Legal · Version 3.1.0 · Last updated 2026-07-26
Guest Talk privacy policy
This policy explains how Guest Talk collects, uses, retains and shares personal data across the Guest Talk marketing website, the Guest Talk hospitality SaaS platform, and the operational workflows we use to run our business. It is written to align with the EU General Data Protection Regulation (Regulation 2016/679, "GDPR"), the Estonian Personal Data Protection Act 2019 ("IKS"), the ePrivacy Directive 2002/58/EC and its national transpositions, and the UK Data Protection Act 2018 for visitors resident in the United Kingdom.
1. Who we are
Data controller. The data controller for personal data processed via our marketing website and for enquiries directed to our sales, support and billing teams is Guest Talk OU, a private limited company registered in Estonia under registration number 14892715, with its registered office at Sepapaja tn 6, 15551 Tallinn, Estonia. Our VAT identifier is EE102847391. Our banking partner is LHV Pank; the IBAN we use for European invoices is EE38 7700 7710 0123 4567.
Data processor. Where we operate the Guest Talk hospitality platform on behalf of a hotel, hostel, aparthotel or similar accommodation operator ("Customer"), we act as a data processor for personal data uploaded, entered or generated inside the Customer workspace. The Customer is the controller for the guest, staff and reservation data it manages inside the platform, and our processing is governed by the Guest Talk Data Processing Addendum ("DPA") available at /legal/dpa.
Data protection officer. We have appointed a Data Protection Officer whose responsibilities include maintaining our record of processing activities, coordinating data subject rights requests, running annual training for staff with access to personal data, and acting as the single point of contact for supervisory authorities. You may reach the DPO at dpo@talkg.fabriza.org. The DPO reports to the CEO and, for independence, is not otherwise involved in determining the purposes and means of processing.
Supervisory authority. Our lead supervisory authority under Article 56 GDPR is Andmekaitse Inspektsioon (AKI, aki.ee). If you believe our processing infringes the GDPR, you may lodge a complaint with the supervisory authority in your Member State of habitual residence, place of work, or place of the alleged infringement.
2. Definitions
We use the terms defined in Article 4 GDPR. For readability, the shorthand definitions below apply throughout this policy.
- Personal data means any information relating to an identified or identifiable natural person, including online identifiers, IP addresses, cookie IDs, and pseudonymised data that can be re-associated with an individual.
- Processing means any operation performed on personal data, whether or not by automated means, including collection, recording, structuring, storage, adaptation, retrieval, consultation, disclosure, restriction, erasure and destruction.
- Controller determines the purposes and means of processing; the Processor processes on behalf of the controller.
- Data subject is the identified or identifiable natural person to whom personal data relate.
- Sub-processor is a third party engaged by the processor to carry out specific processing activities on behalf of the controller.
- Transfer means the movement of personal data to a recipient located in a third country outside the European Economic Area, whether by remote access, replication, or physical shipment.
- Personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
3. What data we collect
3.1 Account and identity data. When you or your organisation opens a Guest Talk workspace we collect your full name, work email address, role or job title, mobile telephone number (optional but recommended for security alerts), preferred user interface language and time zone, and a hashed password. If you sign in via a supported single sign-on provider we receive the subject identifier, email and display name asserted by that provider.
3.2 Billing data. For paid subscriptions we collect the invoice recipient name, billing address, VAT number where applicable, purchase order references, and the identifier of the payment method held by our payment sub-processor. We do not store primary account numbers, card verification values, or full bank account numbers on Guest Talk infrastructure; those data are held by Stripe under PCI DSS Service Provider Level 1.
3.3 Usage and telemetry data. We collect operational logs necessary to secure, debug and improve the service. Logs include user identifier, timestamp, workspace identifier, requested API endpoint, response status code, request latency, and truncated IP address. We do not log request or response payloads by default; verbose logging can be enabled on Customer request for a defined support window and is purged automatically within seven days.
3.4 Cookies and similar technologies. The marketing website uses a single strictly-necessary cookie for cross-site request forgery protection on form submissions. The authenticated application uses session cookies, an anti-CSRF cookie, and (optionally) a language preference cookie. See our cookie policy at /legal/cookies for the full table.
3.5 Communications. When you contact our sales, support, billing or security teams we retain a copy of the correspondence, any attachments you send, and metadata such as timestamps and delivery status. Support tickets are stored in our support tool (see sub-processors below) and are accessible only to authorised Guest Talk staff.
3.6 Guest data uploaded by the Customer. Inside the Customer workspace, the Customer may upload or generate personal data about its guests, staff, prospects, and third-party contacts. Typical categories include guest name, email, telephone, booking reference, arrival and departure dates, room preferences, invoice recipient details, message history, and (where applicable and enabled by the Customer) travel document identifiers required by national police-registration laws. Guest Talk processes these data only as a processor on documented instructions from the Customer.
