Privacy Policy
RIGHT HOTELS SAS · Hotelminder (mindermod.org)
1. Who we are
Hotelminder is an editorial advisory and a hand-picked marketplace of add-on modules for independent hotels that already run their distribution on SiteMinder. The service, the mindermod.org website, the shortlist catalogue and the advisory conversations that surround them are all operated by RIGHT HOTELS SAS, a société par actions simplifiée organised under the laws of the French Republic, with share capital of 10 000 EUR, registered under SIREN 849 917 208 and SIRET 84991720800035 at the Registre du Commerce et des Sociétés de Bobigny 849 917 208, VAT identification number FR33 849917208, whose registered office is located at 7 Allée Jacques Cartier, 93160 Noisy-Le-Grand, France. The company is chaired by its President, Bouzbid Thimothée. In this Privacy Policy, we refer to RIGHT HOTELS SAS as “Hotelminder”, “we”, “us” or “our”. The words “you” or “your” refer to any natural person whose personal data we process — a website visitor, a prospective customer engaged in a scoping call, a subscribing hotelier, a member of a hotelier’s staff granted access to the dashboard, a supplier contact, an applicant to one of our advisory roles, or, in a limited and clearly delimited role, a hotel guest whose reservation information transits through a subscribed module.
2. Scope of this Policy
This document describes how we collect, use, disclose, transfer, retain and secure personal data across every point of contact with Hotelminder: the marketing pages of mindermod.org, the shortlist catalogue and its individual module pages, the advisory correspondence exchanged with our team, the checkout and billing surface where subscriptions are confirmed, the authenticated dashboard where a subscribed hotelier configures the modules that connect to their SiteMinder tenant, our transactional emails, and the direct exchanges you may have with our advisors during a scoping call, an on-property visit or an editorial guide contribution. Where a specific processing activity is regulated by an additional statute — for instance the retention obligations imposed by French tax and accounting law on invoices, or the specific rules of the LCEN 2004-575 on hosting — those specific rules apply in addition to what is set out here. Guest data that flows through the subscribed modules is addressed at Section 5 and is subject in more detail to our Data Processing Addendum at /legal/dpa, which forms the Article 28 RGPD instrument between us and the subscribing hotelier.
3. Legal framework we rely on
We process personal data in compliance with Regulation (EU) 2016/679 of 27 April 2016 (the “RGPD” or GDPR), the French Loi n° 78-17 du 6 janvier 1978 relative à l’informatique, aux fichiers et aux libertés as modified (the “Loi Informatique et Libertés”), the Loi n° 2004-575 du 21 juin 2004 pour la confiance dans l’économie numérique (“LCEN”) for cookies and hosting-related duties, and the applicable provisions of the Code de la consommation and the Code de commerce insofar as those laws touch on how we handle client and prospect data. Our declaration to the French supervisory authority is registered under CNIL, cnil.fr — déclaration n° 2224789. Where our services are marketed to hoteliers established outside France but inside the European Economic Area, the RGPD applies uniformly; where guests whose data transits through our platform are located outside the EEA, the international transfer safeguards described at Section 10 apply.
4. Categories of personal data we collect
We only collect personal data that is strictly relevant to a defined and disclosed purpose. The categories below correspond to the roles you may occupy in relation to Hotelminder.
- Website visitors — technical connection data (IP address, user-agent string, screen resolution, referring page and requested URL) captured by our hosting stack in Roubaix and by our CDN edge at Cloudflare for the sole purpose of routing, security and log-based troubleshooting, plus cookie identifiers described at /legal/cookies.
- Prospective customers on a scoping call — the professional identity of the interlocutor (name, hotel and role), the professional email and telephone at which the follow-up is arranged, notes taken by the advisor about the property, its distribution stack, its channel mix and the operational questions that motivate a shortlist, together with any documents you voluntarily share such as a rate grid, a channel-manager screenshot or a booking-engine report.
