Data Act & Hoxbook Portability


1. Purpose of this page

Hoxbook is a B2B SaaS solution for hotel management. This page serves as the online Hoxbook portability registry and provides switching information as required by Regulation (EU) 2023/2854 ("Data Act"), specifically Articles 26, 28, and 30. It complements Article 13 of the Hoxbook General Subscription and Service Conditions.

The information below is kept up to date to reflect the methods, formats, data structures, technical limitations, and transparency measures actually applicable to the Hoxbook service.


2. Requesting a provider change or data retrieval

The Client may request: a transfer to another data processing service provider; a transfer to an ICT infrastructure under their control; or the retrieval and subsequent erasure of their exportable data and digital assets.

The request must be sent to admin@hoxbook.com from an authorized contact, specifying the hotel property concerned, the requested scope, and, in the event of a provider change, the relevant contact details of the destination provider.

The contractual notice period to start the process is one (1) month. At the end of this notice, the transition period is generally limited to thirty (30) calendar days. If this timeframe is technically impossible to meet, Hoxbook will notify the Client within fourteen (14) business days of the request, state the reasons, and propose an alternative period not exceeding seven (7) months. The Client may extend the transition period once for a duration they deem more appropriate for their own purposes.

During the transition, the Agreement remains applicable. Hoxbook provides reasonable assistance, cooperates in good faith, maintains Service continuity to the extent applicable, informs the Client of known risks to continuity, and maintains a high level of security.

Once the transition is successfully completed, Hoxbook will notify the Client and the Agreement will be considered terminated for the Services concerned. If the Client only requests the erasure of their data and digital assets without switching providers, termination occurs at the end of the notice period.

After the transition period, exportable data remains recoverable for at least thirty (30) calendar days. It is then deleted in accordance with the Agreement and the GDPR Addendum, subject to legal obligations and normal backup rotation.


3. Switching fees

Hoxbook does not charge any specific fees for switching providers, data egress, or standard exports. Standard service fees remain due during the period in which the Agreement remains active.

Any optional custom development, data transformation, or tailored support service that is not necessary to exercise the rights provided by the Data Act may be subject to a separate quote.


4. Exportable data and digital assets

Exportable data includes input and output data, including metadata, generated or co-generated directly or indirectly by the Client's use of Hoxbook, where it is held by Hoxbook and not excluded by the Data Act.

Depending on the active modules and the data actually present at the time of export, the scope may include:

customers and contacts: internal IDs, contact details, language, tags, and profile information;

bookings and stays: booking and PMS references stored in Hoxbook, dates, room, status, guests, and stay details;

Guest Experience: requests, preferences, notes, and personalization details;

operations: tasks, logs, housekeeping, maintenance, concierge, lost and found, incidents, and operational histories;

restaurant and spa: reservations, requests, and operational data from subscribed modules;

communications: conversations, messages, and metadata still stored in Hoxbook;

marketing: campaigns, audiences, consents, opt-outs, and campaign events still stored;

satisfaction: responses, scores, reviews, and associated data;

users: accounts, roles, and permissions useful for migration, to the extent compatible with security;

attachments: documents and files uploaded by the Client;

Client configuration and digital assets: settings, categories, nomenclatures, and other elements created by the Client, where they are technically portable and the Client holds a right of use independent of the Agreement.


5. Excluded data

Source code, algorithms, trade secrets, methods, internal tools, confidential security settings, internal security logs, anti-fraud data, infrastructure telemetry, and any other data or assets protected by intellectual property rights or constituting a trade secret of Hoxbook or a third party are not exported, where their exclusion is permitted by the Data Act and does not unduly prevent or delay the provider change.

Data originating from a third-party service can only be exported by Hoxbook if it is actually held in Hoxbook and the Client has the necessary rights. Data already deleted in accordance with applicable retention rules cannot be retrieved.


6. Structures, formats, and portability standards

The standard export is organized by logical datasets corresponding to the categories described above. It includes an export manifest, available structured data, and attachments where applicable.

Structured data: CSV UTF-8 and/or JSON UTF-8 depending on the resource type. Attachments: native format where available. Manifest: JSON specifying the schema version, export ID, Client and property concerned, generation date, timezone, and included datasets.

Relevant relationships between datasets are maintained using stable IDs within the export scope. Dates and times use ISO 8601 / RFC 3339 with timezone indicators. JSON documents follow RFC 8259, and CSV files follow RFC 4180 principles.

The online schema is updated whenever an exportable structure or format changes. When common specifications or harmonized interoperability standards become applicable to Hoxbook under the Data Act, Hoxbook will update its interfaces and this registry within the regulatory timeframes.


7. Portability interface and export delivery

To facilitate switching, Hoxbook provides a documented open portability interface, accessible in a non-discriminatory manner to the Client and, when authorized by them, to the destination provider. This interface allows the exportable data to be obtained in the formats described above and is provided without specific switching fees.

Depending on the Service configuration, delivery can be done from the Platform, via a secure temporary URL, or through a documented API / export interface. The details needed to use the interface, including authentication, schema version, reasonable rate limits, and retry mechanisms, are provided alongside the interface itself.

Hoxbook does not impose proprietary formats where structured, commonly used, and machine-readable formats are available to perform the switch.


8. Known technical limitations

A destination provider may use a different data model, business rules, or features than Hoxbook. Hoxbook provides the exportable data and structure information required for the switch, but does not guarantee automatic import by a third-party system or the replication of features unique to Hoxbook.

Data from PMS, telecom operators, or other third-party services may be limited by the Client's rights, the actual stored history, and the restrictions of the third-party service. Hoxbook is not required to develop new technology or services, disclose a trade secret or protected asset, or compromise the security or integrity of the Service to perform the switch.


9. International jurisdictions and access

Hoxbook is subject to French and European Union law. The primary Hoxbook application database is deployed in the eu-west-3 region in Paris (France). Hoxbook's configurations of Twilio SMS and SendGrid use European data residency. Cloudflare provides network and security features on a globally distributed infrastructure.

Certain entities of provider groups, support functions, telecom operators, or network infrastructures may fall under jurisdictions outside the European Economic Area. This does not mean that the primary Hoxbook application database is hosted there. Processing and any transfers are governed in accordance with applicable legal mechanisms and the GDPR Addendum for personal data.


10. Measures regarding requests from third-country authorities

For non-personal data held in the European Union, Hoxbook implements technical, organizational, and contractual measures aimed at preventing international access or transfer that would be incompatible with European Union or French law.

These measures notably include:

choosing European regions for primary application data and services where possible;

encrypting communications, managing access control, and limiting privileged access;

minimizing data shared with providers and binding them contractually;

reviewing the validity, scope, and legal basis of public authority requests;

where legally permitted, challenging or seeking clarification on incompatible or excessive requests;

limiting any sharing strictly to legally required data and notifying the Client when such notification is legally authorized.


11. Updates and contact

This registry is updated whenever a change impacts switching procedures, categories, structures, or formats of exportable data, portability interfaces, technical limitations, or information regarding international jurisdictions and access.

Contact for any portability request or question regarding this page: admin@hoxbook.com.

In the event of any conflict with a mandatory provision of the Data Act, that provision shall prevail. Specific contractual terms remain governed by the Order Form and the General Subscription and Service Conditions, subject to mandatory rights granted to the Client.


References

Regulation (EU) 2023/2854 (Data Act), specifically Chapter VI and Articles 28, 30, and 32; Hoxbook General Subscription and Service Conditions; Hoxbook GDPR Addendum.