Skip to content
Vedom home

Security & privacy

Designed so the careful choice is the default.

Vedom will hold your guests’ preferences and your team’s working days. It is in build, and it is being designed so that you rarely need a setting to be safe. This page says what is decided, and what we don’t claim yet.

EU data residency by default.

Your hotel’s data will be stored and processed in the EU by default, including AI processing.

  • Database hosted in Frankfurt
  • Files stored in the EU
  • AI processing on Google Cloud’s EU region, with Claude models
  • Every subprocessor named in your contract, with where it processes data

We will be your processor under GDPR.

Your hotel decides what goes into Vedom and why. We will act only on your instructions, under a data processing agreement (Art. 28 GDPR) that is part of every contract, pilots included.

  • Export and erasure per guest and per staff member
  • Retention periods on by default
  • Audit log for sensitive reads and every permission change
  • 30 days’ notice before a subprocessor is added or replaced

Health and allergy data, handled with care.

Allergies and dietary needs are special-category data (Art. 9 GDPR). Vedom treats them that way.

  • Stored as instructions (“no feathers in 412”), not diagnoses
  • Recorded only with the guest’s explicit consent
  • Visible only to the people who need them, and every read is logged
  • Never sent to an AI model: the fields are stripped before any AI request is built

No staff tracking.

Vedom helps people do the work. It does not watch them.

  • No rankings or leaderboards; per-person performance reports are off by default
  • No location tracking
  • Our own product analytics never track individual staff members
  • A works-council pack (feature description and template works agreement) and a DPIA support pack, drafted and in review with counsel

AI assists. People decide.

The assistant answers with its sources, drafts and translates. It never makes decisions about people. It speaks to a guest only within the topics the hotel allows, through the Vedom Concierge, and only if the hotel switches that on.

  • No hiring, disciplinary or performance decisions by AI
  • Rota and dispatch follow clear rules you can read
  • Guest replies are drafted for a person to send; the Concierge answers alone only on allowed topics, says it is automated, and hands over to a person on request
  • Small, reversible actions run only under a standing approval and land in “review what the assistant did”, with Undo
  • Every AI request is logged per hotel

Security engineering.

Every hotel’s data is kept apart in the application and again in the database.

  • Row-level security in the database, proven by automated isolation tests on every change
  • Encryption in transit and at rest
  • Least-privilege access for our team
  • PMS connections only through documented APIs, with credentials issued to us

What we don’t claim.

Vedom is in build and nobody uses it in a hotel yet. We don’t hold a security certification yet, and we don’t call Vedom “EU-only” until every provider has been checked. An independent penetration test comes before our first paying customer.

This website.

No cookies, no trackers, no requests to third parties. Fonts are served from our own domain. The sign-up form asks for your email only, and nothing happens until you confirm it; our privacy policy names every provider involved. If we add analytics, it stays off until you agree.

Security or privacy question? Write to hello@opmise.com

Put your hotel forward.

Ten founding places for hotels on Apaleo. One email field, and you confirm it before anything else happens. The founder reads every application; yes means a 20-minute call about your hardest morning.