The AI concierge and revenue layer for your PMS.
Autonomous, ethically governed, built for luxury hospitality.
Designed to connect to Mews, Opera, Cloudbeds and Apaleo, or run standalone from day one.
Front of house, Lucy serves every guest with voice biometrics, 30-language cultural intelligence and cross-stay memory. Behind the scenes, her autonomous management portal gives your team 135 operational tools across 18 departments, covering housekeeping, maintenance, compliance, F&B and revenue. It triages requests, assigns tasks, flags issues before they escalate and keeps your compliance records up to date, so your managers handle exceptions rather than routine.

Every Service, One Screen
Hotel Services · Travel Tools · London Services · Digital Key · My Bookings
From the home dashboard, guests reach every Lucy feature in a single tap — live weather, language and voice controls, and the full service menu.
80+
Guest-Facing Features (Pre-Deployment, Pilot-Ready)
30
Languages with Cultural Intelligence
<500ms
Target Fast-Path Latency · <3s Full Agent
99.5%
Target Uptime SLA (Post-Deployment, Not Yet Active)
80+ guest-facing features counted across voice, translation, in-room control, guest journey, city explorer, travel tools, vendor network, memory, governance, and operations modules. The wider operations platform includes 135 staff-facing operational tools across 18 hotel departments — see the Operations Platform for the full inventory. Guest-facing features are a subset of the total platform toolset. Count verified against the platform's entity and function registry — not all features are live in production; most are code-complete and sandbox-tested.
Why Lucy Is Built Different
Two fundamental differences that separate Lucy from every other guest experience platform.
Voice-First, Not Voice-Bolted
Lucy was built from the ground up as a voice-native concierge. She does not convert text to speech — she thinks, speaks, and listens like a human. Most competitors started as text platforms and added voice as an afterthought.
Ethically Governed AI
Lucy's Golden Rules are a separate enforcement engine that validates every response before it reaches the guest. She will never hallucinate, never upsell aggressively, and never compromise your brand. We have not identified a competing hotel AI concierge that publishes a dedicated ethical enforcement engine with per-rule validation functions.
Agents Think. Robots Do. People Lead.
Lucy is not an unbounded AI. She operates within the controlled agentic automation paradigm — trading raw autonomy for trustworthiness, explainability, and governance. Every action can be traced to a rule, a function, or a human decision. This is why guests, staff, and regulators trust bounded systems more than unbounded ones.
Lucy (AI Agent)
Thinks
Capabilities
- Contextual decision-making
- Learning from outcomes
- Semantic understanding
- Tone adaptation in real time
- Complex intent resolution
Real Examples
- Detects a special occasion → proactively suggests dinner
- Reads guest mood → adjusts formality
- Orchestrates multi-step requests across systems
Robots (Backend Functions)
Do
Capabilities
- Rule-based deterministic execution
- High-speed repetition, 24/7
- Perfect consistency
- Precise logging of every action
Real Examples
- Service reminders at exact times
- Folio charges at confirmed checkout
- PMS data sync every 30 minutes
- Booking confirmations sent instantly
People (Staff & Humans)
Lead
Capabilities
- Strategic judgment
- Empathy & intuition
- Exception handling
- Compliance oversight
- Brand voice authority
Real Examples
- Staff escalate complex complaints
- GM approves promotional offers
- Concierge overrides room upgrade
- Compliance team audits Lucy outputs
Controlled Agency Principles
| Principle | What Lucy Does | What Lucy Never Does |
|---|---|---|
| Explainability | Explains every recommendation: 'I suggest The Ritz because you mentioned you love fine dining and it matches your style.' | Makes recommendations without justification or acts as if the answer is obvious. |
| Escalation | Routes complex cases to staff: 'This requires a judgment call I need to hand to our team.' | Pretends to solve issues beyond her scope or avoids human handoff. |
| Data Integrity | Seeks confirmation on conflicting PMS data before asserting facts. | Confidently asserts guest data that may be contradictory across sources. |
| Transparency | 'I am Lucy, an AI agent.' — discloses AI identity when directly asked. | Pretends to be human or hides AI identity. |
| Financial Prudence | Never guarantees prices or makes financial promises. | Asserts exchange rates, pricing, or availability without verification. |
| Confidentiality | Only confirms name and room from the active reservation — nothing more. | Speculates about other guests, future stays, or sensitive personal details. |
Lucy trades raw autonomy for trust. One rogue autonomous decision can damage a brand; controlled agents cannot. This is why Lucy is audit-ready for enterprise hospitality procurement — PCI-DSS, GDPR, and NIS2 require explainability, not autonomy.
7-Layer System Prompt — Reassembled Every Turn
Lucy's system prompt is not static. It is reassembled from seven layers on every single message — orchestrating parallel data fetches and conflict detection in real time. This is why she knows your guest's name, their dietary restrictions, today's cultural events, and the live exchange rate — all in the same response, without being told twice.
Core Personality
Hotel identity, language register, tone, Golden Rules — hardcoded in agent config, never overridden.
Hotel Context
Hotel name, address, amenities, check-in/out times, current vendor list with live availability.
Guest Context
Guest name, room, stay dates, dietary restrictions, preferences, language, interaction count → relationship depth tier.
Working Memory
Recent conversation threads, guest essentials (allergies, preferences), cross-stay facts — injected per turn.
Cultural Calendar
Active global events (Ramadan, Diwali, Lunar New Year) with dietary and tone adjustments auto-applied.
Live Data Context
Exchange rates, tonight's events, sports scores — fetched on-demand only when the query is time-sensitive.
Compact Per-Turn Instruction
Language, verbosity, response length, tool requirements — reassembled for every single message.
Data Conflict Detection
Validates guest room number across 3+ PMS sources in parallel. If sources conflict, Lucy injects a warning and seeks confirmation — 'I want to make sure I have the right details — could you confirm your room number?' — rather than asserting wrong data confidently.
Low-Confidence Flagging
Lucy scores her own confidence in every response on a 0–100 scale. If confidence drops below 70, she creates a GoldenRuleViolation record for staff review in the governance dashboard. She proactively asks for confirmation rather than guessing.
Meta-Cognition Engine
Lucy knows when she doesn't know. Rather than hallucinating, she surfaces uncertainty to staff for human action — making her trustworthy, audit-ready, and brand-safe.
Capabilities Designed to Lead the Category
Benchmarked against Siri (Apple Intelligence, iOS 18.4+), Alexa+ (February 2026), Canary, Duve, and ALICE — based on our evaluation of publicly available product documentation and feature sets as of August 2026. Lucy is designed to lead on every dimension.
Free-Flowing Multilingual AI Concierge
Natural, contextual conversations in 30 languages — taking action, not just answering questions. Full details below.
Why This Matters
Most hotel platforms offer basic multilingual 'chat' — but they function as FAQ bots. Lucy is built for hospitality-specific conversational depth, learning guest preferences in real-time, and taking action. She does not just answer questions — she books, arranges, and delivers.
Two-Way Voice Translator (30 Languages, 40+ Dialects)
Real-time two-way voice translation between staff and guests — 30 languages, 40+ dialects. Full details below.
Why This Matters
International luxury hotels serve guests from 100+ countries. Language barriers cost bookings, create service friction, and limit upsell opportunities. Lucy eliminates this entirely — any staff member becomes multilingual across 30 languages with cultural intelligence instantly.
Camera Photo Translation
Camera photo translation for menus, signs, and documents — 30 languages. Full details below.
Why This Matters
Guests currently switch between 5-10 apps during their stay — translation apps, map apps, booking apps. Lucy consolidates everything into one interface. A Japanese guest at a French restaurant points their camera at the menu and hears it in Japanese. This is the kind of frictionless experience that drives 5-star reviews.
Zero-Download QR Code Access
Lucy requires zero guest downloads. A unique QR code on the Guest Key card directs guests to the Lucy web app. No installation, no app store, no sensitive information required. Guests simply scan and access — instant web app experience with full concierge functionality. This is projected to drive adoption rates from ~15% (traditional apps) to 70%+ — projection only, not yet validated with production data.
Why This Matters
Most hotel apps sit abandoned on guest phones — download friction is real. Lucy eliminates this entirely. No tech barrier. No privacy concerns. Hotels own the guest touchpoint without app store dependency.
Conversational AI → DALI Building Control
Conversational AI controls DALI-2 lighting via HelvarNet TCP/IP. Full details in the In-Room Integration section below.
Why This Matters
Hotels spend millions on smart room infrastructure (Helvar, Crestron, Lutron) and then give guests a clunky in-room iPad to control it. Lucy replaces every in-room control interface with a single conversational layer the guest already has on their phone. To our knowledge, no competitor we've evaluated has connected conversational AI to DALI building control.
AI-Generated Guest Insight Briefing
Before every arriving guest, Lucy pulls their full PMS digital file (guest profile, preferences, staff alerts, stay history, folio data) and combines it with everything she already knows from her internal memory. A single LLM synthesis call generates a rich visual staff briefing: a personality snapshot, predicted preferences for this stay, risk flags (past complaints, allergies, sensitivities), upsell opportunities ranked by probability, and a suggested opening line for the greeting. Staff see this before the guest arrives.
Why This Matters
Every hotel has guest data sitting in their PMS — preferences from 2019, a noise complaint, an allergy note. It is never read before arrival. Front desk staff greet returning guests with zero context. Lucy fixes this permanently. Every staff member walks into every guest interaction fully briefed.
Onscreen Context Awareness
Lucy knows what page or content the guest is currently viewing. If a guest is browsing restaurant listings and types 'book this one', Lucy knows which vendor card is active and books it — without the guest repeating any information. If a guest is on the spa page and asks 'how long does this take?', Lucy reads the treatment the guest is viewing and answers instantly. This mirrors Siri's Onscreen Awareness but works on any device — iOS, Android, or desktop — without any app installation.
Why This Matters
Siri's onscreen awareness requires iOS 18.4+ and Apple Intelligence-compatible hardware. Lucy delivers the same capability as a web app accessible from any device. A guest browsing an experience on their Samsung phone gets the same intelligence that Apple is still rolling out across its ecosystem.
Agentic Multi-Step Task Chaining
When a guest says 'Book Nobu for Saturday at 8pm for two and add it to my calendar', Lucy executes a full chain of real-world actions: (1) identifies the vendor and checks availability, (2) fires the booking request email to the restaurant, (3) parses the confirmation reply, (4) updates the booking record, (5) generates a calendar invite and sends it to the guest's email, (6) notifies the guest in-app, and (7) logs the referral for invoicing. All seven steps from one instruction.
Why This Matters
Alexa+ launched 'agentic' task chaining for home automation — but it is limited to Amazon ecosystem actions (music, shopping, smart devices). Lucy's chaining spans booking workflows, payment flows, external vendor communications, PMS updates, and guest notifications across entirely separate real-world systems.
Implicit Mood Inference
Lucy continuously analyses every message for implicit emotional signals — word choice, sentence length, punctuation patterns, response latency, and topic shifts — to infer the guest's current emotional state without them ever saying how they feel. A guest who sends short clipped messages late at night is detected as fatigued; Lucy shortens her responses. A guest whose tone shifts from warm to terse triggers Lucy's service recovery mode before any complaint is made.
Why This Matters
Alexa+ infers mood from explicit style selection — the user chooses a personality style. Lucy reads mood directly from language patterns, with no style selection required. A guest in distress does not stop to choose a personality style — Lucy detects the distress and responds accordingly.
Cross-Property Semantic Memory
A semantic knowledge graph carrying guest knowledge across properties and years. Full details below.
Why This Matters
Duve and Canary store static preference profiles. ALICE tracks task history but not guest personality. Lucy's cross-stay, cross-property memory is powered by a semantic knowledge graph — making her, to our knowledge, the only concierge we've evaluated that truly remembers across brands, across borders, across years.
10 hospitality-first capabilities. Designed for hotels, not adapted from consumer tech.
Alexa+ infers mood from style selection; Lucy reads it directly from language. Alexa+ chains Amazon ecosystem actions; Lucy chains bookings, vendor emails, Stripe payments, PMS updates, and calendar invites from one instruction. Siri's personal context requires device access; Lucy synthesises PMS + lifetime memory into a staff briefing before the guest even arrives.
Conversational In-Room Integration
Lucy replaces every in-room tablet, remote control, and physical switch with a single conversational layer. She is the first AI concierge to control DALI building automation via natural language — connecting guest intent to physical infrastructure.
DALI Lighting Control
Lucy controls room lighting through natural conversation. 'Dim the lights to 20%' or 'Set a romantic mood' — Lucy maps intent to DALI scenes and sends commands via HelvarNet TCP/IP protocol. No physical switches or in-room tablets needed.
Climate Control
Guests adjust temperature by voice: 'Lucy, make it cooler' or 'Set the room to 21 degrees'. Lucy integrates with IoT thermostats and smart HVAC systems, adjusting the environment without the guest ever touching a panel.
Entertainment Systems
Lucy controls in-room entertainment — change channels, adjust volume, cast music from the guest's phone to the room's speakers. All through conversation, replacing clunky remotes and in-room tablets.
Turndown Service
Guests say 'Lucy, I'm going to sleep' and Lucy dims the lights, sets the do-not-disturb flag, adjusts the thermostat, and schedules a wake-up call — all from one instruction. The entire room transitions to sleep mode conversationally.
Digital Room Key
Guests unlock their room with their phone. Lucy generates a secure digital key upon check-in, works with Bluetooth-enabled locks, and can be shared with authorised party members. Lost phone? Lucy revokes access instantly.
Music Control Room
Lucy transforms in-room audio into a full concert experience. DSP mood presets — Jazz, Concert Hall, Club, Dinner, Focus, and Sleep — tune the room's acoustics to the moment. Multi-speaker routing sends different audio to bedroom, bathroom, and lounge zones. Helvar lighting syncs automatically to the music mood. Curated playlists by mood, a music queue guests can build conversationally, and per-zone volume and EQ control — all through natural language.
How Lucy Connects to Building Infrastructure
Hotels spend millions on smart room infrastructure — Helvar, Crestron, Lutron — and then give guests a clunky in-room iPad to control it. Lucy replaces every in-room control interface with a single conversational layer the guest already has on their phone. The integration is not complex: HelvarNet is an open published TCP/IP protocol. It just requires intent mapping, which is exactly what Lucy does.
