Privacy Policy
Last updated: 23 July 2026
This Privacy Policy explains how personal data is processed when you:
- join or use a membership powered by Regulars;
- purchase a product through the Regulars checkout;
- use a digital membership card;
- interact with the Regulars website or platform;
- contact Regulars;
- represent a hospitality brand using Regulars; or
- otherwise interact with our services.
It also explains the different responsibilities of the hospitality brand and Regulars.
1. Who we are
The Regulars platform is operated by:
Regulars ApS
CVR no. 43492462
Mindebrogade 3, 3rd floor
8000 Aarhus C
Denmark
Email: [email protected]
In this Privacy Policy, we refer to the company as “Regulars,” “we,” “us” or “our.”
2. Who is responsible for your personal data?
Responsibility depends on why your personal data is processed.
2.1 The Hospitality Brand as data controller
When you join a membership, collect rewards or interact with a hospitality brand, that hospitality brand will generally act as the data controller.
The Hospitality Brand determines why and how personal data is used for:
- membership administration;
- stamps, points and rewards;
- discounts and vouchers;
- membership tiers;
- referrals;
- guest segmentation;
- guest communication;
- the Hospitality Brand’s marketing;
- analysis of its guest relationships; and
- its products, locations and services.
The Hospitality Brand’s legal name and contact details must be shown on the membership page, registration form, digital membership card or related privacy notice.
Questions about the Hospitality Brand’s use of personal data should normally be directed to the Hospitality Brand.
2.2 Regulars as data processor
Regulars generally acts as a data processor when we process personal data on behalf of a Hospitality Brand.
This includes providing the technology used to:
- create and host memberships;
- issue and update digital membership cards;
- record stamps, points, visits and rewards;
- manage vouchers and membership benefits;
- send communications on the Hospitality Brand’s instructions;
- connect the membership with supported systems;
- provide reporting and analytics;
- provide technical support; and
- maintain the platform.
When Regulars acts as a processor, the Hospitality Brand remains responsible for:
- selecting a lawful purpose;
- identifying an appropriate legal basis;
- providing required privacy information;
- handling data-subject requests;
- obtaining any required consent;
- ensuring marketing is lawful;
- determining retention periods; and
- ensuring its membership programme complies with applicable law.
Regulars processes the data under a data processing agreement and the Hospitality Brand’s documented instructions.
2.3 Regulars as independent data controller
Regulars acts as an independent data controller when we determine the purpose and essential means of processing.
This includes processing for:
- the Regulars checkout;
- the Guest Service Fee;
- payment and transaction administration;
- accounting and financial documentation;
- fraud prevention;
- platform and network security;
- service monitoring;
- direct support requests to Regulars;
- managing Hospitality Brand accounts;
- billing and commercial relationships;
- protecting and enforcing legal rights;
- complying with legal obligations;
- developing and improving the Regulars platform; and
- operating the Regulars website.
For these activities, Regulars is responsible for complying with applicable data-protection requirements.
2.4 Independent third parties
Certain third parties may process personal data as independent controllers under their own privacy policies.
These may include:
- payment providers;
- banks and card issuers;
- Apple Wallet;
- Google Wallet;
- reservation providers;
- point-of-sale providers;
- marketing platforms;
- delivery platforms; and
- other services selected by you or the Hospitality Brand.
Regulars doesn’t control how an independent third party processes personal data for its own purposes.
3. Scope of this Privacy Policy
This Privacy Policy covers processing performed by Regulars.
It also provides a general explanation of how the Hospitality Brand may use the Regulars platform.
It doesn’t replace the Hospitality Brand’s own privacy notice.
Where a Hospitality Brand determines why and how your personal data is processed, its privacy notice applies to that processing.
Where Regulars acts as an independent controller, this Privacy Policy applies.
4. Personal data we may process
The personal data we process depends on how you interact with Regulars and the Hospitality Brand.
4.1 Identification information
This may include:
- name;
- membership number;
- internal user or account ID;
- profile picture, where offered;
- date of birth, where relevant;
- age or age range; and
- other identifiers required for a specific membership.
4.2 Contact information
This may include:
- email address;
- telephone number;
- postal address, where required;
- business contact information; and
- communication preferences.
