Skip to content
Legal

Privacy Policy

Last updated: 29 August 2026 hello@guestdash.com
In short
  • We are two things at the same time. When we process your data as a visitor to our website or a user of our platform, we are the ones who decide — we are the controller. When the platform processes the data of the guests of a hotel that is our client, the hotel is the one who decides: we are only the processor and we act on its instructions.
  • We do not sell personal data. To anyone, under any circumstances.
  • We do not use our clients’ data to train artificial intelligence models.
  • You can exercise your rights — access, rectification, erasure, objection — by writing to hello@guestdash.com.

The rest of this page explains all of this in detail.

01Who we are

This website and this platform are operated by Guestdash Tecnologia, Unipessoal, Lda., a legal person incorporated under Portuguese law, NIPC 518583090, with its registered office at Rua Manuel Firmino, n.º 45, 3800-213 Aveiro, Portugal.

For any question relating to data protection, including the exercise of your rights, write to hello@guestdash.com.

02Our dual role: when we decide and when we execute

This is the most important part of this policy, and the one that causes the most confusion in platforms like ours. The General Data Protection Regulation distinguishes two roles, and Guestdash performs both, in different contexts.

2.1 · We are the controller when…

…the data is ours to decide about. This is the case for:

  • visitors to our sites guestdash.com, guestdash.pt and guestdash.com.br;
  • prospective clients who contact us, request a demonstration or subscribe to communications;
  • users of our clients’ accounts — the people on the hotel team who log in to the platform;
  • job applicants and business partners.

In these cases, it is we who define the purposes and the means of the processing, and it is to us that you should turn to exercise your rights. It is this processing that Section 3 describes.

2.2 · We are the processor when…

…the data belongs to our clients’ guests. When a hotel uses Guestdash, the data of its guests — name, contact details, booking, messages exchanged, requests made, voice recordings — is processed by us only to the extent that the hotel instructs us.

In that context:

  • the hotel is the controller: it defines the purposes, ensures the legal basis and responds to data subjects;
  • Guestdash is the processor: it processes the data exclusively on the hotel’s documented instructions, under the terms of the services agreement.

If you are a guest of a hotel that uses Guestdash and you want to access, rectify or erase your data, your request must be addressed to the hotel. If you contact us directly, we will forward the request to the hotel responsible and inform you that we have done so — we cannot decide about that data on our own initiative, because it is not ours to decide about.

It is this processing that Section 6 describes.

03What data we process as controller

3.1 · Data you provide to us directly

CategoryExamplesWhen
Identification and contact detailsName, email, telephone, company, job titleContact forms, demonstration requests, newsletter subscription
Account dataUsername, encrypted password, access profile, preferencesWhen creating or using an account on the platform
Contractual and billing dataCompany name, tax identification number, address, billing detailsWhen becoming a client
CommunicationsContent of emails, support requests, conversations with usWhen you contact us
Job applicationsCV, professional background and whatever else you choose to send usWhen applying for a vacancy

3.2 · Data collected automatically

When you visit our website or use the platform, we collect:

  • Technical data: IP address, browser type and version, operating system, language, screen resolution and time zone.
  • Usage data: pages visited, time on each page, source of the visit, actions performed on the platform and access logs with date, time and the feature accessed.
  • Cookies and similar technologies: see our Cookie Policy.

The platform access logs are also a security mechanism: they allow us to detect improper access and to comply with the audit duty we owe to our clients.

04What we use that data for, and on what legal basis

The General Data Protection Regulation requires every processing operation to have a legal basis. Here is ours, processing by processing:

PurposeWhat we doLegal basis
Providing the serviceCreating and managing accounts, making the platform available, providing technical supportPerformance of a contract
Billing and tax obligationsIssuing invoices and keeping accounting recordsLegal obligation
Commercial communicationResponding to demonstration requests and presenting proposalsPre-contractual steps and legitimate interest
News and contentSending communications about the product and the sectorConsent, which can be withdrawn at any time
Platform securityPreventing fraud, detecting improper access, keeping audit logsLegitimate interest
Product improvementUnderstanding how the platform is used and where it failsLegitimate interest
Legal complianceResponding to competent authoritiesLegal obligation
RecruitmentAssessing job applicationsPre-contractual steps

Whenever we rely on legitimate interest, we have first weighed that interest against your rights and freedoms. You can ask us for the details of that assessment, or object to the processing, through hello@guestdash.com.

