Privacy Policy
InnSyst
Effective Date: March 2026 Last Updated: April 17, 2026
1. Introduction
This Privacy Policy ("Policy") explains how InnSyst ("we," "our," "us," or "Company") collects, uses, discloses, and otherwise processes personal information from hotel operators, staff members, and guests through our website (innsyst.com), our cloud-based hotel management platform (hotel.presidiumservices.com), and related services (collectively, the "Platform").
This Policy also applies to any white-label or partner domains that are powered by the InnSyst platform. These domains operate on the same underlying technology and are subject to the same privacy practices described herein. For a current list of white-label domains covered by this Policy, please contact us at [email protected].
We are committed to protecting your privacy and ensuring you have a transparent understanding of our data practices. This Policy applies to all users of the Platform, including hotels and their staff, and describes your rights regarding your personal information.
Last Updated: March 2026
2. Information We Collect
2.1 Information Provided Directly
Hotel Admin and Staff Information:
Name, email address, phone number, job title, and role
Login credentials and authentication information
Communication preferences and account settings
Guest Information:
Name, email address, phone number, and address
Reservation details (check-in/check-out dates, room preferences)
Payment information (limited to first 6 digits and last 4 digits of credit/debit cards, card type, and expiration month/year) — see Section 4 for payment data handling
Special requests, preferences, and stay history
Guest feedback and reviews
Business Information:
Hotel name, address, and property details
Tax ID or business identification information
Billing and invoice information
2.2 Information Collected Automatically
IP address, browser type, and device type
Pages visited within the Platform and time spent on each page
Referring/exit pages and clickstream data
Platform usage patterns and feature adoption
Cookies and similar tracking technologies (see Section 9)
2.3 Information from Third Parties
Payment processors and financial institutions (transaction status and authorization codes)
Cloud service providers who host our Platform
Integrations with booking systems, communication platforms, or reporting tools
3. Legal Basis for Processing (GDPR Compliance)
We process personal information based on one or more of the following legal grounds:
Contractual Necessity: Processing required to provide the Platform and fulfill our contractual obligations
Legitimate Business Interests: Data processing necessary for security, fraud prevention, analytics, and service improvement
Compliance with Law: Processing required to meet legal or regulatory obligations (e.g., tax, booking regulations)
Consent: Where required by law (e.g., marketing communications), we obtain explicit consent before processing
Performance of Official Tasks: Processing on behalf of hotel customers to facilitate their operations
4. How We Use Information
4.1 Core Platform Operations
Providing, maintaining, and improving the InnSyst
Processing reservations, check-ins, and payments
Managing user accounts and authentication
Providing customer support and responding to inquiries
Sending transactional communications (confirmation emails, receipts, payment notifications)
4.2 Business and Legal Purposes
Detecting and preventing fraud, security incidents, and abuse
Complying with legal obligations and regulations (PCI DSS, GDPR, CCPA, tax requirements)
Enforcing our Terms of Service and other agreements
Responding to legal requests or government inquiries
Protecting the rights, property, and safety of our Company, users, and the public
4.3 Service Improvement and Analytics
Analyzing Platform usage to improve features and user experience
Generating anonymized, aggregated reports and insights (not tied to individuals)
Conducting performance monitoring and technical improvements
Training and optimizing our services
We use the following analytics tools on our website (innsyst.com):
Google Analytics (GA4) — provided by Google LLC. Collects anonymized data about traffic sources, user flow, page views, and demographics to help us understand how visitors use our website.
Microsoft Clarity — provided by Microsoft Corporation. Collects behavioral analytics including heatmaps, scroll tracking, and session recordings to help us understand how visitors interact with our website. Session recordings capture mouse movements, clicks, and scrolls. Sensitive content such as passwords, credit card numbers, and form inputs are automatically masked and never recorded.
Umami Analytics — provided by Umami Software, Inc. A privacy-focused analytics service that collects anonymized traffic statistics including page views, referrers, browser type, and country. Umami does not use cookies and does not collect personally identifiable information.
