Terms & Policies

Updated on 17 August 2026

Channex Customer Agreement

Effective from: 17 August 2026

This Channex Customer Agreement (the "Agreement") is between you and Channex.io LTD, a company registered in England and Wales with company number 09250795, whose registered office is at Castell Pigyn Lodge, Abergwili, Carmarthen, SA31 2JL, United Kingdom ("Channex", "we", "us"). If you are agreeing to this Agreement on behalf of a company or other organisation rather than as an individual, then "Customer" or "you" means that organisation, and you confirm you have authority to bind it.

By clicking "I agree" (or a similar button) when you place an Order, or by accessing or using the Channex platform, you agree to be bound by this Agreement.

1. Scope and order of precedence

1.1 This Agreement governs your access to and use of the Channex platform and related services (together, the "Services"). It applies to your first Order and to any later Order that references it. It includes our Privacy Policy, our Acceptable Use Policy, our Security Policy and the Data Protection Addendum at Section 21 below.

1.2 Order of precedence. If there is any conflict or inconsistency between documents, the following order applies, with the first listed prevailing: (a) in respect of the processing of personal data, any European Commission standard contractual clauses, UK International Data Transfer Agreement or Addendum, or other data protection agreement signed between us — these rank first because the clauses themselves require it; (b) any service agreement, partner agreement or addendum signed by an authorised representative of both parties, including its appendices; (c) your Order; (d) this Agreement; (e) any policy referenced in this Agreement. A signed agreement varies this Agreement only to the extent of the conflict — the rest of this Agreement continues to apply.

1.3 This Agreement does not apply to third party products or services that you choose to connect to the Services, which are covered by Section 18 (Third party channels and services).

2. The Services

2.1 Channex provides a hosted inventory management and distribution platform that connects property, hotel and vacation rental systems to online travel agents, booking engines, metasearch channels and other systems that need availability, rate and booking data. The Services are provided over the internet on a subscription basis. There is no software for you to install or host.

2.2 Subject to this Agreement and payment of the applicable fees, we grant you a non-exclusive, non-transferable right to access and use the Services during your Subscription Term, for your own business purposes and in accordance with your Order and our documentation.

2.3 We may change, improve or add to the Services from time to time. We will not make a change that materially reduces the core functionality you are paying for during a Subscription Term without giving you notice under Section 20 (Changes to this Agreement).

2.4 You decide which channels, applications and third parties your properties connect to and share data with. We do not make that choice for you.

3. Your account

3.1 You need a Channex account to place Orders and use the Services. The registration information you give us must be accurate, current and complete, and you must keep it up to date so that we can send you notices, statements and invoices.

3.2 User credentials are issued to named individuals and must not be shared. You must keep them confidential, and tell us promptly if you become aware of any unauthorised use of your account. You are responsible for everything done through your account.

4. Orders and scope of use

4.1 Your Order sets out your authorised scope of use — which may include the number of properties, rooms or units, the number of user seats, and any applicable limits ("Scope of Use") — together with the fees, the currency and the Subscription Term.

4.2 Your users may be your own staff, or contractors, agents or other people acting on your behalf. You are responsible for their compliance with this Agreement.

4.3 You may increase your Scope of Use at any time, through the platform or by placing a new Order. We will charge the additional fees at the rates then applying to your account, in your next billing cycle.

4.4 If you purchase the Services through an authorised reseller or partner, your Scope of Use is as stated in the Order that partner places for you, and your commercial relationship — including payment, support and cancellation — is with them.

5. Your data

5.1 "Your Data" means all data and content you or your users submit to, or generate through, the Services — including property details, room types, rate plans, availability, prices, restrictions, bookings and guest details.

5.2 Your Data belongs to you. You retain all right, title and interest in it. We claim no ownership of it.

5.3 You grant us a non-exclusive, worldwide, royalty-free right to host, copy, store, transmit and process Your Data solely to the extent necessary to provide the Services to you — including transmitting it to the channels and third parties you have chosen to connect — to provide support you request, and to comply with our legal obligations. We will not use Your Data for any other purpose.

5.4 We will not approach your customers. We will not use Your Data to contact, market to, or enter into a business relationship with your clients or their guests, other than as necessary to deliver the Services you have asked us to deliver. This Section 5.4 survives termination of this Agreement.

5.5 You are responsible for the accuracy and legality of Your Data, and for having the rights and permissions needed to provide it to us and to have us transmit it to the channels you connect. Personal data is dealt with in Section 21 (Data Protection Addendum).

5.6 We may generate aggregated, anonymised statistics from platform usage in order to operate, secure and improve the Services. Such statistics never identify you, your properties, your guests or your data.

6. Acceptable use and content

6.1 Your use of the Services must comply with our Acceptable Use Policy and with all applicable laws, including travel, consumer, data protection and anti-spam laws.

6.2 We take a zero tolerance approach to unsolicited messaging. You must not use the Services to send spam, and if you resell or provide access to the Services to your own clients, your terms with them must prohibit the same. The transmission of adult content through the Services is prohibited.

6.3 We have no obligation to monitor content submitted to the Services, and we do not routinely inspect Your Data. Where we reasonably believe content or activity breaches this Agreement, endangers the Services, or exposes us or other customers to legal risk, we may remove the content or suspend the affected access under Section 12 (Suspension).

7. Security

7.1 We implement appropriate technical and organisational measures designed to protect Your Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Those measures are described in our Security Policy, which forms part of this Agreement.

7.2 Using the Services necessarily involves transmitting data across networks we do not own or control. While we encrypt data in transit and take the measures described in our Security Policy, no system can be guaranteed impenetrable, and we cannot warrant that our measures or those of our suppliers will never be defeated.

