Who we are
Welcomeframe is a service operated by NEW INN HOTEL LIMITED, whose registered office is at 14 Market Street, Ellon, Aberdeenshire AB41 9JD. In this policy, “we”, “our” and “us” mean NEW INN HOTEL LIMITED, and “you” means the person using the service.
For the purposes of the UK General Data Protection Regulation and the Data Protection Act 2018, NEW INN HOTEL LIMITED is the controller of the personal data described below. Where the EU General Data Protection Regulation applies to you, the same responsibilities apply to us under that regulation.
You can reach us about anything in this policy at support@newinnellonhotel.com or on +44 7222190682.
Your guests’ data never reaches us
This section comes before the rest because it is the most important thing in the document, and because it is unusual.
The films you make are personal to a specific arriving guest. They carry a name, a date, sometimes a room number and an entry code. Those details belong to your guest, not to you and not to us.
So the product is built so that we never receive them. When you type a guest’s name, an arrival date, a room number or a door code into the workspace:
- it is held in your browser’s session storage, on your own device, and is cleared when you close the tab;
- it is drawn onto the frame by your own browser, using the canvas in the page, at the moment of export;
- it is never transmitted to our servers, never written to our database, never included in a backup, and never sent to any model or third party.
The generated visuals contain no text at all — every word you see on a finished film is composed locally by the page. We designed it this way for two reasons. Generative models are unreliable at rendering exact characters, so a name or a door code could come back subtly wrong. And keeping guest details off our systems means using this product does not make you responsible for having handed your guests’ personal data to another company.
If you ask us to delete “everything about a guest”, there is nothing for us to find. That is by design, and it is the correct answer.
What we collect
Account data
- Email address.
- A password, stored only as a salted hash. We never see or store the password itself.
- A display name, if you choose to set one.
- The tier you are on, and the state of your subscription.
Content data
- Photographs you upload, and the confirmation that each one shows the place as it is.
- Notes you write about a property, a room or an arrival.
- Still frames and clips generated from those photographs.
- Shot orders and must-say lists produced by the ordering pass.
Billing data
- Your subscription tier, billing period, renewal date, and a record of successful and failed charges.
- Card details are entered on, and held by, our payment provider. Full card numbers never reach our servers and we cannot see them. We receive a token, the last four digits, the card brand and the expiry, which is what allows us to show you which card is on file.
- Invoices and the country you told us you are billed from, where tax requires it.
Technical data
- IP address, browser and device type, and operating system.
- Pages visited, actions taken, and errors encountered.
- Allowance usage: what was generated, when, and how much of the allowance it consumed.
Why we process it, and on what legal basis
| Purpose | Data | Lawful basis |
|---|---|---|
| Providing the service you signed up for | Account, content, technical | Performance of a contract |
| Taking payment and managing your subscription | Account, billing | Performance of a contract |
| Keeping records for tax and accounting | Billing | Legal obligation |
| Preventing abuse, fraud and unlawful use | Technical, content | Legitimate interests |
| Fixing faults and improving reliability | Technical, aggregated usage | Legitimate interests |
| Service emails you cannot opt out of, such as a failed payment | Account | Performance of a contract |
| Optional analytics and marketing cookies | Technical | Consent |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights and freedoms, and we have limited what we process accordingly. You can object to processing based on legitimate interests — see your rights.
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
Your photographs are not training data
Photographs and other content you upload are not used to train artificial-intelligence models. Not our own models, and not any third party’s foundation models. This is not a setting that defaults on: there is no path by which your content enters a training set.
Content is sent to our model providers only for the purpose of producing the output you asked for, under contractual terms that forbid its use for training. What we do keep for improving the service is aggregate operational signal that contains no image and no text you wrote: how often a generation failed, how long it took, which error codes occurred.
Who we share it with
We use a small number of processors, each for a specific job:
- Hosting and application infrastructure — running the site and storing your account and content data.
- Our payment provider — taking payment, holding card details, issuing invoices, and telling us whether a charge succeeded. We do not name the provider here because it may change; the current provider is shown at the point of payment, before you enter any card details.
- Model providers — generating still frames and putting approved frames into motion, under terms that prohibit training on your content.
