Back to homepage

Privacy Policy

Language:

Language Note: This document was drafted in Polish. The Polish version is the legally binding version. This English translation is provided for informational purposes only.

Last updated: March 2026 | Version: 1.0

Version: 1.0 Effective date: 10.03.2026 Last updated: March 2026


TABLE OF CONTENTS

  1. Data Controller
  2. Definitions
  3. Scope of Application
  4. Data Collected on the Website
  5. Data Collected in the Admin Panel
  6. Data Collected on Guest Pages
  7. Data Recipients and Sub-processors
  8. Data Transfers Outside the EEA
  9. Data Retention Period
  10. Rights of Data Subjects
  11. Cookies
  12. Automated Processing and Profiling
  13. Data Security
  14. Changes to the Privacy Policy
  15. Contact

1. DATA CONTROLLER

The controller of your personal data is:

Guestivo sp. z o.o. ul. Łęczycka 4/3 53-632 Wrocław NIP: 8952299447 REGON: 543938450 KRS: 0001221700

hereinafter referred to as "Guestivo" or "the Controller".

Contact regarding personal data protection:


2. DEFINITIONS

For the purposes of this Privacy Policy, the following definitions apply:

  • GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data
  • Platform – the Guestivo hotel management system available at guestivo.pl (informational website) and app.guestivo.pl (application)
  • Admin Panel – the part of the Platform available at app.guestivo.pl/admin, intended for hotel staff
  • Guest Pages – the part of the Platform available at app.guestivo.pl/g/{token}, intended for hotel guests
  • Hotel – an entity using the Guestivo Platform to manage its hotel property
  • Guest – a natural person using the Guest Pages in connection with a stay at the Hotel
  • Staff – employees or associates of the Hotel using the Admin Panel

3. SCOPE OF APPLICATION

This Privacy Policy applies to the processing of personal data within:

  1. The guestivo.pl website – informational and marketing website
  2. The Admin Panel – a tool for hotel staff
  3. The Guest Pages – an interface for hotel guests (accessed via email link or QR code)

3.1 Division of Roles Under the GDPR

Guestivo as Data Controller:

  • Data of website visitors (contact forms)
  • Data of hotel owners and staff (user accounts)
  • Data related to subscription management and billing

Guestivo as Data Processor:

  • Hotel guest data (orders, chat, check-ins)
  • Operational hotel data

In the case of hotel guest data, the Hotel is the Data Controller, and Guestivo processes this data on the basis of a data processing agreement with the Hotel.


4. DATA COLLECTED ON THE WEBSITE

4.1 Contact Form

DataPurpose of ProcessingLegal BasisRetention Period
Full nameResponding to inquiryArt. 6(1)(f) GDPR (legitimate interest)Until matter is resolved + 1 year
E-mail addressReturn contactArt. 6(1)(f) GDPRUntil matter is resolved + 1 year
Hotel name (optional)Inquiry contextArt. 6(1)(f) GDPRUntil matter is resolved + 1 year
Message contentHandling the inquiryArt. 6(1)(f) GDPRUntil matter is resolved + 1 year
IP addressSecurity, CAPTCHA verificationArt. 6(1)(f) GDPRDuration of session

4.2 Technical Data

DataPurpose of ProcessingLegal BasisRetention Period
Language preferencesWebsite personalizationArt. 6(1)(a) GDPR (cookie consent)1 year (localStorage)
Analytics dataWebsite improvementArt. 6(1)(a) GDPR (cookie consent)In accordance with cookie policy

5. DATA COLLECTED IN THE ADMIN PANEL

5.1 User Account Data

DataPurpose of ProcessingLegal BasisRetention Period
Full nameUser identificationArt. 6(1)(b) GDPR (performance of contract)Duration of account
E-mail addressLogin, communicationArt. 6(1)(b) GDPRDuration of account
Auth0 identifierAuthenticationArt. 6(1)(b) GDPRDuration of account
Role and permissionsAccess controlArt. 6(1)(b) GDPRDuration of account
IP address (terms acceptance)GDPR complianceArt. 6(1)(c) GDPR (legal obligation)Indefinitely (audit)
Date of terms acceptanceGDPR complianceArt. 6(1)(c) GDPRIndefinitely (audit)

