Privacy Policy
Version 2.2 · last updated 10 October 2026
1. Who we are (the controller)
Mersey Software Ltd trading as HotelSolutionsMod is the controller for personal data collected through this website (https://www.holetsolutionsmod.com) and while providing our Services. Registered in England & Wales (Companies House, Cardiff), company number 13492871, registered office 4th Floor, 14 Castle Street, Liverpool L2 0NE, United Kingdom. Contact: support@holetsolutionsmod.com. We are registered with the Information Commissioner’s Office under reference ZA610394. Our privacy lead handles controller-side queries; where we act as processor for a Customer, that Customer remains your first point of contact for guest-data rights.
2. Categories of data we process
Website visitors: no analytics or advertising cookies are set by default; we store your cookie-banner choice and basket contents in local browser storage. Contact-form messages are stored as email correspondence and any details you volunteer.
Customers and prospective customers: business contact names, work email addresses, phone numbers, property names, platform identifiers and billing references needed to licence, invoice and operate modules.
Guest data processed on behalf of Customers: when a Customer activates guest-facing modules (for example messaging or e-signature), we process guest identifiers, stay dates, room references, contact details and document data strictly under the Customer’s instructions, and only for the duration the module remains active.
Supplier and contractor contacts: identity, bank and engagement details of people and firms we buy services from.
3. Purposes and lawful bases
| Purpose | Data | Basis |
|---|---|---|
| Selling and administering subscriptions | Customer business contacts | Contract (Art. 6(1)(b)) |
| Technical operation of modules via Host Platform APIs | Credentials, config, logs | Contract; legitimate interests (Art. 6(1)(f)) |
| Guest-facing processing on Customer instruction | Guest records | Controller-to-processor terms; Customer ensures Art. 6 basis |
| Invoicing, accounting, tax | Billing details | Legal obligation (Art. 6(1)(c)) |
| Fraud prevention, security logging | Access logs, IP fragments | Legitimate interests |
| Responding to enquiries and support tickets | Correspondence contents | Pre-contract steps / contract; legitimate interests |
| Service announcements and renewal notices | Account contact details | Contract; soft opt-in for existing-customer service email |
We do not send marketing email to non-customers, we do not buy contact lists, and we do not profile visitors for advertising. Service-critical announcements (security notices, renewal reminders, incident updates) are sent because they are part of the service you bought, not because you consented to marketing.
4. Retention periods
Ordering and billing records: 7 years after the last invoice (tax rules). Contractual correspondence: duration of contract + 2 years. Module configuration and API logs: retained 12 months rolling, then deleted. Guest data processed for Customers: 30 days after module deactivation unless a Customer instructs earlier deletion in writing. Unsuccessful enquiries: deleted within 12 months. Support correspondence is reduced to an issue summary 12 months after contract end.
5. Sharing and international transfers
We do not sell personal data. We share only with providers acting under written contracts as our processors: EU-region cloud hosting for application infrastructure, an email service provider for transactional mail, an SMS gateway aggregator where messaging modules are licensed, a payment initiation provider for emailed payment links, and UK-accounting software for invoices. A current sub-processor list is available on request at support@holetsolutionsmod.com and changes are announced by email 30 days in advance with objection rights. Where processing occurs outside the UK, we rely on adequacy regulations, the International Data Transfer Addendum to EU Standard Contractual Clauses, or other safeguards permitted by the UK GDPR. Law-enforcement or regulator requests are answered only where legally compelled, and Customers are notified unless prohibited.
6. Security measures
Encrypted transport (TLS 1.2+), encrypted storage volumes, least-privilege API keys scoped per property, two-factor authentication on internal tools, quarterly dependency patching, centralised audit logging of administrative actions, tested backup restoration, and segregated environments so production credentials never appear in development. No Host Platform passwords are ever requested, known or stored by us. Access to guest-level data is limited to the automated pipelines of the specific module licensed, plus named engineers under break-glass procedure with full audit trail.
7. Cookies and local storage
This site itself sets no tracking cookies. Two first-party local-storage items exist: your basket contents and your banner choice, both described in the Cookie & Storage Policy. Font files load from a public CDN whose provider sees a standard request log (IP, user-agent, timestamp); we receive no analytics back from that. Embedded payment links are hosted by the payment provider under its own privacy terms and apply only when you choose to pay.
