New episode: The Return of the Great Hotelier — with L+R HotelsLive across 60+ European hotel groupsNew deployments live in 3 weeksVoice agents at chain scaleAI Lobby Talk — CIO interviews on YouTubePlatform docs & changelogNew episode: The Return of the Great Hotelier — with L+R HotelsLive across 60+ European hotel groupsNew deployments live in 3 weeksVoice agents at chain scaleAI Lobby Talk — CIO interviews on YouTubePlatform docs & changelog
D3x

ANSWERS

Is hotel AI GDPR compliant?

The short answer

Hotel AI is GDPR compliant when the vendor meets four conditions: data hosted in the EU, a signed data processing agreement (DPA), guest data never used to train third-party foundation models, and audit logs of every AI action. D3x meets all four — EU-hosted and GDPR-aligned, with SOC 2 Type II certification in progress.

01

Why compliance depends on the vendor, not the technology

GDPR doesn't prohibit AI processing guest data; it regulates how. Guest messages contain names, reservation details, and sometimes payment or health information, and under GDPR the hotel is the data controller while the AI vendor is a processor. That means the hotel carries the compliance risk of the vendor's architecture — which is why the checklist below belongs in every procurement.

02

The four things to verify before signing

A compliant setup is checkable in one due-diligence pass. Require written answers on each point:

  • EU data residency: guest data stored and processed in the EU, without silent transfers to US infrastructure outside recognised safeguards
  • A DPA plus data minimisation: a signed data processing agreement, defined retention periods, and a guarantee that guest data is never used to train third-party foundation models
  • Auditability and control: logs of every AI action with its rationale, human-in-the-loop escalation, and a clear process for data subject access and deletion requests

03

Where D3x stands

D3x is EU-hosted and GDPR-aligned: customer and guest data is never used to train third-party foundation models, every AI action is logged with its rationale, and hotel logic is enforced above the LLM through the Skills Engine. SOC 2 Type II certification is in progress, adding independently audited controls on top of the GDPR posture. Hotels running regulated, multi-country portfolios — including groups like Staycity and Best Western properties — operate on this architecture today.

RELATED QUESTIONS

People also ask.

Generally no separate consent is required to respond to a guest's own inquiry — that processing rests on contract performance or legitimate interest. Consent becomes relevant for marketing messages, and hotels should disclose AI use transparently in their privacy notice.

SEE IT IN PRODUCTION

D3x runs 250K+ hotel messages a month.

The AI orchestration layer for hospitality — agents that execute in your PMS, housekeeping, and CRM across messaging, email, and voice.

TALK TO US

Get the answer for your own properties.

30 minutes with the founder — your stack, your channels, and what phase-1 looks like.