Skip to content

Retail, hospitality & leisure

Hotel data backups that keep bookings, guests and tills recoverable

Mindtime backs up the back-office server, till database, front-desk laptops and Microsoft 365 or Google Workspace your hotel or restaurant runs on, to its own Tier III data centres in the Netherlands and Germany, with immutable and air-gapped copies.

In Dutch, German or English.

Shop interior with products on display
  • NL · DEStored only in our own Tier III data centres in the Netherlands and Germany
  • ImmutableObject Lock storage plus an air-gapped copy; every backup job is checked
  • ISO 27001 · NEN 7510Audited security, with a data processing agreement in every contract
  • NL · DE · ENSupport from people, no offshore call centres or chatbots

In short

Hotels and restaurants need off-site backups because the guest register must be shown on request, the Belastingdienst expects seven years of till data stored off-site, and ransomware can stop check-in and payments at once. Mindtime keeps immutable, checked copies of servers, laptops and mailboxes in its own Dutch and German data centres.

What's at stake

The data restaurants and hotels can't afford to lose

  • Reservations and guest profiles

    Bookings from your website, Booking.com and the phone, plus guest preferences and deposits, live in the PMS or reservation system. If they vanish on a Friday afternoon, nobody knows who is arriving.

  • The nachtregister

    Every paid overnight stay must be registered with the guest's name, place of residence and arrival and departure dates. Police and municipal officers can ask to see it, so a lost register is a legal problem as well as an operational one.

  • Till journals, invoices and allergen sheets

    Each order rung up in the restaurant or bar is a tax record, and your recipe and allergen files are what staff rely on when a guest asks about nuts or gluten. Both need to stay complete and readable.

Rules and obligations

What the rules ask of restaurants and hotels

Summarised from the sources listed at the bottom of this page. This is general information, not legal advice.

  1. Keep a guest register (nachtregister)

    Article 438 of the Dutch Criminal Code requires anyone offering overnight stays for payment to keep a register. Municipal rules such as Schiedam's APV list the details: name, place of residence, arrival and departure dates and the type of ID shown. The ID document itself may not be copied or kept, and police or municipal enforcement officers (BOAs) can ask to see the register. [1]

  2. Seven years of till data, held off-site

    According to the Belastingdienst's guidance on reliable till systems, transaction data must remain complete and readable for seven years and may not be condensed. The same guidance states that, because of possible calamities, it must be kept off-site. [3]

  3. Allergen information on record

    Restaurants serving unpackaged food must inform guests about 14 allergens. Even when staff tell guests verbally, the NVWA requires the information to be available in writing or electronically for staff and inspectors, which makes your allergen files records worth protecting. [4]

  4. Report guest data breaches within 72 hours

    Guest records hold contact details, ID information and sometimes payment data. If ransomware or a lost laptop exposes or locks them, the Autoriteit Persoonsgegevens expects a report within 72 hours of discovery. [6]

  5. NIS2: hospitality is not a listed sector

    Accommodation and restaurants are not among the NIS2 sectors that the Dutch Cyberbeveiligingswet covers since 15 August 2026; the food sector entry concerns wholesale and industrial food production and leaves out food service. For micro and small businesses outside the listed sectors, the rules in principle do not apply. [8]

When it goes wrong

Ransomware on a Saturday morning

Illustrative example: a family-run hotel with a restaurant opens the back office on a Saturday morning to find the reservation server and the shared drive encrypted, with a ransom note on screen. The front desk works from printed arrival lists while the owner calls for help. Because the backups are immutable and an air-gapped copy exists, the attacker could not alter them; the server is restored from the last clean backup into an isolated environment, scanned, and then returned to service. The owner reports the incident to the Autoriteit Persoonsgegevens and fills any gap in the nachtregister and till records from paper notes and the payment terminal's overview.