- Email delivery — sending service messages such as a password reset or a renewal notice.
- Analytics — only if you have accepted analytics cookies.
We may also disclose data where we are legally required to, or where it is necessary to establish, exercise or defend legal claims, including responding to a payment dispute. If we are ever involved in a merger or acquisition, personal data may transfer with the business, and we will tell registered users before that happens.
How long we keep it
| Category | Kept for |
|---|---|
| Account data | Until you delete the account, then removed within 30 days |
| Uploaded photographs and generated output | Until you delete them or delete the account. Deletion removes them from active storage at once; operational backups clear within 30 days |
| Billing and invoice records | Seven years, because tax law requires it |
| Technical logs | 90 days |
| Abuse and security records | Up to 12 months, or longer where an investigation is open |
| Guest names, dates, room numbers, entry codes | Never held by us at all |
International transfers
We and our processors operate in more than one country, and your data may be processed outside the United Kingdom and the European Economic Area, including in the United States.
Where that happens, the transfer is covered by an adequacy decision, or by the UK International Data Transfer Addendum to the European Commission’s Standard Contractual Clauses, or by the Standard Contractual Clauses themselves, together with a transfer risk assessment and any supplementary measures that assessment calls for. You can ask us for a copy of the safeguards that apply to a particular transfer.
Your rights
Wherever you live, you can ask us to do all of the following:
- Access — get a copy of the personal data we hold about you.
- Rectify — correct anything inaccurate or incomplete.
- Erase — delete your data, subject to records we must keep by law.
- Restrict — pause our processing while a dispute about accuracy or lawfulness is resolved.
- Port — receive your data in a structured, commonly used, machine-readable format, or have it sent to another provider where technically feasible.
- Object — object to processing based on legitimate interests, and to direct marketing at any time and unconditionally.
- Withdraw consent — where processing relies on consent, withdraw it without affecting what was lawful before.
Write to support@newinnellonhotel.com. We answer within one month, and we will tell you if we need to extend that by up to two further months because a request is complex. We do not charge for this, and we will not ask you for more identification than we need to be sure who you are.
We do not use your data to make solely automated decisions that produce legal or similarly significant effects on you.
California residents
If you are a California resident, the California Consumer Privacy Act as amended gives you the right to know what categories of personal information we collect and why, to request a copy, to request deletion, to request correction, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of them.
We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined by that Act. We honour Global Privacy Control signals sent by your browser as a valid opt-out request, and where a GPC signal is present it overrides any earlier cookie opt-in on this device.
You may use an authorised agent to make a request. Contact us at support@newinnellonhotel.com.
Security
The site is served over HTTPS only. Passwords are stored as salted hashes. Access to production systems is limited to the people who need it and is logged. Card details are handled by our payment provider on infrastructure assessed against the Payment Card Industry Data Security Standard; we never receive a full card number, so there is none for us to lose.
No system is perfect. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office within 72 hours, and we will tell you directly where the risk is high.
Children
This service is for people running accommodation as a business. You must be at least 18 to hold an account. It is not directed at children, we do not knowingly collect personal data from anyone under 18, and if we learn that we have, we delete it. If you believe a child has given us personal data, write to support@newinnellonhotel.com and we will remove it.
Cookies
We set a strictly necessary cookie to keep you signed in and to protect forms against cross-site request forgery. Nothing else is set until you say so. Analytics and marketing cookies are off by default, rejecting is exactly as easy as accepting, and you can change your mind at any time on the cookie preferences page. The full list is in the Cookie Policy.
Changes to this policy
We will post any change here with a new effective date. Where a change materially affects how we handle your personal data, we will email registered users at least 14 days before it takes effect, so that you can object, export your data, or close your account first.
Contact and complaints
Write to support@newinnellonhotel.com, call +44 7222190682, or post to NEW INN HOTEL LIMITED, 14 Market Street, Ellon, Aberdeenshire AB41 9JD. We would always rather hear from you first.
You also have the right to complain to a supervisory authority. In the United Kingdom that is the Information Commissioner’s Office, at ico.org.uk. If you are in the European Economic Area, you may complain to the supervisory authority in your country of residence, place of work, or the place where you think something went wrong. Complaining to a regulator does not stop you also raising the matter with us.