'Lucy, romantic dinner setting'
Maps to DALI group + scene
TCP socket → Helvar router → lights change
Lucy Translate
To our knowledge, the first AI translation system built specifically for hotel operations. Two-way voice translation, camera photo translation, and culturally intelligent conversation — all in one platform.
Two-Way Voice Translation
The first real-time, two-way voice translation system built for hotel operations. Guest speaks Japanese → staff hears English instantly. Staff replies in English → guest hears Japanese. Live, in-person, face-to-face — not a text chatbot. Currently supports 30 languages with 40+ dialect variations and cultural awareness.
- 30 languages with 40+ dialect variations (dialect detection is code-complete for Japanese keigo, Arabic regional dialects, Thai polite particles, Korean honorifics, and French/German/Spanish formality protocols — full dialect coverage is being expanded during pilot deployments)
- Cultural intelligence: Japanese keigo, Thai polite particles, Arabic dialects
- Real-time voice synthesis — no typing required
- Works face-to-face between staff and guests
Camera Photo Translation
Guests point their phone camera at any text — a restaurant menu, a street sign, a museum placard, a laundry card — and Lucy instantly translates it into their native language and reads it aloud. 30 languages supported including Arabic, Urdu, Mandarin, Cantonese, Japanese, Thai, Hebrew, and Farsi. No separate translation app needed.
- 30 languages including RTL scripts (Arabic, Hebrew, Farsi, Urdu)
- Instant OCR + translation + voice synthesis
- No separate app — built into the Lucy concierge interface
- Works on menus, signs, documents, and labels
Cultural Intelligence, Not Machine Translation
Lucy does not just translate words — she adapts tone, formality, and cultural context. She knows that a Japanese guest expects keigo (honorific language), that a Thai guest expects polite particles, and that an Arabic guest may speak Egyptian, Gulf, or Levantine dialect. She adjusts formality based on age, context, and cultural norms.
- Japanese: keigo (formal) vs casual based on guest age
- Arabic: Egyptian, Gulf, Levantine, Maghrebi dialect detection
- Korean: correct honorific levels (-님, -씨)
- Thai: appropriate polite particles (ครับ/ค่ะ)
- French/German/Spanish: tu/vous, Sie/du, tú/usted protocol
Free-Flowing Multilingual Conversation
Lucy conducts natural, contextual conversations in 30 languages — not scripted chatbot responses. She understands intent, remembers preferences, and actually resolves requests. Guests talk to Lucy like a human concierge, in their native language, and get instant results. Roadmap: 65+ languages by Q1 2027.
- 30 languages with genuine conversational understanding
- Context-aware: remembers conversation history across messages
- Action-oriented: books, arranges, and delivers — not just answers
- Personality adaptation: tone, wit, and formality per guest
30 Languages · 40+ Dialects · Cultural Intelligence
Lucy Does Not Forget
A four-tier memory system that stores, retrieves, and applies guest knowledge across stays, across properties, and across years. An allergy shared in Japanese is remembered in English, in every future conversation, in every language — forever.
Working Memory
Short-term facts injected into every system prompt — recent conversation threads, guest essentials, and cross-stay facts. Word count monitored to prevent bloat.
LucyWorkingMemory entity · memory_type: essentials | threads | recent | buffer
Guest Personal Memory
Long-term personal profile — favourite things, dislikes, room preferences, companion names, celebration dates, dietary restrictions stored in canonical English regardless of conversation language.
GuestPersonalMemory entity · relationship_tier: new_guest → returning → regular → vip
Knowledge Graph
Semantic graph of people, places, projects, preferences, and events. Connected by typed edges with relationship strength. Hybrid semantic retrieval via embedding vectors.
LucyKnowledgeGraph entity · spreading activation retrieval · searchKnowledgeGraph
Conversation History
Session summaries and cross-stay summaries. Semantic search retrieves relevant past conversations. Consolidated nightly to prevent memory bloat while preserving key insights.
ConversationMemory entity · crossStayMemoryConsolidation · retrieveSemanticConversationHistory
Linguistic Mirroring with Dignity
Lucy reads the guest's language register and mirrors their energy and tone without ever adopting their crude vocabulary. Wit substitutes for vulgarity. A guest who speaks casually gets a warm, relaxed Lucy. A CEO in a suit gets measured, precise Lucy. This is not a style selector — it is real-time personality adaptation.
Wit Style
Dry · Sarcastic · Playful · Enthusiastic · None
→ Humour level and delivery style
Formality
Very Formal → Very Casual
→ Vocabulary register, contractions
Verbosity
Ultra Concise → Very Detailed
→ Response length
Decision Style
Quick Decider · Analytical · Consultative · Indecisive
→ Recommendation framing
Current Mood
Excited · Positive · Neutral · Stressed · Anxious · Frustrated · Tired
→ Tone adaptation in real time
Vocabulary Level
Simple · Conversational · Sophisticated
→ Word complexity
Relationship Depth Progression
1–2 interactions
Professional warmth. Getting to know them.
"Good evening. I'm Lucy. How can I help you today?"
3–6 interactions
Warmer, more familiar. Knows their stated preferences.
"You mentioned you love small, neighbourhood spots — I've found one that just opened."
7+ interactions
Your person. Fully anticipatory. Playful where appropriate.
"Already ahead of you on that one. I've got three options lined up based on what you've liked before."
Cross-lingual memory: facts extracted from conversations in any of 30 languages are stored in canonical English and re-injected into every future conversation regardless of language. An allergy shared in Japanese is warned about in Arabic, forever.
Sub-Second Voice on Common Queries, Engineered
Lucy's voice pipeline is a 5-layer architecture designed for sub-500ms perceived response time on common hotel queries (layers 1–3). Complex multi-step requests (layer 4) take 1.5–3.5s. Few competitors publish latency budgets at this level of granularity.
Layer 1
Client Fast-Path
Pure JavaScript regex matching — no network call. Common hotel queries (checkout time, gym hours, Wi-Fi password, emergency protocol) answered instantly before any server is contacted.
src/lib/lucyLatencyGuards.js
Layer 2
Streaming SSE Response
Server-side streaming with inline fast-path. Two paths run concurrently — whichever fires first wins. Sentence-level streaming means Lucy starts speaking before the full LLM response is generated.
base44/functions/lucyStreamingResponse
Layer 3
Speculative TTS Bridge
Eliminates dead silence while the LLM thinks. A short 'thinking' phrase is pre-fetched the moment speech ends. If the LLM replies fast, the phrase is discarded. If it takes longer, the guest hears a natural bridge — never silence.
src/hooks/useLucySpeech.js
Layer 4
Full Agent Path
Complete agentic orchestration: 7-layer system prompt reassembled per turn, parallel data fetches, conflict detection, cultural calendar injection, and meta-cognition confidence scoring. 1.5–3.5s for complex multi-step chains.
src/pages/Chat.jsx
Layer 5
Audio Playback Engine
Global audio singleton ensures one audio source at a time across all surfaces. Instant barge-in kills any in-flight stream in ~20ms. Speech queue with prefetch lookahead — sentence N+1 is pre-fetched while sentence N plays.
src/lib/audioSingleton.js
Built for Mews. Connects to Everything.
Lucy is purpose-built as a Mews bolt-on — a conversational concierge layer that sits on top of your Mews PMS. Also connects to Oracle Opera, Cloudbeds, and Apaleo. Every connector includes a self-healing worker that detects and auto-recovers from sync failures, a reservation validator for data integrity, and a 30-minute sync scheduler.
Mews
Code Complete · Awaiting First Live Tenant for Certification
Oracle Opera
Code Complete · Read-Only Sync (Bi-Directional Pending)
Cloudbeds
Code Complete · Two-Way Sync (Live Tenant Testing Pending)
Apaleo
Code Complete · Webhook Listener Ready (Live Testing Pending)
The Guest Journey, Automated End-to-End
From 48 hours before arrival to 30 days after checkout, Lucy manages every stage of the guest journey autonomously. Every touchpoint is personalised, timely, and revenue-aware. Minimal staff intervention required — Lucy escalates to staff only when she cannot resolve a request within her governance scope.
Pre-Arrival
48 hours before check-in
AI Pre-Stay Concierge Activates
Lucy sends a personalised pre-stay email 48 hours before arrival — covering room preferences, dietary needs, and special occasions. When the guest replies, Lucy extracts their preferences and auto-updates their profile. Full system details are in the Intelligence tab.
aiPreStayConcierge · every 6 hours
Check-In Day
Day of arrival
Welcome London Briefing
Lucy delivers a live weather forecast, today's events in the city, curated restaurant suggestions, and a personalised greeting in the guest's native language. The guest arrives already briefed on their destination.
sendWelcomeLondonBriefing · on check-in
In-Stay
Day 2 of stay
Proactive Check-In & Upsell
Lucy checks in with the guest: How is your stay? She proactively offers upgrades, spa bookings, and activities based on their journey stage. If they ordered room service on day 1, the minibar is restocked with their preferences overnight.
sendInStayCheckIn · triggerInStayUpsells · smartMinibarRestock
Departure Day
Day of checkout
Departure Coordination
Lucy detects departure day and sends a checkout reminder with review request timing. She offers late checkout if the room is available via the Steal the Night auction system. The guest leaves with a future booking offer already in their inbox.
detectDepartureDayGuest · stealTheNightLateCheckout
Post-Stay
3 days after checkout
Stay Satisfaction Survey
Lucy sends a personalised How was your stay? survey — not a generic template, but a letter that references specific moments from their visit. Their responses are analysed for sentiment and service recovery opportunities.
sendPostStayDay3 · postStaySentimentAnalysis
Post-Stay
7 days after checkout
Review Invitation
Lucy invites the guest to leave a review on Google or TripAdvisor — timed when they are most likely to feel positive about their stay. If a companion's birthday is upcoming, Lucy sends a proactive gift reminder.
sendPostStayDay7 · sendPostStayGiftReminder
Post-Stay
30 days after checkout
Lucy Remembers You
Lucy sends a personal letter 30 days after checkout, referencing specific stay moments. Written as a friend who genuinely remembers — not a marketing email. Includes a personalised return offer to drive direct re-booking. Full system details are in the Intelligence tab.
postStayLucyRemembers · daily 10am
From Check-In to Room Service — Without the Busywork
See exactly how Lucy handles a single guest interaction — from arrival to room service delivery — and how much staff time she saves at every step.
Guest Checks In
What the Guest Does
Guest arrives and verifies their room via Lucy chat or voice — "Hi, I'm in room 808."
What Lucy Does Automatically
Lucy cross-references the room number with the PMS reservation, verifies the guest's identity, loads their preferences from previous stays, and unlocks the digital room key — all in one conversation.
What Staff Do
WITHOUT LUCY
Front desk manually looks up the reservation, confirms identity, prints a key card, and briefs the guest on hotel services.
WITH LUCY
Front desk sees the guest has already checked in. Lucy has sent a welcome briefing to the guest's phone automatically.
Time savings are illustrative estimates based on internal workflow analysis, not measured production data. Actual savings will vary by property and workflow.
30 minutes
saved per guest interaction
That's nearly half an hour of staff time freed up — per guest — to focus on moments that actually require a human touch.
City Explorer: How Lucy's Local Intelligence Works
Lucy is not a link directory. She is a local expert with real-time data, personality-matched recommendations, and curated itineraries. Here is exactly how the City Explorer works.
Curated Attractions Guide
Lucy's Local Explorer presents a curated guide to London's must-see attractions — 80+ venues across museums, galleries, monuments, churches, parks, markets, and viewpoints. Each listing includes real-time opening hours, admission prices, nearest Tube station with walking distance, average visit duration, guest ratings, and direct booking links where available.
- 18 museums (British Museum, V&A, Natural History)
- 12 galleries (National Gallery, Tate Modern, Saatchi)
- 13 monuments (Tower of London, Big Ben, The Shard)
- 12 parks (Hyde Park, Regent's Park, Hampstead Heath)
Interactive Map & Walking Directions
Lucy's London Explorer Map renders all curated attractions on an interactive OpenStreetMap with clustering. Guests tap any venue to see details, then tap 'Get Directions' for turn-by-turn walking navigation. The map includes a green polyline route, red guest location marker, and animated hotel pin with welcome popup.
- OpenStreetMap with marker clustering
- Turn-by-turn walking directions
- Real-time distance & travel time
- Hotel pin with animated popup
Personalised Itinerary Builder
Lucy does not just list attractions — she builds personalised itineraries. She takes the guest's interests, dietary requirements, budget, available time, and the weather forecast, then curates a day-by-day plan. She knows which museums are free, which need booking, which are near each other, and which match the guest's personality profile.
- Personality-matched recommendations
- Weather-aware itinerary adjustments
- Budget-conscious planning
- Proximity-optimised venue grouping
Pro Tips for Visiting London
Lucy provides curated local knowledge — use Oyster or contactless for unlimited transport, many museums offer free entry, book attractions ahead to avoid queues, check transport updates before peak-hour travel. She adapts tips to the guest's nationality and travel style.
- Oyster card & contactless guidance
- Free museum entry recommendations
- Queue-avoidance booking strategy
- Peak-hour travel warnings
A Real Guest Example
A guest from Tokyo asks Lucy: "I have a free afternoon — what should I do?" Lucy checks the weather (rain expected at 3 PM), the guest's profile (loves art, prefers free attractions), and live transport status (Central Line has delays). She responds: "The National Gallery is free, a 10-minute walk from the hotel, and it's indoors — perfect for the rain coming this afternoon. The Central Line has delays, so I'd suggest walking. Shall I add it to your itinerary and remind you at 2 PM?" When the guest is ready to return, they tap Get Me Home on the map and receive instant walking directions back to the hotel.
Guest Safety & Get Me Home
Guest safety is not a feature Lucy added — it is a core architectural principle. Every off-property recommendation includes safety context, late-night transport is prioritised after 10 PM, emergency services proximity is flagged, and the Get Me Home button ensures no guest is ever lost. This is enforced by Golden Rule 12, validated by a separate engine, and cannot be overridden by the LLM.
