Privacy Policy
Version 2.1 · last updated 21 September 2026
1. Who we are (the controller)
PMS Solution Ltd is the controller for personal data collected through this website (https://www.pmssolution.com) and while providing our Services. Registered in England & Wales (Companies House, Cardiff), company number 14720956, registered office Suite 4D, 53 Whitworth Street, Manchester M1 3WR, United Kingdom. Contact: support@pmssolution.com. We are registered with the Information Commissioner’s Office under reference ZA741350.
2. Categories of data we process
Website visitors: no analytics or advertising cookies are set by default; we store your cookie-banner choice and basket contents in local browser storage. Contact-form messages are stored as email correspondence.
Customers and prospective customers: business contact names, work email addresses, phone numbers, property names and platform identifiers needed to licence and operate modules.
Guest data processed on behalf of Customers: when a Customer activates guest-facing modules (for example messaging or e-signature), we process guest identifiers, stay dates, room references, contact details and document data strictly under the Customer’s instructions.
3. Purposes and lawful bases
| Purpose | Data | Basis |
|---|---|---|
| Selling and administering subscriptions | Customer business contacts | Contract (Art. 6(1)(b)) |
| Technical operation of modules via Host Platform APIs | Credentials, config, logs | Contract; legitimate interests (Art. 6(1)(f)) |
| Guest-facing processing on Customer instruction | Guest records | Controller-to-controller/processor terms; Customer ensures Art. 6 basis |
| Invoicing, accounting, tax | Billing details | Legal obligation (Art. 6(1)(c)) |
| Fraud prevention, security logging | Access logs, IP fragments | Legitimate interests |
4. Retention periods
Ordering and billing records: 7 years after the last invoice (tax rules). Contractual correspondence: duration of contract + 2 years. Module configuration and API logs: retained 12 months rolling, then deleted. Guest data processed for Customers: 30 days after module deactivation unless a Customer instructs earlier deletion in writing. Unsuccessful enquiries: deleted within 12 months.
5. Sharing and international transfers
We do not sell personal data. We share only with providers acting under written contracts as our processors: EU-region cloud hosting for application infrastructure, an email service provider for transactional mail, a payment initiation provider for emailed payment links, and UK-accounting software for invoices. A current sub-processor list is available on request at support@pmssolution.com and changes are announced by email 30 days in advance with objection rights. Where processing occurs outside the UK, we rely on adequacy regulations, the International Data Transfer Addendum to EU Standard Contractual Clauses, or other safeguards permitted by the UK GDPR.
6. Security measures
Encrypted transport (TLS 1.2+), encrypted storage volumes, least-privilege API keys scoped per property, two-factor authentication on internal tools, quarterly dependency patching, centralised audit logging of administrative actions, and tested backup restoration. No Host Platform passwords are ever requested, known or stored by us.
7. Your rights
Under the UK GDPR you have rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent, plus the right not to be subject to solely automated decisions with significant effects. Requests are answered free of charge within one month (extendable once by two months for complex cases) after verifying identity. If you are unhappy with our response you may complain to the Information Commissioner’s Office (ico.org.uk). We respond to verified complaints about controller matters within 30 days.
8. Children
Our services are aimed at hospitality businesses; we do not knowingly collect data from persons under 16 except where a Customer lawfully provides it as part of booking records processed under their own policy.
Retention schedule — detail
| Record type | Holder | Period | Then |
|---|---|---|---|
| Orders, invoices, payment references | Supplier | 7 years after last invoice | HMRC-aligned disposal |
| Customer business contact records | Supplier | Contract term + 24 months | Erased or anonymised |
| Module configuration snapshots and API audit logs | Supplier | Rolling 12 months | Purged automatically |
| Guest data handled as processor | On Customer instruction | 30 days after module deactivation | Certified deletion on request |
| Enquiries that did not become orders | Supplier | 12 months | Deleted without prompt |
| Support correspondence | Supplier | Contract term + 12 months | Reduced to issue summary |
Processing inventory by module type
The following table records, per product family, what personal data the module touches in normal operation. Aggregates and system metrics are not personal data unless combined with identifiers; where that combination occurs it is stated.
| Module family | Data processed | Notes |
|---|---|---|
| Booking widget | Contact details supplied by the guest during checkout on the Customer’s own site | Stored by the Customer’s PMS; the module transmits only order references |
| Messaging (SMS / email journeys) | Name, mobile or email address, stay dates, message delivery metadata | Delivery receipts retained 90 days for dispute resolution |
| eSign arrival packs | Signature event, document hash, IP fragment of signing device, consent wording version | No biometric signature data is generated |
| Revenue & occupancy analytics | Aggregated KPI series; no personal identifiers beyond property-level credentials | Ideal for privacy-minimising deployments |
| Loyalty / CRM scoring | Derived recency-frequency-monetary scores and tier labels per guest record | Profiling transparency set out below |
| Rate parity & metasearch tooling | None — operates on published prices only | N/A |
Sub-processors — current register
We engage a deliberately short list of processor categories, each under a written contract with UK GDPR Article 28 terms:
- EU-region cloud hosting provider running application services and encrypted backups;
- transactional email platform delivering confirmations and account notices;
- SMS gateway aggregator handling carrier submission for messaging modules;
- hosted payment initiation provider used for emailed card-payment links;
- UK bookkeeping software storing invoice copies for statutory accounting.
We use no advertising networks, no data brokers and no social media pixels anywhere in the stack. The named vendor list behind each category above is available on request; additions are announced to account contacts at least 30 days before go-live with a fair objection window, during which affected Customers may terminate the impacted licence pro-rata.
Automated decision-making and profiling
Loyalty scoring and rate recommendations are decision-support outputs: a human (you) validates them before any live price changes or guest-facing treatment follows. We do not carry out solely automated decisions producing legal or similarly significant effects within the meaning of Article 22 UK GDPR. You can switch off scoring components per module from your account settings without affecting the remainder, and historical scores are recalculable so an opt-out never corrupts prior reporting.
Data subject requests, DPO route and breach SLA
Requests (access, rectification, erasure, restriction, portability, objection) go to support@pmssolution.com marked “Data rights”. Identity is verified through your existing account relationship where one exists; otherwise via two-point verification. We answer free of charge within one calendar month, extendable once by two further months for genuinely complex cases with written explanation of why the extension applies.
Data-protection queries intended for our privacy lead should be marked “DPO” in the subject line and route to the same address. As a processor we notify affected Customers of personal-data breaches without undue delay and within 48 hours of confirmation, supplying scope indicators, containment status and remediation timeline in a structured incident note. Internally we run a semi-annual DPIA-lite review across every module family, tracked in our risk register.
9. Changes and versioning
Material changes are notified by email to account contacts 30 days before taking effect and dated above. Historic versions remain available on request.