Skip to content

Privacy Policy

BlueFunnel Systems · BFS Hotelier · a Designblue product

Last updated: 30 September 2026

This page explains what we do with personal information. It covers three different situations, because we sit in a different position in each one.

You might be someone looking at this website or sending us an enquiry. You might be a hotel or resort using a system we built and host. Or you might be a guest who booked a room on a hotel's website that we built. Skip to the part that's you.

1. Who's responsible for what

We're Designblue Philippines Inc., a registered Philippine company with its office in Salcedo Village, Makati City. BlueFunnel Systems and BFS Hotelier are our brand names.

For this website and for enquiries you send us, we're the one responsible for your information. The law calls that the Personal Information Controller.

For the guest records inside a system we built for a hotel, the hotel is responsible and we only handle the information on their instructions. The law calls that the Personal Information Processor. It matters because it decides who you talk to, and each section below says which we are.

2. If you send us an enquiry

We're the one responsible for everything in this section.

What we collect. Your first name, your last name, your mobile number, your email address, your hotel's name, and anything you write in the notes box. You tick a box to confirm you're happy for us to have it, and you can tell us at any time to stop using it and delete it.

Why. To send you a confirmation, to reply to you, and to agree a time for a call. That's all.

Who sees it. The people here who handle enquiries. We don't sell it and we don't rent it. We use it to reach you, so our email service carries your confirmation and we message you on Viber to agree a time. Nobody else gets what you send us.

How long we keep it. Twelve months from the last time we spoke, and then we delete it. Hotels often enquire in one season and decide in the next, so twelve months covers a full year of that without us sitting on your details forever. Ask us to delete it sooner and we will.

No mailing list. We don't put you on one, and we don't send marketing emails. If you hear from us, it's because you asked us something.

3. What this website itself collects

We're the one responsible for everything in this section too.

No analytics, no advertising trackers. We don't use Google Analytics and we carry no advertising or tracking code. We don't set cookies of our own. Google reCAPTCHA, described next, may set cookies or use your browser's storage, and that's Google's doing rather than ours.

Google reCAPTCHA. Our Book a Free Call form and our homepage use Google reCAPTCHA to keep out spam robots. It runs whether or not you send the form. Google receives information about your device and how you interact with the page, and Google handles that under its own privacy policy, at policies.google.com/privacy, rather than this one.

Server records. Like any website, ours keeps standard technical records of visits, such as the internet address a request came from, the page asked for and the time. They're there to keep the site running and secure, and we keep them only as long as they're useful for that.

4. If your hotel uses a system we built

This section is for hotel and resort owners. Your guests' information is yours to answer for, and we hold it only to run the services you pay for, on your instructions.

What we hold for you. Your booking records, and the guest details your booking form collects: normally a name, an email address, a mobile number, the dates of the stay, the room and the rate, and anything a guest writes in a request box. You decide what your form asks for, so if it asks for more than that, that sits in your records too.

Where it's held. Your site and your data sit on managed servers we look after for you, not on a machine in your hotel. Some of the services we use to run your site are based outside the Philippines, so some information is stored or handled abroad. If where we hold your data has to change, we'll tell you in writing first.

Who here can see it. Access is limited to the people who need it to do the work: the Managing Director, the Operations and Strategy Lead, and the technical staff assigned to your account. We don't sell guest data, we don't share it with other clients, and we don't use it to train anything.

The AI assistants. On the Care Plan, the guest AI assistant on your site and the admin AI assistant in your dashboard send what they need to answer a question to an AI provider, and no more. That provider is likely to be outside the Philippines, so some information is handled abroad. We don't use guest information to train anything. If you'd rather nothing went to an AI provider at all, the only way to avoid it is to go without the Care Plan, and your site runs perfectly well without the assistants.

Other companies in the chain. The channel manager that carries your booking platform sync, and the payment platform named on your quote. Card details are handled by that payment platform rather than by us.

