Legal

Privacy Policy

Version 2.2 · last updated 10 October 2026

1. Who we are (the controller)

Mersey Software Ltd trading as HotelSolutionsMod is the controller for personal data collected through this website (https://www.holetsolutionsmod.com) and while providing our Services. Registered in England & Wales (Companies House, Cardiff), company number 13492871, registered office 4th Floor, 14 Castle Street, Liverpool L2 0NE, United Kingdom. Contact: support@holetsolutionsmod.com. We are registered with the Information Commissioner’s Office under reference ZA610394. Our privacy lead handles controller-side queries; where we act as processor for a Customer, that Customer remains your first point of contact for guest-data rights.

2. Categories of data we process

Website visitors: no analytics or advertising cookies are set by default; we store your cookie-banner choice and basket contents in local browser storage. Contact-form messages are stored as email correspondence and any details you volunteer.
Customers and prospective customers: business contact names, work email addresses, phone numbers, property names, platform identifiers and billing references needed to licence, invoice and operate modules.
Guest data processed on behalf of Customers: when a Customer activates guest-facing modules (for example messaging or e-signature), we process guest identifiers, stay dates, room references, contact details and document data strictly under the Customer’s instructions, and only for the duration the module remains active.
Supplier and contractor contacts: identity, bank and engagement details of people and firms we buy services from.

3. Purposes and lawful bases

PurposeDataBasis
Selling and administering subscriptionsCustomer business contactsContract (Art. 6(1)(b))
Technical operation of modules via Host Platform APIsCredentials, config, logsContract; legitimate interests (Art. 6(1)(f))
Guest-facing processing on Customer instructionGuest recordsController-to-processor terms; Customer ensures Art. 6 basis
Invoicing, accounting, taxBilling detailsLegal obligation (Art. 6(1)(c))
Fraud prevention, security loggingAccess logs, IP fragmentsLegitimate interests
Responding to enquiries and support ticketsCorrespondence contentsPre-contract steps / contract; legitimate interests
Service announcements and renewal noticesAccount contact detailsContract; soft opt-in for existing-customer service email

We do not send marketing email to non-customers, we do not buy contact lists, and we do not profile visitors for advertising. Service-critical announcements (security notices, renewal reminders, incident updates) are sent because they are part of the service you bought, not because you consented to marketing.

4. Retention periods

Ordering and billing records: 7 years after the last invoice (tax rules). Contractual correspondence: duration of contract + 2 years. Module configuration and API logs: retained 12 months rolling, then deleted. Guest data processed for Customers: 30 days after module deactivation unless a Customer instructs earlier deletion in writing. Unsuccessful enquiries: deleted within 12 months. Support correspondence is reduced to an issue summary 12 months after contract end.

5. Sharing and international transfers

We do not sell personal data. We share only with providers acting under written contracts as our processors: EU-region cloud hosting for application infrastructure, an email service provider for transactional mail, an SMS gateway aggregator where messaging modules are licensed, a payment initiation provider for emailed payment links, and UK-accounting software for invoices. A current sub-processor list is available on request at support@holetsolutionsmod.com and changes are announced by email 30 days in advance with objection rights. Where processing occurs outside the UK, we rely on adequacy regulations, the International Data Transfer Addendum to EU Standard Contractual Clauses, or other safeguards permitted by the UK GDPR. Law-enforcement or regulator requests are answered only where legally compelled, and Customers are notified unless prohibited.

6. Security measures

Encrypted transport (TLS 1.2+), encrypted storage volumes, least-privilege API keys scoped per property, two-factor authentication on internal tools, quarterly dependency patching, centralised audit logging of administrative actions, tested backup restoration, and segregated environments so production credentials never appear in development. No Host Platform passwords are ever requested, known or stored by us. Access to guest-level data is limited to the automated pipelines of the specific module licensed, plus named engineers under break-glass procedure with full audit trail.

7. Cookies and local storage

This site itself sets no tracking cookies. Two first-party local-storage items exist: your basket contents and your banner choice, both described in the Cookie & Storage Policy. Font files load from a public CDN whose provider sees a standard request log (IP, user-agent, timestamp); we receive no analytics back from that. Embedded payment links are hosted by the payment provider under its own privacy terms and apply only when you choose to pay.

