1. Who are we?

This privacy policy (hereinafter the "Policy") describes how the company:

  • HOXBOOK SAS,

  • A simplified joint-stock company (Société par actions simplifiée),

  • registered with the Paris Trade and Companies Register (RCS) under number 849 409 313,

  • with its registered office located at 61 rue de Lyon 75012 Paris, France,

(hereinafter "Hoxbook", "we", "us") processes personal data as part of:

  • the public website https://www.hoxbook.com (hereinafter the "Site");

  • and the SaaS software platform accessible notably via https://www.app.hoxbook.com (hereinafter the "Platform").

For any questions regarding personal data protection, you can contact us at:

  • Email: admin@hoxbook.com

  • Postal address: HOXBOOK SAS, 61 rue de Lyon 75012 Paris, France

2. Hoxbook's role: data controller / data processor
2.1 When Hoxbook acts as a data controller

Hoxbook acts as a data controller within the meaning of Regulation (EU) 2016/679 of 27 April 2016 ("GDPR") and the French Data Protection Act:

  • for processing operations carried out via the Site (managing contact forms, information requests, B2B sales development, managing professional customer accounts, technical logs related to Site consultation);

  • for certain processing operations carried out via the Platform when necessary to manage the relationship with its business Customers (contract management, billing, support, usage tracking for security and performance purposes).

2.2 When Hoxbook acts as a data processor

For personal data processing operations carried out via the Platform on behalf of Customers (for example, reservation management, property customer relationship management, transactional SMS/email communications), the Customer acts as the data controller and Hoxbook acts as a data processor within the meaning of the GDPR.

In this context:

  • the Customer solely determines the core purposes and means of the processing (what data is collected, what messages are sent, which campaigns are configured, etc.);

  • Hoxbook processes personal data only on documented instructions from the Customer, solely for the performance of the Services;

  • Hoxbook’s detailed obligations as a processor are set out in the "GDPR Data Processing Agreement" Annex attached to the Terms of Service (TOS) and forming an integral part of the contract concluded with the Customer.

3. What data do we collect and for what purposes?

The categories of data collected depend on your relationship with Hoxbook (Site visitor, Platform user, customer of our Customers, etc.).

3.1 Data processed as a data controller
3.1.1 Site visitors and B2B prospects

When you visit the Site or get in touch with us (via contact form or email), Hoxbook may process, in particular:

  • identification and contact details: title, last name, first name, professional email address, phone number, job title, company;

  • request details: subject of the message, content of the request, date and time of contact;

  • technical navigation data: technical logs, IP addresses, connection metadata, device and browser information, for the security and proper functioning of the Site.

Main purposes:

  • managing and following up on contact and information requests;

  • managing commercial relationships and B2B sales development, in compliance with applicable electronic communication rules;

  • ensuring Site security, preventing abuse and intrusion attempts, and producing aggregated technical visitor statistics.

Legal bases:

  • performance of pre-contractual measures at the request of the data subject (responding to an information request);

  • Hoxbook's legitimate interest in developing its B2B business, subject to the rights of the data subjects;

  • compliance with legal obligations (security, dispute management).

3.1.2 Business Customers and Platform Users (Hoxbook side)

As part of managing relationships with its business Customers and the use of the Platform, Hoxbook may process, as a data controller, in particular:

  • identification and contact details of the Customer's representatives and Users: title, last name, first name, professional email address, job title, account login details;

  • contractual and billing data: billing details, information required for contract management, payment deadlines, history of contractual exchanges;

  • technical Platform usage data for security and support purposes: connection logs, activity history, security metadata;

Main purposes:

  • managing the contractual relationship with Customers (subscription, execution, follow-up, and termination of the contract);

  • managing User Accounts, roles, and permissions;

  • billing, accounting, payment processing, and collection management;

  • support, assistance, and maintenance of the Platform;

  • security, preventing fraud and abuse, and improving the quality and performance of the Services.

Legal bases:

  • performance of the contract concluded with the Customer;

  • compliance with legal obligations (especially regarding billing and accounting);

  • Hoxbook's legitimate interest in ensuring the security and proper functioning of the Platform and improving its Services, subject to the rights of the data subjects.

3.2 Data processed as a processor on behalf of Customers

As part of the use of the Platform by Customers (hotels, residences, accommodation establishments), Hoxbook processes, on their behalf, the following personal data, as defined in the TOS and its GDPR annex:

  • Establishment guests' data:

    • identification and contact details (title, last name, first name, contact info, etc.);

    • booking and stay details (dates, room type, services, preferences, history);

    • guest relationship details (communications, special requests, etc.).

  • Customer's internal data:

    • details of the Customer's employees, staff, service providers, and suppliers;

    • details of the Customer's Users (accounts, permissions, activity logs, connection logs);

  • Technical and security data:

    • logs, technical journals, connection metadata, activity traces, and security data required to run and secure the Platform.

  • Transactional communication content:

    • content of transactional messages (emails and SMS) sent via the Platform on behalf of the Customer (booking confirmations, stay information, etc.).

No credit card data is stored by Hoxbook under the Services described in the TOS.

The purposes of this processing (booking management, guest communication, internal operational management of the establishment, etc.) are determined by each Customer, in their capacity as data controller, and detailed in the documentation they provide to their own guests, employees, and partners.

In this context, Hoxbook does not use the data processed on behalf of the Customer for any purposes other than the performance of the Services, unless required by law or specifically agreed upon with the Customer.