Getting your records out. Your dashboard has an export button. It costs nothing, it doesn't depend on the state of your account, and it works for as long as your site is hosted with us, including the 30 days your site stays live after your last paid day. If your site is already offline and you still need your records inside the 60 days below, ask us in writing and we'll send you a copy of your database.

How long we keep it. We keep your data for 60 days from the day your services end, and then we delete it. If you ask us in writing to delete it sooner, we will, and we'll confirm when it's done. Otherwise we'll tell you in writing before we delete anything, and we keep only what the law requires us to keep.

If something goes wrong. If we find out about a security incident affecting your guest data, we'll tell you within 72 hours of knowing, and sooner where we can. We'll tell you what we know and help you with the notifications you have to make. Under Philippine law those notifications are yours to make, and where the law requires them they go to the National Privacy Commission and to the guests affected within 72 hours of when you know, with a fuller report to the Commission within five days. Your clock starts when you know, so the sooner we reach you the more of it you have.

5. If we also make your social content, and how we reach you

Social media content. Each month you put your raw photos and clips into a shared cloud folder, and we put the finished posts back in it. Those photos often show guests and staff. We use them to make your content and for nothing else, only the people working on your account can open the folder, and we never publish anything ourselves.

How we talk to you. We reach you by email, and on Viber or WhatsApp. Those services carry whatever we send through them, under their own terms.

Your account details. To set up your payments we ask for the paperwork and access details the platform needs. We ask for the least we can work with, only the people setting it up can see it, and it stays in your own account rather than becoming ours.

Your own team. We hold your team's dashboard logins and the name of the person who can approve work, so the system runs and so we know whose yes counts.

6. If you're a hotel guest

You booked on a hotel's own website. Your booking is with that hotel, and the hotel decides what information is collected and what it's used for. We built and we host the system for them.

Ask the hotel first. If you contact us instead, we'll tell you to go to the hotel, and we'll pass your request on so it isn't lost. We don't change or delete a hotel's records on our own, because those records aren't ours to decide about. We do act when the hotel instructs us to, and when the law or the National Privacy Commission requires it.

7. Your rights

Under the Data Privacy Act of 2012 you have the right:

1.  To be told what information is held and why.

2.  To see a copy of it.

3.  To have it corrected if it's wrong.

4.  To object to it being used.

5.  To have it erased or blocked, where the law allows.

6.  To get a copy in a form you can take elsewhere.

7.  To be compensated for harm caused by information that's inaccurate or used unlawfully.

Where you gave us your information yourself, you can also withdraw that at any time.

To use any of these, email us at the address below. If your request is about a hotel's guest records, we'll pass it to that hotel and tell you we've done so, because they're the ones who decide.

We'll answer within five working days. If a request needs longer than that, we'll tell you why and how long it will take.

8. Keeping information safe

Access is limited to the people named in section 4. Information travels between you, your guests and our servers over an encrypted connection. We keep the software behind your site up to date, and we work with hosting and service providers that maintain recognised security practices.

No system anywhere is completely safe, and we won't pretend otherwise. What we commit to is keeping the number of people who can reach your data small, keeping what we run patched, and telling you quickly when something has gone wrong.

9. If you're not happy

Tell us first and we'll try to sort it out. You can also complain to the National Privacy Commission, which is the government body that oversees this in the Philippines.

10. Changes to this page

We may update this page, and the date at the top tells you when it last changed. If a change has a real effect on a hotel client, we'll tell you in writing 60 days before it applies, the same notice your service agreement gives you.

11. How to reach us

Designblue Philippines Inc., trading as BFS Hotelier

Salcedo Village, Makati City, Philippines

Privacy questions are handled by our Data Protection Officer, at bluefunnelsystems@gmail.com. We don't publish their name here. Ask us for it and we'll tell you, and we'll tell the National Privacy Commission if they ask.

Last updated: 30 September 2026