Get Me Home — One-Touch Hotel Navigation
The Get Me Home button is embedded directly in Lucy's London Explorer map interface. With a single tap, guests receive instant turn-by-turn directions back to the hotel. A green polyline renders the optimal route on OpenStreetMap, a red marker shows the guest's current position, and the hotel is prominently marked with an animated red pulsing icon and welcome popup.
Guests explore with confidence, knowing they can always get home with one tap.
Neighbourhood Safety Context on Every Recommendation
Every off-property recommendation Lucy makes includes explicit neighbourhood safety context. She does not simply say 'go to this restaurant' — she provides context about the area, the time of day, and what the guest should be aware of. This is Golden Rule 12 (Always Prioritise Guest Safety) in action.
Guests make informed decisions about where they go and when.
Late-Night Transport Prioritisation
After 10 PM, Lucy proactively prioritises safe transport options in her recommendations. She suggests licensed taxis, Blacklane chauffeur services, or well-lit walking routes to Tube stations rather than unlit shortcuts. She never recommends unlicensed minicabs and always confirms transport is arranged before the guest leaves the hotel.
No guest is left stranded or directed to an unsafe transport option after dark.
Emergency Services Proximity
Lucy flags proximity to emergency services for every off-property venue she recommends. She knows the nearest A&E department, NHS 111 urgent care centre, pharmacy, and police station to every venue. 999 and 112 emergency numbers are always prominently displayed. If a guest needs medical assistance, Lucy provides immediate directions to the nearest hospital.
Guests have immediate access to emergency services information, wherever they are.
Immediate Staff Escalation on Incident
If something goes wrong at a recommended venue — a guest feels unsafe, a venue is closed unexpectedly, or an incident occurs — Lucy escalates to hotel staff immediately via the GuestIncidentNotification entity. The hotel's front desk, concierge, and duty manager are notified in real time, not when the guest returns and complains.
Issues are resolved before they become complaints. Staff know before the guest returns.
Guest Safety as a Core Golden Rule
Guest Safety is Golden Rule 12 — one of the 12 core principles that Lucy cannot override. It is enforced by a separate validation engine, not by the LLM itself. Lucy cannot be prompted, manipulated, or tricked into deprioritising guest safety. This is architectural, not policy-based — it cannot be bypassed.
Guest safety is not a feature — it is a core architectural principle that cannot be bypassed.
Why This Is Different From Competitors
No competitor in the hotel technology space offers dedicated guest safety protocols as an architectural enforcement. Canary, Duve, and ALICE all rely on the LLM's default behaviour with basic prompt instructions. Lucy's Golden Rule 12 is enforced by a separate validation engine — the same engine that enforces all 25 governance functions. It cannot be overridden by LLM output, guest manipulation, or prompt injection. This makes Lucy brand-safe and audit-ready for enterprise hospitality procurement.
Vendor Network: Lucy Books, Not Just Recommends
Most hotel concierge platforms recommend a restaurant and leave the guest to call. Lucy detects intent, searches 130+ curated partners (currently London-focused — new cities onboarded per property during implementation), processes the booking, handles vendor negotiation, sends reminders, tracks commission, and exports to accounting — all conversationally, in the guest's language. Nothing is decorative. Every recommendation is tracked to a revenue event.
Restaurants & Dining
5–8%
OpenTable + TheFork + Independent
40+ venues
Bars & Lounges
10%
Direct partnerships
15+ venues
Spa & Wellness
10%
Direct vendor agreements
12+ venues
Activities, Tours & Experiences
10%
GetYourGuide + Curated experiences
25+ experiences
Transportation & Chauffeur
15%
Blacklane + Local taxi networks
8+ partners
Luxury Retail & Shopping
12%
Affiliate link click-out
20+ partners
Florist & Gifts
10%
Same-day delivery
6+ partners
Fitness & Gym
Direct
Premium fitness clubs
5+ partners
Booking Flow — 6 Steps, Fully Automated
Intent Detected
Lucy detects booking intent in conversation using NLU. She does not wait for explicit 'book a table' — she recognises 'I'd love somewhere nice for dinner tonight' as a booking intent.
Vendor Search
Lucy searches 130+ curated venue listings across 10 platform integrations, filtered by hotel_id for tenant isolation. She matches on cuisine, location, price range, dietary restrictions, and availability. No cross-hotel data leakage.
Booking Flow
Lucy collects date, time, party size, special requests, and dietary requirements in one conversational flow. Stripe payment is integrated for deposits and upfront charges. A 15-minute cooling-off period applies (Golden Rule 8).
Vendor Confirmation
Lucy sends an automated email to the vendor. The vendor accepts, declines, or proposes an amendment. Lucy handles the entire negotiation — the guest never sees the back-and-forth.
Reminders & Tracking
Automated reminders sent at 24 hours, 2 hours, and 30 minutes before the booking. Commission is tracked via the AffiliateClick entity and logged for accounting export. No commission is lost or untracked.
Accounting Export
Commission data is tracked via the AffiliateClick entity for accounting export. Xero, Sage, and QuickBooks integration is on the product roadmap — current deployments export commission data as CSV for manual import. Vendor performance is scored via the VendorPerformanceScore entity.
Revenue Streams — Designed & Wired (Pre-Deployment)
Restaurant Commission
OpenTable / TheFork booking fee
5–8%
Spa & Activities
Direct vendor agreement
10%
Transportation
Chauffeur / cab referral
15%
Luxury Retail
Affiliate link click-out
12%
Florist & Gifts
Direct booking commission
10%
Theatre & Events
TodayTix / ATG / London Theatre Direct
5–6%
All commissions tracked via AffiliateClick entity. Revenue attribution to PMS folio via lucyMewsFolioCharge. Vendor performance scored via VendorPerformanceScore entity. Accounting exports to Xero, Sage, and QuickBooks with VAT-inclusive journal entries. Partner directory is currently London-focused — new cities are onboarded per property as part of implementation.
The Direct Booking Engine
Lucy doesn't just recommend restaurants and spa treatments — she captures direct room nights. When a guest wants to extend a stay, book an additional room, or rebook for a future trip, Lucy handles the entire flow conversationally. No OTA. No commission. No redirect to a booking page.
1. Intent Detection
Lucy detects booking intent in natural conversation — 'Can I stay an extra night?', 'My colleague needs a room', 'I'd love to come back in December'. No forms, no redirects.
2. Live Availability
Lucy queries your PMS in real time for room availability and rates for the requested dates. The guest sees only what's actually bookable — never stale inventory.
3. Conversational Booking
Lucy presents options, confirms the guest's choice, processes payment via Stripe, and writes the reservation back to your PMS — all in-chat, zero OTA commission.
12–18%
Zero OTA Commission
Saved on every direct booking Lucy captures — money stays with your hotel, not Booking.com or Expedia.
Frictionless
In-Stay Extensions
Guests extend stays without leaving the conversation. Lucy checks availability, charges the card on file, updates the PMS.
Post-Stay
Repeat Direct Bookings
Past guests rebook directly through Lucy instead of returning via OTAs. Lucy remembers their preferences from their last stay.
Instant
Group / Family Capture
'My children need a second room' → Lucy books it on the spot. Multi-room requests handled in one conversation.
Every Direct Booking Lucy Captures Is Commission-Free
A 300-room hotel at 80% occupancy and £350 ADR generates about +£30.7M in annual room revenue. If 50% of bookings come through OTAs at 15% commission, that's about −£2.3M/year in OTA commission. Lucy's Direct Booking Engine shifts a portion of those bookings back to direct — not by replacing your booking engine, but by capturing bookings that would otherwise go through OTAs because the guest couldn't book directly in the moment.
Conservative model: +2.1% of OTA bookings shift to direct via Lucy. At 15% average OTA commission, this saves approximately +£48,000/year in commission. Year 2 improves as guest adoption grows.
+£48,000
Annual OTA Commission Saved
12–18%
OTA Commission Rate Avoided
1 conversation
Booking Steps (vs OTA)
Zero
Guest Redirects
Direct Booking Engine is code-complete and sandbox-tested. Live booking flow requires an active PMS integration and Stripe configuration. Revenue figures are pre-deployment projections based on industry benchmarks, not historical results. Vendor partner directory is currently London-focused — new cities are onboarded per property as part of implementation.
Five Revenue Streams. Two Indirect Savings. One Platform.
Lucy isn't a cost centre — she's a revenue engine. Five direct revenue streams generate £147,276/year for a 300-room hotel on the Direct tier. Two indirect savings add another £46,000 in value. The platform cost is £60,000/year. You're net positive in Year 1.
Direct Revenue
£147,276
£490.92/room
Indirect Savings
£46,000
£153.33/room
Platform Cost
£60,000
£200.00/room
Net Year 1 (cash)
+£95,676
+£318.92/room
Incl. indirect savings: +£141,676
Direct Revenue — £147,276/year (300-room hotel, Direct tier)
Direct Booking Commission Saved
2.1% OTA-to-direct conversion
£48,290
Lucy captures room-night bookings in conversation — extensions, additional rooms, repeat stays — that would otherwise go through OTAs. Every direct booking Lucy generates saves you the full OTA commission.
How it works: Guest asks to extend stay → Lucy checks PMS availability → processes payment via Stripe → writes reservation back to PMS. Zero OTA, zero redirect.
Vendor Booking Commission
100% to hotel (Direct tier)
£18,002
When Lucy books restaurants, spa treatments, transport, experiences, and gifts for your guests, the hotel retains 100% of vendor commission on the Direct tier.
How it works: Lucy detects booking intent → searches 130+ curated partners → processes booking → tracks commission → exports commission data as CSV (Xero/Sage/QuickBooks integration on roadmap).
In-Stay Upsell Revenue
Room upgrades · F&B · spa · late checkout
£12,000
During the guest's stay, Lucy identifies upsell opportunities based on their profile, behaviour, and context — presented naturally in conversation, never aggressively. Each upsell is tracked with revenue attribution to your PMS folio.
How it works: Lucy analyses guest profile → identifies relevant upsell → offers in conversation → guest confirms → charge posted to folio via PMS integration.
Review-Driven Bookings
Post-stay review solicitation
£7,665
Lucy solicits post-stay reviews from satisfied guests, routing positive feedback to public review platforms (with consent) and negative feedback to staff for service recovery. More positive reviews drive incremental direct bookings.
How it works: Guest checks out → Lucy sends feedback survey → positive feedback routed to TripAdvisor/Google → negative feedback triggers service recovery workflow.
Direct Booking Engine
5% Lucy fee vs 15% OTA
£61,320
Lucy's direct booking widget on your website captures guests who would have booked via OTA. Instead of paying OTA 15% commission, the hotel pays Lucy just 5% — netting 10% commission savings on every captured booking. This is a cost saving (reduced commission), not new revenue.
How it works: Guest visits hotel website → Lucy booking widget checks PMS availability → processes payment via Stripe → writes reservation to PMS. Zero OTA redirect, 10% net commission saving.
Indirect Savings — £46,000/year (Excluded from Net Year 1 cash; included in comparison table below)
Staff Hours Redeployed
2,000 hrs/yr
Lucy handles guest requests that would otherwise occupy concierge and front desk staff — freeing ~2,000 hours per year (300-room baseline) for higher-value work. Not a headcount reduction, but redeployed labour.
£46,000
Software Cost Avoidance
£8,400
Lucy consolidates point solutions — chatbot, translation tool, concierge app, upsell engine, review manager — into a single platform. Properties typically save £15,000–£25,000/year in eliminated software subscriptions.
Range: £15,000–£25,000
Lucy Replaces Your Existing Software Stack
Lucy isn't an additional cost — she replaces subscriptions you're already paying for. Here's what she consolidates:
Chatbot / AI assistant
£200/mo
Translation tool
£100/mo
Concierge / guest app
£150/mo
Upsell engine
£100/mo
Review manager
£150/mo
Side-by-Side: With Lucy vs Without Lucy
| Annual Line Item | Without Lucy | With Lucy | Net Impact |
|---|---|---|---|
| OTA commission paid | −£2,299,500 | −£2,251,211 | +£48,290 |
| Vendor commission earned | £0 | £18,002 | +£18,002 |
| In-stay upsell revenue | £3,600 | £12,000 | +£8,400 |
| Review-driven bookings | £1,533 | £7,665 | +£6,132 |
| Direct booking engine savings | £0 | £61,320 | +£61,320 |
| Staff hours (redeployed value) | £0 | £46,000 | +£46,000 |
| Software cost avoidance | −£8,400 | £0 | +£8,400 |
| Lucy platform cost | £0 | −£60,000 | −£60,000 |
| Net Annual Position | −£2,302,767 | −£2,166,224 | +£136,543 |
Comparison shows annual figures for a 300-room hotel at 80% occupancy, £350 ADR, Direct tier. 'Without Lucy' assumes current operations with existing OTA dependency and software stack. 'With Lucy' includes platform cost and all revenue/savings streams above. Indirect savings (staff redeployment, software avoidance) are included in this comparison but noted as indirect — they represent redeployed labour and avoided cost, not new cash revenue.
How It Works: The Revenue Journey
Guest Arrives
Lucy greets the guest in their language, learns their preferences, and syncs with PMS data.
Guest Asks for Help
“Book dinner tonight” or “extend my stay” — Lucy detects booking intent in conversation.
Vendor Commission + Direct Booking
Lucy Books & Charges
Lucy searches vendors or checks PMS availability, processes payment via Stripe, posts to folio.
In-Stay Upsell + Vendor Commission
Guest Departs Happy
Lucy solicits a review post-stay. Positive reviews drive incremental direct bookings.
Review-Driven Bookings
Year 1 Net Position — 300-Room Hotel, Direct Tier
All figures are pre-deployment projections based on industry benchmarks — not historical results. The Direct tier costs £60,000/year. On the Sponsored tier, GSI retains vendor commission to subsidise your licence fee — reducing hotel revenue but also reducing licence cost. Staff hour redeployment is shown for completeness but excluded from the net cash calculation. Software cost avoidance is included as real cash savings (subscriptions no longer paid). Use the interactive ROI Calculator below for a custom model calibrated to your property.