8. Automated decision-making and profiling

Loyalty scoring and rate recommendations are decision-support outputs: a human (you) validates them before any live price changes or guest-facing treatment follows. We do not carry out solely automated decisions producing legal or similarly significant effects within the meaning of Article 22 UK GDPR. You can switch off scoring components per module from your account settings without affecting the remainder, and historical scores are recalculable so an opt-out never corrupts prior reporting.

9. Your rights

Under the UK GDPR you have rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent, plus the right not to be subject to solely automated decisions with significant effects. Requests are answered free of charge within one month (extendable once by two months for complex cases) after verifying identity. If you are unhappy with our response you may complain to the Information Commissioner’s Office (ico.org.uk). We respond to verified complaints about controller matters within 30 days. Where we act purely as processor, we forward your request to the relevant Customer without delay.

10. Children

Our services are aimed at hospitality businesses; we do not knowingly collect data from persons under 16 except where a Customer lawfully provides it as part of booking records processed under their own policy.

Retention schedule — detail

Record typeHolderPeriodThen
Orders, invoices, payment referencesSupplier7 years after last invoiceHMRC-aligned disposal
Customer business contact recordsSupplierContract term + 24 monthsErased or anonymised
Module configuration snapshots and API audit logsSupplierRolling 12 monthsPurged automatically
Guest data handled as processorOn Customer instruction30 days after module deactivationCertified deletion on request
Enquiries that did not become ordersSupplier12 monthsDeleted without prompt
Support correspondenceSupplierContract term + 12 monthsReduced to issue summary

Processing inventory by module type

The following table records, per product family, what personal data the module touches in normal operation. Aggregates and system metrics are not personal data unless combined with identifiers; where that combination occurs it is stated.

Module familyData processedNotes
Booking widgetContact details supplied by the guest during checkout on the Customer’s own siteStored by the Customer’s PMS; the module transmits only order references
Messaging (SMS / email journeys)Name, mobile or email address, stay dates, message delivery metadataDelivery receipts retained 90 days for dispute resolution
eSign arrival packsSignature event, document hash, IP fragment of signing device, consent wording versionNo biometric signature data is generated
Revenue & occupancy analyticsAggregated KPI series; no personal identifiers beyond property-level credentialsIdeal for privacy-minimising deployments
Rate parity & metasearch toolingNone — operates on published prices onlyN/A

Sub-processors — current register

We engage a deliberately short list of processor categories, each under a written contract with UK GDPR Article 28 terms:

  • EU-region cloud hosting provider running application services and encrypted backups;
  • transactional email platform delivering confirmations and account notices;
  • SMS gateway aggregator handling carrier submission for messaging modules;
  • hosted payment initiation provider used for emailed card-payment links;
  • UK bookkeeping software storing invoice copies for statutory accounting.

We use no advertising networks, no data brokers and no social media pixels anywhere in the stack. The named vendor list behind each category above is available on request; additions are announced to account contacts at least 30 days before go-live with a fair objection window, during which affected Customers may terminate the impacted licence pro-rata.

Data subject requests, DPO route and breach SLA

Requests (access, rectification, erasure, restriction, portability, objection) go to support@holetsolutionsmod.com marked “Data rights”. Identity is verified through your existing account relationship where one exists; otherwise via two-point verification. We answer free of charge within one calendar month, extendable once by two further months for genuinely complex cases with written explanation of why the extension applies.

Data-protection queries intended for our privacy lead should be marked “DPO” in the subject line and route to the same address. As a processor we notify affected Customers of personal-data breaches without undue delay and within 48 hours of confirmation, supplying scope indicators, containment status and remediation timeline in a structured incident note. Internally we run a semi-annual DPIA-lite review across every module family, tracked in our risk register, and a fuller DPIA whenever a module begins processing a new category of personal data.

11. Changes and versioning

Material changes are notified by email to account contacts 30 days before taking effect and dated above. Historic versions remain available on request. Continued use of the Services after the effective date of a change constitutes acceptance, save that changes reducing your statutory rights never take effect by silence alone.