Privacy policy
Last updated: 27 August 2026 · GDPR + Irish Data Protection Act 2018 · DPC registration IE-14872
· I ·Data controller and DPO
The data controller is GuestlinePortal Ltd, 21 Grafton Street, Dublin D02 XH54, Ireland, Ireland. Registered with the Data Protection Commission (DPC) under registration IE-14872. The Data Protection Officer is contactable at dpo@guestlineportal.com, in writing to the Data Protection Officer at the registered office, or by telephone at +353 1 447 55 20.
· II ·Scope
This policy explains how we collect and process personal data of visitors to guestlineportal.com, of Customer users of the Client Portal, and of hotel guests whose data flows through our Service as part of the modules provided to our Customers. Where we process guest data on behalf of a hotel Customer, we act as processor and the hotel Customer is the controller — see the DPA at /dpa. This policy covers our role as controller in respect of the categories listed below.
· III ·Personal data categories
- Website visitors: IP address, browser user-agent, referring page, pages visited, timestamps. Legal basis: Article 6(1)(f) GDPR — legitimate interest in operating and securing the website.
- Client Portal users: full name, work email, property name, work phone, Rezlynx property code. Legal basis: Article 6(1)(b) GDPR — performance of contract.
- Prospects who fill the contact form: full name, email, property name, city or county, message content. Legal basis: Article 6(1)(a) GDPR — consent, given at form submission.
- Support ticket correspondents: full name, email, transcript of the correspondence, attached screenshots. Legal basis: Article 6(1)(b) GDPR — performance of contract, and Article 6(1)(f) — legitimate interest in providing quality support.
- Newsletter subscribers: email address, consent record. Legal basis: Article 6(1)(a) GDPR — consent.
· IV ·Guest data
When our Service processes hotel guest data — reservations, folios, invoice line items, payment card tokens — we act as processor on behalf of the Customer (the hotel). The controller is the Customer. The processing terms are the DPA at /dpa. This policy does not govern that processing.
· V ·Retention
Website visitor logs are retained for 30 days for security and diagnostic purposes and then deleted. Client Portal user records are retained for the duration of the Customer's subscription plus 30 days for retrieval. Contact form messages are retained for 24 months for follow-up. Support tickets are retained for 24 months for quality and audit. Newsletter subscribers are retained until unsubscribe. Financial records (invoices, receipts, bank reconciliation) are retained for seven years to comply with Revenue Commissioners record-keeping obligations.
· VI ·Data location and international transfers
All personal data is stored in the European Union — production data in EU-Central-1 with a Dublin failover. No personal data is transferred outside the European Economic Area. Our email relay (mail.guestlineportal.com) runs from Dublin. Our support ticketing system runs from EU data centres. We do not use any US-hosted CRM, analytics, or marketing automation platform.
· VII ·Data subject rights
You have the right of access, rectification, erasure, restriction of processing, portability and objection under Articles 15 to 22 of the GDPR. To exercise any of these rights write to dpo@guestlineportal.com or to the Data Protection Officer at the registered office. We respond within one calendar month. There is no fee. You also have the right to lodge a complaint with the Data Protection Commission at www.dataprotection.ie, address 21 Fitzwilliam Square South, Dublin 2, D02 RD28, telephone +353 578 684 800.
· VIII ·Cookies
We use essential cookies only for session state and CSRF protection. Analytics and marketing cookies are off by default and only set with your explicit consent through the cookie banner. See /cookies for the full cookie inventory.
· IX ·Security
Access to personal data is restricted to authorised staff on a need-to-know basis. All data is encrypted at rest with AES-256 and in transit with TLS 1.3. Access to production systems requires hardware key MFA. Our security whitepaper at /security-whitepaper details the full control environment.
· X ·Changes
Material changes to this policy are published to /changelog and notified to Client Portal users by email at least 30 days before they take effect. The Irish-specific variant of this notice — with the DPC references and the specific Irish DPA 2018 basis for each processing activity — is at /ie-privacy.