SECURITY & COMPLIANCE

Guest data is hotel trust. We treat it that way.

Altek is built privacy-first, with human-in-the-loop approvals as a governance control. Nothing executes in your systems without the permissions you set.

Least-privilegeaccess
Audit trailevery action
ISO 27001in progress

How we protect guest data

Server stack icon.

Regional data residency

Processing and storage run in dedicated cloud regions, with the region for your properties named in your DPA.

Shield with checkmark icon.

Privacy by design

DPA available; documented data flows; retention policies you control. Built to GDPR standards.

Closed padlock icon.

Certifications in progress

ISO 27001 and SOC 2 certification processes are underway. We'll say certified when we are, never before.

User with lock icon.

Controlled execution

Permissions are defined by property and action. Sensitive actions can require approval, and every execution is recorded in the audit trail.

Closed padlock icon.

Least-privilege access

Altek requests only the scopes needed for the operations you enable, per system: Mews, Opera Cloud, Visbook/BookVisit, Outlook.

Shield with checkmark icon.

Hospitality-only

One industry. Your guest data never trains another sector's product.

For procurement teams

Our security documentation pack is available on request: the DPA, data-flow diagrams, the subprocessor list, and current certification status. Everything your review needs in one place.

Request the security pack

Security & compliance FAQ

What hotel IT and procurement teams ask us most.

Where is guest data hosted?
In dedicated cloud regions, with the region that applies to your properties named in your DPA. Today that is the EU. If your group needs a specific residency for another market, raise it early and we'll confirm what we can support.
Is Altek GDPR compliant?
Altek is built to GDPR standards: a Data Processing Agreement is available, data flows are documented, and retention policies are under your control. The full documentation is included in the security pack. Request it via our contact page.
Is Altek ISO 27001 or SOC 2 certified?
Both certification processes are underway: in progress, not yet completed. We won't claim certified until the audits say so. Current status and supporting documentation are available on request in the security pack.
Can we control what the AI is allowed to do?
Yes, and we treat that as a security control, not a preference. Approval requirements are set per action type and per property: you decide which operations run with a 30-second human approval and which require more. Nothing executes in your PMS outside the permissions you set.

Bring your security review to the call.

Thirty minutes with the people who built it. Walk through the permission model, the audit trail and the approval controls against your own requirements.

  • Security pack sent in advance
  • Walk through data flows and permissions
  • Bring your IT, legal or security questions