How Mindtime protects it

Backup for restaurants and hotels, workload by workload

The software you use, and what we protect around it

MewsMews is a cloud property management system. Check the supplier's export and retention terms for reservations and guest profiles; Mindtime protects the Microsoft 365 or Google Workspace mail, files and front-desk laptops around it.
unTillunTill offers a cloud version (unTill Air) as well as set-ups with hardware in the venue. If your till back office runs on a PC or server on site, Mindtime backs up that machine and its data.
Zenchef (formerly Formitable)Restaurant reservations run as a service here. Export reservation and guest lists regularly to SharePoint, OneDrive or Google Drive, which Mindtime backs up.
Booking.com and other OTA extranetsBookings from online travel agencies are held in their extranet and your channel manager. The confirmation emails in your reservations mailbox are often the quickest way to reconstruct a day, and Mindtime backs up that mailbox.
HACCP and allergen filesMany kitchens keep temperature logs, cleaning lists and allergen sheets in Excel or Word. On a laptop, in OneDrive or on a NAS, they are covered by Mindtime's endpoint, Microsoft 365 and NAS backups.

Before you switch

What restaurants and hotels ask us first

  • Our PMS is in the cloud, so the supplier handles backups.

    The supplier protects its platform; the contract decides what you can recover and for how long, so check those export and retention terms. What usually sits outside the PMS, such as the reservations mailbox, event contracts, the till back office and front-desk laptops, is exactly what Mindtime backs up.

  • We have no IT department.

    You do not need one. Mindtime checks every backup job and monitors around the clock, and when you need help you speak to a person in Dutch, German or English, never a chatbot or an offshore call centre. If you work with a local IT partner, they can manage Mindtime for you from a multi-tenant console.

  • Is guest data stored outside Europe?

    No. Backups are stored only in Mindtime's own Tier III data centres in the Netherlands and Germany, encrypted with AES-256 in transit. A data processing agreement, which the GDPR (AVG) requires anyway, comes with every contract.

FAQ

Questions about backup for restaurants and hotels

What hotel data should be backed up first?

Start with what you cannot recreate: reservation and guest data, the nachtregister, till and invoice records, the reservations mailbox, and contracts for events and groups. Then add the front-desk and office laptops and any server or NAS on site. For cloud systems, check the supplier's export options and keep regular exports in a location that is backed up.

May a hotel copy guests' passports for the register?

No. Dutch municipal guidance says the register records name, place of residence, arrival and departure dates and the type of ID shown, but the ID document itself may not be copied or kept. That keeps the register small, yet it must still be available whenever police or enforcement officers ask, so protect it like any other business record.

Does PCI DSS apply to my hotel or restaurant?

If you store, process or transmit cardholder data, yes: that is the scope set by the PCI Security Standards Council. Hotels that keep card details to secure bookings and venues with payment terminals are typical cases, and your payment provider can tell you which requirements apply. Backups do not replace those measures, but they make sure the systems around your payments can be restored.

What does a ransomware attack mean for a hotel?

Check-in, room allocation, the till and the reservations mailbox can all stop at once. Recovery depends on a copy the attacker could not reach or change. Mindtime's backups are immutable, with a separate air-gapped copy; they are scanned for malware and restored into an isolated environment first. If guest data was affected, the Autoriteit Persoonsgegevens expects a report within 72 hours.

Do hotels and restaurants fall under NIS2?

Usually not. Accommodation and food service are not among the sectors in NIS2 Annexes I and II, which the Dutch Cyberbeveiligingswet implements from 15 August 2026, and micro and small businesses outside those sectors are in principle out of scope. The GDPR, the tax rules and the nachtregister duty still apply, and they all assume you can produce your records.

Can you back up a group of hotels or restaurants?

Yes. Each location's servers, laptops and NAS can be added to one account next to a central Microsoft 365 or Google Workspace tenant. Groups that must keep running if the main server room fails can add Mindtime Disaster Recovery: standby infrastructure, a first test failover typically within 10 days, and quarterly DR tests after that.

See it with your own data

Book a 15-minute demo

We show you a backup and a restore, and answer your questions in Dutch, German or English. No offshore call centres, no chatbots.