4.4 Marketing and Communications (with Consent)
Sending product updates and feature announcements
Sending promotional offers and newsletters (only with user consent or opt-in)
Conducting surveys and feedback requests
We do not send marketing communications to guest email addresses without explicit consent from the hotel.
4.5 Payment Data Use
First 6 and last 4 digits of payment cards are used solely for:
Transaction identification and reconciliation
Fraud detection and prevention
Guest convenience (displaying masked card details for recurring charges)
Fulfilling payment processor requirements
Complete payment card numbers are never stored, processed, or retained by our Platform (see Section 4 of our PCI Compliance Statement)
5. Who We Share Information With
5.1 Hotel Staff and Authorized Users
Information is shared with authorized hotel staff members based on their user role and permissions within the Platform. Hotels are responsible for controlling staff access through role-based permissions.
5.2 Payment Processors and Service Providers
We share data with:
PCI DSS-compliant payment processors (for payment authorization and processing)
Cloud infrastructure providers (for hosting and data storage)
Communication service providers (for email delivery, SMS notifications)
Analytics services: Google Analytics (Google LLC), Microsoft Clarity (Microsoft Corporation), and Umami Analytics (Umami Software, Inc.) — anonymized data only
Customer support tools
All service providers are contractually obligated to maintain confidentiality and comply with data protection laws.
5.3 Legal and Regulatory Authorities
We may disclose information when:
Required by law, regulation, or legal process (e.g., court order, subpoena, government request)
Necessary to enforce our Terms of Service and other agreements
Necessary to protect our rights, privacy, safety, and property
Responding to claims of illegal activity or negligence
5.4 Data Sharing with Hotels and Hotel Owners
Hotels are responsible for managing guest data according to applicable privacy laws. Guest information may be shared with:
Hotel management companies and franchise operators (as specified in hotel management agreements)
Hotel ownership and corporate entities
Third parties authorized by the hotel (e.g., marketing vendors, loyalty programs)
Hotels are responsible for obtaining any necessary guest consent before sharing data with third parties.
5.5 Business Transfers
If our Company is acquired, merges with another entity, or undergoes bankruptcy, personal information may be transferred as part of that transaction. Users will be notified of any material change in how their information is handled.
5.6 Anonymized and Aggregated Data
We may share anonymized, aggregated data that cannot identify individuals (e.g., industry benchmarks, usage statistics) with third parties for analytics, research, and business intelligence purposes.
6. Data Retention
6.1 Active User Data
Hotel Staff and Admin Information: Retained during active use of the Platform. Deleted within 30 days of account termination or cancellation of service.
Guest Reservation and Stay Data: Retained for the duration of the hotel's subscription to the Platform. Specific retention periods can be configured by hotels based on their business needs.
6.2 Cardholder Data
Limited Cardholder Data (First 6 and Last 4 Digits): Retained as long as the hotel subscription is active, or per hotel preference. Deleted upon account closure or guest request.
Complete Cardholder Data: Never stored by our Platform. Handled and retained only by PCI DSS-compliant payment processors.
6.3 Transactional and Payment Records
Retained in compliance with tax, accounting, and regulatory requirements (typically 7 years for financial records).
Retained for fraud investigation, chargeback resolution, and legal disputes as necessary.
6.4 Backup Data
Data may be retained in backup systems for up to 30-90 days to ensure business continuity and disaster recovery.
Backup data is subject to the same security and confidentiality protections as active data.
6.5 Legal Hold
If we receive a legal request or become aware of potential litigation, we may retain data beyond normal retention periods as required by law.
7. User Rights and Choices
7.1 GDPR Rights (European Users)
If you are located in the European Union or United Kingdom, you have the following rights:
Right to Access: Request access to your personal information and receive a copy
Right to Rectification: Request correction of inaccurate or incomplete information
Right to Erasure ("Right to be Forgotten"): Request deletion of your personal information, subject to legal exceptions
Right to Restrict Processing: Request limitation on how we use your information
Right to Data Portability: Request your data in a portable format
Right to Object: Object to certain types of data processing
Right to Withdraw Consent: Withdraw consent at any time (doesn't affect prior processing)
Right to Lodge a Complaint: File a complaint with your local data protection authority
Response Timeline: We will respond to data subject requests within 30 days (extendable to 60-90 days for complex requests).
7.2 CCPA Rights (California Residents)
If you are a California resident, you have the following rights:
Right to Know: Request to know what personal information is collected, used, and shared
Right to Delete: Request deletion of personal information (subject to exceptions)
Right to Correct: Request correction of inaccurate personal information
Right to Opt-Out: Opt out of the sale or sharing of personal information
Right to Limit: Limit use and disclosure of sensitive personal information
Right to Non-Discrimination: We do not discriminate for exercising your privacy rights
Response Timeline: We will respond to requests within 45 days. Requests may be extended by an additional 45 days if necessary.
7.3 Other State Privacy Rights
Many other U.S. states (Colorado, Connecticut, Delaware, Indiana, Iowa, Mississippi, Montana, New Hampshire, Tennessee, Utah, Virginia) have enacted privacy laws. If applicable to your state, similar rights to those listed above apply. Contact us for specific information about your state's requirements.
7.4 Marketing Communications
You can opt out of promotional emails and marketing communications by clicking the "Unsubscribe" link in any email or by contacting us.
You can manage communication preferences in your Platform account settings.
We will honor opt-out requests within 10 business days.
7.5 Cookies and Tracking
You can disable cookies in your browser settings, though some Platform features may not function properly.
See Section 9 (Cookies) for additional information and opt-out options.
7.6 Exercising Your Rights
To exercise any of the rights described above, submit a request to:
Email: [email protected] Mail: InnSyst (Presidium Services LLC), 8996 Little Bluestem Dr, Land O Lakes, FL 34637 Web Form: https://innsyst.com/contact
We will verify your identity before processing your request. If you are requesting on behalf of a hotel or business, we may require proof of authorization.
8. Data Security
8.1 Security Measures
We implement industry-standard security controls to protect personal information:
Encryption in Transit: All data transmitted to and from the Platform uses TLS 1.2+ encryption (HTTPS)
Encryption at Rest: Databases and storage systems containing personal information are encrypted using AES-256 or equivalent
Access Controls: Role-based access controls restrict data access to authorized personnel only
Multi-Factor Authentication: MFA required for administrator access to sensitive systems
Firewalls and Network Security: Industry-standard firewalls and intrusion detection systems protect our infrastructure
Vulnerability Management: Regular security assessments, penetration testing, and vulnerability scanning
Patch Management: Timely application of security updates and patches to all systems
Secure Development: Security best practices followed during development, including code reviews and testing
8.2 Incident Response and Breach Notification
In the event of a data breach:
Investigation: We will investigate the breach to determine scope and impact
Notification: We will notify affected users, hotels, and regulators as required by law within the required timeframes:
GDPR: 72 hours to relevant data protection authorities
CCPA/CPRA: Prompt notification to affected individuals
Other States: Per applicable state breach notification laws
Cooperation: We will cooperate with law enforcement and regulatory authorities as required
9. Cookies and Tracking Technologies
9.1 Cookies
We use cookies to:
Maintain your login session and remember preferences
Analyze Platform usage and improve functionality
Prevent fraud and enhance security
Provide a personalized user experience
9.2 Types of Cookies
Essential Cookies: Required for Platform functionality (cannot be disabled)
Performance Cookies: Track usage analytics and performance metrics
Preference Cookies: Remember your settings and choices
Marketing Cookies: Used to deliver personalized content (with consent where required)
9.3 Your Cookie Choices
Most browsers allow you to refuse cookies or alert you when cookies are set
Disabling essential cookies may impair Platform functionality
You can manage cookie preferences through your browser or our cookie management tools
9.4 Do Not Track Signals
Some browsers include a "Do Not Track" feature. Our Platform does not currently respond to "Do Not Track" signals, but you can disable tracking through browser settings and our cookie controls.
