Galaxy HotelCloud

Privacy policy

Last updated: 2 October 2026

Data controller

PassportScan LTD, 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom, VAT GB922941816, is the controller of the data collected by the galaxy-hotel.net website and of the account data of Galaxy Hotel Cloud. For any question about data protection write to info@galaxy-hotel.net.

This notice is given under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and the UK GDPR. It addresses visitors of the website, the people who sign up and use the PMS and, for the part that concerns them, the guests of the properties that use it.

Three different situations

You visit the website or fill in a form: we process the data you leave as controller.

You use Galaxy Hotel Cloud as a user of a property: we process your account data as controller, to provide the service.

You are a guest of a hotel that uses Galaxy Hotel Cloud: the controller of your data is the hotel. We keep the data on its behalf as processor and use it for no other purpose. To exercise your rights, contact the property.

Data collected by the website

The «Try for free» form asks for name, e-mail, phone, property name, number of rooms, country and language, plus a password we keep only in hashed form. The contact form asks for name, e-mail, phone, company, rooms and your message. With every submission we record the IP address and the time, to limit abuse and automated submissions.

Legal basis: the pre-contractual steps you asked for (creation of the trial environment) and, for the contact form, the consent you give by ticking the box. Sign-up requests not confirmed within 48 hours through the link sent by e-mail create no environment.

Distributors

Whoever applies to become a distributor leaves us the company name, VAT number, country, city, name, e-mail and phone of the contact person, website and a message, plus the IP address and time of sending. We use them to assess the application and, if approved, to manage the agreement and pay the commissions (for this the distributor also gives us its bank details). Legal basis: pre-contractual measures requested and the contract; the data of the agreement are kept for its duration and then for the accounting obligations.

If a property signs up with the code or the link of a distributor, that distributor sees its commercial data: name of the property, name, e-mail and phone of the contact person, country, state of the trial or subscription, fee and amounts paid (net). It never sees the data entered in the management software nor those of the guests. The distributor processes them as an independent controller to follow the property commercially; legal basis: the property's choice to name it and our legitimate interest in acknowledging its work. The property can ask us at any time to unlink it from the distributor.

Account data and use of the PMS

For every user of a property we keep name, e-mail, role and permissions, language, hashed password and the date of the last login. We record the operations of the platform (logins, actions of the maintenance portal, API keys created and revoked, calls to the public API per key, webhook deliveries) and the technical logs of the servers, kept for 30 days.

We send you service e-mails: address confirmation, password recovery, notices about the free trial, the subscription and maintenance. We send no newsletter without your consent.

Legal basis: the contract with the property and our legitimate interest in keeping the service secure and preventing abuse.

Billing data and payments

For the subscription we process company name, address, VAT number, billing e-mail and the payment history. Card payments happen on Stripe's pages: the card data is collected and stored by Stripe, we receive only the outcome and a customer identifier. Bank transfers happen outside the service.

Legal basis: the contract and the accounting and tax obligations, which require us to keep billing documents for ten years.

Data entered in the PMS by the properties

Reservations, guest records, identity documents, folios, invoices, contracts with agencies and companies, messages to guests: this is the property's data, and the property is its controller. We process it only on its instructions and within the data processing agreement contained in the Terms of service.

Transmissions to Alloggiati Web, to the regional statistics systems (ISTAT), to SES Hospedajes, to the Italian e-invoicing exchange system and to the PassportScan service start from the PMS on the property's command or setting: recipients and contents are decided by the property.

Where the data is and how we protect it

The service is hosted on Amazon Web Services in the Milan region (eu-south-1), European Union. The database is encrypted at rest, connections travel over TLS, every property has its own database schema separated from the others. Automatic backups run every day and are kept for 7 days. A web application firewall protects access and limits anomalous requests.

Access by our staff to the data of the properties is limited to support and maintenance and is logged. We do not sell data and do not use it for advertising.

Providers and recipients

To provide the service we rely on these providers, which process data on our behalf:

Amazon Web Services EMEA SARL — hosting, database, backups and sending of the platform's e-mails (Milan region).

Stripe Payments Europe Ltd — card payments and subscription management.

Cloudflare, Inc. — anti-bot check (Turnstile) on the forms of the website: it receives IP address, browser and connection characteristics.

jsDelivr — content delivery network that serves the API reference viewer on the Developers page: it receives the IP address of whoever opens it.

Only when the property enables the integration: PassportScan (reading of guest documents), Open-Meteo (weather forecast: receives only the coordinates of the property), Photon by Komoot (address completion: receives the address text, never names).

Stripe and Cloudflare may transfer data outside the European Union under standard contractual clauses and the Data Privacy Framework. The United Kingdom, where the controller is based, is covered by an adequacy decision of the European Commission. We disclose data to authorities only when the law requires it.

How long

Unconfirmed sign-up requests: 30 days, then deleted. Contact requests: 12 months.

Account and property data: for the whole duration of the contract. When the free trial expires or the subscription ends, the environment is suspended and kept for 90 days so that you can reactivate it or export the data; then it is deleted. You can ask for earlier deletion.

Backups: 7 days. Technical and firewall logs: 30 days.

Billing documents: 10 years, as required by law.

Your rights

You can ask for access to your data, rectification, erasure, restriction of processing, portability, and object to processing based on legitimate interest; you can withdraw a consent at any time. Write to info@galaxy-hotel.net: we answer within 30 days.

You have the right to lodge a complaint with a supervisory authority: in Italy the Garante per la protezione dei dati personali, in Spain the AEPD, in France the CNIL, in the United Kingdom the ICO, or the authority of the country where you live.

If you are a guest of a property, your rights are exercised towards the property: if you write to us, we forward the request and help the property answer it.

Cookies

The website and the PMS use no profiling cookies and no analytics tools. What is stored in the browser is described in the Cookie policy.

Minors

The website and the service address businesses and their staff: we do not knowingly collect data of people under 16.

Changes

We update this notice when the service or the providers change. The date at the top marks the latest version; material changes are communicated by e-mail to registered users.