PRIVACY POLICY

Hotel Card System

1. General Information

This Privacy Policy defines the rules for processing personal data within the use of the Hotel Card System.

  • Data Controller of Users: The data controller of personal data of persons using an account (Clients) in the system is Sławomir Roszkowski, an entrepreneur conducting business activity under the registered business name: ROSZKOWSKI Sławomir Roszkowski, with the principal place of business at: Olszany 82, 58-141 Strzegom, Poland, registered in the Central Registration and Information on Business (CEIDG), Tax ID (NIP): 8841521115, Business Registration Number (REGON): 891059440.
  • Data Processor of Guests: In the case of hotel guests' data (entered into the system by hotels) – the Data Controller is the User (e.g., hotel, apartment manager), and the Service Provider acts solely as a data processor (Processor) on behalf of the User, based on a data processing agreement.
  • Contact: Any questions regarding privacy protection and the exercise of the rights of data subjects should be directed to the e-mail address: support@hotelcardsystem.com

2. Scope of Processed Data

The system processes data necessary for the proper provision of access management services:

User Data (System Clients):

  • First and last name, email address, company details (VAT ID, address).
  • Authorization data (login, encrypted password).
  • Technical data: IP address, Tenant ID, login history.

Hotel Guest Data (entrusted for processing):

  • First and last name (optional, depending on User configuration).
  • Dates and times of the planned stay.
  • Access data: generated PIN codes, RFID card identifiers, digital keys (eKeys).
  • Event logs: information about the time and place of code or card use in locks integrated with the system (e.g., data from TTLock Open Platform).

3. Purpose of data processing

Personal data are processed for the purpose of:

  • Providing services electronically in the SaaS model (Hotel Card System).
  • Managing access to properties and integrating with physical devices.
  • Technical and administrative maintenance of the User's account.
  • Ensuring system security and counteracting abuse.
  • Fulfilling legal and accounting obligations incumbent on the Data Controller.

4. Legal basis

The legal basis for data processing, depending on the operation, is:

  • Art. 6(1)(b) of the GDPR – necessity for the performance of a contract or to take steps at the request of the data subject prior to entering into a contract.
  • Art. 6(1)(c) of the GDPR – compliance with legal obligations (e.g., issuing invoices, tax regulations).
  • Art. 6(1)(f) of the GDPR – legitimate interest pursued by the Data Controller (ensuring network security, diagnostics, enforcement of claims).

5. Entrustment and Transfer of Data (Paddle, TTLock, and others)

Data may be transferred to third parties for the proper performance of the Service, including:

  • Payment Operator: Transaction data (including email address, payment card details) are processed directly by Paddle.com Market Limited (or its affiliates), acting as the official seller (Merchant of Record). The Service Provider does not store or have access to full payment card details of Users.
  • Lock Infrastructure Provider: Data necessary to generate access are transferred to the operator TTLock Open Platform.
  • IT Infrastructure: Data may be stored on external servers of cloud and hosting service providers.
  • Transfer outside the EEA: Due to the use of global service providers (e.g., Paddle, TTLock), data may be transferred outside the European Economic Area. The Service Provider uses only services from entities that guarantee a high level of data protection in accordance with GDPR standards.

The Service Provider is not responsible for the independent privacy policies of third-party providers, provided they act as separate Data Controllers.

6. Data Retention Period

  • for the duration of the contract
  • up to 12 months from the last account activity

After this time, the account may be deleted, and the data will enter a 14-day quarantine period.

7. Rights of Data Subjects

The data subject has the right to: access data, rectification, erasure, restriction of processing, and data portability. In the case of guest data – contact the Controller (User).

8. Data Security

The Service Provider uses technical and organizational measures to protect data; however, it does not guarantee 100% security and is not responsible for hacking attacks or actions of third parties.

9. Logs and Monitoring

The system may record logins, user operations, and system events for security and diagnostic purposes.

10. Cookies

The system may use cookies to maintain sessions and improve application performance.

11. Changes to the policy

The Policy may be updated. Users will be informed electronically.

Last update: May 25, 2026