7.3 Card processing for the Services is carried out by PCI DSS compliant service providers. Each party is responsible for its own compliance with the Payment Card Industry Data Security Standard in respect of cardholder data within its own environment.

8. Support

8.1 Technical support is included in your subscription fees at no additional charge. We provide support by web chat, email and telephone during our published support hours.

8.2 Where you provide the Services to your own clients under a partner or reseller arrangement, you provide first line support to those clients and we provide second line support to you.

9. Service availability

9.1 We will provide the Services with the level of skill and care reasonably expected of a competent provider of comparable services, and will use commercially reasonable efforts to correct any error or interruption as soon as possible.

9.2 Uptime commitment. We will provide at least 99.5% uptime availability, measured monthly. At 99.5%, permitted unavailability is approximately 3 hours 39 minutes per month, or 1 day 19 hours 49 minutes per year.

9.3 The uptime commitment excludes scheduled maintenance — including regular error corrections and software updates — and unavailability caused by a Force Majeure Event, by your own systems or connectivity, or by a third party channel or service you have connected. We will not carry out scheduled maintenance between 06:00 and 18:00 GMT.

9.4 Remedy. If we fail to meet the uptime commitment in any month, you may terminate this Agreement immediately on written notice, and we will refund any fees you have prepaid for the unused remainder of your Subscription Term.

10. Fees and payment

10.1 Currency and rates. Fees are charged in the currency stated in your Order, at the rates set out in it.

10.2 Invoicing. Unless your Order says otherwise, fees are invoiced monthly in arrears on the 1st of each month and are due within fourteen (14) days of the invoice date. Where you pay by card, you authorise us to charge that card for subscription fees, renewals and any additional usage.

10.3 Price changes. We may change our fees on ninety (90) days' advance written notice. A change takes effect at the end of that notice period and applies to existing and future properties alike. If you do not accept a price change, you may terminate under Section 13.4 before it takes effect.

10.4 Taxes. Fees exclude VAT and any other applicable taxes or duties, which you will pay in addition where they are chargeable. If you hold a valid exemption, tell us and we will provide the invoicing documentation you need.

10.5 Except as set out in Section 9.4 (service availability remedy), Section 11 (30-day satisfaction refund), Section 20.3 (changes you do not accept) and Section 21.7 (subprocessor objection), fees are non-refundable and non-creditable once due.

11. 30-day satisfaction refund

If you are a new customer and you are not satisfied with the Services, you may cancel within 30 days of your first payment and we will refund your first monthly invoice in full. This right applies to new customers only and is limited to the first monthly invoice. To use it, contact us at support@channex.io within the 30-day period.

12. Suspension

12.1 We may suspend your access to the Services, without liability, if an invoice remains unpaid more than thirty (30) days after its due date, or if your use of the Services breaches the Acceptable Use Policy or applicable law.

12.2 We will give you notice and a reasonable opportunity to put things right before suspending, unless the problem is urgent — for example where your account is compromised, or your use threatens the security or operation of the Services or other customers — in which case we may suspend immediately and tell you promptly afterwards.

12.3 Suspension is limited to what is necessary, and we will restore access promptly once the cause is resolved.

13. Term, renewal and termination

13.1 Term. Unless your Order says otherwise, the initial Subscription Term is one (1) year from the start date in your Order.

13.2 Renewal. The Subscription Term renews automatically for successive periods of one (1) year unless either party gives the other written notice of non-renewal at least thirty (30) days before the end of the then-current term.

13.3 Termination for breach or insolvency. Either party may terminate immediately on written notice if the other materially breaches this Agreement and does not remedy the breach within thirty (30) days of a written request to do so, or if the other enters into bankruptcy, administration, liquidation, composition proceedings or any similar proceedings.

13.4 Termination for convenience. Either party may terminate this Agreement for any reason on thirty (30) calendar days' written notice.

13.5 Effect of termination. On termination, your right to access the Services ends. Rights and obligations that accrued before termination — including your obligation to pay fees already due, and either party's right to claim for a breach that existed at or before termination — are unaffected. Except where this Agreement says otherwise, you will not receive a credit or refund for prepaid but unused fees on a termination for convenience by you.

13.6 Transition assistance. If you ask us in writing, we will provide reasonable transition assistance for up to sixty (60) days after termination, at your cost. We will agree the scope and fees with you in writing before we start. This is conditional on your account not being in material payment breach.

13.7 Return and deletion of Your Data. During the Subscription Term and for thirty (30) days after it ends, you may export Your Data from the platform, or ask us to provide it to you in a commonly used format. After that period we may delete Your Data in accordance with the retention schedule in our Security Policy.

13.8 Survival. The following survive termination: Sections 5.2 and 5.4 (ownership of and non-approach to Your Data), 10 (Fees and payment, in respect of amounts already due), 13.5 to 13.8 (effect of termination, transition assistance, return and deletion of Your Data, and this Section), 14 (Restrictions), 16 (Ownership and feedback), 17 (Confidentiality), 19.2 (Warranty disclaimer), 19.3 (Limitation of liability), 19.4 (Indemnities), 21.13 and 21.14 (deletion of personal data, and liability under the Data Protection Addendum), 22 (Governing law and jurisdiction) and 25 (General).

14. Restrictions

Except as expressly permitted in this Agreement, in your Order, or in a separate agreement signed by us, you will not:

  • rent, lease, sell, sublicense, transfer or provide access to the Services to a third party;
  • use the Services for the benefit of, or to provide a service to, a third party;
  • incorporate the Services into a product or service you supply to a third party;
  • reverse engineer, decompile or disassemble any part of the Services, or attempt to derive their source code or non-public APIs, except to the extent the law permits despite this restriction;
  • circumvent or interfere with any mechanism in the Services intended to limit your use, or with any security or authentication measure;
  • remove or obscure any proprietary notice in the Services; or
  • access the Services in order to build a competing product.