Where the basis is consent, you can withdraw it at any time, without affecting the lawfulness of the processing carried out until then.

05Who we share data with

We do not sell personal data. We share only what is necessary, and only with:

5.1 · Sub-processors

We work with service providers that process data on our behalf, under a written contract that binds them to security and confidentiality standards equivalent to ours. The categories are:

CategoryWhat for
Cloud hosting and infrastructureRunning the platform and storing the data
Communications and messagingSending and receiving messages on the supported channels
Artificial intelligence model providersProcessing natural language in the text and voice agents
Voice transcription and synthesisConverting speech to text and text to speech
Transactional email and communicationsSending notifications and messages
Usage analyticsUnderstanding how the site and the product are used
Billing and paymentsProcessing payments and issuing invoices
Support and request managementHandling support requests

The up-to-date list of sub-processors, identifying each one and its location, is available at guestdash.com/subcontratantes and is communicated to clients under the terms of the contract. Clients are informed in advance of material changes to the list.

5.2 · A note on artificial intelligence

Because it is a legitimate and frequent question, we answer it explicitly:

  • We do not use our clients’ data, nor the data of their guests, to train artificial intelligence models — whether ours or third parties’.
  • We use model providers in processing mode, under contractual terms that exclude the use of the data to train their models.
  • Where the hotel chooses to connect its own account with a provider directly, the processing also becomes governed by the terms the hotel has accepted with that provider.

5.3 · Other recipients

  • Public authorities, where there is a legal obligation or a lawful order.
  • Advisers — lawyers, accountants and auditors — under a duty of confidentiality.
  • In the event of a corporate reorganisation, such as a merger or acquisition, the data may be transferred, with the safeguards in this policy being maintained. You will be informed if that happens.

06Guest data: what the platform processes on the hotels’ behalf

This section describes, transparently, what happens on the platform when a hotel uses it — even though, in these cases, the controller is the hotel and not us.

6.1 · What data

Depending on the modules the hotel activates:

  • Identification and booking: name, contact details, language, booking and stay data, coming from the property management system or from the booking channels.
  • Conversations: messages exchanged on the connected channels, including the history.
  • Voice: recordings of calls and interactions with voice agents, and their transcriptions and summaries.
  • Requests and operations: requests made, bookings, validated attendance, responses to satisfaction surveys, forms and digital signatures.
  • Documents: where the hotel activates document collection modules, the documents the guest provides.

6.2 · Special categories of data

In the hotel context, some information provided by the guest may reveal special categories of data — for example, a dietary restriction may point to religious beliefs or a health condition, and an accessibility request may reveal a disability. This data is processed exclusively on the instruction of the hotel as controller, which is responsible for ensuring the applicable condition for lawfulness under Article 9 of the General Data Protection Regulation. Guestdash does not use this data for any purpose of its own.

6.3 · Principles we always apply

Regardless of the hotel’s instructions, we apply by default:

  • Isolation between clients: each hotel’s data is segregated and no client has access to another’s data.
  • Access control: granular profiles and permissions, so that each hotel employee sees only what they need.
  • Encryption: data encrypted in transit and at rest.
  • Audit logs: relevant actions are logged, identifying who carried them out.
  • Retention periods: defined with the hotel. Voice recordings have a configured retention period and are not kept indefinitely.
  • Breach notification: we notify the hotel of any personal data breach within a maximum of 72 hours after becoming aware of it.
  • Return or deletion at the end: once the contract ends, the data is returned in a structured and accessible format, or deleted, according to the hotel’s instruction and unless a legal obligation requires otherwise.

6.4 · If you are a guest and want to exercise your rights

Contact the hotel where you stayed — it is the controller. If you prefer to contact us, we will forward your request to the hotel and inform you that we have done so.

07International transfers

Our infrastructure is hosted preferentially in the European Union.

Some of our sub-processors — in particular providers of communications and of artificial intelligence models — may process data outside the European Economic Area. In those cases, we ensure that the transfer has a valid basis under Chapter V of the General Data Protection Regulation, namely:

  • an adequacy decision of the European Commission concerning the destination country; or
  • Standard Contractual Clauses approved by the European Commission, accompanied by the additional technical and organisational measures determined by the transfer impact assessment.

