Security posture
We process reservations, guest contact details and rate data on behalf of UK hotels. This page states plainly how that data is hosted, encrypted, tokenised, logged and restored — so your DPA reviewers can check our claims rather than take them on faith.
Hosting regions
Production workloads run in EU-region data centres with primary infrastructure in London and burst capacity in Frankfurt. Guest data does not leave those regions; cross-region replication stays within them.
Transport encryption
All endpoints enforce TLS 1.2 or newer with modern cipher suites; TLS 1.0/1.0-era handshakes are rejected. Internal service-to-service traffic is encrypted as well, not just the public edge.
Storage encryption
Data at rest — databases, document stores for e-signed arrival packs, backups — is encrypted with AES-256. Encryption keys are rotated on a documented schedule and never stored alongside the data they protect.
Short-lived scoped tokens
Connections to your Rezlynx environment use short-lived access tokens minted against the scoped key you created inside your own settings. Tokens carry only the permissions each module needs, referencing the Rezlynx permission model directly, and expire quickly rather than lingering.
Internal two-factor authentication
Every member of staff with production access authenticates with hardware-backed two-factor authentication. Access follows least privilege, is reviewed monthly, and revoked the day it is no longer needed.
Quarterly dependency sweeps
Third-party libraries are swept every quarter against published advisories, plus emergency checks when critical CVEs land. Patch windows are announced to affected customers when update behaviour could be observed.
Backups and recovery
RPO 15 minutes. Continuous transaction-log shipping means at most fifteen minutes of data can be lost in a worst-case site failure.
RTO 2 hours. Recovery time objective for full service restoration, rehearsed rather than assumed.
Quarterly restore drills. Every quarter we restore from backup into an isolated environment and verify integrity end-to-end — including the e-signature document chain, where a broken timestamp would matter legally. Drill summaries are available to customers on request under NDA-equivalent terms within your DPA review.
Backups are encrypted with the same AES-256 standard as production, retained per the schedule published in our privacy policy, and never leave their host region.
Audit logs
Twelve months of audit logs cover administrative actions, API token issuance, scope changes, module toggles, rate-table writes accepted by customers, and support sessions touching customer configuration. Logs are immutable during retention, searchable by your named contacts for your own property's entries, and exported alongside invoices on request.
Access by our engineers to live customer environments requires an elevated session that is logged with reason codes; you can request any such entry tied to your account for the full twelve-month window.
Vulnerability disclosure
Report suspected issues to security@hotelrezlynx.com. We acknowledge within one business day and triage against severity bands agreed in advance. Good-faith research against your own account or a written permission from us is welcome; findings affecting shared components are credited anonymously unless you ask otherwise.
Critical issues affecting guest-facing behaviour are patched first, communicated to all active customers with plain-English notes, and reflected in the next release summary published through the client area.
Regulatory standing
Pendle Software Ltd is registered with the Information Commissioner's Office under registration ZA582146. Where modules handle guest records we act strictly as processor under a written data processing agreement, while controller-side handling of our own customer records follows the UK GDPR and the Data Protection Act 2018.
The privacy policy documents retention schedules per data category, and cancellation triggers deletion within 30 days as confirmed in writing. Data-residency questions common in hotel group procurement reviews are answered in writing within one business day.
Something unlisted? Ask the Leeds desk — security answers come from engineers, not scripts.