1import{jsxRuntimeExports as e,Helmet as t}from"./react-vendor-Cl5BoUFb.js";import{Header as i}from"./Header-BZn6RWTw.js";import{Alert as s,AlertDescription as o,Tabs as r,TabsList as a,TabsTrigger as n,TabsContent as l,Card as c,CardHeader as d,CardTitle as p,CardContent as u,Accordion as m,AccordionItem as h,AccordionTrigger as y,AccordionContent as g,Badge as f}from"./ui-vendor-CVwrz00e.js";import{Settings as x,FileText as b,Shield as v,Database as P,CircleHelp as j}from"./icons-vendor-BUK3cUnC.js";import"./main-OLIzgs0k.js";import"./index-YHYuFPvV.js";import"./query-vendor-Ct1xBef-.js";import"./analytics-lib-CvkHC-Ld.js";import"./nav-lib-tIVQ3Mlj.js";import"./video-modal-C9YG8PUQ.js";import"./feature-flags-lib-C1N11fmc.js";const N=[{id:"business-applicability",title:"Business Applicability",fields:[{id:"business-applicability-notes",label:"Business Applicability Notes",type:"notes",description:'Describe why your hotel qualifies as a "business" under the CCPA/CPRA. This populates the Notes column in the exported audit pack.',example:'"[Property Name] is operated by [management company], a for-profit entity doing business in California that collects personal information of California residents and exceeds $25M annual gross revenue. The property collects PI from guests during reservation, check-in, stay, and post-stay marketing."'},{id:"business-applicability-docs",label:"Business Applicability Supporting Docs",type:"docs",description:"Link to your hotel's corporate entity filing, business license, or a document confirming the revenue threshold. A URL to a privacy policy that identifies the legal entity also works.",tip:'A link to your privacy policy\'s "About Us" or entity disclosure section is the easiest option if you do not have a public filing.'}]},{id:"pi-scope",title:"PI Scope",fields:[{id:"pi-scope-notes",label:"PI Scope Notes",type:"notes",description:"Summarize the categories of personal information your property collects. Reference hotel-specific data categories.",example:'"Property collects identifiers (name, email, phone, address), financial information (credit card via PCI-compliant processor), commercial information (reservation history, folio charges), internet activity (website browsing via cookies), geolocation (IP-based), and inferences (guest preferences, loyalty tier)."'},{id:"pi-scope-docs",label:"PI Scope Supporting Docs",type:"docs",description:"Link to your ROPA export or Data Map page. Once exported from HotelComply, host the PDF and paste the link here.",tip:"You can export a ROPA summary from Dashboard â ROPA Builder. Host the PDF in Google Drive and share the link."}]},{id:"privacy-policy",title:"Privacy Policy Compliance",fields:[{id:"privacy-policy-notes",label:"Privacy Policy Compliance Notes",type:"notes",description:"Confirm your privacy policy covers the required CPRA disclosures and note the last review date.",example:'"Privacy policy at [URL] discloses: categories of PI collected, purposes of collection, consumer rights (access, delete, correct, opt-out), retention periods, and contact methods. Last updated [date]. Reviewed annually."'},{id:"privacy-policy-docs",label:"Privacy Policy Supporting Docs",type:"docs",description:"Your privacy policy URL. This should be the live public URL where guests can read the full policy."}]},{id:"opt-out",title:"Opt-Out Mechanism",fields:[{id:"opt-out-notes",label:"Opt-Out Mechanism Notes",type:"notes",description:"Describe how guests can opt out of the sale or sharing of their personal information.",example:"\"'Do Not Sell or Share My Personal Information' link is displayed in the website footer. GPC signals are honored automatically via cookie consent platform. Opt-out requests are logged in HotelComply and enforced across PMS and marketing systems within 15 business days.