Last updated: September 21, 2026
This Policy describes how Modular Systems LLC collects, uses, shares and retains personal data when operating its sites, products and services. We generally act as controller for Customer administration data and as processor or service provider under Customer instructions for guest data uploaded by the Customer.
1. Data we collect
- Customer and user data: name, role, company, email, phone, credentials, permissions and communications.
- Billing data: plan, invoices, payment status and transaction references. Full card data is processed by the payment processor.
- Operational and guest data managed by the Customer: reservations, contact details, stays, operational preferences, accounts and billing, depending on modules used.
- Technical data: IP address, device, browser, access logs, security events and feature usage.
2. Purposes
We use data to provide, configure, secure and improve services; authenticate users; process payments; provide support; meet legal obligations; prevent fraud and abuse; and communicate operational or contractual information.
3. Legal bases
Where the GDPR applies, we process data based on contract performance, legitimate interests, legal compliance or consent, as appropriate. For data processed on behalf of a Customer, the Customer determines the legal basis and instructions.
4. Providers and transfers
We share data only as necessary with infrastructure, hosting, security, communication, operational analytics, support and payment providers; advisers under confidentiality; or authorities when legally required. We may process data in the United States and other countries where providers operate, using required contractual safeguards.
5. Retention
We retain data during the service term and afterward as needed to comply with law, resolve disputes, maintain records and protect rights. Customer data is deleted or returned under the agreement and reasonable backup cycles unless legal retention is required.
6. Security
We use reasonable administrative, technical and organizational controls, including access control, logging, encryption where appropriate and vendor management. No system is completely infallible; we will provide incident notice as required.
7. Individual rights
Depending on jurisdiction, individuals may request access, correction, update, deletion, portability, restriction or objection; withdraw consent; and complain to a competent authority. Colombia’s Law 1581 of 2012 also provides rights to know, update, correct and, where appropriate, delete data or revoke authorization. Rights under applicable data protection law apply in the EEA and United Kingdom.
8. Guest-data requests
When Modular Systems processes data for a hotel, the guest should first direct a request to the hotel, which determines the processing. We will assist the Customer as required by contract and law.
9. Cookies and logs
We may use strictly necessary cookies for authentication, security and preferences. If we add non-essential technologies, we will provide legally required notices and controls.
10. Children
The services are offered to businesses and are not directed to children. Hotels may process data about minor guests where needed to provide accommodation and supported by an appropriate legal basis.
11. Changes and contact
We may update this Policy to reflect legal or service changes. We will publish the updated date and communicate material changes where appropriate. To exercise rights or ask questions, email info@modularsystems.com.co.