Axis Pro legal
Last updated Sep 20, 2026
On this page
- 1. Purpose & Scope
- 2. Information Asset Classification
- 3. Access Control
- 4. Data Protection & Encryption
- 5. Network & Infrastructure Security
- 6. Incident Response
- 7. Guest Data & Booking Channel Integration Security
- 8. Personnel Security & Training
- 9. Third-Party & Vendor Security
- 10. Policy Governance & Compliance
This Policy is published in three full-text language versions within this document: English, Español, and Português. Each version applies in full.
This Policy applies to all Aloha Systems Corp. employees, contractors, interns, and third parties with access to Axis Pro systems or data.
1. Purpose & Scope
This Information Security Policy ("Policy") establishes the framework, responsibilities, and minimum standards for protecting the confidentiality, integrity, and availability of information assets owned, processed, or handled by Aloha Systems Corp. in connection with Axis Pro (the hospitality management platform formerly known as "Aloha Pro" or "Alojate Pro"). This Policy applies to all personnel (employees, contractors, interns, partners) and all systems, networks, and data used in connection with Axis Pro, including the Property Management System, Channel Manager, AI Co-Manager, Spaces module, APIs, Client data, and Guest data.
This Policy is designed to be consistent with and support Aloha Systems Corp.'s obligations under: the Axis Pro Master Subscription Agreement and Axis Pro Terms and Conditions with Clients; the Axis Pro Privacy Policy; applicable data protection law, including the GDPR, the LGPD, and Chilean Law No. 19,628 and Law No. 21,719; and internationally recognized security standards including the NIST Cybersecurity Framework (CSF) and ISO/IEC 27001 principles. This Policy does not govern the payment processing systems operated by Aloha Pay, which maintains its own information security policy.
2. Information Asset Classification
All information assets handled in connection with Axis Pro are classified into the following tiers:
| Level | Includes | Handling Requirement |
|---|---|---|
| Restricted | API keys, passwords, encryption keys, Guest PII (including identification or passport numbers collected for check-in or legal compliance), payment metadata visible within Axis Pro | Encrypted at rest and in transit. Access by role-based authorization only. Logs all access. |
| Confidential | Client and Property data, business strategy, MSA and Order Form terms, pricing, source code, internal financial data | Need-to-know access. Confidentiality obligations apply. Secure disposal required. |
| Internal | Internal procedures, employee data, operational communications | Available to Aloha Systems Corp. personnel only. Not shared externally without authorization. |
| Public | Website content, product descriptions, published policies | No special handling required. |
3. Access Control
Role-Based Access Control (RBAC). Access to Axis Pro systems and data is granted based on job function and the principle of least privilege. Access rights are reviewed quarterly and revoked immediately upon role change or termination.
Multi-Factor Authentication (MFA). MFA is required for all personnel accessing production systems, the Client dashboard, and any system containing Restricted or Confidential data.
Password Standards. Passwords must be at least 14 characters, include upper/lowercase letters, numbers, and special characters. Passwords must not be shared. An approved password manager must be used for all system credentials.
Third-Party Access. Vendors, contractors, and third parties (including Clients accessing via API, and connected Booking Channels) receive only the minimum access necessary. Third-party access agreements must include confidentiality and security obligations equivalent to this Policy.
4. Data Protection & Encryption
Encryption at Rest. All Restricted and Confidential data stored in Axis Pro systems must be encrypted using AES-256 or equivalent. Databases containing Guest identification data must use field-level encryption for sensitive fields.
Encryption in Transit. All data transmitted over public networks must use TLS 1.2 or higher. API and Channel Manager communications must use HTTPS/TLS. Unencrypted transmission of Restricted or Confidential data is prohibited.
Data Minimization. Aloha Systems Corp. collects only the data necessary for the provision of Axis Pro, compliance with applicable law, and fraud and abuse prevention. Data that is no longer required must be securely deleted in accordance with the retention schedule below.
Retention Schedule. Reservation and stay records: retained as required by applicable hospitality registration and tax record-keeping obligations, and as further described in the Axis Pro Privacy Policy. Guest PII: retained only as long as necessary for the purposes described in the Axis Pro Privacy Policy; deleted upon a valid request except where retention is required by law. Audit logs: 3 years minimum.
5. Network & Infrastructure Security
Network Segmentation. Production infrastructure must be isolated from development, staging, and corporate networks. Firewall rules must implement a default-deny policy with explicit allow rules for required traffic only.
Vulnerability Management. Security patches for operating systems and critical applications must be applied within 30 days of release (critical patches within 7 days). Aloha Systems Corp. will conduct at minimum annual penetration testing of Axis Pro and its API infrastructure.