4.3 Membership information
This may include:
- Hospitality Brand memberships;
- membership status;
- joining date;
- participating location;
- membership tier;
- stamps;
- points;
- vouchers;
- rewards;
- discounts;
- referrals;
- prepaid balances;
- subscription status;
- benefit eligibility; and
- redemption history.
4.4 Transaction and activity information
This may include:
- visit dates;
- participating locations;
- Qualifying Purchases;
- transaction amounts;
- purchased products or product categories;
- stamps or points earned;
- vouchers issued or redeemed;
- rewards earned or redeemed;
- refunds;
- cancellations;
- chargebacks;
- subscription payments; and
- other membership activity.
Regulars may receive detailed product information where it is provided through a connected system.
In other cases, Regulars may receive only the information required to record the relevant membership activity.
4.5 Purchase and checkout information
When you make a purchase through Regulars, we may process:
- the product purchased;
- the Hospitality Brand;
- the Brand Price;
- the Guest Service Fee;
- the Total Price;
- currency;
- payment status;
- payment-provider references;
- refund information;
- subscription frequency;
- billing status;
- purchase date;
- Order Confirmation details; and
- information required to manage the purchase.
Payment-card numbers and security codes are generally collected directly by the payment provider.
Regulars doesn’t normally receive or store your complete payment-card number or security code.
4.6 Wallet and device information
This may include:
- digital pass identifiers;
- wallet type;
- device or pass tokens;
- card installation status;
- card update information;
- operating system;
- browser type;
- language;
- device type;
- IP address;
- request timestamps; and
- technical diagnostic information.
This information may be required to issue, update, secure and troubleshoot digital membership cards.
4.7 Communications
We may process information contained in:
- support requests;
- emails;
- contact forms;
- meeting notes;
- complaints;
- feedback;
- surveys;
- sales conversations; and
- other communications with Regulars.
4.8 Hospitality Brand information
If you represent a Hospitality Brand, we may process:
- your name;
- work email;
- work telephone number;
- job title;
- company;
- account permissions;
- login information;
- platform activity;
- commercial correspondence;
- billing contacts;
- training participation;
- support history; and
- actions taken within the platform.
4.9 Marketing and consent information
This may include:
- whether consent was requested;
- consent wording;
- the date and method of consent;
- communication channels selected;
- withdrawals;
- objections;
- unsubscribe activity;
- suppression records; and
- evidence required to demonstrate compliance.
4.10 Security and compliance information
This may include:
- login records;
- access logs;
- security events;
- suspected fraud;
- unusual activity;
- dispute information;
- account restrictions;
- audit records;
- identity-verification information; and
- information required by law or a payment provider.
4.11 Sensitive personal data
Regulars doesn’t intentionally request special categories of personal data, such as information about health, political beliefs, religion or sexual orientation, through ordinary membership functionality.
You shouldn’t provide sensitive personal data unless it is necessary and you have been specifically asked to provide it through an appropriate and secure process.
If sensitive information is provided unexpectedly, it may be deleted, restricted or processed only where a valid legal basis applies.
5. How Regulars uses personal data as a controller
The sections below explain Regulars’ principal purposes and legal bases.
5.1 Checkout and purchase administration
Purpose
To:
- provide the checkout;
- create and administer Orders;
- calculate and collect the Guest Service Fee;
- issue Order Confirmations;
- administer subscriptions;
- facilitate refunds;
- communicate about purchases; and
- resolve transaction issues.
Legal basis
Processing is generally necessary to perform a contract or take steps requested before entering into a contract, under GDPR Article 6(1)(b).
5.2 Payment administration
Purpose
To:
- facilitate payments;
- connect transactions with the Hospitality Brand;
- reconcile payments;
- manage failed payments;
- facilitate refunds;
- address payment disputes; and
- maintain transaction records.
Legal basis
Processing is generally based on:
- performance of a contract, GDPR Article 6(1)(b);
- compliance with legal obligations, GDPR Article 6(1)(c); and
- our legitimate interests in administering payments and preventing financial loss, GDPR Article 6(1)(f).
5.3 Accounting and tax compliance
Purpose
To:
- maintain accounting records;
- document the Guest Service Fee;
- prepare financial reporting;
- comply with tax requirements;
- support audits; and
- respond to public authorities.