5.2 Subscription Data

DataPurpose of ProcessingLegal BasisRetention Period
Billing dataInvoicingArt. 6(1)(b) GDPRIn accordance with tax regulations (5 years)
Payment historyBilling, supportArt. 6(1)(b) GDPRIn accordance with tax regulations
Payment gateway data (Stripe)Processing subscription paymentsArt. 6(1)(b) GDPRDuration of contract

5.3 Operational Data

DataPurpose of ProcessingLegal BasisRetention Period
Activity logsSecurity, auditArt. 6(1)(f) GDPRIndefinitely (audit)
Status change historyOperations trackingArt. 6(1)(f) GDPRIndefinitely

5.4 Authentication via Auth0

Authentication of Admin Panel users is performed through the Auth0 service (Okta, Inc.). Auth0 processes:

  • E-mail address
  • Password (encrypted, stored exclusively in Auth0)
  • Session data and authentication tokens

User passwords are managed by Auth0 and are not stored in Guestivo's production systems. More information: Auth0 Privacy Policy.


6. DATA COLLECTED ON GUEST PAGES

6.1 Information About the Guest Data Controller

The Data Controller of hotel guest personal data is the Hotel whose guests are visiting. Guestivo processes guest data solely as a Data Processor on the basis of a data processing agreement with the Hotel.

For matters regarding the processing of guest personal data, please contact the Hotel directly.

6.2 Data Collected Automatically

DataPurpose of ProcessingLegal BasisRetention Period
QR token (room identifier)Access to servicesArt. 6(1)(b) GDPR (performance of contract with the Hotel)Until checkout date
Terms acceptance (date, IP, version)GDPR complianceArt. 6(1)(c) GDPR30 days (cookie) + database

6.3 Data Provided Voluntarily

DataPurpose of ProcessingLegal BasisRetention Period
Guest full nameOrder identificationArt. 6(1)(b) GDPRIn accordance with Hotel policy
E-mail addressCommunication, confirmationsArt. 6(1)(b) GDPRIn accordance with Hotel policy
Phone numberCommunicationArt. 6(1)(b) GDPRIn accordance with Hotel policy
DataPurpose of ProcessingLegal BasisRetention Period
Orders (items, prices)Order fulfillmentArt. 6(1)(b) GDPRIn accordance with Hotel policy
Service requestsRequest fulfillmentArt. 6(1)(b) GDPRIn accordance with Hotel policy
Chat messagesCommunication with receptionArt. 6(1)(b) GDPRIndefinite
Transfer reservationsTransfer fulfillmentArt. 6(1)(b) GDPRIn accordance with Hotel policy
Late checkout requestsRequest fulfillmentArt. 6(1)(b) GDPRIn accordance with Hotel policy

6.5 Payment Data

DataPurpose of ProcessingLegal BasisRetention Period
Payment method (selection)Payment processingArt. 6(1)(b) GDPRDuration of transaction
Transaction identifier (Tpay or Stripe)Payment trackingArt. 6(1)(b) GDPRIn accordance with regulations

IMPORTANT: Payment card data (card number, expiration date, CVV code) is not processed or stored in Guestivo systems. Guest payments are handled by an external payment gateway selected by the Hotel (Tpay or Stripe) in accordance with its security policy and PCI DSS requirements.

6.6 Online Check-in Data

DataPurpose of ProcessingLegal BasisRetention Period
Full name (all guests)Hotel registrationArt. 6(1)(c) GDPR (legal obligation)In accordance with Hotel policy
Date of birthHotel registrationArt. 6(1)(c) GDPRIn accordance with Hotel policy
NationalityHotel registrationArt. 6(1)(c) GDPRIn accordance with Hotel policy
Document number and typeHotel registrationArt. 6(1)(c) GDPRIn accordance with Hotel policy
Document expiration dateHotel registrationArt. 6(1)(c) GDPRIn accordance with Hotel policy
Residential addressHotel registrationArt. 6(1)(c) GDPRIn accordance with Hotel policy
Identity document photosFacilitating check-in (optional)Art. 6(1)(a) GDPR (consent)Deleted immediately after processing

