PRIVACY POLICY
PMSPilot (Koban Management LLC) Effective from: January 2026 Last updated: August 2026
1. CONTROLLER
Controller within the meaning of the GDPR and national data protection laws:
PMSPilot / Koban Management LLC 30 N Gould St Ste R Sheridan, WY 82801 United States of America Email: [email protected]
Data Protection Officer (DPO): [email protected] The operator/owner acts as Data Protection Officer
2. SCOPE
This Privacy Policy applies to:
- Users of the PMSPilot website (pmspilot.com)
- Users of the PMSPilot platform (hoteliers, hospitality businesses)
- Guests whose data is processed in PMSPilot
It complies with:
- GDPR (General Data Protection Regulation) — EU countries
- BDSG (Federal Data Protection Act) — Germany
- FADP (Swiss Federal Act on Data Protection) — Switzerland
- DSG (Austrian Data Protection Act) — Austria
- PDPA (Personal Data Protection Act) — Thailand
- Privacy Act 1988 — Australia
- PIPEDA — Canada
3. AUTOMATIC DATA COLLECTION ON WEBSITE VISITS
3.1 Server log data
When visiting pmspilot.com, the following information is collected automatically:
- IP address of the requesting device
- Date and time of access
- Requested files (URL, path)
- Referring website (referrer)
- Browser type and operating system
- Website interaction data (non-identifying)
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in system security, error analysis, abuse detection)
Retention: 30 days (automatically deleted)
3.2 Google Analytics
We use Google Analytics 4 to analyse website usage.
Data collected:
- Page views and visit duration
- Country of origin and language
- Device type (mobile/desktop)
- Usage flow and conversions
Legal basis: Art. 6(1)(a) GDPR (your explicit consent, required on first visit)
Privacy settings:
- IP anonymisation is enabled
- No Google cookies (session-based only)
- You may decline Google Analytics via the cookie banner on the website
Google processing: Google LLC (USA) — processing under Standard Contractual Clauses (SCCs) pursuant to GDPR Chapter V
Opt-out: https://tools.google.com/dlpage/gaoptout
4. COOKIES
4.1 Types of cookies
We use the following cookies:
| Cookie type | Purpose | Legal basis | Retention |
|---|---|---|---|
| Session cookies | Login, CSRF protection | Art. 6(1)(f) GDPR | Session duration |
| Authentication cookies | Two-factor authentication (2FA) | Art. 6(1)(f) GDPR | 30 days |
| Language/theme cookies | Store your language preference | Art. 6(1)(f) GDPR | 1 year |
| Analytics cookies | Google Analytics (if enabled) | Art. 6(1)(a) GDPR | 14 months |
4.2 Cookie management
On first visit you are asked which cookies you accept:
- Strictly necessary: enabled automatically
- Analytics: optional (Google Analytics)
- Marketing: currently not used
You can manage cookies anytime via Cookie Settings in the footer.
5. DATA PROCESSING IN HOTEL MANAGEMENT
5.1 Guest data
Hoteliers using PMSPilot process the following guest data via the platform:
Identification data:
- First and last name
- Email address
- Phone number
- Address (street, city, country, ZIP)
Documents & compliance:
- ID type and number (passport, national ID)
- Date of birth
- Nationality
- (Optional) ID photo (PDPA requirement Thailand)
Reservation & stay data:
- Arrival and departure dates
- Room type and price
- Number of persons
- Special requests (allergies, accessibility, etc.)
