Ultra Guest
Privacy
This page summarises how personal data is handled on the platform. The guest-facing Privacy Policy and the Data Processing Agreement are the authoritative documents; this is a procurement-friendly overview.
Controller and processor
- The hotel is the controller; Ultra Guest is the processor, acting on the hotel's documented instructions.
- The hotel is responsible for providing privacy notices to its guests and for obtaining and recording any consent required (including for marketing and loyalty participation). The platform provides features to capture and record consent.
Lawful basis and consent
- Processing is carried out on the lawful basis the hotel relies on (for example, performance of the guest's contract, the hotel's legitimate interests, or consent).
- A per-purpose consent ledger records consent and withdrawal events, so a hotel can demonstrate the basis for marketing and other optional processing.
Data-subject rights
- Guests can exercise access and erasure rights. The platform supports data-subject access requests (a structured export of the guest's identity, stays, orders, conversations, wallet, and consent records) and erasure (anonymization across guest records, withdrawal of consent, and soft-deletion of financial records that must be retained for legal reasons).
- Requests received directly by Ultra Guest are forwarded to the hotel; the hotel responds as controller.
Retention
- Personal data is kept only as long as needed and then deleted or anonymized on a per-category schedule, configurable per hotel. See the Data Map for details. Financial and ledger records are retained under legal-obligation requirements.
International transfers
- Some processing takes place outside the EEA. In particular, AI inference uses Amazon Bedrock in AWS us-east-1 (United States), and platform hosting and email run on AWS in the same region. This is disclosed plainly — it is not hidden behind vague language.
- For guests or hotels in the EEA, the UK, or Switzerland, such transfers are made under the EU Standard Contractual Clauses (Module Two: controller-to-processor) and supplementary measures (encryption and prompt-context minimisation). A transfer-impact assessment supports this posture, and an Article 27 representative is appointed where required. The applicable details are completed with each customer; see the DPA (clause 9) and the Sub-processors register.
Cookies
- Only strictly necessary cookies are set before consent (to keep a guest signed in and remember language).
- Analytics or marketing cookies are set only after consent and only where the hotel has enabled them. Consent can be withdrawn. See the guest-facing Cookie Notice for categories and lifetimes.