Partners and resellers. The first three restrictions above do not apply to the extent we have appointed you as a reseller, or granted you white label or embedding rights, under a signed agreement. If you have such an agreement, that agreement defines what you may do and prevails under Section 1.2.

15. Branding and attribution

15.1 Unless we have agreed otherwise in writing, where you present the Services or their output to your own users you should include a reasonable attribution to Channex.

15.2 White label. This attribution requirement does not apply where we have granted you white label rights under a signed agreement. Under such an agreement you may apply your own branding and styling to the platform, and no Channex attribution is required. Fees may apply where custom development work is needed to deliver your branding.

16. Ownership and feedback

16.1 The Services are made available to you on a subscription basis. We and our licensors retain all right, title and interest in the Services, the platform, all underlying technology, and any modifications or derivative works of them. No rights are granted to you except those expressly set out in this Agreement.

16.2 If you choose to send us suggestions, ideas or other feedback about the Services, we may use it freely to develop and improve our products, without obligation or payment to you. Feedback is not your Confidential Information. This does not give us any rights in Your Data.

17. Confidentiality

17.1 Each party may receive information from the other that is identified as confidential, or that a reasonable person would understand to be confidential from its nature or the circumstances of disclosure ("Confidential Information"). Your Data is your Confidential Information. The non-public technical and commercial details of the Services are ours.

17.2 The receiving party will keep the other's Confidential Information confidential, use it only to perform this Agreement, and disclose it only to those of its personnel and professional advisers who need it and are bound by equivalent obligations.

17.3 These obligations do not apply to information that is or becomes public through no fault of the receiving party, was already lawfully known to it, is lawfully received from a third party without restriction, or is independently developed without use of the Confidential Information. A party may disclose Confidential Information where required by law, regulation or court order, giving the other party advance notice where it is lawful to do so.

18. Third party channels and services

18.1 The Services connect to online travel agents, booking engines, metasearch providers, property management systems, payment providers and other third parties. Those third parties are not under our control. Your relationship with each of them — including their commercial terms, their commission, their content rules and their treatment of your data — is between you and them.

18.2 We do not warrant the availability, accuracy or performance of any third party channel or service, and we are not liable for a third party's acts, omissions, outages or changes to its interfaces. Where a channel changes or withdraws its interface, we will use commercially reasonable efforts to update the Services, but we cannot guarantee continuity of any particular connection.

18.3 When you connect a third party to your account, you authorise us to exchange Your Data with it as needed for that connection to work.

19. Warranties, liability and indemnities

19.1 Mutual warranties. Each party warrants that it has the legal power and authority to enter into this Agreement, and that the person accepting it has authority to bind that party.

19.2 Warranty disclaimer. Other than the commitments expressly given in Sections 7 (Security), 9 (Service availability) and 19.1, and to the maximum extent permitted by law, the Services are provided without further warranty of any kind, whether express, implied or statutory, including any implied warranty of satisfactory quality, fitness for a particular purpose or non-infringement. We do not warrant that the Services will be uninterrupted or entirely error-free, or that they will meet requirements we have not agreed with you in writing. Nothing in this Section limits your statutory rights where they cannot lawfully be excluded.

19.3 Limitation of liability.

(a) Subject to 19.3(c), neither party is liable to the other for any indirect, special, incidental or consequential loss or damage, including loss of profit, loss of revenue, loss of goodwill, loss of anticipated savings or loss of data, whether or not the loss was foreseeable or the party was advised of its possibility.

(b) Subject to 19.3(c), each party's total aggregate liability under or in connection with this Agreement — whether in contract, tort (including negligence), breach of statutory duty or otherwise — will not exceed the total fees paid or payable by you in the three (3) months immediately preceding the event giving rise to the claim.

(c) Nothing in this Agreement limits or excludes either party's liability for: (i) death or personal injury caused by its negligence; (ii) fraud or fraudulent misrepresentation; (iii) your obligation to pay fees properly due; or (iv) any other liability that cannot lawfully be limited or excluded under the laws of England and Wales.

(d) The parties agree that the limitations in this Section 19.3 are reasonable, having regard to the fees charged for the Services and to the allocation of risk between the parties.

19.4 Indemnities.

(a) By you. You will indemnify us against third party claims, and reasonable legal costs, arising from your material breach of this Agreement, from Your Data or your own content infringing a third party's rights, or from your violation of applicable law.

(b) By us. We will defend you against any third party claim that the Services, used in accordance with this Agreement, infringe that third party's patent, copyright, trademark or trade secret, and we will indemnify you against damages and costs finally awarded or agreed in settlement. This does not apply where the claim arises from combining the Services with something we did not provide, or from Your Data. If a claim is made or we reasonably expect one, we may procure the right for you to continue using the Services, modify or replace them with something functionally equivalent, or terminate the affected Services and refund prepaid fees for the unused term.

(c) Procedure. The indemnified party must notify the indemnifier promptly, give it sole control of the defence and settlement, and provide reasonable cooperation at the indemnifier's expense. The indemnifier will not settle in a way that imposes an obligation or admits liability on behalf of the indemnified party without its prior written consent.

20. Changes to this Agreement

20.1 We may update this Agreement and the policies it references — to reflect changes in the law, new regulatory requirements, or changes to the Services.

20.2 If a change materially reduces your rights, we will notify you at least thirty (30) days before it takes effect, by email to your billing or technical contact or by a notice in the platform. Other changes take effect when published.

