Legal
Data Deletion
Effective: 27 August 2026
This page explains how to ask for personal data held in Deemora Concierge to be deleted, what to include in the request, and what happens next.
1. How to make a request
Send an email to support@deemora.co with "Data Deletion Request" as the subject. A request can be made by a guest, by a member of hotel staff about their own account, or by a provider about their own account.
2. What to include
Enough information to locate the right records, and no more than that:
- Your name, as it would appear on the request or account.
- The hotel concerned.
- The approximate dates of the stay, or of the request.
- The contact number or email address that was used with the service.
- A short description of what you would like deleted — a specific request, or all data held about you.
3. Never send credentials
Do not include a password, a one-time code, an access token, a full card number, or any other credential. This information is never needed to process a deletion request, and it should not be sent by email. If a message containing a credential is received, it will not be used to verify anything.
4. Verification
Before a request is acted on, it must be reasonably established that the person making it is the person the data relates to, or is entitled to make the request on their behalf. This may mean asking a follow-up question about the request or stay, or confirming the request from the contact address or number already associated with the record. This step exists to protect the data from being deleted or disclosed on someone else's say-so.
5. The hotel's involvement
Deemora Concierge is provided to hotels, and much of the guest data in it is held in order to serve a particular hotel, which holds the direct relationship with its guests. A deletion request may therefore be coordinated with the hotel concerned, and the hotel may need to act on parts of it. You may also raise a deletion request with the hotel directly.
6. What happens next
- The request is acknowledged.
- Identity, or entitlement to make the request, is verified as described above.
- The records concerned are located and reviewed against the retention grounds below.
- Data that can be deleted is deleted or de-identified, and you are told what was done and what, if anything, had to be kept and why.
Requests are handled within a reasonable period and in line with applicable law. Deletion is not immediate, and this page does not promise immediate deletion.
7. Data that may need to be kept
Some records cannot be deleted on request, because there is a legal or operational obligation to keep them. This typically includes:
- Records connected to payments, invoicing, or tax, for the period required by applicable accounting and regulatory obligations.
- Records relevant to an active dispute, complaint, investigation, or legal claim, until it is resolved.
- Security and audit records kept to protect the service and the people using it.
Where data has to be kept, it is kept only for that reason and for no longer than that reason requires, and its use is restricted accordingly.
8. Messages already delivered
Deleting data from the platform does not delete messages that have already been delivered to a device. A WhatsApp, SMS, or email message that has reached a phone or a mailbox remains there until the recipient deletes it, and messages held by the messaging provider are subject to that provider's own retention. A copy held by the hotel outside the platform is subject to the hotel's own arrangements.
9. Contact
Deletion requests and questions about this page: support@deemora.co.