How we secure your data
A plain-language summary of the technical and organisational measures behind PMS Rezlynx modules — written for owners, general managers and IT reviewers evaluating whether to grant our software an API credential.
Hosting regions and infrastructure
Application workloads run primarily in a London region, which keeps guest and booking data within the United Kingdom for the majority of properties we serve. A Frankfurt region acts as secondary site for disaster recovery continuity; replication between the two travels over private, encrypted links and satisfies transfer safeguards under the UK GDPR. Property-specific requests to pin all processing to one jurisdiction are accommodated wherever provider capacity allows — say so during activation and it becomes part of your order record.
Infrastructure is provisioned from code rather than clicked together: environment definitions are version-controlled, reviewed and re-applied identically across staging and production, so what was audited last quarter is exactly what runs today.
Encryption and key handling
All endpoints enforce TLS 1.2 or newer; older protocol versions are rejected outright rather than merely discouraged. Data at rest sits on volumes encrypted with AES-256. Credentials supplied through activation links are encrypted before storage, accessible only to the module runtime that needs them, never printed into logs, never emailed in clear text.
API access between modules and hosts uses short-lived scoped tokens: each token carries only the permissions agreed in your read/write matrix, expires automatically, and is refreshed without widening its scope. Long-lived secrets exist only where a provider interface demands them, and those are rotated every twelve months or immediately on suspicion.
Internal access control
Staff accounts operate under least privilege with mandatory two-factor authentication — including on monitoring dashboards and build systems, not just production consoles. Production data is viewed only through masked interfaces by default; unmasking requires a logged justification tied to a support ticket. Every administrative action lands in a centralised audit log retained for twelve months, available to you on request during incident reviews or contract due diligence.
No PMS Rezlynx employee ever holds, sees or needs the password of any hotel platform account. If anyone claiming to represent us asks you for one over email or telephone, treat it as impersonation and tell us.
Patching cadence
Operating system and platform patches apply inside thirty days of release under normal severity, seventy-two hours when critical. Dependencies receive a full sweep every quarter, plus targeted upgrades whenever advisories touch components we expose publicly. Each sweep runs against a staging clone first; regression results are attached to release notes so your team can see what changed and why.
Backups and continuity
Backups run continuously with a fifteen-minute recovery point objective; restoration drills execute quarterly against the stated two-hour recovery time objective, and drill records are kept alongside the audit log. Failover exercises cover database restore, webhook replay from dead-letter queues and token re-validation, because a backup that has never been restored is a hope rather than a plan.
Vulnerability disclosure
Report suspected vulnerabilities to security@pmsrezlynx.com — acknowledgement arrives within one business day, a triage assessment within five. We practise coordinated disclosure: reporters are credited by name where they wish, timelines are shared openly, and fixes ship with regression notes. Please avoid destructive testing on shared infrastructure; we can issue isolated evaluation environments for serious testers on request.
Sub-processors and supervision
We deliberately keep the processor chain short. Beyond the core infrastructure described above, named categories currently include transactional email delivery, hosted payment-link issuance and UK accounting software for invoicing — each bound by written processing terms, listed in detail in the privacy policy, with changes announced thirty days in advance and objection rights preserved. Personal data processing happens strictly under your instruction as controller; this website and our modules alike operate under ICO registration ZA685214, supervised by the Information Commissioner's Office in line with the UK GDPR and the Data Protection Act 2018.