Legal basis
Processing is necessary to comply with legal obligations under GDPR Article 6(1)(c).
5.4 Fraud prevention and security
Purpose
To:
- detect fraud;
- prevent unauthorised access;
- investigate misuse;
- protect digital cards;
- secure accounts;
- monitor system integrity;
- prevent abuse of rewards;
- manage security incidents; and
- protect Guests, Hospitality Brands and Regulars.
Legal basis
Processing is based on our legitimate interests in protecting the platform, users, transactions and business under GDPR Article 6(1)(f).
Where processing is required by law, GDPR Article 6(1)(c) may also apply.
5.5 Customer support
Purpose
To:
- respond to questions;
- resolve technical problems;
- investigate complaints;
- correct platform errors;
- administer requests; and
- improve support.
Legal basis
Processing may be based on:
- performance of a contract, GDPR Article 6(1)(b);
- our legitimate interests in providing support and resolving issues, GDPR Article 6(1)(f); or
- compliance with legal obligations, GDPR Article 6(1)(c).
5.6 Hospitality Brand accounts
Purpose
To:
- create and manage business accounts;
- administer access and permissions;
- deliver platform services;
- provide onboarding and training;
- provide reports;
- manage subscriptions and billing;
- communicate about the service; and
- enforce the Subscription Agreement.
Legal basis
Processing may be based on:
- performance of a contract, GDPR Article 6(1)(b), where the individual is a contracting party;
- our legitimate interests in fulfilling a business relationship, GDPR Article 6(1)(f); and
- compliance with legal obligations, GDPR Article 6(1)(c).
Our legitimate interest is to communicate with the employees and representatives needed to deliver and administer the service.
5.7 Product development and service improvement
Purpose
To:
- understand how the platform is used;
- identify errors;
- improve user experience;
- improve performance;
- develop functionality;
- understand aggregate membership patterns;
- conduct internal analysis; and
- maintain service quality.
Legal basis
Processing is based on our legitimate interests in operating and improving the Regulars platform under GDPR Article 6(1)(f).
Where reasonably possible, we use aggregated, anonymised or pseudonymised information.
We don’t use this purpose to override the Hospitality Brand’s instructions where Regulars acts as a processor.
5.8 Business development
Purpose
To:
- respond to enquiries;
- manage prospective Hospitality Brands;
- arrange demonstrations;
- prepare proposals;
- develop business relationships;
- maintain sales records; and
- follow up on relevant business conversations.
Legal basis
Processing is based on:
- steps requested before entering into a contract, GDPR Article 6(1)(b); or
- our legitimate interests in developing and operating our business, GDPR Article 6(1)(f).
5.9 Direct marketing by Regulars
Purpose
To send information about Regulars to relevant business contacts.
Legal basis
The legal basis depends on the communication, recipient and applicable marketing rules.
It may include:
- consent under GDPR Article 6(1)(a); or
- legitimate interests under GDPR Article 6(1)(f), where permitted.
Where electronic marketing requires consent under applicable marketing law, Regulars will obtain the required consent unless a lawful exception applies.
You may object to direct marketing at any time.
5.10 Legal claims and compliance
Purpose
To:
- establish legal rights;
- enforce agreements;
- defend legal claims;
- handle disputes;
- respond to authorities;
- comply with court orders;
- comply with legal obligations; and
- document compliance.
Legal basis
Processing may be based on:
- compliance with legal obligations, GDPR Article 6(1)(c); and
- our legitimate interests in protecting and enforcing legal rights, GDPR Article 6(1)(f).
6. Processing for Hospitality Brands
When Regulars acts as a processor, the Hospitality Brand determines the purpose and legal basis.
Typical membership processing may include:
- creating the membership;
- issuing the membership card;
- recording visits and purchases;
- calculating stamps or points;
- issuing rewards;
- managing membership tiers;
- administering referrals;
- sending service messages;
- analysing membership performance;
- segmenting Guests;
- sending marketing where lawful; and
- integrating membership data with other systems.
Depending on the activity, the Hospitality Brand may rely on:
- performance of a contract;
- consent;
- legitimate interests;
- compliance with a legal obligation; or
- another applicable legal basis.
