PRIVACY POLICY

PMSPilot (Koban Management LLC) Effective from: January 2026 Last updated: August 2026


1. CONTROLLER

Controller within the meaning of the GDPR and national data protection laws:

PMSPilot / Koban Management LLC 30 N Gould St Ste R Sheridan, WY 82801 United States of America Email: [email protected]

Data Protection Officer (DPO): [email protected] The operator/owner acts as Data Protection Officer


2. SCOPE

This Privacy Policy applies to:

  • Users of the PMSPilot website (pmspilot.com)
  • Users of the PMSPilot platform (hoteliers, hospitality businesses)
  • Guests whose data is processed in PMSPilot

It complies with:

  • GDPR (General Data Protection Regulation) — EU countries
  • BDSG (Federal Data Protection Act) — Germany
  • FADP (Swiss Federal Act on Data Protection) — Switzerland
  • DSG (Austrian Data Protection Act) — Austria
  • PDPA (Personal Data Protection Act) — Thailand
  • Privacy Act 1988 — Australia
  • PIPEDA — Canada

3. AUTOMATIC DATA COLLECTION ON WEBSITE VISITS

3.1 Server log data

When visiting pmspilot.com, the following information is collected automatically:

  • IP address of the requesting device
  • Date and time of access
  • Requested files (URL, path)
  • Referring website (referrer)
  • Browser type and operating system
  • Website interaction data (non-identifying)

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in system security, error analysis, abuse detection)

Retention: 30 days (automatically deleted)

3.2 Google Analytics

We use Google Analytics 4 to analyse website usage.

Data collected:

  • Page views and visit duration
  • Country of origin and language
  • Device type (mobile/desktop)
  • Usage flow and conversions

Legal basis: Art. 6(1)(a) GDPR (your explicit consent, required on first visit)

Privacy settings:

  • IP anonymisation is enabled
  • No Google cookies (session-based only)
  • You may decline Google Analytics via the cookie banner on the website

Google processing: Google LLC (USA) — processing under Standard Contractual Clauses (SCCs) pursuant to GDPR Chapter V

Opt-out: https://tools.google.com/dlpage/gaoptout


4. COOKIES

4.1 Types of cookies

We use the following cookies:

Cookie typePurposeLegal basisRetention
Session cookiesLogin, CSRF protectionArt. 6(1)(f) GDPRSession duration
Authentication cookiesTwo-factor authentication (2FA)Art. 6(1)(f) GDPR30 days
Language/theme cookiesStore your language preferenceArt. 6(1)(f) GDPR1 year
Analytics cookiesGoogle Analytics (if enabled)Art. 6(1)(a) GDPR14 months

4.2 Cookie management

On first visit you are asked which cookies you accept:

  • Strictly necessary: enabled automatically
  • Analytics: optional (Google Analytics)
  • Marketing: currently not used

You can manage cookies anytime via Cookie Settings in the footer.


5. DATA PROCESSING IN HOTEL MANAGEMENT

5.1 Guest data

Hoteliers using PMSPilot process the following guest data via the platform:

Identification data:

  • First and last name
  • Email address
  • Phone number
  • Address (street, city, country, ZIP)

Documents & compliance:

  • ID type and number (passport, national ID)
  • Date of birth
  • Nationality
  • (Optional) ID photo (PDPA requirement Thailand)

Reservation & stay data:

  • Arrival and departure dates
  • Room type and price
  • Number of persons
  • Special requests (allergies, accessibility, etc.)

