Privacy Policy
Last updated: Oct 1, 2026
1. Who we are
Nexus RMS is a revenue management and pricing platform for hotels, operated by [Company legal name], registered at [address], [Chamber of Commerce / KvK number] ("Nexus RMS", "we", "us").
This policy explains how we handle personal data when you visit our website at rndnexus.app, create an account, or connect a property management system (PMS) to Nexus RMS. It applies to hotel staff who use the platform, to visitors of our website, and, where noted, to hotel guests whose data passes through a connected PMS.
2. Our role: controller or processor
We act in two different roles under the EU General Data Protection Regulation (GDPR), depending on whose data it is.
| Data | Our role | Who decides how it is used |
|---|---|---|
| Your account, billing and support data | Controller | Nexus RMS |
| Website visitor and analytics data | Controller | Nexus RMS |
| Reservation, rate and guest data from your connected PMS | Processor | The hotel (our customer) |
When we process PMS data, we do so only on the hotel's documented instructions under our Data Processing Agreement (DPA). Hotel guests who want to exercise their rights should contact the hotel directly; we will help the hotel respond.
3. Information we collect
We collect only what we need to run the platform and price your rooms.
| Category | Examples | Source |
|---|---|---|
| Account data | Name, work email, hotel name, role, password hash | You |
| Billing data | Company name, VAT number, billing address, invoices | You, our payment provider |
| Property and pricing data | Room types, rates, restrictions, occupancy, availability, pricing rules | Your PMS, you |
| Reservation data | Stay dates, room type, rate, channel, booking status, revenue | Your PMS |
| Limited guest data | Booking reference, country of residence, and any guest fields the PMS includes in reservation records | Your PMS |
| Usage and device data | IP address, browser, log-in times, pages used, error logs | Automatically |
| Support data | Messages and attachments you send us | You |
We do not need guest payment card data, ID documents or special-category data, and we ask hotels not to send it. Where the PMS returns guest names or contact details in reservation records, we do not use them for pricing and [discard / pseudonymise] them [timeframe].
4. How we use information and our legal bases
Where we are the controller, we rely on the following legal bases under Article 6 GDPR.
| Purpose | Legal basis |
|---|---|
| Create and manage your account; provide pricing recommendations and forecasts | Performance of contract |
| Billing, invoicing and tax records | Legal obligation; contract |
| Security, fraud prevention, debugging and service reliability | Legitimate interests |
| Improving our models and features using aggregated, de-identified data | Legitimate interests |
| Product updates and service emails | Contract; legitimate interests |
| Marketing emails | Consent (you can withdraw at any time) |
| Non-essential cookies and analytics | Consent |
We do not sell personal data and do not use it for advertising profiling. Pricing recommendations are generated automatically, but hotel staff decide whether to apply them; no decision with legal effect on an individual is made solely by automated means.
5. PMS integrations (Mews and Apaleo)
Nexus RMS connects to Mews and Apaleo only after an authorised user at the hotel grants access. Through these connections we:
- Read property configuration, availability, reservations and revenue data to build forecasts and recommendations.
- Write rates and restrictions back to the PMS, only when you approve a price or enable automatic updates.
We store access tokens encrypted and use them only for these purposes. You can disconnect at any time from your Nexus RMS settings or from the PMS itself; we then stop syncing and delete PMS data as described in Section 8. Mews and Apaleo handle data under their own privacy policies, and their use of data is outside our control.
7. International transfers
We aim to store and process data within the European Economic Area (EEA). Where a provider processes data outside the EEA, we rely on an adequacy decision (including the EU-US Data Privacy Framework where the provider is certified) or the European Commission's Standard Contractual Clauses, with additional safeguards where needed. You can request a copy of the relevant safeguards by contacting us.
8. Data retention
We keep data only as long as needed for the purposes above.
| Data | Retention |
|---|---|
| Account data | For the life of the account, then deleted within [30] days of closure |
| PMS reservation and pricing data | For the life of the contract; deleted within [30] days of disconnection or termination, unless the hotel asks for an export first |
| Guest identifiers from PMS records | [Not stored / pseudonymised within X days] |
| Billing records | 7 years, as required by Dutch tax law |
| Server and security logs | [90] days |
| Support messages | [2] years after the ticket closes |
Aggregated, de-identified data that can no longer identify a hotel or person may be kept longer to improve our models.
9. Security
We protect data with measures appropriate to the risk, including:
- Encryption in transit (TLS) and at rest, including PMS access tokens
- Hashed passwords and role-based access within each hotel account
- Strict separation of each hotel's data
- Least-privilege access for our staff, with access logging
- Regular backups and dependency updates
No system is perfectly secure. If a breach affects your personal data, we will notify the relevant hotel without undue delay and, where required, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours.
10. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your data ("right to be forgotten")
- Restrict or object to certain processing, including processing based on legitimate interests
- Receive your data in a portable format
- Withdraw consent at any time, without affecting earlier processing
Email [privacy@domain] to make a request. We reply within one month and may ask you to verify your identity. You may also complain to the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl) or the authority in your EU country.
12. Children, changes and contact
Children. Nexus RMS is a business tool for hotel professionals and is not intended for anyone under 16. We do not knowingly collect their data.
Changes. We may update this policy as the service evolves. We will post the new version here with a new "Last updated" date and notify account holders by email of material changes.
Contact. [Company legal name], [address]. Email: [privacy@domain].