The Hospitality Brand is responsible for explaining its legal bases in its own privacy notice.
Regulars doesn’t independently authorise the Hospitality Brand to use personal data for any purpose.
7. Guest segmentation and profiling
The Regulars platform may allow a Hospitality Brand to group or segment Guests based on information such as:
- time since the last visit;
- visit frequency;
- purchase frequency;
- spending;
- stamps or points;
- membership tier;
- voucher usage;
- reward activity;
- subscription status;
- preferred location; and
- engagement with the membership.
This may constitute profiling under the GDPR.
Where Regulars performs this processing on behalf of a Hospitality Brand, the Hospitality Brand is responsible for:
- selecting a lawful basis;
- providing clear information;
- respecting objections;
- obtaining consent where required;
- preventing unfair discrimination; and
- ensuring that the profiling is proportionate.
You have an absolute right to object to profiling used for direct marketing.
8. Automated decision-making
Regulars doesn’t ordinarily make decisions about Guests based solely on automated processing that produce legal effects or similarly significant effects.
Automated tools may assist with:
- segmentation;
- fraud detection;
- security monitoring;
- reward calculation;
- account-risk indicators; and
- operational recommendations.
These tools don’t normally make legally or similarly significant decisions without human involvement.
If Regulars introduces solely automated decision-making that has legal or similarly significant effects, we will provide the information and safeguards required by law.
9. Marketing communications
Marketing is separate from ordinary membership administration.
Joining a membership doesn’t automatically mean that you have consented to marketing.
A Hospitality Brand must independently ensure that it has permission to send marketing through channels such as:
- email;
- SMS;
- push notifications;
- digital wallet messages; and
- other electronic communications.
Marketing consent must be freely given, specific, informed and unambiguous where consent is required.
You may withdraw consent or object to direct marketing at any time.
Withdrawing marketing consent doesn’t automatically:
- end your membership;
- cancel a purchase;
- cancel a subscription;
- delete your membership data; or
- prevent necessary service messages.
Service messages may include:
- security notifications;
- payment information;
- subscription administration;
- material programme changes;
- balance corrections;
- expiry information;
- purchase confirmations; and
- responses to your requests.
10. Sources of personal data
We may receive personal data:
- directly from you;
- from the Hospitality Brand;
- from Hospitality Brand employees;
- from the Regulars platform;
- from a point-of-sale integration;
- from a reservation integration;
- from a marketing integration;
- from a payment provider;
- from a digital wallet provider;
- from your device or browser;
- from transaction or membership activity;
- from publicly available business sources;
- from a business partner or referral; and
- from professional advisers or public authorities.
Where Regulars receives personal data from another source, the party providing the information is responsible for having a lawful basis to disclose it.
11. Required and optional information
Some information is required to provide a membership, purchase or platform service.
Required fields will normally be identified during registration or checkout.
If you don’t provide required information, it may not be possible to:
- create your membership;
- issue your digital card;
- process your purchase;
- administer a subscription;
- provide a requested benefit;
- verify your identity; or
- respond fully to your request.
Other information may be optional.
Examples may include:
- telephone number;
- date of birth;
- profile picture;
- additional profile information; and
- optional marketing preferences.
The Hospitality Brand must explain why optional information is requested.
12. Who receives personal data?
We may disclose personal data to the following recipients or categories of recipients.
12.1 The Hospitality Brand
The Hospitality Brand may access data relating to its own membership programme, Guests and purchases.
A Hospitality Brand isn’t permitted to access another Hospitality Brand’s Guest data through Regulars.
12.2 Regulars personnel
Authorised Regulars employees and contractors may access personal data where necessary for:
- support;
- platform operation;
- security;
- billing;
- compliance;
- development; and
- other authorised business purposes.
Access is limited according to role and need.
12.3 Service providers and subprocessors
We use service providers that support:
- cloud hosting;
- databases;
- security;
- system monitoring;
- email delivery;
- push and wallet delivery;
- customer support;
- payment processing;
- accounting;
- communication;
- analytics;
- software development; and
- business administration.
Where a provider acts as our processor or subprocessor, we require an appropriate data processing agreement.