\""},{id:"opt-out-docs",label:"Opt-Out Supporting Docs",type:"docs",description:'Screenshot URL of the footer link, or the URL of your "Do Not Sell or Share" page.',tip:"A screenshot hosted in Google Drive works well if you do not have a dedicated opt-out URL."}]},{id:"vcr-protocol",title:"VCR Protocol (Identity Verification)",fields:[{id:"vcr-protocol-notes",label:"VCR Protocol Notes",type:"notes",description:"Describe your identity verification procedure for consumer requests. Auditors look for a documented process that prevents fraudulent access to guest data.",example:'"Consumer requests submitted via online form require confirmation number + last name + email match. Phone requests require confirmation number + last name + last four digits of payment card. Authorized agent requests require notarized power of attorney or written authorization signed by the consumer."'},{id:"vcr-protocol-docs",label:"VCR Supporting Docs",type:"docs",description:"Link to your internal SOP document or the HotelComply DSAR form URL."}]},{id:"training",title:"Training Program",fields:[{id:"training-notes",label:"Training Program Notes",type:"notes",description:"Document your staff privacy training cadence, audience, and delivery method.",example:'"All front desk staff and management complete a 30-minute CCPA/CPRA awareness training module covering consumer rights, DSAR intake procedures, and escalation to privacy contact. Training delivered via [method]. Refresher scheduled annually."'},{id:"training-docs",label:"Training Supporting Docs",type:"docs",description:"Link to your training materials, completion log, or LMS records.",tip:"A sign-in sheet or LMS completion export from your last training session is sufficient evidence."}]},{id:"security",title:"Security Controls",fields:[{id:"security-notes",label:"Security Control Notes",type:"notes",description:"Summarize the technical and organizational measures protecting guest PI.",example:'"Guest PI protected via encrypted PMS connections (TLS 1.2+), PCI-DSS Level 4 compliance for payment card data, role-based access controls in Opera limiting guest profile access to front desk and management, nightly encrypted backups, and documented incident response plan."'},{id:"security-docs",label:"Security Supporting Docs",type:"docs",description:"Link to your PCI-DSS attestation, security policy, or IT vendor security documentation."}]},{id:"nondiscrimination",title:"Nondiscrimination",fields:[{id:"nondiscrimination-notes",label:"Nondiscrimination Notes",type:"notes",description:"Confirm that guests who exercise privacy rights are not denied services, charged different rates, or given different loyalty benefits.",example:'"Loyalty program benefits are not conditioned on PI consent. Guests who exercise opt-out, deletion, or access rights retain full access to loyalty points, room upgrades, and member rates. No price differentials or service degradation for exercising CPRA rights. Reviewed annually."'},{id:"nondiscrimination-docs",label:"Nondiscrimination Supporting Docs",type:"docs",description:"Link to loyalty program terms or an internal review memo confirming no discriminatory treatment."}]}],S=[{id:"portability-format",label:"Portability Export Format",type:"input",description:"Choose the file format(s) used for data portability responses. For a hotel, CSV and PDF is the most practical â CSV for structured reservation and folio data, PDF for the response cover letter.",example:'"CSV and PDF"',tip:"If you use HotelComply's DSAR export, the default output is PDF. Note your actual format here."},{id:"portability-sample",label:"Portability Sample Export Link",type:"input",description:"Leave blank until you run your first DSAR export from Dashboard â DSAR Queue. Once generated, paste the file path or hosted link here as evidence.",tip:"Auditors may ask to see a sample export to verify the format is readable. A redacted example works fine."