Your data
Data & security
Your guests trust your hotel with their details. Here is exactly how atithiai looks after them.
Who’s responsible for what
- Your hotel is the Data Fiduciary for your guests’ data: you decide why it’s collected and how it’s used.
- atithiai is your Data Processor: we handle guest data only to run your receptionist, following your instructions and the commitments on this page.
- For your own team’s data and for our website, we are the Data Fiduciary; see our Privacy policy.
What data passes through atithiai
| Data | Where it comes from | What it’s used for |
|---|---|---|
| Guest messages and voice notes | Guests, on WhatsApp | Understanding and answering the guest |
| Guest name and WhatsApp number | Replying, and linking the chat to bookings | |
| Booking details: dates, guests, room, amount | The conversation | Quotes, holds and confirmations |
| Deposit status | Your payment gateway | Confirming a booking once the deposit is paid |
| Rooms, rates, photos and policies | Your hotel | Giving guests accurate answers |
| Staff names, phone numbers and emails | Your hotel | Access to atithiai and handing chats over |
We don’t ask guests for ID documents or card details through atithiai, and card and UPI details never reach us. If a guest sends something sensitive anyway, it’s treated like any other message and deleted on the same schedule.
Where it’s stored and processed
- Database — India. Guest conversations, bookings and hotel settings are stored in our Supabase (PostgreSQL) database in the AWS Mumbai region.
- Automation server. Our server on Amazon Web Services passes messages between WhatsApp, the AI and the database. It keeps only short-lived processing logs.
- WhatsApp. Meta’s WhatsApp Business Platform delivers messages. Meta keeps message content for up to 30 days to deliver it, then deletes it.
- AI. Groq runs the AI model that reads each message and drafts the reply, in the United States. By default Groq doesn’t keep these requests (except for up to 30 days when needed to investigate abuse or failures) and never trains its models on them.
Who can see it
- Your team: only the people you add, and only for your hotel.
- Other hotels: never. Every record belongs to one hotel and is protected by row-level security in the database.
- atithiai: only our founding team, and only when needed to set up, support or fix your receptionist.
How we protect it
- Encryption in transit (HTTPS/TLS) between every part of the system, and encryption at rest in the database.
- Row-level security that keeps every hotel’s data separate.
- Two-factor authentication on every admin account, and API keys and secrets kept out of our code.
- Payment gateway keys used only to create deposit links and check payments.
- Security logs kept for at least a year.
- Regular backups, so data can be restored if something fails.
How long we keep it
| Data | Kept for |
|---|---|
| Guest conversations and bookings | While your hotel uses atithiai, or a shorter period you ask for. Deleted within 30 days after your account closes. |
| Message copies on WhatsApp’s servers | Up to 30 days (Meta’s policy). |
| AI requests at Groq | Not kept by default; up to 30 days only to investigate abuse or failures. |
| Hotel settings and staff accounts | While you’re a customer. Deleted within 30 days after your account closes. |
| Consultation requests from our website | 12 months after our last contact, unless you become a customer. |
| Invoices and billing records | As long as Indian tax and accounting laws require (up to 8 years). |
| Security logs | 1 year. |
What we never do
- Sell guest or hotel data.
- Use it for advertising, or share it with advertisers.
- Use your guests’ conversations to train AI models.
- Message your guests for our own marketing.
If something goes wrong
If we find a personal data breach affecting your guests, we’ll tell you without delay — within 24 hours of confirming it — with what happened, which data was involved and what we’re doing about it, so you can inform your guests and the Data Protection Board of India. Where we are responsible for the data ourselves, we inform the Board and the people affected directly.
Guest requests
If a guest asks you to see, correct or delete their data, tell us and we’ll help you respond within 7 days. If a guest contacts us directly, we pass the request to you and act on your instructions, unless the law requires otherwise. Guests can also follow the steps on Delete your data.
When you leave atithiai
You can ask for an export of your guest conversations and bookings at any time, and for 30 days after your account closes. After those 30 days we delete your hotel’s data from our systems, except billing records we must keep by law. Copies in backups are overwritten in the normal backup cycle within a further 30 days.
Our service providers
These providers process data for us. Each is bound to use it only to provide its service and to protect it.
| Provider | What they do |
|---|---|
| Meta Platforms (WhatsApp Business Platform) | Delivers WhatsApp messages. |
| Groq | Runs the AI model, in the United States. |
| Supabase | Hosts our database, in the AWS Mumbai region in India. |
| Amazon Web Services | Runs our automation server. |
| Hostinger | Hosts the atithiai.in website (no guest data). |
| Web3Forms | Delivers website form submissions to our inbox (no guest data). |
We’ll update this list, and tell our customers, before adding a provider that handles guest data.
Questions
Write to our Grievance Officer, Aditya Kashyap, at hello@atithiai.in or call +91 92511 16376.