Privacy Notice (UK GDPR & Data Protection Act 2018)
1. Overview
This Privacy Notice explains how ACCOMODOO.COM LTD (“Accomodoo”, “we”, “our”, “us”) collects, uses, shares and protects personal data when you:
- visit our websites,
- contact us,
- request a demo or trial,
- create an account, or
- use our platform, including operational tools for short-term rental management.
Depending on the context, Accomodoo acts as:
- Controller for its own websites, business, accounts, billing, security, marketing and compliance activities; for the booking administration and payment administration carried out on the websites it operates; and for the Guest Information and Support Services it supplies to Guests.
- Processor only where it makes its software platform available to a third-party business customer that determines the purposes and means of the processing, and processes data under that customer’s documented instructions.
For bookings made through websites operated by Accomodoo, including VeniceApartments.org, Accomodoo is an independent controller of Guest data. The relevant Property Owner remains the supplier of the accommodation and is a separate controller for the rental agreement and for the legal obligations relating to the property.
2. Data controller and contact details
ACCOMODOO.COM LTD 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom Company number: 16327953
ICO registration: ACCOMODOO.COM LTD — Reference ZB978729 (ico.org.uk/register)
Contact emails: Legal and privacy: legal@accomodoo.com Complaints: complaints@accomodoo.com
3. Personal data we collect
Depending on how you interact with us, we may collect:
A) Website and enquiry data (Controller)
- Identification and contact details (name, email, phone, company)
- Enquiry content and communications
- Marketing preferences
B) Account and customer admin data (Controller)
- User profile data for administration, billing and support
- Business details (company name, address, billing information)
- Contract and subscription records
- Support tickets, call notes and troubleshooting logs
C) Booking and platform data
Where Accomodoo operates the booking website, it processes the data below as controller. Where it makes the platform available to a third-party business customer, it processes the same categories as processor for that customer.
- Guest data (name, contact details, booking details, stay dates, messages)
- Identification data of each guest, where required by law for guest registration
- Country of residence and other information used to determine the applicable VAT or tax treatment
- Booking and payment-administration data, including booking amounts, payment status, transaction references, refunds and chargebacks
- Operational data (tasks and checklists for cleaning, check-in and maintenance; status updates; notes; photo reports)
- Owner portal data (owner contact details, tax identification details required for withholding and reporting obligations, portfolio visibility as configured)
- Technical logs for security and reliability
D) Technical and usage data
- IP address, device and browser identifiers, log files, timestamps, referring pages, and feature usage analytics, subject to cookie settings and legal requirements.
Special category data. We do not intentionally collect special category data. If users upload it into free-text fields or documents, we will minimise its use and protect it appropriately.
4. Where we get data from
- Directly from you, through forms, email, calls, platform usage, bookings and guest communications
- From our customers or your employer, where you are a user invited to their workspace
- From devices, cookies and similar technologies (see section 8)
- From connected booking channels, payment providers, Property Owners and authorised local service providers
5. How we use personal data and our legal bases
We process personal data where we have a lawful basis under Article 6 UK GDPR.
Operate, secure and maintain our websites and services Legal basis: legitimate interests
Respond to enquiries, schedule demos and provide customer support Legal basis: contract or steps prior to entering a contract; legitimate interests
Create and administer accounts; billing and subscription management Legal basis: contract; legal obligation (for example, accounting records)
Supply the Guest Information and Support Services to Guests, including the processing of guest data to produce stay-specific information Legal basis: contract with the Guest
Operate the platform for Property Owners, including listing distribution, availability and booking administration Legal basis: contract with the Property Owner; legitimate interests
Administer payments and settlements, and generate the rental agreement on behalf of the Property Owner Legal basis: contract; legitimate interests
Collect and make available guest identification data for the guest registration required by law, and comply with withholding, certification and reporting obligations relating to short-term rentals Legal basis: legal obligation
Determine and record the applicable VAT or tax treatment and issue invoices Legal basis: legal obligation; contract
Service communications, such as security, uptime and product updates Legal basis: legitimate interests; contract where applicable
Marketing communications, where permitted Legal basis: consent and/or legitimate interests, as applicable
Analytics and product improvement Legal basis: legitimate interests, and consent where required for non-essential cookies
Compliance, dispute handling and enforcement Legal basis: legal obligation; legitimate interests
Where we act as a processor for a third-party business customer, that customer is the controller of the relevant guest, owner, booking and platform-content data, we process that data only under the customer’s documented instructions, and that customer is responsible for providing the privacy information required to its own guests, owners and authorised users.
For bookings made through websites operated by Accomodoo, we act as an independent controller and provide that privacy information directly through the privacy policy published on the relevant website.
6. Sharing and disclosures
We may share personal data with:
- the relevant Property Owner, connected booking channels, payment providers and independent local service providers, where necessary to administer bookings and payments and to enable those providers to supply their own services
- service providers and processors (hosting, email, analytics, CRM, customer support tooling, security, backups), acting under contracts and appropriate safeguards
- professional advisers, such as legal and accounting advisers, where necessary
- authorities, where legally required or to protect rights and safety
- parties involved in a corporate transaction, such as buyers, investors and their advisers, with confidentiality safeguards
We do not sell personal data.