Hospitality Brands can obtain information about Regulars’ current subprocessors through their contractual documentation or by contacting [email protected].
12.4 Payment providers
Payment providers may receive:
- contact information;
- transaction information;
- payment references;
- device information;
- fraud-prevention information; and
- other information required to process a payment.
Payment providers may act as independent controllers for parts of their processing.
12.5 Wallet and device providers
Apple, Google and other wallet providers may process information required to:
- add a digital card;
- store the card;
- display it;
- update it;
- secure the wallet; and
- operate their services.
Their processing is governed by their own terms and privacy policies.
12.6 Integrations selected by the Hospitality Brand
A Hospitality Brand may choose to connect Regulars with:
- a point-of-sale system;
- a reservation system;
- a marketing platform;
- an accounting system;
- an ordering platform;
- a payment system; or
- another business service.
The Hospitality Brand is responsible for ensuring that the connection and disclosure are lawful.
12.7 Professional advisers
We may disclose information to:
- lawyers;
- auditors;
- accountants;
- insurers;
- financial advisers; and
- other professional advisers.
Disclosure is limited to what is reasonably necessary.
12.8 Authorities and legal recipients
We may disclose personal data where required or permitted by law, including to:
- courts;
- law-enforcement authorities;
- tax authorities;
- supervisory authorities;
- regulators; and
- other public authorities.
12.9 Business transfers
Personal data may be disclosed as part of:
- an investment;
- merger;
- acquisition;
- reorganisation;
- financing;
- sale of assets; or
- transfer of the Regulars business.
The recipient may only use the information in accordance with applicable law and the purposes disclosed in this Privacy Policy, unless another lawful basis applies.
13. International transfers
Regulars aims to use providers located in the EU or EEA where reasonably appropriate.
Some service providers or their group companies may be located outside the EU or EEA, or may provide support from another country.
Where personal data is transferred outside the EU or EEA, we use an applicable legal transfer mechanism, which may include:
- an adequacy decision adopted by the European Commission;
- the European Commission’s Standard Contractual Clauses;
- Binding Corporate Rules;
- additional contractual, organisational or technical safeguards; or
- another transfer mechanism permitted by law.
Where required, we assess whether additional safeguards are necessary.
You may contact [email protected] for further information about the transfer safeguards relevant to Regulars’ processing.
Confidential or commercially sensitive information may be redacted from copies of contractual safeguards.
14. Data retention
We retain personal data only for as long as it is reasonably necessary for the relevant purpose or required by law.
The following are our standard retention periods or criteria.
14.1 Membership data processed for a Hospitality Brand
Regulars retains membership data according to:
- the Hospitality Brand’s instructions;
- the data processing agreement;
- the duration of the Hospitality Brand’s use of Regulars;
- the status of the membership;
- legal requirements; and
- valid requests from the Hospitality Brand.
When the Hospitality Brand’s agreement ends, data is returned, deleted or retained in accordance with the data processing agreement and applicable law.
Residual copies may remain temporarily in protected backups until they are overwritten through the ordinary backup cycle.
14.2 Checkout and financial records
Order, payment, Guest Service Fee and accounting records are normally retained for five years from the end of the relevant financial year, or longer where required by law or an unresolved legal matter.
14.3 Hospitality Brand account information
Business account and commercial relationship information is normally retained for the duration of the relationship and for up to 24 months afterwards.
Information may be retained longer where required for:
- accounting;
- security;
- disputes;
- legal claims; or
- another lawful purpose.
14.4 Support communications
Support correspondence is normally retained for up to 24 months after the matter is resolved.
It may be retained longer where necessary for an ongoing dispute, security matter or legal claim.
14.5 Security logs
Ordinary security and technical logs are normally retained for up to 12 months.
Relevant records may be retained longer where they concern:
- a security incident;
- fraud;
- misuse;
- a dispute;
- an investigation; or
- a legal claim.
14.6 Prospective Hospitality Brands
Sales and business-development information is normally retained for up to 24 months after the most recent meaningful interaction.
It may be deleted earlier if the contact objects or the information is no longer relevant.
14.7 Marketing consent and objections
Marketing preferences are retained while relevant.
