This version updated 2nd June 2025.
This Privacy Policy explains how Hotelworld AI Limited (“we”, “us”, or “our”) collects, uses, shares, and protects personal data when providing AI agent services to business customers. We are committed to compliance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the EU AI Act. This policy describes your rights and our obligations regarding your information.
We may collect the following categories of personal data:
We do not intentionally collect sensitive personal data unless necessary and with explicit consent.
We process personal data for the following purposes:
We only process personal data for specified, explicit, and legitimate purposes, and do not use it in ways incompatible with those purposes.
Our AI agents may process personal data autonomously to deliver services, including automated decision-making. Where such processing has legal or significant effects, data subjects have the right to request human intervention, express their point of view, and contest decisions.
We may use information from public social media profiles to better understand customer preferences and enhance the services provided to customers. We do this based on our clients’ legitimate interest in improving the experience of their customers. You have the right to object to this processing at any time.
We provide clear, plain-language explanations of how our AI agents operate, including the logic, significance, and consequences of automated decisions, as required by GDPR and the EU AI Act.
We may share your data with:
If we use third-party AI platforms, we disclose their identity and ensure they meet GDPR and CCPA requirements.
You have the following rights, subject to applicable law:
For California residents, you may also opt out of the sale or sharing of personal information and request information about data disclosures.
We collect only the data necessary for our stated purposes and retain it only as long as required by law or business needs. We implement robust security measures, including encryption, access controls, and regular audits, to protect your data from unauthorized access or disclosure.
We conduct Data Protection Impact Assessments (DPIAs) for high-risk processing, as required by GDPR and the EU AI Act. Our systems are regularly monitored for compliance, and we maintain detailed records of processing activities, consent, and data access.
If your data is transferred outside your jurisdiction (e.g., from the EU to the US), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or equivalent mechanisms.
We may update this Privacy Policy to reflect changes in law or our practices. We will notify you of significant updates and post the revised policy on our website.
For questions or to exercise your rights, contact us at: compliance@hotelworld.ai