7. International transfers
Where personal data is transferred outside the UK, we use recognised safeguards such as UK adequacy regulations, the International Data Transfer Agreement, or other contractual and technical measures appropriate to the transfer risk.
8. Cookies and similar technologies
We use cookies and similar technologies for core functionality and, where enabled, for analytics and performance. Where required, we obtain consent for non-essential cookies. You can control cookies through your browser settings and any on-site cookie controls.
9. Retention
We retain personal data only for as long as reasonably necessary.
Enquiry and sales data is normally retained for up to 24 months. Account, contract, billing and support records may be retained for the duration of the customer relationship and for up to six years afterwards. Booking, invoicing, tax and VAT records are retained for the applicable statutory period.
Identification data is retained only for the period necessary for verification, lawful transmission or reporting.
Where Accomodoo acts as a processor, retention and deletion are governed by the customer contract, customer settings and documented instructions.
Data may be retained for longer where required in connection with a legal obligation, dispute, investigation or claim.
10. Your rights (UK GDPR)
Subject to conditions and exemptions, you may have the right to:
- access, rectification, erasure and restriction
- object to processing based on legitimate interests
- data portability, where applicable
- withdraw consent, where we rely on consent
To exercise your rights: legal@accomodoo.com Complaints: complaints@accomodoo.com
You also have the right to complain to the ICO.
If you are a guest or other third party whose data is processed by a third-party business customer using our platform, we may direct you to that customer, which is the controller. This does not apply to bookings made through websites operated by Accomodoo, where we are the controller and you can contact us directly.
11. Automated decision-making
We do not generally use automated decision-making producing legal or similarly significant effects. If this changes, we will update this Notice and provide appropriate information.
12. Changes to this Notice
We may update this Notice from time to time. The latest version and effective date will be published on our website. Where a change materially affects how we use personal data, we will provide additional notice where required by law.
Data Protection & Information Security Policy
1. About this Policy
This Policy is a public, high-level summary of the organisational and technical measures used by ACCOMODOO.COM LTD (“Accomodoo”, “we”, “our”, “us”) to protect personal data and confidential information. It supports compliance with the UK GDPR and the Data Protection Act 2018, and is designed to reduce the risk of unauthorised access, loss, misuse, alteration or disclosure.
Status: this document is published for transparency. It does not form part of any contract, except to the extent required by applicable law.
2. Who we are
ACCOMODOO.COM LTD 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom Company number: 16327953
ICO registration: ACCOMODOO.COM LTD — Reference ZB978729 (ico.org.uk/register)
Contacts: Legal: legal@accomodoo.com Complaints: complaints@accomodoo.com
3. Scope
This Policy applies to all Accomodoo directors, officers, employees, agency staff and contractors (“Personnel”), and to all information processed by or on behalf of Accomodoo, including:
- personal data processed for operating our websites and customer relationships;
- personal data processed within our platform, including its booking and operations features, and in connection with the listing distribution, booking administration and information services described in our Privacy Notice;
- system credentials, access tokens and other confidential business information.
Personnel must comply with this Policy as a condition of access to Accomodoo systems.
4. Data protection principles
We process personal data in accordance with the UK GDPR principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.
5. Governance and accountability
We maintain a governance framework which includes:
- management accountability for privacy and security;
- a designated privacy and security owner for oversight, training and incident coordination;
- risk-based reviews of higher-risk processing;
- supplier and sub-processor due diligence and contractual controls appropriate to risk.
6. Key security controls (summary)
6.1 Access control
- Access to guest, owner, property and booking-related data is restricted according to role, business need and service scope
- Multi-factor authentication for administrative and cloud accounts
- Joiner, mover and leaver procedures, with prompt revocation on role change or termination
- Strong password and credential management standards
6.2 Encryption and secure communications
- Encryption in transit (TLS 1.2 or above) where supported
- Encryption at rest for supported storage and managed systems
- Secure secret storage for keys and tokens where applicable
6.3 Monitoring, vulnerability management and testing
- Security logging and monitoring proportionate to system risk
- Regular patching and remediation based on severity
- Periodic vulnerability scans and security reviews for internet-facing services
6.4 Resilience and backups
- Backups for critical systems and configuration
- Disaster recovery and business continuity measures proportionate to service criticality
- Periodic restore tests where appropriate
6.5 Training and confidentiality
- Confidentiality obligations for Personnel and need-to-know handling
- Periodic privacy and security awareness training
7. Data lifecycle controls
- Collection and use only for defined purposes, and only the minimum data necessary, including in relation to platform, booking administration and information service activities
- Retention aligned to legal, operational and contractual requirements
- Secure deletion or anonymisation when no longer required
8. International transfers
Where personal data is transferred outside the UK, we use recognised safeguards such as UK adequacy regulations, the International Data Transfer Agreement, or other contractual and technical measures appropriate to risk.
9. Incident and breach management
We maintain procedures to identify, contain, investigate and remediate incidents. Suspected incidents must be reported immediately within the organisation. Where required, we notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware, and notify affected individuals where legally required.
10. Supplier and contractor requirements
Where suppliers or contractors access Accomodoo data, we require appropriate controls including confidentiality, access restrictions, incident notification, and secure return or deletion on termination.
11. Review and changes
This Policy is reviewed at least annually and whenever our processing, systems or risk profile materially changes. The latest version will be published on our website.
