Jason Noronha, CEO and Co-founder of D3x, on the Skift Data + AI Summit Europe panel, 6 October, LondonMeet D3x at IHS Munich, 16-17 September, stand B56New episode: The Return of the Great Hotelier, with L+R HotelsLive across 60+ European hotel groupsNew deployments live in 3 weeksVoice agents at chain scaleAI Lobby Talk: CIO interviews on YouTubePlatform docs & changelogJason Noronha, CEO and Co-founder of D3x, on the Skift Data + AI Summit Europe panel, 6 October, LondonMeet D3x at IHS Munich, 16-17 September, stand B56New episode: The Return of the Great Hotelier, with L+R HotelsLive across 60+ European hotel groupsNew deployments live in 3 weeksVoice agents at chain scaleAI Lobby Talk: CIO interviews on YouTubePlatform docs & changelog
D3x

Answers

Is hotel AI GDPR compliant?

Hotel AI is GDPR compliant when the vendor meets four conditions: data hosted in the EU, a signed data processing agreement (DPA), guest data never used to train third-party foundation models, and audit logs of every AI action. D3x meets all four: EU-hosted and GDPR-aligned, with SOC 2 Type II certification in progress.

01

Why does GDPR compliance depend on the vendor, not the technology?Link to this section

GDPR doesn't prohibit AI processing guest data; it regulates how. Guest messages contain names, reservation details, and sometimes payment or health information, and under GDPR the hotel is the data controller while the AI vendor is a processor. That means the hotel carries the compliance risk of the vendor's architecture, which is why the checklist below belongs in every procurement.

02

What four things should you verify before signing?Link to this section

A compliant setup is checkable in one due-diligence pass. Require written answers on each point:

  • EU data residency: guest data stored and processed in the EU, without silent transfers to US infrastructure outside recognised safeguards
  • A DPA plus data minimisation: a signed data processing agreement, defined retention periods, and a guarantee that guest data is never used to train third-party foundation models
  • Auditability and control: logs of every AI action with its rationale, human-in-the-loop escalation, and a clear process for data subject access and deletion requests

03

Where does D3x stand on GDPR and data residency?Link to this section

D3x is EU-hosted and GDPR-aligned: customer and guest data is never used to train third-party foundation models, every AI action is logged with its rationale, and hotel logic is enforced above the LLM through the Skills Engine. SOC 2 Type II certification is in progress, adding independently audited controls on top of the GDPR posture. That same governance is why the hotel AI implementation timeline stays short, days to weeks on standard integrations, without weakening the DPA. Hotels running regulated, multi-country portfolios, including groups like Staycity and Best Western properties, operate on this architecture today.

Generally no separate consent is required to respond to a guest's own inquiry, that processing rests on contract performance or legitimate interest. Consent becomes relevant for marketing messages, and hotels should disclose AI use transparently in their privacy notice.

SEE IT IN PRODUCTION

Ready to see hotel AI in production?Link to this section

D3x runs 250K+ hotel messages a month — agents that execute in your PMS, housekeeping, and CRM across messaging, email, and voice.

TALK TO US

Get the answer for your own properties.Link to this section

30 minutes with the founder, your stack, your channels, and what phase-1 looks like.