GDPR Policy

AccuBook Limited
Data Protection Policy
01/01/2026
For any enquiries email us at info@guestdiary.com

AccuBook Limited Privacy Notice Last updated: January 2026

For any enquiries email us at info@guestdiary.com

1. Introduction

This is the Privacy Notice of AccuBook Limited trading as GuestDiary.com with a registered  address at Drumcroagh, Donegal Town, Co. Donegal, Ireland (hereinafter AccuBook, we, us  or our in this Policy). In this privacy notice we will describe how we collect, use, share and  otherwise process personal data.

This privacy policy applies to all users in the EU/EEA and adheres to the General Data  Protection Regulation (GDPR). Please read the following carefully to understand our  practices regarding your personal data and how we will treat it.

We are committed not only to the letter of the law, but also to the spirit of the law and place  high importance on the correct, lawful, and fair handling of all personal data, respecting the  legal rights, privacy, and trust of all individuals with whom we deal.

2. Who We Are

We are AccuBook Limited, trading as GuestDiary.com, a company registered in Republic of  Ireland under number 334922 and our important information is set out below. We provide an  all-in-one cloud-based software solution on a subscription basis (our “Service”) for hospitality  businesses, for the purpose of this notice referred to as the “Hospitality Provider”. 

Name or title of Data Protection Officer: Gerry Haughey • Email address: info@guestdiary.com • Postal address: Lurganboy, Donegal Town, Co. Donegal, Ireland • [Telephone number: +353 (0)74 970 6666•

Under the GDPR, AccuBook acts as both a data processor and a data controller depending  on whose personal data is being processed and for what purpose. We act as a data  processor on behalf of our hospitality clients in relation to guest reservation details and as a data controller in relation to personal data we process for our own business purposes. This  notice explains both roles clearly in separate sections below.

3. HOTEL GUESTS

Information for Hotel Guests If you are a guest who has made a reservation with one of our hospitality or accommodation  customers that uses our software the Hospitality Provider is the data controller.

AccuBook processes personal data of hotel guests only on the instruction of the Hospitality  Provider. The Hospitality Provider determines what data is collected, why it is used and how  long it is retained. Data processed by AccuBook includes guest names, contact details,  reservation details, but we do not use this data for our own purposes. Guest personal data is  processed exclusively for the purpose of enabling reservation management, guest  communications, check-in/check-out processes, and related hospitality operations.

AccuBook supports Hospitality Providers in fulfilling GDPR requests in accordance with  Article 28 GDPR, and assists the controller in ensuring compliance with the obligations  pursuant to Articles 32 to 36 GDPR.

If you are a hotel guest and wish to exercise your GDPR rights (access, rectification,  erasure, etc.) in relation to your reservation data, please contact the Hospitality Provider  directly.

4. OUR CUSTOMERS/HOSPITALITY PROVIDERS

4.1. Information for Our Customers/Hospitality Providers

If you are a customer of AccuBook and therefore a Hospitality Provider, we collect, use,  share and otherwise process personal data for administrative, contractual and support  purposes, including account management, billing and technical support. In this context,  AccuBook is the data controller.

4.2. Personal Data We Collect

When using our services we will collect, use, store, and transfer personal data including

[Identity Data: first name, last name, title of you and your employees] •

[Contact Data: first name, last name, contact address, email address and telephone • numbers, your communication preferences]

[Profile Data: your email address, username, and password.] •

[Transaction Data: billing and delivery addresses, VAT details, payment card details, • history of your payments, purchases, refunds and the applicable terms and  conditions of your purchases.]

[Usage Data: logs and detail of your use of our Services, being the dates and times • on which you access our Services, any error or debugging information, and the  resources that you access]

[Technical Data: IP Address, operating system, server logs] •

[Communication Data: emails, service tickets, call records and copies of the • communications between you and us.]

[Cookies Data: ……] •

We do not intentionally collect any special categories of personal data about you  (this includes  details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual  orientation, political opinions, trade union membership, information about your health, and  genetic and biometric data

4.3. How We Collect Personal Data

Collection Source

Category of Personal Data Collected

Purpose/Why We Collect this Data

Directly from You

Identity Data, Contact Data and Profile Data

Deliver customer support, and to enable account creation and management

From your use of our Services we will automatically collect personal data.

Technical Data, Usage Data, Profile Data and Communication Data (if required).

Operate and monitor our Services, as well as for troubleshooting and security purposes.

From Third Parties - We may receive data about you from third parties such as payment processors for billing purposes

Identity Data, Contact Data, Transaction Data

To provide Services, process payments, deliver marketing communications (where consented), and support our customers

From Publicly Available Sources such as company websites, directories or social media profiles you make publicly accessible.

