Information Security Policy

How we protect the systems and data our customers depend on, under our ISO/IEC 27001 certified information security management system.

Awaiting legal review. The structure below is agreed. The clauses under each heading are to be drafted and approved by counsel before this page is published.

Owner: Compliance Version: Draft Applies to: All staff, contractors and systems
01

Purpose and scope

The systems, data and people covered, and the relationship to our ISO/IEC 27001 certification.

02

Governance and responsibility

Who owns information security, how it is reviewed, and the reporting line to management.

03

Risk assessment

How security risks are identified, rated and treated, and how often that is repeated.

04

Access control

Least-privilege principles, joiner-mover-leaver process, and administrative access to customer environments.

05

Data classification and handling

How hotel operating data and guest personal data are classified, stored and transmitted.

06

Encryption and key management

Requirements in transit and at rest, and how keys are held.

07

Hosting and physical security

Controls at the hosting layer, including isolation between customers and data residency commitments.

08

Change and vulnerability management

Patching cadence, testing before release, and how vulnerabilities are tracked to closure.

09

Supplier and third-party security

Assessment of subprocessors and vendors, and the terms required of them.

10

Incident response

Detection, triage, containment, customer notification timelines and post-incident review.

11

Business continuity and recovery

Backup, tested restore, and the recovery objectives we commit to.

12

Awareness and training

Security training for staff, and the additional requirements for engineering and support roles.

13

Compliance and audit

Internal audit, external certification audits, and how findings are closed out.

Reporting a security concern

Suspected vulnerabilities or incidents should be reported to [email protected] without delay. Customers with a live incident should also call the 24/7 support line.