Privacy Policy
Giorgio Profili S.r.l. · Last updated 27 July 2026
Giorgio Profili S.r.l. (“we”, “us”) operates a WhatsApp guest-messaging platform for short-stay accommodation businesses (including our own accommodation in Tokyo). This policy explains what personal data we process when you message a WhatsApp business number connected to our platform, why, and the choices you have.
Our role. For guest conversations of our own accommodation, and for platform (staff) accounts, Giorgio Profili S.r.l. is the data controller. For guest conversations of other accommodation businesses using the platform, we process data as a processor on that business’s behalf and instructions — that business is the controller. If you are a guest, you can contact the accommodation you stayed with, or write to us directly and we will handle or route your request.
Information we collect
When you send a message to a WhatsApp business number connected to our platform, we receive and store:
- Your WhatsApp phone number and WhatsApp profile name.
- The content of the messages you send us and that we send you (text and, where applicable, references to media such as images or documents).
- Message metadata such as timestamps and delivery/read status.
- Booking details the accommodation links to your conversation — such as check-in and check-out dates, room or unit name, and party size — from its booking system.
We do not collect your contacts, location, or any data from your device beyond the messages you choose to send us.
Dashboard accounts for accommodation staff are provisioned by us at the accommodation business’s request — there is no self-service sign-up, so we only ever hold staff account data the business has asked us to create. For each account we store a username, a salted password hash (never the password itself), and login timestamps.
How we use it
- To answer your questions and provide guest support before, during and after your stay.
- To keep a history of our conversation so we can assist you consistently.
- To draft suggested replies for our staff using an AI assistant (the staff member reviews and sends the reply).
We rely on our legitimate interest in communicating with guests, and on performing our accommodation contract with you, as the legal bases for this processing.
Service providers
We share data only with providers that help us deliver this service:
- Meta Platforms / WhatsApp — the messaging platform that delivers messages between you and us.
- Amazon Web Services — conversations are stored in a private database on our own server, hosted with AWS in the European Union.
- Anthropic (Claude) — processes message text to generate suggested reply drafts. Message content is not used by Anthropic to train its models.
We do not sell your personal data or use it for advertising. Because these providers operate internationally, your data may be processed outside your country, including in the EU and the United States, under appropriate safeguards.
Data retention
- Conversation history and linked booking context are deleted or anonymised 12 months after your last message, unless the accommodation instructs otherwise or a stay is still ongoing. You can ask us to delete your data earlier at any time (see below).
- When an accommodation business stops using the platform, its account data and remaining guest conversations are deleted within 90 days of termination, except records we must keep to comply with a legal obligation.
- When accommodation staff delete a conversation in the dashboard, that action constitutes the business’s instruction to us to delete the data, and the contact record and message history are removed immediately and irreversibly.
Your rights
Depending on your location — including under the EU GDPR and Japan’s Act on the Protection of Personal Information (APPI) — you may have the right to access, correct, export or delete your personal data, and to object to or restrict its processing. To exercise any of these rights, contact us and we will respond within a reasonable time; see our Data Deletion page for the deletion process. Business administrators who connected a WhatsApp Business account through Meta’s Embedded Signup can ask us to update or change the Facebook account (Facebook ID) associated with the connection by emailing info@giorgioprofili.com. If you are in the EU you may also lodge a complaint with the Italian supervisory authority (Garante per la protezione dei dati personali).
Security
Access to the dashboard is restricted and authenticated. Data in transit is encrypted (HTTPS), and stored data is protected by our providers’ security controls.
Changes to this policy
We may update this policy from time to time. The “last updated” date above reflects the latest version.
Contact
For any privacy question or request, email us at info@giorgioprofili.com.