Legal
Privacy Policy
Last updated: 18 June 2026
This Privacy Policy explains how HotioPMS LLC ("HotioPMS LLC", "we", "us", or "our") collects, uses, discloses, and protects personal information when you visit hotiopms.com, use HotioPMS® at app.hotiopms.com, or interact with our booking engine, self check-in portal, channel tools, or related services (collectively, the "Services"). HotioPMS® is a registered trademark of HotioPMS LLC.
We are committed to lawful, fair, and transparent processing of personal information in accordance with the Protection of Personal Information Act, 2013 ("POPIA") in South Africa, the General Data Protection Regulation ("GDPR") where applicable, and other relevant data protection laws.
1. Who we are
HotioPMS LLC (https://hotiopms.com) is the data controller for personal information we collect through our website, marketing activities, billing, and customer support for HotioPMS®.
When you use the Services to manage guest reservations, Hotio generally acts as a data processor on your behalf. You, as the property operator, remain the data controller for guest and employee personal information you upload or generate in the PMS.
- Privacy enquiries: [email protected]
- Information Officer (POPIA): [email protected]
- Support: [email protected]
2. Scope
This policy applies to:
- Visitors to hotio.com and related marketing pages;
- Account holders, authorised users, and billing contacts at subscribing properties;
- Guests who interact with a property's Hotio-powered booking engine or self check-in portal;
- Individuals who contact us for demos, support, or employment enquiries.
Third-party websites, OTAs, payment providers, or integrations linked from the Services are governed by their own privacy policies.
3. Information we collect
3.1 Account and property data
When you register or subscribe, we may collect:
- Name, email address, phone number, and job title;
- Property name, address, room inventory, rates, policies, and branding assets;
- Billing details, tax/VAT numbers, and transaction records;
- Login credentials (stored using industry-standard hashing; we do not store plain-text passwords).
3.2 Guest and reservation data (processed on your behalf)
Through the PMS, booking engine, and self check-in, properties may store:
- Guest names, contact details, nationality, and identification or passport information;
- Booking references, stay dates, room assignments, folio and payment records;
- Special requests, housekeeping notes, and digital guest register entries;
- Proof-of-payment uploads where EFT or manual payment workflows are used.
You are responsible for providing guests with appropriate privacy notices and obtaining lawful grounds to collect this information.
3.3 Usage and technical data
- IP address, browser type, device identifiers, and approximate location;
- Log files, audit trails, session metadata, and error reports;
- Feature usage, performance metrics, and security event logs;
- Cookies and similar technologies (see Section 10).
3.4 Communications
If you subscribe to our newsletter, request a demo, or contact support, we collect the information you provide and correspondence related to your enquiry.
4. How we use information
We use personal information to:
- Provide, maintain, secure, and improve the Services;
- Process subscriptions, invoices, and account administration;
- Enable reservations, channel distribution, reporting, and guest-facing portals;
- Send service notifications, security alerts, and product updates;
- Respond to support requests and investigate incidents;
- Comply with legal obligations and enforce our Terms of Service;
- Send marketing communications where permitted, you may opt out at any time using the unsubscribe link or by emailing [email protected].
We do not sell personal information to third parties.
5. Legal bases for processing
Depending on context, we rely on:
- Contract: processing necessary to deliver the Services you subscribe to;
- Legitimate interests: securing our platform, preventing fraud, improving products, and communicating about your account, balanced against your rights;
- Legal obligation: tax, accounting, regulatory, or law-enforcement requests;
- Consent: where required for marketing cookies or optional features.
Where we process guest data on your instructions, you must ensure an appropriate lawful basis exists under POPIA, GDPR, or applicable local law.
7. International transfers
Your data may be processed in South Africa and other countries where our providers operate. Where personal information is transferred outside South Africa or the EEA, we implement safeguards such as standard contractual clauses, adequacy decisions, or equivalent mechanisms required by POPIA and GDPR.
8. Retention
We retain personal information only as long as necessary for the purposes described, including:
- Active subscription period plus a reasonable wind-down period after termination;
- Backup cycles (typically up to 90 days after primary deletion);
- Periods required by tax, accounting, or dispute-resolution laws.
Upon termination, you may export your data during any notice period we provide. After deletion requests, residual copies may persist in encrypted backups for a limited time before automatic purging.
9. Security
We implement administrative, technical, and physical safeguards designed to protect personal information, including:
- TLS/SSL encryption in transit for web and API traffic;
- Encryption at rest for production databases where supported;
- Role-based access controls and audit logging within the PMS;
- Regular patching, monitoring, and vulnerability management;
- Employee confidentiality obligations and security awareness training.
No method of transmission or storage is completely secure. You must keep account credentials confidential and notify us immediately of suspected unauthorised access at [email protected].
11. Your rights
Subject to applicable law, you may have the right to:
- Access personal information we hold about you;
- Request correction of inaccurate or incomplete data;
- Request deletion or restriction of processing;
- Object to certain processing based on legitimate interests;
- Request data portability in a structured, machine-readable format;
- Withdraw consent where processing is consent-based;
- Lodge a complaint with the Information Regulator (South Africa) or your local supervisory authority.
Guest requests relating to stays should generally be directed to the property that collected the data. We will assist our customers in responding where we act as processor.
To exercise your rights, email [email protected]. We may verify your identity before responding and will reply within timeframes required by law (typically 30 days under POPIA).
12. GDPR (European visitors and guests)
Where GDPR applies, Hotio supports the rights listed above and processes data in accordance with Articles 6 and 28. Customers requiring a Data Processing Agreement (DPA) may request one at [email protected].
Our lawful bases are set out in Section 5. Where we rely on legitimate interests, you may object. International transfers use appropriate safeguards as described in Section 7.
13. Children
The Services are intended for business use by properties and adults. We do not knowingly collect personal information from children under 16 without appropriate parental or guardian consent arranged by the subscribing property.
14. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated date. Continued use of the Services after changes take effect constitutes acceptance where permitted by law.
15. Contact
Questions about this Privacy Policy or our data practices: [email protected]
This document is provided for general information and does not constitute legal advice. We recommend that you review these terms with qualified legal counsel for your specific circumstances.