Payment data:

  • Credit card numbers (tokenised, not fully stored)
  • Payment method (Stripe/PayPal)
  • Billing address

Additional data (optional):

  • Reviews and comments
  • Chat messages (OTA Live Chat module)
  • Guest IP address (for security)

5.2 Legal basis for guest data processing

Processing is performed by hoteliers (controllers); PMSPilot is processor (Art. 28 GDPR):

  • Art. 6(1)(b) GDPR: performance of contract (reservation, check-in, billing)
  • Art. 6(1)(c) GDPR: legal obligation (registration duty, tax filing)
  • Art. 6(1)(f) GDPR: legitimate interest (fraud detection, security)

6. RETENTION PERIODS (COUNTRY-SPECIFIC)

PMSPilot deletes and anonymises data automatically according to local laws:

6.1 Thailand (PDPA & Thai Revenue Code)

Data typePeriodRules
Personal data (name, address, etc.)2 years after last checkoutPDPA requirement
ID documents (TM6)1 year after last checkoutPDPA compliance
Check-in details2 yearsPDPA
Booking & invoice data5 yearsThai Revenue Code (statutory)

Automatic cleanup: daily at 03:00 (hotel timezone)

6.2 EU / GDPR (Germany, Austria, Switzerland)

Data typePeriod
Personal guest dataDeleted after end of contract + 3 years (or sooner on request)
ID documentsDeleted after end of contract + 1 year
Booking & invoice data10 years (German Commercial Code HGB §257)
Audit logs7 years (compliance, personal data breaches)

6.3 Australia (Privacy Act)

Data typePeriod
Personal dataDeleted after end of contract + 2 years
ID documentsDeleted after end of contract + 1 year

6.4 Canada (PIPEDA)

Data typePeriod
Personal dataDeleted after end of contract + 2 years

6.5 Anonymisation instead of deletion

After retention periods expire, data is anonymised (not deleted):

  • Names, addresses → removed
  • ID numbers → removed
  • Booking data → retained anonymously for statistics

7. FURTHER PROCESSING

7.1 Premium modules (paid)

If the customer activates the following modules, we additionally process:

ModuleAdditional dataPurpose
Channel ManagerOTA sync data, price updatesSync with Booking.com, Airbnb, etc.
OTA Live ChatChat messages, guest namesLive chat with guests via OTA platforms
Guest reviewsReview texts, ratings, guest namesCollecting & displaying reviews
FiskalyCash register data, transaction detailsGerman fiscal compliance (GoBD)

Legal basis: Art. 6(1)(b) GDPR (performance of contract)

7.2 Automated decision-making

PMSPilot does not use automated decision-making (e.g. creditworthiness, price discrimination).


8. DISCLOSURE TO THIRD PARTIES (SUB-PROCESSORS)

8.1 Sub-processors under Art. 28 GDPR

PMSPilot processes data only with the following certified processors:

Sub-processorCountryPurposeData protection agreement
StripeUSA/EUPayment processing (cards)SCCs, PCI DSS
PayPalUSA/EUPayment processing (PayPal accounts)SCCs
ChannexUSA/EUChannel manager (OTA integration)SCCs
CloudflareUSA/EUCDN, DDoS protection, backupsSCCs
AWSUSA/EU/OtherServer infrastructure, storageSCCs, ISO 27001
SendGridUSAEmail delivery (reservation confirmations)SCCs
Google AnalyticsUSAWebsite analyticsSCCs

Standard Contractual Clauses (SCCs): All sub-processors are protected by SCCs pursuant to GDPR Chapter V.

8.2 Right to object to sub-processors

You may object in writing to a new sub-processor within 30 days ([email protected]).

  • On a justified objection: termination without penalty is possible
  • We notify by email at least 30 days before implementing a new sub-processor

8.3 Disclosure without a processing agreement

Data is not disclosed to:

  • Marketing partners
  • Data brokers
  • Public databases
  • Advertising networks

Exceptions (legally required):

  • Tax authorities (tax filing)
  • Police/judicial authorities (suspicion of criminal offences)
  • Registration authorities (guest registration in some countries)

9. INTERNATIONAL DATA TRANSFERS

9.1 Data flows

  • Primary storage: Cloudflare EU
  • Backups: EU
  • Processing: where technically required for service delivery

9.2 Safeguards

All international transfers occur under:

  • EU Standard Contractual Clauses (SCCs) — GDPR Chapter V
  • Adequacy decisions (where available)
  • Technical encryption (AES-256 at rest, TLS 1.3 in transit)

9.3 Transfers blocked by authorities

If a data protection authority blocks a transfer, data will be moved to EU servers (chargeable to the customer).