- Subscribing hotels and their staff — legal name of the hotel, VAT number, invoicing address, IBAN if a SEPA mandate is set up, first and last name of the authorised signatory, first and last name and business email of each user granted access to the dashboard, role assigned in the dashboard, hashed passwords, TOTP secrets for multi-factor authentication, session identifiers, audit trail of dashboard actions, module configuration values, and correspondence exchanged with our advisors.
- Guest data passing through subscribed modules — for modules that read from or write to the SiteMinder API, reservation-level personal data such as guest full name, arrival and departure date, room type, guest email or phone number where the hotel has captured it, rate code, stay value, loyalty tier and any note or preference the hotel has attached. This category is processed under the subscribing hotel’s controllership; Hotelminder acts as processor under Article 28 RGPD.
- Applicants to the advisory — CV, cover letter, LinkedIn URL and any references you volunteer when writing to careers@mindermod.org.
- Press contacts and editorial contributors — name, publication, email and the exchanges attached to the pitch.
5. Purposes and legal bases (Article 6 RGPD)
We assign each processing operation to one, and only one, primary legal basis. Ancillary bases may apply for demonstrable subsidiary purposes such as security or accounting compliance.
- Delivering the subscribed service — provisioning the dashboard, connecting the modules to the SiteMinder tenant, applying configuration changes and issuing invoices. Legal basis: performance of a contract, Article 6(1)(b) RGPD.
- Answering a scoping-call request or an enquiry — organising the first advisory conversation and following up. Legal basis: steps taken at the request of the data subject prior to entering into a contract, Article 6(1)(b) RGPD.
- Sending transactional operational emails — invoices, dashboard alerts, security notifications, module change notices. Legal basis: performance of a contract or, where required, legal obligation, Article 6(1)(b) and Article 6(1)(c) RGPD.
- Sending editorial updates to existing subscribing hoteliers — advisory newsletter about the shortlist and the products already in use at the property. Legal basis: legitimate interest, Article 6(1)(f) RGPD, balanced against the right to object at any time via one-click unsubscribe.
- Prospecting a new hotelier that has not yet subscribed — cold outreach initiated by our advisors. Legal basis: legitimate interest, Article 6(1)(f) RGPD, in accordance with the CNIL guidance on B2B prospecting; every outbound message contains a clear opt-out and a right to object under Article 21 RGPD.
- Meeting French tax and accounting duties — retention of invoices, contracts, and correspondence relevant to accounting. Legal basis: legal obligation, Article 6(1)(c) RGPD, in application of the Code de commerce and the Livre des procédures fiscales.
- Securing the service and preventing abuse — logging, rate-limiting, incident response, log retention for post-mortem. Legal basis: legitimate interest, Article 6(1)(f) RGPD, balanced by short retention windows and access limits.
- Non-essential analytics and preference cookies — measuring aggregate use of the marketing pages. Legal basis: consent, Article 6(1)(a) RGPD, obtained through the consent interface described at /legal/cookies.
- Guest data transiting through subscribed modules — processed on the subscribing hotel’s instructions. The legal basis on which the hotel relies is documented in the hotel’s own privacy notice to its guests; Hotelminder acts as processor and does not add a new legal basis of its own.
6. Purpose-by-purpose retention (Article 5(1)(e) RGPD)
We retain personal data only for as long as is necessary to fulfil the purpose for which it was collected. The following table summarises the maximum active retention periods; where a legal obligation imposes a longer archival duration, we archive the data in restricted-access storage until that duration expires.
