ULTRAHOSPITALITY.AI ← Back to home

Privacy Policy

Operated by Ultra Hospitality · Effective 15 June 2026 · Version 1 · Governed by Egypt's Personal Data Protection Law (Law No. 151 of 2020), GDPR-aligned

In short: We are a business-to-business hospitality technology platform. We collect only the data needed to run our two products for hotels and their guests, we never sell personal data, our email is strictly transactional and consent-based, and every non-essential message includes a one-click unsubscribe. Details below.

1. Who we are

UltraHospitality.AI is operated by Ultra Hospitality ("we", "us", "the Platform"), registered at 14 Syria St., Mohandessin, Giza, Egypt. We provide two products:

For guest bookings on Ultra Guest, the hotel is the data controller of the guest relationship and the merchant of record; Ultra Hospitality acts as the technology processor on the hotel's documented instructions, and as an independent controller only for platform security, fraud prevention, legal compliance, and de-identified analytics.

2. The personal data we collect

CategoryExamples
Account & contactName, work email, phone, employer/hotel, role, preferred language.
Guest & stay dataReservation reference, room, check-in/out dates, supplied by the hotel's booking/PMS.
Order & booking dataItems viewed/booked, quantities, scheduling, special requests.
Procurement data (SupplyChain)A hotel's own e-invoice data, used to compute its procurement savings.
Dietary & allergen preferencesOnly what a guest volunteers, handled as sensitive data.
Payment metadataAmount, currency, status, gateway reference, card last-4/scheme. We never store full card numbers, CVV, or bank credentials — these go directly to the payment gateway.
Conversation dataAI concierge and support messages.
Technical & usageIP, device/browser, approximate location from IP, pages viewed, diagnostic logs.
Consent recordsTime, scope, and version of each consent given or withdrawn.

3. Email & communications how we use email

Email is central to how we serve hotels and guests, so we are explicit about it:

4. Why we use your data (lawful bases)

5. Who we share data with

We share personal data only as needed and under contract: with the hotel that controls the guest relationship; with payment gateways to process payments; with cloud and AI sub-processors that host the platform and power the concierge (see §6); and with authorities where legally required. We do not sell personal data.

6. International transfers

We use Amazon Web Services, including Amazon SES (email) and Amazon Bedrock (AI) in the US East (N. Virginia) region. Some data — for example concierge message content and the data needed to send an email — is processed in the United States under the cross-border safeguards of the PDPL and GDPR Chapter V (contractual data-protection clauses, encryption in transit, access controls, and data minimisation).

7. How long we keep data, and your rights

We retain personal data only as long as necessary, then delete or irreversibly anonymise it; financial and legal records are kept for the period the law requires. Subject to the PDPL and GDPR you may request access, rectification, erasure, restriction, portability, objection, and you may withdraw consent at any time. To exercise a right, contact us at the addresses below; you may also complain to Egypt's Personal Data Protection Center.

8. Security

We apply encryption in transit, strict tenant isolation (each tenant's data is logically separated and access is re-validated on every request), least-privilege access controls, hardened infrastructure, and append-only audit logging. Payment card data is handled by the gateway and is never stored by us.

9. Cookies

We use strictly necessary cookies for sign-in and security, and — only with consent — analytics cookies to improve the service. Guests can manage choices from the cookie banner in the guest app.

10. Children

The platform is intended for adults (18+) and is not directed at children. We do not knowingly collect data from minors without a guardian's consent.

11. Changes

We may update this policy; the version and effective date appear at the top. Material changes will be notified prominently and, where required, we will seek renewed consent.

12. Contact