Evidence of consent, withdrawal, objection or unsubscribe activity may be retained for up to five years after the relevant event where necessary to demonstrate compliance or defend legal claims.
A limited suppression record may be retained after an objection or unsubscribe request to ensure that further marketing isn’t sent.
14.8 Legal claims
Information relevant to a dispute or legal claim may be retained until:
- the matter has been resolved;
- the applicable limitation period has expired; and
- any related legal obligation has ended.
14.9 Anonymised information
Regulars may retain information that has been irreversibly anonymised.
Information that can no longer reasonably be linked to an identifiable person isn’t personal data and isn’t covered by this Privacy Policy.
15. Aggregated and anonymised information
We may create aggregated or anonymised information for:
- product analysis;
- service improvement;
- statistics;
- benchmarking;
- capacity planning;
- research;
- performance reporting; and
- understanding general hospitality trends.
We take steps designed to prevent an individual Guest from being identified from this information.
We may retain and use properly anonymised information without applying the personal-data retention periods in this Privacy Policy.
16. Cookies and tracking technologies
The public Regulars website doesn’t use cookies, advertising pixels or comparable technologies to track visitors for analytics or advertising.
We therefore don’t maintain a separate Cookie Policy.
Our hosting and security infrastructure may still process basic technical information required to:
- deliver the website;
- establish a network connection;
- prevent attacks;
- investigate errors; and
- maintain security.
This may include:
- IP address;
- browser information;
- request time;
- requested page;
- response status; and
- security events.
This processing is based on our legitimate interests in providing and securing the website.
If we introduce cookies or comparable non-essential tracking technologies, we will update our information and request consent where required before using them.
17. Your data-protection rights
Your rights depend on the circumstances and applicable law.
They may include the following.
17.1 Right to information
You have the right to receive clear information about how your personal data is processed.
17.2 Right of access
You may request confirmation of whether personal data about you is processed and obtain:
- access to the data;
- a copy;
- information about the purposes;
- categories of data;
- recipients;
- retention;
- sources; and
- applicable rights.
17.3 Right to rectification
You may request correction of inaccurate personal data and completion of incomplete information.
17.4 Right to erasure
You may request deletion of personal data where the legal conditions are met.
The right to erasure isn’t absolute.
Information may be retained where processing is necessary for:
- a legal obligation;
- accounting;
- fraud prevention;
- freedom of expression;
- public-interest purposes;
- legal claims; or
- another lawful exception.
17.5 Right to restriction
You may request that processing be restricted where:
- you dispute the accuracy of the information;
- the processing is unlawful and you oppose deletion;
- the information is needed for a legal claim; or
- you have objected and the assessment is pending.
17.6 Right to data portability
Where processing is automated and based on consent or a contract, you may have the right to receive personal data you provided in a structured, commonly used and machine-readable format.
Where technically feasible, you may request direct transfer to another controller.
This right doesn’t apply to all information, including all inferred or calculated data.
17.7 Right to object
You may object to processing based on legitimate interests for reasons relating to your particular situation.
Processing will stop unless the controller demonstrates compelling legitimate grounds or the processing is required for legal claims.
17.8 Absolute right to object to direct marketing
You may object to direct marketing at any time.
This includes profiling related to direct marketing.
Once you object, the relevant personal data may no longer be used for that marketing.
17.9 Right to withdraw consent
Where processing is based on consent, you may withdraw consent at any time.
Withdrawal doesn’t affect the lawfulness of processing performed before consent was withdrawn.
Withdrawing consent doesn’t prevent processing based on another valid legal basis.
17.10 Rights concerning automated decisions
You have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, except where an applicable legal exception and required safeguards apply.
17.11 Right to complain
You may complain to the competent data-protection authority.
In Denmark, the supervisory authority is:
The Danish Data Protection Agency
Carl Jacobsens Vej 35
2500 Valby
Denmark
You may also have the right to complain to the supervisory authority in the EU or EEA country where you live, work or believe an infringement occurred.
18. How to exercise your rights
18.1 Requests concerning a Hospitality Brand
If your request concerns:
- your membership;
- stamps or points;
- rewards;
- Hospitality Brand marketing;
- Hospitality Brand segmentation;
- purchase history used by the Hospitality Brand; or
- another Hospitality Brand purpose,
you should normally contact the Hospitality Brand directly.
