Skip to content
Legal

Data Protection

Last updated: 25 July 2026

Note: This is a template policy provided for launch readiness. It should be reviewed and approved by a qualified legal adviser before going live.

Current legal operator and public correspondence particulars are awaiting confirmation. For business enquiries, contact [email protected].

This Data Protection statement explains how RevROI Hospitality safeguards the client and operational data we handle while delivering our services. It complements our Privacy Policy.

Our commitment

Handling hospitality data responsibly is central to how we work. We are committed to protecting the confidentiality, integrity and availability of every client’s information, and to complying with the UK GDPR and the Data Protection Act 2018 as amended.

Client and operational data

In the course of our work we may access commercially sensitive information, including revenue reports, booking data, and access to property management systems (PMS) and OTA extranets. This access is governed by written service and confidentiality terms and, where the facts require it, an appropriate data-processing agreement before the relevant access begins.

Data minimisation and access control

We request only the access we genuinely need, for only as long as we need it. Access is restricted to authorised personnel, credentials are managed securely, and access is revoked promptly at the end of an engagement.

Payment-card information

Where reservations involve virtual or guest payment cards, we follow PCI-aware handling practices. Card data is never stored on this website, and it is processed only within the property’s own secure systems and approved tools.

Sub-processors

Where we use third-party tools to deliver our services, we select providers that offer appropriate security and data-protection guarantees and put suitable contractual terms in place. The public website currently uses Cloudflare for hosting and security and Resend for contact-form email delivery. Client-service sub-processors are identified in the relevant agreement or processor schedule where required.

Data subject rights

Individuals whose data we process retain their rights under the UK GDPR, including access, rectification and erasure. Requests relating to data we process on behalf of a client are coordinated with that client as the data controller.

Breach handling

Before accepting live client operational data, the applicable incident procedure, contacts and notification route must be approved and tested. Where a breach affects individuals or a client, it is assessed, contained and handled in line with the applicable legal and contractual obligations.

International transfers

Where data is transferred outside the UK, we ensure an appropriate safeguard is in place, as required by law.

Reviewing this statement

We review this statement periodically and will publish any updates on this page.

Contact

For any data-protection question, email [email protected].