Privacy Policy
Language Note: This document was drafted in Polish. The Polish version is the legally binding version. This English translation is provided for informational purposes only.
Last updated: March 2026 | Version: 1.0
Version: 1.0 Effective date: 10.03.2026 Last updated: March 2026
TABLE OF CONTENTS
- Data Controller
- Definitions
- Scope of Application
- Data Collected on the Website
- Data Collected in the Admin Panel
- Data Collected on Guest Pages
- Data Recipients and Sub-processors
- Data Transfers Outside the EEA
- Data Retention Period
- Rights of Data Subjects
- Cookies
- Automated Processing and Profiling
- Data Security
- Changes to the Privacy Policy
- Contact
1. DATA CONTROLLER
The controller of your personal data is:
Guestivo sp. z o.o. ul. Łęczycka 4/3 53-632 Wrocław NIP: 8952299447 REGON: 543938450 KRS: 0001221700
hereinafter referred to as "Guestivo" or "the Controller".
Contact regarding personal data protection:
- E-mail: support@guestivo.pl
2. DEFINITIONS
For the purposes of this Privacy Policy, the following definitions apply:
- GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data
- Platform – the Guestivo hotel management system available at guestivo.pl (informational website) and app.guestivo.pl (application)
- Admin Panel – the part of the Platform available at app.guestivo.pl/admin, intended for hotel staff
- Guest Pages – the part of the Platform available at app.guestivo.pl/g/{token}, intended for hotel guests
- Hotel – an entity using the Guestivo Platform to manage its hotel property
- Guest – a natural person using the Guest Pages in connection with a stay at the Hotel
- Staff – employees or associates of the Hotel using the Admin Panel
3. SCOPE OF APPLICATION
This Privacy Policy applies to the processing of personal data within:
- The guestivo.pl website – informational and marketing website
- The Admin Panel – a tool for hotel staff
- The Guest Pages – an interface for hotel guests (accessed via email link or QR code)
3.1 Division of Roles Under the GDPR
Guestivo as Data Controller:
- Data of website visitors (contact forms)
- Data of hotel owners and staff (user accounts)
- Data related to subscription management and billing
Guestivo as Data Processor:
- Hotel guest data (orders, chat, check-ins)
- Operational hotel data
In the case of hotel guest data, the Hotel is the Data Controller, and Guestivo processes this data on the basis of a data processing agreement with the Hotel.
4. DATA COLLECTED ON THE WEBSITE
4.1 Contact Form
| Data | Purpose of Processing | Legal Basis | Retention Period |
|---|---|---|---|
| Full name | Responding to inquiry | Art. 6(1)(f) GDPR (legitimate interest) | Until matter is resolved + 1 year |
| E-mail address | Return contact | Art. 6(1)(f) GDPR | Until matter is resolved + 1 year |
| Hotel name (optional) | Inquiry context | Art. 6(1)(f) GDPR | Until matter is resolved + 1 year |
| Message content | Handling the inquiry | Art. 6(1)(f) GDPR | Until matter is resolved + 1 year |
| IP address | Security, CAPTCHA verification | Art. 6(1)(f) GDPR | Duration of session |
4.2 Technical Data
| Data | Purpose of Processing | Legal Basis | Retention Period |
|---|---|---|---|
| Language preferences | Website personalization | Art. 6(1)(a) GDPR (cookie consent) | 1 year (localStorage) |
| Analytics data | Website improvement | Art. 6(1)(a) GDPR (cookie consent) | In accordance with cookie policy |
5. DATA COLLECTED IN THE ADMIN PANEL
5.1 User Account Data
| Data | Purpose of Processing | Legal Basis | Retention Period |
|---|---|---|---|
| Full name | User identification | Art. 6(1)(b) GDPR (performance of contract) | Duration of account |
| E-mail address | Login, communication | Art. 6(1)(b) GDPR | Duration of account |
| Auth0 identifier | Authentication | Art. 6(1)(b) GDPR | Duration of account |
| Role and permissions | Access control | Art. 6(1)(b) GDPR | Duration of account |
| IP address (terms acceptance) | GDPR compliance | Art. 6(1)(c) GDPR (legal obligation) | Indefinitely (audit) |
| Date of terms acceptance | GDPR compliance | Art. 6(1)(c) GDPR | Indefinitely (audit) |
5.2 Subscription Data
| Data | Purpose of Processing | Legal Basis | Retention Period |
|---|---|---|---|
| Billing data | Invoicing | Art. 6(1)(b) GDPR | In accordance with tax regulations (5 years) |
| Payment history | Billing, support | Art. 6(1)(b) GDPR | In accordance with tax regulations |
| Payment gateway data (Stripe) | Processing subscription payments | Art. 6(1)(b) GDPR | Duration of contract |
5.3 Operational Data
| Data | Purpose of Processing | Legal Basis | Retention Period |
|---|---|---|---|
| Activity logs | Security, audit | Art. 6(1)(f) GDPR | Indefinitely (audit) |
| Status change history | Operations tracking | Art. 6(1)(f) GDPR | Indefinitely |
5.4 Authentication via Auth0
Authentication of Admin Panel users is performed through the Auth0 service (Okta, Inc.). Auth0 processes:
- E-mail address
- Password (encrypted, stored exclusively in Auth0)
- Session data and authentication tokens
User passwords are managed by Auth0 and are not stored in Guestivo's production systems. More information: Auth0 Privacy Policy.