Identity Data, Contact Data To verify information, maintain business contact, and support optional marketing activities

From your Devices or Systems

Technical Data and Usage Data

To secure our Services and improve functionality

4.4. Legal Basis for Using Your Data

We will use your data for the purposes of providing you with our Service and service  improvements. We will only use your personal data when we have a lawful basis to do so  and in compliance with GDPR. Our lawful basis for each purpose for which we use your  personal data is specified below.

Performance of a contract • Our Service is operated on a subscription basis where we will have a contract with  you.We process your personal data to perform this contract with you or where you  ask us to take steps before we enter into this contract with you, including account  access and management, access to our platform, user authentication, and security.   Where we rely on performance of a contract and you do not provide the necessary  information, we will be unable to perform your contract.

Legitimate interests • It may be necessary to use your data for our legitimate business interests and your  interests in order to provide our Services to you. Our legitimate interests include  operating, maintaining, and improving our Services; ensuring platform security,  stability, and availability; preventing fraud, and providing customer support and  resolving issues. We make sure we consider and balance any potential impact on  you (both positive and negative) and your fundamental rights before we process your  personal data for our legitimate interests

Consent • We will process personal data where you have freely consented before the  processing. This may include marketing communications or other optional features or  services we offer. You can withdraw your consent at any time, as set out in further  detail below.

Legal obligation • Where we need to use your personal data to comply with a legal or regulatory  obligations, such as accounting and financial record-keeping and tax compliance.  Where we rely on legal obligation and you do not provide the necessary information,  we may be unable to fulfil a right you have or comply with our obligations to you, or  we may need to take additional steps, such as informing law enforcement or a public  authority or applying for a court order.

4.5. How We Use Your Personal Data

AccuBook uses certain categories of your personal data for the purposes on the bases set out  below:-

Purpose/Activity

Categories of Personal Data Used

Lawful Basis

Account access and management

Identity Data
Contact Data
Profile Data
Transaction Data

Performance of a contract

Operating, maintaining, and improving our Services, analytics, customer support and communications, security

Identity Data
Contact Data
Usage Data
Technical Data
Communication Data

Legitimate interests

Billing, Payment and Administration

Identity Data
Contact Data
Profile Data
Transaction Data

Legal obligation

Marketing where a data subject has opted in, and Business Development

Communication Data
Identity Data
Contact Data
Profile Data

Consent 4.6.

Disclosures of Your Personal Data

We may share your personal data with the following third parties:

1. Service providers, acting as processors

2. Our professional advisors based in Ireland including lawyers,  auditors, insurers, consultants and other advisors who provide legal,  accounting, insurance and [OTHER] services.

3. Your service providers that you have appointed and we need to contact to fulfil your  requests, such as your banking or payment card provider to process your  transactions.

4. Third party partners where you have consented to receive marketing from or with  them.

5. Third parties to whom we may choose to sell, transfer or merge parts of our business  or our assets. Alternatively, we may seek to acquire other businesses or merge with  them. If a change happens to our business, then the new owners may use your  personal data in the same way as set out in this privacy notice.

4.7.  How We Securely Store your Personal Data

We securely store and process personal data using Microsoft Azure data centres located within the European Union.

4.8. International Transfer

We may from time-to-time transfer, store or process (‘transfer’ includes making available  remotely) personal data to countries outside of the EEA. This such transfer of personal data  to a country outside of the EEA shall take place only if one or more of the following applies:

1. The transfer is to a destination that the European Commission has determined  ensures an adequate level of protection for personal data;

2. Where no adequacy decision exists, transfers are only made if we implement  appropriate safeguards, such as: Standard Contractual Clauses approved by the  European Commission, Binding Corporate Rules (BCRs), approved codes of conduct  or certification mechanisms, or contractual clauses authorised by the relevant data  protection authority;

3. The transfer is necessary to perform a contract between you and AccuBook. For  example, hosting or processing your data outside the EEA to provide our Services;

4. The transfer is made with the informed consent of the relevant data subject. You can  withdraw consent at any time;

5. The transfer is necessary for the conduct or defence of legal claims;

6. Transfers may be necessary to protect your vital interests, or those of another  person, where you are unable to provide consent.

We take all reasonable steps to ensure that your personal data remains protected during any  transfer outside the EEA and that your rights under the GDPR are safeguarded.

4.9. Data Security

We ensure that all personal data collected, held, and processed is kept secure and protected  against unauthorised or unlawful processing and against accidental loss, destruction, or  damage.

Our security measures include, but are not limited to:-

Technical Measures - electronic copies of personal data stored securely using passwords  and data encryption, encryption at rest and in transit, software (including, but not limited to,  applications and operating systems) kept up-to-date, requirements for strong passwords and  regular password changes

Organisational Measures – GDPR training for staff, access to personal data limited to staff  who require access (least privilege), periodic review of internal policies and procedures,  contractual obligations for third parties binding them and their employees to GDPR-compliant handling. 