10. Data Protection for Hotel Staff and Guests
10.1 Hotel Responsibilities
Hotels using the Platform are responsible for:
Obtaining guest consent where required by law before collecting and processing guest information
Maintaining their own privacy notices and policies for guests
Securing and controlling access to guest information within the Platform
Ensuring compliance with privacy laws applicable to their jurisdiction
Notifying guests of any data breaches affecting guest information
10.2 Platform's Role
We act as a data processor on behalf of hotels. We:
Process data according to hotels' instructions and contracts
Implement appropriate security measures to protect data
Do not use hotel data or guest data for our own marketing or business purposes (except with explicit permission)
Will notify hotels of any data requests or legal orders we receive
Support hotels' compliance with applicable privacy laws
10.3 Data Processing Agreement
Hotels and our Company execute a Data Processing Agreement (DPA) that defines roles, responsibilities, and security obligations for handling guest and hotel data. The DPA incorporates Standard Contractual Clauses for international data transfers where required by GDPR.
11. Children's Privacy
Our Platform is not intended for children under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child, we will delete it immediately.
12. International Data Transfers
12.1 Global Platform
Our Platform operates globally and data may be transferred, stored, or processed in countries other than where you reside. Some countries may not provide the same level of data protection as your home country.
12.2 Data Transfer Mechanisms
For international transfers, we use:
Standard Contractual Clauses (SCCs): For transfers to countries not deemed to have adequate data protection
Privacy Shield or Adequacy Decisions: Where applicable and recognized
Hotel Consent: When required by applicable law
12.3 GDPR Compliance
Data transfers to countries outside the EU/EEA comply with GDPR Chapter V requirements. We execute Standard Contractual Clauses with service providers and sub-processors to ensure adequate safeguards.
13. Third-Party Links and Services
Our Platform may contain links to third-party websites, applications, and services that are not operated by us. We are not responsible for the privacy practices of third-party services. When using third-party integrations or visiting external sites, please review their privacy policies independently.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:
Posting the updated Policy on our website with the "Last Updated" date
Sending you a notification email if the change significantly affects how we handle your data
Requiring your explicit consent if required by law
Your continued use of the Platform following posted updates constitutes your acceptance of the revised Policy. For significant changes, we will provide you with a 30-day notice period.
15. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact:
Data Protection Officer / Privacy Team
Email: [email protected] Phone: (520) 815-7571 Mailing Address: InnSyst (Presidium Services LLC) 8996 Little Bluestem Dr Land O Lakes, FL 34637 United States
EU Data Protection Authority (for GDPR complaints): Contact your local Data Protection Authority
California Attorney General (for CCPA complaints): California Attorney General 300 South Spring Street Los Angeles, CA 90013 Website: oag.ca.gov
16. Additional Information
16.1 Data Retention Schedule
16.2 Legal Basis Reference (GDPR Article 6)
Our processing is justified under:
Article 6(1)(a): Consent (marketing communications, non-essential cookies)
Article 6(1)(b): Contract performance (providing Platform services)
Article 6(1)(c): Legal obligation (tax records, payment processing compliance)
Article 6(1)(f): Legitimate interests (security, fraud prevention, service improvement)
16.3 Acknowledgments
This Privacy Policy complies with GDPR, CCPA/CPRA, and applicable state privacy laws as of April 2026
Policies and practices are reviewed annually and updated to reflect regulatory changes
Professional legal review is recommended before implementing this policy in your jurisdiction
Document prepared: March 2026 Effective Date: March 2026 Last Updated: April 2026 Next Review Date: March 2027
This Privacy Policy is provided for informational purposes and should be reviewed by legal counsel before implementation to ensure compliance with applicable laws in your specific jurisdiction.