},{id:"portability-usable",label:"Portability output is readily usable",type:"toggle",description:"Toggle on when a guest can open and read the export without special software. CSV opens in Excel/Google Sheets; PDF opens in any browser. Both satisfy this requirement."},{id:"portability-portable",label:"Portability output is portable",type:"toggle",description:"Toggle on when the guest can transmit the data to another entity. CSV satisfies this requirement inherently by design."}
1,{id:"deletion-verification",label:"Deletion Verification Method",type:"input",description:"Describe how you confirm that data is actually gone after a deletion request is fulfilled.",example:'"Post-deletion search in Opera PMS by guest name and confirmation number. Vendor deletion confirmation emails archived in HotelComply. Spot-check in Revinate and loyalty platform."'},{id:"deletion-automated",label:"Deletion process documented",type:"toggle",description:"Toggle off for most hotels at this stage. If your DSAR workflow triggers documented deletion scripts across all systems, toggle on. Most properties handle deletion manually through PMS admin functions."},{id:"deletion-vendors-notified",label:"Service providers notified for deletion",type:"toggle",description:"Toggle on when a deletion request comes in and you notify each vendor listed in your ROPA that processes guest PI. This is a CPRA requirement when using service providers."},{id:"opt-out-type",label:"Opt-Out Type",type:"input",description:'Specify the type(s) of opt-out applicable to your property. "Do Not Sell or Share" is the standard CPRA opt-out. If you also handle GPC signals, note both.',example:'"Do Not Sell or Share My Personal Information; GPC signal honored"'},{id:"opt-out-restriction",label:"12-month restriction active",type:"toggle",description:"Under CPRA, once a guest opts out, you cannot ask them to reconsider for 12 months. Toggle on to confirm this restriction is in place."},{id:"opt-out-resoicitation",label:"Re-solicitation blocked",type:"toggle",description:"Once a guest opts out, no marketing re-solicitation should reach them until the 12-month window expires. Toggle on to confirm this suppression is enforced."},{id:"opt-out-expiration",label:"Opt-Out Expiration Date",type:"input",description:"Leave blank unless you have a specific opt-out request with a known date. When a real opt-out is logged, enter the date 12 months from the opt-out request.",tip:"This is per-request, not a global setting. Most operators leave this blank and track per-request dates in the DSAR queue."},{id:"deletion-notes",label:"Deletion Process Notes",type:"textarea",description:"Describe the full deletion workflow including exceptions, timeframes, system coverage, and service provider notification.",example:'"Deletion requests processed within 45 days. Guest PI purged from Opera PMS, Revinate, InfoGenesis, and loyalty platform. Service providers notified via email with confirmation number only (no guest PII shared in directive). Exceptions applied for active reservations, pending folios, legal holds, and fraud investigations per CPRA § 1798.105(d)."'},{id:"opt-out-notes-vcr",label:"Opt-Out Enforcement Notes",type:"textarea",description:"Describe how suppression is applied across systems and how long enforcement takes.",example:'"Opt-out requests honored within 15 business days. Guest record flagged in Opera PMS and Revinate to suppress marketing. GPC signals processed automatically via cookie consent platform. 12-month re-solicitation restriction enforced via CRM suppression list."'