Privacy Policy
Last updated · August 15, 2026
This policy describes how InnAgent Inc. ("InnAgent", "we") handles personal data in operating its guest communication and management platform for hotels.
It covers two distinct groups of people with different legal roles, and that distinction runs through the whole document: the clients who license the platform, and the guests served through it.
1. Our two roles
We are the CONTROLLER of our clients' data — the hotel staff who license, access and administer the platform. We decide why and how that data is processed.
We are the PROCESSOR of guest data. When a guest messages a hotel on WhatsApp or makes a booking, it is the hotel, as controller, that determines the purpose of that processing. We act on its behalf and within the limits of our agreement with it.
In practice: guest requests about their own data go to the hotel, and we handle whatever the hotel forwards to us about them. If a guest contacts us directly, we route the request to the responsible hotel and tell the guest we have done so.
2. Data we process
From clients (as controller):
- Identification and business contact details: name, work email, phone, role and associated hotel.
- Access data: credentials, login records, IP address and actions taken in the platform.
- Contractual and billing data.
From guests (as processor, on the hotel's behalf):
- Identification and contact details: name, phone and email, held in the conversation engine.
- The content of conversations exchanged with the hotel across integrated channels, including WhatsApp.
- The booking reference in the hotel's management system, where there is one.
- Where the corresponding modules are licensed and switched on: further booking data (dates, accommodation, amounts and preferences), the identity document required by lodging rules, and technical data about how the contact originated, used to measure the effectiveness of the hotel's campaigns.
From anyone writing through the form on this site (as controller): name, email, hotel where given, and the content of the message.
This data is used only to answer the enquiry and carry the commercial conversation it starts. The legal basis is our legitimate interest in responding to people who contact us and, once the conversation advances, steps taken prior to entering into a contract. It does not feed marketing campaigns and is neither sold nor shared.
The message reaches our inbox by email and is retained for as long as the conversation and the corresponding commercial record last. The site does not store submissions in a database of its own. To have it deleted sooner, just ask by email.
3. What we use it for
We do not sell personal data. We do not use one client's conversations or guest data to benefit another client, nor to train general-purpose artificial intelligence models.
- Running automated and human service across the hotel's channels.
- Recording, retrieving and reconciling bookings with the client's property management system (PMS).
- Producing the reports and indicators the hotel uses to run its own operation.
- Measuring the performance of the hotel's campaigns, where that module is licensed and switched on.
- Keeping the platform secure, investigating incidents and meeting legal obligations.
4. Legal bases
We process client data on the basis of performance of the contract, compliance with legal obligations, and our legitimate interest in maintaining and protecting the platform.
For guest data, the legal basis is determined by the controlling hotel — as a rule, performance of the accommodation contract, compliance with a legal obligation, or consent, as the case may be.
5. Artificial intelligence in guest service
Where automated guest service is licensed and switched on, part of the service is carried out by an automated agent that interprets the guest's messages and queries the hotel's systems to answer. Conversations are processed by language model providers we contract, under agreements that prohibit the use of that content to train their models.
The agent hands the conversation to a member of the hotel's team when the case calls for it, and the guest may ask for a human at any time.
6. Sharing
We share data only with those needed for the platform to work:
We keep this list up to date, and we give clients reasonable notice before a new provider that processes personal data comes in.
- The contracting hotel, which is the natural recipient of its own guests' data.
- Supabase — database and authentication, including the account access emails, with data stored in the European Union (Sweden).
- Vercel — application hosting and execution, in the European Union (Sweden).
- Sentry — error and performance monitoring, with data stored in Germany. It receives error messages and performance measurements; it does not receive conversation content.
- Stripe — payment processing. It receives billing and card details directly from whoever subscribes, on a page it hosts; it does not receive guest data.
- Resend — delivery of our transactional email: account access emails, team invitations, platform notifications and the messages from this site's form.
- Google and Facebook — only where a person chooses to sign in with an account from one of those providers, and only to authenticate them.
- Language model providers, where automated guest service is licensed and switched on.
- Meta Platforms, where communication takes place over one of its channels — WhatsApp Business Platform, Instagram Direct or Messenger — under its policies.
- Telegram Messenger — when the hotel connects a Telegram bot as a service channel.
- The property management system (PMS) chosen by the hotel, to record and retrieve bookings.
- Public authorities, where required by law or court order.
7. Where the data sits, and when it leaves the country
Data processed on the platform is stored in the European Union: the database and the application in Sweden, the conversation engine — which we run on our own infrastructure — in Finland, and error monitoring in Germany.
InnAgent Inc. is a company incorporated in the United States, and our team accesses those systems from outside the European Union and Brazil. That access is an international transfer and relies on the safeguards required by applicable law.
For clients in Brazil, this means data is processed outside the national territory, with the same safeguards. Some supporting providers — payment, email delivery, sign-in with a Google or Facebook account, and the WhatsApp Business Platform itself — operate globally and may process data outside the European Union, under the terms we hold with them.
8. Isolation between hotels
The platform is multi-tenant: several hotels operate on shared infrastructure. Isolation between them is enforced at the database layer, so that a query made in one hotel's context cannot reach another hotel's records. This is an architectural requirement, not an optional setting.
9. Retention
Client data is kept for the duration of the contractual relationship and for the statutory periods that follow.
Guest data is kept for the period set by the controlling hotel, subject to the retention periods that apply to lodging activity. On termination, we return or delete data as the hotel instructs, except where the law requires us to keep it.
10. Data subject rights
Applicable law grants data subjects rights including confirmation and access, correction, anonymisation, portability, information about sharing, withdrawal of consent, and deletion.
Clients exercise these rights with us directly, at admin@innagent.ai. Guests should contact the hotel they deal with; if they contact us, we route the request to the responsible hotel.
You also have the right to lodge a complaint with a data protection authority. In Brazil, with the Autoridade Nacional de Proteção de Dados (ANPD). In the European Economic Area, with the supervisory authority of the country where you live, where you work, or where the alleged breach took place — in France, the CNIL. Without limiting that right, we ask that you talk to us first: it is usually faster.
Our communication channel for data subjects is admin@innagent.ai.
11. How to request deletion of your data
If you are a guest of a hotel that uses InnAgent: the hotel is responsible for your data, so ask it for deletion directly. If you would rather write to us, at admin@innagent.ai, we forward your request to the responsible hotel, tell you we have done so, and delete the data in our systems as soon as the hotel confirms.
If you have an account on the platform: write to admin@innagent.ai from the account's email address. We confirm receipt and complete the deletion, except for what the law requires us to keep — in which case we tell you what and for how long.
If you talked to a hotel over WhatsApp: those messages are the hotel's responsibility, and the request follows the first route above.
These requests are handled by our team on request by email. There is no self-service deletion tool in the platform today.
12. Security
We apply technical and organisational controls appropriate to the nature of the data, including encryption in transit, identity-based access control, environment segregation, audit logging of platform actions, and centralised secret management.
In the event of a security incident that may pose material risk or harm, we act according to the role we hold over the data affected. For our clients' data, of which we are the controller, we notify those affected and the competent authority within the statutory deadlines. For guest data, of which we are the processor, we notify the controlling hotel without undue delay, with the information it needs to meet its own deadlines; notifying the authority and the data subjects is the hotel's responsibility in that case, and we support it with whatever is within our reach.
13. Cookies
This website uses no tracking cookies and no behavioural analytics. The platform dashboard uses only the cookies strictly necessary for session authentication.
14. Changes
Material changes to this policy are communicated to clients by email and reflected on this page, with the date at the top updated.
15. Contact
For any privacy or data protection matter, including exercising your rights: admin@innagent.ai.