6. DATA COLLECTED ON GUEST PAGES
6.1 Information About the Guest Data Controller
The Data Controller of hotel guest personal data is the Hotel whose guests are visiting. Guestivo processes guest data solely as a Data Processor on the basis of a data processing agreement with the Hotel.
For matters regarding the processing of guest personal data, please contact the Hotel directly.
6.2 Data Collected Automatically
| Data | Purpose of Processing | Legal Basis | Retention Period |
|---|---|---|---|
| QR token (room identifier) | Access to services | Art. 6(1)(b) GDPR (performance of contract with the Hotel) | Until checkout date |
| Terms acceptance (date, IP, version) | GDPR compliance | Art. 6(1)(c) GDPR | 30 days (cookie) + database |
6.3 Data Provided Voluntarily
| Data | Purpose of Processing | Legal Basis | Retention Period |
|---|---|---|---|
| Guest full name | Order identification | Art. 6(1)(b) GDPR | In accordance with Hotel policy |
| E-mail address | Communication, confirmations | Art. 6(1)(b) GDPR | In accordance with Hotel policy |
| Phone number | Communication | Art. 6(1)(b) GDPR | In accordance with Hotel policy |
6.4 Service-Related Data
| Data | Purpose of Processing | Legal Basis | Retention Period |
|---|---|---|---|
| Orders (items, prices) | Order fulfillment | Art. 6(1)(b) GDPR | In accordance with Hotel policy |
| Service requests | Request fulfillment | Art. 6(1)(b) GDPR | In accordance with Hotel policy |
| Chat messages | Communication with reception | Art. 6(1)(b) GDPR | Indefinite |
| Transfer reservations | Transfer fulfillment | Art. 6(1)(b) GDPR | In accordance with Hotel policy |
| Late checkout requests | Request fulfillment | Art. 6(1)(b) GDPR | In accordance with Hotel policy |
6.5 Payment Data
| Data | Purpose of Processing | Legal Basis | Retention Period |
|---|---|---|---|
| Payment method (selection) | Payment processing | Art. 6(1)(b) GDPR | Duration of transaction |
| Transaction identifier (Tpay or Stripe) | Payment tracking | Art. 6(1)(b) GDPR | In accordance with regulations |
IMPORTANT: Payment card data (card number, expiration date, CVV code) is not processed or stored in Guestivo systems. Guest payments are handled by an external payment gateway selected by the Hotel (Tpay or Stripe) in accordance with its security policy and PCI DSS requirements.
