Privacy

Privacy Policy

How Sarucci collects, uses, stores and protects your personal data.Version 1.0

📋 AT A GLANCE — What this Policy covers

This Privacy Policy explains how Sarucci Inc. collects, uses, stores, and protects your personal data when you and your team use the Sarucci Revenue Intelligence Platform. It applies to hotel owners, General Managers, Revenue Managers, Commercial Directors, and other personnel who access or manage the platform on behalf of their hotel.

This policy is written to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, and applicable international privacy law.

1.Who We Are (Data Controller)

Sarucci Inc. (“Sarucci”, “we”, “us”, “our”) is the controller of personal data collected when you visit our website or register for and use the Sarucci Platform.

CompanySarucci Inc.
Registered Address16192 Coastal Highway Lewes, Delaware 19958 Sussex County
Data Protection Contact[email protected]
Websitewww.sarucci.com/privacy

If you are accessing the Platform as a user on behalf of a hotel business (Client), the hotel business is also a Data Controller in respect of your personal data. Please also refer to your employer’s own privacy notices.

2.What Personal Data We Collect

We collect personal data in the following categories:

2.1 Account & Identity Data

  • Full name and job title (e.g., General Manager, Revenue Manager, Commercial Director)
  • Business email address and phone number
  • Hotel name, brand, and property details
  • Username and encrypted password

2.2 Platform Usage Data

  • Log data: IP addresses, browser type, device identifiers, pages visited, and feature usage
  • Actions performed in the platform (e.g., reports generated, rates set, forecasts reviewed)
  • Session timestamps and duration

2.3 Hotel Performance & Revenue Data

  • Hotel revenue figures, occupancy rates, ADR, and RevPAR data you upload or connect
  • Rate and pricing data (including competitor benchmarking results)
  • Demand forecasts and historical booking data

Note: This data primarily relates to your hotel property. Where individuals can be identified (e.g. through named accounts), it constitutes personal data and is handled accordingly.

2.4 Communication Data

  • Emails, chat messages, and support tickets you send to us
  • Responses to surveys, feedback forms, or product research requests
  • Voice recordings and the transcripts derived from them, where you interact with our real-time voice consultant

2.5 Data We Do Not Collect

✅ We do NOT collect the following:

Hotel guest personal data (unless you specifically upload it); payment card numbers (we use PCI-DSS compliant payment processors); special category data (health, biometric, etc.); children’s data.

If you inadvertently upload data outside these categories, please contact [email protected] immediately.

4.How Long We Keep Your Data

We retain personal data only for as long as necessary for the purposes described in this policy, or as required by law.

Data TypeRetention PeriodReason
Account & identity dataDuration of Agreement + 3 yearsFraud prevention, legal claims
Platform usage logs13 monthsSecurity, debugging, analytics
Revenue & hotel performance dataDuration of Agreement + 30 days post-termination export window, then deletedService provision; Client export right
Billing and invoice records7 yearsTax and accounting obligations
Support communications3 years from case closureService quality, legal disputes
Marketing consent recordsUntil consent is withdrawn + 1 yearCompliance with consent obligations

5.Who We Share Your Data With

We do not sell, rent, or trade your personal data to third parties. We share data only as described below:

5.1 Sub-processors

We use carefully vetted third-party sub-processors to help us deliver the Platform. All sub-processors are bound by data processing agreements meeting GDPR standards. Our current sub-processors are:

  • Google Cloud Platform and Firebase (Google Cloud EMEA Limited / Google LLC) — hosting, managed databases, object storage, authentication and delivery of the Platform, in the European Union and the United Kingdom
  • Amazon Web Services (Amazon Web Services EMEA SARL / Amazon Web Services, Inc.) — supplementary hosting, compute and storage
  • Zoho Corporation Private Limited — transactional and system email delivery and our support mailbox
  • Anthropic PBC, OpenAI Ireland Limited / OpenAI, L.L.C., and Google LLC (Gemini API) — large language model processing for our AI analyst, AI consultant and agentic advisor features
  • RunPod, Inc. — GPU compute for our real-time voice consultant (speech recognition, speech synthesis and avatar rendering) and for machine learning model training
  • Google Maps Platform (Google LLC) — map rendering and geocoding on our market and competitor intelligence screens
  • Analytics provider — anonymised and aggregated Platform usage analytics
  • Stripe (Stripe Payments Europe, Limited / Stripe, Inc.) — subscription billing, invoicing and payment processing (we do not store payment card data)

An up-to-date list of our sub-processors, including entity names and locations, is maintained at sarucci.com/sub-processors. Where a sub-processor is listed above by category rather than by name, we will name the engaged entity on that page before it begins processing personal data. We will notify you of any new sub-processor at least 30 days in advance and you may object in writing within that period.

5.2 Legal & Regulatory Disclosure

We may disclose personal data to law enforcement, regulatory bodies, or courts where required by applicable law, provided we give you prior written notice where legally permitted.