You can request information about the safeguards applicable to a specific transfer through hello@guestdash.com.

08How long we keep the data

DataPeriod
Account and contractual dataFor the duration of the contract and, thereafter, for the applicable limitation period
Billing and accounting10 years, as required by Portuguese law
Commercial contacts without a contractUp to 2 years after the last contact
Communications and newsUntil you withdraw your consent
Access and security logs12 months
Job applications12 months after the end of the process, unless consent is given for longer retention
Guest data, as processorAccording to the instruction of the hotel as controller

Once the periods have elapsed, the data is deleted or irreversibly anonymised.

09Your rights

Under the General Data Protection Regulation, you have the right to:

  • Access your data and obtain a copy;
  • Rectify incorrect or incomplete data;
  • Erase your data, where applicable;
  • Restrict the processing in certain circumstances;
  • Portability: receive your data in a structured, commonly used and machine-readable format, or ask for it to be transmitted to another controller;
  • Object to processing based on legitimate interest, including for direct marketing purposes;
  • Withdraw your consent at any time, where the processing is based on it;
  • Not be subject to solely automated decisions producing legal effects or similarly significantly affecting you.

How to exercise them: write to hello@guestdash.com. We will reply within one month, extendable by a further two months in complex cases, and you will be informed of that extension. We may ask for additional details to confirm your identity — only to make sure we do not hand your data to someone else.

Complaints: if you consider that your rights have not been respected, you have the right to lodge a complaint with the supervisory authority. In Portugal, the Comissão Nacional de Proteção de Dados, at www.cnpd.pt. We would nevertheless appreciate the opportunity to resolve the matter with you first.

10Automated decisions

As controller, we do not take solely automated decisions producing legal effects concerning you or similarly significantly affecting you.

The artificial intelligence agents available on the platform answer questions and carry out requests in accordance with the configuration and the supervision defined by each hotel. Defining those flows, including the cases in which the interaction is escalated to a human employee, is for the hotel as controller.

11Security

We apply technical and organisational measures appropriate to the risk, including:

  • encryption in transit and at rest;
  • access control by profile, with the principle of least privilege;
  • strong authentication and password policies;
  • logical segregation between clients;
  • audit logs of relevant actions;
  • backups and recovery procedures;
  • monitoring and incident response;
  • periodic assessment of providers and of our own security posture.

No system is infallible. If a personal data breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify you and the Comissão Nacional de Proteção de Dados under the terms and within the periods legally required.

12Minors

The platform is intended for professionals and is not directed at minors. We do not knowingly collect data of minors through our website. Data of minors may arise in the context of a hotel booking, for example children included in a stay — in that case, the processing is the responsibility of the hotel, which must ensure the appropriate legal basis.

13For users in Brazil

If you access our services from Brazil, in particular through guestdash.com.br, the processing of your personal data also complies with the Brazilian General Data Protection Law, Law no. 13.709/2018.

For the purposes of the LGPD:

  • where this policy refers to the controller, read controlador; where it refers to the processor, read operador. The logic is the same: the hotel is the controlador of its guests’ data and Guestdash is the operador, processing it on the hotel’s instructions;
  • the data subject rights provided for in Article 18 of the LGPD — confirmation of the processing, access, correction, anonymisation, deletion, portability, information about sharing and withdrawal of consent — can be exercised through hello@guestdash.com, with a reply within the applicable legal periods;
  • the competent supervisory authority is the Autoridade Nacional de Proteção de Dados, at www.gov.br/anpd;
  • if you are a guest of a Brazilian hotel that uses Guestdash, your request must be addressed to the hotel, in its capacity as controlador, as described in Section 6.

14Changes to this policy

We may update this policy, as the product, the law or our practices evolve. We will always publish the version in force on this page, with the date of the last update. If the change is material, we will inform clients by email or through the platform, with reasonable notice.

15Contacts

Guestdash Tecnologia, Unipessoal, Lda.
NIPC 518583090
Rua Manuel Firmino, n.º 45, 3800-213 Aveiro, Portugal
hello@guestdash.com