20.3 If you do not accept a change that materially reduces your rights, you may terminate before it takes effect, and we will refund a pro rata share of any fees you have prepaid for the period after termination. Continuing to use the Services after the change takes effect means you accept it.

20.4 Signed agreements. Where you have a signed service agreement, partner agreement or addendum with us, we may not vary the terms of that signed document by updating this Agreement. Changes to a signed document require a written instrument executed by authorised representatives of both parties.

21. Data Protection Addendum

21.1 Definitions. "Controller", "processor", "data subject", "personal data", "processing" and "special categories of personal data" have the meanings given in Data Protection Law. "Data Protection Law" means the UK General Data Protection Regulation and the Data Protection Act 2018, and, where applicable to the processing, Regulation (EU) 2016/679 (the EU GDPR) and any national implementing legislation, in each case as amended or replaced from time to time. "Customer Personal Data" means personal data contained in Your Data and processed by us on your behalf under this Agreement.

21.2 Roles. You are the controller of Customer Personal Data and we are your processor. We process Customer Personal Data only on your documented instructions, which are the instructions contained in this Agreement, your Order, your configuration of the Services and your choice of connected channels. We will tell you if we consider an instruction to breach Data Protection Law. Each party will comply with the obligations that apply to it under Data Protection Law, and a material breach of Data Protection Law by either party is a material breach of this Agreement.

21.3 Subject matter and scope. The subject matter of the processing is the provision of the Services. It lasts for the Subscription Term plus the retention periods in our Security Policy. The nature and purpose is the hosting, transmission and management of property, rate, availability and booking data. The categories of data subject are your personnel and the guests who book with your properties. The personal data typically comprises names, postal and email addresses, telephone numbers, booking details and, where you enable it, payment card details and identity document numbers.

21.4 Prohibited data. Do not submit special categories of personal data to the Services unless we have expressly agreed in writing to process it.

21.5 Confidentiality. We ensure that anyone we authorise to process Customer Personal Data is subject to a duty of confidentiality and has been trained appropriately.

21.6 Security. We implement appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, and unauthorised disclosure or access. Our current measures are described in our Security Policy.

21.7 Subprocessors. You give us general authorisation to engage subprocessors to process Customer Personal Data for the purpose of providing the Services. We maintain a current list of our subprocessors, which is available on request from support@channex.io. We will give you at least thirty (30) days' notice before adding or replacing a subprocessor. We impose data protection terms on each subprocessor that are no less protective than those in this Section 21, and we remain liable for their acts and omissions. You may object to a new subprocessor on reasonable data protection grounds, in which case we will either not make the change or, if that is not reasonably possible, you may terminate the affected Services without penalty and receive a refund of prepaid fees for the unused term. Where standard contractual clauses are in place between us, the subprocessor authorisation regime in those clauses applies instead of the general authorisation in this Section 21.7 — which may require our obtaining your specific prior written authorisation for each new subprocessor.

21.8 International transfers. We will not transfer Customer Personal Data to a country outside the UK or the EEA unless the transfer is made in accordance with Data Protection Law — for example to a country covered by UK adequacy regulations or a European Commission adequacy decision, under the UK International Data Transfer Agreement or Addendum, or under the European Commission's standard contractual clauses, in each case with any supplementary measures required.

21.9 Data subject rights. Taking account of the nature of the processing, we will assist you by appropriate technical and organisational measures, so far as is reasonably possible, in responding to requests from data subjects exercising their rights. If a data subject contacts us directly about Customer Personal Data, we will not respond substantively but will refer them to you and pass on the details promptly.

21.10 Assistance. We will provide you with reasonable assistance with data protection impact assessments and prior consultations with a supervisory authority, and with your obligations to keep Customer Personal Data secure and to notify personal data breaches, taking into account the nature of the processing and the information available to us.

21.11 Personal data breach. We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the information reasonably available to us so that you can meet your own notification obligations. We will take reasonable steps to remedy or mitigate the breach and keep you informed of material developments.

21.12 Audit. We will make available the information reasonably necessary to demonstrate our compliance with this Section 21, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you appoint. Audits are limited to once in any twelve-month period unless a personal data breach or a regulator requires otherwise, must be on at least thirty (30) days' notice, during business hours, subject to confidentiality, and must not unreasonably disrupt our operations. Where a current third party audit report or certification answers your question, we may provide that instead.

21.13 Deletion or return. On termination, we will delete or return Customer Personal Data in accordance with Section 13.7 and the retention schedule in our Security Policy, except to the extent we are required by law to retain it, or where it sits on backup media, in which case we will isolate it and protect it from further processing until deletion.

21.14 Liability. Liability arising under or in connection with this Section 21 is subject to the limitations and exclusions in Section 19.3. This does not limit or affect any liability owed directly to a data subject under standard contractual clauses signed between us: that liability is governed by those clauses and cannot be varied by this Agreement.

22. Governing law and jurisdiction

22.1 This Agreement, and any dispute or claim arising out of or in connection with it or its subject matter (including non-contractual disputes or claims), is governed by and construed in accordance with the laws of England and Wales.

22.2 The parties submit to the exclusive jurisdiction of the courts of England and Wales.

22.3 Before starting proceedings, the parties will consult in good faith and try to reach a resolution. This does not prevent either party from applying to any court of competent jurisdiction for injunctive or other urgent relief, in particular to protect intellectual property rights or Confidential Information.

23. Publicity

We will not identify you as a Channex customer, or use your name or logo in our promotional materials, without your prior written consent. Where you give consent, you may withdraw it at any time by emailing support@channex.io, and we will remove the reference from materials under our control within thirty (30) days.

