Security
RGPD-first · EU residency

The security posture behind the Hotelminder shortlist.

Hotelminder holds boutique guest data through the modules our customers activate. This page is the written posture — where data lives, who touches it, how we honour RGPD, what happens if something goes wrong. Not the auditor's version; the General Manager's version.

TLS 1.3 everywhere — no unencrypted traffic between browser, module and SiteMinder API
MFA on every admin account — enforced, not optional, no bypass path
OVHcloud Roubaix — the entire stack hosted in France, backups within the EEA

EU data residency

Hotelminder services are hosted on OVHcloud Roubaix, France. All primary databases, application servers, background workers, message queues and file object stores sit inside French OVHcloud datacentres. Backups are geo-distributed across the OVHcloud French footprint (Roubaix, Gravelines and Strasbourg). No production data leaves the European Economic Area at any point, including for disaster recovery.

The observability stack — Datadog and Sentry — runs on the vendors' EU tenants exclusively. Neither tenant receives guest personal data; both are used for module code health signals and non-personal error captures only. This is documented in the Data Processing Addendum and reviewed quarterly.

RGPD Article 32 — security of processing

Hotelminder is a data processor for guest personal data on behalf of the hotel property (the data controller). Article 32 of the RGPD requires appropriate technical and organisational measures. In practice:

  • Encryption in transit — TLS 1.3. All connections between the guest's browser, the module code, the SiteMinder API and the Hotelminder-owned services use TLS 1.3 with modern cipher suites. HSTS is enforced with a two-year max-age.
  • Encryption at rest — AES-256. Every OVHcloud volume that holds guest data is encrypted with AES-256 at the volume layer. Application-level encryption is layered on top of the sensitive fields (guest email addresses, phone numbers, message contents) using envelope encryption with keys held in an OVHcloud Key Management Service.
  • Access control — principle of least privilege. Engineers receive access to production only to resolve a specific incident, time-bound, logged and revoked after resolution. No standing production access exists for any role, including the founder. Break-glass procedures require dual-authorisation.
  • Audit logging. Every access to a guest record is logged with the operator identity, the timestamp, the operation performed and the request context. Logs are retained for eighteen months and are available on request to the property (data controller).

ISO 27001 alignment and ANSSI recommendations

Hotelminder does not currently hold an ISO 27001 certification — the certification calendar is planned for 2027. In the meantime, the internal information security policy is aligned with the Annex A controls of ISO 27001:2022. Independent alignment against the ANSSI (Agence nationale de la sécurité des systèmes d'information) hospitality-sector recommendations is reviewed quarterly by an external French security consultant retained on advisory.

Sub-processors

Guest personal data is processed by a small, named set of sub-processors, listed below with the specific purpose and the residency. This list is versioned in the Data Processing Addendum and thirty days' written notice is given before a sub-processor is added.

  • OVHcloud — hosting and object storage, Roubaix / Gravelines / Strasbourg (France).
  • Cloudflare — edge caching and DDoS mitigation, EU points-of-presence only.
  • Stripe — payment card capture and processing, EU data region.
  • Postmark — transactional email delivery, EU region tenant.
  • Datadog EU — observability, EU tenant, no guest personal data.
  • Sentry EU — error tracking, EU tenant, no guest personal data.
  • Meta WhatsApp Business Cloud — only if the property activates the GuestJoy Concierge Expander module. Meta processes the message content for delivery on the WhatsApp channel; the property is a joint data controller with Meta for that channel.

Incident response and breach notification

Hotelminder maintains a written incident-response runbook, reviewed twice yearly. Detection is via Datadog EU alerting on rate-limit anomalies, error thresholds and unusual data-access patterns. The on-call rotation runs across the three-person advisory team plus the integrations lead. Response objectives are triage within one hour and containment within four.

Per RGPD Article 33, personal-data breaches likely to affect the rights and freedoms of natural persons are notified to the CNIL within 72 hours of detection. The data controller (the property) is notified without undue delay in parallel. A written post-mortem is delivered to affected properties within fifteen working days of resolution.

Bug bounty and responsible disclosure

Hotelminder operates a responsible-disclosure programme reachable at abuse@mindermod.org. In-scope: all mindermod.org production surfaces, the module code endpoints, and the SiteMinder API integration layer. Out of scope: SiteMinder Limited's own infrastructure, third-party sub-processors, denial-of-service testing.

Rewards are paid in EUR by wire transfer within thirty days of report validation, ranging from €100 for low-severity findings to €5 000 for critical remotely-exploitable issues. The bounty desk is staffed by the integrations lead personally — no external triage vendor.

Data subject rights (guest rights under RGPD)

Access, rectification, erasure, restriction and portability requests from a guest are honoured by the property (the data controller) with Hotelminder acting as processor. For requests routed to Hotelminder directly, we forward them to the property within two working days and support the property's response with the export or deletion action within the technical response window RGPD requires. The Data Protection Officer, Camille Dubois-Renard, oversees these flows and is reachable at dpo@mindermod.org.

Auditor asking a specific question? The full Data Processing Addendum is on the legal page. For specific security questionnaires from a property's insurance carrier, group risk team or an ISO 27001 auditor, the advisor team responds within five working days — send the questionnaire to privacy@mindermod.org.