}],w=[{id:"5-1-policy",label:"5.1 â Compliance Processes and Procedures",type:"textarea",description:"One row per policy document, pipe-separated. Format: Policy | Location | Last Updated | Review Frequency | Status",example:["CPRA Privacy Policy|https://yourhotel.com/privacy|2026-01-15|Annual|Current","DSAR Response Procedure|Google Drive/Privacy/DSAR_SOP.pdf|2026-02-01|Annual|Current","Data Breach Response Plan|Google Drive/Privacy/Breach_Plan.pdf|2025-11-01|Annual|Current","Data Retention Policy|Google Drive/Privacy/Retention.pdf|2026-01-15|Annual|Current"].join("\n"),tip:"Each row becomes one line in the audit pack table. Blank lines are ignored."},{id:"5-2-training",label:"5.2 â Training Program",type:"textarea",description:"One row per training module, pipe-separated. Format: Module | Audience | Completion Rate | Last Delivered | Next Scheduled",example:["CCPA/CPRA Awareness|Front Desk Staff|100%|2026-01-20|2027-01-20","DSAR Intake Procedures|Front Desk + Management|100%|2026-01-20|2027-01-20","Privacy Incident Reporting|All Staff|85%|2026-01-20|2027-01-20"].join("\n")},{id:"5-4-security",label:"5.4 â Security Measures",type:"textarea",description:"One row per control, pipe-separated. Format: Control | Implementation Status | Responsible Party | Last Assessment | Notes",example:["PCI-DSS Compliance|Implemented|IT Manager|2025-12-01|Level 4 merchant; SAQ-A-EP completed","Access Controls (Opera)|Implemented|Front Office Manager|2026-01-15|Role-based; GM + FD only access guest profiles","Encrypted Data Transmission|Implemented|IT Manager|2025-12-01|TLS 1.2+ for all PMS connections","Incident Response Plan|Documented|General Manager|2026-02-01|72-hour notification procedure documented","Data Backup & Recovery|Implemented|IT Manager|2025-12-01|Nightly encrypted backups; 30-day retention"].join("\n")},{id:"5-5-nondiscrimination",label:"5.5 â Nondiscrimination Review",type:"textarea",description:"One row per reviewed element, pipe-separated. Format: Element | Compliant Yes/No | Evidence | Last Review | Notes",example:["Loyalty Program|Yes|Program terms do not condition benefits on PI consent|2026-01-15|No price differentials for exercising rights","Room Rate Pricing|Yes|Rates are not affected by privacy preference|2026-01-15|Verified in Opera rate configuration","Service Quality|Yes|Service standards apply regardless of privacy elections|2026-01-15|Front desk SOP reviewed","Financial Incentives|Yes|No financial incentive programs tied to PI collection|2026-01-15|N/A - no such programs active"].join("\n")}],C=[{id:"dpa-retention",label:"Retention/use/disclosure limits included",type:"toggle",description:'Confirm that your executed DPAs contain language such as: "shall not retain, use, or disclose personal information for any purpose other than performing the services." This restricts vendors from using guest data for their own purposes.'}
1,{id:"dpa-deletion",label:"Deletion on business direction included",type:"toggle",description:'Confirm DPAs include: "shall delete personal information upon written request of the business." This ensures you can fulfill CPRA deletion requests across your vendor ecosystem.'},{id:"dpa-subprocessing",label:"Sub-processing authorization clause included",type:"toggle",description:'Confirm DPAs include: "shall not engage sub-processors without prior written consent." This prevents your vendors from onward-transferring guest data without your knowledge.'},{id:"dpa-security",label:"Security measures clause included",type:"toggle",description:'Confirm DPAs reference encryption, access controls, or industry standards for protecting personal information. The clause does not need to be exhaustive â a reference to "appropriate technical and organizational measures" is sufficient.'},{id:"dpa-audit",label:"Audit rights clause included",type:"toggle",description:'Confirm DPAs grant the right to audit or assess compliance, e.g., "business may audit or assess compliance." This is required to demonstrate oversight of your processor network under CPRA.'