24. Force majeure

24.1 Neither party is liable for any delay or failure to perform (other than a failure to pay amounts due) caused by an event beyond its reasonable control — including strike, blockade, war, act of terrorism, riot, natural disaster, epidemic, failure of power, telecommunications or data networks, or refusal of a licence by a government agency (a "Force Majeure Event").

24.2 The affected party will give written notice within five (5) business days of the event, describing its nature and expected duration, and will use commercially reasonable efforts to mitigate and overcome it. If a Force Majeure Event continues for sixty (60) consecutive days or more, either party may terminate this Agreement on fourteen (14) days' written notice without liability, other than for fees already due and payable.

25. General

25.1 Notices. Notices under this Agreement must be in writing, in English. Notices to us go to support@channex.io. Notices to you go to the email address on your account, or through the platform, and are deemed given on the next business day after sending.

25.2 Assignment. You may not assign or transfer this Agreement without our prior written consent, which we will not unreasonably withhold if the assignee agrees to be bound by it. We may assign this Agreement, in whole or in part, to an affiliate or in connection with a merger, acquisition or sale of all or substantially all of our assets. On a merger or consolidation of either party, the surviving entity is bound by this Agreement.

25.3 Independent contractors. Nothing in this Agreement creates an agency, partnership, joint venture or employment relationship. Neither party may bind the other.

25.4 Costs. Except as a court orders, each party bears its own legal costs in relation to any dispute.

25.5 Severability. If any provision of this Agreement is held invalid or unenforceable, it will be applied in the narrowest way that makes it enforceable, or severed if that is not possible, and the remaining provisions continue in full force.

25.6 Waiver. A failure or delay in enforcing a provision is not a waiver of it, and does not prevent later enforcement.

25.7 Third party rights. A person who is not a party to this Agreement has no right under the Contracts (Rights of Third Parties) Act 1999 to enforce any of its terms.

25.8 Entire agreement. This Agreement, together with your Order and any signed agreement or addendum between us, is the entire agreement between the parties about the Services, and supersedes all prior communications, proposals and representations about them. Section 1.2 governs any conflict between those documents. Nothing in this Section limits liability for fraud or fraudulent misrepresentation.

25.9 Interpretation. "Including" means "including without limitation". Section headings are for convenience and do not affect interpretation.

Privacy Policy

Effective from: 17 August 2026

Introduction

This Privacy Policy explains what information Channex.io LTD ("Channex", "we", "us") collects, why we collect it, what we do with it, and the choices you have. Channex.io LTD is a company registered in England and Wales with company number 09250795, whose registered office is at Castell Pigyn Lodge, Abergwili, Carmarthen, SA31 2JL, United Kingdom.

We are the data controller for the information described in this policy. We comply with the UK General Data Protection Regulation and the Data Protection Act 2018, and with the EU GDPR where it applies to our processing.

Two different roles — please read this first

Channex handles personal data in two distinct capacities, and different rules apply to each.

1. As a controller — information about you, our customer. When you visit our website, ask for a demo, register an account, or contact support, we decide how your information is used. That is what this Privacy Policy covers.

2. As a processor — booking and guest data belonging to our customers. When an accommodation provider uses the Channex platform, the property and guest data flowing through it belongs to that provider. They decide what happens to it; we process it on their instructions. This Privacy Policy does not govern that data — the Data Protection Addendum in Section 21 of our Customer Agreement does.

If you are a guest who has booked a stay and you want to access, correct or delete your data, please contact the property you booked with. They are the controller of your booking. If you contact us, we will pass your request to them promptly, but we cannot act on it ourselves.

Scope

This policy applies to our website at channex.io and its subdomains, and to the Channex platform and related hosted services (together, the "Services"). It does not apply to third party services you choose to connect to the platform — such as online travel agents, property management systems or payment providers — each of which has its own privacy policy that you should review.

Information we collect

Account and profile information. When you register or maintain an account we collect your name, business email address, telephone number, business postal address, job title, and your notification and marketing preferences.

Billing information. We collect the billing details needed to invoice you. Card payments are handled by our payment providers — we do not store your full card number on our own systems.

Property and operational data. The data you enter into the platform about your properties, room types, rate plans, availability, prices, restrictions and bookings. Where this includes personal data about guests, we process it as your processor, not as a controller — see "Two different roles" above.

Support and correspondence. Records of your contact with us — support tickets, web chat transcripts, emails and call notes — and anything you choose to include in them.

Website and platform logs. As with most internet services, our servers record IP address, browser type and version, operating system, referring and exit URLs, timestamps, language and locale settings, and the pages or platform functions accessed. We use logs to operate and secure the Services, diagnose faults and investigate abuse.

Usage analytics. Information about which features of the platform are used and how, so that we can understand what works and what needs improving.

How we use your information, and our lawful basis

To provide the Services — creating and administering your account, delivering the platform, processing your instructions, and providing support. Lawful basis: performance of our contract with you.

To bill you and keep our records — invoicing, collecting payment, and maintaining accounting records. Lawful basis: performance of our contract, and compliance with our legal obligations.

To communicate with you about the Services — service announcements, security alerts, maintenance notices, changes to terms, and responses to your questions. These are not marketing and you cannot opt out of them while you hold an account. Lawful basis: performance of our contract.

To secure and improve the Services — monitoring for fraud and abuse, diagnosing faults, analysing usage patterns, and developing new features. Lawful basis: our legitimate interest in running a secure, functioning and improving product.

To send marketing — information about features, offers and events. Lawful basis: your consent, or our legitimate interest in marketing to existing business customers about similar services. You can opt out at any time.

