Privacy notice
Last updated: 17 September 2026
This notice explains how StayMeld handles personal data through this website and while providing hotel guest-messaging services connected to Meta products such as Instagram, Messenger and WhatsApp.
1. Who we are
StayMeld is the operator of this website and service. The full registered name, registered address and company registration details will be inserted before launch. Privacy questions and requests can be sent to hello@staymeld.com.
2. Our data-protection roles
StayMeld generally acts as a controller for website enquiries, prospective-customer contacts, security and its own business administration. When a hotel uses StayMeld to handle guest conversations, the hotel generally acts as controller and StayMeld acts as its processor under a data processing agreement. The exact role depends on the processing activity.
3. Data we process
- Contact and enquiry data, such as name, work email, hotel, website, country, preferred contact method and message.
- Hotel and integration data, including connected Meta business identifiers, configuration, permissions and access credentials or tokens.
- Guest conversation data, including messages, channel identifiers, profile information made available by the channel, timestamps and conversation status.
- Hotel knowledge and booking-related information supplied by the hotel or returned by connected systems.
- Technical and security data, such as IP address, device/browser information, logs and diagnostic events.
- Language preference stored in a functional cookie when a visitor selects a language.
4. Why we process data
Depending on the context, processing is based on steps requested before a contract, performance of a contract, legitimate interests, compliance with law, or the hotel’s documented instructions. Consent is used where applicable law specifically requires it.
- To respond to enquiries and arrange demonstrations.
- To connect and operate hotel messaging channels and provide requested chatbot functionality.
- To route conversations to hotel staff and support booking-related requests.
- To secure, troubleshoot and improve the reliability of the service.
- To comply with legal obligations and establish or defend legal claims.
5. Where data comes from
We receive data directly from website visitors and hotel representatives, from hotels that configure the service, from guests who contact a hotel through a connected channel, and from Meta or other systems the hotel chooses to connect.
6. Recipients and subprocessors
Data may be shared only as needed with the relevant hotel, Meta companies, cloud hosting and database providers, communications and support providers, logging/security providers, and AI or language-model providers used to generate responses. A verified subprocessor list, including provider locations and purposes, must be published or made available before production use.
We do not sell personal data. Guest conversations will not be used to train StayMeld or third-party general-purpose models unless this has been separately agreed, transparently disclosed and is legally permitted.
7. International transfers
Some providers may process data outside Serbia, the EEA or the guest’s country. Where required, transfers will use an adequacy decision, standard contractual clauses or another legally recognised safeguard. The actual transfer mechanism must match the final provider list.
8. Retention
We keep personal data only for as long as needed for the relevant purpose, contractual commitments, security and legal obligations. Before launch, the production policy must specify and implement verified periods for sales enquiries, conversation content, integration credentials, technical logs and backups. On termination, processor data is returned or deleted as agreed with the hotel, subject to legal retention requirements.
9. Your rights
Depending on applicable law, individuals may request access, correction, deletion, restriction, portability or objection, and may withdraw consent where processing relies on consent. Guests should normally contact the hotel first because the hotel controls their conversation data; StayMeld will assist the hotel. A complaint may also be made to the competent data-protection authority.
10. Automated chat and human handoff
StayMeld may generate automated replies using hotel information and connected systems. The service is intended to answer enquiries and support booking journeys, not to make legal or similarly significant decisions about guests. Hotels should provide a route to a human for sensitive, unusual or unresolved requests.
11. Security, cookies and changes
We use technical and organisational safeguards appropriate to the risk, including access controls, tenant separation, protected credential storage and monitoring. No online service is completely secure.
The language cookie is used only to remember the visitor’s choice. If analytics or marketing technologies are introduced, this notice and any consent controls will be updated before they are enabled.
We may update this notice as the service, providers or law changes. Material changes will be identified by a new last-updated date and, where appropriate, an additional notice.