6.6 Online Check-in Data
| Data | Purpose of Processing | Legal Basis | Retention Period |
|---|---|---|---|
| Full name (all guests) | Hotel registration | Art. 6(1)(c) GDPR (legal obligation) | In accordance with Hotel policy |
| Date of birth | Hotel registration | Art. 6(1)(c) GDPR | In accordance with Hotel policy |
| Nationality | Hotel registration | Art. 6(1)(c) GDPR | In accordance with Hotel policy |
| Document number and type | Hotel registration | Art. 6(1)(c) GDPR | In accordance with Hotel policy |
| Document expiration date | Hotel registration | Art. 6(1)(c) GDPR | In accordance with Hotel policy |
| Residential address | Hotel registration | Art. 6(1)(c) GDPR | In accordance with Hotel policy |
| Identity document photos | Facilitating check-in (optional) | Art. 6(1)(a) GDPR (consent) | Deleted immediately after processing |
6.7 Digital Lock Control Data
| Data | Purpose of Processing | Legal Basis | Retention Period |
|---|---|---|---|
| Guest security PIN | Door access authorization | Art. 6(1)(b) GDPR | BCrypt hash (never plaintext) |
| Failed attempt count | Abuse protection | Art. 6(1)(f) GDPR | Duration of stay |
| Access expiration dates | Access control | Art. 6(1)(b) GDPR | Duration of stay |
7. DATA RECIPIENTS AND SUB-PROCESSORS
7.1 List of Sub-processors
Your personal data may be transferred to the following entities:
| Sub-processor | Purpose | Data Location | Website |
|---|---|---|---|
| Microsoft Azure (Microsoft Corporation) | Cloud infrastructure, data storage, email communication, monitoring | EU (Poland Central, West Europe, North Europe) | azure.microsoft.com |
| Auth0 (Okta, Inc.) | Admin panel user authentication | USA/EU | auth0.com |
| Stripe, Inc. | Subscription payment processing, commission billing, guest payments (Stripe Connect) | USA/EU | stripe.com |
| Tpay (Krajowy Integrator Płatności S.A.) | Online guest payment processing (alternative to Stripe Connect) | Poland | tpay.com |
| Meta Platforms, Inc. (WhatsApp Business) | Guest communication via WhatsApp | USA/EU | business.whatsapp.com |
| Twilio, Inc. | Sending SMS messages to guests | USA/EU | twilio.com |
| Resend, Inc. | Alternative transactional email provider | USA | resend.com |
| OpenRouter, Inc. | AI Concierge, menu digitization | USA | openrouter.ai |
| Seam Labs, Inc. | Digital lock integration | USA | seam.co |
| Apaleo GmbH | PMS integration (reservation sync, folio) | EU (Germany) | apaleo.com |
| Cloudbeds Inc. | PMS integration (reservation sync) | USA | cloudbeds.com |
| Mews Systems B.V. | PMS integration (reservation sync, folio) | EU (Netherlands) | mews.com |
7.2 Categories of Other Recipients
Your data may also be transferred to:
- Public authorities when required by law
- IT service providers (support, maintenance)
- Law firms (when necessary)
- Auditors (to the extent required)
8. DATA TRANSFERS OUTSIDE THE EEA
Some of our sub-processors are based outside the European Economic Area (EEA). When transferring data outside the EEA, we apply the following safeguards:
8.1 Standard Contractual Clauses (SCCs)
Data transfers to the USA are carried out on the basis of Standard Contractual Clauses approved by the European Commission (Decision 2021/914).
8.2 Entities Subject to Transfers
| Entity | Location | Transfer Basis |
|---|---|---|
| Auth0 (Okta) | USA | SCCs + supplementary measures |
| Stripe, Inc. | USA | SCCs + supplementary measures |
| Meta Platforms, Inc. (WhatsApp) | USA | SCCs in accordance with Meta's policy |
| Twilio, Inc. | USA | SCCs + supplementary measures |
| Resend, Inc. | USA | SCCs + supplementary measures |
| OpenRouter, Inc. | USA | SCCs + supplementary measures |
| Seam Labs, Inc. | USA | SCCs + supplementary measures |
| Cloudbeds Inc. | USA | SCCs + supplementary measures |
8.3 Supplementary Measures
- Data encryption in transit (TLS 1.2+)
- Data encryption at rest
- Role-based access control
- Access monitoring
9. DATA RETENTION PERIOD
9.1 Data with Automatic Deletion
| Data Type | Retention Period | Deletion Method |
|---|---|---|
| Identity document photos | Immediately after processing | Automatic deletion |
| Demo data | Short-lived | Automatic deletion |
| Pending payments | Until transaction completion | Status change |
| AI Concierge conversation history | Temporarily, for the duration of the session | Cache removal |
9.2 Data with Manual Deletion
| Data Type | Retention Period | Deletion Method |
|---|---|---|
| User accounts | Until account deletion | Anonymization on request |
| Hotel data | Until hotel deletion | Soft deletion (72h grace period) |
| Chat messages | Indefinite | On request of hotel administrator |
| Guest data | In accordance with Hotel policy | On Hotel request |
9.3 Data Retained Indefinitely
| Data Type | Reason for Retention |
|---|---|
| Audit logs | Security and compliance |
| Terms acceptance history | GDPR compliance |
| Status change history | Operations tracking |
10. RIGHTS OF DATA SUBJECTS
10.1 Your Rights
Under the GDPR, you are entitled to the following rights:
| Right | Description |
|---|---|
| Right of access (Art. 15 GDPR) | The right to obtain confirmation of whether we process your data and to access it |
| Right to rectification (Art. 16 GDPR) | The right to correct inaccurate data |
| Right to erasure (Art. 17 GDPR) | The right to request the deletion of data ("right to be forgotten") |
| Right to restriction (Art. 18 GDPR) | The right to request restriction of processing |
| Right to data portability (Art. 20 GDPR) | The right to receive data in a structured format |
| Right to object (Art. 21 GDPR) | The right to object to processing |
| Right to withdraw consent | The right to withdraw consent at any time |
10.2 How to Exercise Your Rights
To exercise your rights, please contact us:
- E-mail: support@guestivo.pl
We will respond to your request within 30 days of receipt. In justified cases, this period may be extended by an additional 60 days.
