Legal

CERQA privacy policy

Last updated: 2026-08-28

CERQA is a digital concierge and guest experience platform for hotels. Hotels use it to give guests access to services during their stay and to run their own operations. This page explains in plain language what data goes into the platform, who answers for it and what you can ask for.

Who answers for your data

The hotel is the data controller: it decides which data is processed and why. CERQA is the processor: we process the data on the hotel's instructions and on its behalf.

In practice this means access, rectification and erasure requests go to the hotel, and CERQA cannot delete a hotel's records on its own, not even at the request of the person they describe.

What the platform collects — guests

  • Reservation data received from the hotel's property management system: name, room number, arrival and departure dates, and the stay's access code.
  • Orders and requests you place: room service, hotel shop, laundry, amenities, table bookings, and the notes you attach to them.
  • Chat messages with the hotel and their attachments, including the language you chose for translation.
  • Do-not-disturb and cleaning preferences you set for your room.
  • The language you select and basic usage of the guest pages, used to show the hotel which services are in demand.

Guest access is tied to the stay. The access code expires at checkout and the guest session stops working from that moment.

What the platform collects — hotel staff

  • First name, last name, email, phone, job title and department, created by the hotel from the dashboard.
  • Shifts, time-off requests and clock-in/clock-out records.
  • Latitude and longitude: only when clocking in or out, and only if the location permission was granted. If it is denied, the punch is still recorded, without coordinates.
  • Chat messages, their attachments and reactions.
  • Task and cleaning assignment status, form and survey responses, and support tickets.
  • Notification token, device platform and chosen language.

What the platform does NOT collect

  • No advertising identifiers and no advertising.
  • No tracking across other apps or websites.
  • No access to your contacts, health data, financial data or browsing history.
  • We do not sell data and we do not share it with data brokers.

Payments

CERQA does not take card details. Charges for services ordered during a stay are settled through the hotel's own systems and payment provider, and appear on the folio the hotel issues.

Third parties that are genuinely involved

Supabase: hosting and database. Everything listed above lives there.

Apaleo and equivalent property management systems: reservation data flows between the hotel's PMS and CERQA so the platform knows who is staying and until when.

Apple (APNs) and Google (FCM): they deliver push notifications. A notification carries readable text, which means its content and the fact that you use the platform for that hotel pass through those services. It is not advertising or tracking, but it is a real disclosure and we prefer to state it rather than hide it. If you turn notifications off, nothing is sent.

AI providers: the concierge assistant and message translation send the text of your question, and the relevant hotel content, to an artificial intelligence service that generates the reply. That service processes the text only to answer you; it is not used to train models or for advertising.

Google: only if you sign in with your Google account. It is optional and serves only to access an account the hotel already created.

GetYourGuide: when you open an excursion recommendation, you leave CERQA for their site, which applies its own privacy policy.

How long data is kept

Guest chat content and service requests are kept for the stay and for the period the hotel needs to resolve billing and disputes, then deleted or anonymised for statistics.

Time and absence records for staff are not erased on request: they are employment records the hotel is required by law to keep, including after someone leaves. In Spain, RD-ley 8/2019 sets four years. GDPR allows this in Article 17(3)(b), which exempts processing necessary to comply with a legal obligation.

Your rights

You can ask for access to your data, its rectification, its erasure, restriction of processing and portability. Those requests go to the hotel, who decides. If you write to us, we pass the request to whoever administers the account.

Hotel staff can also request account deletion directly — the account deletion page lists exactly what is erased and how to ask for it.

Complaints

If you believe your data is not being handled properly, you can complain to a data protection authority: in Spain, the Agencia Española de Protección de Datos (AEPD, www.aepd.es); in Germany, the federal authority (BfDI) or your state authority. If you live elsewhere, to your country's supervisory authority.

Contact

Write to us at privacidad@cerqa.de.