We know nothing about your guests.
Where the data lives, who sees it, how long it stays, and which single step leaves the European Union. Set out in full, because it is the question everybody asks us.
What happens between the question and the answer
Four steps, and only one of them leaves the European Union.
The guest writes
They scan the room's QR code and the chat opens in the browser. They do not register, they leave no email, they create no account: there is no name attached to the question.
The question meets your content
Hours, services, house rules and whatever you uploaded sit indexed on servers in the European Union. The semantic search pulls out the pieces needed to answer.
The model composes the answer
The question and those pieces go to the language model, which is OpenAI. It is the only step in which a fragment of your content leaves the European Union, and we use the European residency options where they are available.
The answer comes back to the chat
The guest reads it, and if need be starts a request. The conversation and the request stay inside your property, in the European Union, and your staff sees them.
Where each thing lives
Row by row, without gathering everything under the word “security”.
| Data | Where it sits | Who sees it |
|---|---|---|
| The content you upload, and the index the assistant searches | Germany, on Contabo | Your staff. Extracts go to the model at the moment of answering |
| The files, images and documents you upload | Milan, on Amazon S3 | Your staff, and guests for the ones you publish |
| The conversations with the assistant and the requests | Germany, with the backups in the European Union | Owner and Front desk, according to role |
| The extracts sent to the model to compose an answer | United States, on OpenAI | The model provider, which does not use them to train it |
| Your property's billing data | European Union and United States, on Stripe | Our accounts department. Card details never pass through us |
| Your guest's personal data | Does not exist | Nobody |
The shortest row in the table.
It is the only entry with neither a place nor a person against it, and it is the one that keeps the rest of this page short.
To open the chat the guest scans the room's QR code. We do not ask for a name, we do not ask for an email, they do not have to create an account and they do not have to install anything. A list of your guests does not exist on our side.
What remains is the conversation: the question they asked, the answer they got, the room they were writing from and the language they spoke. Your staff needs it to deal with the request and you need it to understand what people ask you, and it sits inside your property the way a sheet of paper behind the desk would.
If a guest then writes their own name inside a message, that message is a piece of your property's content like any other, under the same rules as this page. But it is not something we asked them for.
What we put in writing for you
These are not good intentions: they are in the data processing agreement, which is public and which you can read right now.
In concrete terms
- Your content does not train the model. That holds for us and for the provider, under the contractual options that rule out training on the data sent.
- One single transfer outside the Union, the one towards the model. Everything else, backups included, stays in Europe.
- One property's data never leaves that property: the isolation holds for the assistant's search too, and there are automated tests checking it at every release.
- Encryption in transit, and at rest for the data that calls for it. Staff credentials are stored in a form that cannot be reversed.
- If there is a breach we tell you within 48 hours, with what we know and what we are doing about it.
- Inside the property you decide who sees what. Owner and Front desk have different permissions, and each person can be assigned to a team.
Thirty days, twelve months or twenty-four
It depends on the plan, and it is the same figure you find on the price list.
- 30 daysPlan Essential
- 12 monthsPlan Plus
- 24 monthsPlan Premium
Those are the ceilings, and you can lower them from the settings. Above them, though, another rule holds, the same on every plan: when a stay closes, whatever concerns the guest is anonymised or deleted, and the deletion reaches the translations and the assistant's index too. What remains are the statistics, which are numbers and not people.
If one day you stop, you have thirty days to export everything from the panel. Then we delete: see the three plans
This website and the application are two different things
So far we have been talking about the application, the one with the documents and the providers just listed. The site you are reading is another matter, with a privacy policy of its own.
Up here there are Google's statistics, and if you fill in the contact form your request passes through an email service and your address can reach, in hashed form, the advertising tools we use. Some of those providers sit outside the European Union, and the tags concerning them fire only if you gave consent from the banner.
None of this touches your guests: they are two separate systems, and somebody scanning a QR code in a room does not pass through here. The full list of the site's providers, with each one's country, is in the privacy policy.
The questions that come from the office keeping the records.
Does my property's content train the artificial intelligence?
No. The model receives the guest's question and the extracts of your content needed to answer it, and uses them to compose that one answer. The business APIs we work with rule out using that data for training, and that is what the contract provides for, not a box somebody here has to remember to tick.
I need the DPA for my record of processing activities. Where do I find it?
It is public, with the list of sub-processors and security measures at the end: you can read it and download it at app.consergio.ai/legal/dpa, and it is the same document you accept when you register the property. If you need a signed copy write to info@consergio.ai.
Who is the data controller for my guests' data?
Your property. The content you upload and the conversations your guests have with the assistant stay yours, and we process them to make the service work for you: in GDPR terms you are the controller and we are the processor. The data processing agreement is what puts that in writing.
You can read the agreement right now.
The DPA is public and carries the list of sub-processors and security measures at the end. If your office has a question it does not answer, put it to us.
Do you need a signed copy? Write to info@consergio.ai