Back to Dashboard

Privacy Policy

Effective: January 1, 2026 — Last updated: June 1, 2026

1. Data We Collect

We collect name, email, phone, payment method, stay preferences, and loyalty program data to fulfill your reservation and provide hotel services. We log AI interactions as required by the EU AI Act.

2. Automated Decision-Making (GDPR Article 22)

We use AI systems for dynamic pricing, fraud scoring, and room recommendations. You have the right to request human review of any automated decision that significantly affects you. Contact privacy@prismhms.com to exercise this right.

3. EU AI Act Compliance

Our dynamic pricing and fraud detection systems are registered as high-risk AI systems per EU AI Act Article 6. Enforcement deadline: August 1, 2026. All AI decisions are logged and available upon request.

4. Data Retention

Guest records: 7 years (tax compliance). AI decision logs: 3 years (EU AI Act). Folio records: 7 years (GAAP). Digital key logs: 2 years (security).

5. Your Rights

Under GDPR, you have the right to access, rectify, erase, and port your data. EU residents may file complaints with your national supervisory authority. To exercise your rights: privacy@prismhms.com

6. AI Communication Consent

AI-generated communications (pre-arrival messages, loyalty offers, post-stay follow-ups) are only sent with your explicit consent. You may withdraw consent at any time by emailing privacy@prismhms.com.

7. Digital Keys

Digital room keys are issued via a third-party digital key provider and are revoked immediately upon checkout. Door access logs are retained for 90 days for security purposes.

Data Controller: Prism HMS / Cosby AI Solutions LLC
Contact: privacy@prismhms.com | security@prismhms.com

Powered by Cosby AI Solutions — cosbyaisolutions.com