Privacy Policy

HotOps · Last updated: 21 August 2026

1. Controller and roles

HotOps is responsible for the website, hotel registrations, contract and billing data, and support requests:

HotOps Solutions, Archil Begashvili
Großfriedrichsburger Str. 8c
81827 Munich, Germany
Email: info@hotops.app

Each hotel is the controller for personal data it processes for hotel operations. HotOps processes that data on the hotel's behalf under a data processing agreement.

2. Staff and end users

The hotel determines the purposes, legal basis and retention of operational processing. This policy supplements but does not replace the hotel's own privacy notices. Authorised hotel users may see names, positions, departments, leadership status, optional profile images and operational content according to their role. These data are not shared with unrelated hotels.

3. Data and purposes

HotOps processes account and business contact data; hotel and billing data; staff roles and optional profile information; lost-property, guest-request, task, handover, repair, complaint and room-status data; selected photos and text; support messages; push tokens; and necessary device, access and security logs. These data are used to provide and secure the service, organise hotel operations, communicate with guests and users, handle support and billing, and prevent misuse. Please do not enter special-category data unless strictly necessary and legally permitted.

The public contact form processes name, email address, optional hotel name and phone number, and the message. It stores the request in the protected HotOps support inbox and triggers a push notification. No external form or email-delivery service is used.

4. Legal bases

HotOps processes its own contract, registration and support data under Art. 6(1)(b), (c) and (f) GDPR. The relevant hotel determines and communicates the legal basis for operational processing.

5. Recipients, AI and transfers

HotOps uses Supabase for database, authentication and protected storage, Expo for builds, updates and push notifications, OpenAI for optional user-initiated photo analysis and text correction, and the contracted website host for delivery and server logs. AI output is only a suggestion reviewed by staff; no solely automated decision with legal or similarly significant effects is made. The database is configured in an EU region. Where processing outside the EU/EEA occurs and no adequacy decision applies, safeguards such as EU Standard Contractual Clauses are used. Current subprocessor information is available from info@hotops.app.

6. Retention

7. Security

HotOps uses TLS, role-based access, tenant-separated database policies and private photo storage with time-limited access links.

8. Your rights

Where applicable, you have rights of access, rectification, erasure, restriction, portability and objection. Contact the relevant hotel for operational data and info@hotops.app for HotOps' own data. You may complain to a supervisory authority; HotOps is generally supervised by the Bavarian Data Protection Authority.

9. Required data and website storage

Required registration, login and service data must be provided for the relevant function. HotOps uses no marketing or analytics trackers. Technically necessary local browser data may be removed through browser settings.

10. Changes to this policy

HotOps may update this policy when its features, service providers or legal requirements change. Material changes will be communicated in an appropriate manner. The version published here applies, and its update date is shown above.