Last updated: August 21, 2025

Privacy Policy - hospitality

We believe it is very important for you to know what data we collect about you, how we collect it, and why it is necessary.

This privacy policy is designed for specific use cases in the hospitality industry. For information about our personal data management practices in other sectors, please refer to our general privacy policy.

What data does Bookline collect?
Bookline collects only the personal data needed to operate the conversational assistant on behalf of our hospitality clients. This typically includes identification details (name, phone number), the content of voice and WhatsApp interactions, and operational metadata such as timestamps and dispatch context. We do not collect sensitive categories of data and we never sell personal data to third parties.
How and for what purpose is this data collected?
Data is collected when you contact a Bookline client through our voice or WhatsApp assistant. The purposes are: (i) to fulfil your request and complete the communication on the client's behalf; (ii) to provide operational analytics to our clients; and (iii) to comply with applicable legal obligations. The legal bases under GDPR are contract performance, legitimate interest, and legal obligation.
How does Bookline protect my data?
Bookline applies industry-standard technical and organisational measures, including transport encryption (TLS), encryption at rest, role-based access controls, audit logging, and regular security reviews. Data is processed in EU-based infrastructure. Sub-processors are bound by data-processing agreements aligned with GDPR requirements.
How long does Bookline keep my personal data?
Personal data is retained only for as long as needed to fulfil the purposes for which it was collected and to satisfy applicable legal retention obligations. After that period, data is deleted or irreversibly anonymised. Specific retention periods are defined in our agreements with the data-controller client you contacted.
How does Bookline share and transfer my data?
Your data is shared with the Bookline client you contacted (the data controller) and, where strictly necessary, with vetted sub-processors that support our infrastructure (cloud hosting, telephony, messaging). Where any transfer outside the European Economic Area is required, it is governed by Standard Contractual Clauses or another GDPR-approved mechanism.
What rights do I have regarding data protection?
You have the GDPR rights of access, rectification, erasure, restriction, portability, and objection, as well as the right to withdraw consent and to lodge a complaint with a supervisory authority (in Spain, the AEPD). To exercise any of these rights in connection with Bookline\'s processing, contact dpo@bookline.ai. To exercise them against the client you contacted, address your request directly to that controller.