Security & Compliance
Your guests' data, treated like a guest
GRAND is hosted in the EU and GDPR-ready from day one. Card payments are handled by Adyen, so card data never touches our systems. And we're working toward SOC 2 and ISO 27001 certification, expected end of 2026.
Book a demoSecurity that's table stakes, not a feature
The boring fundamentals, done properly, so you never have to think about them.
Your data is stored and processed inside the European Union, under European law. GDPR isn't an add-on: it's how GRAND was built from day one.
Data is encrypted in transit and at rest. Access inside GRAND follows role-based permissions, so your team sees exactly what their job needs, no more.
Every card payment runs through Adyen, a PCI DSS Level 1 certified provider. Card data never touches GRAND's systems, the strictest compliance burden stays where it belongs.
We're working toward SOC 2 Type 1 and Type 2 and ISO 27001, expected end of 2026, independent auditors verifying what we already practise.
Certifications
Audited by outsiders, not by ourselves
We're on the road to SOC 2, Type 1 and Type 2, and ISO 27001, with both expected end of 2026. The controls they certify aren't waiting for the audit: they're already part of how we build and run GRAND today.
- SOC 2 Type 1 and Type 2 in progress
- ISO 27001 in progress
- Both expected end of 2026
Payments & PCI DSS
Card data that never touches us
Payments in GRAND run on Adyen, the same provider trusted by the world's biggest brands, certified PCI DSS Level 1. Card numbers travel directly from your guest to Adyen, so the heaviest compliance burden in hospitality never lands on you or on us.
- Card data never touches GRAND's systems
- Processed by Adyen: PCI DSS Level 1
- Payments land on the right bill automatically
Data protection & GDPR
Your guests' rights, handled in the product
GDPR isn't a policy document in a drawer, it's built into GRAND. Guest data lives in the EU, a data processing agreement is available for every customer, and exporting or deleting a guest's data is something you can actually do.
- Hosted in the EU
- Data processing agreement available
- Export or delete guest data on request
Got a question?
Where is my data hosted?
In the EU. Your property's data, guests, bookings, invoices, is stored and processed inside the European Union, under European law.
Are you SOC 2 or ISO 27001 certified?
Not yet, both are in progress. We are working toward SOC 2 Type 1 and Type 2 and ISO 27001, expected end of 2026. The controls behind them are already part of how we run. Ask us for a status update anytime.
How are card payments secured?
Every card payment runs through Adyen, a PCI DSS Level 1 certified payment provider. Card numbers go straight from your guest to Adyen, they are never stored on or transmitted through GRAND's systems.
Are you GDPR compliant, do you offer a DPA?
Yes. GRAND is built GDPR-ready: EU hosting, guest-data rights handled in the product, and a data processing agreement available for every customer.
Get a glimpse of the future
We help you do more across all hospitality operations, delivering excellence in every guest interaction.
Book a demo