Skip to main content

Security & Compliance

Your guests' data, treated like a guest

GRAND is hosted in the EU and GDPR-ready from day one. Card payments are handled by Adyen, so card data never touches our systems. And we're working toward SOC 2 and ISO 27001 certification, expected end of 2026.

Book a demo

Security that's table stakes, not a feature

The boring fundamentals, done properly, so you never have to think about them.

Hosted in the EU.

Your data is stored and processed inside the European Union, under European law. GDPR isn't an add-on: it's how GRAND was built from day one.

Encrypted, everywhere.

Data is encrypted in transit and at rest. Access inside GRAND follows role-based permissions, so your team sees exactly what their job needs, no more.

Payments by Adyen.

Every card payment runs through Adyen, a PCI DSS Level 1 certified provider. Card data never touches GRAND's systems, the strictest compliance burden stays where it belongs.

Certifications underway.

We're working toward SOC 2 Type 1 and Type 2 and ISO 27001, expected end of 2026, independent auditors verifying what we already practise.

Certifications

Audited by outsiders, not by ourselves

We're on the road to SOC 2, Type 1 and Type 2, and ISO 27001, with both expected end of 2026. The controls they certify aren't waiting for the audit: they're already part of how we build and run GRAND today.

  • SOC 2 Type 1 and Type 2 in progress
  • ISO 27001 in progress
  • Both expected end of 2026

Payments & PCI DSS

Card data that never touches us

Payments in GRAND run on Adyen, the same provider trusted by the world's biggest brands, certified PCI DSS Level 1. Card numbers travel directly from your guest to Adyen, so the heaviest compliance burden in hospitality never lands on you or on us.

  • Card data never touches GRAND's systems
  • Processed by Adyen: PCI DSS Level 1
  • Payments land on the right bill automatically

Data protection & GDPR

Your guests' rights, handled in the product

GDPR isn't a policy document in a drawer, it's built into GRAND. Guest data lives in the EU, a data processing agreement is available for every customer, and exporting or deleting a guest's data is something you can actually do.

  • Hosted in the EU
  • Data processing agreement available
  • Export or delete guest data on request
Read our privacy policy

Got a question?

Where is my data hosted?

In the EU. Your property's data, guests, bookings, invoices, is stored and processed inside the European Union, under European law.

Are you SOC 2 or ISO 27001 certified?

Not yet, both are in progress. We are working toward SOC 2 Type 1 and Type 2 and ISO 27001, expected end of 2026. The controls behind them are already part of how we run. Ask us for a status update anytime.

How are card payments secured?

Every card payment runs through Adyen, a PCI DSS Level 1 certified payment provider. Card numbers go straight from your guest to Adyen, they are never stored on or transmitted through GRAND's systems.

Are you GDPR compliant, do you offer a DPA?

Yes. GRAND is built GDPR-ready: EU hosting, guest-data rights handled in the product, and a data processing agreement available for every customer.

Get a glimpse of the future

We help you do more across all hospitality operations, delivering excellence in every guest interaction.

Book a demo