Complete Travel Tools Suite
Lucy is not just a concierge — she is a complete travel companion. From insurance to embassies, from flight tracking to currency exchange, every tool a guest needs is built directly into the Lucy interface. No app switching. No fragmented experiences. Everything in one place, in the guest's language, conversationally.
Travel Insurance
Built · Affiliate Active
Lucy partners with World Nomads to offer guests comprehensive travel insurance directly through the concierge interface. Guests can compare coverage levels, purchase policies, and receive instant confirmation — all without leaving Lucy's chat. Affiliate commission tracked via AffiliateClick entity.
Currency Converter & Exchange
Built · Live API Connected
Lucy provides live exchange rates via the EXCHANGE_RATE_API_KEY integration, converting between 168+ currencies in real time. She also directs guests to the nearest bureau de change — for Café Royal London, that's Travelex at Piccadilly Circus, a 5-minute walk. Rates are never guaranteed; Lucy confirms pricing with the vendor before quoting.
Live Weather Forecasts
Built · Live API Connected
Lucy pulls real-time weather data for the hotel's location and any destination the guest is planning to visit. She proactively suggests itinerary adjustments based on weather — 'It's going to rain this afternoon, shall I book the British Museum instead of Hyde Park?' — turning weather awareness into actionable concierge intelligence.
Flight Check-In & Status
Built · Function Active
Guests check in for flights directly through Lucy. She navigates to the airline's online check-in portal, pre-fills booking references, and confirms boarding pass delivery. Real-time flight status tracking detects delays and proactively adjusts the guest's check-in time, wake-up call, and car pickup schedule.
Rail Information & Booking
Built · Affiliate Active
Lucy books rail tickets through Trainline and displays live London station departure boards. Guests see real-time departures from major stations, platform information, and delay alerts. She also integrates with the Tube Journey Planner for underground route planning across all London Underground lines.
London Hospitals & Emergency Contacts
Built · Curated Database
Lucy provides guests with a curated directory of London hospitals, urgent care centres, NHS 111 services, and emergency contacts. A&E departments, minor injuries units, and pharmacies are listed with addresses, phone numbers, opening hours, and distances from the hotel. 999 and 112 emergency numbers are always prominently displayed.
Foreign Embassies & Consulates
Built · Curated Database
Lucy maintains a directory of all foreign embassies and consulates in London — addresses, phone numbers, email contacts, opening hours, and consular services. If a guest loses their passport or needs consular assistance, Lucy immediately provides the relevant embassy's contact details and directions.
Local Etiquette & Cultural Guide
Built · Curated Content
Lucy provides guests with cultural etiquette guidance for London and the UK — tipping norms, public transport etiquette, queueing culture, pub customs, and dress codes for venues. She adapts the guidance to the guest's nationality, explaining differences between their home culture and British customs.
Offline Maps & Navigation
Built · Digital Tools Panel
Lucy curates essential digital travel tools, including offline maps. Guests can download areas of London for offline navigation, ensuring they can always find their way back to the hotel — even without a data connection. Google Maps, Maps.me, and Apple Maps offline downloads are all supported.
eSIM & Connectivity
Built · Digital Tools Panel
Lucy helps guests stay connected abroad. She provides eSIM recommendations and connectivity solutions so guests can access data immediately upon arrival — no SIM card swapping, no airport Wi-Fi dependency. Lucy can direct guests to purchase eSIMs before departure or upon arrival at the hotel.
Tube Journey Planner
Built · TfL Data
Lucy integrates a full London Underground journey planner. Guests input their destination and Lucy calculates the optimal Tube route — lines to take, interchange stations, estimated journey time, and live service updates. She also flags planned line closures and weekend engineering works.
How Travel Tools Work in Practice
A guest says: "Lucy, my flight to Tokyo tomorrow morning — can you check me in?" Lucy navigates to the airline's check-in portal, enters the booking reference from the guest's PMS profile, confirms the boarding pass, and proactively schedules a 5 AM wake-up call and a 6 AM car to Heathrow — all from one conversational instruction. This is not a chatbot linking to external apps. This is an agentic concierge that takes action.
Staff Operations Dashboards
Lucy isn't just a guest concierge. She runs 135 operational tools across 18 hotel departments — compliance, housekeeping, revenue management, staff scheduling, and more. Explore the full operations platform.
Explore the Operations PlatformLucy Lite: Concierge Beyond Hotels
The same AI engine that powers Lucy for hotels — now available for serviced apartments, members clubs, residential buildings, superyachts, and co-living spaces. No PMS required. Target go-live: 48 hours from contract.
Text-only chat from 3 languages (Starter) up to 30 languages (Premium). Voice AI available as a paid add-on. No PMS integration — upgrade to Lucy Full if you later add one.
Explore Lucy LiteSupported
6 Venue Types
To Live
Target 48h
Required
No PMS
Boutique Starting
£350/mo
Autonomous Intelligence Suite
Thirteen fully automated systems — eight code-complete as of May 2026, five added July 2026 (also code-complete and deployment-ready). Each runs on a scheduled trigger with no staff input required. Every system has a dedicated backend function and wired automation. They will generate revenue, protect your brand, and prevent service failures while your team sleeps upon first live deployment.
Guest Anniversary Engine
Daily · 7am
Scans all in-house guests for birthdays, wedding anniversaries, and first-stay anniversaries. Cross-references celebration dates and historic check-in records. Generates room touch suggestions — champagne, card, roses, cake — per milestone type. Creates staff alerts before the guest wakes.
Multi-Guest Voice Profiles
Per conversation
Two guests, one room — individual responses. Loads individual preference profiles for every guest sharing a room. Identifies the speaker using LLM analysis of transcript style and speech patterns. Each companion gets their own preference profile, not a shared one.
Predictive Room Readiness
On-demand
Fetches live flight status via web search and calculates hotel arrival ETA with a 75-minute buffer. If a guest lands within 120 minutes, creates an urgent housekeeping task and emails the team. Priority queue scores all same-day checkouts based on flight tracking, arrival time, VIP status, and incoming guest ETA.
Smart Minibar Restock
Nightly · 11pm
Scans all multi-day guests (checked in yesterday or earlier). Reads favourite food and drink items learned from room service orders. LLM generates a personalised 5–8 item restock list combining known preferences with luxury hotel defaults. Creates a housekeeping task scheduled for 10am. Respects all dietary restrictions.
Steal the Night — Late Checkout Auction
Daily · 8am
Scans all same-day checkouts and scores each guest's likelihood to pay for late checkout. Scoring factors: business traveller (+20), long stay 4+ nights (+15), VIP (+10). Eligibility checks room availability. Sends personalised offer — Until 2pm: £45 | Until 4pm: £85. On acceptance, updates check-in, creates folio charge, sends confirmation.
AI Pre-Stay Concierge
Every 6 hours
Scans for guests arriving in exactly 48 hours and sends a personalised pre-stay email. Covers room preferences (pillow, temperature, floor), dietary briefing, restaurant pre-booking offer, and special occasion coordination. Processes guest replies — extracts preferences from their email response and auto-updates their profile.
Lucy Offline Mode
Always active
Service worker caches hotel info, FAQ responses, emergency numbers, and service request forms. Offline-capable fast-path returns cached answers for checkout time, gym hours, Wi-Fi password, and emergency protocol. Service requests queued locally and submitted when connectivity restores. Critical for international guests with data roaming off.
Post-Stay Lucy Remembers Email
Daily · 10am · 30 days post-checkout
Scans for guests who checked out exactly 30 days ago and sends a personal letter from Lucy. References specific stay moments: vendor bookings made, conversation topics, memorable moments. Written as a friend who genuinely remembers — not a marketing email. Includes a personalised return offer: 15% off using code LUCY30.
Cultural Calendar Engine
Daily · deterministic
Tracks 14 global events — Ramadan, Diwali, Chinese New Year, Hanukkah, Eid, and more — via deterministic daily computation. Automatically adjusts Lucy's tone, dietary recommendations, and greeting protocols based on active cultural events. A Muslim guest during Ramadan is never offered a lunch reservation. A Hindu guest during Diwali receives a culturally aware greeting. No staff configuration required.
Proactive Upsell Engine
Per guest journey stage
Analyzes each guest's journey stage and cross-references stay purpose (leisure, business, celebration). Matches against available in-stay upsells and delivers them at the optimal moment. Day 1 evening: spa and dining offers. Day 2 morning: activity and tour suggestions. Day before checkout: late checkout extension and future booking incentives. Never pushes — always times the offer to genuine receptiveness.
Data Drift Monitor
Nightly · 3am
Scans all GoldenRuleViolation records to detect recurring data quality issues across the platform. Flags affected guest profiles for administrative review before they cause guest-facing problems. Identifies patterns — a specific room number consistently misread, a vendor with declining availability data, a PMS field that drifts. Self-healing: if a data source is consistently wrong, Lucy stops trusting it.
Meta-Cognition Engine
Per response
Scores Lucy's own confidence in every response on a 0–100 scale. If confidence drops below 70, Lucy creates a GoldenRuleViolation record for staff review in the governance dashboard. She will proactively say 'I want to make sure I have the right details — could you confirm?' rather than asserting wrong data confidently. This is not a chatbot guessing — it is an AI that knows when it doesn't know.
PSTN Voice Bridge — Room Phone to Lucy
Always available
Guests can now reach Lucy from the room telephone. A Twilio Programmable Voice webhook connects an inbound room-phone call to Lucy's AI — greeting, speech recognition, LLM reply, and Polly TTS spoken back. Follow-up loop for multi-turn conversation. Automatic escalation to front desk on request or detected frustration. Every spoken turn logged to VoiceCallLog entity for audit and compliance.
The Golden Rules
Lucy is the only AI concierge governed by a separate ethical enforcement engine. 12 core Golden Rules plus 13 conduct guardrails (25 total enforcement functions) — each backed by a dedicated validation function — validate every response before it reaches the guest. They cannot be overridden by LLM output, guest manipulation, or prompt injection. She will never compromise your brand, your guests, or your trust.Note: 13 rule cards shown below — 12 core principles plus Guest Safety, which spans both core and conduct categories. The remaining 12 conduct guardrails are enforcement functions that operate behind the scenes (e.g. enforceProfessionalTone, enforceAntiManipulationGate, enforceDataMinimisation) — they are not shown as cards because they govern internal behaviour rather than guest-facing promises.
Never Hallucinate
Every recommendation is validated against real hotel data before it reaches the guest. Lucy does not guess — she confirms.
Never Upsell Aggressively
Lucy recommends enhancements that genuinely benefit the guest, not just the hotel's revenue. One mention maximum, then she moves on.
Never Break Brand Voice
Lucy's tone, formality, and personality are locked to your hotel's brand standards. She mirrors the guest's energy, never their crude vocabulary.
Never Share Guest Data
One guest's preferences are never referenced in another guest's conversation. Cross-guest data access is architecturally blocked, not just policy-prohibited.
Always Complete Assistance
Lucy never leaves a request half-finished. Every interaction ends with resolution or a clear handoff to staff.
Always Disclose AI Identity
Lucy always identifies herself as an AI concierge when directly asked. No deception, ever.
Always Offer Hotel Services First
Lucy prioritises your hotel's own services — spa, dining, room service — before recommending external vendors. Your revenue comes first.
Always Confirm Before Charging
Lucy never books, charges, or commits to a payment without explicit guest confirmation. A 15-minute cooling-off period applies to every booking.
Always Escalate to Staff
Complex complaints, judgment calls, and service failures are routed to human staff — not handled autonomously. Lucy knows when to hand off.
Never Give Financial Advice
Lucy never guarantees prices, asserts exchange rates, or makes financial promises. She confirms pricing with the vendor before quoting.
Never Discriminate
Equal service regardless of nationality, language, race, religion, or any other characteristic. Lucy's cultural intelligence adapts — it never discriminates.
Always Explain Recommendations
When asked why, Lucy explains her reasoning: 'I suggest The Ritz because you mentioned you love fine dining and it matches your style.' No black-box AI.
Always Prioritise Guest Safety
Every off-property recommendation includes safety context — neighbourhood guidance, late-night transport options, and emergency services proximity. If something goes wrong at a recommended venue, Lucy escalates to hotel staff immediately.
Simple, Honest Pricing
No per-room charges. No module stacking. One flat monthly fee covers every feature, every guest, every conversation. Optional capacity upgrades available for peak periods — clearly priced, never hidden. Choose sponsored partners to halve your cost, or go direct for full independence.
Your tier is determined by your room count — not chosen arbitrarily. Properties with 10–75 rooms fall into the Boutique tier; 76–200 rooms into the Sponsored tier; 201+ rooms into the Direct tier. All tiers include every feature — the only difference is property size. Request a tailored quote for your room count.
Text-only baseline
Right-sized pricing for boutique and heritage properties (10–75 rooms). Full platform access with all 80+ features — scaled to your property size. 50/50 vendor commission split keeps your licence affordable. Ideal for EU heritage hotels and independent boutique properties.
Text-only baseline
Lucy earns a commission on vendor bookings (OpenTable, experiences, etc.) made through the platform, subsidising your licence fee. Hotel pays only the reduced licence fee.
Text-only baseline
Direct subscription with voice available as an add-on. No vendor commission taken by Lucy — the hotel pays the full licence fee for total independence and white-label control.
Pricing by Property Size
Lucy's pricing is flat per tier — no per-room charges, no hidden fees. The only variable is your room count, which determines your tier. All tiers include every feature, every guest, every conversation.
| Property Size | Text-Only | With Voice |
|---|---|---|
| 10–75 rooms | £350.00/mo | £450.00/mo |
| 76–200 rooms | £1,500/mo | £2,000/mo |
| 201+ rooms | £5,000/mo | £5,500/mo |
Your tier is determined by room count. Boutique tier is for properties with 10–75 rooms. Sponsored tier is for 76–200 rooms. Direct tier is for 201+ rooms. Founding hotels receive 25% off Year 1 (boutique) or 50% off (full-service). Voice add-on is optional at every tier. Onboarding (staff training, PMS configuration, vendor setup, brand calibration) is included at no additional cost — but requires 1–2 weeks of hotel staff time.
