1.Overview
RegolithX operates as a data processor. Your hotel operates as the data controller. This distinction is legally significant under GDPR (Regulation (EU) 2016/679) and Indonesia's UU PDP (Personal Data Protection Law). As a data processor, we only process personal data on your documented instructions and do not determine the purposes or means of that processing.
As the data controller, your hotel is responsible for ensuring you have a lawful basis for collecting and processing guest data, providing privacy notices to guests, and honouring their data subject rights.
2.Data We Collect
Account Data
- ›Name and email address of hotel staff and administrators
- ›Hotel name, address, and property configuration details
- ›Billing information (invoicing name and address — no card numbers stored by RegolithX)
- ›Account credentials (passwords stored as salted hashes; never in plain text)
Operational Data
This is data you input into the platform to run your hotel operations:
- ›Guest names, email addresses, and phone numbers
- ›Reservation records, check-in and check-out dates, room assignments
- ›Maintenance requests and staff task assignments
- ›In-room orders and upsell transactions
- ›Web push notification tokens for guest communications
- ›OTA integration data synced from Booking.com, Agoda, Airbnb, and other connected channels
Automatically Collected Data
- ›IP address and approximate geolocation (country/city level) for security logging
- ›Browser type, operating system, and device information
- ›Pages visited, features used, and session duration for product analytics
- ›Crash reports and error logs to improve platform stability
3.AI & Third-Party Processing
RegolithX uses Anthropic's Claude API to power several AI features. When you use these features, certain data inputs are transmitted to Anthropic's servers for processing.
Third-Party Service Providers
- ›Anthropic Claude API — AI language model processing for assistant, pricing, and upsell features
- ›Supabase — primary database, authentication, and file storage infrastructure
- ›OTA Providers (Booking.com, Agoda, Airbnb, etc.) — channel management data sync
- ›Payment Gateways — Midtrans, GoPay, OVO, Dana, ShopeePay, QRIS for payment processing
- ›Web Push Services — browser-based push notification delivery
4.Data Storage & Security
We apply security measures across all layers of the platform. Primary data storage is located in Singapore, within an AWS / Supabase-managed environment.
- ›TLS 1.3 encryption for all data in transit between your browser, our servers, and third-party APIs
- ›AES-256 encryption for all data at rest
- ›Row-Level Security (RLS) — each hotel account can only read and write its own data; cross-tenant data access is architecturally prevented
- ›Multi-tenant isolation ensures no hotel can access another hotel's guest records, reservations, or operational data
- ›Access to production infrastructure is restricted to authorised RegolithX engineers via multi-factor authentication
- ›Automated backups with point-in-time recovery
5.Payment & Sensitive Data
- ›Card numbers — handled exclusively by the payment gateway (Midtrans). RegolithX never stores, logs, or transmits raw card numbers. We receive only a masked token and transaction status.
- ›Passport and ID scans — these must be stored locally by the hotel (e.g., on your front-desk device or in a physical register). Do not upload passport or ID images to the RegolithX platform.
- ›Bank account credentials — if stored for payout purposes, encrypted at rest with AES-256 and never exposed in API responses or logs.
- ›Biometric data — not collected or processed by RegolithX under any circumstances.
6.Hotel Guest Data
Your hotel, as the data controller, bears primary responsibility for how you use guest data within RegolithX. Specifically:
- ›Obtaining valid guest consent before using AI features that process their personal data
- ›Providing guests with a clear privacy notice that discloses AI processing of their data
- ›Honouring guest requests to access, correct, or delete their personal data
- ›Ensuring that your team members who use RegolithX understand your hotel's data protection obligations
Recommended Consent Language
We recommend including the following (or equivalent) on your check-in form or guest communication:
“[Hotel Name] uses RegolithX, an AI-powered hotel management platform, to manage your reservation and provide personalised services. Your name, contact details, and reservation information may be processed by AI systems to deliver faster responses and tailored recommendations. Your data is stored securely and will not be sold to third parties. You may request access to or deletion of your data at any time by contacting [hotel email].”
7.Your Rights
Hotel operators (as our direct customers) have the following rights regarding personal data we hold about them and their accounts:
Access
Request a copy of all personal data we hold about your account.
Rectification
Correct inaccurate or incomplete personal data at any time.
Erasure
Request deletion of your account and all associated data.
Portability
Receive your data in a machine-readable format (JSON/CSV).
Restriction
Request that we limit processing while a dispute is resolved.
Objection
Object to processing based on legitimate interests.
To exercise any of these rights, contact privacy@regolithx.com. We respond to all requests within 30 days and will never charge a fee for reasonable requests.
8.Data Retention
- ›Active hotel and guest data is retained for the duration of your active subscription.
- ›All hotel and guest data is permanently deleted within 30 days of account cancellation — no exceptions.
- ›Immediate deletion is available upon written request to privacy@regolithx.com.
- ›Anonymised, aggregated analytics (e.g., total reservation volume, feature usage trends) may be retained indefinitely as they cannot be linked to any individual.
- ›Billing records and invoices are retained for 7 years in compliance with Indonesian tax law (UU Perpajakan).
- ›Web push notification tokens are deleted immediately upon unsubscribe or on account cancellation.
We use a minimal set of cookies. We do not use advertising cookies and we do not sell your data to advertisers.
Session authentication tokens, CSRF protection, and security cookies. These are required for the platform to function and cannot be disabled.
Language selection and display settings. These improve your experience but are not required.
Anonymous usage data to help us understand which features are used and where the platform can be improved. No personally identifiable information is included.
10.Contact
For all privacy-related enquiries, data subject requests, or breach notifications, contact us at:
Email: privacy@regolithx.com
We comply with GDPR Article 33 — any confirmed personal data breach will be notified to the relevant supervisory authority within 72 hours of becoming aware of it.
We will provide 14 days' advance notice before any material changes to this Privacy Policy, delivered to the email address on your account.
Also read our legal terms
Terms of Service →