Payment data:
- Credit card numbers (tokenised, not fully stored)
- Payment method (Stripe/PayPal)
- Billing address
Additional data (optional):
- Reviews and comments
- Chat messages (OTA Live Chat module)
- Guest IP address (for security)
5.2 Legal basis for guest data processing
Processing is performed by hoteliers (controllers); PMSPilot is processor (Art. 28 GDPR):
- Art. 6(1)(b) GDPR: performance of contract (reservation, check-in, billing)
- Art. 6(1)(c) GDPR: legal obligation (registration duty, tax filing)
- Art. 6(1)(f) GDPR: legitimate interest (fraud detection, security)
6. RETENTION PERIODS (COUNTRY-SPECIFIC)
PMSPilot deletes and anonymises data automatically according to local laws:
6.1 Thailand (PDPA & Thai Revenue Code)
| Data type | Period | Rules |
|---|---|---|
| Personal data (name, address, etc.) | 2 years after last checkout | PDPA requirement |
| ID documents (TM6) | 1 year after last checkout | PDPA compliance |
| Check-in details | 2 years | PDPA |
| Booking & invoice data | 5 years | Thai Revenue Code (statutory) |
Automatic cleanup: daily at 03:00 (hotel timezone)
6.2 EU / GDPR (Germany, Austria, Switzerland)
| Data type | Period |
|---|---|
| Personal guest data | Deleted after end of contract + 3 years (or sooner on request) |
| ID documents | Deleted after end of contract + 1 year |
| Booking & invoice data | 10 years (German Commercial Code HGB §257) |
| Audit logs | 7 years (compliance, personal data breaches) |
6.3 Australia (Privacy Act)
| Data type | Period |
|---|---|
| Personal data | Deleted after end of contract + 2 years |
| ID documents | Deleted after end of contract + 1 year |
6.4 Canada (PIPEDA)
| Data type | Period |
|---|---|
| Personal data | Deleted after end of contract + 2 years |
6.5 Anonymisation instead of deletion
After retention periods expire, data is anonymised (not deleted):
- Names, addresses → removed
- ID numbers → removed
- Booking data → retained anonymously for statistics
7. FURTHER PROCESSING
7.1 Premium modules (paid)
If the customer activates the following modules, we additionally process:
| Module | Additional data | Purpose |
|---|---|---|
| Channel Manager | OTA sync data, price updates | Sync with Booking.com, Airbnb, etc. |
| OTA Live Chat | Chat messages, guest names | Live chat with guests via OTA platforms |
| Guest reviews | Review texts, ratings, guest names | Collecting & displaying reviews |
| Fiskaly | Cash register data, transaction details | German fiscal compliance (GoBD) |
Legal basis: Art. 6(1)(b) GDPR (performance of contract)
7.2 Automated decision-making
PMSPilot does not use automated decision-making (e.g. creditworthiness, price discrimination).
8. DISCLOSURE TO THIRD PARTIES (SUB-PROCESSORS)
8.1 Sub-processors under Art. 28 GDPR
PMSPilot processes data only with the following certified processors:
| Sub-processor | Country | Purpose | Data protection agreement |
|---|---|---|---|
| Stripe | USA/EU | Payment processing (cards) | SCCs, PCI DSS |
| PayPal | USA/EU | Payment processing (PayPal accounts) | SCCs |
| Channex | USA/EU | Channel manager (OTA integration) | SCCs |
| Cloudflare | USA/EU | CDN, DDoS protection, backups | SCCs |
| AWS | USA/EU/Other | Server infrastructure, storage | SCCs, ISO 27001 |
| SendGrid | USA | Email delivery (reservation confirmations) | SCCs |
| Google Analytics | USA | Website analytics | SCCs |
Standard Contractual Clauses (SCCs): All sub-processors are protected by SCCs pursuant to GDPR Chapter V.
8.2 Right to object to sub-processors
You may object in writing to a new sub-processor within 30 days ([email protected]).
- On a justified objection: termination without penalty is possible
- We notify by email at least 30 days before implementing a new sub-processor
8.3 Disclosure without a processing agreement
Data is not disclosed to:
- Marketing partners
- Data brokers
- Public databases
- Advertising networks
Exceptions (legally required):
- Tax authorities (tax filing)
- Police/judicial authorities (suspicion of criminal offences)
- Registration authorities (guest registration in some countries)
9. INTERNATIONAL DATA TRANSFERS
9.1 Data flows
- Primary storage: Cloudflare EU
- Backups: EU
- Processing: where technically required for service delivery
9.2 Safeguards
All international transfers occur under:
- EU Standard Contractual Clauses (SCCs) — GDPR Chapter V
- Adequacy decisions (where available)
- Technical encryption (AES-256 at rest, TLS 1.3 in transit)
9.3 Transfers blocked by authorities
If a data protection authority blocks a transfer, data will be moved to EU servers (chargeable to the customer).
