Hotel software security and GDPR data protection
How Lodgic360 secures and processes customer data, guest data and personal data in line with the GDPR.
In short
LODGIC360 is cloud hotel software with EU hosting, encryption and role-based access for hotels of every size, from boutique hotels to hotel chains. Its fully integrated platform combines PMS, RMS, CMS and POS on one database, with custom development for each hotel and local Belgian support. A data processing agreement sets out GDPR data processing arrangements.
Last updated:
We take our responsibility for your data seriously. In short: we host within the European Union, encrypt data both in transit and at rest, apply strict per-customer access control, always sign a data processing agreement (DPA), and hold cyber insurance covering up to €250,000 per claim.
Hosting in the EU
Our applications run on modern cloud infrastructure hosted within the European Union.
Encryption in transit & at rest
All connections use TLS/HTTPS; databases and backups are stored encrypted.
Data processing agreement (DPA)
Available on request and a standard part of every customer contract.
Cyber insurance
Coverage up to €250,000 per claim, on top of our own security measures.
1Technical infrastructure
2Third-party connections
3Encryption & database security
4Access control & authentication
5Backups & business continuity
6GDPR — our processing approach
7Rights of data subjects
8Incidents & breach notification
9Continuous improvement
Extra assurance via Hiscox CyberClear
In addition to our technical and organisational measures, KNR BV holds a cyber insurance policy with Hiscox SA, renewed annually. This policy complements — and does not replace — our own security measures.
- Coverage up to €250,000 per claim and per insurance year for cyber incidents (including data breaches, hacking, cyber extortion)
- Additional sub-limits of €50,000 for cyber fraud and €50,000 for invoice manipulation
- Geographic coverage: worldwide, excluding the US and Canada
- Access to the Hiscox incident line (24/7) for rapid assistance in case of a claim
Questions about security or need a DPA?
Get in touch with our team. A data processing agreement is provided separately on request.
Frequently asked questions
Where is my hotel's guest data hosted and how is it protected?
LODGIC360 hosts its applications within the European Union and encrypts databases and backups at rest. Connections between the browser, application and database use TLS/HTTPS. Each customer's environment is logically separated from other customers. As a general rule, personal data is not processed outside the European Economic Area.
Can I restrict hotel staff access according to their roles?
LODGIC360 provides role-based access rights for each hotel operation, including reception, back-office and administrator roles. Staff use individual accounts and can only access the information their role requires. Database row-level security separates customer data. Mandatory password renewal and access management when staff change are also available.
Can hotel data be restored after an incident or staff error?
All production databases receive automated daily backups, which are stored encrypted and periodically tested for recovery. Point-in-time recovery is available following incidents or human error. LODGIC360 also monitors its infrastructure to detect outages proactively. These measures support data recovery and business continuity for hotel operations.
Does LODGIC360 provide a GDPR data processing agreement?
A data processing agreement is included in every customer contract and is also available separately on request, with an up-to-date list of subprocessors. Your hotel remains the data controller, while LODGIC360 processes data according to your instructions and the agreement. Your hotel is the first contact for guest rights requests, with support available for tasks such as exporting or deleting data.
What happens if a security incident affects my hotel's data?
LODGIC360 has an internal procedure for detecting, assessing and following up security incidents. Customers are informed without undue delay when an incident may affect their data. Where legally required, LODGIC360 supports notification to the competent supervisory authority within the statutory 72-hour deadline. Cyber insurance supplements its technical and organisational security measures.