To meet legal obligations and protect our rights — responding to lawful requests, enforcing our agreements, and establishing or defending legal claims. Lawful basis: legal obligation, and our legitimate interest in protecting our business.

We do not sell your personal information, and we do not share it with third parties for their own marketing purposes.

We do not use the data flowing through the platform to market to your clients or their guests. This commitment is also a contractual one — see Section 5.4 of our Customer Agreement.

Cookies and similar technologies

We use cookies and similar technologies to keep you signed in, remember your preferences, and understand how our website and platform are used. Strictly necessary cookies are set without consent because the Services cannot function without them. Analytics and any advertising cookies are set only where you have consented, and you can change or withdraw that consent at any time through the cookie settings on our website or your browser settings.

We currently use Google Analytics to understand website usage. You can prevent Google Analytics from collecting your data using Google's opt-out browser add-on.

Who we share information with

Service providers. We use third parties for hosting, infrastructure, backup and storage, email delivery, payment processing, analytics and customer support tooling. They process information on our instructions and are bound by contractual data protection obligations. A current list of our subprocessors is available on request from support@channex.io.

Channels and connected services you choose. When you connect a channel or third party to your account, we transmit the property, rate, availability and booking data required for that connection to work. You choose which connections to make, and you can disconnect them at any time.

Legal and safety. We may disclose information where we reasonably believe it is necessary to comply with a law, regulation, legal process or lawful governmental request; to enforce our agreements and policies; to protect the security and integrity of the Services; or to protect Channex, our customers or the public from harm or illegal activity.

Business transfers. If we are involved in a merger, acquisition, financing or sale of assets, information may be transferred as part of that transaction. We will notify you by email or a prominent notice in the platform of any change of ownership affecting your personal information, and of any choices you have.

With your consent. In any other case, we share your personal information only where you have asked us to or agreed that we may. Customer testimonials and case studies are published only with your prior written consent, which you may withdraw.

International transfers

The Channex platform and its databases are hosted in the European Union, on infrastructure provided by Amazon Web Services and DigitalOcean. Booking and guest data you send us is stored in the EU. Some supporting services — such as website analytics — may process limited data outside the UK and EEA. Where personal information is transferred outside the UK or the EEA, we make the transfer in accordance with data protection law — relying on UK adequacy regulations or a European Commission adequacy decision where one covers the destination, and otherwise putting in place the UK International Data Transfer Agreement or Addendum, or the European Commission's standard contractual clauses, with any supplementary measures required. You can request details of the safeguards applying to a specific transfer by emailing support@channex.io.

Security

The measures we take to protect information are described in our Security Policy below. Data transmitted between you and the Services is encrypted in transit using TLS (HTTPS). No system can be guaranteed impenetrable, and while we take the measures described in our Security Policy, we cannot guarantee that information will be absolutely safe from intrusion.

How long we keep information

We keep personal information only as long as we need it for the purpose we collected it for, or as long as the law requires. The specific retention periods for platform data — bookings, availability and rate data, card details and account data — are set out in the Data Retention section of our Security Policy, and we apply them consistently.

Beyond that, we keep account and contact information for as long as your account is active and for six years afterwards, in line with the limitation period for contract claims. We keep invoices and accounting records for seven years, as UK tax law requires. Marketing contact details are kept until you opt out.

Your rights

Under UK and EU data protection law you have the right to:

  • request a copy of the personal information we hold about you;
  • have inaccurate information corrected;
  • have your information erased, where there is no overriding reason for us to keep it;
  • restrict or object to our processing, including objecting to direct marketing at any time;
  • receive your information in a portable, machine-readable format;
  • withdraw consent, where we rely on consent, without affecting processing carried out before you withdrew it; and
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make such decisions.

To exercise any of these rights, email support@channex.io. We will respond within one month. Our security procedures mean we may ask you to verify your identity first. There is no charge unless a request is manifestly unfounded or excessive.

Much of your account information can be corrected or updated directly in your account settings. Where your account is managed by an administrator at your organisation, they may also be able to access, amend or delete it.

Where we hold information because the law requires it — for example invoice records, or guest registration information that must be provided to local health and safety or police authorities — we will keep the minimum required until that obligation expires, even if you ask us to delete it. We will tell you when this applies.

Marketing preferences

You can opt out of marketing emails using the unsubscribe link in any marketing message, in your account settings, or by emailing us. Opt-out requests are usually processed immediately, and always within ten (10) business days. You will still receive transactional and service messages about your account.

Children

The Services are business tools and are not directed to children. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

Complaints

If you wish to complain about how we have handled your personal information, contact us by email, telephone or letter — we do not require complaints in writing. We deal with complaints promptly and will respond within 28 days.

If you are dissatisfied with the outcome, you can escalate internally by emailing evan@channex.io.

You also have the right to complain to a supervisory authority. In the UK this is the Information Commissioner's Office (ico.org.uk, helpline 0303 123 1113). If you are in the EEA, you may complain to your local supervisory authority. We would appreciate the chance to address your concerns first.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Effective from" date at the top. If we make a material change, we will give you additional notice — by email, or by a notice in the platform or on our website — before it takes effect.

Contact us

Email: support@channex.io

Post: Channex.io LTD, Castell Pigyn Lodge, Abergwili, Carmarthen, SA31 2JL, United Kingdom

Acceptable Use Policy

Effective from: 17 August 2026

Channex moves live availability, rates and bookings between accommodation providers and the channels they sell on. When the platform is misused, the damage lands on other people — a property whose rooms are oversold, a guest charged for a stay that does not exist, a channel that suspends a connection everyone depends on. This policy sets out what we do not allow.

