EU GDPR (2016/679) ePrivacy Directive UK Data Protection Act
Privacy Policy & EU Consent
Comprehensive transparency regarding how HotelMate Ltd processes personal data, protects privacy rights, and guarantees uncompromised, freely revocable consent across the European Economic Area (EEA), the United Kingdom, and globally.
Effective Date: September 2026·Version: 3.2 (EU Consent Aligned)·Jurisdiction: EEA & UK
Welcome to the official EU Privacy and Data Protection Policy for HotelMate Ltd ("HotelMate", "we", "us", or "our"). HotelMate delivers an all-in-one, AI-powered hospitality management ecosystem, comprising our Property Management System (PMS), Booking Engine, Channel Manager, Point of Sale (POS), Guest Self-Service portal, Housekeeping coordination, Accounting, and Customer Relationship Management (CRM).
We operate in strict adherence with European privacy standards, notably:
EU General Data Protection Regulation
Regulation (EU) 2016/679 (GDPR) enforcing data subject rights, strict legal bases, transparency, and accountability.
ePrivacy Directive & EDPB Guidelines
Directive 2002/58/EC (amended by 2009/136/EC) and EDPB Guidelines 05/2020 on active, opt-in consent for non-essential cookies.
UK GDPR & Data Protection Act 2018
Retained UK privacy legislation overseen by the Information Commissioner's Office (ICO).
02
EU Consent & Cookie Preferences Center
In compliance with GDPR Article 7(3) and the ePrivacy Directive, you have the fundamental right to withdraw or modify your consent at any time as easily as you granted it. Below is your live consent configuration. Any change you save takes effect immediately.
Your Real-Time Consent Status
Anonymous Consent Reference: HM-EU-INIT · Last Updated: 9/29/2026 at 7:42:05 PM
Customized Preferences
Strictly Necessary Cookies & Core Processing
Always Active
Required for platform security, load balancing, user authentication, CSRF token validation, and storing your consent preferences. These cookies cannot be deactivated under EU law.
Functional & Preference Cookies
Optional
Enables enhanced functionality such as preserving your chosen language, regional date/time formatting, preferred hotel property modules, and live chat widget session retention.
Analytics & Performance Metrics
Optional
Allows us to monitor aggregated traffic patterns, identify page speed bottlenecks, and improve usability. All IP addresses are anonymized before transmission; no profiling is executed.
Marketing & Partnership Attribution
Optional
Evaluates the effectiveness of educational webinar campaigns and partner referral programs. HotelMate never sells your data to third-party ad brokers or data brokers.
Changes take immediate effect in this browser session.
03
Data Controller & Data Protection Officer (DPO)
For the personal data collected through this corporate website and for account administrative contacts of subscribing hotels, the designated Data Controller is:
241/1, Pipe Road, Koswatta, Battaramulla, Sri Lanka
Our Data Protection Officer monitors ongoing GDPR compliance, conducts Data Protection Impact Assessments (DPIAs) for new AI feature releases, and serves as the primary contact for EU data subjects and European supervisory authorities.
04
Dual Role Architecture: Controller vs. Processor
To maintain absolute transparency under GDPR Article 28, HotelMate distinguishes between two distinct capacities in which personal data is processed:
HotelMate as Data Controller
Whose data: Website visitors, hotel property owners creating trial accounts, newsletter subscribers, webinar attendees, and prospective business partners.
Purposes: Invoicing, billing, license management, platform security, client support communications, and legal compliance.
Governing terms: This Privacy Policy and our Terms of Service.
HotelMate as Data Processor
Whose data: Hotel guests whose booking records, room assignments, folios, and POS orders are inputted into HotelMate by our subscribing hotel clients.
Role of the Hotel: The hotel or resort is the Data Controller who determines why and how guest data is processed.
Our Commitment: We process guest data solely on the documented instructions of the hotel under a binding Data Processing Addendum (DPA) meeting GDPR Article 28 standards.
05
Lawful Grounds for Processing (GDPR Articles 6 & 9)
Under the European General Data Protection Regulation, every instance of personal data processing must be backed by an articulated legal basis under Article 6:
Art. 6(1)(a) Consent or Soft Opt-in under ePrivacy
06
Specific Rules for EU Consent (Article 7 & EDPB)
Whenever processing is grounded in your consent, HotelMate satisfies the strict standards outlined in GDPR Article 4(11), Article 7, and the European Data Protection Board (EDPB) Guidelines 05/2020:
01
Freely Given
No cookie walls or forced consent. You can fully browse and access our educational resources without accepting non-essential cookies.
02
Specific & Informed
Consent is granularly separated into distinct purposes (Preferences, Analytics, Marketing) rather than bundled into a single checkbox.
03
Unambiguous Affirmative Action
We do not use pre-ticked checkboxes or infer consent from continued scrolling. Explicit user clicks are required.
04
Easily Revocable
You may reopen your preferences anytime using the persistent "EU Privacy & Cookies" floating badge or through Section 02 above.
07
Categories of Personal Data Collected
We collect only the minimum personal data necessary to achieve the designated purposes:
Identity & Contact Data: First name, last name, hotel/property name, job title, corporate email address, telephone number, and communication records when inquiring via our contact forms.
Technical & Telemetry Data: Internet Protocol (IP) address, browser family and version, operating system, screen resolution, referral URLs, request timestamps, and anonymized user interaction events.
Financial & Transaction Data: Invoices, payment confirmation IDs, and billing addresses.Note: Payment card details are processed directly by certified PCI-DSS Level 1 payment processors and are never stored on HotelMate servers.
