ANSWERS
Is hotel AI GDPR compliant?
The short answer
Hotel AI is GDPR compliant when the vendor meets four conditions: data hosted in the EU, a signed data processing agreement (DPA), guest data never used to train third-party foundation models, and audit logs of every AI action. D3x meets all four — EU-hosted and GDPR-aligned, with SOC 2 Type II certification in progress.
01
Why compliance depends on the vendor, not the technology
GDPR doesn't prohibit AI processing guest data; it regulates how. Guest messages contain names, reservation details, and sometimes payment or health information, and under GDPR the hotel is the data controller while the AI vendor is a processor. That means the hotel carries the compliance risk of the vendor's architecture — which is why the checklist below belongs in every procurement.
02
The four things to verify before signing
A compliant setup is checkable in one due-diligence pass. Require written answers on each point:
- EU data residency: guest data stored and processed in the EU, without silent transfers to US infrastructure outside recognised safeguards
- A DPA plus data minimisation: a signed data processing agreement, defined retention periods, and a guarantee that guest data is never used to train third-party foundation models
- Auditability and control: logs of every AI action with its rationale, human-in-the-loop escalation, and a clear process for data subject access and deletion requests
03
Where D3x stands
D3x is EU-hosted and GDPR-aligned: customer and guest data is never used to train third-party foundation models, every AI action is logged with its rationale, and hotel logic is enforced above the LLM through the Skills Engine. SOC 2 Type II certification is in progress, adding independently audited controls on top of the GDPR posture. Hotels running regulated, multi-country portfolios — including groups like Staycity and Best Western properties — operate on this architecture today.
RELATED QUESTIONS
People also ask.
Generally no separate consent is required to respond to a guest's own inquiry — that processing rests on contract performance or legitimate interest. Consent becomes relevant for marketing messages, and hotels should disclose AI use transparently in their privacy notice.
SEE IT IN PRODUCTION
D3x runs 250K+ hotel messages a month.
The AI orchestration layer for hospitality — agents that execute in your PMS, housekeeping, and CRM across messaging, email, and voice.
TALK TO US
Get the answer for your own properties.
30 minutes with the founder — your stack, your channels, and what phase-1 looks like.