},{id:"dpa-breach",label:"Breach notification clause included",type:"toggle",description:"Confirm DPAs specify a notification timeline (typically 48â72 hours) for the vendor to report a data breach affecting your guests. This supports your 72-hour regulatory reporting obligation.",tip:"Until DPAs are reviewed, leave these unchecked. An unchecked state accurately reflects that review is pending and is better than marking verified prematurely."}];function D({type:t}){return"notes"===t||"textarea"===t?e.jsx(f,{variant:"outline",className:"text-xs bg-blue-50 text-blue-700 border-blue-200",children:"Free text"}):"docs"===t?e.jsx(f,{variant:"outline",className:"text-xs bg-green-50 text-green-700 border-green-200",children:"URL / link"}):"toggle"===t?e.jsx(f,{variant:"outline",className:"text-xs bg-amber-50 text-amber-700 border-amber-200",children:"Toggle"}):e.jsx(f,{variant:"outline",className:"text-xs",children:"Input"})}function A({field:t}){return e.jsxs(h,{value:t.id,className:"border rounded-lg px-1 mb-2",children:[e.jsx(y,{className:"px-3 py-3 text-sm font-medium hover:no-underline",children:e.jsxs("span",{className:"flex items-center gap-2 text-left",children:[e.jsx(D,{type:t.type}),t.label]})}),e.jsxs(g,{className:"px-3 pb-4 space-y-3",children:[e.jsx("p",{className:"text-sm text-muted-foreground",children:t.description}),t.example&&e.jsxs("div",{className:"space-y-1",children:[e.jsx("p",{className:"text-xs font-semibold text-foreground uppercase tracking-wide",children:"Example"}),e.jsx("pre",{className:"text-xs bg-muted rounded-md p-3 whitespace-pre-wrap leading-relaxed text-foreground",children:t.example})]}),t.tip&&e.jsxs(s,{className:"border-amber-200 bg-amber-50/50",children:[e.jsx(j,{className:"h-4 w-4 text-amber-600"}),e.jsx(o,{className:"text-xs text-amber-800",children:t.tip})]})]})]})}function R(){return e.jsxs("div",{className:"min-h-screen bg-background",children:[e.jsxs(t,{children:[e.jsx("title",{children:"Settings Guide | HotelComply"}),e.jsx("meta",{name:"description",content:"Field-by-field guide for completing the HotelComply Settings page and populating your CCPA, CPRA, and GDPR compliance audit pack."})]}),e.jsx(i,{}),e.jsx("main",{className:"container mx-auto px-4 sm:px-6 py-6 sm:py-8",children:e.jsxs("div",{className:"max-w-4xl mx-auto space-y-6",children:[e.jsxs("div",{className:"space-y-1",children:[e.jsxs("div",{className:"flex items-center gap-2 text-sm text-muted-foreground",children:[e.jsx(x,{className:"h-4 w-4"}),e.jsx("span",{children:"Settings"}),e.jsx("span",{children:"/"}),e.jsx("span",{children:"Guide"})]}),e.jsx("h1",{className:"text-2xl sm:text-3xl font-bold text-foreground",children:"Settings Field Guide"}),e.jsx("p",{className:"text-muted-foreground",children:"Field-by-field reference for completing your audit pack evidence and compliance configuration."})]}),e.jsxs(s,{className:"border-blue-200 bg-blue-50",children:[e.jsx(b,{className:"h-4 w-4 text-blue-600"}),e.jsxs(o,{className:"text-sm text-blue-800",children:["Every field in the ",e.jsx("strong",{children:"Privacy & Audit Pack Disclosure"})," section of Settings maps directly to a row in your exported audit pack. Complete these fields to generate audit-ready evidence for CCPA, CPRA, and GDPR reviews."]})]}),e.jsxs(r,{defaultValue:"audit-evidence",children:[e.jsxs(a,{className:"grid w-full grid-cols-2 sm:grid-cols-4 h-auto",children:[e.jsx(n,{value:"audit-evidence",className:"text-xs sm:text-sm",children:"Audit Evidence"}),e.jsx(n,{value:"vcr-config",className:"text-xs sm:text-sm",children:"VCR Config"}),e.jsx(n,{value:"section-v",className:"text-xs sm:text-sm",children:"Section V"}),e.jsx(n,{value:"dpa-checklist",className:"text-xs sm:text-sm",children:"DPA Checklist"})]}
