01 / 03Data Privacy

Data Privacy

How your operational data is processed.

This document explains how Prostay handles the operational data your property creates day to day: reservations, folios, payments, messaging history and any guest profile information you capture inside the product.

Last updated
April 22, 2026
Effective date
May 1, 2026

You are the controller of your operational data. Prostay is the processor. The Data Processing Addendum (DPA) is annexed to your subscription agreement and is summarised in plain English on this page.

Section 01

Roles

  • You (the property or hotel group) are the data controller for the guest data you process through Prostay.
  • Prostay Limited is the data processor. We process the data only on your documented instructions.

Section 02

What we process on your behalf

  • Reservations and folio postings.
  • Guest contact data (name, email, phone, country) and ID references where you choose to capture them.
  • Payment events and tokenised payment methods (card numbers themselves never reach our servers).
  • Messaging history with guests on connected channels.
  • Internal notes, tasks and audit log entries.

Section 03

Sub-processors

We rely on a small set of vetted sub-processors to deliver Prostay. They are listed in the table inside the product (Settings → Trust → Sub-processors) and we notify you 30 days before any change.

Section 04

International transfers

We host customer data in the EU (Frankfurt) by default. Where data is transferred outside the EU/UK to a sub-processor, we rely on the European Commission Standard Contractual Clauses and apply additional technical and organisational measures.

Section 05

Security controls

  • Encryption in transit (TLS 1.2+) and at rest (AES-256).
  • Tenant isolation at the database level. No shared production credentials.
  • Continuous logging and immutable audit trails for sensitive actions.
  • Annual third-party penetration tests and ongoing vulnerability scanning.

Section 06

Incident response

In the event of a security incident affecting your data, we notify your designated contact within 72 hours of confirmation, with the facts known at the time, an initial impact assessment and a remediation plan.

Section 07

Helping you respond to data subject requests

When a guest asks you to access, correct or delete their data, you can self-serve from inside the product. We provide a guided workflow that finds every record across reservations, messages, folio history and the audit log.

If you need help, write to office@prostay.com and our DPO will assist within 5 business days.

03 / 03Get in touch

A real human reviews every legal request.

If you have a question about this Data Privacy notice or want to exercise a right under it, write to us. We answer within five business days.