8. Automated decision-making and profiling
Loyalty scoring and rate recommendations are decision-support outputs: a human (you) validates them before any live price changes or guest-facing treatment follows. We do not carry out solely automated decisions producing legal or similarly significant effects within the meaning of Article 22 UK GDPR. You can switch off scoring components per module from your account settings without affecting the remainder, and historical scores are recalculable so an opt-out never corrupts prior reporting.
9. Your rights
Under the UK GDPR you have rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent, plus the right not to be subject to solely automated decisions with significant effects. Requests are answered free of charge within one month (extendable once by two months for complex cases) after verifying identity. If you are unhappy with our response you may complain to the Information Commissioner’s Office (ico.org.uk). We respond to verified complaints about controller matters within 30 days. Where we act purely as processor, we forward your request to the relevant Customer without delay.
10. Children
Our services are aimed at hospitality businesses; we do not knowingly collect data from persons under 16 except where a Customer lawfully provides it as part of booking records processed under their own policy.
Retention schedule — detail
| Record type | Holder | Period | Then |
|---|---|---|---|
| Orders, invoices, payment references | Supplier | 7 years after last invoice | HMRC-aligned disposal |
| Customer business contact records | Supplier | Contract term + 24 months | Erased or anonymised |
| Module configuration snapshots and API audit logs | Supplier | Rolling 12 months | Purged automatically |
| Guest data handled as processor | On Customer instruction | 30 days after module deactivation | Certified deletion on request |
| Enquiries that did not become orders | Supplier | 12 months | Deleted without prompt |
| Support correspondence | Supplier | Contract term + 12 months | Reduced to issue summary |
Processing inventory by module type
The following table records, per product family, what personal data the module touches in normal operation. Aggregates and system metrics are not personal data unless combined with identifiers; where that combination occurs it is stated.
| Module family | Data processed | Notes |
|---|---|---|
| Booking widget | Contact details supplied by the guest during checkout on the Customer’s own site | Stored by the Customer’s PMS; the module transmits only order references |
| Messaging (SMS / email journeys) | Name, mobile or email address, stay dates, message delivery metadata | Delivery receipts retained 90 days for dispute resolution |
| eSign arrival packs | Signature event, document hash, IP fragment of signing device, consent wording version | No biometric signature data is generated |
| Revenue & occupancy analytics | Aggregated KPI series; no personal identifiers beyond property-level credentials | Ideal for privacy-minimising deployments |
| Rate parity & metasearch tooling | None — operates on published prices only | N/A |
Sub-processors — current register
We engage a deliberately short list of processor categories, each under a written contract with UK GDPR Article 28 terms:
- EU-region cloud hosting provider running application services and encrypted backups;
- transactional email platform delivering confirmations and account notices;
- SMS gateway aggregator handling carrier submission for messaging modules;
- hosted payment initiation provider used for emailed card-payment links;
- UK bookkeeping software storing invoice copies for statutory accounting.
We use no advertising networks, no data brokers and no social media pixels anywhere in the stack. The named vendor list behind each category above is available on request; additions are announced to account contacts at least 30 days before go-live with a fair objection window, during which affected Customers may terminate the impacted licence pro-rata.
Data subject requests, DPO route and breach SLA
Requests (access, rectification, erasure, restriction, portability, objection) go to support@holetsolutionsmod.com marked “Data rights”. Identity is verified through your existing account relationship where one exists; otherwise via two-point verification. We answer free of charge within one calendar month, extendable once by two further months for genuinely complex cases with written explanation of why the extension applies.
Data-protection queries intended for our privacy lead should be marked “DPO” in the subject line and route to the same address. As a processor we notify affected Customers of personal-data breaches without undue delay and within 48 hours of confirmation, supplying scope indicators, containment status and remediation timeline in a structured incident note. Internally we run a semi-annual DPIA-lite review across every module family, tracked in our risk register, and a fuller DPIA whenever a module begins processing a new category of personal data.
11. Changes and versioning
Material changes are notified by email to account contacts 30 days before taking effect and dated above. Historic versions remain available on request. Continued use of the Services after the effective date of a change constitutes acceptance, save that changes reducing your statutory rights never take effect by silence alone.