Privacy Policy
This policy explains how SereneDeck handles personal data relating to website visitors, customer accounts, hotel staff and hotel guests.
Effective 31 August 2026
Document version 2026-08-31
1. Who we are
SereneDeck is operated by ADNorden, CVR 27802753, Havremarksvej 13, 6500 Vojens, Denmark. Privacy enquiries can be sent to contact@serenedeck.com.
2. Our role
SereneDeck is the data controller for website enquiries, account administration, billing, service security and its own legal obligations. For operational guest and staff data entered by a hotel, the hotel is normally the controller and SereneDeck processes the data on the hotel's documented instructions. Hotel guests should direct rights requests to their hotel.
3. Data we process
- Business account data, including hotel name, user name, work email, role and timezone.
- Security data, including password hashes, hashed session and access credentials, login timestamps and limited request identifiers used to prevent abuse.
- Billing data, including Stripe customer and subscription identifiers, plan, status, invoices, billing address and business tax information.
- Hotel operational data, which may include room numbers, guest names, stay dates, party size, booking references, reservations, notes and PMS identifiers.
- Audit history, support communications, invitation details and service configuration.
- Import files and import history supplied or configured by the customer.
- Functional browser storage described in our Cookie Notice.
4. Purposes and legal bases
We process account and billing information to enter into and perform the customer contract; security and service-administration data for our legitimate interests in providing a secure and reliable service; and accounting or compliance information to meet legal obligations. Operational hotel data is processed under the customer's instructions and Data Processing Agreement. Consent is used only where a specific optional activity legally requires it.
5. Recipients and subprocessors
Data is disclosed only where needed to provide the service, process payments, send transactional email, host and secure the application, obtain professional advice or comply with law. Current service providers and their purposes are listed on the Subprocessors page. Hotels may also connect systems or storage accounts they select and control.
6. International transfers
Where a provider processes data outside the EU/EEA, SereneDeck uses an applicable lawful transfer mechanism, such as an adequacy decision or the European Commission's standard contractual clauses, together with supplementary safeguards where required. Details are available on request.
7. Retention
- Active login sessions expire after no more than 30 days and expired records are cleaned up.
- Raw import artifacts are retained for up to 90 days; detailed row content is removed when the artifact expires.
- Operational hotel data is retained while the customer account is active and according to the hotel's instructions, contractual requirements and configured workflows.
- Following an account-deletion request, SereneDeck coordinates export, subscription closure and deletion, except for information that must be retained by law or to establish or defend legal claims.
- Accounting material is retained for five years from the end of the financial year to which it relates where Danish bookkeeping law requires it.
8. Security
Measures include encrypted network transport, password hashing, hashed session and access tokens, role-based access, tenant scoping, audit records, restricted administrative access and environment-managed secrets. Security measures are reviewed as the service and risk profile evolve.