10.3 Right to Lodge a Complaint
You have the right to lodge a complaint with the supervisory authority:
President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych) ul. Stawki 2 00-193 Warszawa www.uodo.gov.pl
10.4 Notice for Hotel Guests
As a hotel guest, for matters concerning your personal data, please contact the Hotel where you are staying directly. The Hotel is the Controller of your data and is responsible for fulfilling your rights.
11. COOKIES
11.1 What Are Cookies
Cookies are small text files stored on your device when you use our website.
11.2 Types of Cookies Used
| Category | Consent Required | Examples |
|---|---|---|
| Necessary | No | guestivo-consent, session |
| Functional | Yes | cf_turnstile (CAPTCHA) |
| Preferences | Yes | guestivo-language |
11.3 Managing Cookies
You can manage your cookie settings:
- Through the cookie banner on the website
- Through your browser settings
- Through the "Manage cookies" button in the website footer
11.4 Detailed Cookie Policy
Detailed information about the cookies used can be found in our Cookie Policy.
12. AUTOMATED PROCESSING AND PROFILING
12.1 AI Services
We use the following services that utilize artificial intelligence:
AI Concierge (Chatbot)
| Aspect | Description |
|---|---|
| Purpose | Information assistant for guests |
| Provider | OpenRouter (Google Gemini / Grok) |
| Data processed | Chat messages, hotel context (menu, services) |
| Personal data | We do NOT send names, e-mail addresses, or other personal data to the AI |
| Storage | Temporary server cache (for the duration of the session) |
| Impact on decisions | Informational only, does not make decisions |
Sentiment Analysis
| Aspect | Description |
|---|---|
| Purpose | Detection of negative guest feedback |
| Provider | Azure AI Language |
| Data processed | Chat message content (max 500 characters) |
| Personal data | We do not send guest-identifying data |
| Storage | Results saved with the message |
| Impact on decisions | Alert for staff (requires manual action) |
Identity Document OCR
| Aspect | Description |
|---|---|
| Purpose | Facilitating online check-in |
| Provider | Azure AI Document Intelligence |
| Data processed | Identity document photos |
| Storage | Data is not permanently stored by the OCR service |
| Guest control | The guest always reviews and edits extracted data |
| Optionality | Entirely optional — data can be entered manually |
12.2 No Automated Decision-Making
In accordance with Art. 22 GDPR, we inform you that we do not make decisions based solely on automated processing that produce legal effects or similarly significantly affect the data subjects.
All AI processing results are exclusively informational or supportive in nature and require human verification.
13. DATA SECURITY
13.1 Technical Measures
We apply appropriate technical measures to protect data, including:
- Encryption in transit — connections are encrypted in accordance with industry standards
- Encryption at rest — sensitive data is encrypted
- Secure credential storage — passwords are managed by Auth0, PINs are hashed using secure algorithms
- File access control — time-limited access
- Multi-level access control — role-based permission system
13.2 Organizational Measures
- Multi-tenant isolation — all queries filtered by HotelId
- Data minimization — we collect only necessary data
- Training — staff are trained in data protection
- Breach procedures — we have breach response procedures in place
13.3 Abuse Protection
- Rate limiting — protection against attacks
- CAPTCHA verification — form protection
- Blocking mechanisms — protection against unauthorized access attempts
14. CHANGES TO THE PRIVACY POLICY
14.1 Notification of Changes
We will inform you of significant changes to this Privacy Policy through appropriate means of communication, such as a notice on the website, an e-mail notification, or an in-app message.
14.2 Versioning
Each version of the Privacy Policy is marked with a version number and effective date. Change history can be obtained by contacting us.
15. CONTACT
15.1 Data Controller
Guestivo sp. z o.o. ul. Łęczycka 4/3 53-632 Wrocław
15.2 Data Protection Contact
- E-mail: support@guestivo.pl
15.3 Supervisory Authority
President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych) ul. Stawki 2 00-193 Warszawa Phone: 22 531 03 00 www.uodo.gov.pl
Document version: 1.0 Publication date: 10.03.2026 Last updated: March 2026