject requests routed through us — contact:

security@peaqplus.com

Include your property or account, the scope of the review, and any procurement deadline. We will route the request to the responsible team.

For demo or general sales: book a demo →