As a Property Manager using OnSeason, you're responsible for handling guest data with care. OnSeason gives you the tools to comply with GDPR (General Data Protection Regulation — the EU law governing personal data) and respect your guests' data rights.

#### **Your Responsibilities**

When guests book through your booking engine, you are the data controller — you decide how and why their personal data is processed. OnSeason acts as a data processor on your behalf, storing and managing the data according to your instructions.

#### **This means:**

You must respond to guest data requests within the legally required timeframe (typically 30 days under GDPR)

You are responsible for having a lawful basis for processing guest data (booking fulfillment is a valid basis)

You should be able to explain to guests what data you hold and why

GDPR applies to all guests in the EU/EEA, regardless of where your business is based. If you accept bookings from European guests, these rules apply to you.

#### **Exporting Guest Data**

If a guest asks what data you hold about them (Right of Access) or wants a copy of their data (Data Portability), you can export everything in a few clicks.

- **Open the guest's profile —** Go to Bookings \> Guests and click on the guest who made the request.

- **Find Data Management —** Scroll to the "Data Management" section at the bottom of their profile.

- **Export their data —** Click "Export Guest Data" — a JSON file downloads automatically.

The exported file contains all data OnSeason holds about the guest: personal details, booking history, messages, internal notes, and marketing preferences.

The exported file includes a timestamp and the guest's name in the filename for your records. Store exported data securely and share it with the guest via a secure channel.

#### **Deleting Guest Data**

If a guest requests that their data be erased (Right to Erasure), OnSeason lets you permanently delete their personal information.

- **Open the guest's profile —** Go to Bookings \> Guests and click on the guest who made the request.

- **Find Data Management —** Scroll to the "Data Management" section.

- **Click Delete Guest Data —** Click "Delete Guest Data" to open the confirmation dialog.

- **Review what will be deleted —** Read the confirmation dialog carefully — it explains exactly what will be removed.

- **Confirm by typing DELETE —** Type DELETE in the confirmation field to prevent accidental deletions.

- **Permanently delete —** Click "Permanently Delete" — this action cannot be undone.

#### **What Gets Deleted**

When you delete a guest's data, the following is permanently removed: personal information (name, email, phone number), all messages sent to the guest, all internal notes about the guest, and marketing preferences.

- **Booking records are anonymized —** the reservation data stays in your system for financial records, but all personal identifiers are removed. You can still see that a booking happened (dates, property, amount) but not who made it.

Deleting guest data is permanent and cannot be undone. Booking records will be anonymized but not deleted, as they are needed for financial reporting and tax compliance.

#### **Who Can Delete Guest Data**

Only Admins and Owners can permanently delete guest data. Members and Viewers cannot access the delete function. This restriction prevents accidental data loss.

#### **Best Practices**

- **Export before deleting —** download the guest's data before deletion, in case you need records for legal or tax purposes

Keep a log of data requests and your responses for compliance auditing

- **Respond promptly —** GDPR requires action within 30 days of receiving a request

- **Review your retention policy —** consider how long you keep guest data after their last booking and document your decision