Home

Privacy policy

How personal information is used for website enquiries, customer relationships and the hotel integrations provided by LevelConnect.

Last updated:

1. Scope and roles

This policy concerns the website and contracted services of Level Hospitality SAS, operating under the LevelConnect brand, within the framework of Colombian Law 1581 of 2012 and applicable regulations. Privacy enquiries and requests may be sent to support@levelconnect.co.

For website enquiries and its own customer administration, Level Hospitality SAS determines the purposes of processing and acts as controller. For guest information processed on an accommodation provider’s documented instructions, the accommodation provider is the controller and Level Hospitality SAS acts as processor. Authorities and other recipients may have independent duties and policies for data they receive.

2. Information and purposes

Website enquiries include the name, business email, company and message you submit. We use them to respond, prepare requested proposals and follow up on your enquiry. Technical records may include IP address, request details and mail delivery logs for security and troubleshooting. Please do not include guest identity documents or sensitive information in the public contact form.

Depending on the contracted integration, processing may include authorized user details, property identifiers, guest identification and contact details, nationality, stay dates, reservation and billing records, submission results and support communications. These are used to operate the agreed integration, reconcile records, investigate errors and support the customer, within its instructions and applicable legal requirements.

Information is not to be reused for unrelated advertising or sold. Any additional purpose requiring authorization must be explained and separately authorized before processing.

3. Authorization and special categories

Where authorization is required, it must be prior, informed and capable of being evidenced. A privacy notice or use of this website does not replace authorization required by law. The accommodation provider is responsible for the lawful collection of guest data and for instructing LevelConnect within that lawful scope.

Do not supply sensitive data unless strictly necessary and lawfully authorized or otherwise legally permitted. Answering questions about sensitive data is optional where the law so provides. Children’s data requires the applicable safeguards, respect for their best interests and fundamental rights, and intervention of their legal representative where required.

4. Recipients and international processing

Information may be communicated to the PMS or other integrations selected by the customer, to SIRE or TRA when reporting is enabled and legally appropriate, and to providers needed for hosting, communications or technical support. Access must be limited to the relevant purpose, with contractual confidentiality and data protection obligations where applicable. Disclosures may also be required by a competent authority.

If an arrangement involves processing outside Colombia, the applicable rules on international transmission or transfer must be met, including the required contractual safeguards, authorization or legal exception. Customers may request information about the providers and locations applicable to their contracted service; this policy does not authorize unrestricted international transfers.

5. Retention and security

Information should be kept only for the period necessary for the stated purpose, the service agreement, applicable retention obligations and the establishment or defence of legal claims. At the end of that period it must be deleted or anonymized as appropriate. Customer instructions, legally required records and backup lifecycles may affect the timing of deletion; an erasure request does not remove records held independently by an authority.

LevelConnect must adopt appropriate technical and organizational safeguards and restrict access to authorized purposes. No internet service can promise absolute security. Suspected incidents should be reported to support@levelconnect.co; applicable investigation and notification duties remain in force.

6. Cookies and external services

This website uses session functionality to remember the selected language and support request security. You can manage cookies in your browser, although disabling them may affect the contact form or language preference. External links lead to services governed by their own policies. Any optional tracking requiring consent must be disclosed and authorized before activation.

7. Your rights and how to exercise them

Subject to applicable law, you may access, know, update and correct your personal information, request evidence of authorization, ask how it has been used, and request deletion or revoke authorization when no legal or contractual duty requires retention. You may exercise these rights free of charge and complain to Colombia’s Superintendencia de Industria y Comercio after completing the applicable enquiry or complaint procedure.

Email support@levelconnect.co with your request, a reply address and sufficient information to identify the relevant relationship or records. We may request proportionate proof of identity or authority to protect your information. For guest records controlled by a hotel, contact that establishment; requests received by LevelConnect will be coordinated with the relevant controller.

Enquiries are answered within ten business days of receipt. If more time is needed, we will explain the reason before expiry and specify a response date no more than five additional business days later. Complete complaints are answered within fifteen business days from the day after receipt; a justified extension may not exceed eight additional business days, with prior notice. Incomplete complaints and referrals are handled under the applicable statutory procedure.

8. Policy updates

The date above identifies this policy version. Material changes will be communicated through an appropriate channel. New uses requiring authorization will not be based solely on publication of a revised policy. Processing remains subject to the applicable legal basis and the rights of data subjects.