4. Subprocessors, hosting, and data transfers
4.1 Main hosting of the Platform

The primary application data processed via the Hoxbook Platform, including data hosted in the application and the main database, is hosted by Supabase on infrastructure located in Metropolitan France, in accordance with the primary settings configured by Hoxbook.

For the main hosting of the application and database, Hoxbook does not arrange any voluntary transfer of this data outside of France or the European Economic Area.

4.2 Technical subprocessors and communication providers

Hoxbook may use sub-processors for limited purposes, including:

  • Supabase: main hosting and database;

  • Cloudflare: DNS, network security, and, where applicable, content delivery services;

  • SendGrid: sending transactional emails;

  • Twilio: sending transactional SMS.

Processing related to transactional emails and SMS is carried out via providers located in Ireland, within the European Union, in accordance with the settings configured by Hoxbook.

The data shared with these providers is strictly limited to what is necessary:

  • for hosting and running the Platform;

  • for sending, deliverability, security, and tracking of communications (email address and/or phone number, elements required for personalization, message content, technical metadata).

Unless subject to a duly justified legal, evidentiary, or security constraint, data related to transactional communications is retained only for the time strictly necessary for processing, and then deleted within a maximum of thirty (30) days.

4.3 Customer information on subprocessors

The sub-processors that Hoxbook may use for processing carried out on behalf of Customers (as a data processor under the GDPR) are listed and governed in the "GDPR Data Processing Agreement" Annex attached to the TOS. Hoxbook will inform Customers of any plan to add or replace a sub-processor under the conditions set out in the contract.

5. Retention periods

Hoxbook retains personal data for no longer than is necessary for the purposes for which it is processed, and in any event in compliance with the retention periods set out in the TOS, the GDPR annex, and applicable regulations.

As an indication:

  • transactional communication data sent via SendGrid and Twilio is kept for the time strictly necessary for delivery, deliverability, and security, and then deleted within a maximum of thirty (30) days, unless a legal or evidentiary constraint applies;

  • logs, technical journals, and security data are kept for a period reasonably necessary for Platform security, incident detection, and establishing proof in the event of a dispute;

  • contract management and billing data is retained for the duration of the contractual relationship, and then archived for the applicable legal statute of limitations.

For processing carried out as a processor, retention periods are determined by the Customer (the data controller); Hoxbook returns and/or deletes the data at the end of the contract, under the conditions set out in the TOS and the GDPR annex.

6. Data security

Hoxbook implements appropriate technical and organizational measures in line with industry standards, implementation costs, the nature, scope, context, and purposes of processing, as well as risks to the data subjects.

These measures include, depending on the environments concerned:

  • encryption of data in transit;

  • cryptographic protection of backups and, where relevant, data at rest;

  • permission management and access controls;

  • user and administrator authentication;

  • logging of access and relevant actions;

  • regular backups;

  • security controls or audits at reasonable intervals;

  • continuity, recovery, and resilience measures.

While Hoxbook implements reasonable security measures, it cannot guarantee the absolute absence of security incidents, intrusion, corruption, loss, alteration, or unavailability of data, particularly when the incident originates outside its sphere of control.

7. Your rights (GDPR) and how to exercise them
In accordance with applicable regulations, you have the following rights regarding your personal data, under the conditions defined by law:
  • right of access;

  • right to rectification;

  • right to erasure (right to be forgotten);

  • right to restriction of processing;

  • right to object, particularly regarding sales development;

  • right to data portability, where applicable;

  • right to set guidelines regarding the handling of your data after your death.

7.1 When Hoxbook is the data controller

For processing where Hoxbook is the data controller (Site, Customer relationship management, use of the Platform by Customer Users on Hoxbook's side), you can exercise your rights by contacting us at:

  • Email: [GDPR contact email to be completed]

  • Postal address: HOXBOOK SAS, [address to be completed]

We may ask you to provide appropriate proof of identity if necessary.

7.2 When Hoxbook acts on behalf of a Customer

For processing carried out by Hoxbook on behalf of a Customer (establishment guest data, Customer's internal data, etc.), it is up to that Customer, in their capacity as data controller, to handle your requests to exercise your rights.

In this case, we invite data subjects to contact the relevant establishment (hotel, residence, etc.) directly. If Hoxbook receives a request regarding such data, we will forward it to the Customer data controller without responding to it directly, unless instructed otherwise by the Customer or required by law.

7.3 Lodging a complaint with the supervisory authority

You also have the right to lodge a complaint with the competent supervisory authority, and in France specifically with the CNIL (www.cnil.fr).

8. Cookies and trackers

The Site and Platform may use cookies or similar technologies, in particular to:

  • enable the correct technical functioning of our online Services (authentication, maintaining sessions, security);

  • improve browsing comfort;

  • produce aggregated audience measurements.

Cookies strictly necessary for the operation of the Services are placed without prior consent, within the limits allowed by regulations. Other cookies, when used, are implemented in compliance with applicable rules and, where appropriate, subject to your consent through a dedicated banner or preference module.

Additional information may be provided in a specific cookie banner or cookie policy accessible from the Site.

9. Updates to this Policy

This Policy may be updated, in particular to reflect:

  • potential legislative or regulatory developments;

  • changes to the processing operations carried out by Hoxbook;

  • the addition or replacement of sub-processors under the conditions agreed with Customers.