It applies to everyone using the Services, and it forms part of the Customer Agreement. "Services" means the Channex platform and APIs, and the websites we operate, including channex.io and its subdomains. "Content" means any data, text, code, images or other material you submit to, or transmit through, the Services.

We apply this policy to the substance of what you do, not only to the wording below. If something is not listed here but is clearly of the same kind, we may still act on it.

Inventory, rates and bookings

These matter most, because they affect guests and channels directly.

  • Listing, connecting or managing a property you do not own or are not authorised to act for
  • Publishing availability you do not have, or rates you do not intend to honour
  • Using the Services to take bookings you know you cannot fulfil
  • Misrepresenting a property, its location, its facilities or its licensing status on a connected channel
  • Using the Services in a way that breaches your own agreement with a connected channel, or that is designed to circumvent that channel's rules on rates, parity, cancellation or content
  • Submitting deliberately false or manipulated booking, cancellation or modification data

Disruption and system integrity

  • Probing, scanning or testing the vulnerability of any system or network hosting the Services, unless we have agreed to it in writing in advance
  • Tampering with, reverse engineering or attacking the Services, circumventing any security or authentication measure, or attempting to gain unauthorised access to the Services, related systems, networks or data
  • Modifying, disabling or otherwise compromising the integrity or performance of the Services
  • Intercepting or deciphering transmissions to or from the servers running the Services
  • Placing an unreasonable load on our infrastructure — including exceeding documented API rate limits, polling far more often than the documentation provides for, or running automated processes that consume disproportionate resources
  • Sharing user credentials, or accessing the Services through an account that was not issued to you
  • Accessing the Services by any means other than our published interfaces and APIs, including scraping

If you believe you have found a security vulnerability, please report it to support@channex.io. We will not pursue a good-faith researcher who reports a genuine issue promptly and does not access or alter other customers' data.

Wrongful activity

  • Using the Services for any unlawful purpose, or in breach of any applicable law — including data protection, consumer, tax, export control and local accommodation licensing laws
  • Misrepresenting who you are, or disguising the origin of Content — including spoofing, phishing, manipulating headers or identifiers, impersonating another person or business, or falsely implying a relationship with Channex
  • Using the Services to violate someone's privacy — publishing other people's private or confidential information without permission, or harvesting personal information from the Services
  • Using the Services to stalk, harass or threaten anyone
  • Reselling, sublicensing or providing access to the Services to a third party without a signed agreement permitting it (see Section 14 of the Customer Agreement)

Messaging and guest communications

  • Sending unsolicited communications, advertising or spam through the Services. We take a zero tolerance approach to this — see Section 6.2 of the Customer Agreement
  • Messaging guests for any purpose other than servicing their booking, unless you have their consent and a lawful basis to do so
  • Sending messages that do not comply with applicable marketing, consumer and travel regulations

If you provide the Services to your own clients, your terms with them must prohibit the same conduct.

Content

Do not submit or transmit Content that:

  • infringes anyone's intellectual property or other rights, or that you do not have the right to submit
  • is deceptive, fraudulent, defamatory, obscene, threatening or harassing
  • is pornographic or sexually explicit. The transmission of adult content through the Services is prohibited
  • attacks or demeans people on the basis of race, ethnicity, national origin, religion, sex, gender, sexual orientation, disability or medical condition
  • contains viruses, worms, scripting exploits or similar harmful material

Child sexual abuse material will be removed and reported to law enforcement and to the appropriate authority — in the United Kingdom, the Internet Watch Foundation, and elsewhere the equivalent body, including the National Center for Missing and Exploited Children in the United States.

Enforcement

Where we believe this policy has been breached, we will normally tell you and give you a reasonable opportunity to put it right. Where the breach is urgent — for example where it threatens the security of the Services, exposes guests to harm, or puts a channel connection at risk for other customers — we may suspend access immediately and tell you promptly afterwards. Suspension and termination are governed by Sections 12 and 13 of the Customer Agreement, and this does not affect any other remedy available to us.

To report a suspected breach of this policy, email support@channex.io.

Security Policy

Effective from: 17 August 2026

Overview

The Channex connectivity platform lets accommodation providers, property management systems and independent software vendors connect to distribution channels and exchange availability, rate and booking data. Protecting that data is central to the service — a failure here affects our customers' businesses and their guests, not just us. We take a risk-based approach to security, and this policy sets out the measures we have in place.

No single control protects customer data. What protects it is a set of layers — the physical security of the facilities our infrastructure runs in, network and system controls above that, and the access rules that determine what any individual can reach. This policy describes each layer, and is explicit about which parts we operate ourselves and which we rely on our providers for.

Where your data is hosted

Channex does not operate its own data centres. The platform runs on infrastructure provided by Amazon Web Services and DigitalOcean.

Platform data is hosted in the European Union. We use EU regions for the Channex platform and its databases, so the availability, rate and booking data you send us — including guest personal data — is stored in the EU.

Some supporting services we use, such as website analytics, may process limited data outside the EU. Where that involves a restricted transfer of personal data, we put the appropriate safeguards in place — see the International transfers section of our Privacy Policy. A current list of our subprocessors is available on request from support@channex.io.

Standards and compliance

  • Our controls are designed in line with the ISO 27001 information security standard
  • Our handling of cardholder data is designed in line with the PCI DSS technical requirements, and card processing is carried out by PCI compliant service providers
  • We meet our obligations under the UK GDPR and the Data Protection Act 2018, and put the UK International Data Transfer Agreement or Addendum, or the European Commission's standard contractual clauses, in place with customers, partners and suppliers where a restricted transfer requires them

Where we say our controls are designed in line with a standard, we mean we have adopted the practices that standard describes, not that we hold a certification against it. Channex is not itself certified to ISO 27001 or PCI DSS. Our infrastructure and payment providers do hold their own certifications, and their current status is available on request from support@channex.io.

