Data Privacy
How your operational data is processed.
This document explains how Prostay handles the operational data your property creates day to day: reservations, folios, payments, messaging history and any guest profile information you capture inside the product.
- Last updated
- April 22, 2026
- Effective date
- May 1, 2026
- Questions
- office@prostay.com
You are the controller of your operational data. Prostay is the processor. The Data Processing Addendum (DPA) is annexed to your subscription agreement and is summarised in plain English on this page.
Section 01
Roles
- You (the property or hotel group) are the data controller for the guest data you process through Prostay.
- Prostay Limited is the data processor. We process the data only on your documented instructions.
Section 02
What we process on your behalf
- Reservations and folio postings.
- Guest contact data (name, email, phone, country) and ID references where you choose to capture them.
- Payment events and tokenised payment methods (card numbers themselves never reach our servers).
- Messaging history with guests on connected channels.
- Internal notes, tasks and audit log entries.
Section 03
Sub-processors
We rely on a small set of vetted sub-processors to deliver Prostay. They are listed in the table inside the product (Settings → Trust → Sub-processors) and we notify you 30 days before any change.
Section 04
International transfers
We host customer data in the EU (Frankfurt) by default. Where data is transferred outside the EU/UK to a sub-processor, we rely on the European Commission Standard Contractual Clauses and apply additional technical and organisational measures.
Section 05
Security controls
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Tenant isolation at the database level. No shared production credentials.
- Continuous logging and immutable audit trails for sensitive actions.
- Annual third-party penetration tests and ongoing vulnerability scanning.
Section 06
Incident response
In the event of a security incident affecting your data, we notify your designated contact within 72 hours of confirmation, with the facts known at the time, an initial impact assessment and a remediation plan.
Section 07
Helping you respond to data subject requests
When a guest asks you to access, correct or delete their data, you can self-serve from inside the product. We provide a guided workflow that finds every record across reservations, messages, folio history and the audit log.
If you need help, write to office@prostay.com and our DPO will assist within 5 business days.
A real human reviews every legal request.
If you have a question about this Data Privacy notice or want to exercise a right under it, write to us. We answer within five business days.