6.7 Digital Lock Control Data

DataPurpose of ProcessingLegal BasisRetention Period
Guest security PINDoor access authorizationArt. 6(1)(b) GDPRBCrypt hash (never plaintext)
Failed attempt countAbuse protectionArt. 6(1)(f) GDPRDuration of stay
Access expiration datesAccess controlArt. 6(1)(b) GDPRDuration of stay

7. DATA RECIPIENTS AND SUB-PROCESSORS

7.1 List of Sub-processors

Your personal data may be transferred to the following entities:

Sub-processorPurposeData LocationWebsite
Microsoft Azure (Microsoft Corporation)Cloud infrastructure, data storage, email communication, monitoringEU (Poland Central, West Europe, North Europe)azure.microsoft.com
Auth0 (Okta, Inc.)Admin panel user authenticationUSA/EUauth0.com
Stripe, Inc.Subscription payment processing, commission billing, guest payments (Stripe Connect)USA/EUstripe.com
Tpay (Krajowy Integrator Płatności S.A.)Online guest payment processing (alternative to Stripe Connect)Polandtpay.com
Meta Platforms, Inc. (WhatsApp Business)Guest communication via WhatsAppUSA/EUbusiness.whatsapp.com
Twilio, Inc.Sending SMS messages to guestsUSA/EUtwilio.com
Resend, Inc.Alternative transactional email providerUSAresend.com
OpenRouter, Inc.AI Concierge, menu digitizationUSAopenrouter.ai
Seam Labs, Inc.Digital lock integrationUSAseam.co
Apaleo GmbHPMS integration (reservation sync, folio)EU (Germany)apaleo.com
Cloudbeds Inc.PMS integration (reservation sync)USAcloudbeds.com
Mews Systems B.V.PMS integration (reservation sync, folio)EU (Netherlands)mews.com

7.2 Categories of Other Recipients

Your data may also be transferred to:

  • Public authorities when required by law
  • IT service providers (support, maintenance)
  • Law firms (when necessary)
  • Auditors (to the extent required)

8. DATA TRANSFERS OUTSIDE THE EEA

Some of our sub-processors are based outside the European Economic Area (EEA). When transferring data outside the EEA, we apply the following safeguards:

8.1 Standard Contractual Clauses (SCCs)

Data transfers to the USA are carried out on the basis of Standard Contractual Clauses approved by the European Commission (Decision 2021/914).

8.2 Entities Subject to Transfers

EntityLocationTransfer Basis
Auth0 (Okta)USASCCs + supplementary measures
Stripe, Inc.USASCCs + supplementary measures
Meta Platforms, Inc. (WhatsApp)USASCCs in accordance with Meta's policy
Twilio, Inc.USASCCs + supplementary measures
Resend, Inc.USASCCs + supplementary measures
OpenRouter, Inc.USASCCs + supplementary measures
Seam Labs, Inc.USASCCs + supplementary measures
Cloudbeds Inc.USASCCs + supplementary measures

8.3 Supplementary Measures

  • Data encryption in transit (TLS 1.2+)
  • Data encryption at rest
  • Role-based access control
  • Access monitoring

9. DATA RETENTION PERIOD

9.1 Data with Automatic Deletion

Data TypeRetention PeriodDeletion Method
Identity document photosImmediately after processingAutomatic deletion
Demo dataShort-livedAutomatic deletion
Pending paymentsUntil transaction completionStatus change
AI Concierge conversation historyTemporarily, for the duration of the sessionCache removal

9.2 Data with Manual Deletion

Data TypeRetention PeriodDeletion Method
User accountsUntil account deletionAnonymization on request
Hotel dataUntil hotel deletionSoft deletion (72h grace period)
Chat messagesIndefiniteOn request of hotel administrator
Guest dataIn accordance with Hotel policyOn Hotel request

9.3 Data Retained Indefinitely

Data TypeReason for Retention
Audit logsSecurity and compliance
Terms acceptance historyGDPR compliance
Status change historyOperations tracking

10. RIGHTS OF DATA SUBJECTS

10.1 Your Rights

Under the GDPR, you are entitled to the following rights:

RightDescription
Right of access (Art. 15 GDPR)The right to obtain confirmation of whether we process your data and to access it
Right to rectification (Art. 16 GDPR)The right to correct inaccurate data
Right to erasure (Art. 17 GDPR)The right to request the deletion of data ("right to be forgotten")
Right to restriction (Art. 18 GDPR)The right to request restriction of processing
Right to data portability (Art. 20 GDPR)The right to receive data in a structured format
Right to object (Art. 21 GDPR)The right to object to processing
Right to withdraw consentThe right to withdraw consent at any time

10.2 How to Exercise Your Rights

To exercise your rights, please contact us:

We will respond to your request within 30 days of receipt. In justified cases, this period may be extended by an additional 60 days.