10. SECURITY MEASURES

10.1 Technical measures

  • AES-256-GCM encryption for data at rest
  • TLS 1.3 encryption for data in transit
  • Web Application Firewall (WAF) against attacks
  • Intrusion Detection System (IDS)
  • Automated daily backups (geographically distributed)
  • Security patches within 7 days for critical vulnerabilities

10.2 Organisational measures

  • Role-based access control (RBAC)
  • Two-factor authentication (2FA) for all accounts
  • Staff data-protection training (annual)
  • Confidentiality obligations for all staff
  • Audit logs for all data access
  • Incident response plan with 72-hour notification duty

11. DATA SUBJECT RIGHTS

You have the following rights under the GDPR (Art. 12–22):

11.1 Right of access (Art. 15 GDPR)

You may request which of your data PMSPilot processes at any time.

11.2 Right to rectification (Art. 16 GDPR)

You may have inaccurate data corrected.

11.3 Right to erasure (Art. 17 GDPR) — "right to be forgotten"

You may request deletion of your data if:

  • No legal ground for retention remains (e.g. tax duty expired)
  • Your interests prevail (e.g. fraud prevention)

Request: [email protected]

Exceptions: Booking/invoice data must be retained for 5–10 years (tax law)

11.4 Right to restriction (Art. 18 GDPR)

You may request that your data not be processed while lawfulness is reviewed.

11.5 Right to data portability (Art. 20 GDPR)

You may receive your data in a machine-readable format (JSON, CSV, Excel).

  • Export in PMS: Dashboard → "Settings" → "Export data"
  • Or by request: [email protected]

11.6 Right to object (Art. 21 GDPR)

You may object to processing (e.g. marketing emails).

11.7 Right to withdraw consent (Art. 7(3) GDPR)

You may withdraw consent at any time (e.g. for Google Analytics).

11.8 Automated decisions (Art. 22 GDPR)

You have the right not to be subject to decisions based solely on automated processing.

  • PMSPilot does not make automated decisions about you

11.9 Complaint to a supervisory authority (Art. 77 GDPR)

You may lodge a complaint with the competent data protection authority:

CountryAuthorityWebsite
GermanyFederal Commissioner for Data Protection (BfDI)https://www.bfdi.bund.de
AustriaAustrian Data Protection Authority (DSB)https://www.dsb.gv.at
SwitzerlandFederal Data Protection and Information Commissioner (FDPIC)https://www.edoeb.admin.ch
EU generalEuropean Data Protection Board (EDPB)https://edpb.ec.europa.eu

12. PERSONAL DATA BREACHES

12.1 Notification duty (Art. 33 GDPR)

If a personal data breach occurs (hack, data leak, etc.):

  1. PMSPilot notifies you within 72 hours with nature and scope of the breach, affected data/persons, likely consequences and countermeasures taken
  2. You are responsible for notifying authorities (where required) and affected persons

13. CONTACT

13.1 General questions

Email: [email protected] Website: pmspilot.com

13.2 Privacy & data protection concerns

Data Protection Officer (DPO): [email protected] Response time: 14 days

13.3 Business address

Koban Management LLC 30 N Gould St Ste R Sheridan, WY 82801 United States of America


14. CHANGES TO THIS PRIVACY POLICY

We may amend this Privacy Policy. Changes will be:

  • Published on this website
  • Communicated by email (if substantial)
  • Effective 30 days after publication

Last updated: August 2026 Next review: August 2027


© 2026 Koban Management LLC. All rights reserved.

Privacy Policy | PMSPilot