Use and Access – limitation on transferring personal data with approval only, restriction on  sharing personal data informally, personal data handled with care at all times and not left  unattended

Disposal/Retention – secure deletion when personal data no longer required, retention only  for appropriate periods

4.10. Data Retention

We will not keep personal data for any longer than is necessary in light of the purpose or  purposes for which that personal data was originally collected, held, and processed. When  personal data is no longer required, all reasonable steps will be taken to erase or otherwise  dispose of it without delay.

4.11. Your Legal Rights under GDPR

You have the following rights under data protection laws in relation to your personal data.

Access

Request access to and/or a copy of the personal data we process about you (commonly known as a data subject access request). This enables you to check that we are lawfully processing it.

Correction

Request correction of any incomplete or inaccurate data we hold about you. (We may need to verify the accuracy of the new data you provide to us.)

Deletion

Request us to delete or remove personal data where there is no good reason for us continuing to process it. You also can ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we have processed your information unlawfully or where we need to erase your personal data to comply with law. (In some cases, we may need to continue to retain some of your personal data where required by law. If these apply, we will notify you at the time of our response.)

Objection

Object to us processing your personal data where (a) we are relying on legitimate interests as the lawful basis and you feel the processing impacts on your fundamental rights and freedoms, or (b) the processing is for direct marketing purposes. In some cases, we may refuse your objection if we can demonstrate that we have compelling legitimate grounds to continue processing your information which override your rights and freedoms.

Restriction

Restriction. Request that we restrict or suspend our processing of your personal data:
• if you want us to establish the data's accuracy;
• where our use of the data is unlawful, but you do not want us to erase it

• where we no longer require it, but you need us to hold onto it to establish, exercise or defend legal claims; or
• you have objected to our use of your data, but we need to verify whether we have overriding legitimate grounds to use it.

Data portability

Request we transfer certain of your personal data to you or your chosen third party in a structured, commonly used, machine-readable format. This right only applies to information processed by automated means that we process on the lawful bases of consent or performance of a contract.

Withdraw consent.

Withdraw your consent at any time where we are relying on consent to process your personal data. Please know that this does not affect the lawfulness of any processing carried out before you withdraw your consent, and after withdrawal, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.

Complain to the data protection regulator.

If you are unhappy with how we process your personal data, we ask that you contact us first using the details below so that we have the chance to put it right. However, you also have the right to make a complaint to the Data Protection Commission (DPC).

You can exercise any of these rights at any time by contacting us at info@guestdiary.com.

4.12.  Personal Data Breach Notification

We have put in place procedures to detect and respond to personal data breaches and notify  you and any applicable regulator. In the event of a personal data breach that is likely to  result in a risk to the rights and freedoms of individuals, we will notify the Data Protection  Commission without undue delay, and where required, no later than 72 hours after becoming  aware of the breach, as required under the GDPR.

Where a personal data breach is likely to result in a high risk to your rights and freedoms, we  will also notify you without undue delay and provide information about the nature of the  breach, the likely consequences, and the measures taken or proposed to address it.

We maintain internal records of all personal data breaches, including the facts relating to the  breach, its effects, and the remedial action taken.

5. Our Complaints Process

If you are unhappy with how we process your personal data, we ask that you contact us first  using the details below so that we have the chance to put it right. In order to raise a  compliant, please contact us at [email address].

You also have a right to make a complaint in respect of the handling or processing of your  personal data by AccuBook at any time with:

our lead supervisory authority in the EEA, which is the Data Protection Commission • (DPC). The DPC can be contacted via their website, which has an online complaints  portal https://www.dataprotection.ie/en/individuals/exercising-your-rights/raising-concern-commission , by telephone on 01 7650100 or 1800 437 737 or by post at  Data Protection Commission, 6 Pembroke Row, Dublin 2, D02 X963, Ireland A relevant data protection supervisory authority in the EEA state where you live, • where you work, or where the issues with our use of your personal data arose. For a  list of EEA data protection supervisory authorities and their contact details see here 

6. Other

AccuBook does not use personal data in automated decision-making processes.  Please note that our Services are not intended for children OR those under 16 and we do  not knowingly collect data relating to children.

7. Changes to the privacy notice and your duty to inform us of changes

We keep our privacy notice under regular review.

This version was last updated on 01/01/2026. It may change and, if it does, those changes will  be posted on this page and notified to you [by push notification OR by email OR when you  next start the App or log onto your account]. [The new notice may be displayed on-screen  and you OR You] may be required to read and acknowledge the changes to continue your  use of the App or the Services.

It is important that the personal data we hold about you is accurate and current. Please keep  us informed if your personal data changes during our relationship with you.

Implementation of Policy

This Policy shall be deemed effective as of 01/01/2026. No part of this Policy shall have retroactive effect and shall thus apply only to matters occurring on or after this date.

This Policy has been approved and authorised by:

Name: Andy Bassett

Position: Director

Date: 01/01/2026

Due for Review by: 01/01/2027

Signature: