Privacy Policy
Last updated: 14 November 2026 · Version 3.2
On this page
- Who we are
- Scope and roles
- Categories of personal data
- Purposes and legal bases
- Data retention
- Data sharing and subprocessors
- International transfers
- Data residency and hosting
- Security measures
- Your rights as a data subject
- Automated decisions and profiling
- Children
- Cookies overview
- Complaints and supervisory authority
- Changes to this policy
- How to contact us
1. Who we are
Talk with Guest, Lda ("Talk with Guest", "Talkguest", "we", "us") is a Portuguese limited liability company registered at Conservatória do Registo Comercial de Lisboa under NIPC 516 842 397, with share capital of five thousand euros and registered office at Rua Rodrigo da Fonseca 123, 1.º Esq, 1250-190 Lisboa, Portugal. Talkguest operates a Software-as-a-Service platform for hotels, aparthotels and short-stay operators, delivering messaging, upsell orchestration and guest verification workflows.
This Privacy Policy explains how we collect and process personal data when hotel operators subscribe to our platform, when their guests interact with automated conversations, and when visitors browse talk.mindbery.org. It is issued in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and Portuguese Lei n.º 58/2019 of 8 August, which executes the GDPR in the national legal order.
2. Scope and roles
Talk with Guest acts in two distinct capacities. In respect of website visitors, prospective customers, subscribers and personnel of subscribing hotels, we act as a data controller within the meaning of Article 4(7) GDPR. In respect of personal data of hotel guests processed on behalf of a subscribing hotel through the Talkguest platform, we act as a data processor under Article 4(8) GDPR, with the hotel operator being the controller responsible for the lawfulness of processing.
Where we act as processor, our processing obligations are governed by the Data Processing Addendum incorporated by reference into the subscription agreement. This Privacy Policy addresses controller-level activities. For processor-level activities involving guest reservation data, guest identity data and hotel telemetry, please consult the Data Processing Addendum available in the legal section.
3. Categories of personal data
We process the following categories of personal data as a controller. First, account and identification data of hotel personnel: full name, professional email address, professional phone number, job title, preferred language and the hotel property to which the user is assigned. Second, authentication data: hashed passwords, session identifiers, multi-factor authentication seeds, device fingerprints and login timestamps.
Third, billing data: legal entity name, NIF or equivalent tax identification, billing address, SEPA mandate details (IBAN, mandate reference and signatory), invoice history and payment method fingerprints. Fourth, contractual and support correspondence: emails, ticket transcripts, meeting notes and voice recordings where the operator explicitly agrees to the recording of a call.
Fifth, product usage telemetry: pages visited within the operator console, feature usage frequency, aggregated performance metrics and, where explicitly enabled by the operator, session replays with masked input fields. Sixth, website analytics data collected from visitors to talk.mindbery.org: IP address (truncated at the last octet), browser type, referrer, and pages viewed.
4. Purposes and legal bases
Each processing activity is grounded in a specific legal basis. Account provisioning and delivery of the subscribed service rely on Article 6(1)(b) GDPR, the performance of a contract to which the operator is a party. Billing, invoice issuance and the fulfilment of Portuguese tax obligations rely on Article 6(1)(c), compliance with a legal obligation, in particular the Portuguese fiscal code and Decreto-Lei n.º 28/2019 governing electronic invoicing.
Support communications and the improvement of platform reliability rely on Article 6(1)(f), the legitimate interest of Talk with Guest and its subscribers in operating a robust and secure service. Marketing communications sent to prospective operators rely on consent under Article 6(1)(a) where the recipient is a private individual, and on legitimate interest with an unconditional right to object where the recipient is a legal person acting through a professional email address.
Website analytics rely on consent obtained through the cookie banner. Fraud prevention, abuse detection and defence of legal claims rely on our legitimate interest under Article 6(1)(f). Where we invoke legitimate interest as a legal basis, we have documented the balancing test and made it available on request to privacy@talk.mindbery.org.
5. Data retention
Retention periods are defined per data category and per purpose. Account and authentication data are retained for the duration of the subscription and for twelve months thereafter to permit reactivation. Billing data and issued invoices are retained for ten calendar years, as required by Article 123 of the Portuguese Corporate Income Tax Code (Código do IRC) and by Decreto-Lei n.º 28/2019.
Support correspondence is retained for three years from the closing of the ticket, aligning with the general limitation period for contractual claims under Portuguese civil law. Product usage telemetry is retained in identified form for thirteen months and then aggregated into anonymous statistics. Website analytics with consent are retained for twenty-five months. Marketing consent records are retained for the duration of the consent plus three years for evidentiary purposes.
Where a subscribing hotel terminates its contract, guest-facing conversation data processed on the hotel's behalf is exported and returned to the hotel within thirty days, then deleted from active systems within a further sixty days and from backup systems within one hundred and eighty days.
6. Data sharing and subprocessors
Talk with Guest does not sell personal data. We share personal data only with subprocessors that support the delivery of the service and with counterparties strictly necessary for our legal or contractual obligations. Our current subprocessor list is published at talk.mindbery.org/legal/subprocessors and includes the underlying hosting provider (OVHcloud, Portugal and Ireland), the transactional email carrier (Mailgun EU region), the customer messaging suite (Intercom, EU tenancy), the error monitoring provider (Sentry, Frankfurt region) and the invoicing gateway (Stripe Payments Europe, Ireland, for card-based settlements).