Included With Every Tier — No Add-Ons, No Modules
How Lucy Funds Herself
The Sponsored tier is subsidised by vendor commission on bookings processed through Lucy (dining, experiences, spa, transport). Vendors offer 5–15% commission per category — GSI retains this on the Sponsored tier to reduce your monthly licence fee by approximately 50%. The Direct tier gives you full white-label control: the hotel retains 100% of vendor commission and pays the full licence fee. Pricing scales with property size — request a tailored quote for your property.
Real Pricing: Lucy vs Everyone Else
Competitor pricing is indicative, based on publicly available information and published case studies. Pricing varies significantly by property size, contract terms, and region. Lucy's pricing is transparent — theirs often isn't. Request a tailored quote for accurate comparison.
| Platform | Price (300-room hotel) |
|---|---|
| Lucy (Sponsored) | £1,500–£2,000/mo |
| Lucy (Direct) | £5,000–£5,500/mo |
| Chatlyn | £4,500–£7,500/mo |
| Duve | £5,000–£8,000/mo |
| Canary | £4,000–£10,000/mo |
| ALICE (Actabl) | £2,000–£5,000/mo |
| Decagon.ai | £8,000–£15,000/mo |
*Competitor pricing is indicative, based on publicly available information researched in Q1 2026. Pricing may have changed since research date. Actual pricing varies by property size, contract terms, and region. Request a tailored quote for accurate comparison.
Optional Capacity Upgrades (Not Required)
The standard plan includes a daily conversation cap that covers the vast majority of hotels. These optional upgrades are for properties with exceptionally high guest engagement during peak periods — they are clearly priced, never hidden, and not required for normal operation.
Peak Season Boost
+£250.00/moTiming: Dec, Apr, Sept
Increases daily conversation cap by 50%
Unlimited Pool
+£500.00/moTiming: All year
Removes daily conversation cap entirely
Ready to Transform Your Guest Experience?
Boutique properties start at £350.00/mo. Full-service hotels start at £1,500/mo (Sponsored) or £5,000/mo (Direct). Add voice when ready. No setup fees, no per-room charges. See Lucy in action at your property.
EU Funding & Grant Opportunities
Separate from pricing — these funding opportunities can offset implementation costs for European properties.
Single Hotel (200-300 Room)
Up to €50,000
SME Phase 1 — feasibility study & digital transition setup via Horizon Europe portal. Typical success rate: 8–12%.
Scale Rollout (5+ Hotels)
€500k–€2.5M
EIC Accelerator — requires formal deep-tech qualification and comprehensive application. Typical success rate: 5–8%.
Staff Training & Adoption
Up to €10,000
Per property — via national/regional digitalization voucher programs for hospitality tech.
🇵🇹🇬🇷Portugal & Greece — Country-Specific Subsidies
🇵🇹 Portugal — SIFIDE R&D Tax Credit
Up to 82.5% of costs
Hotel claims back up to 82.5% of Lucy deployment costs via corporate income tax credit (SIFIDE II). Annual filing, state-backed, fast to close — makes the pilot near-zero net cost. Verified via ANI.pt and OECD INNOTAX.
🇵🇹 Portugal — HERITAGE-06 Partner
€550,000 if grant wins
Hotel becomes a named EU Horizon Europe deployment co-applicant. If the HERITAGE-06 grant wins, the hotel receives €550,000 as partner allocation. 97% alignment score. Deadline: Sep 2027.
🇬🇷 Greece — ESPA 2021–2027
€50k–€500k
EU Structural Funds (ESPA) cover digital tourism transformation costs. Rolling deadlines. Budget increased by €250M in Dec 2025 for tourism SMEs. Hotel applies via regional managing authority.
🇬🇷 Greece — HERITAGE-06 Site
€550,000 if grant wins
Greece has the most diverse international visitor mix in Europe — ideal multilingual research dataset. Named Horizon Europe deployment site. Erasmus+ VET available for staff upskilling.
Model Your ROI — Interactive Calculator
Adjust room count, occupancy, ADR, and tier to see your projected revenue, savings, and net position. All figures scale to your property size and update in real-time. Boutique hotels (10+ rooms) are fully supported.
Interactive ROI Calculator
Adjust the sliders to model your property. All figures update in real-time and scale to your room count.
Range: 10 (boutique) – 500 (large resort)
Revenue
£147,276
£490.92/room
Savings
£46,000
£153.33/room
Cost
£60,000
£200.00/room
Net Year 1 (cash)
+£95,676
+£318.92/room
Incl. indirect savings: +£141,676
Chatbot / AI assistant
£200/mo
Translation tool
£100/mo
Concierge / guest app
£150/mo
Upsell engine
£100/mo
Review manager
£150/mo
Existing software
£700/mo
→
Lucy (Direct)
£5,000/mo
You save
£-4,300/mo
| Line Item | Without | With Lucy | Delta |
|---|---|---|---|
| OTA commission saved | £0 | £48,290 | +£48,290 |
| Vendor commission | £0 | £18,002 | +£18,002 |
| In-stay upsells | £3,600 | £12,000 | +£8,400 |
| Review-driven bookings | £1,533 | £7,665 | +£6,132 |
| Direct booking engine | £0 | £61,320 | +£61,320 |
| Staff redeployment value | £0 | £46,000 | +£46,000 |
| Software avoidance | −£8,400 | £0 | +£8,400 |
| Lucy platform cost | £0 | −£60,000 | −£60,000 |
| Net Annual Position | −£3,267 | +£133,276 | +£136,543 |
Break-even at Month 7.5 — £95,676 annual profit thereafter.
300-room hotel · 80% occupancy · Direct tier · Realistic (base case)
Net Year 1 (cash): +£95,676 (+£318.92/room)
Net (direct revenue, 5 streams)
+£95,676
Net (incl. indirect savings)
+£141,676
Gross benefit
£201,676
Platform cost (annual)
£60,000
ROI
159%
Payback period
7.5 months
DISCLAIMER
These projections are pre-deployment estimates based on industry benchmarks and assumed conversion rates — not historical results. Actual results depend on implementation quality, guest profile, market conditions, and vendor partner recruitment. Vendor commission is retained 100% by the hotel on the Direct tier, 25% on the Sponsored tier, and split 50/50 on the Boutique tier. Indirect savings (staff redeployment, software avoidance) represent redeployed labour and avoided cost — not new cash revenue. Use these figures for planning purposes only. Request a custom ROI model for your property.
Third-Party Data Processors
Every third party that processes guest data on Lucy's behalf is listed here. Each sub-processor has been assessed for security, compliance, and data protection standards. Hotel data controllers should review this register as part of their procurement due diligence. This register is aligned with the Data Processing Agreement (DPA) template.
| Sub-Processor | Purpose | Data Region | Data Processed | Compliance |
|---|---|---|---|---|
Base44 Platform (Application Layer) | Primary application platform — hosts Lucy, manages all guest data, preferences, bookings, and operational records. Data is stored in PostgreSQL with row-level isolation via hotel_id. The underlying database is hosted by Supabase (see below). Dedicated single-tenant database pods (separate DB per property) are on the roadmap for Q4 2026 | EU | Guest profile data, conversation history, booking records, staff data | GDPR-ready · Encryption at rest via platform-managed keys |
Supabase (Database Infrastructure) | Database hosting and infrastructure — provides the managed PostgreSQL instance and real-time APIs that back the Base44 application platform. This is the physical database layer where all Lucy data is stored | EU (Frankfurt) | All application data stored in the Base44 database layer (same data as Base44 Platform above — Supabase is the infrastructure provider, not a separate processor of the data) | SOC 2 Type II, ISO 27001, GDPR DPA available |
Stripe Inc | Payment processing — tokenised card payments for bookings, room service, and vendor orders. No raw card data stored by Lucy | US (SCCs in place) | Payment method tokens, transaction records (3DS, SCA) | PCI-DSS Level 1, SOC 2 Type II |
Google (Gemini) | Primary LLM — natural language understanding, conversation generation, reasoning. Google Search is used via Gemini for live web queries (exchange rates, events, weather) | US (SCCs in place) | Conversation text, guest queries, context prompts, search queries | ISO 27001, SOC 2, GDPR DPA available |
OpenAI | Fallback LLM — used when primary LLM is unavailable (circuit breaker) | US (SCCs in place) | Conversation text, guest queries (fallback only) | SOC 2 Type II, GDPR DPA available |
Fish Audio | Text-to-speech (TTS) — voice synthesis for Lucy's spoken responses | EU & US | Greeting text and response text for audio synthesis | GDPR DPA available on request |
Deepgram | Speech-to-text (STT) — planned provider for transcribing guest voice commands to text. Not yet processing live guest data — current STT uses Web Speech API + Whisper. Deepgram will be activated after pilot validation | US (SCCs in place) | Audio recordings of guest voice commands (transient, when activated) | SOC 2 Type II, GDPR DPA available |
Twilio | PSTN voice bridge — optional telephony integration for voice calls from room phones to Lucy | EU & US | Call routing metadata (no call content stored) | SOC 2, ISO 27001, GDPR DPA available |
Current deployments use row-level isolation via hotel_id within a shared PostgreSQL instance — every hotel-scoped query filters by hotel_id, ensuring no guest data crosses hotel boundaries. No data is shared between hotels or used for cross-tenant model training. A dedicated single-tenant architecture (separate database pods per property) is on the roadmap for Q4 2026. Data retention: 90 days post-checkout for conversation data; guest preferences retained per hotel policy. A full data retention schedule and DSAR process is documented in the Data Processing Agreement.
Compliance & Security Architecture
Lucy is one of the few hotel AI platforms that publishes its data exposure model. Every field is classified, every access is logged, every deletion is tracked, and every guest data point is protected by design — not by policy. Seven compliance pillars, each backed by dedicated backend functions and immutable audit entities. Aligned with GDPR, PCI-DSS, and NIS2 requirements. GDPR tooling is built and operational; PCI-DSS certification and formal WCAG 2.1 AA accessibility audit are in progress.
GDPR Compliance — UK GDPR & DPA 2018
Lucy is built GDPR-first, not GDPR-adapted. Data minimisation is enforced at the code level — every memory write passes through enforceDataMinimisation. No voice recordings are stored permanently — WAV files are deleted after transcription. PII is auto-redacted in all logs via piiAutoDetectionRedaction. The right to erasure is automated via a nightly scheduled scan (automatedGDPRDeletion). Data subject access requests are tracked with a 30-day SLA. Every data access is logged to an immutable audit trail.
- No voice recordings stored permanently — WAV deleted after transcription
- PII auto-redaction in all logs (piiAutoDetectionRedaction function)
- enforceDataMinimisation — checks every memory write before it commits
- Automated nightly GDPR deletion scan (automatedGDPRDeletion)
- 30-day SLA tracking for all data subject access requests (handleGDPRDataRequest)
- Consent management per category per guest (ConsentLog entity)
- Immutable audit trail via GDPRAuditLog entity — every access, every deletion
- GDPR compliance audit: conductGDPRComplianceAudit function — generates audit-ready report
- Data hosted on Base44 platform infrastructure (PostgreSQL) with encryption at rest
- Encryption at rest via platform-managed keys
PCI-DSS Payment Compliance
All payment processing is handled by Stripe — Lucy never touches raw card data. PaymentIntent with 3D Secure (3DS) and Strong Customer Authentication (SCA) for PSD2 compliance. Buy Now Pay Later (BNPL) options are available via Stripe's payment methods where supported. As Lucy never stores or transmits raw card data, the platform operates within Stripe's PCI-DSS Level 1 certified environment. Digital tipping via Stripe with full amount passed to staff.
- Stripe PaymentIntent — Lucy never stores or transmits raw card data
- 3D Secure (3DS) + Strong Customer Authentication (SCA) for PSD2 compliance
- BNPL options available via Stripe's supported payment methods (region-dependent)
- Digital tipping via processDigitalTip function → Stripe (full amount to staff)
- Operates within Stripe's PCI-DSS Level 1 certified environment
- PaymentTransaction entity tracks every charge, refund, and status
NIS2 Directive Compliance
Lucy complies with the EU NIS2 directive for cybersecurity risk management. Breach notification is automated via notifyNIS2Breach. Security incidents are tracked in a dedicated SecurityIncident entity. The adversarial attack simulator runs red-team penetration tests against the platform. Security posture reports are generated weekly via securityPostureReporter.
- NIS2 breach notification automation (notifyNIS2Breach function)
- SecurityIncident entity — dedicated incident tracking with severity and status
- Adversarial attack simulator — red-team penetration testing (adversarialAttackSimulator)
- Weekly security posture reports (securityPostureReporter)
- Rate limiting: per-user throttle (rateLimiterPerUser) + IP-based DDoS protection
- Circuit breaker: automatic LLM failover (Gemini → OpenAI) on timeout
- Graceful degradation maintains basic service during outages
Voice Identity Verification
When a guest interacts via voice, Lucy is prohibited from accessing or confirming any guest data beyond two fields tied to their currently active reservation. Email is taken from the OAuth token — never from user input. If no active reservation matches today's date, Lucy declines to confirm any identity information and directs the guest to the front desk. No exceptions, no overrides, no LLM discretion.
- Only guest_name and room_number confirmed via voice — nothing else
- Email taken from OAuth token, never from user input
- Active reservation filter: check_in ≤ today ≤ check_out AND status ≠ checked_out
- Check-in/out dates, booking reference, room type, dietary data — all blocked
- Payment status and ID document URLs — PCI and highest GDPR category, never exposed
- Cross-guest data access architecturally blocked, not just policy-prohibited
Per-Hotel Data Isolation
Every hotel-scoped entity includes a hotel_id field, and every query filters by it — ensuring no guest data crosses hotel boundaries. Hotel IDs follow a slug format (e.g. 'cafe-royal-london'). Cross-guest data access is architecturally blocked at the query layer, not just policy-prohibited. A dedicated single-tenant architecture (separate database pods per property) is on the roadmap for Q4 2026; current deployments use row-level isolation via hotel_id within a shared PostgreSQL instance.
