All documents

Privacy notice

What data ATQAR processes, why it does so, how long it is retained, and how to make a request.

Published
Updated

Effective date: 3 August 2026.

This Notice describes how personal data is processed in connection with ATQAR, a web application for organising work in hotels and apartments.

1. Who processes data

The ATQAR service administration (the “Administration”) operates the Service and processes the data required for its operation and security.

The organisation that gave you access — your employer or customer — decides whom to add to the Service, what work to manage, and what information to enter. For that information, it acts as the controller and the Administration acts on its instructions.

If you have a question about why you can see particular data, contact the owner or an administrator of your organisation. Send questions about the Service itself through the help page.

2. What data is processed

Account. Sign-in name, display name, role, interface language, organisation membership, and whether a password change is required. Every active employee belongs to every property in the organisation; overview pages show them together. A password is stored only as an irreversible hash.

Passwordless Login. If you add passwordless login, the Service stores your device’s public key, the device name you provide, the date it was added, and the date of the last sign-in. The private part of the key remains on the device and is not available to the Administration.

Sessions. A session identifier in a secure cookie and creation and end times. Sessions are stored on the server, so access can be terminated immediately.

Work in the Service. Tasks, their states, assignments, deadlines, comments, described results, and blocker reasons. Every action is recorded in the history with who performed it and when.

Guests and stays. A guest record contains a display name, telephone number in E.164 format, an optional note, and a blocklist indicator with its reason and author. A stay record links the guest to a room, check-in and checkout dates, an optional external booking reference, cleaning settings, and the recorded facts of check-in and closure.

Photos and videos. If file uploads are enabled for your organisation, photographs and recordings may be attached to work results. They are stored in a private environment and are available only to people with access to the relevant task.

Telegram. If you connect Telegram, the Service stores the identifier of your bot chat and your alert preference. An outgoing alert may contain the exact current task title, up to 160 characters long; the description, comments, blocker reason, and guest name and contact details are not copied. Commands and text responses that you send to the bot yourself during a started workflow are processed by the Service and may become a task action or comment. The bot does not accept new photos or videos; they are uploaded only through the secure web application. Historical Telegram files remain in the previous private environment until deleted under the applicable rules. An incomplete workflow is stored temporarily until it is completed or expires. The bot has no access to other chats or conversations outside your dialogue with it.

Browser notifications (Web Push). If you allow notifications for this device, the Service stores the subscription for it: the delivery service address and the cryptographic keys required to send messages. The subscription is used only to deliver notifications about work that concerns you and is withdrawn at your choice.

Demo requests and support enquiries. The public form stores the message and exactly one contact method selected and submitted by you: an email address, telephone number, or Telegram username. This data is used for sales purposes: to respond to a request for an ATQAR demonstration, or to respond to a support enquiry. Do not enter passwords, guest data, or other information that is not needed for the response.

Demonstration access. If you opened the product from the website without registering, a separate temporary organisation with a fictional hotel is created for you. Everything you enter into it is stored only there and is not visible to other visitors. The accounts inside it are generated automatically; their passwords are issued to nobody and cannot be used — the only way in is the same button on the website. Do not enter real information about guests or employees into the demonstration: it exists to show the product, not to run a property on.

Technical data. IP address, request time, requested address, browser and operating-system information, response codes, and security-event records such as failed sign-in attempts.

3. What the Service does not do

The Administration does not use third-party advertising or web analytics systems. The Service does not track your location or build a behavioural profile outside work actions in the Service itself.

The Service is not a booking system. It keeps only a minimal guest directory for operational work. The Service does not store prices, payments, the number of occupants, or guests’ documents, addresses, email addresses, or correspondence.

Do not submit anything through comments, descriptions, or attached files that is not required for the work, including guest documents, payment details, passwords, or access codes.