| Data category | Purpose | Active retention | Archival |
|---|---|---|---|
| Scoping-call notes on prospects | Follow-up on the enquiry | 12 months from last contact | — |
| Cold-prospect professional contacts | B2B prospecting | 36 months from last contact | — |
| Dashboard user accounts | Service delivery | Life of the subscription + 3 months | — |
| Invoices and payment records | Legal obligation | Life of the subscription + 3 months | + 120 months (10 years, Code de commerce art. L123-22) |
| Audit logs of dashboard actions | Security, contractual proof | 13 months rolling | — |
| HTTP access logs | Security, troubleshooting | 6 months | — |
| Reservation-level guest data on our side | Delivery of the subscribed module | As instructed by the hotelier, default 24 months | — |
| Cookie consent record | Proof of consent | 13 months | — |
| Applicant CVs | Advisory recruitment | 24 months if no offer | — |
| Aggregated, non-identifying analytics | Product improvement | Indefinite, once anonymised beyond re-identification | — |
7. Recipients of personal data
We do not sell personal data. Personal data is disclosed to the following categories of recipient strictly for the purposes above:
- Members of the Hotelminder advisory team, each subject to a strict duty of confidentiality embedded in their employment or contractor agreement, on a need-to-know basis governed by role-based access control.
- Sub-processors listed in Section 8 acting on our written instructions under an Article 28 RGPD contract.
- Professional advisers — statutory auditor (commissaire aux comptes), external counsel, chartered accountant — under professional secrecy.
- Competent public authorities and courts where we are legally compelled to disclose under a valid legal instrument, and never on the strength of an informal request.
- An acquirer or successor in the event of a merger, acquisition, transfer of assets or reorganisation of RIGHT HOTELS SAS, in which case the successor is bound by an obligation to continue processing on the same terms.
8. Sub-processors
We rely on a small number of specialist sub-processors, each chosen for its European footprint and each bound by a data processing agreement. The current list is:
| Sub-processor | Role | Location of processing |
|---|---|---|
| OVHcloud SAS | Application hosting, database, backups | Roubaix, France |
| Cloudflare, Inc. (via EU legal entity) | Edge routing and CDN | EEA edge nodes, EU-US Data Privacy Framework certified |
| Stripe Payments Europe Ltd. | Card payments | Ireland, with sub-flow to the United States under SCCs |
| Postmark (ActiveCampaign LLC) | Transactional email delivery | United States, under SCCs |
| Datadog EU | Observability, application metrics | Frankfurt, Germany |
| Sentry EU (Functional Software Ireland Ltd.) | Error tracking | Frankfurt, Germany |
Any change to this list is announced with at least fifteen (15) calendar days’ notice on the changelog page and by email to dashboard administrators, giving the subscribing hotelier a documented window to object as provided under our Data Processing Addendum.
9. International transfers
Our default position is to keep personal data within the European Economic Area. Where a sub-processor forms part of a group whose parent or affiliates are located outside the EEA, we transfer personal data only under one of the following instruments: (i) an adequacy decision of the European Commission (for instance the EU-US Data Privacy Framework where a US recipient is certified under it), or (ii) the Standard Contractual Clauses of 4 June 2021 (Decision 2021/914) with Annex I (parties, categories of data and data subjects, transfer specifications), Annex II (technical and organisational measures) and Annex III (list of sub-processors) as applicable, together with a Transfer Impact Assessment that documents the supplementary technical, contractual and organisational measures we have added. In all cases, personal data at rest is encrypted with AES-256 and personal data in transit is protected by TLS 1.3, so that a foreign authority accessing the underlying infrastructure would receive only opaque ciphertext.
10. Your rights (Articles 15–22 RGPD)
You have the following rights, exercisable free of charge, without any obligation to justify your request:
- Right to be informed (Articles 13–14 RGPD), realised in the first instance through this Policy.
- Right of access (Article 15 RGPD), including a copy of the personal data we hold about you.
- Right to rectification (Article 16 RGPD), when the data is inaccurate or incomplete.
- Right to erasure or “right to be forgotten” (Article 17 RGPD), subject to the exceptions listed in that Article, in particular the retention of invoicing records required by tax law.
- Right to restriction of processing (Article 18 RGPD), typically pending verification of the accuracy of the data or of the lawfulness of a specific processing activity.