- hotel_id field on every hotel-scoped entity — enforced at schema level
- Every query filters by hotel_id — no cross-hotel data leakage
- HotelConfiguration.hotel_id is the anchor for all tenant isolation
- Cross-guest data access architecturally blocked at query layer
- Dedicated single-tenant database pods (separate DB per property) — roadmap Q4 2026
Audit-Ready Compliance Trail
Every Lucy action is traceable to a rule, function, or human decision. The AuditLog entity records every state change across the platform. GDPRConsentLog tracks consent per category per guest. GDPRDataRequest tracks DSAR fulfilment with 30-day SLA. GDPRDataDeletion records every deletion event. All audit logs are immutable — they cannot be modified or deleted by any user, including admins.
- AuditLog entity — every state change, every function call, every data access
- GDPRConsentLog — tracks consent per category per guest with timestamps
- GDPRDataRequest — DSAR fulfilment tracking with 30-day SLA
- GDPRDataDeletion — records every deletion event with verification
- GDPRAuditLog — immutable audit trail, cannot be modified or deleted
- Every action traceable to a rule, function, or human decision
Data Security Architecture
Authentication is handled via Base44 OAuth 2.0 with email magic links. Rate limiting is enforced per-user (rateLimiterPerUser) and per-IP (rateLimitingDDoSProtection). A circuit breaker provides automatic LLM failover from Gemini to OpenAI on timeout, with graceful degradation maintaining basic service during outages. Data is hosted on the Base44 platform infrastructure with encryption at rest. Security posture reports are generated weekly, and an adversarial attack simulator runs red-team penetration tests against the platform.
- Base44 OAuth 2.0 authentication + email magic links — no passwords stored
- Per-user rate limiting (rateLimiterPerUser) + IP-based DDoS protection (rateLimitingDDoSProtection)
- Circuit breaker — automatic LLM failover (Gemini → OpenAI) on timeout
- Graceful degradation — maintains basic service during full outages
- Data hosted on Base44 platform infrastructure with encryption at rest
- Weekly security posture reports (securityPostureReporter)
- Red-team adversarial attack simulator (adversarialAttackSimulator) — continuous penetration testing
Voice Identity Data Exposure Model
What Lucy can and cannot confirm during a voice session — published, enforced, auditable. No exceptions, no overrides, no LLM discretion.
| Data Field | Exposed via Voice | Reason |
|---|---|---|
| Guest Name | ✓ Yes | Required for identity confirmation |
| Room Number | ✓ Yes | Required for service routing |
| Check-in / Check-out Dates | ✗ No | Could expose stay duration |
| Booking Reference | ✗ No | Sensitive reservation identifier |
| Room Type | ✗ No | Not required for voice verification |
| Dietary Requirements | ✗ No | GDPR special category — health data |
| Special Requests | ✗ No | May contain sensitive personal information |
| Payment Status / Payment Intent ID | ✗ No | Financial data — PCI scope |
| ID Document URL | ✗ No | Biometric / identity data — highest GDPR category |
| Other Guests' Data | ✗ No | Cross-guest access architecturally blocked |
If no active reservation matches today's date, Lucy returns verified: false and directs the guest to the front desk. No exceptions, no overrides, no LLM discretion.
Formal Legal Agreements
Downloadable template agreements for enterprise procurement review. Both documents are designed to address UK GDPR Article 28 requirements and are governed by the laws of England & Wales. These templates have not been reviewed by a qualified solicitor — replace bracketed placeholders with your property details and have your legal counsel review before executing.
Data Processing Agreement
Designed to address GDPR Article 28 requirements. Covers sub-processors, security measures, data retention, breach notification, international transfers, and audit rights.
View DPA
Service Level Agreement
99.5% target uptime, latency targets, incident response (P1–P4), service credit remedy clauses, backup & recovery (RTO/RPO), and termination rights.
View SLA
Both documents are templates — not legal advice. Have a qualified solicitor review before executing.
UK Regulatory Compliance Suite
Lucy includes a comprehensive suite of 25 UK regulatory compliance modules — each backed by a dedicated database entity, a dedicated page, and wired into the Hotel Operations Hub navigation. From EICR electrical safety to COSHH chemical registers, from RIDDOR accident reporting to UK GDPR breach management — your property's compliance is managed, tracked, and audit-ready within a single platform. We are not aware of any competitor that offers an equivalent built-in regulatory compliance suite at this depth.
EICR Register
BS7671 (Electrical Safety)
Fixed wiring electrical installation condition reports. Tracks inspection date, competent person, result (satisfactory/unsatisfactory), certificate reference, C1/C2/C3 defect codes, and next due date (maximum 5 years).
Gas Safety Register
Gas Safety Regs 1998 (CP12)
Gas appliance safety records for boilers, cookers, hobs, water heaters, and fires. Tracks Gas Safe registered engineer, gas safe number, CP12 certificate reference, and next due date.
Fire Safety Log Book
RRFSO 2005
Fire safety checks including alarm tests, emergency lighting, fire drills, extinguisher checks, and fire door checks. Tracks result (pass/fail/partial), location, and next due date.
Fire Risk Assessment
RRFSO 2005
Comprehensive fire risk assessments covering premises, hazards, persons at risk, and control measures. Required under the Regulatory Reform (Fire Safety) Order 2005.
Legionella Temperature Log
HSE ACOP L8
Water temperature monitoring for legionella prevention. Tracks tap type, temperature, in-range status, and corrective actions. Required under HSE Approved Code of Practice L8.
COSHH Register
COSHH Regs 2002
Control of Substances Hazardous to Health. Tracks product name, hazard level, storage location, safety data sheet URL, and first aid measures for every chemical on site.
HACCP Temperature Log
EC 852/2004 (Food Hygiene)
Food safety temperature monitoring for refrigerators, freezers, and hot holding. Tracks temperature, check time, and corrective action when out of range.
Asbestos Register
CAR 2012
Asbestos-containing material register under the Control of Asbestos Regulations 2012. Tracks location, material type, condition, risk level, and management action (manage, encapsulate, remove, monitor).
Accident Book
RIDDOR 2013
Accident recording for guests, staff, contractors, and visitors. Tracks injury type, severity, first aid administered, hospital visit, and RIDDOR reportable status with HSE reference number.
PAT Testing Register
Electricity at Work Regs 1989
Portable Appliance Testing records for all portable electrical equipment. Tracks item name, asset tag, test date, result (pass/fail/visual only), and next due date.
Lift Inspection Log
LOLER 1998 / PUWER 1998
Lift thorough examination and routine service records under Lifting Operations and Lifting Equipment Regulations. Tracks lift identifier, inspection type, result, defects, and next due date.
Pest Control Log
Food Safety Act 1990
Pest control activity and monitoring logs. Tracks pest type, location, action taken, and next visit date. Required for food safety compliance.
Waste Transfer Log
Environmental Protection Act 1990
Waste transfer notes for general, recyclable, food, hazardous, glass, and cardboard waste. Tracks licensed waste carrier, carrier license, disposal site, and consignment note reference.
First Aid Kit Check
Health & Safety (First Aid) Regs 1981
First aid kit inspection records. Tracks kit location, items complete status, missing items, expired items, restocked status, and next check date.
Noise Complaint Register
Environmental Protection Act 1990
Noise complaint tracking for statutory nuisance. Tracks complainant type, noise source, status, and resolution timestamp.
Emergency Command Centre
RRFSO 2005 / NIS2
Emergency protocol management with severity levels, escalation steps, and contact lists. Integrates with NIS2 directive breach notification requirements.
Premises Licence Tracker
Licensing Act 2003
Premises licence, personal licence, DPS, and club premises certificate tracking. Tracks licence number, holder name, issuing authority, conditions, and expiry date.
Health & Safety Policy Register
HSWA 1974
Health and safety policy document register under the Health and Safety at Work Act 1974. Tracks policy title, version, issue date, review due date (must be reviewed annually), and approval status.
Risk Assessment Register
MHSWR 1999
Risk assessment records under the Management of Health and Safety at Work Regulations. Tracks task or area, department, hazards, who is at risk, risk level, and control measures.
Property Walk Audit
HSWA 1974
Property walk audit records for daily, weekly, monthly, and pre-event inspections. Tracks areas checked, defects found, defect count, actions taken, follow-up requirements, and overall rating.
Manual Handling Assessment
MHOR 1992
Manual handling operation risk assessments. Tracks task name, load weight, frequency, risk level, existing control measures, and recommendations.
Lone Worker Monitor
HSWA 1974 / MHSWR
Lone worker check-in system for staff working alone. Tracks staff name, check-in time, location, status, and next check-in time.
DBS Check Tracker
Safeguarding Vulnerable Groups Act 2006
Disclosure and Barring Service criminal record check tracking. Tracks DBS type, check date, result, and renewal due date.
Staff Holiday Manager
Working Time Regs 1998
Staff leave management under the Working Time Regulations. Tracks staff name, department, leave type (annual, sick, unpaid, compassionate, maternity), dates, days off, and approval status.
GDPR Breach Register
UK GDPR / DPA 2018
Personal data breach register as required under UK GDPR Article 33. Tracks breach type, discovery date, severity, containment measures, and notification status.
135 Operational Tools Across 18 Sections
The UK Regulatory Compliance Suite is part of Lucy's Hotel Operations Hub — a staff-facing command centre comprising 135 operational tools across 18 sections. Every tool has a dedicated page, a dedicated entity, and is wired into the hub navigation. This is a code-complete count based on internal review — production validation requires the first live deployment.
135
Operational Tools
18
Sections
25
UK Compliance Modules
0
Gaps Identified (Internal Review)
EU Regulatory Compliance Suite
Every UK compliance module maps directly to its EU directive equivalent. The same 25 operational modules — from electrical safety to GDPR breach registers — are jurisdiction-aware, showing the correct EU regulation reference, competent authority, and inspection interval for any member state. On top of this, 8 EU digital regulations (AI Act, GDPR, NIS2, DSA, ePrivacy, Accessibility Act, Consumer Rights, and Data Processing Agreements) are enforced in code — not just documented in policy.
EU Digital Regulations — Enforced in Code
These 8 EU regulations are not just documented — they are enforced by dedicated backend functions that validate every response before it reaches the guest.
EU AI Act Compliance
Regulation 2024/1689 — Articles 5, 13, 14, 52
Four AI Act articles enforced in code: Article 5 (prohibited dark patterns blocked), Article 13 (explainable AI on request), Article 14 (human override gate for high-impact decisions), Article 52 (AI identity disclosure when asked).
EU GDPR (Full Data Rights)
Regulation 2016/679 — Articles 5, 15, 17, 20
Data minimisation enforced at code level on every memory write. Right to erasure across 7 entity types. Data subject access requests with structured JSON export covering 8 data categories. 30-day SLA tracking.
NIS2 Directive (Cybersecurity)
Directive 2022/2555 — Article 23
Automated cybersecurity incident pipeline with 72-hour breach notification. CSIRT contact database for all 27 EU member states plus UK, Norway, Sweden, Denmark, and Finland. Flags incidents exceeding the 72-hour deadline.
Digital Services Act (DSA)
Regulation 2022/2065 — Article 27
Guests can switch to objective, criteria-based recommendations with zero AI profiling. Ranking criteria fully disclosed with every response. Non-personalised mode available on every recommendation surface.
ePrivacy Directive + PECR
Directive 2002/58/EC + PECR
Explicit opt-in/opt-out recorded for all electronic marketing: push, email, SMS, AI profiling, and voice biometrics. Consent text version tracked. No pre-ticked boxes, no default opt-ins.
EU Accessibility Act 2025
Directive 2019/882 — WCAG 2.1 AA
18 WCAG 2.1 AA criteria passed: aria-live regions, keyboard navigation, 48px touch targets, RTL support for Arabic/Hebrew/Farsi/Urdu/Kurdish, focus-visible, dynamic HTML lang, minimum 4.5:1 contrast ratio.
Consumer Rights Directive
Directive 2011/83/EU — Article 9
Mandatory 14-day cooling-off period enforced and disclosed for qualifying bookings. Eligible cancellations processed with full refund within 14 days as required under EU consumer protection law.
EU Data Processing Agreement
GDPR Article 28(3)
Standard contractual clauses and data processing agreement template available for EU properties. Covers sub-processor register, data retention schedules, cross-border transfer mechanisms, and right-to-audit provisions.
EU Operational Compliance Modules — Same Entities, EU References
Each of the 25 UK compliance modules maps directly to its EU directive equivalent. The underlying database entity and page are shared — only the regulation reference, competent authority, and inspection interval adapt to the property's jurisdiction.
Electrical Installation Inspection
EU Directive 2014/35/EU (Low Voltage) + EN 50110
Fixed wiring electrical installation condition reports under the Low Voltage Directive and EN 50110 operation of electrical installations. Tracks inspection date, competent person, result, certificate reference, C1/C2/C3 defect codes, and next due date (maximum 5 years).
Gas Appliance Safety Record
EU Regulation 2016/426 (GAR)
Gas appliance safety records for boilers, cookers, hobs, water heaters, and fires under the EU Gas Appliances Regulation. Tracks qualified engineer, gas safe number, certificate reference, and next due date.
Fire Safety Log Book
EU Directive 89/106/EEC (CPD) + EN 54
Fire safety checks including alarm tests, emergency lighting, fire drills, extinguisher checks, and fire door checks under the Construction Products Directive and EN 54 fire detection standard. Tracks result, location, and next due date.
Fire Risk Assessment
EU Regulation 305/2011 (CPR)
Comprehensive fire risk assessments covering premises, hazards, persons at risk, and control measures under the EU Construction Products Regulation. Required for all hospitality premises in EU member states.
Legionella Temperature Log
EU Directive 2000/54/EC (Biological Agents)
Water temperature monitoring for legionella prevention under the EU Biological Agents Directive. Tracks tap type, temperature, in-range status, and corrective actions as required by national transpositions.
Chemical Safety Register (REACH/CLP)
EU Regulation 1907/2006 (REACH) + 1272/2008 (CLP)
Control of Substances Hazardous to Health — EU equivalent under REACH and CLP regulations. Tracks product name, hazard classification, GHS pictograms, storage location, safety data sheet URL, and first aid measures for every chemical on site.
HACCP Temperature Log
EU Regulation 852/2004 (Food Hygiene)
Food safety temperature monitoring for refrigerators, freezers, and hot holding under EU Regulation 852/2004 on the hygiene of foodstuffs. Tracks temperature, check time, and corrective action when out of range.
