Inn AgentInn Agent

Privacy Policy

Last updated · July 25, 2026

This policy describes how Inn Agent LLC ("Inn Agent", "we") handles personal data in operating its guest communication and management platform for hotels.

It covers two distinct groups of people with different legal roles, and that distinction runs through the whole document: the clients who license the platform, and the guests served through it.

1. Our two roles

We are the CONTROLLER of our clients' data — the hotel staff who license, access and administer the platform. We decide why and how that data is processed.

We are the PROCESSOR of guest data. When a guest messages a hotel on WhatsApp or makes a booking, it is the hotel, as controller, that determines the purpose of that processing. We act on its behalf and within the limits of our agreement with it.

In practice: guest requests about their own data go to the hotel, and we give the hotel the technical means to answer them. If a guest contacts us directly, we route the request to the responsible hotel and tell the guest we have done so.

2. Data we process

From clients (as controller):

  • Identification and business contact details: name, work email, phone, role and associated hotel.
  • Access data: credentials, login records, IP address and actions taken in the platform.
  • Contractual and billing data.

From guests (as processor, on the hotel's behalf):

  • Identification and contact details: name, phone, email and, where lodging rules require it, identity document.
  • The content of conversations exchanged with the hotel across integrated channels, including WhatsApp.
  • Booking data: dates, accommodation, amounts, preferences and stay history.
  • Technical data about how the contact originated, used to measure the effectiveness of the hotel's campaigns.

3. What we use it for

We do not sell personal data. We do not use one client's conversations or guest data to benefit another client, nor to train general-purpose artificial intelligence models.

  • Running automated and human service across the hotel's channels.
  • Recording, retrieving and reconciling bookings with the client's property management system (PMS).
  • Producing the reports and indicators the hotel uses to run its own operation.
  • Measuring the performance of the hotel's campaigns, where that module is licensed and switched on.
  • Keeping the platform secure, investigating incidents and meeting legal obligations.

4. Legal bases

We process client data on the basis of performance of the contract, compliance with legal obligations, and our legitimate interest in maintaining and protecting the platform.

For guest data, the legal basis is determined by the controlling hotel — as a rule, performance of the accommodation contract, compliance with a legal obligation, or consent, as the case may be.

5. Artificial intelligence in guest service

Part of the service is carried out by an automated agent that interprets the guest's messages and queries the hotel's systems to answer. Conversations are processed by language model providers we contract, under agreements that prohibit the use of that content to train their models.

The agent hands the conversation to a member of the hotel's team when the case calls for it, and the guest may ask for a human at any time.

6. Sharing

We share data only with those needed for the platform to work:

  • The contracting hotel, which is the natural recipient of its own guests' data.
  • Infrastructure, database and cloud hosting providers.
  • Language model providers, for automated service.
  • Meta Platforms, where communication takes place over the WhatsApp Business Platform, under its policies.
  • The property management system (PMS) chosen by the hotel, to record and retrieve bookings.
  • Public authorities, where required by law or court order.

7. International transfers

Part of our infrastructure and some providers sit outside Brazil, including in the European Union and the United States. Those transfers are made with the safeguards required by applicable law, including standard contractual clauses with the providers.

8. Isolation between hotels

The platform is multi-tenant: several hotels operate on shared infrastructure. Isolation between them is enforced at the database layer, so that a query made in one hotel's context cannot reach another hotel's records. This is an architectural requirement, not an optional setting.

9. Retention

Client data is kept for the duration of the contractual relationship and for the statutory periods that follow.

Guest data is kept for the period set by the controlling hotel, subject to the retention periods that apply to lodging activity. On termination, we return or delete data as the hotel instructs, except where the law requires us to keep it.

10. Data subject rights

Applicable law grants data subjects rights including confirmation and access, correction, anonymisation, portability, information about sharing, withdrawal of consent, and deletion.

Clients exercise these rights with us directly, at admin@innagent.ai. Guests should contact the hotel they deal with; if they contact us, we route the request to the responsible hotel.

11. Security

We apply technical and organisational controls appropriate to the nature of the data, including encryption in transit, identity-based access control, environment segregation, audit logging of platform actions, and centralised secret management.

In the event of a security incident posing material risk to data subjects, we notify affected clients and the competent authority within the statutory deadlines.

12. Cookies

This website uses no tracking cookies and no behavioural analytics. The platform dashboard uses only the cookies strictly necessary for session authentication.

13. Changes

Material changes to this policy are communicated to clients by email and reflected on this page, with the date at the top updated.

14. Contact

For any privacy or data protection matter, including exercising your rights: admin@innagent.ai.