- Right to data portability (Article 20 RGPD), for data you have provided to us on the basis of consent or contract, delivered in a structured, commonly used and machine-readable format.
- Right to object (Article 21 RGPD), notably against prospecting and against processing based on legitimate interest.
- Right not to be subject to a decision based solely on automated processing (Article 22 RGPD) — see Section 12 below on the absence of any such decision.
- Right to lodge a complaint with the CNIL, 3 Place de Fontenoy — TSA 80715 — 75334 Paris Cedex 07, or via cnil.fr.
- Right to give post-mortem instructions in respect of your personal data under Article 40-1 of the Loi Informatique et Libertés.
Requests may be sent to privacy@mindermod.org or in writing to the DPO at the postal address above. We respond within one (1) month of receipt, extended by two (2) further months for particularly complex requests, in which case we notify you of the extension and its reasons. Where we need to confirm your identity we request the minimum information sufficient to prevent an unauthorised disclosure.
11. Security measures (Article 32 RGPD)
We implement and continuously maintain technical and organisational measures appropriate to the risk of processing. These include encryption in transit (TLS 1.3 with modern cipher suites), encryption at rest (AES-256 for databases and object storage), tenant-level isolation of subscribing hoteliers, least-privilege role-based access control, mandatory multi-factor authentication for staff, quarterly access reviews, centralised secret management, immutable audit logs, private-VPC network isolation, dependency vulnerability scanning at each release, annual penetration testing by an accredited external party, controlled change management, and a documented business continuity plan with tested restore drills against the OVHcloud Roubaix primary and its EEA-located secondary. Personal data breaches, once we become aware of them, are notified to the CNIL within seventy-two (72) hours where required by Article 33 RGPD, and to affected data subjects where the breach is likely to result in a high risk to their rights and freedoms as required by Article 34 RGPD.
12. Automated decision-making
Hotelminder does not take any decision based solely on automated processing that produces legal effects or similarly significantly affects you within the meaning of Article 22 RGPD. Recommendation features embedded in certain modules — for example a rate suggestion in a revenue module — are advisory only, presented to a human operator at the hotel who reviews and approves, adjusts or rejects the suggestion before it is written back to the SiteMinder tenant. Where a hotelier chooses to configure narrow, hotelier-defined guardrails for automatic micro-adjustments, the framework operates strictly within those guardrails and can be paused instantly.
13. Cookies
The mindermod.org site uses a strictly-necessary set of cookies for session management and CSRF protection, together with a preference cookie for the consent state and, subject to your consent, non-essential cookies for aggregate measurement. The full list, the retention of each cookie and the interface to withdraw consent are set out at /legal/cookies. The consent record is retained for thirteen (13) months in accordance with CNIL recommendation.
14. Children
The Hotelminder platform is a business-to-business service directed at hoteliers and their staff. It is not directed at children and we do not knowingly collect personal data of natural persons under the age of sixteen (16). Where a reservation transiting through a subscribed module concerns a minor, the subscribing hotelier remains responsible for the lawfulness of that processing in its capacity as controller.
15. Changes to this Policy
We may amend this Privacy Policy from time to time to reflect changes in the law, in CNIL or European Data Protection Board guidance, in our processing activities or in the list of sub-processors. Material changes are notified to dashboard administrators at least thirty (30) days before the effective date. The current version and its adoption date are always visible at the top of this page.
16. Contact — Data Protection Officer
For any question about this Privacy Policy, to exercise a right listed at Section 10, or to raise a data-protection concern, please write to our Data Protection Officer Camille Dubois-Renard at dpo@mindermod.org, or by post to RIGHT HOTELS SAS — Data Protection Officer, 7 Allée Jacques Cartier, 93160 Noisy-Le-Grand, France. General enquiries: privacy@mindermod.org. Regulator: CNIL, cnil.fr — déclaration n° 2224789.