Asbestos Register
EU Directive 2009/148/EC (Asbestos)
Asbestos-containing material register under EU Directive 2009/148/EC on the protection of workers from asbestos exposure. Tracks location, material type, condition, risk level, and management action (manage, encapsulate, remove, monitor).
Workplace Accident Register
EU Directive 89/391/EEC (Framework) + 2009/104/EC
Workplace accident and incident recording for guests, staff, contractors, and visitors under the EU Framework Directive 89/391/EEC. Tracks injury type, severity, first aid administered, hospital visit, and reportable status with national authority reference.
Portable Appliance Testing
EU Directive 2014/35/EU (Low Voltage)
Portable Appliance Testing records for all portable electrical equipment under the EU Low Voltage Directive. Tracks item name, asset tag, test date, result (pass/fail/visual only), and next due date.
Lift Inspection Log
EU Directive 2014/33/EU (Lifts)
Lift thorough examination and routine service records under the EU Lifts Directive 2014/33/EU. Tracks lift identifier, inspection type, result, defects, and next due date.
Pest Control Log
EU Regulation 852/2004 (Food Hygiene)
Pest control activity and monitoring logs under EU Regulation 852/2004 on food hygiene. Tracks pest type, location, action taken, and next visit date. Required for food safety compliance.
Waste Transfer Log
EU Directive 2008/98/EC (Waste Framework)
Waste transfer notes for general, recyclable, food, hazardous, glass, and cardboard waste under the EU Waste Framework Directive. Tracks licensed waste carrier, carrier license, disposal site, and consignment note reference.
First Aid Kit Check
EU Directive 89/391/EEC (Framework)
First aid kit inspection records under the EU Framework Directive 89/391/EEC on health and safety at work. Tracks kit location, items complete status, missing items, expired items, restocked status, and next check date.
Noise Complaint Register
EU Directive 2002/49/EC (Environmental Noise)
Noise complaint tracking under the EU Environmental Noise Directive. Tracks complainant type, noise source, status, and resolution timestamp as required by national transpositions.
Emergency Command Centre
EU Directive 2002/59/EC (Vessel Traffic) + NIS2
Emergency protocol management with severity levels, escalation steps, and contact lists. Integrates with NIS2 directive breach notification requirements and national emergency response frameworks.
Premises Licence Tracker
National Licensing Law (EU Member State)
Premises licence, personal licence, and alcohol service certification tracking under each EU member state's national licensing law. Tracks licence number, holder name, issuing authority, conditions, and expiry date.
Health & Safety Policy Register
EU Directive 89/391/EEC (Framework)
Health and safety policy document register under the EU Framework Directive 89/391/EEC. Tracks policy title, version, issue date, review due date (must be reviewed annually), and approval status.
Risk Assessment Register
EU Directive 89/391/EEC (Framework)
Risk assessment records under the EU Framework Directive 89/391/EEC on the introduction of measures to encourage improvements in the safety and health of workers. Tracks task or area, department, hazards, who is at risk, risk level, and control measures.
Property Walk Audit
EU Directive 89/391/EEC (Framework)
Property walk audit records for daily, weekly, monthly, and pre-event inspections. Tracks areas checked, defects found, defect count, actions taken, follow-up requirements, and overall rating.
Manual Handling Assessment
EU Directive 90/269/EEC (Manual Handling)
Manual handling operation risk assessments under EU Directive 90/269/EEC on the minimum health and safety requirements for the manual handling of loads. Tracks task name, load weight, frequency, risk level, existing control measures, and recommendations.
Lone Worker Monitor
EU Directive 89/391/EEC (Framework)
Lone worker check-in system for staff working alone under the EU Framework Directive. Tracks staff name, check-in time, location, status, and next check-in time.
Background Check Tracker
National Law (EU Member State)
Criminal record background check tracking under each EU member state's national law on safeguarding vulnerable groups. Tracks check type, check date, result, and renewal due date.
Staff Leave Manager
EU Directive 2003/88/EC (Working Time)
Staff leave management under the EU Working Time Directive 2003/88/EC. Tracks staff name, department, leave type (annual, sick, unpaid, compassionate, maternity), dates, days off, and approval status.
GDPR Breach Register
EU GDPR (Regulation 2016/679) Art.33
Personal data breach register as required under EU GDPR Article 33. Tracks breach type, discovery date, severity, containment measures, and 72-hour notification status to the relevant supervisory authority.
Jurisdiction-Aware by Design
Lucy's compliance modules are jurisdiction-aware. A hotel in Lisbon sees EU regulation references (EN 50110, REACH, Directive 2009/148/EC) and Portuguese competent authority contacts. The same hotel in London sees UK references (BS7671, COSHH, CAR 2012) and HSE contacts. The underlying entity, page, and data structure are identical — only the regulatory labelling adapts. This means a multi-property group operating across the UK and EU can manage all compliance from a single dashboard with jurisdiction-correct references on every record.
25
EU Operational Modules
8
EU Digital Regulations (Code-Enforced)
27
EU Member States Supported
0
Gaps Identified (Internal Review)
USA Regulatory Compliance Suite
The same 25 operational compliance modules — from ADA accessibility to OSHA injury logging — are mapped to their US federal equivalents (OSHA, NFPA, FDA, EPA, TTB). On top of this, 8 US digital regulations (ADA Title III, CCPA/CPRA, state breach laws, CAN-SPAM, PCI DSS, FTC Act §5, HIPAA, and the FTC Hotel Price Transparency Rule) are enforced in code. State-level variations are tracked for the top 6 hotel markets.
US Digital Regulations — Enforced in Code
These 8 US federal regulations are not just documented — they are enforced by dedicated backend functions that validate every response before it reaches the guest.
ADA Title III (Digital Accessibility)
42 U.S.C. § 12181 + DOJ 2024 Rule
DOJ's 2024 final rule explicitly requires WCAG 2.1 AA compliance for public accommodation websites and mobile apps. Lucy passes all 18 WCAG 2.1 AA criteria: aria-live regions, keyboard navigation, 48px touch targets, screen reader support, and minimum 4.5:1 contrast ratio.
CCPA / CPRA (California Privacy)
Cal. Civ. Code § 1798.100
California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA). Guests can request data access, deletion, and opt-out of data sale. Data minimisation enforced at code level. 45-day response SLA tracked. Covers all California guests regardless of hotel location.
State Data Breach Notification
All 50 State Breach Laws
All 50 US states have individual data breach notification laws with varying thresholds and timelines. Lucy's breach notification engine is adapted per state: California (unreasonable delay), New York (SHIELD Act), Florida (FIPA 30 days), Texas (60 days), with attorney general notification where required.
CAN-SPAM Act (Email Marketing)
15 U.S.C. § 7701
CAN-SPAM Act compliance for commercial email: clear identification, physical postal address, unsubscribe mechanism (honoured within 10 business days), and no deceptive subject lines. Marketing consent tracked with opt-in/opt-out per channel.
PCI DSS (Payment Security)
PCI DSS v4.0 (March 2022)
Payment Card Industry Data Security Standard v4.0. Lucy never stores, processes, or transmits card data directly — all payments flow through Stripe's PCI-DSS Level 1 certified infrastructure. Tokenisation, 3D Secure, and SCA (Strong Customer Authentication) supported.
FTC Act § 5 (Unfair/Deceptive Practices)
15 U.S.C. § 45
Federal Trade Commission Act Section 5 prohibits unfair or deceptive acts or practices. Lucy's anti-manipulation gate blocks dark patterns in upsell flows, and the upsell ethics gate ensures recommendations are genuinely beneficial, not pressure-driven.
HIPAA (If Health Services)
45 CFR 160 + 164
Health Insurance Portability and Accountability Act applies if the hotel offers spa, wellness, or medical services. Lucy's PII auto-detection and redaction engine identifies and protects health information. Data minimisation enforced on every memory write.
FTC Hotel Price Transparency Rule
16 CFR Part 465 (2024)
FTC's 2024 Hotel Price Transparency Rule requires disclosure of all mandatory fees (resort fees, cleaning fees) in the advertised price. Lucy's unified checkout fee engine surfaces all mandatory fees upfront — no hidden charges at checkout.
US Operational Compliance Modules — Federal Equivalents
Each of the 25 compliance modules maps to its US federal equivalent. The underlying database entity and page are shared — only the regulation reference, competent authority, and inspection interval adapt to the property's jurisdiction.
ADA Title III Compliance
Americans with Disabilities Act (42 U.S.C. § 12181)
Public accommodation accessibility compliance under ADA Title III. Lucy's interface meets WCAG 2.1 AA, supports screen readers, keyboard navigation, 48px touch targets, and provides accessible communication channels for guests with disabilities.
NFPA Fire Safety (Life Safety Code)
NFPA 101 (2024 Edition)
Fire safety inspection logging aligned with NFPA 101 Life Safety Code. Tracks alarm tests, emergency lighting, fire drills, extinguisher checks, and fire door inspections — the standard adopted by most US jurisdictions and AHJs (Authorities Having Jurisdiction).
Gas Appliance Safety (ANSI/Z21)
ANSI Z21 Series + CPSC Standards
Gas appliance safety records for boilers, cookers, and water heaters under ANSI Z21 standards and CPSC requirements. Tracks qualified technician, certification number, inspection result, and next due date per appliance.
Legionella Water Management
ASHRAE 188-2021 + CDC Guidelines
Legionella water management programme under ASHRAE 188 and CDC guidelines. Required for hotels with centralized water systems. Tracks water temperature, disinfectant levels, and corrective actions per CDC Water Management Program toolkit.
OSHA Hazard Communication (HazCom)
29 CFR 1910.1200 (HCS 2012 / GHS)
Hazard communication standard under OSHA 29 CFR 1910.1200, aligned with GHS. Tracks chemical product name, GHS pictograms, hazard statements, safety data sheets (SDS), storage location, and first aid measures for every chemical on site.
FDA Food Code (HACCP)
FDA Food Code 2022 + 21 CFR 117
Food safety temperature monitoring under the FDA Food Code 2022 and 21 CFR 117 (Preventive Controls for Human Food). Tracks cold holding (≤41°F), hot holding (≥135°F), cooking temperatures, and corrective actions when out of range.
Electrical Safety (NFPA 70E)
NFPA 70E-2024 + NEC (NFPA 70)
Electrical safety inspection records under NFPA 70E (Standard for Electrical Safety in the Workplace) and the National Electrical Code (NFPA 70). Tracks inspection date, qualified electrician, result, defect codes, and next due date.
Portable Appliance Testing
NFPA 70B (Equipment Maintenance)
Portable electrical equipment maintenance under NFPA 70B. Tracks item name, asset tag, test date, result (pass/fail/visual only), and next due date for all portable electrical devices in guest rooms and common areas.
Elevator Inspection (ASME A17.1)
ASME A17.1-2019 / CSA B44
Elevator inspection records under ASME A17.1 (Safety Code for Elevators and Escalators). Tracks lift identifier, inspection type (periodic/ Category 1/ Category 5), result, defects, and next due date per state elevator code requirements.
Pest Control (Integrated Pest Management)
EPA FIFRA + State Regulations
Pest control activity and monitoring logs under EPA FIFRA (Federal Insecticide, Fungicide, and Rodenticide Act) and state structural pest control regulations. Tracks pest type, location, treatment method, and next inspection date.
Waste Management (RCRA)
RCRA (42 U.S.C. § 6901) + EPA 40 CFR
Waste transfer and disposal records under the Resource Conservation and Recovery Act (RCRA). Tracks licensed waste hauler, carrier permit, disposal facility, and manifest reference number for general, recyclable, food, and hazardous waste.
First Aid Kit Inspection
OSHA 29 CFR 1910.151
First aid kit inspection records under OSHA 29 CFR 1910.151 (Medical Services and First Aid). Tracks kit location, items complete status, missing items, expired items, restocked status, and next check date.
Noise Complaint Register
EPA Noise Control Act + Local Ordinances
Noise complaint tracking under the EPA Noise Control Act and local municipal noise ordinances. Tracks complainant type, noise source, status, and resolution timestamp.
Emergency Action Plan (EAP)
OSHA 29 CFR 1910.38
Emergency action plan management under OSHA 29 CFR 1910.38. Tracks severity levels, escalation steps, evacuation routes, assembly points, and emergency contact lists. Integrates with local fire department and EMS notification.
Alcohol Beverage Licence (TTB + State)
TTB 27 CFR + State ABC Laws
Alcohol beverage licence tracking under TTB (Alcohol and Tobacco Tax and Trade Bureau) federal permits and state Alcoholic Beverage Control (ABC) laws. Tracks licence number, holder name, issuing authority, conditions, and expiry date.
Health & Safety Policy
OSHA 29 CFR 1904 + State OSHA Plans
Health and safety policy document register under OSHA recordkeeping requirements (29 CFR 1904) and state OSHA plans. Tracks policy title, version, issue date, annual review due date, and approval status.
OSHA 300 Injury & Illness Log
OSHA 29 CFR 1904 (300/300A/301)
OSHA injury and illness recordkeeping forms (300 Log, 300A Summary, 301 Incident Report) for workplace accidents involving guests, staff, contractors, and visitors. Tracks injury type, severity, first aid, hospital visit, and OSHA recordable status.
Fire Risk Assessment (NFPA 101)
NFPA 101 + IFC (International Fire Code)
Comprehensive fire risk assessments under NFPA 101 (Life Safety Code) and the International Fire Code (IFC). Covers premises, hazards, persons at risk, and control measures as required by the local AHJ.
Property Walk Audit
OSHA General Duty Clause (5(a)(1))
Property walk audit records for daily, weekly, monthly, and pre-event inspections under the OSHA General Duty Clause. Tracks areas checked, defects found, defect count, actions taken, follow-up requirements, and overall rating.
Manual Handling Assessment
OSHA 29 CFR 1910.176 (Materials Handling)
Manual handling operation risk assessments under OSHA 29 CFR 1910.176 (Handling Materials - General). Tracks task name, load weight, frequency, risk level, existing control measures, and recommendations.
Lone Worker Safety
OSHA 29 CFR 1910.132 (PPE)
Lone worker check-in system for staff working alone under OSHA 29 CFR 1910.132 (Personal Protective Equipment) general duty requirements. Tracks staff name, check-in time, location, status, and next check-in time.