5.3 Business Transfers

If Sarucci is involved in a merger, acquisition, or sale of assets, personal data may be transferred to the successor entity, provided it agrees to process personal data under privacy terms no less protective than this policy. We will notify you in advance of any such transfer.

5.4 Aggregated & Anonymised Data

We may share aggregated, anonymised industry benchmarking and insights data with third parties (for example, in published hotel industry reports). This data cannot be used to identify you or your hotel.

6.International Data Transfers

Sarucci Inc. is incorporated in the United States. The Platform itself is hosted in the European Union (Belgium) and the United Kingdom (London). Some of our sub-processors — in particular our AI providers and certain compute providers — process personal data in the United States and other jurisdictions, which may not provide the same level of data protection as your home country. Annex C of our Data Processing Addendum sets out where each sub-processor processes data.

Where we transfer personal data outside the EEA or UK, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission (for EEA transfers)
  • The UK International Data Transfer Agreement (IDTA) (for UK transfers)
  • Adequacy decisions by the European Commission or UK Secretary of State, where applicable

You may request a copy of the relevant transfer safeguards by emailing [email protected].

7.Security

We take the security of your personal data seriously. Our technical and organisational security measures include:

  • SOC 2 Type II certification (annual audit)
  • TLS 1.2+ encryption for all data in transit
  • AES-256 encryption for data at rest
  • Role-based access controls (RBAC) and least-privilege principles
  • Multi-factor authentication (MFA) for platform access
  • Regular penetration testing by independent security firms
  • Formal incident response and breach notification procedures

In the event of a personal data breach that is likely to affect your rights and freedoms, we will notify you without undue delay and in any event within 72 hours of becoming aware of the breach.

8.Your Rights Under GDPR

If you are located in the EEA, UK, or another jurisdiction with similar data protection rights, you have the following rights in respect of your personal data:

RightWhat it meansGDPR Article
AccessRequest a copy of the personal data we hold about you.Art. 15
RectificationAsk us to correct inaccurate or incomplete data about you.Art. 16
ErasureAsk us to delete your personal data where there is no longer a legal basis to process it.Art. 17
RestrictionAsk us to pause processing your data in certain circumstances.Art. 18
PortabilityReceive a copy of your data in a structured, machine-readable format to transfer to another provider.Art. 20
ObjectionObject to processing based on legitimate interests, including direct marketing.Art. 21
Withdraw ConsentWhere processing is based on consent, withdraw it at any time without affecting prior processing.Art. 7(3)
Automated DecisionsRequest human review of any automated decisions that significantly affect you.Art. 22

📬 How to Exercise Your Rights

Email: [email protected] · Subject line: “GDPR Rights Request”

We will respond within 30 days. We may ask you to verify your identity before acting on a request. There is no charge for exercising your rights, unless a request is manifestly unfounded or excessive.

9.Cookies & Tracking Technologies

The Sarucci Platform uses cookies and similar tracking technologies. A full Cookie Policy is available at sarucci.com/cookies.

In summary:

  • Strictly necessary cookies: Required for the Platform to function. You cannot opt out of these.
  • Functional cookies: Remember your preferences (e.g. language, dashboard layout). You can disable these.
  • Analytics cookies: Help us understand how the Platform is used (anonymised). You can opt out via your platform settings.
  • Marketing cookies: Used only with your explicit consent. We do not use third-party advertising cookies on the Platform.

You can manage cookie preferences in your Platform account settings or via your browser settings at any time.

10.Children’s Data

The Sarucci Platform is designed for use by hospitality professionals and is not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected such data, please contact [email protected] immediately.

11.Automated Decision-Making

The Platform uses algorithms to generate revenue recommendations, demand forecasts, and rate optimisation suggestions. These are provided as decision-support tools only. All pricing and revenue decisions remain under the control of you and your team. No fully automated decisions with legal or similarly significant effects are made solely by the Platform without human review.

12.Complaints & Supervisory Authority

If you are not satisfied with how we handle your personal data or your rights request, you have the right to lodge a complaint with your local data protection supervisory authority:

  • European Union: Your national Data Protection Authority (full list at edpb.europa.eu)
  • United Kingdom: Information Commissioner’s Office (ICO) — ico.org.uk
  • United States: While there is no federal supervisory authority equivalent, state-level rights may apply (e.g., CCPA in California)

We would always appreciate the opportunity to address your concerns before you approach a supervisory authority. Please contact us first at [email protected].

13.Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes at least 30 days before they take effect by email and by prominent notice within the Platform. The “Last Updated” date at the top of this document indicates when it was most recently revised.

Your continued use of the Platform after the effective date of an updated policy constitutes acceptance of the changes. If you do not agree with material changes, you may terminate your subscription in accordance with the Service Agreement.

14.Contact Us

For any questions, requests, or concerns relating to this Privacy Policy or your personal data:

Data Protection Contact[email protected]
General Enquiries[email protected]
Privacy Portalsarucci.com/privacy
Questions about this document? Contact us at [email protected]