10. SECURITY MEASURES
10.1 Technical measures
- AES-256-GCM encryption for data at rest
- TLS 1.3 encryption for data in transit
- Web Application Firewall (WAF) against attacks
- Intrusion Detection System (IDS)
- Automated daily backups (geographically distributed)
- Security patches within 7 days for critical vulnerabilities
10.2 Organisational measures
- Role-based access control (RBAC)
- Two-factor authentication (2FA) for all accounts
- Staff data-protection training (annual)
- Confidentiality obligations for all staff
- Audit logs for all data access
- Incident response plan with 72-hour notification duty
11. DATA SUBJECT RIGHTS
You have the following rights under the GDPR (Art. 12–22):
11.1 Right of access (Art. 15 GDPR)
You may request which of your data PMSPilot processes at any time.
- Request to: [email protected]
- Response: within 30 days
11.2 Right to rectification (Art. 16 GDPR)
You may have inaccurate data corrected.
- Editable in the PMS dashboard (name, address, etc.)
- Or by request to [email protected]
11.3 Right to erasure (Art. 17 GDPR) — "right to be forgotten"
You may request deletion of your data if:
- No legal ground for retention remains (e.g. tax duty expired)
- Your interests prevail (e.g. fraud prevention)
Request: [email protected]
Exceptions: Booking/invoice data must be retained for 5–10 years (tax law)
11.4 Right to restriction (Art. 18 GDPR)
You may request that your data not be processed while lawfulness is reviewed.
11.5 Right to data portability (Art. 20 GDPR)
You may receive your data in a machine-readable format (JSON, CSV, Excel).
- Export in PMS: Dashboard → "Settings" → "Export data"
- Or by request: [email protected]
11.6 Right to object (Art. 21 GDPR)
You may object to processing (e.g. marketing emails).
- Request: [email protected]
- We honour objections within 14 days
11.7 Right to withdraw consent (Art. 7(3) GDPR)
You may withdraw consent at any time (e.g. for Google Analytics).
- Via Cookie Settings in the footer
- Or by email: [email protected]
11.8 Automated decisions (Art. 22 GDPR)
You have the right not to be subject to decisions based solely on automated processing.
- PMSPilot does not make automated decisions about you
11.9 Complaint to a supervisory authority (Art. 77 GDPR)
You may lodge a complaint with the competent data protection authority:
| Country | Authority | Website |
|---|---|---|
| Germany | Federal Commissioner for Data Protection (BfDI) | https://www.bfdi.bund.de |
| Austria | Austrian Data Protection Authority (DSB) | https://www.dsb.gv.at |
| Switzerland | Federal Data Protection and Information Commissioner (FDPIC) | https://www.edoeb.admin.ch |
| EU general | European Data Protection Board (EDPB) | https://edpb.ec.europa.eu |
12. PERSONAL DATA BREACHES
12.1 Notification duty (Art. 33 GDPR)
If a personal data breach occurs (hack, data leak, etc.):
- PMSPilot notifies you within 72 hours with nature and scope of the breach, affected data/persons, likely consequences and countermeasures taken
- You are responsible for notifying authorities (where required) and affected persons
13. CONTACT
13.1 General questions
Email: [email protected] Website: pmspilot.com
13.2 Privacy & data protection concerns
Data Protection Officer (DPO): [email protected] Response time: 14 days
13.3 Business address
Koban Management LLC 30 N Gould St Ste R Sheridan, WY 82801 United States of America
14. CHANGES TO THIS PRIVACY POLICY
We may amend this Privacy Policy. Changes will be:
- Published on this website
- Communicated by email (if substantial)
- Effective 30 days after publication
Last updated: August 2026 Next review: August 2027
© 2026 Koban Management LLC. All rights reserved.