Book a consultation

Your data

Data & security

Your guests trust your hotel with their details. Here is exactly how atithiai looks after them.

Last updated 5 October 2026

Who’s responsible for what

  • Your hotel is the Data Fiduciary for your guests’ data: you decide why it’s collected and how it’s used.
  • atithiai is your Data Processor: we handle guest data only to run your receptionist, following your instructions and the commitments on this page.
  • For your own team’s data and for our website, we are the Data Fiduciary; see our Privacy policy.

What data passes through atithiai

DataWhere it comes fromWhat it’s used for
Guest messages and voice notesGuests, on WhatsAppUnderstanding and answering the guest
Guest name and WhatsApp numberWhatsAppReplying, and linking the chat to bookings
Booking details: dates, guests, room, amountThe conversationQuotes, holds and confirmations
Deposit statusYour payment gatewayConfirming a booking once the deposit is paid
Rooms, rates, photos and policiesYour hotelGiving guests accurate answers
Staff names, phone numbers and emailsYour hotelAccess to atithiai and handing chats over

We don’t ask guests for ID documents or card details through atithiai, and card and UPI details never reach us. If a guest sends something sensitive anyway, it’s treated like any other message and deleted on the same schedule.

Where it’s stored and processed

  • Database — India. Guest conversations, bookings and hotel settings are stored in our Supabase (PostgreSQL) database in the AWS Mumbai region.
  • Automation server. Our server on Amazon Web Services passes messages between WhatsApp, the AI and the database. It keeps only short-lived processing logs.
  • WhatsApp. Meta’s WhatsApp Business Platform delivers messages. Meta keeps message content for up to 30 days to deliver it, then deletes it.
  • AI. Groq runs the AI model that reads each message and drafts the reply, in the United States. By default Groq doesn’t keep these requests (except for up to 30 days when needed to investigate abuse or failures) and never trains its models on them.

Who can see it

  • Your team: only the people you add, and only for your hotel.
  • Other hotels: never. Every record belongs to one hotel and is protected by row-level security in the database.
  • atithiai: only our founding team, and only when needed to set up, support or fix your receptionist.

How we protect it

  • Encryption in transit (HTTPS/TLS) between every part of the system, and encryption at rest in the database.
  • Row-level security that keeps every hotel’s data separate.
  • Two-factor authentication on every admin account, and API keys and secrets kept out of our code.
  • Payment gateway keys used only to create deposit links and check payments.
  • Security logs kept for at least a year.
  • Regular backups, so data can be restored if something fails.

How long we keep it

DataKept for
Guest conversations and bookingsWhile your hotel uses atithiai, or a shorter period you ask for. Deleted within 30 days after your account closes.
Message copies on WhatsApp’s serversUp to 30 days (Meta’s policy).
AI requests at GroqNot kept by default; up to 30 days only to investigate abuse or failures.
Hotel settings and staff accountsWhile you’re a customer. Deleted within 30 days after your account closes.
Consultation requests from our website12 months after our last contact, unless you become a customer.
Invoices and billing recordsAs long as Indian tax and accounting laws require (up to 8 years).
Security logs1 year.

What we never do

  • Sell guest or hotel data.
  • Use it for advertising, or share it with advertisers.
  • Use your guests’ conversations to train AI models.
  • Message your guests for our own marketing.

If something goes wrong

If we find a personal data breach affecting your guests, we’ll tell you without delay — within 24 hours of confirming it — with what happened, which data was involved and what we’re doing about it, so you can inform your guests and the Data Protection Board of India. Where we are responsible for the data ourselves, we inform the Board and the people affected directly.

Guest requests

If a guest asks you to see, correct or delete their data, tell us and we’ll help you respond within 7 days. If a guest contacts us directly, we pass the request to you and act on your instructions, unless the law requires otherwise. Guests can also follow the steps on Delete your data.

When you leave atithiai

You can ask for an export of your guest conversations and bookings at any time, and for 30 days after your account closes. After those 30 days we delete your hotel’s data from our systems, except billing records we must keep by law. Copies in backups are overwritten in the normal backup cycle within a further 30 days.

Our service providers

These providers process data for us. Each is bound to use it only to provide its service and to protect it.

ProviderWhat they do
Meta Platforms (WhatsApp Business Platform)Delivers WhatsApp messages.
GroqRuns the AI model, in the United States.
SupabaseHosts our database, in the AWS Mumbai region in India.
Amazon Web ServicesRuns our automation server.
HostingerHosts the atithiai.in website (no guest data).
Web3FormsDelivers website form submissions to our inbox (no guest data).

We’ll update this list, and tell our customers, before adding a provider that handles guest data.

Questions

Write to our Grievance Officer, Aditya Kashyap, at hello@atithiai.in or call +91 92511 16376.