Russian hosting, multi-tenant isolation and consent flows built into authorisation — not bolted on afterwards.
Architecture and Data Protection by Design
Where guest and resident data is stored
The platform runs on Russian hosting infrastructure and meets the requirements of Federal Law 152-FZ on personal data. Every operator works inside an isolated tenant, so service apartment data from one property never crosses paths with another. The processing of guest and resident personal data in aparthotel contexts is documented at contract level — operator and processor roles are defined explicitly.
- Hosting jurisdiction: Russian data centres, no cross-border transfers
- Tenant model: multi-tenant SaaS with strict logical isolation per organisation
- Regulatory basis: 152-FZ compliant SaaS for hospitality operators
- Audit posture: documented controller and processor roles per organisation
Consent built into the workflow
Consent to process personal data is part of every authorisation flow — the Telegram bot, the web chat, and the resident onboarding code. A resident receives an access code from reception at check-in and activates their account before any request is recorded. No silent data collection, no manual paperwork on the desk.
- Bot and web chat: explicit consent step before the first message is processed
- Resident activation: code-based onboarding with logged confirmation
- Knowledge base scope: the assistant answers strictly from your documents, never invents facts