Trust · Security · Compliance
How Hostella protects your data.
We handle bookings, guest messages, payment records, and PMS credentials for villa operators across the EU and APAC. Here's everything our compliance teams want to know — published openly.
Sub-processors
Who we trust with your data
We publish every third-party service that processes customer data on our behalf. Sub-processor changes are announced 30 days in advance via this page and email to billing contacts.
Security controls
What we actually do
Encryption in transit
Always onTLS 1.3 enforced on all endpoints. HSTS preloaded with 2-year max-age. No mixed-content possible.
Encryption at rest
AES-256-GCMAES-256-GCM for all customer secrets (BYO API keys, PMS credentials such as Hostaway, webhook secrets). Database disk encryption via Supabase.
Access control
RBACRole-based permissions (owner, operator, admin, viewer) enforced at the route layer. Super-admin bypass requires platform-level credentials and is logged.
Audit logging
Actor-attributedWrite actions (reservation changes, settings updates, member access, platform-setting changes) are logged with actor identity and timestamp.
Backups
Provider-managedAutomated database backups managed by Supabase on dedicated infrastructure. Restore procedure documented in our incident-response runbook.
Secret management
Vault patternCustomer API keys (BYO Anthropic, PMS/Hostaway credentials) encrypted with AES-256-GCM using a derived key. The platform never logs raw secret values.
Vulnerability management
Recurring auditsRecurring multi-agent security audits of the full codebase (authorization, tenant isolation, injection, cost abuse), with confirmed findings fixed before release. Dependencies updated on a regular cadence.
Incident response
72h disclosureDocumented incident-response runbook covering triage, containment, eradication, and notification. Customer-impacting incidents are disclosed by email without undue delay, at most 72 hours after confirmation.
Data residency & GDPR
Your data, your jurisdiction.
Where your data lives
The primary database is hosted in Tokyo (APAC) and the application runs in Singapore — the regions closest to the villas we serve in Thailand, Bali, Vietnam and surrounding markets. Customer data is not replicated outside that region.
GDPR rights
- Right to access: request a full data export
- Right to erasure: account deletion within 30 days
- Right to portability: JSON + CSV export of all bookings, conversations, properties
- Right to object: opt out of any non-essential processing
Documents & contact
Resources for your legal team
Data Processing Agreement (DPA)
Standard EU SCCs · GDPR Article 28 compliant · countersigned copy available on request.
Page last reviewed: 2026-08-03 · For changes to sub-processor list, watch this page or email contact@hostellagent.com.