Legal
Privacy Policy
Effective: 27 August 2026
This policy explains how personal data is handled in Deemora Concierge, the hotel guest-service platform operated by Deemora. It is written for the Concierge service specifically. Deemora also operates a separate experiences marketplace at deemora.co, which has its own policy; this policy does not describe that service.
1. Scope
This policy applies to Deemora Concierge — the platform hotels use to receive, route, and resolve guest service requests, together with the communication and coordination features that support it. It covers hotel guests whose requests are handled through the platform, hotel staff and management who use it, and service providers who receive work through it.
2. The hotel relationship
Deemora Concierge is provided to hotels. The hotel holds the direct relationship with its guests, decides which services it offers, and determines what guest information it collects in order to deliver them. Deemora operates the platform and, where the hotel has engaged it, provides concierge personnel and operational support. In practical terms this means the hotel is the primary party responsible for its guests' service data, and Deemora handles that data to run the service on the hotel's behalf and to operate and secure the platform itself.
3. Information handled
The categories of personal data handled through the platform are:
- Guest and request information — the guest name associated with a request, room number, a contact number or email address where one is provided, the details and notes of the request itself, and the guest's preferred language.
- Stay context — the stay a request belongs to, and the dates and status associated with it.
- Quotes and approvals — where a service requires a price, the quoted amount, its status, and the record of approval or decline.
- Payment-related information — the status of a payment and the reference issued by the payment provider. Deemora does not store full card numbers or card security codes.
- Communication records — messages sent to or received from a guest through the hotel's chosen channels, together with delivery and status information.
- Account information — for hotel staff, management, and service providers: name, work contact details, role, and sign-in and activity records.
- Technical and security records — network address, device and browser information, session data, and logs of significant actions taken in the platform.
4. Why data is handled
- To receive, route, and resolve guest service requests.
- To communicate with guests about their requests.
- To coordinate with service providers where a request requires one.
- To present quotes and record approvals where a service is chargeable.
- To support payment and, where applicable, refund processes operated on the hotel's payment gateway.
- To give hotel management visibility of service performance and accountability.
- To operate, secure, support, and improve the platform, and to investigate misuse.
- To meet legal and regulatory obligations.
5. Basis for handling personal data
Personal data is handled on one or more of the following bases, consistent with the Personal Data Protection Law of the Kingdom of Saudi Arabia and other applicable regulations:
- Performance of a contract, or steps taken at a person's request — for example, acting on a guest's service request.
- Compliance with a legal or regulatory obligation.
- Consent, where consent is the appropriate basis and has been given.
- Legitimate interests — operating and securing the service, preventing fraud and abuse, and resolving disputes.
6. Messaging channels
Guest messaging runs on channels chosen by the hotel — typically WhatsApp, SMS, or email. Two arrangements are supported, and which one applies depends on the hotel:
- The hotel's own accounts — the hotel owns its WhatsApp Business account and number, its SMS sender identity, or its email sending domain, and Deemora integrates them.
- A Deemora-operated account — where a hotel has engaged Deemora to provide the messaging account as a service, messages are sent through an account operated by Deemora on that hotel's behalf.
Messages about a guest's request normally identify the hotel, because the hotel is the guest's relationship. Where a message must identify Deemora — for example for a legal, payment, or operator-identification reason — it will do so clearly.
7. WhatsApp and Meta
Where WhatsApp is used, messages are delivered through the WhatsApp Business Platform provided by Meta. Meta acts as the communication infrastructure: to deliver a message, the recipient's phone number and the message content necessarily pass through Meta's systems, and Meta's own terms and privacy policies govern WhatsApp itself and the WhatsApp application on the guest's device. Deemora does not control Meta's processing of that data. Business-initiated messages use message templates that are reviewed and approved by Meta before they can be sent.
8. Sharing
Personal data may be shared in the following circumstances:
- With the hotel — the hotel receives the guest and request information needed to deliver its service and to manage its own operations.
- With service providers — where a request is fulfilled by a third-party provider, that provider receives what it needs to carry out the work, such as the request details and a means of coordination.
- With communication providers — the messaging platforms described above, in order to deliver messages.
- With payment providers — where a service is paid for, the payment provider receives what it needs to process the payment. Payments run on the hotel's own gateway and merchant account; Deemora is not the merchant of record.
- With technical service providers — the hosting, storage, email, and infrastructure providers used to run the platform, under obligations of confidentiality and security.
- With competent authorities — where required by a binding legal request, or to establish, exercise, or defend legal claims.
Personal data is not sold.
9. Processing outside the Kingdom
Some processing may take place outside the Kingdom of Saudi Arabia, because certain technical, communication, and payment providers operate internationally. Where that happens, it is done in a manner intended to maintain an appropriate level of protection and consistent with applicable requirements. This policy does not claim that all data remains within the Kingdom.
10. Security
Deemora applies organisational and technical measures appropriate to the service, including role-based access controls that limit staff to the hotel and the data their role requires, encryption of data in transit, restricted administrative access, and logging of significant actions so that they can be reviewed. No system can be guaranteed to be completely secure, and no such guarantee is made here.
11. Retention
Personal data is kept for as long as it is needed for the purpose it was collected for, and then for as long as a legitimate reason to keep it remains — in particular:
- Operational records are kept while the hotel's service is active and the record remains relevant to it.
- Records connected to payments, invoicing, or tax are kept for the period required by applicable accounting and regulatory obligations.
- Records relevant to an active dispute, investigation, or legal claim are kept until it is resolved.
- Security and audit records are kept for a period appropriate to their protective purpose.
When a record is no longer needed on any of these grounds, it is deleted or de-identified. Because retention periods depend on the obligation involved and on the hotel's own arrangements, this policy does not state a single fixed period.
12. Your rights
Subject to applicable law, and in particular the Personal Data Protection Law of the Kingdom of Saudi Arabia, you may have the right to:
- Ask what personal data is held about you and obtain access to it.
- Ask for inaccurate data to be corrected or completed.
- Ask for data to be deleted, where deletion is permitted.
- Ask for processing to be restricted or object to it, where that right applies.
- Withdraw consent, where handling is based on consent.
Identity, or ownership of the request the data relates to, may need to be verified before a request is acted on. Because much of the data is held to serve a hotel, a request may be coordinated with the hotel concerned, and you may also raise it with the hotel directly.
13. Deletion requests
Instructions for requesting deletion of personal data, including what information to provide, are published on the data deletion page.
14. Children
The platform is not directed at children, and personal data is not knowingly collected from a child without the involvement of a parent or guardian. Where a guest request concerns a minor, it is handled through the accompanying adult and the hotel.
15. Changes to this policy
This policy may be updated from time to time. The updated version takes effect when it is published on this page, and the effective date above is revised accordingly.
16. Contact
Questions about this policy, or requests concerning personal data, can be sent to support@deemora.co. Please do not include passwords, one-time codes, card numbers, or other credentials in your message.