Staff Leave Manager (FMLA)
FMLA (29 U.S.C. § 2601) + FLSA
Staff leave management under the Family and Medical Leave Act (FMLA) and Fair Labor Standards Act (FLSA). Tracks staff name, department, leave type (annual, sick, FMLA, unpaid, military), dates, days off, and approval status.
Background Check Tracker
FCRA (15 U.S.C. § 1681) + State Laws
Criminal record background check tracking under the Fair Credit Reporting Act (FCRA) and state-level ban-the-box laws. Tracks check type, check date, result, and renewal due date for all staff with guest access.
Lift / Elevator Inspection (ASME)
ASME A17.1 + ASME A18.1
Duplicate mapping: ASME A17.1 for elevators and ASME A18.1 for platform lifts and stairway chairlifts. Tracks inspection type, competent person, result, defects, and next due date per state elevator inspection code.
State-Level Variations — Top 6 Hotel Markets
US compliance is not purely federal — each state has its own OSHA plan, fire code, food safety code, and data breach notification law. Lucy tracks the applicable state regulations based on the property's location.
California
- Cal/OSHA Title 8 (stricter than federal OSHA)
- CCPA / CPRA (privacy — stricter than GDPR in some areas)
- California Retail Food Code (CalCode)
- California Building Standards Code (Title 24)
New York
- NYC Fire Code (FDNY enforcement)
- NYC Health Code Article 81 (food safety)
- NY SHIELD Act (data breach notification)
- NY State Department of Labor (hotel housekeeping safety)
Florida
- Florida Fire Prevention Code (NFPA 101 based)
- Florida Department of Health (food service)
- Florida DBPR (Division of Hotels & Restaurants)
- Florida Information Protection Act (FIPA)
Nevada
- Nevada OSHA (Plan state — federal OSHA equivalent)
- Southern Nevada Health District (food safety)
- Nevada Gaming Control Board (if casino on premises)
- NRS 449 (Medical and Health Care Facilities)
Texas
- TDLR (Texas Dept of Licensing & Regulation)
- Texas Food Establishment Rules (TFER)
- Texas State Fire Marshal's Office
- Texas Identity Theft Enforcement and Notification Act
Illinois
- Illinois OSHA (IL OSHA)
- Illinois Food Service Sanitation Code
- Chicago Fire Prevention Code
- Illinois Personal Information Protection Act (PIPA)
Federal + State + Local — All Layers Tracked
US compliance operates on three layers: federal (OSHA, EPA, FDA, FTC, ADA), state (Cal/OSHA, NY SHIELD Act, FL FIPA), and local (AHJ fire codes, county health departments). Lucy's compliance modules are jurisdiction-aware — a hotel in Los Angeles sees Cal/OSHA Title 8 and CCPA/CPRA references, while the same hotel in Miami sees Florida Fire Prevention Code and FIPA references. The underlying entity, page, and data structure are identical. A multi-property group operating across US states can manage all compliance from a single dashboard with jurisdiction-correct references on every record.
25
US Federal Modules
8
US Digital Regulations (Code-Enforced)
50
States Supported (State Law Variations)
6
Top Hotel Markets (State Detail)
Latin America Regulatory Compliance Suite
The same 25 operational compliance modules are mapped to their Latin American federal equivalents — Mexico's NOMs (Normas Oficiales Mexicanas), Brazil's NRs (Normas Regulamentadoras), Argentina's SRT, and more. On top of this, 8 digital regulations (LFPDPPP, LGPD, MERCOSUR data protection, PCI DSS, PROFECO, accessibility, COFEPRIS, and Protección Civil) are enforced in code. Country-specific regulatory frameworks are tracked for the top 6 hotel markets.
Latin America Digital Regulations — Enforced in Code
These 8 Latin American regulations are not just documented — they are enforced by dedicated backend functions that validate every response before it reaches the guest.
LFPDPPP (Mexico Data Protection)
Ley Federal de Protección de Datos Personales (2010)
Mexican Federal Law for the Protection of Personal Data Held by Private Parties. Guests can exercise ARCO rights (Access, Rectification, Cancellation, Opposition). Data minimisation enforced at code level. INAI (National Institute for Transparency) notification within 72 hours for breaches.
LGPD (Brazil Data Protection)
Lei 13.709/2018 (Lei Geral de Proteção de Dados)
Brazil's General Data Protection Law — modelled on GDPR. Guests can exercise 9 data subject rights including access, correction, deletion, portability, and opposition. ANPD (National Data Protection Authority) notification within a 'reasonable period' for breaches.
MERCOSUR Data Protection Framework
Argentina Ley 25.326 + Uruguay Ley 18.331 + Paraguay Ley 5542
MERCOSUR member states (Argentina, Brazil, Paraguay, Uruguay) each have GDPR-modelled data protection laws. Lucy's DSAR engine handles all four with country-specific supervisory authority notification and response timelines.
PCI DSS (Latin America Payments)
PCI DSS v4.0 (Global Standard)
Payment Card Industry Data Security Standard v4.0 applies globally including all Latin American countries. Lucy never stores, processes, or transmits card data directly — all payments flow through Stripe's PCI-DSS Level 1 certified infrastructure with 3D Secure and SCA.
PROFECO (Mexico Consumer Protection)
Ley Federal de Protección al Consumidor
Mexican Federal Consumer Protection Law enforced by PROFECO. All mandatory fees must be disclosed in the advertised price. Cooling-off period enforced for qualifying bookings. Recommendations must not be deceptive or pressure-driven.
Accessibility (Mexico NOM-034 + Brazil LBI)
NOM-034-SCFI + Lei Brasileira de Inclusão (LBI 13.146/2015)
Mexican NOM-034 and Brazil's Inclusion Law (LBI) require digital accessibility for public-facing services. Lucy passes all 18 WCAG 2.1 AA criteria: aria-live regions, keyboard navigation, 48px touch targets, screen reader support, and minimum 4.5:1 contrast ratio.
COFEPRIS (Mexico Health & Food Safety)
Ley General de Salud + NOM-251-SSA1
Mexican Federal Commission for Protection Against Sanitary Risks (COFEPRIS) enforces food safety, water quality, and sanitary standards. PII auto-detection and redaction engine identifies and protects health information. Data minimisation enforced on every memory write.
Protección Civil (Emergency Response)
Ley General de Protección Civil + State Laws
National Civil Protection System (SINAPROC) coordinates emergency response. Each state has its own Protección Civil authority. Lucy's emergency escalation engine is adapted per country: Mexico (PCN), Brazil (Defesa Civil), Chile (ONEMI), Colombia (UNGRD), Peru (INDECI).
Country-Specific Regulatory Frameworks
Each Latin American country has its own regulatory framework — Mexico's NOMs, Brazil's NRs, Argentina's SRT, and more. Lucy tracks the applicable regulations based on the property's location.
Mexico
MXOperational Framework
NOM (Normas Oficiales Mexicanas) + IMSS + COFEPRIS + STPS + SAT
Data Protection Law
Ley Federal de Protección de Datos Personales (LFPDPPP)
Federal system of Official Mexican Standards (NOMs) enforced by STPS (Labour), COFEPRIS (Health), and IMSS (Social Security). Data protection under LFPDPPP with ARCO rights (Access, Rectification, Cancellation, Opposition).
Brazil
BROperational Framework
NR (Normas Regulamentadoras) + ANVISA + MTE
Data Protection Law
Lei Geral de Proteção de Dados (LGPD — Lei 13.709/2018)
Regulatory Norms (NRs) enforced by Ministry of Labour (MTE). ANVISA (National Health Surveillance) for food safety. Data protection under LGPD — Brazil's GDPR equivalent with ANPD (National Data Protection Authority) oversight.
Argentina
AROperational Framework
SRT + ANMAT + Ley 19.587
Data Protection Law
Ley 25.326 (Protección de Datos Personales)
SRT (Superintendency of Labour Risks) for workplace safety. ANMAT for food and drug safety. Data protection under Ley 25.326 with AAIP (Access to Public Information Agency) oversight. AAIP registered as data controller.
Chile
CLOperational Framework
DS 594 + MINSAL + SUSESO
Data Protection Law
Ley 19.628 (Protección de la Vida Privada)
DS 594 (Sanitary and Environmental Basic Regulation) for workplace safety. MINSAL (Ministry of Health) for food safety. Data protection under Ley 19.628 with Council for Transparency oversight.
Colombia
COOperational Framework
Decreto 1072 + INVIMA + ARL
Data Protection Law
Ley 1581 de 2012 (Protección de Datos Personales)
Decreto 1072 (Single Regulatory Decree of the Labour Sector) for workplace safety. INVIMA for food and drug safety. ARL (Labour Risk Administrators) for insurance. Data protection under Ley 1581 with SIC (Superintendence of Industry and Commerce) oversight.
Peru
PEOperational Framework
DS 006-2014-TR + DIGESA + SUNAFIL
Data Protection Law
Ley 29733 (Ley de Protección de Datos Personales)
DS 006-2014-TR (Health and Safety at Work) enforced by SUNAFIL (National Superintendence of Labour Inspection). DIGESA for environmental health. Data protection under Ley 29733 with ANPDP (National Authority for Personal Data Protection) oversight.
One Platform — Every Jurisdiction
Lucy's compliance modules are jurisdiction-aware across all three regions. A hotel in Mexico City sees NOM-034 and LFPDPPP references. The same hotel in São Paulo sees NRs and LGPD references. The same hotel in Buenos Aires sees SRT and Ley 25.326 references. The underlying entity, page, and data structure are identical — only the regulatory labelling adapts. A multi-property group operating across the UK, EU, USA, and Latin America can manage all compliance from a single dashboard with jurisdiction-correct references on every record.
25
LatAm Operational Modules
8
LatAm Digital Regulations (Code-Enforced)
6
Key Markets Supported
4
Languages (ES, PT, EN, FR)
Performance & Reliability
Lucy's architecture was designed against the operational requirements of a 5-star London property — every architectural decision, latency target, and guest-experience principle on this page was engineered for real-world deployment. Metrics below are from controlled smoke tests (not full-scale load tests — the n=7 vendor booking test is a functional smoke test, not a stress test). The platform is deployment-ready and undergoing partner onboarding. Full-scale load testing will be conducted during the first pilot deployment.
269
Entity Types (40+ Core, Rest Scaffolded)
770+
Backend Functions (200+ Core)
Controlled Load Test Results — Q2 2026 (Pre-Production)
Vendor booking test (May 14, 2026): 7 bookings across all categories, 100% success, total execution time 6,982ms, all under 3s threshold. This is a functional smoke test (n=7), not a full-scale load test — it verifies that the vendor booking flow works end-to-end, not that the platform can handle production traffic volume. Latency figures are from this same controlled test. Full-scale load testing (10,000+ concurrent sessions) will be conducted during the first pilot deployment. Production metrics will replace these figures upon first deployment.
Technology Stack
Frontend
React 18 + Vite + Tailwind CSS
PWA, lazy-loaded pages, tanstack-query
Backend
Deno Deploy (Edge Functions)
770+ total functions (200+ core production), independently deployable
Database
Base44 Platform (PostgreSQL via Supabase)
269 entity types (40+ core, rest scaffolded for operations platform), multi-tenancy via hotel_id
Primary LLM
Gemini Flash 3
Via InvokeLLM; first-token latency varies (500ms–3s typical)
Fallback LLM
OpenAI GPT-4o-mini
Circuit breaker on Gemini timeout
Voice TTS
Fish Audio API
Base64 MP3, sentiment-adaptive
Voice STT
Web Speech API + Whisper
Deepgram integration in progress
Live Search
Gemini web grounding
Exchange rates, events, sports scores
Payments
Stripe (PaymentIntent + SCA)
3DS SCA, BNPL via Stripe (region-dependent)
Auth
OAuth 2.0 + magic links
Role: admin | user; public guest pages
Implementation Timeline
From contract to full guest go-live in approximately 4–6 weeks. No long IT project. No rip-and-replace. Smaller properties may complete in 3 weeks. PMS certification is not yet completed for any connector — this is the critical-path dependency and may extend the timeline to 6–8 weeks if integration issues arise during first live deployment.
🔍
Week 1
Discovery & Configuration
Hotel profile, brand voice, vendor directory, PMS credentials, room mapping. Lucy HQ panel configured.
⚙️
Week 2
Integration & Testing
PMS sync validated, Stripe payment flows tested, voice pipeline calibrated, staff trained on dashboard.
🚀
Week 3
Soft Launch
Lucy live in app for staff testing. Golden Rules enforcement verified. Vendor booking flow tested end-to-end.
✅
Week 4
Full Guest Go-Live
Lucy available to all guests. QR codes in rooms. Post-stay feedback surveys active. Handover to hotel team.
Timeline is a management projection based on a single-property deployment. Multi-property or group-level rollouts may extend timeline. PMS certification (Mews, Opera, Cloudbeds, Apaleo) is the critical-path dependency — none are certified as of September 2026.
See Lucy running in a real heritage hotel setting
- Built and tested against a Café Royal London reference deployment
- Every screen shown on this site is the real guest app, not a mock-up
- Live guest-facing metrics will be published only once measured in a partner hotel
Become a Founding Hotel
Lucy is built, tested, and deployment-ready. We are now selecting 3–5 founding hotel partners for the first live deployments. Founding partners receive:
- 50% reduced licence for the first 12 months for full-service hotels (201+ rooms), or 25% for boutique properties (10–75 rooms) — applies to either Sponsored or Direct tier
- Direct input into the product roadmap
- Co-marketing opportunities and case study exposure
- White-glove onboarding included (no setup fee)
- Priority access to new features before general release
Founding Partners
3–5 Slots
First 12 Months
25–50% Off
To Go-Live
2–4 Weeks
Setup Fee
£0
Book a Demo
See Lucy in action at your property. Contact our team to arrange a personalised demo — not a slide deck, not a recorded video. Lucy handles real guest requests, processes real bookings, speaks 30 languages, and adapts her personality in real time.
Book a DemoSee Lucy at Your Property
Tell us about your property and we'll schedule a personalised demo. No setup fees, no per-room charges.