Ultra Guest
Security
Ultra Guest protects guest personal data with technical and organisational measures appropriate to the risk. This page summarises the platform-level posture; the Data Processing Agreement (clause 6.3) is the contractual statement of these measures.
Tenant isolation
- Each hotel is a separate tenant. The tenant is resolved from the request host and re-validated against the authenticated session on every request; a mismatch fails closed (the request is treated as not found rather than disclosing another tenant's data).
- Authorization is re-derived in the database on every endpoint, so a missing scope returns no rows rather than another tenant's records.
Encryption and hosting
- Personal data is encrypted in transit (TLS) and at rest.
- The platform runs on a dedicated, self-hosted database and identity stack, isolated from any other Ultra product environment. PostgreSQL and the authentication service run on this infrastructure.
- Object storage for uploaded media is encrypted.
Access control and audit
- Access is granted on a least-privilege, need-to-know basis with role-based authorization.
- Security-relevant events are written to an append-only audit trail.
- Structured pricing, availability, and tax facts and unverified allergen content are excluded from any translation or AI caching path.
Payments
- In the current billing posture, Ultra Guest does not store full payment card numbers. Online payments are handled by PCI-compliant payment providers, or are taken at the property. Card data does not flow through Ultra Guest's storage.
Resilience and breach response
- Backups and recovery measures are maintained to restore availability after an incident.
- On becoming aware of a personal-data breach affecting a hotel's data, Ultra Guest notifies the hotel without undue delay and within 72 hours, with the information available at the time, and assists the hotel's investigation and remediation. The hotel, as controller, makes any required notifications to its supervisory authority and to affected guests.
Retention and deletion
- Personal data is retained only as long as needed for its purpose, then deleted or anonymized on a per-category schedule. Financial and ledger records are retained where law requires.
- See the Data Map for per-category retention and deletion behavior, and the Privacy page for data-subject access and erasure.