Data responsibilities
Define which party controls each purpose, which providers process information and which system remains authoritative.
Security and data protection
FirstConnect is designed to coordinate hotel workflows while preserving guest choice, staff accountability and clearly defined responsibilities across connected providers.
The hotel and its providers must define processing purposes, notices, access and retention in the applicable arrangements. FirstConnect’s workflow can support guest choice and staff oversight, but configuration alone does not establish legal compliance.
Operating principles
These are design and configuration principles. The active controls and provider responsibilities for a hotel must be confirmed in its agreed implementation.
Define which party controls each purpose, which providers process information and which system remains authoritative.
Limit staff access according to role, property and operational responsibility.
Connect purpose-specific guest choices to eligible communication workflows.
Request and display only information needed for the approved hotel process.
Retain relevant submissions, approvals, status changes and exceptions according to the agreed policy.
Configure retention and deletion responsibilities according to contract, legal basis and property policy.
Document PMS, messaging, payment, infrastructure and support providers actually used for an implementation.
Establish operating routes for security events and applicable guest data requests.
Scope boundaries
Approval levels, access scope, communication eligibility and retention settings depend on property configuration.
Specific PMS, booking, messaging, payment and access connections are reviewed with the property before activation.
Operational queues and metrics shown on this site are examples, not live hotel records or achieved results.
Security architecture, hosting, backups, incident procedures and assurance evidence require internal verification before publication as technical commitments.
Available resources
A public DPA, subprocessor list, cookie policy, responsible-disclosure policy and dedicated security contact are not yet published. Request current materials during a pilot discussion.