Legal document

Privacy Policy

This policy explains how we collect, use, and protect personal data when you visit conciergeai.es or use the ConciergeAI service.

Last updated 23 June 2026
Version 1.0
Governing law The Netherlands · GDPR

We take your privacy seriously. This Privacy Policy describes how Rayco Sales — operating under the trading name Synaptim Labs — collects, uses, and protects personal data in connection with the ConciergeAI service and the website at conciergeai.es.

If you are a hotel guest communicating with one of our hotel customers through ConciergeAI, please note that the hotel acts as the data controller for that conversation. Please contact the hotel directly to exercise your rights regarding that processing.

01Data controller

For the purposes of the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the controller of personal data processed in connection with the Website and the ConciergeAI service (where we act as controller) is:

In these Terms we refer to ourselves as "Synaptim Labs", "we", "us", or "our".

02When this policy applies

This Privacy Policy applies in two scenarios:

  • When you visit conciergeai.es — for example, to read about the product, browse pricing, or send an email enquiry.
  • When you use ConciergeAI as a hotel customer — meaning you are an employee or representative of a hotel that has contracted ConciergeAI and you access our platform.
If you are a hotel guest communicating with a hotel through ConciergeAI, the data controller is the hotel itself, not Synaptim Labs. In that case, Synaptim Labs acts as a data processor on behalf of the hotel under a separate Data Processing Agreement. To exercise your privacy rights, please contact the hotel directly.

03Personal data we process

3.1 Website visits and communication

When you visit conciergeai.es or contact us by email (for example, hola@conciergeai.es), we may process the following:

  • Technical data: IP address, browser type, operating system, device type, language, time zone.
  • Usage data: pages visited, time spent, links clicked, scroll depth.
  • Communication data: the content of your email and any information you choose to share (name, company, role).

Purpose

To operate the Website, ensure its security, understand how visitors use it, and respond to your enquiries.

Legal basis

Our legitimate interest (Article 6(1)(f) GDPR) in operating the Website and responding to enquiries; steps prior to entering a contract (Article 6(1)(b) GDPR) where you contact us as a prospective customer; your consent (Article 6(1)(a) GDPR) for analytics cookies, collected through our cookie banner.

3.2 Analytics

We use Google Analytics 4 ("GA4"), a service provided by Google Ireland Limited, to understand how visitors use the Website and to improve it. We have configured GA4 with the following privacy-protective measures:

  • IP address anonymisation enabled;
  • Data not used for advertising personalisation;
  • Retention period set to the minimum allowed by the service.

GA4 cookies are only set after you consent through our cookie banner. You can withdraw your consent at any time through the cookie settings link in the footer.

3.3 Customer subscriptions

When a hotel becomes a customer of ConciergeAI, we process administrative data of the contact person (name, role, business email, business phone, signature on the agreement) and billing data (company name, billing address, VAT number, payment details).

Purpose

To manage the contract, issue invoices, comply with accounting and tax obligations, and communicate with the customer about the Services.

Legal basis

Performance of the contract (Article 6(1)(b) GDPR) and compliance with our legal obligations such as Dutch tax law (Article 6(1)(c) GDPR).

3.4 Product usage data

When employees of a hotel customer log in to the ConciergeAI dashboard, we collect information about how the product is used: features accessed, actions performed, time of access, and basic technical data of the session.

Purpose

To operate the service, ensure security, troubleshoot issues, and improve the product.

Legal basis

Performance of the contract (Article 6(1)(b) GDPR) and our legitimate interest (Article 6(1)(f) GDPR) in maintaining and improving the Services.

3.5 Email inbox integration

ConciergeAI can connect to the email inbox of a hotel customer to read incoming messages from guests, generate AI-drafted replies, and (when the hotel approves) send replies on behalf of the hotel. In that case:

  • We access only the inboxes and folders explicitly authorised by the hotel.
  • We process the content of emails strictly to provide the Services (reading, drafting, classification, summarisation).
  • We do not use the content of guest emails to train AI models or for any purpose other than the agreed Services.
  • The hotel acts as data controller for the personal data of its guests. Synaptim Labs acts as data processor under the Data Processing Agreement signed with each hotel.
If you are a guest who has communicated with a hotel via email and the hotel uses ConciergeAI to manage that communication, the hotel is responsible for the processing of your personal data. Please contact the hotel directly to exercise your rights.

04Sharing your personal data

We do not sell your personal data. We share personal data only when necessary to provide the Services, comply with the law, or protect our rights, and only with the following categories of recipients:

  • Service providers (subprocessors): cloud hosting, AI model providers, messaging infrastructure, analytics, and email infrastructure. These providers act as processors on our behalf and are bound by data processing agreements. A current list of subprocessors is provided to hotel customers in the Data Processing Agreement and updated on reasonable notice when subprocessors change.
  • Hotel customers: if you are a guest, the relevant hotel — as data controller — has access to your communications and personal data processed through the Services.
  • Public authorities: where required by law, court order, or to protect rights, property, or safety.
  • Professional advisors: lawyers, accountants, or auditors, where strictly necessary and under confidentiality obligations.

We do not share personal data with third parties for their own marketing purposes.

05International transfers

Synaptim Labs is based in the European Union. We store personal data primarily on servers located within the European Economic Area (EEA).

Some of our subprocessors (for example, providers of AI models or analytics services) may process personal data outside the EEA. When this happens, we rely on the legal safeguards required by the GDPR:

  • Adequacy decisions adopted by the European Commission (such as the EU-US Data Privacy Framework, where applicable);
  • Standard Contractual Clauses (SCCs) approved by the European Commission;
  • Additional technical and organisational measures where appropriate.

06Retention and security

6.1 Retention periods

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, applying the following criteria:

  • Technical and analytics data: aligned with the GA4 retention period (currently 14 months), after which the data is automatically deleted.
  • Communication data (emails to us): for the duration of our relationship and, after that, for the period required by applicable legal obligations.
  • Customer subscription data: for the duration of the contract and up to seven (7) years afterwards, as required by Dutch tax law.
  • Product usage data: for the duration of the customer relationship and a reasonable period afterwards for security, audit, and improvement purposes.
  • Email inbox content: retained according to the configuration agreed with each hotel customer in the Data Processing Agreement. We do not keep guest email content beyond what is necessary to provide the Services.
  • Cookie consent records: up to 12 months from the last interaction.

6.2 Security measures

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include encryption of data in transit (HTTPS), access controls, logging, and periodic security reviews. While we take security seriously, no method of transmission or storage is 100% secure.

07Your privacy rights

Under the GDPR, you have the following rights:

  • Access: request a copy of the personal data we hold about you.
  • Rectification: request correction of inaccurate or incomplete data.
  • Erasure: request deletion of your personal data, where applicable.
  • Restriction: request that we limit the processing of your data.
  • Objection: object to processing based on our legitimate interest.
  • Portability: receive your data in a structured, commonly used, machine-readable format.
  • Withdraw consent: at any time, where processing is based on consent.
  • Lodge a complaint: with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl) or with the supervisory authority of your country of residence.

To exercise any of these rights, please contact us at hola@conciergeai.es We will respond within one month of receiving your request. We may need to verify your identity before responding.

If you are a hotel guest: to exercise your rights regarding communications with a hotel, please contact the hotel directly, as the hotel is the data controller for that processing.

08Updates and contact

8.1 Updates to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, our service, or applicable law. The "Last updated" date at the top of this document indicates when the policy was last revised. Significant changes will be communicated through a visible notice on the Website.

8.2 Contact

For any questions, requests, or complaints regarding this Privacy Policy: