Privacy Policy

Last updated: January 2026

1. Data controller

The data controller for personal data processed through the StayHelp service is Touch Informatica (contact: info@stayhelp.app). This policy explains how we collect, use and protect personal data of account holders and, where applicable, of guests who interact with our customers' bots.

2. What we collect

Account data: name, email address, password hash, language, timezone, Stripe customer ID, Telegram user ID once you claim your bot.
Bot configuration: encrypted Telegram bot token, knowledge base entries, rooms list, welcome message.
Guest interactions: chat messages exchanged between guests and the bot, detected guest language, timestamps. These are stored on behalf of our customer (the property owner).
Technical data: IP address of web requests, browser user agent, session cookies, minimal server logs for troubleshooting.

3. Why we collect it (legal basis)

We process account and bot data to provide the service (performance of contract, GDPR Art. 6(1)(b)). We process guest messages on our customers' behalf as a processor. We process minimal technical logs for security and troubleshooting (legitimate interest, GDPR Art. 6(1)(f)). We send transactional emails (signup confirmation, billing notices) under the same contractual basis. We do not use your data for advertising or sell it to third parties.

4. How long we keep it

Account and billing data are kept for the duration of your subscription and for up to 7 years after termination where required by tax and accounting laws. Guest conversation data is retained for 90 days by default and then deleted (customers can shorten this in Settings). Server logs are kept for 30 days.

5. Third-party processors

To operate the service we rely on the following sub-processors: Telegram (messaging infrastructure), Stripe (payments, PCI-DSS certified), DeepSeek (AI model for classification and answer generation), SMTP2GO (transactional email delivery), and a European cloud infrastructure provider for hosting and database. Processing agreements are in place with each provider. An up-to-date list is available on request.

6. Cookies

Usamos dos tipos de cookies. Estrictamente necesarias: una cookie de sesión para mantenerte autenticado, un token CSRF para la seguridad de los formularios y una cookie para la preferencia de idioma — siempre activas, no requieren consentimiento. Analytics (Google Analytics): se carga solo si aceptas en el banner de cookies mostrado en tu primera visita. Los datos se anonimizan (IP enmascarada) y se usan exclusivamente para medir el uso agregado del sitio. Puedes cambiar tu elección en cualquier momento desde "Configuración cookies" en el pie de página. No usamos cookies publicitarias ni de seguimiento entre sitios.

7. Your rights

Under the GDPR you have the right to: access your personal data; correct inaccurate data; request deletion ("right to be forgotten"); restrict or object to processing; receive your data in a portable format; lodge a complaint with your data protection authority (in Italy: Garante per la protezione dei dati personali, www.garanteprivacy.it). To exercise these rights, email us at info@stayhelp.app.

8. International transfers

Our primary infrastructure is hosted in the European Union. Some sub-processors (notably Telegram, Stripe, DeepSeek) may process data outside the EU. Where they do, we rely on standard contractual clauses or adequacy decisions approved by the European Commission.

9. Security

We encrypt Telegram bot tokens at rest using AES-256. Passwords are hashed with BCrypt. All connections to our web and API endpoints use TLS. Access to production data is limited to authorized personnel.

10. Children

The service is intended for business users (B&B and hotel operators). It is not directed at children under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

11. Changes to this policy

We may update this policy from time to time. Material changes will be announced by email to the account owner at least 30 days in advance.

12. Contact

For any privacy question or to exercise your rights, email us at info@stayhelp.app.

13. Marketing directo (correo postal B2B) — interés legítimo

Responsable: Touch Informatica Srls, NIF IT02431740683, Strada Statale 16 BIS MARE 94, 65010 Spoltore (PE) Italia, PEC: touchinformatica@pec.it.

Finalidad: envío de correo postal (cartas comerciales) a establecimientos de alojamiento existentes (hoteles, B&B, casas vacacionales, agroturismos, alquileres de corta duración) para promocionar el servicio StayHelp.

Categorías de destinatarios: titulares o representantes legales de establecimientos de alojamiento en la Unión Europea.

Categorías de datos: nombre comercial y dirección postal. Sin teléfonos personales, sin email, sin datos de comportamiento ni perfilado.

Origen de los datos: directorios públicos de alojamientos (registros mercantiles, portales públicos como Booking.com / Airbnb / Tripadvisor en sus áreas B2B, sitios oficiales de los propios establecimientos).

Base jurídica: interés legítimo según el art. 6.1.f) RGPD. Hemos realizado el test de equilibrio (LIA).

Frecuencia: como máximo una o dos cartas al año por destinatario.

Conservación: las direcciones se conservan solo el tiempo necesario para los envíos programados y luego se eliminan; las solicitudes de oposición se incluyen en una lista de supresión permanente.

Cómo oponerse: en cualquier momento y de forma gratuita:
· enviando un email a privacy@touchinformatica.it con el nombre y la dirección del establecimiento, O
· enviando una carta a la dirección del responsable.

Otros derechos: acceso, rectificación, supresión, limitación y reclamación a la autoridad de control (sección 7).

Sin cesión a terceros: las direcciones no se venden ni se comparten.