Legal

Privacy Policy

Version 2.1 · last updated 21 September 2026

1. Who we are (the controller)

PMS Rezlynx Ltd is the controller for personal data collected through this website (https://www.pmsrezlynx.com) and while providing our Services. Registered in England & Wales (Companies House, Cardiff), company number 14320487, registered office Fourth Floor, Cavendish House, 36 Bennetts Hill, Birmingham B2 5SN, United Kingdom. Contact: support@pmsrezlynx.com. We are registered with the Information Commissioner’s Office under reference ZA685214.

2. Categories of data we process

Website visitors: no analytics or advertising cookies are set by default; we store your cookie-banner choice and basket contents in local browser storage. Contact-form messages are stored as email correspondence.
Customers and prospective customers: business contact names, work email addresses, phone numbers, property names and platform identifiers needed to licence and operate modules.
Guest data processed on behalf of Customers: when a Customer activates guest-facing modules (for example messaging or e-signature), we process guest identifiers, stay dates, room references, contact details and document data strictly under the Customer’s instructions.

3. Purposes and lawful bases

PurposeDataBasis
Selling and administering subscriptionsCustomer business contactsContract (Art. 6(1)(b))
Technical operation of modules via Host Platform APIsCredentials, config, logsContract; legitimate interests (Art. 6(1)(f))
Guest-facing processing on Customer instructionGuest recordsController-to-controller/processor terms; Customer ensures Art. 6 basis
Invoicing, accounting, taxBilling detailsLegal obligation (Art. 6(1)(c))
Fraud prevention, security loggingAccess logs, IP fragmentsLegitimate interests

4. Retention periods

Ordering and billing records: 7 years after the last invoice (tax rules). Contractual correspondence: duration of contract + 2 years. Module configuration and API logs: retained 12 months rolling, then deleted. Guest data processed for Customers: 30 days after module deactivation unless a Customer instructs earlier deletion in writing. Unsuccessful enquiries: deleted within 12 months.

5. Sharing and international transfers

We do not sell personal data. We share only with providers acting under written contracts as our processors: EU-region cloud hosting for application infrastructure, an email service provider for transactional mail, a payment initiation provider for emailed payment links, and UK-accounting software for invoices. A current sub-processor list is available on request at support@pmsrezlynx.com and changes are announced by email 30 days in advance with objection rights. Where processing occurs outside the UK, we rely on adequacy regulations, the International Data Transfer Addendum to EU Standard Contractual Clauses, or other safeguards permitted by the UK GDPR.

6. Security measures

Encrypted transport (TLS 1.2+), encrypted storage volumes, least-privilege API keys scoped per property, two-factor authentication on internal tools, quarterly dependency patching, centralised audit logging of administrative actions, and tested backup restoration. No Host Platform passwords are ever requested, known or stored by us.

7. Your rights

Under the UK GDPR you have rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent, plus the right not to be subject to solely automated decisions with significant effects. Requests are answered free of charge within one month (extendable once by two months for complex cases) after verifying identity. If you are unhappy with our response you may complain to the Information Commissioner’s Office (ico.org.uk). We respond to verified complaints about controller matters within 30 days.

8. Children

Our services are aimed at hospitality businesses; we do not knowingly collect data from persons under 16 except where a Customer lawfully provides it as part of booking records processed under their own policy.

Retention schedule — detail

Record typeHolderPeriodThen
Orders, invoices, payment referencesSupplier7 years after last invoiceHMRC-aligned disposal
Customer business contact recordsSupplierContract term + 24 monthsErased or anonymised
Module configuration snapshots and API audit logsSupplierRolling 12 monthsPurged automatically
Guest data handled as processorOn Customer instruction30 days after module deactivationCertified deletion on request
Enquiries that did not become ordersSupplier12 monthsDeleted without prompt
Support correspondenceSupplierContract term + 12 monthsReduced to issue summary

Processing inventory by module type

The following table records, per product family, what personal data the module touches in normal operation. Aggregates and system metrics are not personal data unless combined with identifiers; where that combination occurs it is stated.

Module familyData processedNotes
Booking widgetContact details supplied by the guest during checkout on the Customer’s own siteStored by the Customer’s PMS; the module transmits only order references
Messaging (SMS / email journeys)Name, mobile or email address, stay dates, message delivery metadataDelivery receipts retained 90 days for dispute resolution
eSign arrival packsSignature event, document hash, IP fragment of signing device, consent wording versionNo biometric signature data is generated
Revenue & occupancy analyticsAggregated KPI series; no personal identifiers beyond property-level credentialsIdeal for privacy-minimising deployments
Loyalty / CRM scoringDerived recency-frequency-monetary scores and tier labels per guest recordProfiling transparency set out below
Rate parity & metasearch toolingNone — operates on published prices onlyN/A

Sub-processors — current register

We engage a deliberately short list of processor categories, each under a written contract with UK GDPR Article 28 terms:

We use no advertising networks, no data brokers and no social media pixels anywhere in the stack. The named vendor list behind each category above is available on request; additions are announced to account contacts at least 30 days before go-live with a fair objection window, during which affected Customers may terminate the impacted licence pro-rata.

Automated decision-making and profiling

Loyalty scoring and rate recommendations are decision-support outputs: a human (you) validates them before any live price changes or guest-facing treatment follows. We do not carry out solely automated decisions producing legal or similarly significant effects within the meaning of Article 22 UK GDPR. You can switch off scoring components per module from your account settings without affecting the remainder, and historical scores are recalculable so an opt-out never corrupts prior reporting.

Data subject requests, DPO route and breach SLA

Requests (access, rectification, erasure, restriction, portability, objection) go to support@pmsrezlynx.com marked “Data rights”. Identity is verified through your existing account relationship where one exists; otherwise via two-point verification. We answer free of charge within one calendar month, extendable once by two further months for genuinely complex cases with written explanation of why the extension applies.

Data-protection queries intended for our privacy lead should be marked “DPO” in the subject line and route to the same address. As a processor we notify affected Customers of personal-data breaches without undue delay and within 48 hours of confirmation, supplying scope indicators, containment status and remediation timeline in a structured incident note. Internally we run a semi-annual DPIA-lite review across every module family, tracked in our risk register.

9. Changes and versioning

Material changes are notified by email to account contacts 30 days before taking effect and dated above. Historic versions remain available on request.

HomeCatalogPricingRezlynxAboutFAQSupportContact
HomeCatalogPricingRezlynxAboutFAQSupportContact