Privacy Policy
This policy describes how GuestAI, Inc. (“MyGuest”, “we”) processes personal data in connection with the MyGuest service — AI voice and text agents for hospitality (switchboard, guest-stay agents, chat) — and our website.
1. Who we are; roles
Controller vs. processor . For guest data processed through the service (calls, messages, recordings, transcripts), the hotel or property operator using MyGuest (our “Customer”) is the data controller, and GuestAI, Inc. acts as a data processor on the Customer’ s documented instructions, under a data processing agreement (Art. 28 GDPR). For data of our Customers’ representatives and users of our website and billing (account data, contact details, payment records), GuestAI, Inc. is the controller. Contact: GuestAI, Inc., 1111B S Governors Ave, #58573, Dover, DE 19904, USA · privacy@myguest.ai. EU/EEA representative (Art. 27 GDPR):
[to be confirmed by counsel prior to publication].
2. Data we process
Guest interaction data (as processor): caller phone number, call audio recordings, transcripts and summaries, SMS/chat content, interaction metadata (time, duration, routing path), and any personal data the guest volunteers during a conversation (e.g., name, reservation details).
Customer account data (as controller): names and business contact details of Customer’ s sta, configuration and knowledge-base content, usage and billing records, payment card token processed by our payment provider (we do not store full card numbers).
Special categories: we do not intentionally collect them. Guests are not asked to provide such data; incidental disclosures in free-form speech are processed only as part of the recording/transcript.
3. Purposes and legal bases
Providing the service (answering, routing, summarizing, callback lists): performance of the contract with the Customer; as processor — the Customer’ s instructions. The Customer is responsible for its own legal basis toward guests (Art. 6 GDPR) and for informing guests (Art. 13/14 GDPR).
Quality, safety and abuse prevention (reviewing failed interactions, correcting agent errors): legitimate interest or Customer instruction.
Service improvement: guest conversation content is not used to train foundation models.
Billing and administration (as controller): contract performance and legal obligations (tax, accounting).
4. AI transparency
MyGuest agents identify themselves as AI assistants at the start of an interaction, consistent with EU transparency requirements for AI systems interacting with natural persons (Regulation (EU) 2024/1689 — the AI Act). A caller may request transfer to a human at any time; the agent will route the request per the Customer’ s configuration.
5. Subprocessors and recipients
We use veed subprocessors to operate the service:
Telephony and SMS: Twilio
Speech and conversational voice: ElevenLabs
Large language models: Anthropic; OpenAI
Cloud infrastructure and productivity: Google (Cloud / Workspace)
Payments and billing (controller scope): Stripe
Each subprocessor is bound by a data processing agreement; we remain responsible for their performance. The current list is maintained on this page and updated as providers change.
6. International transfers
GuestAI, Inc. is a U.S. company and some subprocessors process data in the United States. T ransfers of EU/EEA personal data are safeguarded by the EU Standard Contractual Clauses and/or the EU U.S. Data Privacy Framework, depending on the provider’ s certification status, together with supplementary measures where required. Copies of relevant safeguards are available on request at privacy@myguest.ai.
7. Retention
Call recordings: 12 months, or as instructed by the Customer, whichever is shorter.
Transcripts and summaries: 24 months, or per Customer instruction.
Account and billing data: for the contract term and statutory retention periods.
8. Data subject rights
Guests may exercise GDPR rights (access, rectification, erasure, restriction, objection, portability) against the Customer as controller; we assist the Customer under the DP A and redirect requests received directly . Customer representatives may contact us at privacy@myguest.ai. Data subjects in the EU/EEA may lodge a complaint with their supervisory authority; in Poland — the President of the Personal Data Protection Oice (UODO).
9. Security
We apply technical and organizational measures appropriate to the risk: encryption in transit, access controls and least privilege, environment separation, logging, subprocessor due diligence, and personnel confidentiality undertakings. Details are set out in the data processing agreement concluded with each Customer.
10. Changes
We may update this policy; material changes will be notified to Customers. The current version is always available at myguest.ai/privacy-policy.