GDPR Policy
AccuBook Limited
Data Protection Policy
01/01/2026
For any enquiries email us at info@guestdiary.com
AccuBook Limited Privacy Notice Last updated: January 2026
For any enquiries email us at info@guestdiary.com
1. Introduction
This is the Privacy Notice of AccuBook Limited trading as GuestDiary.com with a registered address at Drumcroagh, Donegal Town, Co. Donegal, Ireland (hereinafter AccuBook, we, us or our in this Policy). In this privacy notice we will describe how we collect, use, share and otherwise process personal data.
This privacy policy applies to all users in the EU/EEA and adheres to the General Data Protection Regulation (GDPR). Please read the following carefully to understand our practices regarding your personal data and how we will treat it.
We are committed not only to the letter of the law, but also to the spirit of the law and place high importance on the correct, lawful, and fair handling of all personal data, respecting the legal rights, privacy, and trust of all individuals with whom we deal.
2. Who We Are
We are AccuBook Limited, trading as GuestDiary.com, a company registered in Republic of Ireland under number 334922 and our important information is set out below. We provide an all-in-one cloud-based software solution on a subscription basis (our “Service”) for hospitality businesses, for the purpose of this notice referred to as the “Hospitality Provider”.
Name or title of Data Protection Officer: Gerry Haughey • Email address: info@guestdiary.com • Postal address: Lurganboy, Donegal Town, Co. Donegal, Ireland • [Telephone number: +353 (0)74 970 6666•
Under the GDPR, AccuBook acts as both a data processor and a data controller depending on whose personal data is being processed and for what purpose. We act as a data processor on behalf of our hospitality clients in relation to guest reservation details and as a data controller in relation to personal data we process for our own business purposes. This notice explains both roles clearly in separate sections below.
3. HOTEL GUESTS
Information for Hotel Guests If you are a guest who has made a reservation with one of our hospitality or accommodation customers that uses our software the Hospitality Provider is the data controller.
AccuBook processes personal data of hotel guests only on the instruction of the Hospitality Provider. The Hospitality Provider determines what data is collected, why it is used and how long it is retained. Data processed by AccuBook includes guest names, contact details, reservation details, but we do not use this data for our own purposes. Guest personal data is processed exclusively for the purpose of enabling reservation management, guest communications, check-in/check-out processes, and related hospitality operations.
AccuBook supports Hospitality Providers in fulfilling GDPR requests in accordance with Article 28 GDPR, and assists the controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 GDPR.
If you are a hotel guest and wish to exercise your GDPR rights (access, rectification, erasure, etc.) in relation to your reservation data, please contact the Hospitality Provider directly.
4. OUR CUSTOMERS/HOSPITALITY PROVIDERS
4.1. Information for Our Customers/Hospitality Providers
If you are a customer of AccuBook and therefore a Hospitality Provider, we collect, use, share and otherwise process personal data for administrative, contractual and support purposes, including account management, billing and technical support. In this context, AccuBook is the data controller.
4.2. Personal Data We Collect
When using our services we will collect, use, store, and transfer personal data including
[Identity Data: first name, last name, title of you and your employees] •
[Contact Data: first name, last name, contact address, email address and telephone • numbers, your communication preferences]
[Profile Data: your email address, username, and password.] •
[Transaction Data: billing and delivery addresses, VAT details, payment card details, • history of your payments, purchases, refunds and the applicable terms and conditions of your purchases.]
[Usage Data: logs and detail of your use of our Services, being the dates and times • on which you access our Services, any error or debugging information, and the resources that you access]
[Technical Data: IP Address, operating system, server logs] •
[Communication Data: emails, service tickets, call records and copies of the • communications between you and us.]
[Cookies Data: ……] •
We do not intentionally collect any special categories of personal data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data
4.3. How We Collect Personal Data
Collection Source
Category of Personal Data Collected
Purpose/Why We Collect this Data
Directly from You
Identity Data, Contact Data and Profile Data
Deliver customer support, and to enable account creation and management
From your use of our Services we will automatically collect personal data.
Technical Data, Usage Data, Profile Data and Communication Data (if required).
Operate and monitor our Services, as well as for troubleshooting and security purposes.
From Third Parties - We may receive data about you from third parties such as payment processors for billing purposes
Identity Data, Contact Data, Transaction Data
To provide Services, process payments, deliver marketing communications (where consented), and support our customers
From Publicly Available Sources such as company websites, directories or social media profiles you make publicly accessible.
