KleidiFlowHospitality operations

Privacy at KleidiFlow

Clear purpose. Limited data. Accountable handling.

This policy explains how the independently operated KleidiFlow software project, based in Greece, handles personal data on this website and in its property-management service.

Effective 17 August 2026
Plain-language summary

We do not sell personal data, buy recipient lists or use guest records for advertising. Accommodation businesses control their guest data. KleidiFlow processes that data only to provide and secure the service.

1. Scope

This policy covers visitors to kleidiflow.com, people who contact us, authorised KleidiFlow staff users, and guests whose accommodation provider uses KleidiFlow. It does not replace the privacy notice of the accommodation business responsible for a guest reservation.

2. Our role

Website and account administration

KleidiFlow is the controller for information submitted directly to us for product enquiries, support, account administration, security and legal compliance.

Accommodation guest data

The accommodation business is normally the data controller for reservation and guest data. KleidiFlow acts as its processor, following documented instructions and the applicable service agreement. Questions about a stay should usually be addressed first to the accommodation business.

3. Data we process

  • Website and enquiry data: email address, name, organisation and the content of a message you send us.
  • Staff account data: identity-provider subject, business email, display name, property membership, role, MFA assurance and security events.
  • Property operations data: rooms, reservations, dates, prices, payments, operational notes and audit history.
  • Guest data entered by a property: name, contact details, stay information and, only when required for the accommodation workflow, identity or self check-in details.
  • Technical data: IP-derived security information, request timestamps, device/browser information, delivery state and restricted diagnostics.

We ask customers not to place unnecessary sensitive information in free-text notes.

4. Purposes and legal bases

  • Provide requested information and operate the service—steps before a contract and performance of a contract.
  • Authenticate users, protect tenants, prevent abuse and investigate failures—our and our customers' legitimate interests in a secure, reliable service.
  • Meet accounting, security and legal obligations—compliance with applicable law.
  • Send optional marketing in the future—only on a separate, freely given and withdrawable consent. We do not currently use guest records for marketing.

Accommodation businesses determine their own lawful basis for guest and reservation processing and must provide their own guest-facing notice.

5. Service providers and transfers

We use carefully selected infrastructure, identity, database, email-delivery, monitoring and backup providers only as needed to operate KleidiFlow. Access is limited by purpose and contract. We do not sell personal data.

We prefer European hosting and processing locations. If a provider processes data outside the European Economic Area, we require an applicable lawful transfer mechanism and appropriate safeguards.

6. Retention

Website enquiries and support correspondence are retained only while needed to answer the request, maintain necessary business records and handle disputes. Security logs and diagnostics have bounded operational retention.

Property and guest records follow the customer's documented instructions, configured retention controls and applicable hospitality, accounting and tax obligations. Data is deleted or anonymised when no longer required, subject to legal holds and mandatory retention.

7. Your rights

Depending on the circumstances, you may request access, correction, erasure, restriction, portability, or object to processing. Where processing relies on consent, you may withdraw it at any time without affecting earlier lawful processing.

To protect other people, we may need to verify your identity. For guest records, we may refer the request to the relevant accommodation controller. You may also complain to the Hellenic Data Protection Authority or your local supervisory authority.

8. Security

Our controls include verified identity, MFA, tenant-scoped roles, database row-level security, application-level protection for sensitive guest fields, audit records, restricted diagnostics and encrypted backups. No internet service is risk-free; we maintain processes to investigate and respond to suspected incidents.

9. Contact and policy changes

Privacy enquiries and rights requests: privacy@kleidiflow.com. General enquiries: hello@kleidiflow.com.

KleidiFlow is an independently operated software project based in Greece. The contracting operator's full legal and registration details are supplied in customer agreements and to service providers during verification. We will update this public notice when the operating entity or processing materially changes.