1),e.jsx(l,{value:"audit-evidence",className:"space-y-4 mt-4",children:e.jsxs(c,{children:[e.jsxs(d,{className:"pb-2",children:[e.jsxs(p,{className:"text-base flex items-center gap-2",children:[e.jsx(b,{className:"h-4 w-4 text-primary"}),"Audit Pack Evidence â Notes & Supporting Documents"]}),e.jsxs("p",{className:"text-sm text-muted-foreground",children:["Each section below corresponds to a compliance requirement area. For each area you provide a free-text ",e.jsx("strong",{children:"Notes"})," field (your compliance narrative) and a ",e.jsx("strong",{children:"Supporting Docs"})," field (a URL or file path to your evidence)."]})]}),e.jsx(u,{className:"space-y-4",children:N.map(t=>e.jsxs("div",{className:"space-y-1",children:[e.jsx("h3",{className:"text-sm font-semibold text-foreground pt-2",children:t.title}),e.jsx(m,{type:"multiple",className:"space-y-1",children:t.fields.map(t=>e.jsx(A,{field:t},t.id))})]},t.id))})]})}),e.jsx(l,{value:"vcr-config",className:"space-y-4 mt-4",children:e.jsxs(c,{children:[e.jsxs(d,{className:"pb-2",children:[e.jsxs(p,{className:"text-base flex items-center gap-2",children:[e.jsx(v,{className:"h-4 w-4 text-primary"}),"Section IV â VCR Configuration (4.3 / 4.4 / 4.5)"]}),e.jsx("p",{className:"text-sm text-muted-foreground",children:"These structured inputs populate the portability proof, deletion process documentation, and opt-out enforcement log sections of your audit pack."})]}),e.jsx(u,{children:e.jsx(m,{type:"multiple",className:"space-y-1",children:S.map(t=>e.jsx(A,{field:t},t.id))})})]})}),e.jsx(l,{value:"section-v",className:"space-y-4 mt-4",children:e.jsxs(c,{children:[e.jsxs(d,{className:"pb-2",children:[e.jsxs(p,{className:"text-base flex items-center gap-2",children:[e.jsx(P,{className:"h-4 w-4 text-primary"}),"Section V â Structured Configuration (5.1 / 5.2 / 5.4 / 5.5)"]}),e.jsx("p",{className:"text-sm text-muted-foreground",children:"Each field accepts one entry per line using pipe-separated values. Each line becomes one row in the corresponding audit pack table."})]}),e.jsxs(u,{className:"space-y-3",children:[e.jsxs(s,{className:"border-blue-200 bg-blue-50",children:[e.jsx(j,{className:"h-4 w-4 text-blue-600"}),e.jsxs(o,{className:"text-xs text-blue-800",children:[e.jsx("strong",{children:"Format:"})," Each column is separated by a pipe character ",e.jsx("code",{className:"bg-blue-100 px-1 rounded",children:"|"}),". Each new line is a new table row. The column order must match the label shown above each field."]})]}),e.jsx(m,{type:"multiple",className:"space-y-1",children:w.map(t=>e.jsx(A,{field:t},t.id))})]})]})}),e.jsx(l,{value:"dpa-checklist",className:"space-y-4 mt-4",children:e.jsxs(c,{children:[e.jsxs(d,{className:"pb-2",children:[e.jsxs(p,{className:"text-base flex items-center gap-2",children:[e.jsx(v,{className:"h-4 w-4 text-primary"}),"5.3.1 â DPA Required Clauses Checklist"]}),e.jsx("p",{className:"text-sm text-muted-foreground",children:"Toggle each clause on only after you have reviewed your executed Data Processing Agreements and confirmed the clause is present. These six clauses are required under CPRA for service provider agreements."})]}),e.jsxs(u,{className:"space-y-3",children:[e.jsxs(s,{className:"border-amber-200 bg-amber-50",children:[e.jsx(j,{className:"h-4 w-4 text-amber-600"}),e.jsx(o,{className:"text-xs text-amber-800",children:"Until DPAs are reviewed, leave all toggles off. An accurate unchecked state is better than prematurely marking clauses as verified. The Vendor Library can help you identify which vendors need updated DPAs."})]}),e.jsx(m,{type:"multiple",className:"space-y-1",children:C.map(t=>e.jsx(A,{field:t},t.id))})]})]})})]})]})})]})}export{R as default};
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.