Identity Data, Contact Data To verify information, maintain business contact, and support optional marketing activities
From your Devices or Systems
Technical Data and Usage Data
To secure our Services and improve functionality
4.4. Legal Basis for Using Your Data
We will use your data for the purposes of providing you with our Service and service improvements. We will only use your personal data when we have a lawful basis to do so and in compliance with GDPR. Our lawful basis for each purpose for which we use your personal data is specified below.
Performance of a contract • Our Service is operated on a subscription basis where we will have a contract with you.We process your personal data to perform this contract with you or where you ask us to take steps before we enter into this contract with you, including account access and management, access to our platform, user authentication, and security. Where we rely on performance of a contract and you do not provide the necessary information, we will be unable to perform your contract.
Legitimate interests • It may be necessary to use your data for our legitimate business interests and your interests in order to provide our Services to you. Our legitimate interests include operating, maintaining, and improving our Services; ensuring platform security, stability, and availability; preventing fraud, and providing customer support and resolving issues. We make sure we consider and balance any potential impact on you (both positive and negative) and your fundamental rights before we process your personal data for our legitimate interests
Consent • We will process personal data where you have freely consented before the processing. This may include marketing communications or other optional features or services we offer. You can withdraw your consent at any time, as set out in further detail below.
Legal obligation • Where we need to use your personal data to comply with a legal or regulatory obligations, such as accounting and financial record-keeping and tax compliance. Where we rely on legal obligation and you do not provide the necessary information, we may be unable to fulfil a right you have or comply with our obligations to you, or we may need to take additional steps, such as informing law enforcement or a public authority or applying for a court order.
4.5. How We Use Your Personal Data
AccuBook uses certain categories of your personal data for the purposes on the bases set out below:-
Purpose/Activity
Categories of Personal Data Used
Lawful Basis
Account access and management
Identity Data
Contact Data
Profile Data
Transaction Data
Performance of a contract
Operating, maintaining, and improving our Services, analytics, customer support and communications, security
Identity Data
Contact Data
Usage Data
Technical Data
Communication Data
Legitimate interests
Billing, Payment and Administration
Identity Data
Contact Data
Profile Data
Transaction Data
Legal obligation
Marketing where a data subject has opted in, and Business Development
Communication Data
Identity Data
Contact Data
Profile Data
Consent 4.6.
Disclosures of Your Personal Data
We may share your personal data with the following third parties:
1. Service providers, acting as processors
2. Our professional advisors based in Ireland including lawyers, auditors, insurers, consultants and other advisors who provide legal, accounting, insurance and [OTHER] services.
3. Your service providers that you have appointed and we need to contact to fulfil your requests, such as your banking or payment card provider to process your transactions.
4. Third party partners where you have consented to receive marketing from or with them.
5. Third parties to whom we may choose to sell, transfer or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this privacy notice.
4.7. How We Securely Store your Personal Data
We securely store and process personal data using Microsoft Azure data centres located within the European Union.
4.8. International Transfer
We may from time-to-time transfer, store or process (‘transfer’ includes making available remotely) personal data to countries outside of the EEA. This such transfer of personal data to a country outside of the EEA shall take place only if one or more of the following applies:
1. The transfer is to a destination that the European Commission has determined ensures an adequate level of protection for personal data;
2. Where no adequacy decision exists, transfers are only made if we implement appropriate safeguards, such as: Standard Contractual Clauses approved by the European Commission, Binding Corporate Rules (BCRs), approved codes of conduct or certification mechanisms, or contractual clauses authorised by the relevant data protection authority;
3. The transfer is necessary to perform a contract between you and AccuBook. For example, hosting or processing your data outside the EEA to provide our Services;
4. The transfer is made with the informed consent of the relevant data subject. You can withdraw consent at any time;
5. The transfer is necessary for the conduct or defence of legal claims;
6. Transfers may be necessary to protect your vital interests, or those of another person, where you are unable to provide consent.
We take all reasonable steps to ensure that your personal data remains protected during any transfer outside the EEA and that your rights under the GDPR are safeguarded.
4.9. Data Security
We ensure that all personal data collected, held, and processed is kept secure and protected against unauthorised or unlawful processing and against accidental loss, destruction, or damage.
Our security measures include, but are not limited to:-
Technical Measures - electronic copies of personal data stored securely using passwords and data encryption, encryption at rest and in transit, software (including, but not limited to, applications and operating systems) kept up-to-date, requirements for strong passwords and regular password changes
Organisational Measures – GDPR training for staff, access to personal data limited to staff who require access (least privilege), periodic review of internal policies and procedures, contractual obligations for third parties binding them and their employees to GDPR-compliant handling.
