Skip to content
Security and compliance

What your technology team will want to ask.

We process guest data on the hotel’s behalf. This page sets out, plainly, the practices and the responsibilities of each party.

Confirm these statements with the technical team before publishing. Specific certifications and locations should reflect the contracted infrastructure.

Clearly defined roles

The hotel is the controller of its guests’ data. Guestdash acts as processor, on the hotel’s instructions, under a data processing agreement.

Hosting in the European Union

The production infrastructure is hosted in the European Union. For clients in Brazil, the location is set contractually.

Encryption in transit and at rest

All traffic is encrypted in transit, and data is encrypted at rest in the database and in the backups.

Access by role

Users, roles and API keys managed at group level, with visibility limited to what each role needs to see.

Auditable log

Actions on the platform are logged, allowing an audit of who did what and when, including access to guest data.

Isolation by property

Each property has its own context and knowledge base. We do not mix data between clients.

AI with no cross-training

We do not use one client’s guest data to train general-purpose models. Each agent’s knowledge belongs to the hotel.

Declared sub-processors

The list of providers that process data on our behalf is made available and kept up to date, under a duty of confidentiality.

Backups and recovery

Periodic backups with a tested recovery procedure, and recovery objectives defined in the contract.

Access control

Access control and authentication

Who logs in, from where, when and with what proof.

Two-step verification

Beyond the password, login can require a one-time code generated by an authenticator app — Google Authenticator, Microsoft Authenticator, Authy and equivalents. It can be made mandatory for the whole environment, with recovery codes in case the device is lost.

Single sign-on (SSO)

Login with the hotel’s corporate credentials, via OIDC — compatible with Google Workspace, Microsoft Entra and Okta. Users are created automatically on first access, with the default role set by the hotel. With SSO active, the second factor is managed by the hotel’s identity provider.

IP-restricted access

Each environment can limit access to authorised addresses and network ranges. Outside the list, access is blocked — at login and on every request. With safeguards so nobody locks themselves out.

Time windows

Access can be limited to defined days and hours — by user, by role or for the whole environment, always in the property’s time zone. At the end of the window, the session is actually closed, with a configurable warning to finish what is in progress.

Authorised email domains

Only accounts from the domains defined by the hotel can enter — for example, only @yourhotel.com addresses. The rule applies at login, on environment switching and when inviting new users.

Access logs

Who logged in, from where and when, with the outcome and reason for each block — unauthorised IP, outside hours, second factor. With filters, per-event detail, CSV export and retention configurable by the hotel.

Frequently asked

The questions we always get.

Who is the controller of the guests’ data?
The hotel. Guestdash acts as processor, on the hotel’s instructions, under a data processing agreement. See the Privacy Policy.
Where is the data hosted?
On infrastructure hosted in the European Union. For clients in Brazil, the location is set in the contract.
Do you use guest data to train AI models?
We do not use one client’s data to train general-purpose models. Each agent’s knowledge base belongs to the hotel and is isolated by property.
Can you audit who accessed what?
Yes. Actions are logged, allowing an audit of who did what and when.
Do you have two-factor authentication and SSO?
Yes. Two-step verification via authenticator app, made mandatory per environment as needed, and single sign-on via OIDC with the usual corporate identity providers. With SSO active, the second factor is managed by the hotel’s identity provider.
Can you restrict access by network or by time?
Yes. Access can be limited to authorised IP addresses and to day and time windows — by user, role or environment, in the property’s time zone. All blocks are recorded in the access logs, with the reason.

Send us your security questionnaire.

We answer the questionnaire and provide the data processing agreement before any commitment.