avvicenda

Política de privacidad

La versión jurídica completa disponible actualmente está redactada en inglés. Para cualquier consulta escribe a hello@avvicenda.eu.

This policy explains how personal data is processed on avvicenda.eu, for pilot applications and, where already used, in the avvicenda™ application. Version: October 2026.

1. Controller

Fabrice Mack Hernandez, trading under the business names MH Group and avvicenda™, Hohlenmatten 6, 79379 Müllheim, Germany. Email: hello@avvicenda.eu.

For data a hotel enters into the application, the relevant hotel is generally the controller and avvicenda™ acts as processor under a separate Article 28 GDPR data processing agreement. The provider above is controller for the website, applications, contract administration and account administration.

2. Website access and hosting

The website is hosted by Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus, in an EU data centre. A visit technically requires processing of the IP address, time, requested URL, referrer, browser, operating system and transfer status.

The purpose is secure and reliable delivery and defence against attacks. The legal basis is our legitimate interest under Article 6(1)(f) GDPR. Logs are normally retained for no more than 30 days and longer only where required for a security incident or legal duty.

3. Pilot applications and contact

When the form is submitted, we process first name, email address and hotel name plus optional details about country, team size, shifts, current tools and the message. Required fields are marked and the data comes directly from the applicant.

We process this data to review the application, make contact and prepare a possible B2B contract under Article 6(1)(b) GDPR. General enquiries are also processed under our legitimate interest in answering business communications, Article 6(1)(f) GDPR.

We use Formspree, Inc., USA, to transmit the form. Where data is transferred to the USA, Formspree relies on EU Standard Contractual Clauses. See https://formspree.io/legal/privacy-policy/.

If no cooperation results, application data is deleted no later than six months after the selection process, unless a legal duty or specific legal claim requires longer retention.

4. Audience measurement with Plausible

We use Plausible Analytics by Plausible Insights OÜ, Estonia, for aggregate audience measurement. Its script is loaded from plausible.io. Plausible uses no cookies or persistent identifiers and does not store raw IP addresses or user agents. It hashes them with a daily rotating salt to count visits, and processes visitor analytics in the EU.

The legal basis is our legitimate interest under Article 6(1)(f) GDPR in understanding content use without creating cross-person or cross-device profiles. No advertising profiles are created. See https://plausible.io/data-policy.

5. Account and product use

Depending on the subscribed functions, registration and use may involve name, business email, role, language, hotel and organisation data, login and security events, plus content submitted by the hotel. This may include handovers, tasks, messages, knowledge, attachments, room or event references and voice recordings.

AI functions assist with transcription, categorisation, translation, summaries and suggestions. The application itself does not store voice recordings; how long the transcription service retains them depends on its terms. Avvi assistant histories are deleted automatically after 30 days and may be deleted earlier. For categorisation, summaries and the assistant we use Claude via AWS Bedrock; neither AWS nor the model provider uses these inputs and outputs for training. There are no automated decisions with legal or similarly significant effects under Article 22 GDPR.

Our own account and contract processing relies on Article 6(1)(b) GDPR. For hotel-controlled data, avvicenda™ processes only on documented hotel instructions and under the processing agreement.

6. Recipients and service providers

For the website and applications we use Hostinger (hosting), Formspree (form transmission) and Plausible (aggregate analytics). Depending on the product function, the application may use Supabase (database, authentication and storage), Amazon Web Services Bedrock (AI processing in EU data centres, EU inference profile), Mistral AI (translation), Gladia (transcription) and Resend (transactional email).

Providers receive only data needed for their purpose and, where acting as processors, are bound under Article 28 GDPR. For third-country transfers we use an adequacy decision or appropriate safeguards, particularly EU Standard Contractual Clauses. A copy of relevant safeguards can be requested at hello@avvicenda.eu, subject to redaction of protected business information.

Other recipients may include advisers, authorities or courts where required by law or to establish, exercise or defend legal claims.

7. Retention

Website logs are normally kept for no more than 30 days. Unsuccessful pilot applications are deleted within six months. Contract and account data is held for the contract and then under statutory limitation and retention periods. Invoices and tax records are retained for the legally required period.

Hotel-controlled product content is held for the contract term. Customers generally have 30 days after termination to export data, followed by deletion under the processing agreement and retention policy unless law requires otherwise.

8. Cookies, local fonts and external links

The public website uses no tracking cookies and stores no advertising or analytics identifiers in the browser. The protected application may use strictly necessary session or security cookies; login cannot work without them. Fonts are served locally.

A connection to social networks or other external services is made only when the corresponding link is clicked. The external provider’s privacy policy then applies.

9. Required data

Application and account fields marked as required are needed to process the request or provide the service. Without them, we cannot handle the application or provide the service. Optional fields may be left blank.

10. Data-subject rights

Subject to statutory requirements, individuals have rights of access, rectification, erasure, restriction, portability and objection to processing based on Article 6(1)(e) or (f) GDPR. Consent may be withdrawn for the future at any time.

Requests may be sent to hello@avvicenda.eu. Employees using avvicenda™ should first contact their hotel about hotel-controlled content; we assist the hotel with the request.

11. Complaints and updates

Individuals may complain to a data protection authority, particularly where they live, work or believe an infringement occurred. The authority for the provider currently established in Germany is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg: https://www.baden-wuerttemberg.datenschutz.de/.

We update this policy when services, purposes or legal requirements change. The current version is available at https://avvicenda.eu/privacy.