Is hotel AI GDPR compliant?
Hotel AI is GDPR compliant when the vendor meets four conditions: data hosted in the EU, a signed data processing agreement (DPA), guest data never used to train third-party foundation models, and audit logs of every AI action. D3x meets all four: EU-hosted and GDPR-aligned, with SOC 2 Type II certification in progress.
01
Why does GDPR compliance depend on the vendor, not the technology?Link to this section
GDPR doesn't prohibit AI processing guest data; it regulates how. Guest messages contain names, reservation details, and sometimes payment or health information, and under GDPR the hotel is the data controller while the AI vendor is a processor. That means the hotel carries the compliance risk of the vendor's architecture, which is why the checklist below belongs in every procurement.
02
What four things should you verify before signing?Link to this section
A compliant setup is checkable in one due-diligence pass. Require written answers on each point:
- EU data residency: guest data stored and processed in the EU, without silent transfers to US infrastructure outside recognised safeguards
- A DPA plus data minimisation: a signed data processing agreement, defined retention periods, and a guarantee that guest data is never used to train third-party foundation models
- Auditability and control: logs of every AI action with its rationale, human-in-the-loop escalation, and a clear process for data subject access and deletion requests
03
Where does D3x stand on GDPR and data residency?Link to this section
D3x is EU-hosted and GDPR-aligned: customer and guest data is never used to train third-party foundation models, every AI action is logged with its rationale, and hotel logic is enforced above the LLM through the Skills Engine. SOC 2 Type II certification is in progress, adding independently audited controls on top of the GDPR posture. That same governance is why the hotel AI implementation timeline stays short, days to weeks on standard integrations, without weakening the DPA. Hotels running regulated, multi-country portfolios, including groups like Staycity and Best Western properties, operate on this architecture today.
RELATED QUESTIONS
What else do operators ask?Link to this section
Generally no separate consent is required to respond to a guest's own inquiry, that processing rests on contract performance or legitimate interest. Consent becomes relevant for marketing messages, and hotels should disclose AI use transparently in their privacy notice.
SEE IT IN PRODUCTION
Ready to see hotel AI in production?Link to this section
D3x runs 250K+ hotel messages a month — agents that execute in your PMS, housekeeping, and CRM across messaging, email, and voice.
TALK TO US
Get the answer for your own properties.Link to this section
30 minutes with the founder, your stack, your channels, and what phase-1 looks like.
