Security & privacy
Your data and your guests’ data, kept with care
This page explains what the system does today and what we commit to before any hotel goes live. We do not show certificates we have not earned yet.
What works today
- Encrypted connections between devices and the server.
- An audit log: every sensitive action with who did it and when, and it cannot be edited.
- Role-based access: each person sees their own work; managers see their departments.
- Each hotel’s data is kept apart from every other hotel’s at database level.
- The guest page needs no sign-up, and a room’s code works only while the room is occupied.
- Everything in the demo is synthetic; there are no real guest details in the demo hotel.
Staff privacy
- Request timers are there to serve the guest, not to watch people.
- The room entry log is seen only by supervisors and security; staff see their own visits.
- No public league tables between colleagues.
The voice agent
- It says it is a digital assistant at the start of every call; the guest can press 0 for a person at any time.
- If it fails, the call goes to a person within five seconds.
- It does not keep card numbers; they are removed from the text if spoken.
Before any hotel goes live
- We sign PDPL data-processing terms with you.
- The platform is designed for in-Kingdom hosting of live hotels, and we confirm the hosting location in writing before go-live.
- An independent penetration test before the pilot, and a plan towards ISO 27001.