Each subprocessor is bound by a written agreement that mirrors the obligations we owe as processor to our subscribing hotels, including confidentiality, security, breach notification, and assistance with data subject requests. We conduct an annual review of subprocessor security postures and publish material changes with at least thirty days' advance notice through our changelog and by email to the operator's primary billing contact.
7. International transfers
Our primary hosting infrastructure is located in Portugal, with high-availability replication in Ireland. Personal data remains within the European Economic Area under normal operating conditions. Where an ancillary subprocessor is established outside the EEA, or where personnel outside the EEA may access personal data (for example, a support engineer connecting from Brazil under our globally distributed on-call rota), we rely on the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 and, where required, on supplementary technical measures including transport encryption, at-rest encryption with keys held in Portugal and access logging.
8. Data residency and hosting
All customer data and guest conversation logs are stored on infrastructure physically located within the European Union. Primary production workloads run in OVHcloud's Roubaix and Sines regions, with disaster-recovery in Ireland. We do not replicate customer data to regions outside the EEA. Talkguest publishes region indicators in the operator console so that hotel administrators can verify at any moment where their tenancy is hosted.
9. Security measures
We implement the technical and organisational measures described in Annex II of the Data Processing Addendum. These include, but are not limited to, encryption of data in transit using TLS 1.2 or higher, encryption at rest using AES-256, role-based access control with the principle of least privilege, mandatory multi-factor authentication for all personnel, quarterly penetration testing by an independent third party, annual ISO/IEC 27001-aligned internal audits, dedicated security incident response with a maximum internal detection-to-triage target of two hours, and secure software development lifecycle practices including mandatory peer code review and automated vulnerability scanning of dependencies.
10. Your rights as a data subject
Under Articles 15 to 22 GDPR you may exercise the following rights: the right of access to the personal data we hold about you, the right to rectify inaccurate or incomplete data, the right to erasure where the data is no longer necessary or where you withdraw consent, the right to restriction of processing during the verification of a rectification or objection, the right to data portability in a structured, commonly used and machine-readable format, the right to object to processing based on legitimate interest or direct marketing, and the right not to be subject to a decision based solely on automated processing that produces legal effects.
Requests should be sent to privacy@talk.mindbery.org or by post to the registered office indicated in section one. We reply within thirty calendar days from receipt, extendable by two further months in cases of complexity or volume, with prior notice. Where the data subject is a guest of a hotel that uses Talkguest, we forward the request to the relevant hotel controller within seventy-two hours and provide the controller with the necessary technical assistance to respond.
11. Automated decisions and profiling
Talkguest uses automated logic to route messages, suggest upsell offers and flag potentially fraudulent bookings for human review. These processes do not produce legal effects on data subjects or similarly significantly affect them, since a human hotel operator retains final decision-making authority. Guests are informed within the conversation interface that they are speaking to an automated assistant and may at any moment request a human operator.
12. Children
Our services are directed at hotel operators, not at children. We do not knowingly collect personal data of children under sixteen years of age. Where a guest under this age uses a Talkguest-powered conversation surface, the hotel controller is responsible for obtaining parental or guardian consent as required by national law transposing Article 8 GDPR.
13. Cookies overview
The talk.mindbery.org website uses strictly necessary cookies to remember consent choices and to preserve the language preference of the visitor. Analytics, functional and marketing cookies are placed only after affirmative consent obtained through the cookie banner. A detailed cookie inventory, retention periods and vendors is available in the Cookie Policy. Consent can be withdrawn at any moment through the cookie preferences link located in the footer of every page.
14. Complaints and supervisory authority
If you consider that our processing of your personal data infringes the GDPR or Lei n.º 58/2019, you may lodge a complaint with the Comissão Nacional de Proteção de Dados (CNPD), the Portuguese supervisory authority, at Avenida D. Carlos I, 134, 1.º, 1200-651 Lisboa, or through the online form at cnpd.pt. You may also address a supervisory authority in the Member State of your habitual residence or place of the alleged infringement. We nonetheless invite you to contact us first so that we may address your concerns directly.
15. Changes to this policy
Material changes to this Privacy Policy are announced at least thirty days in advance through the talk.mindbery.org changelog, by email to the primary billing contact of each subscribing hotel and by an in-product notification. Non-material corrections such as typographical adjustments are applied without prior notice and reflected in the version number at the top of this page.
16. How to contact us
You can contact the Talk with Guest privacy team at privacy@talk.mindbery.org for any general inquiry, or the Data Protection Officer, Rita Ferreira Marques, at dpo@talk.mindbery.org for questions concerning the exercise of your rights, the interpretation of this policy or the reporting of an incident. Postal correspondence should be addressed to Talk with Guest, Lda, Rua Rodrigo da Fonseca 123, 1.º Esq, 1250-190 Lisboa, Portugal. Guest Talk personnel are available on business days from nine to eighteen hours Western European Time.