Skip to content

Your data

It is yours, and here is how we hold to that.

Everything below is contractual. Each promise points to the article that carries it, by its heading — a number goes stale, a heading can still be found.

Where it lives

A dedicated server in the European Union, at OVH, in Roubaix. Encrypted backups are held by a provider separate from the host, also in the European Union. No data leaves the European Economic Area.

Written in Legal notice — Hosting and location of the data

Who it belongs to

Your guests’ and travellers’ data is yours. You are the controller; we are only the processor. The contract required by article 28 of the GDPR is not an annex to chase down: it is written into our terms, and you accept it together with them. If you have your own and we sign it, yours prevails.

Written in Terms — Data protection — data processing agreement

What we do not do

We sell no data. No profiling, no automated decision-making. The public site sets no audience-measurement or advertising cookie — which is why it imposes no banner on you.

Written in Legal notice — What we do not do

When we have to step in

Sometimes your book has to be opened to get you out of trouble. Start with what we cannot do: we cannot learn your password, we cannot change it, and we cannot enter without leaving a trace. Here is what it takes to enter.

  • An explicitly authorised operator — not just anyone on our side.
  • A written reason, recorded before the session opens.
  • Twenty minutes, no more.
  • A line in the log, including when an action is refused.

We write this down because any provider can technically reach the data it hosts. The question is not whether it is possible — it is on what conditions, and whether anyone can check.

Written in Terms — Confidentiality, and who on our side has access to your data

How you take it back

Your bookings and customer records export to CSV from your own book, at any time, without telling us and without us having to act. No exit, migration or retrieval fee. We assist you through a transition period of thirty days, extendable on request.

Written in Terms — Portability and change of provider

How you erase it

You erase your account from your workspace, without going through us. At the end of the contract you choose: a complete copy of your data, or its deletion. Without an answer from you within thirty days, we delete. Deletion is final — active systems first, then the encrypted backups at the end of their rotation, which does not exceed thirty days.

Written in Terms — The fate of the data at the end of the contract

What protects it

Encrypted traffic, passwords never kept in the clear, sessions that expire, and separation by establishment enforced by the database and not by the application alone. Databases are backed up every fifteen minutes, encrypted, with a provider separate from the host. And restoration is not a promise: we exercise it at least once a quarter, on each database.

Written in Terms — Security

None of this is decided after the fact.

These commitments sit in the contract you accept when you sign up. You can read the whole of it before you begin.