Skip to content
Nexus RMS

Privacy Policy

Last updated: Oct 1, 2026

1. Who we are

Nexus RMS is a revenue management and pricing platform for hotels, operated by [Company legal name], registered at [address], [Chamber of Commerce / KvK number] ("Nexus RMS", "we", "us").

This policy explains how we handle personal data when you visit our website at rndnexus.app, create an account, or connect a property management system (PMS) to Nexus RMS. It applies to hotel staff who use the platform, to visitors of our website, and, where noted, to hotel guests whose data passes through a connected PMS.

2. Our role: controller or processor

We act in two different roles under the EU General Data Protection Regulation (GDPR), depending on whose data it is.

DataOur roleWho decides how it is used
Your account, billing and support dataControllerNexus RMS
Website visitor and analytics dataControllerNexus RMS
Reservation, rate and guest data from your connected PMSProcessorThe hotel (our customer)

When we process PMS data, we do so only on the hotel's documented instructions under our Data Processing Agreement (DPA). Hotel guests who want to exercise their rights should contact the hotel directly; we will help the hotel respond.

3. Information we collect

We collect only what we need to run the platform and price your rooms.

CategoryExamplesSource
Account dataName, work email, hotel name, role, password hashYou
Billing dataCompany name, VAT number, billing address, invoicesYou, our payment provider
Property and pricing dataRoom types, rates, restrictions, occupancy, availability, pricing rulesYour PMS, you
Reservation dataStay dates, room type, rate, channel, booking status, revenueYour PMS
Limited guest dataBooking reference, country of residence, and any guest fields the PMS includes in reservation recordsYour PMS
Usage and device dataIP address, browser, log-in times, pages used, error logsAutomatically
Support dataMessages and attachments you send usYou

We do not need guest payment card data, ID documents or special-category data, and we ask hotels not to send it. Where the PMS returns guest names or contact details in reservation records, we do not use them for pricing and [discard / pseudonymise] them [timeframe].

4. How we use information and our legal bases

Where we are the controller, we rely on the following legal bases under Article 6 GDPR.

PurposeLegal basis
Create and manage your account; provide pricing recommendations and forecastsPerformance of contract
Billing, invoicing and tax recordsLegal obligation; contract
Security, fraud prevention, debugging and service reliabilityLegitimate interests
Improving our models and features using aggregated, de-identified dataLegitimate interests
Product updates and service emailsContract; legitimate interests
Marketing emailsConsent (you can withdraw at any time)
Non-essential cookies and analyticsConsent

We do not sell personal data and do not use it for advertising profiling. Pricing recommendations are generated automatically, but hotel staff decide whether to apply them; no decision with legal effect on an individual is made solely by automated means.

5. PMS integrations (Mews and Apaleo)

Nexus RMS connects to Mews and Apaleo only after an authorised user at the hotel grants access. Through these connections we:

  • Read property configuration, availability, reservations and revenue data to build forecasts and recommendations.
  • Write rates and restrictions back to the PMS, only when you approve a price or enable automatic updates.

We store access tokens encrypted and use them only for these purposes. You can disconnect at any time from your Nexus RMS settings or from the PMS itself; we then stop syncing and delete PMS data as described in Section 8. Mews and Apaleo handle data under their own privacy policies, and their use of data is outside our control.

6. Sharing and sub-processors

We share personal data only with service providers that help us run Nexus RMS, under contracts that bind them to GDPR-level protection.

ProviderPurposeLocation
Cloudflare, Inc.Hosting, database, CDN, securityEU / global network
[Payment provider, e.g. Stripe]Subscription billing[EU / US]
[Email provider]Transactional and service email[Location]
[Analytics / error monitoring provider]Product analytics, error logs[Location]
Mews, ApaleoPMS data exchange you authoriseEU

We may also disclose data when required by law, to protect our rights, or to a successor in a merger or acquisition, who must honour this policy. We will keep an up-to-date sub-processor list at [link] and notify customers before adding a new one.

7. International transfers

We aim to store and process data within the European Economic Area (EEA). Where a provider processes data outside the EEA, we rely on an adequacy decision (including the EU-US Data Privacy Framework where the provider is certified) or the European Commission's Standard Contractual Clauses, with additional safeguards where needed. You can request a copy of the relevant safeguards by contacting us.

8. Data retention

We keep data only as long as needed for the purposes above.

DataRetention
Account dataFor the life of the account, then deleted within [30] days of closure
PMS reservation and pricing dataFor the life of the contract; deleted within [30] days of disconnection or termination, unless the hotel asks for an export first
Guest identifiers from PMS records[Not stored / pseudonymised within X days]
Billing records7 years, as required by Dutch tax law
Server and security logs[90] days
Support messages[2] years after the ticket closes

Aggregated, de-identified data that can no longer identify a hotel or person may be kept longer to improve our models.

9. Security

We protect data with measures appropriate to the risk, including:

  • Encryption in transit (TLS) and at rest, including PMS access tokens
  • Hashed passwords and role-based access within each hotel account
  • Strict separation of each hotel's data
  • Least-privilege access for our staff, with access logging
  • Regular backups and dependency updates

No system is perfectly secure. If a breach affects your personal data, we will notify the relevant hotel without undue delay and, where required, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours.

10. Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Delete your data ("right to be forgotten")
  • Restrict or object to certain processing, including processing based on legitimate interests
  • Receive your data in a portable format
  • Withdraw consent at any time, without affecting earlier processing

Email [privacy@domain] to make a request. We reply within one month and may ask you to verify your identity. You may also complain to the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl) or the authority in your EU country.

11. Cookies and similar technologies

We use strictly necessary cookies to keep you logged in, remember settings and protect the service (for example, Cloudflare security cookies). These do not require consent.

We use analytics or other non-essential cookies only after you accept them in our cookie banner, and you can change your choice at any time via [Cookie settings link]. We do not use advertising or cross-site tracking cookies.

12. Children, changes and contact

Children. Nexus RMS is a business tool for hotel professionals and is not intended for anyone under 16. We do not knowingly collect their data.

Changes. We may update this policy as the service evolves. We will post the new version here with a new "Last updated" date and notify account holders by email of material changes.

Contact. [Company legal name], [address]. Email: [privacy@domain].