Privacy Policy
Last updated: January 2026
1. Data controller
The data controller for personal data processed through the StayHelp service is Touch Informatica (contact: info@stayhelp.app). This policy explains how we collect, use and protect personal data of account holders and, where applicable, of guests who interact with our customers' bots.
2. What we collect
Account data: name, email address, password hash, language, timezone, Stripe customer ID, Telegram user ID once you claim your bot.
Bot configuration: encrypted Telegram bot token, knowledge base entries, rooms list, welcome message.
Guest interactions: chat messages exchanged between guests and the bot, detected guest language, timestamps. These are stored on behalf of our customer (the property owner).
Technical data: IP address of web requests, browser user agent, session cookies, minimal server logs for troubleshooting.
3. Why we collect it (legal basis)
We process account and bot data to provide the service (performance of contract, GDPR Art. 6(1)(b)). We process guest messages on our customers' behalf as a processor. We process minimal technical logs for security and troubleshooting (legitimate interest, GDPR Art. 6(1)(f)). We send transactional emails (signup confirmation, billing notices) under the same contractual basis. We do not use your data for advertising or sell it to third parties.
4. How long we keep it
Account and billing data are kept for the duration of your subscription and for up to 7 years after termination where required by tax and accounting laws. Guest conversation data is retained for 90 days by default and then deleted (customers can shorten this in Settings). Server logs are kept for 30 days.
5. Third-party processors
To operate the service we rely on the following sub-processors: Telegram (messaging infrastructure), Stripe (payments, PCI-DSS certified), DeepSeek (AI model for classification and answer generation), SMTP2GO (transactional email delivery), and a European cloud infrastructure provider for hosting and database. Processing agreements are in place with each provider. An up-to-date list is available on request.
6. Cookies
We use two kinds of cookies. Strictly necessary: a session cookie to keep you logged in, a CSRF token for form security, and a language preference cookie — these are always active and do not require consent. Analytics (Google Analytics): loaded only if you accept via the cookie banner shown on your first visit. Analytics data is anonymized (IP address is masked) and used solely to measure aggregate site usage. You can change your choice at any time via "Cookie settings" in the footer. We do not use advertising or cross-site tracking cookies.
7. Your rights
Under the GDPR you have the right to: access your personal data; correct inaccurate data; request deletion ("right to be forgotten"); restrict or object to processing; receive your data in a portable format; lodge a complaint with your data protection authority (in Italy: Garante per la protezione dei dati personali, www.garanteprivacy.it). To exercise these rights, email us at info@stayhelp.app.
8. International transfers
Our primary infrastructure is hosted in the European Union. Some sub-processors (notably Telegram, Stripe, DeepSeek) may process data outside the EU. Where they do, we rely on standard contractual clauses or adequacy decisions approved by the European Commission.
9. Security
We encrypt Telegram bot tokens at rest using AES-256. Passwords are hashed with BCrypt. All connections to our web and API endpoints use TLS. Access to production data is limited to authorized personnel.
10. Children
The service is intended for business users (B&B and hotel operators). It is not directed at children under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. Material changes will be announced by email to the account owner at least 30 days in advance.
12. Contact
For any privacy question or to exercise your rights, email us at info@stayhelp.app.
13. Direct marketing (B2B paper mail) — legitimate interest
Controller: Touch Informatica Srls, P.IVA IT02431740683, Strada Statale 16 BIS MARE 94, 65010 Spoltore (PE), PEC: touchinformatica@pec.it.
Purpose: sending paper mail (commercial letters) to existing accommodation businesses (hotels, B&Bs, holiday homes, agriturismi, vacation rentals) to promote the StayHelp service.
Categories of recipients: owners or legal representatives of accommodation businesses operating in the EU.
Categories of personal data: business name, postal address. No personal phone, no email, no behavioural or browsing data, no profiling.
Source of the data: publicly available business directories (Italian Chamber of Commerce/REA registers, public booking portals such as Booking.com / Airbnb / Tripadvisor business listings, official websites of the accommodation businesses themselves).
Legal basis: legitimate interest under Art. 6(1)(f) GDPR. We have carried out a balancing test (LIA): the recipients are businesses contacted exclusively at their public business address, in a B2B context they reasonably expect; the message is relevant to their commercial activity (a tool for hospitality operators); we use only postal mail (not the more intrusive email/phone channels); we offer a simple, free opt-out mechanism.
Frequency: at most one or two letters per year per recipient.
Retention: postal addresses are kept only for the time strictly necessary to send the planned mailings, then deleted; opt-out requests are stored in a permanent suppression list to ensure no further mail is sent.
How to opt out: at any time, free of charge, you can stop further postal communications by:
· sending an email to privacy@touchinformatica.it with the name and address of the accommodation business, OR
· sending a paper letter to the postal address of the data controller above.
Other rights: you can also exercise the rights of access, rectification, erasure, restriction and complaint to the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali, www.gpdp.it) as described in section 7 above.
No transfer to third parties: we do not sell or share the postal addresses with anyone. They are used internally by Touch Informatica Srls only.