Privacy Policy
How we handle personal data for our own website and business contacts, and how we handle guest data on behalf of our customers.
1. Who we are
This policy is issued by Your Brand Travel International AB, a company registered in Sweden with company registration number 559391-1018, based in Stockholm, Sweden.
Xbrandify and direct.guide are brands operated by Your Brand Travel International AB. In this policy, "we", "us" and "Xbrandify" refer to Your Brand Travel International AB.
Registered address: [TO CONFIRM: registered address].
2. Scope of this policy
This policy covers personal data we process in connection with our website, our sales and marketing activities, our business relationships, and the operation of our product.
Our product is an AI-powered visual guest experience and concierge layer sold B2B to hotels, travel companies and brands. Where guest interactions take place inside a customer's own deployment of the product, that customer's own privacy notice governs the relationship with the guest, and this policy describes only our role as a service provider.
3. Our role under GDPR
Under the EU General Data Protection Regulation, the role we hold depends on whose data is being processed and why.
We act as data controller for personal data relating to our own website visitors, prospects and business contacts. We decide why and how that data is processed.
We act as data processor for end-guest data processed on behalf of our customers. In that case the hotel or travel company is the data controller for the guest data, decides the purposes of the processing, and instructs us through a written agreement. We process such data only on those documented instructions.
4. What personal data we collect and why
Website visitors. We process technical and usage information generated when you visit our website, so that we can deliver, secure and improve it. See section 11 on cookies.
Prospects and business contacts. When you contact us or request a demo, we process the details you submit, which include your name, work email address, company and any message or context you choose to give us, together with your role or segment where you tell us. We use this to respond to you, arrange and run demos, manage our customer and prospect relationships, and send business communications about our product.
Customer users. For people who access the product on behalf of a customer, we process account and access information needed to provide, secure and support the service.
Guest interactions handled on behalf of customers. Where a hotel, travel company or brand deploys the product, guest interactions such as messages and requests, and any data the customer makes available to the service, are processed by us as processor for the purpose of providing the service to that customer. The categories of data and the purposes are determined by the customer as controller and set out in the agreement between us.
Detailed data categories per processing activity: [TO CONFIRM: detailed data inventory].
5. Legal bases under Article 6
Where we act as controller, we rely on the following legal bases:
- Contract (Article 6(1)(b)): to enter into and perform an agreement with you or the organisation you represent, including providing accounts and support.
- Legitimate interests (Article 6(1)(f)): to respond to enquiries, run and follow up on demos, manage and develop our business relationships, secure our website and services, and communicate with business contacts about our product. You can object to processing based on legitimate interests, as described in section 10.
- Consent (Article 6(1)(a)): where we ask for it, for example for certain cookies or where consent is required for specific communications. You can withdraw consent at any time.
- Legal obligation (Article 6(1)(c)): where we must process data to comply with applicable law, including accounting and tax obligations.
Where we act as processor, the legal basis for the processing is determined by our customer as controller.
6. Google user data
Where a customer or Xbrandify connects a Google account to the application, the application requests the following restricted scopes:
gmail.modifyis used to read and organise messages in the connected mailbox so that the application can understand incoming guest and customer enquiries and keep the mailbox state accurate, for example by updating labels or read status on messages it has handled.gmail.sendis used to send replies and messages from the connected mailbox on behalf of the account holder, so that responses to enquiries come from the account holder's own address.
Xbrandify's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, data received from Google APIs is not sold, is not used for advertising purposes, and is not read by humans, except with the explicit consent of the user, for security purposes such as investigating abuse, to comply with applicable law, or where the data is aggregated and anonymised.
7. Subprocessors
We use a limited number of service providers to help us operate the product and our business. Where they process personal data on our behalf, they act as subprocessors, are bound by written agreements, and may only process data on our instructions.
[TO CONFIRM: full subprocessor list]
| Subprocessor | Purpose | Location |
|---|---|---|
| [TO CONFIRM: subprocessor name] | [TO CONFIRM: purpose] | [TO CONFIRM: location] |
| [TO CONFIRM: subprocessor name] | [TO CONFIRM: purpose] | [TO CONFIRM: location] |
8. International transfers
Where personal data is transferred outside the European Economic Area, we put in place an appropriate transfer mechanism under Chapter V of the GDPR, such as an adequacy decision or the European Commission's Standard Contractual Clauses, together with any additional measures required in the circumstances.
Transfer destinations and mechanisms in place per provider: [TO CONFIRM: transfer destinations and safeguards].
9. Retention
We keep personal data only for as long as we need it for the purposes described in this policy, and then delete or anonymise it, unless a longer period is required by law.
[TO CONFIRM: retention periods]
Where we act as processor, retention and deletion of guest data follow the customer's instructions and the agreement between us.
10. Your rights
Subject to the conditions in the GDPR, you have the right to request access to your personal data, to have inaccurate data corrected, to have data erased, to restrict processing, to data portability, to object to processing based on legitimate interests, and to withdraw consent where processing is based on consent.
To exercise these rights in relation to data where we act as controller, contact us using the details in section 12. If your request concerns guest data processed on behalf of a hotel or travel company, please contact that organisation as the controller. If we receive such a request directly, we will forward it to the relevant customer.
You also have the right to lodge a complaint with a supervisory authority. In Sweden the supervisory authority is Integritetsskyddsmyndigheten (IMY).
12. How to contact us
For any question about this policy or about how we handle personal data, contact Your Brand Travel International AB, Stockholm, Sweden.
Privacy contact: [TO CONFIRM: privacy contact email]
Data protection officer, if appointed: [TO CONFIRM: DPO details]
13. Changes to this policy
We may update this policy as our product, our processing activities or applicable law change. When we do, we will revise the "Last updated" date at the top of this page. Where a change is significant, we will take reasonable steps to inform affected individuals or customers.