Joffrey — Digital Concierge

Privacy Policy

Effective date: September 2026

This privacy policy describes how the Joffrey – Digital Concierge Chrome extension (“the Extension”), operated by The Capital Hotels Group (Pty) Ltd (“we”, “us”, “our”), collects, uses, and protects information when you use the Extension in connection with a supported Property Management System (“PMS”).

Service availability

The Extension is not a free or publicly available tool. It is a commercial service provided exclusively to registered clients of The Capital Hotels Group who have entered into a service agreement with us. The Extension will only function at properties where the required Joffrey backend systems have been deployed and configured. Unauthorised users cannot access the Extension's features — authentication is enforced via Azure Active Directory, and access is limited to staff at subscribed properties.

Who this policy applies to

This policy applies to authorised hotel staff at client properties where the Joffrey service has been activated. The Extension is not intended for use by the general public. If you are a hotel guest, your personal data is governed by the property's guest privacy notice, not this policy.

What we collect

The Extension processes the following categories of information:

How we use your information

We use the information described above solely to:

Payment card data

The Extension facilitates the capture of payment card references for operational purposes. No full card numbers, CVVs, or sensitive authentication data are stored locally in the browser or in chrome.storage. Card data handling is performed server-side in accordance with applicable PCI DSS requirements.

Data storage and security

Local data stored via chrome.storage is limited to non-sensitive session preferences and cached form state. All operational and guest data is transmitted over HTTPS to the Joffrey backend API, hosted on Microsoft Azure infrastructure. Access is secured via Azure AD authentication, and data at rest is encrypted using Azure-managed encryption.

Data sharing

We do not sell, rent, or share personal data with third parties for marketing or advertising purposes. Data may be shared with:

Data retention

Locally stored session data (chrome.storage) is cleared when the Extension is uninstalled or when the user signs out. Server-side operational data is retained in accordance with The Capital Hotels Group's data retention policies and applicable legal requirements.

Your rights

If you are a staff member and wish to access, correct, or request deletion of your personal data, or if you have any questions about this policy, please contact us using the details below. Where the Protection of Personal Information Act (POPIA) or other applicable data protection legislation applies, we will process your request in accordance with those requirements.

Remote code

The Extension loads configuration data and UI components from the Joffrey backend API to ensure property-specific workflows remain current. Remote code is fetched exclusively from our own authenticated API endpoints. No third-party scripts are loaded at runtime.

Changes to this policy

We may update this policy from time to time. Material changes will be communicated via the Extension or through internal channels. The effective date at the top of this page reflects the most recent revision.

ContactThe Capital Hotels Group (Pty) Ltd
Email: itsupport@thecapital.co.za