Legal

Privacy Policy

Effective date: 1 January 2026  ·  Last updated: 29 March 2026

RegolithX (“we”, “our”, or “us”) is committed to protecting the privacy of hotel operators and their guests. This policy explains how we collect, use, store, and safeguard information when you use the RegolithX platform.

1.Overview

RegolithX operates as a data processor. Your hotel operates as the data controller. This distinction is legally significant under GDPR (Regulation (EU) 2016/679) and Indonesia's UU PDP (Personal Data Protection Law). As a data processor, we only process personal data on your documented instructions and do not determine the purposes or means of that processing.

As the data controller, your hotel is responsible for ensuring you have a lawful basis for collecting and processing guest data, providing privacy notices to guests, and honouring their data subject rights.

ℹ️
This distinction means that if a guest contacts you to exercise their right to erasure, you — as the data controller — must honour that request. We provide the tools to help you do so; contact privacy@regolithx.com and we will delete the relevant records from our systems.

2.Data We Collect

Account Data

  • Name and email address of hotel staff and administrators
  • Hotel name, address, and property configuration details
  • Billing information (invoicing name and address — no card numbers stored by RegolithX)
  • Account credentials (passwords stored as salted hashes; never in plain text)

Operational Data

This is data you input into the platform to run your hotel operations:

  • Guest names, email addresses, and phone numbers
  • Reservation records, check-in and check-out dates, room assignments
  • Maintenance requests and staff task assignments
  • In-room orders and upsell transactions
  • Web push notification tokens for guest communications
  • OTA integration data synced from Booking.com, Agoda, Airbnb, and other connected channels

Automatically Collected Data

  • IP address and approximate geolocation (country/city level) for security logging
  • Browser type, operating system, and device information
  • Pages visited, features used, and session duration for product analytics
  • Crash reports and error logs to improve platform stability

3.AI & Third-Party Processing

RegolithX uses Anthropic's Claude API to power several AI features. When you use these features, certain data inputs are transmitted to Anthropic's servers for processing.

⚠️
Guest data may be processed by Anthropic's API for AI-powered responses. This includes inputs to features such as Dynamic Pricing AI, AI Upselling, and the Hotel AI assistant. By using these features, you confirm that you have a lawful basis to share this data with our AI provider.

Third-Party Service Providers

  • Anthropic Claude API — AI language model processing for assistant, pricing, and upsell features
  • Supabase — primary database, authentication, and file storage infrastructure
  • OTA Providers (Booking.com, Agoda, Airbnb, etc.) — channel management data sync
  • Payment Gateways — Midtrans, GoPay, OVO, Dana, ShopeePay, QRIS for payment processing
  • Web Push Services — browser-based push notification delivery
ℹ️
For hotels processing data of EU residents, we offer Anthropic's zero data retention API tier upon request. Under this configuration, Anthropic does not store or log any data submitted through API requests. Contact privacy@regolithx.com to enable this for your account.

4.Data Storage & Security

We apply security measures across all layers of the platform. Primary data storage is located in Singapore, within an AWS / Supabase-managed environment.

  • TLS 1.3 encryption for all data in transit between your browser, our servers, and third-party APIs
  • AES-256 encryption for all data at rest
  • Row-Level Security (RLS) — each hotel account can only read and write its own data; cross-tenant data access is architecturally prevented
  • Multi-tenant isolation ensures no hotel can access another hotel's guest records, reservations, or operational data
  • Access to production infrastructure is restricted to authorised RegolithX engineers via multi-factor authentication
  • Automated backups with point-in-time recovery

5.Payment & Sensitive Data

⚠️
We never send raw payment card numbers, passport scans, national ID numbers, or biometric data to the Claude API or any AI system. These categories of sensitive data are processed offline and are never transmitted to third-party AI services.
  • Card numbers — handled exclusively by the payment gateway (Midtrans). RegolithX never stores, logs, or transmits raw card numbers. We receive only a masked token and transaction status.
  • Passport and ID scans — these must be stored locally by the hotel (e.g., on your front-desk device or in a physical register). Do not upload passport or ID images to the RegolithX platform.
  • Bank account credentials — if stored for payout purposes, encrypted at rest with AES-256 and never exposed in API responses or logs.
  • Biometric data — not collected or processed by RegolithX under any circumstances.

6.Hotel Guest Data

Your hotel, as the data controller, bears primary responsibility for how you use guest data within RegolithX. Specifically:

  • Obtaining valid guest consent before using AI features that process their personal data
  • Providing guests with a clear privacy notice that discloses AI processing of their data
  • Honouring guest requests to access, correct, or delete their personal data
  • Ensuring that your team members who use RegolithX understand your hotel's data protection obligations

Recommended Consent Language

We recommend including the following (or equivalent) on your check-in form or guest communication:

“[Hotel Name] uses RegolithX, an AI-powered hotel management platform, to manage your reservation and provide personalised services. Your name, contact details, and reservation information may be processed by AI systems to deliver faster responses and tailored recommendations. Your data is stored securely and will not be sold to third parties. You may request access to or deletion of your data at any time by contacting [hotel email].”

7.Your Rights

Hotel operators (as our direct customers) have the following rights regarding personal data we hold about them and their accounts:

Access

Request a copy of all personal data we hold about your account.

Rectification

Correct inaccurate or incomplete personal data at any time.

Erasure

Request deletion of your account and all associated data.

Portability

Receive your data in a machine-readable format (JSON/CSV).

Restriction

Request that we limit processing while a dispute is resolved.

Objection

Object to processing based on legitimate interests.

To exercise any of these rights, contact privacy@regolithx.com. We respond to all requests within 30 days and will never charge a fee for reasonable requests.

8.Data Retention

  • Active hotel and guest data is retained for the duration of your active subscription.
  • All hotel and guest data is permanently deleted within 30 days of account cancellation — no exceptions.
  • Immediate deletion is available upon written request to privacy@regolithx.com.
  • Anonymised, aggregated analytics (e.g., total reservation volume, feature usage trends) may be retained indefinitely as they cannot be linked to any individual.
  • Billing records and invoices are retained for 7 years in compliance with Indonesian tax law (UU Perpajakan).
  • Web push notification tokens are deleted immediately upon unsubscribe or on account cancellation.

9.Cookies

We use a minimal set of cookies. We do not use advertising cookies and we do not sell your data to advertisers.

EssentialCannot be disabled

Session authentication tokens, CSRF protection, and security cookies. These are required for the platform to function and cannot be disabled.

PreferenceCan be disabled

Language selection and display settings. These improve your experience but are not required.

AnalyticsCan be disabled

Anonymous usage data to help us understand which features are used and where the platform can be improved. No personally identifiable information is included.

10.Contact

For all privacy-related enquiries, data subject requests, or breach notifications, contact us at:

Email: privacy@regolithx.com

We comply with GDPR Article 33 — any confirmed personal data breach will be notified to the relevant supervisory authority within 72 hours of becoming aware of it.

We will provide 14 days' advance notice before any material changes to this Privacy Policy, delivered to the email address on your account.

Also read our legal terms

Terms of Service →