What data do we store?

Channex stores the data needed to operate the platform: information about your organisation, its properties and its users, and the booking data that must pass between your systems and the channels you connect. We store only what the Services require, and we process booking and guest data as your processor, on your instructions — see the Data Protection Addendum in Section 21 of the Customer Agreement.

For authentication:

  • Usernames and email addresses, and credentials stored as salted hashes

For channel management:

  • Property details — name, address, contact email, facilities, images, room types, rate plans, availability, prices and restriction data
  • Booking data — including, where present, the booker's name and address, guest names, and payment card details

Physical security

Physical security is provided by our infrastructure providers, Amazon Web Services and DigitalOcean, at their own facilities. Channex personnel have no physical access to those facilities. The providers' data centres hold current certifications to major information security standards, including ISO 27001 and PCI DSS, and their published controls include:

  • Multi-factor access control, including keycard and biometric protocols, with continuous interior and exterior surveillance
  • Access restricted to authorised data centre personnel, with prior clearance and escort required to enter a production area
  • Background screening of data centre staff
  • Redundant power and cooling, including N+1 UPS and HVAC

Current certifications and audit reports for each provider are published by them, and we can point you to the relevant documents on request.

Process and policy

The first layer of defence is a defined set of security processes. Channex applies a number of process and policy measures that keep security a priority at our most important layer — our people.

Change control

A formal change control process reduces the risk associated with system changes. It tracks changes made to our systems and verifies that risks have been assessed, inter-dependencies explored, and the necessary policies and procedures considered and applied, before any change is authorised.

Training

Channex employees authorised to access the platform undergo periodic training on compliance with our security policies. Personnel who may handle sensitive customer data receive regular training covering security, auditing, access control and data protection compliance.

Authorised access

Operational access to production systems is limited to a restricted set of Channex operations personnel who need it for their role. Access requires individual named credentials with multi-factor authentication, is granted on a least-privilege basis, is reviewed periodically, and is revoked promptly when someone changes role or leaves. Administrative access is separated from general employee systems, and privileged actions are logged for audit.

Infrastructure

Between the hosting layer and the Channex application layer sits the infrastructure that supports the platform. Security is applied consistently across it.

Firewalls

All network access to our virtual hosts is protected by a multi-layered firewall operating in deny-all mode. Inbound access is permitted only on explicitly opened ports, and only to the hosts that require it. Database servers sit behind an additional firewall and are not reachable from the internet.

Networking

Platform servers are allocated to security groups with specific network-level settings, supplemented by stateful firewalls at the individual instance level. Separate private networks segregate production, testing and development environments, and separate end-user traffic from administrative traffic.

Traffic is segregated across three tiers — the public-facing application tier, the internal service tier, and the data tier — with access between them permitted only on explicitly opened ports.

Encryption

Data transmitted between you and the platform, and between the platform and connected channels, is encrypted in transit using TLS. Data at rest is encrypted using the encryption facilities provided by our hosting providers.

Systems hardening

The platform uses a number of coordinated technologies, and many capabilities they ship with are not required. Consistent with industry practice, we review the stack to identify unnecessary services and remove or disable them, reducing the surface available to an attacker.

No root access

All customer access to the platform is through our user interface, our APIs and dedicated tools, each requiring authentication with privileges appropriate to the request. Customers do not have root or administrative access to any part of the underlying technology stack; access is only ever via the application layer.

Unnecessary ports closed

As described under Firewalls, any port on any server or virtual host that is not required for the operation of the platform is disabled.

Security patches

We have policies and procedures in place to keep all components of the platform — operating systems, hypervisors, middleware, databases and application dependencies — updated with their vendors' security patches.

Data retention

Customer data is not stored for longer than it is needed. We require data about properties, bookings and users in order to operate the platform, and we remove it according to the schedule below, or earlier on request.

Data is also removed if it becomes out of date or no longer valid. This can happen through the removal of a connected service, the termination of an account, or other events originating from connected service providers.

While an account is open:

  • Availability, rate and restriction data is removed for past dates daily.
  • Credit card information is held until 7 days after the booking departure date, then deleted.
  • Bookings are deleted once they reach 2 years after the departure date.

After an account is cancelled or terminated:

  • Account data — usernames, credentials, properties, channels and bookings — is deleted within 30 days of cancellation, or sooner on request. The 30-day window exists so that data can be exported during the period described in Section 13.7 of the Customer Agreement.
  • Where the retention rules above would give different answers, the shorter period applies: cancelling an account deletes its bookings within 30 days, regardless of departure date.
  • We retain the minimum data the law requires us to keep — for example invoice records for seven years, and guest registration information where it must be provided to local health and safety or police authorities — until that obligation expires. Retained data is isolated and protected from further processing.
  • Data held on backup media is deleted on the normal backup rotation cycle, and is not restored into production after an account is deleted.

Reporting a vulnerability

If you believe you have found a security vulnerability in the Channex platform, please report it to support@channex.io. We will acknowledge your report and keep you informed while we investigate. We will not pursue a good-faith researcher who reports a genuine issue promptly and does not access, alter or retain other customers' data.

In summary

A mature security posture needs coordinated attention across technology, policy, procedure and people. The risk-based approach described here is intended to give strength at every layer, and to be clear about where our responsibilities end and our providers' begin.

If you are evaluating Channex and need more detail — a completed security questionnaire, provider audit reports, or the subprocessor list — email support@channex.io and we will help.

Questions About Our Policies?

If you have any questions about these terms and policies, please contact us at support@channex.io. Formal notices under the Customer Agreement must also be sent to that address.