Where guest data lives
Each production environment is built in Amazon Web Services' London region (eu-west-2) when a hotel signs — we don't run an empty one in advance, so today there is none. Guest data at rest, including backups and uploaded files, stays in that region, encrypted. Some of our processors handle data outside the UK — OpenAI, which powers the assistant, is in the United States — under documented transfer safeguards; the full list is in our privacy policy.
What we do (and don't) do with your data
Guest transcripts and your knowledge-base content stay in your account. We do not use guest data to train any model — yours, ours, or a third party's. The retrieval system that powers your Concierge runs against your private corpus only, with no leakage to other customers.
We will use only aggregate, fully anonymised metrics (response time, deflection rate, channel mix) to inform our product roadmap. Nothing identifying ever leaves your account.
GDPR and DPA
Innquire processes guest personal data on your behalf as a Data Processor under the GDPR. A Data Processing Addendum (DPA) is available on request and forms part of every customer contract. The DPA covers sub-processors, data export, deletion timelines, and breach notification commitments.
Guests can exercise their GDPR rights (access, rectification, erasure) directly through your Innquire dashboard. Administrative actions are written to a hash-chained audit log you can verify on screen; the seven-year write-once archive of that log is switched on and proved when your production environment is built.
AI safety
The Concierge is built on retrieval-augmented generation against your private knowledge base. Prompting is conservative: when the system isn't confident, it deflects to a human rather than guessing. This is intentional — we'd rather lose a deflection metric than damage a guest's trust.
Every AI reply is logged with its source citations. If a guest's complaint references something the AI said, you can see exactly which knowledge-base passages informed the answer and when they were last updated.
The model cannot take a payment or check a guest out on its own: the guest confirms both on screen. The one outbound lookup it can make — live web search — is off unless your hotel switches it on.
Compliance roadmap
SOC 2 is on our security roadmap; we're happy to share our current control inventory under NDA. ISO 27001 is on the longer-term roadmap for larger deployments that require it.
Integration security
Our Mews adapter (built, and tested read-only with each hotel during onboarding before any writes are enabled; Cloudbeds, Apaleo and Opera are on the roadmap) uses Mews's official Connector API, with credentials stored encrypted.
Payments run through Stripe and follow PCI-SAQ-A: card data never touches Innquire's servers. Tokens only.
Reporting a vulnerability
If you've found a security issue, please email security@innquire.uk. We acknowledge within one business day and aim for resolution timelines that scale with severity. We do not currently run a public bug bounty but we welcome responsible disclosure.