Use and Access – limitation on transferring personal data with approval only, restriction on sharing personal data informally, personal data handled with care at all times and not left unattended
Disposal/Retention – secure deletion when personal data no longer required, retention only for appropriate periods
4.10. Data Retention
We will not keep personal data for any longer than is necessary in light of the purpose or purposes for which that personal data was originally collected, held, and processed. When personal data is no longer required, all reasonable steps will be taken to erase or otherwise dispose of it without delay.
4.11. Your Legal Rights under GDPR
You have the following rights under data protection laws in relation to your personal data.
Access
Request access to and/or a copy of the personal data we process about you (commonly known as a data subject access request). This enables you to check that we are lawfully processing it.
Correction
Request correction of any incomplete or inaccurate data we hold about you. (We may need to verify the accuracy of the new data you provide to us.)
Deletion
Request us to delete or remove personal data where there is no good reason for us continuing to process it. You also can ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we have processed your information unlawfully or where we need to erase your personal data to comply with law. (In some cases, we may need to continue to retain some of your personal data where required by law. If these apply, we will notify you at the time of our response.)
Objection
Object to us processing your personal data where (a) we are relying on legitimate interests as the lawful basis and you feel the processing impacts on your fundamental rights and freedoms, or (b) the processing is for direct marketing purposes. In some cases, we may refuse your objection if we can demonstrate that we have compelling legitimate grounds to continue processing your information which override your rights and freedoms.
Restriction
Restriction. Request that we restrict or suspend our processing of your personal data:
• if you want us to establish the data's accuracy;
• where our use of the data is unlawful, but you do not want us to erase it
• where we no longer require it, but you need us to hold onto it to establish, exercise or defend legal claims; or
• you have objected to our use of your data, but we need to verify whether we have overriding legitimate grounds to use it.
Data portability
Request we transfer certain of your personal data to you or your chosen third party in a structured, commonly used, machine-readable format. This right only applies to information processed by automated means that we process on the lawful bases of consent or performance of a contract.
Withdraw consent.
Withdraw your consent at any time where we are relying on consent to process your personal data. Please know that this does not affect the lawfulness of any processing carried out before you withdraw your consent, and after withdrawal, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
Complain to the data protection regulator.
If you are unhappy with how we process your personal data, we ask that you contact us first using the details below so that we have the chance to put it right. However, you also have the right to make a complaint to the Data Protection Commission (DPC).
You can exercise any of these rights at any time by contacting us at info@guestdiary.com.
4.12. Personal Data Breach Notification
We have put in place procedures to detect and respond to personal data breaches and notify you and any applicable regulator. In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the Data Protection Commission without undue delay, and where required, no later than 72 hours after becoming aware of the breach, as required under the GDPR.
Where a personal data breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay and provide information about the nature of the breach, the likely consequences, and the measures taken or proposed to address it.
We maintain internal records of all personal data breaches, including the facts relating to the breach, its effects, and the remedial action taken.
5. Our Complaints Process
If you are unhappy with how we process your personal data, we ask that you contact us first using the details below so that we have the chance to put it right. In order to raise a compliant, please contact us at [email address].
You also have a right to make a complaint in respect of the handling or processing of your personal data by AccuBook at any time with:
our lead supervisory authority in the EEA, which is the Data Protection Commission • (DPC). The DPC can be contacted via their website, which has an online complaints portal https://www.dataprotection.ie/en/individuals/exercising-your-rights/raising-concern-commission , by telephone on 01 7650100 or 1800 437 737 or by post at Data Protection Commission, 6 Pembroke Row, Dublin 2, D02 X963, Ireland A relevant data protection supervisory authority in the EEA state where you live, • where you work, or where the issues with our use of your personal data arose. For a list of EEA data protection supervisory authorities and their contact details see here
6. Other
AccuBook does not use personal data in automated decision-making processes. Please note that our Services are not intended for children OR those under 16 and we do not knowingly collect data relating to children.
7. Changes to the privacy notice and your duty to inform us of changes
We keep our privacy notice under regular review.
This version was last updated on 01/01/2026. It may change and, if it does, those changes will be posted on this page and notified to you [by push notification OR by email OR when you next start the App or log onto your account]. [The new notice may be displayed on-screen and you OR You] may be required to read and acknowledge the changes to continue your use of the App or the Services.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during our relationship with you.
Implementation of Policy
This Policy shall be deemed effective as of 01/01/2026. No part of this Policy shall have retroactive effect and shall thus apply only to matters occurring on or after this date.
This Policy has been approved and authorised by:
Name: Andy Bassett
Position: Director
Date: 01/01/2026
Due for Review by: 01/01/2027
Signature: