Privacy Policy
Last updated: 20 August 2026
This policy explains what personal data Boris processes, why, for how long, and what you can ask us to do about it. Boris is a booking and workspace management platform, so it handles data about the businesses that use it and about their customers and guests. Those two roles are treated differently, and the distinction is set out below.
Who is responsible
Boris is operated by [legal entity name], [registered address].
For the account data of the people who sign up and use the panel, we are the controller: we decide what is collected and why.
For the data a workspace loads into Boris about its own customers and guests, the workspace is the controller and we act as a processor on its instructions. Practically, that means requests about a guest record should go to the property or space that holds it; if one reaches us first, we will forward it rather than act on it ourselves.
What we process
The data falls into five groups.
- Account data. Name, email address, a hashed password, the identity provider when you sign in with Google or Microsoft, two-factor settings, and your role within a workspace.
- Workspace data. The business details you configure: legal name, address, tax identifiers, resources, opening hours, pricing and integration settings.
- Customer and guest data. Names, contact details, identity document details, nationality, dates of birth, tax identifiers, and the bookings, invoices and memberships attached to them.
- Transaction data. Bookings, payments, invoices, refunds, tourist tax records and channel payouts.
- Technical data. Session cookies, IP addresses in server and security logs, audit records of actions taken in the panel, and the execution ledger that records every side effect a booking produced.
Why we process it
- To perform the contract. Creating accounts, authenticating users, running bookings, issuing invoices and taking payments.
- To comply with a legal obligation. Filing guests with the authorities where the law requires it, calculating and reporting tourist tax, and keeping accounting records.
- For our legitimate interests. Keeping the service secure, preventing abuse, diagnosing faults and improving the product. We balance this against your interests and keep the data involved to a minimum.
- With consent, where an optional integration or communication asks for it. Consent can be withdrawn at any time without affecting what was done before.
Identity documents are deleted, not archived
When a guest completes online check-in, they may be asked to photograph an identity document, because the law requires the stay to be reported. Once that report is filed, the legal basis for holding the image is spent.
Boris therefore destroys document photographs automatically: at the moment the stay is filed with the authority, and at 23:59 on the arrival day regardless of whether filing succeeded. The image is removed from storage and from the database. There is no setting to extend this, because a setting to extend it would be a setting to accumulate passports.
The details transcribed from the document — name, date of birth, document number, nationality — are kept as part of the guest record, because that is what the filing obligation and any later inspection require. The photograph itself is not.
Reporting guests to public authorities
Where a workspace provides accommodation, national law may require each guest to be reported. Boris supports SES.Hospedajes in Spain and Alloggiati Web in Italy, and transmits only the fields those systems require, within the deadline they set.
This transmission is a legal obligation of the accommodation provider. It cannot be opted out of while the obligation applies, and the reference the authority returns is stored as evidence that the report was accepted.
Payments
Card payments are handled by our payment provider. Card numbers never reach Boris and are never stored by us; we keep the payment reference, amount, status and method so that a booking can be reconciled.
Service providers and integrations
Boris relies on providers to host the service, deliver email and process payments. In addition, a workspace can enable integrations that necessarily share data with a third party, such as door access, guest WiFi, printing, accounting, property management systems, booking channels and messaging.
These integrations are optional and off by default. Enabling one is an instruction to send the data that integration needs; disabling it stops further transmission but does not delete what the third party already received, which has to be requested from them.
How long we keep data
- Account data: while the account exists, and a short period afterwards to handle disputes.
- Booking, invoice and tax records: for the period accounting and tax law requires, which is typically several years and is not shortened by a deletion request.
- Identity document photographs: until the stay is filed, and never past the end of the arrival day.
- Security and audit logs: a limited period proportionate to investigating incidents.
Where data is processed
Data is processed within the European Economic Area wherever possible. Where a provider processes data outside it, we rely on the safeguards the law provides for such transfers, such as the European Commission's standard contractual clauses.
Your rights
Subject to the conditions the law attaches to each, you can ask to:
- access the personal data we hold about you, and receive a copy;
- correct data that is inaccurate or incomplete;
- delete data we no longer have a basis to keep;
- restrict or object to certain processing;
- receive data you gave us in a portable format;
- withdraw consent where processing was based on it.
Write to [privacy contact email]. If your request concerns data held by a workspace about you as its customer or guest, contact that workspace: they decide, and we act on their instructions.
If you believe we have handled your data unlawfully, you may complain to [competent supervisory authority].
Cookies
Boris sets a session cookie so that you stay signed in. It is HTTP-only, restricted with SameSite and marked Secure over HTTPS. It is necessary for the service to function and is not used to track you across other sites. A language preference may also be stored so the interface opens in the language you chose.
Because those are strictly necessary, they do not require your consent. Anything beyond them does: the notice on the public site asks separately, refusing is as easy as accepting, and nothing optional runs unless you allow it. Your answer is kept in your browser rather than in a cookie, and the "Cookies" link in the footer reopens the notice if you want to change it.
Security
Passwords are stored hashed and never in a recoverable form. Access to workspace data is scoped so that one workspace cannot read another's. Panel actions that change data pass through cross-site request forgery checks, and transport is encrypted over HTTPS. No system is immune, so if a breach ever affects your rights we will notify you and the supervisory authority as the law requires.
Changes to this policy
When this policy changes materially we will update the date at the top and, for changes that affect you, tell account holders directly rather than relying on you to re-read the page.