Guest Data (Processed on Behalf of Hotels): Names, stay dates, passport/ID details where mandated by local hospitality laws, room choices, and meal preferences. This data is subject to the hotel's own privacy notice and our Processor DPA.
08
Cookies & Tracking Technologies Disclosures
Below is the transparent audit of cookies and local storage tokens utilized across our web application:
Cookie Name
Provider
Purpose
Category
Duration
hotelmate_eu_consent_v1
HotelMate
Records your EU cookie and GDPR consent preferences
Necessary
1 Year
__cf_bm / csrf_token
HotelMate / Cloudflare
Protects forms and API endpoints against CSRF attacks and automated bot abuse
Necessary
Session / 30 mins
hotelmate_lang
HotelMate
Preserves chosen language and locale settings across visits
Functional
6 Months
twk_*
Tawk.to
Maintains live customer support chat continuity and message queue
Functional
Session / 3 Months
_ga, _ga_*
Google Analytics (EU Anonymized)
Aggregated traffic analytics with mandatory IP masking enabled
Analytics
14 Months
_va_analytics
Vercel Analytics
Anonymous page latency and Core Web Vitals performance tracking
Analytics
30 Days
09
Third-Party Service Providers & Sub-processors
To deliver high availability and enterprise-grade reliability, HotelMate engages carefully vetted third-party sub-processors bound by strict confidentiality and data protection agreements under GDPR Article 28:
Amazon Web Services (AWS)
EU-West (Ireland & London)
Encrypted primary database storage, cloud infrastructure, and backup management.
Vercel Inc.
Global Edge Network
Frontend hosting, serverless compute execution, and edge content delivery.
PCI-DSS Payment Gateways
Stripe / PayHere / Adyen
Tokenized payment processing conforming to Level 1 PCI-DSS security standards.
Tawk.to Live Chat
Customer Support
Real-time conversational messaging and inquiry ticket generation.
10
International Data Transfers & Standard Contractual Clauses
HotelMate operates its primary European infrastructure within EEA data centers (such as AWS Frankfurt and AWS Ireland). Where personal data is accessed or transferred outside the European Economic Area (for instance, to our specialized R&D center in Sri Lanka or cloud vendor personnel), we ensure an equivalent standard of protection through:
European Commission Standard Contractual Clauses (SCCs): Module 1 (Controller to Controller) and Module 2 (Controller to Processor) execution pursuant to Commission Implementing Decision (EU) 2021/914.
UK International Data Transfer Addendum (IDTA): For data transfers subject to UK GDPR.
Supplementary Technical Safeguards: Mandatory TLS 1.3 transit encryption, AES-256 data-at-rest encryption, and strict role-based access control preventing unapproved surveillance access.
11
Your GDPR Data Subject Rights (Articles 15–22)
Under Chapter III of the GDPR, European and UK residents possess powerful, enforceable legal rights:
Art. 15 Right of Access
Obtain confirmation as to whether your data is being processed, and receive a complete copy in an intelligible format.
Art. 16 Right to Rectification
Demand immediate correction of inaccurate or incomplete personal records without undue delay.
Art. 17 Right to Erasure
Also known as the "Right to be Forgotten". Request complete deletion when data is no longer necessary or consent is revoked.
Art. 18 Restriction of Processing
Temporarily pause active processing while data accuracy or legitimate grounds are contested.
Art. 20 Data Portability
Receive your personal data in a structured, commonly used, machine-readable format (e.g. JSON/CSV) to transmit to another vendor.
Art. 21 Right to Object
Object to processing based on legitimate interests or direct marketing at any time. We will cease processing immediately.
12
Exercise Your Rights (Data Subject Request Portal)
We respond to all verified requests within one calendar month as mandated by GDPR Article 12(3). You may submit a request directly through this form or email us at privacy@hotelmate.co.uk.
In accordance with GDPR Article 32, HotelMate implements comprehensive state-of-the-art security mechanisms calibrated to risk levels:
TLS 1.3 & AES-256
End-to-end encryption in transit and AES-256 for persistent database storage.
Role-Based Access Control
Principle of least privilege (PoLP) with multi-factor authentication (MFA) enforcement.
Vulnerability Audits
Continuous automated code scanning, dependency monitoring, and independent pentesting.
Daily Geo-Replicated Backups
Disaster recovery testing with encrypted snapshots isolated from production.
14
Data Retention & Erasure Schedules
We do not retain personal data longer than necessary for the purposes for which it was gathered. Typical schedules include:
Website Consent Preferences: Retained in your local browser storage for 12 months, after which re-confirmation is requested.
Sales & Demo Inquiries: Retained for 24 months following the last active communication, unless a customer contract is signed or deletion is requested earlier.
Client Contract & Billing Records: Retained for 7 years post-contract termination pursuant to statutory tax and financial audit requirements.
Server Security & Access Logs: Retained on rolling 90-day automated purge cycles.
15
Lodging a Complaint with a Supervisory Authority
If you believe that our processing of your personal data infringes European or UK privacy regulations, you have the statutory right under GDPR Article 77 to lodge a formal complaint with a competent Data Protection Authority (DPA), in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement:
European Data Protection Board (EDPB)
Provides access to all 27 EU National Data Protection Authorities.
We review this Privacy Policy periodically to reflect technological advances, new HotelMate module launches, and evolving European case law. Any material change will be announced via an update banner on our site or by direct notification to active account administrators prior to taking effect.
Version 3.2 (Current): September 2026 — Enhanced interactive EU Consent Management Center, re-aligned EDPB guidelines, and explicit dual-role disclosures.
Version 3.1: March 2025 — Updated AWS Frankfurt data transfer documentation and SCC references.
Version 3.0: January 2024 — Comprehensive GDPR compliance overhaul for multi-module PMS platform.