Guest requests (GDPR) - erasure and data export
What it is
The Guest requests screen in the website administration. You find a specific guest and either download a complete copy of their personal data or erase that data.
It is part of every plan, including Basic. This is not an extra feature - it is a legal obligation every accommodation provider has to meet, regardless of how much they pay for software.
What it is for
Under GDPR a guest may request a copy of the data you hold about them (Articles 15 and 20) and its deletion (Article 17). You have 30 days to respond.
Important: the property handles the request, not Ubytora. You are the controller of guest data; Ubytora is only the processor providing you with the tool. If a guest writes to us, we redirect them to you.
First, verify who is asking
The system cannot do this for you. Anyone can write from someone else's e-mail address - and without verification you would erase another person's data, or hand their personal data to a stranger. Both are breaches in themselves.
Verification is your responsibility as the controller. In practice it is enough that the request comes from the e-mail used on the reservation, or that the guest provides details you can check against it (stay dates, reservation code).
The scope is ONE property
You will find data held by your property here, not by the whole Ubytora platform. If the same guest also booked with another accommodation provider, they will not know about this request - they are a separate controller and the guest has to contact them directly.
Tell the guest this. Otherwise they leave believing their data disappeared "everywhere".
How to handle a request
- Open Guest requests in the left menu.
- Enter the guest e-mail or name (at least 3 characters) and click Find.
- Click View data next to the guest you found. You will see everything the system holds about them - before anything is changed.
- Depending on what the guest asked for:
- Download data copy (JSON) - downloads a file to send to the guest as an attachment;
- Erase guest data - opens a confirmation; the erasure runs only after that.
The guest list is deliberately not shown when the screen opens. This is a tool for handling one specific request, not a contact listing.
What the data copy contains
A JSON file with the guest profile, their reservations, guest register entries, reviews, waiting list entries, e-mail campaign records and sent text messages.
The photo of the identity document is not returned as a file - only the information whether one exists. Those photos are automatically deleted after 90 days anyway.
Erasure is anonymisation, not row deletion
This is the most common misunderstanding, so let us be precise.
A reservation carries two things at once: the guest's personal data (name, e-mail, phone) and an economic fact (on date X the room was occupied for Y €). If the whole row were deleted, your revenue and occupancy figures would change retroactively and stop matching your filed tax return.
So the personal data is overwritten permanently and the record of the reservation stays. The name becomes "Zmazaný hosť" (deleted guest), the e-mail becomes a non-existent address, the phone and notes are cleared. Such a record can no longer be linked to a specific person, so under GDPR (Recital 26) it is no longer personal data - the guest's request has been fulfilled.
Data that carries no accounting or statistical record - for example a waiting list entry or a sent text message - is deleted in full.
What erasure does NOT include (tell the guest up front)
The screen shows these categories in the This stays - and why panel before you confirm. This is not an excuse, these are legal obligations:
| What stays | Why | For how long |
|---|---|---|
| Guest register (name, date of birth, address, document number) | Acts 253/1998 and 404/2011 Coll. | 5 years, then deleted automatically |
| Issued invoices and receipts | Act 431/2002 Coll. on accounting | 10 years |
| Dates, room and amount on the reservation | no longer personal data once the name is removed | permanently |
| The record that the guest unsubscribed from offers | without it campaigns would start reaching them again | permanently |
If you promise the guest that "everything" will be erased, you promise something you cannot deliver.
Erasure cannot be undone
That is why it is confirmed in a second step. After confirming you will see a summary of what the erasure actually touched - that is also what you can confirm back to the guest.
If the guest books with you again, a new profile is created. That is not a bug - it follows from the fact that they gave you their data once more.
Everything is written to the Audit log
Every export and every erasure is recorded in your Audit log - who, when and which guest it concerned. This lets you prove during an inspection that the request was handled and when.
Retention periods run without any request
You do not have to wait for anything or trigger anything. Every day the system anonymises guest data 3 years after the stay ends, deletes guest register entries after 5 years, document photos after 90 days, records of sent text messages after 12 months, resolved support requests 3 years after they were closed, and unused waiting list entries 30 days after the requested date. The tool on this page lets you do the same thing earlier and for one specific guest, when they ask.
Who has access
The account owner and the Manager. Reception and the other roles do not - erasure is irreversible and it is an act of the controller, not of daily operations. More in Team members and roles.
Common problems
I cannot find the guest. Try the exact e-mail they used when booking. If they booked with a different address than the one they are writing from, search by name.
The guest is labelled "already anonymised". Their data has already been removed - either by an earlier request or automatically once the retention period expired. Nothing further is needed.
The Erase guest data button is inactive. Either the guest is already anonymised, or your subscription is paused. You can still download the data copy - the guest's right of access does not depend on your subscription.
The guest asks for erasure but has an unpaid reservation with us. Erasure does not cancel the debt - the invoice and the reservation record both stay. Consider handling the request after the matter is settled; the right to erasure does not cover data needed to establish or defend legal claims.
I am afraid this will break my accounting. It will not. Erasure does not touch issued documents or any amounts - see the table above.