H Hotel Waitlist
  • Benefits
  • How It Works
  • Pricing
  • About
Get Started

UK Data Protection & Security Overview

Last updated: 21 July 2026

Waitlist Ltd trading as Hotel Waitlist provides technology to Hotels that captures expressed booking interest, sends Hotel-approved follow-up and attributes direct bookings. Our privacy programme is designed around the UK GDPR, Data Protection Act 2018 and PECR. EU GDPR applies where the relevant processing falls within its territorial scope.

This page is an operational overview. The Privacy Notice explains use of information, and the binding Data Processing Addendum governs Guest information processed for Hotel clients.

Our roles

ContextWaitlist Ltd's usual role
Hotel account, billing and contract contactsController
Visitors to hotelwaitlist.io and demonstration enquiriesController
Security and legal-compliance recordsController
Guest waitlist and communication data used for a HotelProcessor; Hotel is Controller
Hotel-specific attribution analyticsProcessor, except limited invoice/legal records
Effectively anonymised service statisticsOutside data-protection law once individuals cannot be identified

The exact role depends on the facts. It is documented during Hotel onboarding.

Guest-data lifecycle

  1. A Hotel deploys the Hotel Waitlist tag/form and provides layered privacy information.
  2. An interested Guest submits contact details, requested dates and preferences.
  3. We store and use that information on the Hotel's documented instructions.
  4. We send Hotel-approved availability or booking communications through authorised providers.
  5. Session interactions, coupon-code redemptions and booking events are used to report attribution and Commission without counting a booking twice.
  6. Opt-outs are applied to suppression records.
  7. Guest information is deleted or returned according to the Hotel's instructions and the DPA.

Communications and PECR

We distinguish a message expressly requested by a Guest from direct marketing. Marketing email, SMS or similar communication is sent only where the responsible Hotel has identified and documented a valid PECR route, such as valid consent or every condition of an applicable soft opt-in. Messages identify the sender and provide an opt-out where required.

AI optimisation

The Service can analyse booking preferences, communication engagement and outcomes to recommend or select timing, subject lines and Hotel-approved offers. This is intended to improve relevance and booking conversion and is not intended to make a decision with legal or similarly significant effects on a Guest.

Property-specific learning is performed for the relevant Hotel. Identifiable Guest information is not used for cross-property learning unless expressly configured and supported by a documented lawful, transparent basis. Effectively anonymised and aggregated performance statistics may be used to improve the Service.

We assess new high-risk AI or profiling uses before deployment and support objections to direct-marketing profiling.

Data Processing Addendum

Each Hotel agreement includes Article 28 terms covering:

  • Processing details and documented instructions;
  • confidentiality and security;
  • Subprocessors;
  • Data Subject rights assistance;
  • Personal Data Breach assistance;
  • international transfers;
  • audits and compliance information; and
  • return and deletion after termination.

The applicable DPA version must be presented and recorded when a Hotel accepts the Service.

Subprocessors

We use contracted providers only where needed to supply functions such as infrastructure hosting, message delivery, support, security and billing. Each provider that Processes Guest information is bound by data-protection obligations appropriate to its role, and we remain responsible as required by the DPA.

Hotel clients receive a current, versioned Subprocessor list and notice of relevant changes. The public list shows each verified legal entity, purpose, processing location and transfer mechanism.

International transfers

We identify restricted transfers and use a mechanism permitted under UK GDPR, such as UK adequacy regulations, the UK IDTA, or EU SCCs combined with the UK Addendum. We complete the applicable transfer risk/data protection assessment and apply supplementary measures where required. EU transfer requirements are addressed separately where EU GDPR applies.

Security

Our security programme addresses:

  • access control and authentication;
  • protection of information in transit and storage;
  • logging, monitoring and incident response;
  • vulnerability, patch and change management;
  • secure development;
  • backup, continuity and recovery;
  • supplier review; and
  • staff confidentiality and training.

Detailed controls are available to Hotel clients through appropriate due diligence. Public claims about protocol versions, encryption algorithms, penetration testing, MFA, certifications and hosting regions are made only when supported by current evidence.

Personal Data Breaches

We maintain an incident-response process. Where we act as Processor, we notify the affected Hotel without undue delay after becoming aware of a Guest Personal Data Breach and provide available information and reasonable assistance. The Hotel is responsible for Controller notifications, with our support.

Rights and requests

Guests should normally contact the Hotel identified on their form or message because it is the Controller. Requests sent to privacy@hotelwaitlist.io are routed or supported appropriately. We assist Hotels with access, correction, deletion, restriction, portability, objection and consent-withdrawal requests as required by the DPA.

Retention and deletion

Guest information follows the Hotel's documented retention configuration or instructions. We delete or return it when the Service ends, subject to limited legal, security, backup and suppression requirements. Controller records such as contracts and invoices follow applicable legal and claims periods.

Contact and complaints

Privacy contact: privacy@hotelwaitlist.io

Waitlist Ltd, company number 17010598

23 Cranley Gardens, London, England, N10 3AA

The UK supervisory authority is the Information Commissioner's Office:

  • https://ico.org.uk/
  • 0303 123 1113

We use the title Privacy Contact for privacy@hotelwaitlist.io. We will identify a Data Protection Officer only if Waitlist Ltd formally appoints one under UK GDPR.

Privacy Notice · Terms of Service · UK Data Protection & Security · Cookie Settings

© 2026 Waitlist Ltd trading as Hotel Waitlist. All rights reserved. Company No. 17010598.