This Privacy Policy describes how we collect, use, store and protect your personal data when you use the SmartestGuide application, in accordance with GDPR (EU) 2016/679.
II. What personal data we collect
From guests (end users)
First name (optional β only if the guest chooses to enter it) β personalisation of communication
Stay dates β providing relevant information
Avatar conversation content β AI improvement, typically anonymised
Device information, IP address β technical optimisation and security
From hotels (clients)
Identification and contact details, payment data, administration access credentials
III. Legal basis for processing
Consent β for most guest data (first name, email, marketing)
Contract performance β for app functionality and hotel contract
Your data is shared only with the relevant hotel, the contracted processors listed below and public authorities when required by law.
Processors (sub-processors)
Anthropic, PBC (USA) β the Claude AI model generates assistant responses; it processes conversation text (the guest's question and related context, e.g. hotel information). Data is not used to train AI models.
OpenAI, L.L.C. (USA) β voice output of the assistant (text-to-speech); it processes only the text of the response being read aloud.
Apaleo GmbH (Germany) β hotel property management system (PMS): if the hotel uses Apaleo and the guest links their stay, we read reservation details (room number, stay dates) from Apaleo solely to answer the guest's question. We do not permanently store this data.
Railway Corp. (hosting, EU region) β application and database hosting.
Stripe, Inc. β payment processing for hotels (clients); it does not process guest data.
Brevo (Sendinblue GmbH, Germany) β transactional e-mails to hotels.
V. International transfers
Data is primarily processed within the EU/EEA. Any transfer outside the EU/EEA (in particular Anthropic, OpenAI and Stripe, based in the USA) is carried out in compliance with GDPR β under standard contractual clauses or the EU-U.S. Data Privacy Framework.
VI. Retention periods
App usage data: duration of use + 3 years, then anonymised
Marketing contacts: until consent is withdrawn
Billing data: 10 years under Czech tax regulations
VII. Your rights
Right of access, rectification, erasure ("right to be forgotten")
Right to restriction of processing and data portability
Right to object and to withdraw consent at any time
Right to lodge a complaint with the Czech Data Protection Authority (ΓOOΓ)
To exercise your rights, please contact us by email. We will respond within 1 month.
VIII. Security
We apply data encryption, access controls, regular backups, firewalls and security audits to protect your personal data.
IX. Changes to this Policy
We will notify you of material changes via the app or website. We recommend checking this page regularly.