LEGAL

Privacy Policy

How we handle personal data for our own website and business contacts, and how we handle guest data on behalf of our customers.

Last updated: [TO CONFIRM: last updated date]

1. Who we are

This policy is issued by Your Brand Travel International AB, a company registered in Sweden with company registration number 559391-1018, based in Stockholm, Sweden.

Xbrandify and direct.guide are brands operated by Your Brand Travel International AB. In this policy, "we", "us" and "Xbrandify" refer to Your Brand Travel International AB.

Registered address: [TO CONFIRM: registered address].

2. Scope of this policy

This policy covers personal data we process in connection with our website, our sales and marketing activities, our business relationships, and the operation of our product.

Our product is an AI-powered visual guest experience and concierge layer sold B2B to hotels, travel companies and brands. Where guest interactions take place inside a customer's own deployment of the product, that customer's own privacy notice governs the relationship with the guest, and this policy describes only our role as a service provider.

3. Our role under GDPR

Under the EU General Data Protection Regulation, the role we hold depends on whose data is being processed and why.

We act as data controller for personal data relating to our own website visitors, prospects and business contacts. We decide why and how that data is processed.

We act as data processor for end-guest data processed on behalf of our customers. In that case the hotel or travel company is the data controller for the guest data, decides the purposes of the processing, and instructs us through a written agreement. We process such data only on those documented instructions.

4. What personal data we collect and why

Website visitors. We process technical and usage information generated when you visit our website, so that we can deliver, secure and improve it. See section 11 on cookies.

Prospects and business contacts. When you contact us or request a demo, we process the details you submit, which include your name, work email address, company and any message or context you choose to give us, together with your role or segment where you tell us. We use this to respond to you, arrange and run demos, manage our customer and prospect relationships, and send business communications about our product.

Customer users. For people who access the product on behalf of a customer, we process account and access information needed to provide, secure and support the service.

Guest interactions handled on behalf of customers. Where a hotel, travel company or brand deploys the product, guest interactions such as messages and requests, and any data the customer makes available to the service, are processed by us as processor for the purpose of providing the service to that customer. The categories of data and the purposes are determined by the customer as controller and set out in the agreement between us.

Detailed data categories per processing activity: [TO CONFIRM: detailed data inventory].

6. Google user data

Where a customer or Xbrandify connects a Google account to the application, the application requests the following restricted scopes:

  • gmail.modify is used to read and organise messages in the connected mailbox so that the application can understand incoming guest and customer enquiries and keep the mailbox state accurate, for example by updating labels or read status on messages it has handled.
  • gmail.send is used to send replies and messages from the connected mailbox on behalf of the account holder, so that responses to enquiries come from the account holder's own address.

Xbrandify's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, data received from Google APIs is not sold, is not used for advertising purposes, and is not read by humans, except with the explicit consent of the user, for security purposes such as investigating abuse, to comply with applicable law, or where the data is aggregated and anonymised.

7. Subprocessors

We use a limited number of service providers to help us operate the product and our business. Where they process personal data on our behalf, they act as subprocessors, are bound by written agreements, and may only process data on our instructions.

[TO CONFIRM: full subprocessor list]

SubprocessorPurposeLocation
[TO CONFIRM: subprocessor name][TO CONFIRM: purpose][TO CONFIRM: location]
[TO CONFIRM: subprocessor name][TO CONFIRM: purpose][TO CONFIRM: location]

8. International transfers

Where personal data is transferred outside the European Economic Area, we put in place an appropriate transfer mechanism under Chapter V of the GDPR, such as an adequacy decision or the European Commission's Standard Contractual Clauses, together with any additional measures required in the circumstances.

Transfer destinations and mechanisms in place per provider: [TO CONFIRM: transfer destinations and safeguards].

9. Retention

We keep personal data only for as long as we need it for the purposes described in this policy, and then delete or anonymise it, unless a longer period is required by law.

[TO CONFIRM: retention periods]

Where we act as processor, retention and deletion of guest data follow the customer's instructions and the agreement between us.

10. Your rights

Subject to the conditions in the GDPR, you have the right to request access to your personal data, to have inaccurate data corrected, to have data erased, to restrict processing, to data portability, to object to processing based on legitimate interests, and to withdraw consent where processing is based on consent.

To exercise these rights in relation to data where we act as controller, contact us using the details in section 12. If your request concerns guest data processed on behalf of a hotel or travel company, please contact that organisation as the controller. If we receive such a request directly, we will forward it to the relevant customer.

You also have the right to lodge a complaint with a supervisory authority. In Sweden the supervisory authority is Integritetsskyddsmyndigheten (IMY).

11. Cookies

Our website uses cookies and similar technologies that are necessary to deliver and secure the site, and, where we ask for your consent, cookies used for analytics or similar purposes. You can control cookies through your browser settings and, where a consent mechanism is presented, through that mechanism.

Cookies currently set on this website: [TO CONFIRM: cookie inventory].

12. How to contact us

For any question about this policy or about how we handle personal data, contact Your Brand Travel International AB, Stockholm, Sweden.

Privacy contact: [TO CONFIRM: privacy contact email]

Data protection officer, if appointed: [TO CONFIRM: DPO details]

13. Changes to this policy

We may update this policy as our product, our processing activities or applicable law change. When we do, we will revise the "Last updated" date at the top of this page. Where a change is significant, we will take reasonable steps to inform affected individuals or customers.