Privacy policy
Last updated 4 October 2026
Corella is operated by Bellboy Technologies, a company registered in the United Arab Emirates (“we”, “us”). This policy explains what personal data we handle on the Corella website and in the Corella service, why, and the choices you have. Questions go to dev@getcorella.com.
Two different roles
For our website and our own customers’ accounts, we decide what data is collected and why, and this policy describes it.
For data held in a hotel’s systems (its property management system, CRM, task management or reputation tools), our customer decides which systems are connected and what the data is used for. We process that data on our customer’s behalf and on their instructions, under our agreement with them. If you are a hotel guest or employee and your data reached us this way, the hotel or our customer is your first point of contact; we will help them answer you.
What we collect
On the website
- The website sets no cookies and runs no analytics or advertising trackers. Its fonts are served from our own servers, not a third party.
- The servers that host the site may keep standard request logs (IP address, browser type, page requested and time) for security and to keep it running.
- If you book a call, the booking is handled by Cal.com, which collects the details you enter under its own privacy policy and shares the booking with us.
- If you email us, we keep the email and your contact details to reply.
In the Corella service
- Account data: your organisation’s name, the properties you add, and the names and contact details of people who use the service. API tokens are stored only as a one-way hash; we can’t read them back.
- Credentials for hotel systems: encrypted as soon as a system is connected, decrypted only in memory when Corella calls that system, and never returned by our API.
- Data from connected hotel systems: what those systems hold for the parts that are connected, for example reservations and stays, guest profiles and contact details, housekeeping status, service requests, reviews and survey responses, and CRM contacts and deals. Connectors are built to drop fields Corella doesn’t need and shouldn’t hold, such as payment card numbers, before anything is stored.
- Operational records: logs of API requests and syncs, an audit trail of any write actions and who approved them, and error reports. Logs redact credentials, and error reports exclude request headers, cookies, request bodies and user details.
How we use it
- To provide the service: connecting systems, syncing data and answering API requests.
- To keep the service secure, find and fix problems, and prevent misuse.
- To support our customers and reply to people who contact us.
- To meet our legal obligations.
We don’t sell personal data, we don’t use it for advertising, and we never use data from a hotel’s systems to train AI models. We use that data only to provide the service to the customer who connected it.
Where data protection law requires a legal basis, we rely on performing our contract with our customers, our legitimate interest in running and securing the service, our legal obligations, and your consent where that is needed.
Who we share it with
- Service providers who host and operate parts of the service for us, such as cloud hosting, error monitoring, email and call scheduling. They act on our instructions and under contract.
- The connected systems themselves, which receive the requests Corella sends using the credentials a hotel provided.
- Authorities, when the law requires it.
- A buyer or successor, if our business is reorganised or sold, under the same protections.
International transfers
We are based in the United Arab Emirates and our customers and their hotels are in many countries, so data may be processed outside the country where it was collected. When it is, we use the safeguards the applicable law requires.
How long we keep it
- Account data: while the account is active, and afterwards as the law requires.
- Data from a hotel system: while that connection exists. Deleting a connection deletes everything synced through it. Records a system stops listing are marked as gone and kept until the connection is deleted or our customer asks us to remove them.
- Records of individual sync jobs: 7 days.
- Logs and error reports: for a limited period, for security and troubleshooting.
Security
Credentials are sealed with encryption and API tokens are hashed. Each connection’s permissions decide what Corella may read and write; every write passes a permission check and leaves an audit trail. Every request is scoped to the organisation that made it, so one customer can’t see another’s data. No system is perfectly secure, and we will tell affected customers about a breach as the law requires.
Your rights
Depending on where you are, including under the UAE Personal Data Protection Law and the EU and UK GDPR, you may have the right to access, correct or delete your personal data, to object to or restrict how it’s used, and to receive a copy. Email dev@getcorella.com and we’ll respond within the time the law allows. For data that came from a hotel’s systems, we’ll pass your request to the customer responsible for it and help them answer. You can also complain to your data protection authority.
Children
The website and service are for businesses and aren’t directed at children. Hotel systems may contain data about guests of any age; that data is handled as described above.
Changes
We’ll update this page when our practices change and change the date at the top. Significant changes will be communicated to customers directly.
Contact
Bellboy Technologies, United Arab Emirates. dev@getcorella.com. See also our terms of service.