Security & Trust
Your hotel's data, protected.
Concierly is built for hotels that take guest and staff data seriously — encrypted, access-controlled, and designed to support your GDPR obligations from day one.
Our security commitments
The safeguards that protect every room status, work order, and guest record in Concierly.
Encryption in transit and at rest
All data is encrypted in transit with TLS and stored encrypted at rest.
Role-based access controls
Every team member sees only the data their role requires — visibility is limited by role-based access controls.
Regular security audits
We carry out regular security audits and vulnerability assessments.
SOC 2 compliant infrastructure
Concierly runs on SOC 2 compliant infrastructure through our hosting providers.
Breach notification
In the event of a data breach, we notify affected hotel administrators without undue delay — and within 72 hours where the GDPR requires — notify the relevant authorities as required by law, and take immediate steps to contain and remediate the incident.
Data rights built in
Access, correct, and delete personal data — and export it in standard formats.
For procurement & data-protection teams
What your data-protection review needs to know about Concierly.
Concierly is a data processor
Subscribing hotels act as data controllers for their staff and guest data; Concierly processes it on the hotel's behalf.
DPA available on request
If your hotel requires a Data Processing Agreement (DPA) under GDPR or other regulations, contact us at hello@concierly.io.
Sub-processor change notice
We notify hotel administrators of changes to our sub-processors with reasonable advance notice.
International transfers
Where data crosses borders, we ensure adequate protections through standard contractual clauses.
Read the full policies
Every commitment on this page comes from our published policies.
Questions about security?
Book a demo and bring your IT or data-protection team — we'll walk through exactly how Concierly handles your data.