4. Why data is processed

  • to let you sign in and to protect sign-in;
  • to let each person see every property in their organisation, but only the work and related data permitted by their role and relationship to the task;
  • to make work traceable: who was assigned, what was done, and who accepted it;
  • to recognise a returning guest, manage stay periods, and warn about a blocklist entry;
  • to send alerts about work that concerns you;
  • for sales purposes, to respond to a request for a demonstration of the Service or to a support enquiry;
  • to detect and investigate failures and attempted unauthorised access;
  • to comply with applicable law.

5. Action history is not rewritten

Action records are immutable. A mistake is corrected by a new visible action — cancellation, return for rework, reclassification, or a recorded link to another task — rather than deletion of the previous record.

This is intentional: the purpose of the Service is to make it possible to reconstruct what actually happened. Bear this in mind when writing comments and describing a result.

6. Cookies and data on the device

The Service uses only what it needs to operate: a session cookie, cross-site-request-forgery protection, and the saved language choice. There are no advertising or third-party analytics cookies.

The application may save some supporting files on the device so that it can open with a poor connection. Work data is not changed offline.

7. Who can access data

Within the Service, every active employee can select any property in their organisation, but selection is a filter and does not expand their role. An employee sees personally assigned work, their own reports, and permitted recent history; an administrator and owner work across the organisation.

The guest directory is available to the owner and administrator across the organisation. A housekeeper or technician receives a guest’s name only through their current, personally assigned task. The minimal room directory used to report a problem does not contain the guest, stay, note, readiness, or other people’s tasks. The telephone number, note, blocklist status, and complete guest history are available only to the owner and administrator.

Outside the Service, data may be disclosed only to the extent necessary: to infrastructure and communications providers bound by confidentiality obligations, and to public authorities when required by law.

When Telegram is used, messages pass through Telegram’s infrastructure and may be stored there under its rules. ATQAR does not control copies held by Telegram and cannot guarantee their deletion from that service. An optional copy of a demo request or support enquiry may be delivered to a private Telegram support group. This Telegram copy is outside ATQAR’s physical retention control; the original record in ATQAR remains authoritative regardless of delivery.

The Administration does not sell data.

8. Where data is processed

The Service infrastructure is located outside the Republic of Kazakhstan, in the United Kingdom. This includes the database, backups, logs, and attached-file storage.

The customer organisation, as controller, is responsible for complying with cross-border personal-data-transfer requirements for information it enters.

9. How long data is retained

Account data and work, guest, and stay records are retained while the organisation uses the Service and afterwards for as long as needed to meet obligations and protect legal claims. Sessions end on sign-out or expiry. Technical logs are retained for a limited period proportionate to the security purpose.

Demo requests and support enquiries, including exactly the submitted message and the one submitted contact method, are retained in ATQAR for no more than 365 days from creation. This 365-day ATQAR retention period does not apply to the optional Telegram copy, which remains outside ATQAR’s physical retention control.

If linked stay history prevents deletion of a guest record, the guest’s data is anonymised in place: the name is replaced with a service label, the telephone number with a unique service value, and the note and blocklist reason are cleared. Stay periods and their link to the anonymised record remain.

Unattached files are deleted when their upload period expires. Attached photos and videos are deleted 30 days after a task was last closed or cancelled; reopening the task stops the countdown until it closes again. Media files are not included in backups, and a safe record of their deletion remains in the history.

The temporary organisation behind demonstration access is deleted whole when the visit expires, together with every record you entered into it, including the notification queue and the technical rows tied to it. It needs no separate deletion request, and its contents cannot be recovered afterwards. Files, if any were uploaded, are deleted under the general rules for media described above.

At the end of the applicable period, data is deleted or irreversibly anonymised.

10. Your rights

Where provided by applicable law, you may request access to, correction or deletion of your data, restrict or object to processing, withdraw consent for the future, and complain to a supervisory authority.

Send a request to the owner or an administrator of your organisation, as the organisation decides whom to add to the Service and what work information to enter. If the request concerns operation of the Service itself, use the channel identified in section 1.

The Administration may verify the identity of the requester and refuse a request where permitted by law, for example if deleting a record would damage an action history that the law requires to be retained.

11. Changes

The Administration may change this Notice if data processing or applicable law changes. The current version and its effective date are published on this page.