1. Who we are
[COMPANY_LEGAL_NAME] (“we”, “us”) operates DAS (Dofa Audit System), a reporting service that organizes information from hotel night-audit reports into a performance dashboard for hotel owners, operators and management companies.
This policy covers both this public website and the DAS customer dashboard. Where the two differ, we say so.
2. Information we collect
2.1 Website visitors
If you submit an enquiry or demo request, we collect what you choose to give us — typically your name, work email address, phone number (optional), company, role, number of properties, the PMS you use, and your message. We also receive standard technical information that any web server receives, such as IP address, browser type and the pages requested.
2.2 Customer account information
For customers, we hold the account details needed to run access control: a username, a display name, the hotels that account is permitted to see, and credentials used to sign in.
2.3 Hotel report information
The core of the service is information from the reports a hotel’s property management system produces after its nightly audit. Depending on the reports supplied and the hotel’s configuration, this may include revenue and room revenue, occupancy, ADR, RevPAR, rooms sold and available, forecast figures, market segment performance, daily financial information, operational report data, and month-to-date and year-to-date performance.
2.4 Operational and financial data
We retain derived daily figures for each property so that the dashboard can show history, trends and property-to-property comparison over time.
2.5 Guest-related information
Our purpose is performance and financial reporting, not guest profiling. Some hotel reports may nevertheless contain guest-related operational detail. We do not seek out guest personal information, we do not use it for marketing, and we do not sell it. Where a metric does not require guest-level detail, it is kept out of the reporting views.
3. How we use information
- To provide the dashboard and the reporting features a customer has signed up for.
- To operate access control, so each user sees only the properties they are permitted to see.
- To respond to demo requests and enquiries.
- To maintain, troubleshoot, secure and improve the service.
- To meet legal, accounting and regulatory obligations.
We do not sell personal information, and we do not use hotel report data to build products for anyone other than the customer it belongs to.
4. Cookies and analytics
The customer dashboard sets one strictly necessary cookie to keep you signed in. It holds a signed session reference and an expiry time, is marked HTTP-only and secure, is restricted to the site’s own origin, and expires after a period of inactivity. It is not used for advertising or cross-site tracking.
[STATE WHETHER THIS PUBLIC SITE USES ANY ANALYTICS. If you add analytics later, name the provider here and describe what it collects. As built today, this marketing site sets no cookies and loads no third-party scripts.]
5. Service providers
We use a small number of infrastructure providers to run the service — for example web hosting and content delivery, source code hosting, and the email service used to receive hotel reports. These providers process information on our behalf and under their own security commitments. [LIST THE PROVIDERS YOU WANT TO NAME PUBLICLY.]
6. How we protect information
- Every dashboard page requires authentication; unauthenticated requests receive no hotel content.
- Access is scoped per property, and content belonging to hotels a user may not see is removed server-side before the page is delivered.
- Traffic is served over HTTPS.
- Sessions expire automatically after a period of inactivity.
- Raw report files are not published with the dashboard.
- Credentials for the reporting mailbox are held as encrypted configuration, not in source control.
No system can be guaranteed completely secure. We do not currently hold SOC 2, PCI, ISO or HIPAA certification, and this policy does not claim any such certification.
7. Retention
We keep customer account information for as long as the account is active. Daily performance history is retained so the dashboard can show trends over time. Enquiry correspondence is kept for as long as needed to respond and to maintain a record of the enquiry. [CONFIRM YOUR RETENTION PERIODS AND STATE THEM HERE.]
8. Your rights
Depending on where you live, you may have the right to request access to the personal information we hold about you, to ask us to correct or delete it, to object to or restrict certain processing, and to request a copy in a portable format. To make a request, contact us using the details below. Where hotel data belongs to a customer organization, we will direct the request to that customer, who controls it. [CONFIRM WHICH PRIVACY LAWS APPLY TO YOU — e.g. state privacy laws, GDPR — AND ADD ANY REQUIRED DISCLOSURES.]
9. Children
The service is a business tool and is not directed to children. We do not knowingly collect personal information from children.
10. Changes to this policy
We may update this policy as the product changes. The “last updated” date at the top reflects the current version, and material changes will be communicated to customers.
11. Contact us
Questions about this policy or about the information we hold:
- [COMPANY_LEGAL_NAME]
- [COMPANY_ADDRESS]
- Email: [CONTACT_EMAIL]
- Phone: [CONTACT_PHONE]