Security & GDPR

    Hotel software security and GDPR data protection

    How Lodgic360 secures and processes customer data, guest data and personal data in line with the GDPR.

    In short

    LODGIC360 is cloud hotel software with EU hosting, encryption and role-based access for hotels of every size, from boutique hotels to hotel chains. Its fully integrated platform combines PMS, RMS, CMS and POS on one database, with custom development for each hotel and local Belgian support. A data processing agreement sets out GDPR data processing arrangements.

    Last updated:

    We take our responsibility for your data seriously. In short: we host within the European Union, encrypt data both in transit and at rest, apply strict per-customer access control, always sign a data processing agreement (DPA), and hold cyber insurance covering up to €250,000 per claim.

    Hosting in the EU

    Our applications run on modern cloud infrastructure hosted within the European Union.

    Encryption in transit & at rest

    All connections use TLS/HTTPS; databases and backups are stored encrypted.

    Data processing agreement (DPA)

    Available on request and a standard part of every customer contract.

    Cyber insurance

    Coverage up to €250,000 per claim, on top of our own security measures.

    1Technical infrastructure

    • Our applications run on modern cloud infrastructure hosted within the European Union. • Every customer environment is logically separated from other customers, so the data of one property is never accessible to another. • PMS, CMS and POS communicate via secure APIs and webhooks, including between themselves. • Development, test and production environments are strictly separated.

    2Third-party connections

    • CMS connections with booking channels (OTAs) run via the certified Channex infrastructure. • Only necessary data (reservation data, no payment card data) is exchanged with these third parties. • For every external connection we verify in advance that the partner operates in a GDPR-compliant way.

    3Encryption & database security

    • Encryption in transit: all connections between browser, application and database use TLS/HTTPS. • Encryption at rest: databases and backups are stored encrypted at infrastructure level. • Passwords are never stored in readable form — only as hashed and salted values.

    4Access control & authentication

    Access to data is limited according to the principle of least privilege: a user only sees and edits what their role requires. • Role-based access rights (e.g. front desk, back office, administrator) per property. • Row Level Security in the database, so the data of customer A is technically unreachable for customer B. • Personal, individual user accounts — no shared logins. • Option for enforced password rotation and access management when staff changes.

    5Backups & business continuity

    • Automated daily backups of all production databases. • Point-in-time recovery in case of incidents or human error. • Backups are stored encrypted and periodically tested for restorability. • Infrastructure monitoring to detect outages proactively.

    6GDPR — our processing approach

    For the data processed through our products (including guest data, reservations and staff data), Lodgic360 (KNR BV) acts as the processor and the hospitality business as the controller. As a customer you decide which data is processed and for what purpose; we process that data only according to your instructions and our agreement. • Data processing agreement (DPA): available on request and a standard part of every customer contract. • Legal basis: performance of the contract between you and your guest, and your legitimate interest as a hotel operator. • Retention periods: data is not kept longer than necessary for the purpose of processing or legal retention obligations. • Transfers outside the EEA: personal data is in principle not processed outside the European Economic Area. • Sub-processors: an up-to-date list of sub-processors is attached to the data processing agreement.

    7Rights of data subjects

    Guests and employees whose data is processed via Lodgic360 retain their rights under the GDPR: the right of access, rectification, erasure, restriction of processing, data portability and objection. As a hospitality business you remain the first point of contact for your guests; we support you where needed to fulfil a request, for example by exporting or deleting data from the system.

    8Incidents & breach notification

    • Internal procedure for detecting, assessing and following up security incidents. • Customers are informed without undue delay of any incident that may affect their data. • Where legally required, we support you with a notification to the competent supervisory authority within the statutory 72-hour deadline.

    9Continuous improvement

    Security is not a one-off project but an ongoing process. We track vulnerabilities and updates of our underlying platforms, apply patches where needed and periodically review our approach in line with the evolution of our product offering (PMS, CMS and POS).
    Cyber insurance

    Extra assurance via Hiscox CyberClear

    In addition to our technical and organisational measures, KNR BV holds a cyber insurance policy with Hiscox SA, renewed annually. This policy complements — and does not replace — our own security measures.

    • Coverage up to €250,000 per claim and per insurance year for cyber incidents (including data breaches, hacking, cyber extortion)
    • Additional sub-limits of €50,000 for cyber fraud and €50,000 for invoice manipulation
    • Geographic coverage: worldwide, excluding the US and Canada
    • Access to the Hiscox incident line (24/7) for rapid assistance in case of a claim

    Questions about security or need a DPA?

    Get in touch with our team. A data processing agreement is provided separately on request.

    Frequently asked questions

    Where is my hotel's guest data hosted and how is it protected?

    LODGIC360 hosts its applications within the European Union and encrypts databases and backups at rest. Connections between the browser, application and database use TLS/HTTPS. Each customer's environment is logically separated from other customers. As a general rule, personal data is not processed outside the European Economic Area.

    Can I restrict hotel staff access according to their roles?

    LODGIC360 provides role-based access rights for each hotel operation, including reception, back-office and administrator roles. Staff use individual accounts and can only access the information their role requires. Database row-level security separates customer data. Mandatory password renewal and access management when staff change are also available.

    Can hotel data be restored after an incident or staff error?

    All production databases receive automated daily backups, which are stored encrypted and periodically tested for recovery. Point-in-time recovery is available following incidents or human error. LODGIC360 also monitors its infrastructure to detect outages proactively. These measures support data recovery and business continuity for hotel operations.

    Does LODGIC360 provide a GDPR data processing agreement?

    A data processing agreement is included in every customer contract and is also available separately on request, with an up-to-date list of subprocessors. Your hotel remains the data controller, while LODGIC360 processes data according to your instructions and the agreement. Your hotel is the first contact for guest rights requests, with support available for tasks such as exporting or deleting data.

    What happens if a security incident affects my hotel's data?

    LODGIC360 has an internal procedure for detecting, assessing and following up security incidents. Customers are informed without undue delay when an incident may affect their data. Where legally required, LODGIC360 supports notification to the competent supervisory authority within the statutory 72-hour deadline. Cyber insurance supplements its technical and organisational security measures.