10.3 Right to Lodge a Complaint

You have the right to lodge a complaint with the supervisory authority:

President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych) ul. Stawki 2 00-193 Warszawa www.uodo.gov.pl

10.4 Notice for Hotel Guests

As a hotel guest, for matters concerning your personal data, please contact the Hotel where you are staying directly. The Hotel is the Controller of your data and is responsible for fulfilling your rights.


11. COOKIES

11.1 What Are Cookies

Cookies are small text files stored on your device when you use our website.

11.2 Types of Cookies Used

CategoryConsent RequiredExamples
NecessaryNoguestivo-consent, session
FunctionalYescf_turnstile (CAPTCHA)
PreferencesYesguestivo-language

11.3 Managing Cookies

You can manage your cookie settings:

  • Through the cookie banner on the website
  • Through your browser settings
  • Through the "Manage cookies" button in the website footer

Detailed information about the cookies used can be found in our Cookie Policy.


12. AUTOMATED PROCESSING AND PROFILING

12.1 AI Services

We use the following services that utilize artificial intelligence:

AI Concierge (Chatbot)

AspectDescription
PurposeInformation assistant for guests
ProviderOpenRouter (Google Gemini / Grok)
Data processedChat messages, hotel context (menu, services)
Personal dataWe do NOT send names, e-mail addresses, or other personal data to the AI
StorageTemporary server cache (for the duration of the session)
Impact on decisionsInformational only, does not make decisions

Sentiment Analysis

AspectDescription
PurposeDetection of negative guest feedback
ProviderAzure AI Language
Data processedChat message content (max 500 characters)
Personal dataWe do not send guest-identifying data
StorageResults saved with the message
Impact on decisionsAlert for staff (requires manual action)

Identity Document OCR

AspectDescription
PurposeFacilitating online check-in
ProviderAzure AI Document Intelligence
Data processedIdentity document photos
StorageData is not permanently stored by the OCR service
Guest controlThe guest always reviews and edits extracted data
OptionalityEntirely optional — data can be entered manually

12.2 No Automated Decision-Making

In accordance with Art. 22 GDPR, we inform you that we do not make decisions based solely on automated processing that produce legal effects or similarly significantly affect the data subjects.

All AI processing results are exclusively informational or supportive in nature and require human verification.


13. DATA SECURITY

13.1 Technical Measures

We apply appropriate technical measures to protect data, including:

  • Encryption in transit — connections are encrypted in accordance with industry standards
  • Encryption at rest — sensitive data is encrypted
  • Secure credential storage — passwords are managed by Auth0, PINs are hashed using secure algorithms
  • File access control — time-limited access
  • Multi-level access control — role-based permission system

13.2 Organizational Measures

  • Multi-tenant isolation — all queries filtered by HotelId
  • Data minimization — we collect only necessary data
  • Training — staff are trained in data protection
  • Breach procedures — we have breach response procedures in place

13.3 Abuse Protection

  • Rate limiting — protection against attacks
  • CAPTCHA verification — form protection
  • Blocking mechanisms — protection against unauthorized access attempts

14. CHANGES TO THE PRIVACY POLICY

14.1 Notification of Changes

We will inform you of significant changes to this Privacy Policy through appropriate means of communication, such as a notice on the website, an e-mail notification, or an in-app message.

14.2 Versioning

Each version of the Privacy Policy is marked with a version number and effective date. Change history can be obtained by contacting us.


15. CONTACT

15.1 Data Controller

Guestivo sp. z o.o. ul. Łęczycka 4/3 53-632 Wrocław

15.2 Data Protection Contact

15.3 Supervisory Authority

President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych) ul. Stawki 2 00-193 Warszawa Phone: 22 531 03 00 www.uodo.gov.pl


Document version: 1.0 Publication date: 10.03.2026 Last updated: March 2026