Its contact information should appear on the membership page, card or registration confirmation.
Regulars will assist the Hospitality Brand where required under the data processing agreement.
18.2 Requests concerning Regulars
If your request concerns processing for which Regulars is the controller, contact: [email protected]
Please describe:
- who you are;
- your relationship with Regulars;
- the Hospitality Brand, where relevant;
- the email or telephone number connected with the service; and
- the right you wish to exercise.
18.3 Identity verification
We may request reasonable information to verify your identity before acting on a request.
We won’t request more information than reasonably necessary for verification.
18.4 Response time
We will respond without undue delay and normally within one month.
The period may be extended by up to two additional months where a request is complex or numerous.
If an extension is required, you will be informed within the initial one-month period.
18.5 Fees
Requests are generally handled without charge.
A reasonable fee may be charged, or a request may be refused, where it is manifestly unfounded or excessive, particularly because it is repetitive.
19. Data security
Regulars implements technical and organisational measures designed to protect personal data against:
- unauthorised access;
- unlawful processing;
- accidental loss;
- destruction;
- alteration;
- unauthorised disclosure; and
- misuse.
Measures may include:
- access controls;
- role-based permissions;
- authentication controls;
- encryption in transit;
- encryption at rest where appropriate;
- secure development practices;
- logging and monitoring;
- backups;
- vulnerability management;
- vendor assessment;
- incident-response procedures;
- confidentiality obligations; and
- employee training.
Security measures are reviewed according to the risks presented by the processing.
No online service can guarantee absolute security.
You are responsible for protecting:
- your device;
- your email account;
- your digital wallet;
- your management links;
- your passwords; and
- other access credentials.
20. Personal-data breaches
Where Regulars acts as a processor, we will inform the relevant Hospitality Brand of a personal-data breach without undue delay in accordance with the data processing agreement.
Where Regulars acts as a controller, we will:
- investigate the incident;
- take reasonable containment measures;
- document the breach;
- notify the competent authority where required; and
- inform affected individuals where required by law.
21. Children and young people
The Regulars platform may be used by Hospitality Brands offering memberships suitable for families or young people.
The Hospitality Brand is responsible for:
- setting appropriate age requirements;
- determining whether parental involvement is required;
- providing age-appropriate information;
- obtaining parental consent where legally required; and
- ensuring that marketing to children is lawful and appropriate.
Regulars doesn’t knowingly use children’s personal data for its own direct marketing.
If you believe that a child’s personal data has been processed unlawfully, contact the Hospitality Brand or [email protected].
22. We don’t sell personal data
Regulars doesn’t sell or rent personal data to third parties for their independent advertising purposes.
We may disclose data to service providers, Hospitality Brands and other recipients as described in this Privacy Policy.
23. Links and third-party services
Regulars may link to websites or services operated by third parties.
Their processing is governed by their own privacy policies.
Regulars isn’t responsible for the content, security or privacy practices of an independent third-party service.
24. Changes to this Privacy Policy
We may update this Privacy Policy to reflect:
- changes to our services;
- changes to our processing;
- changes in law;
- new integrations;
- new security practices;
- organisational changes; or
- clarification of existing information.
The updated version will show a new “Last updated” date.
Where a change materially affects how Regulars processes personal data as a controller, we will provide additional notice where reasonably appropriate or legally required.
A material new purpose won’t be applied retroactively without an appropriate legal basis and any required information or consent.
25. Relationship with other legal documents
This Privacy Policy should be read together with:
- the Subscription Agreement;
- the Data Processing Agreement;
- the Guest Terms of Service;
- the Membership Terms of Use;
- the Hospitality Brand’s privacy notice;
- the Hospitality Brand’s Programme Details; and
- any privacy information shown during checkout or registration.
If these documents conflict on a data-protection matter, mandatory data-protection law takes priority.
26. Contact
Questions about Regulars’ processing of personal data may be sent to:
Regulars ApS
CVR no. 43492462
Mindebrogade 3, 3rd floor
8000 Aarhus C
Denmark
Email: [email protected]
Questions about a specific membership, reward or Hospitality Brand marketing activity should normally be directed to the relevant Hospitality Brand.