3.7 Aggregate and anonymised metrics. We generate aggregate statistics from usage data (for example, weekly active user counts across the fleet, API latency percentiles, cache hit rates). These metrics are engineered so that no individual user or property can be identified.
4. Lawful bases for processing
We process personal data on the following lawful bases under Article 6(1) GDPR:
- Contract (Art. 6(1)(b)): account and identity data, billing data, and the operational processing of workspace data are necessary to perform the Master Subscription Agreement between the Customer and Guest Talk.
- Legitimate interest (Art. 6(1)(f)): service security telemetry, fraud prevention, network monitoring, aggregate analytics, response to abuse reports, and unsolicited business-to-business communications relating to material product updates or security disclosures.
- Consent (Art. 6(1)(a)): newsletter subscriptions, optional marketing emails, cookies that are not strictly necessary (there are none on the marketing website at present), and specific customer-referenceable case studies.
- Legal obligation (Art. 6(1)(c)): retention of financial records under the Estonian Accounting Act, disclosure to competent authorities on receipt of a valid legal order, and compliance with the Digital Services Act and other applicable EU regulations.
5. Purposes of processing
We use personal data to (i) provide, secure and improve the Guest Talk platform and marketing website; (ii) authenticate users, protect against unauthorised access and defeat automated abuse; (iii) invoice Customers, process refunds and collect on overdue accounts; (iv) respond to sales enquiries, support tickets, security disclosures and data subject rights requests; (v) send transactional emails such as invoice notifications, security alerts and product incident reports; (vi) analyse product usage in aggregate to prioritise engineering investments; (vii) comply with statutory obligations including tax, accounting and law-enforcement requests; and (viii) defend legal claims.
6. Retention schedule
We retain personal data only for as long as necessary for the purposes for which they were collected. The table below summarises our default retention periods.
- Account records — for the duration of the subscription plus 90 days for orderly deletion of the workspace and up to 6 months in encrypted cold backups.
- Billing and tax records — 7 years from the end of the financial year, as required by the Estonian Accounting Act.
- Operational logs — 30 days rolling in hot storage; aggregated (no user identifiers) beyond that.
- Security audit trails — 12 months (extended to 24 months for records that support open incident investigations).
- Support tickets — 24 months from the last message on the ticket.
- Sales correspondence — up to 24 months from the last meaningful contact.
- Newsletter subscriptions — until the subscriber unsubscribes or bounces persistently, plus a 30-day suppression list to prevent re-subscription in error.
- Customer workspace guest data — governed by the Customer as controller; on termination of the subscription Guest Talk retains the workspace for 30 days to allow orderly extraction and then permanently deletes it, subject to backup rotation cycles that fully overwrite within 90 days.
- Job applications — 6 months from the closing of the vacancy (12 months with explicit applicant consent for future openings).
7. Sub-processors
Guest Talk engages a small number of specialist sub-processors to operate the platform. Each sub-processor is contracted under GDPR-compliant terms mirroring the obligations imposed on Guest Talk under our DPA. We maintain a public list at this URL and notify Customers of intended additions with at least 30 days' notice.
- Amazon Web Services EMEA SARL — primary hosting in the eu-central-1 (Frankfurt) region. Location: Luxembourg. Role: infrastructure and managed services (EC2, RDS, S3, KMS).
- Cloudflare, Inc. — content delivery network and DDoS mitigation. Location: United States (EU data-flow via SCC-covered service, Enterprise plan with EU data localisation for edge cache).
- Stripe Payments Europe, Ltd. — payment processing for card and SEPA collections. Location: Ireland.
- Postmark (ActiveCampaign LLC) — transactional email delivery. Location: United States, EU delivery infrastructure.
- Zendesk International Ltd. — customer support ticketing. Location: Ireland.
- Fathom Analytics — cookieless, privacy-first website analytics. Location: Canada (adequacy decision).
- Twilio Ireland Ltd. — SMS notifications and voice fallback for two-factor authentication. Location: Ireland.
- Meta Platforms Ireland Ltd. — WhatsApp Business API for opted-in guest messaging. Location: Ireland.
- HubSpot Ireland Ltd. — marketing contact database and outbound sales workflows (marketing lists only; no product usage data). Location: Ireland.
- Datadog EMEA SAS — application performance monitoring and real user monitoring. Location: France.
- Loggly (SolarWinds Ireland Ltd.) — centralised log aggregation. Location: Ireland.
- Sentry (Functional Software Ireland Ltd.) — error tracking and release health. Location: Ireland.
Sub-processors are subject to independent security assessments at onboarding and re-assessed annually. Our Vendor Risk Management standard requires ISO 27001, SOC 2 Type II or an equivalent independent attestation for any provider with access to personal data.