Monitoring and Logging. Aloha Systems Corp. maintains security event logs for all access to production systems, reservation data, and administrative actions. Logs must be stored in a tamper-evident manner and reviewed regularly for anomalous activity.
Cloud Security. All cloud infrastructure used to operate Axis Pro must comply with SOC 2 Type II or equivalent standards. Aloha Systems Corp. will maintain documentation of cloud service provider security certifications for key infrastructure providers.
6. Incident Response
Aloha Systems Corp. maintains an Incident Response Plan (IRP) that governs the detection, containment, investigation, and notification procedures for security incidents. The following summarizes key obligations:
Reporting. All personnel must report suspected security incidents immediately to security@axispro.travel. Incidents involving Restricted data must be escalated to the CEO and legal counsel within 2 hours of detection.
Client Notification. In the event of a confirmed security incident materially affecting Client or Guest Data, Aloha Systems Corp. will notify affected Clients without undue delay and in any event within 72 hours of confirmation, consistent with Section 9 (Security) of the Axis Pro Privacy Policy and subject to any limitations required by law enforcement.
Post-Incident Review. A root cause analysis and lessons-learned report must be completed within 30 days of any significant security incident. Remediation actions must be tracked to closure.
7. Guest Data & Booking Channel Integration Security
The following controls apply specifically to the reservation and integration functions that distinguish a hospitality management platform:
Channel Manager Integration Security. Connections with Booking Channels use authenticated, rate-limited API keys and webhook signature verification to prevent unauthorized modification of availability, pricing, or reservation data. Anomalous synchronization patterns (such as sudden mass cancellations or price changes) trigger automated alerts for compliance and engineering review.
Property and User Verification. Aloha Systems Corp. applies identity and business verification checks at onboarding to reduce the risk of a Property being registered by an unauthorized party or of a User account being used to impersonate a legitimate hospitality business.
Account Takeover Prevention. Aloha Systems Corp. monitors User accounts for anomalous login patterns, credential stuffing, and unauthorized access attempts, applying step-up authentication and temporary holds where warranted, to protect Guest data and prevent unauthorized redirection of reservations or Payments.
Guest Identification Data. Identification and passport data collected for check-in or legal compliance purposes is treated as Restricted data under Section 2 and is accessible only to the Property's authorized Users and to Aloha Systems Corp. personnel with a legitimate operational need.
Payments Interface. Where Client enables Payments through Aloha Pay or another provider, Axis Pro does not store full payment card numbers; sensitive payment credentials are collected and processed directly by the payment provider, consistent with Section 3(c) of the Axis Pro Privacy Policy.
8. Personnel Security & Training
Background Checks. All Aloha Systems Corp. employees and contractors with access to Restricted or Confidential data must complete a background check prior to access being granted.
Security Training. All personnel must complete security awareness training upon onboarding and annually thereafter, covering phishing recognition, password hygiene, data handling, and incident reporting.
Clean Desk & Screen Lock. Personnel must not leave Restricted or Confidential data visible and unattended. Workstations must auto-lock after 5 minutes of inactivity.
Offboarding. Upon termination of employment or engagement, all access rights must be revoked within 2 hours. Equipment must be returned and accounts deprovisioned on the termination date.
9. Third-Party & Vendor Security
All third-party vendors and service providers with access to Axis Pro systems or data must demonstrate adequate security controls before engagement. This includes: execution of a confidentiality and data processing agreement; annual review of the vendor's SOC 2 report or equivalent; and a contractual right for Aloha Systems Corp. to audit vendor security controls. Booking Channels, Aloha Pay, and other payment providers are subject to additional due diligence appropriate to the nature and volume of their access.
10. Policy Governance & Compliance
This Policy is owned by Aloha Systems Corp.'s CEO and Legal/Compliance function. It is reviewed annually and updated as required to reflect changes in the threat landscape, applicable law, or Axis Pro's operations. Violations of this Policy may result in disciplinary action, termination of engagement, and/or legal consequences depending on severity.
Compliance with this Policy is mandatory for all personnel and third parties within its scope. Personnel who become aware of a potential violation must report it immediately to security@axispro.travel or to the CEO. Aloha Systems Corp. will not retaliate against any person who in good faith reports a security concern.
Policy Owner: CEO / Legal & Compliance, Aloha Systems Corp. | Version 1.0 | September 2026 | Next review: September 2027
Governing Language: This Policy is published in English, Spanish, and Portuguese. In the event of any conflict or inconsistency among versions, the English version shall prevail.