8. International transfers
The majority of processing takes place in the European Union. Where a sub-processor is located outside the EEA or transfers data outside the EEA, we rely on one or more of the following safeguards: (a) an adequacy decision of the European Commission, (b) the Standard Contractual Clauses adopted by the European Commission in Decision 2021/914 (Module 2, controller-to-processor, and Module 3, processor-to-processor as applicable), (c) supplementary technical and organisational measures identified through a Transfer Impact Assessment, or (d) explicit consent for a specific transfer where no other basis is available. Copies of SCCs and the applicable TIAs are available on request from the DPO.
9. Your rights as a data subject
Where Guest Talk acts as controller you may exercise the following rights, subject to the conditions and exceptions in Chapter III GDPR. Where Guest Talk acts as processor for a Customer, please direct your request to the Customer; we will support the Customer in responding under Article 28(3)(e) GDPR.
- Right of access (Art. 15) — obtain confirmation as to whether we process personal data concerning you and, if so, a copy of the data and the information listed in Art. 15(1).
- Right to rectification (Art. 16) — have inaccurate personal data corrected without undue delay.
- Right to erasure (Art. 17) — have your data erased where one of the grounds in Art. 17(1) applies.
- Right to restriction (Art. 18) — restrict processing where accuracy is contested, processing is unlawful and you oppose erasure, or you have objected under Art. 21.
- Right to portability (Art. 20) — receive data you have provided to us in a structured, commonly used, machine-readable format and transmit it to another controller.
- Right to object (Art. 21) — object to processing based on legitimate interest, including profiling; we will stop unless we demonstrate compelling legitimate grounds that override your interests.
- Right to withdraw consent (Art. 7(3)) — where processing is based on consent, withdraw it at any time without affecting the lawfulness of processing based on consent before its withdrawal.
- Right to lodge a complaint (Art. 77) — with our lead supervisory authority (Andmekaitse Inspektsioon (AKI, aki.ee)) or your local supervisory authority.
To exercise any right, contact dpo@talkg.fabriza.org. We may request additional information to confirm your identity where reasonable. We aim to respond within one month; we may extend this by up to two additional months for complex or numerous requests, in which case we will notify you within the first month.
10. Automated decision-making
Guest Talk does not use personal data for automated decision-making, including profiling, that produces legal effects or significantly affects data subjects. Fraud-scoring on payment attempts is performed by our payment processor, Stripe; contested decisions may be appealed via the Stripe Radar review flow.
11. Cookies
Cookies are documented in a dedicated policy at /legal/cookies. In short: the marketing site uses one strictly-necessary session cookie for CSRF protection; the authenticated application uses session and preference cookies (all first-party). We do not deploy third-party advertising cookies or cross-site trackers.
12. Children
Guest Talk is a business-to-business service and is not directed at children. The platform is not intended for use by anyone under sixteen. We do not knowingly collect personal data from children through our marketing website. If you believe a child has provided data to us, contact the DPO and we will delete the records promptly.
13. Security measures
We maintain administrative, technical and physical safeguards designed to protect personal data against unauthorised or unlawful processing, accidental loss, destruction or damage. Measures include AES-256 encryption at rest for all databases and object storage; TLS 1.3 in transit with modern cipher suites; multi-factor authentication enforced for all Guest Talk staff and available to all customer users; role-based access control aligned with the principle of least privilege; quarterly access reviews; segregation of production and non-production environments; annual penetration testing conducted by an independent CREST-accredited firm; continuous vulnerability scanning; a documented incident response process with tabletop exercises twice a year; and a business continuity plan tested at least annually. Our engineering practices align with ISO/IEC 27001 controls and SOC 2 Trust Services Criteria for Security and Availability.
14. Personal data breach notification
Where a personal data breach is likely to result in a risk to the rights and freedoms of natural persons, we will notify the competent supervisory authority within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR. Where a breach is likely to result in a high risk, we will additionally notify affected data subjects without undue delay, per Article 34. As a processor we notify Customers within 24 hours of confirmed awareness under our DPA.
15. Changes to this policy
We may update this policy from time to time. Material changes will be announced by email to workspace administrators at least 30 days before they take effect; the "Last updated" date at the top will always reflect the current version. A change log is kept below.
- v3.1.0 (2026-07-26) — expanded sub-processor list; clarified retention schedule; added detailed transfer safeguards; updated DPO contact information.
- v3.0.0 (2026-01-15) — full rewrite to align with the EU Data Act and updated Estonian data protection guidance.
- v2.2.0 (2025-06-01) — added Meta WhatsApp Business API sub-processor; expanded automated decision-making disclosure.
16. Contact
For any question about this policy, to exercise a data subject right, or to report a security concern, contact:
- Data Protection Officer — dpo@talkg.fabriza.org
- Legal team — legal@talkg.fabriza.org
- Security disclosures — security@talkg.fabriza.org
- Postal — Guest Talk OU, Sepapaja tn 6, 15551 Tallinn, Estonia