02 · Privacy
Your data.
Our commitments.
What we collect, why, for how long, and with whom. Without the fine-print silence of standard terms.
Last updated · 5 October 2026
This privacy policy describes how NMB Technologies F.Z.C ("MyKonci", "we") collects, uses and protects your personal data as part of its virtual concierge service for short-term rental owners (WhatsApp/SMS chatbot and voice agent).
01Data controller
The controller of personal data is NMB Technologies F.Z.C.
Representative in the European Union (article 27 of the GDPR): Nicolas Moussa, [email protected].
Data protection contact: Nicolas Moussa, reachable at [email protected] for any question regarding the protection of your personal data and the exercise of your GDPR rights.
02Roles: controller and processor
MyKonci acts in two distinct roles under the GDPR, depending on the type of data being processed:
- MyKonci is controller for its customers' own data (user account, email, billing, usage logs, prospect data) and for data of visitors of the mykonci.com site.
- MyKonci is processor (article 28 of the GDPR) for all final guest data processed via the platform on behalf of the professional or individual customer. In that case, the MyKonci customer is the controller vis-à-vis its guests: it is for the customer to inform them, in line with articles 13 and 14 of the GDPR.
A data processing agreement (DPA) within the meaning of article 28 of the GDPR is signed at subscription and governs the whole processing relationship. It is available on request at [email protected].
03Data collected
We process the following data categories:
- Customer identification data: surname, first name, email address, phone number.
- Professional data: number of apartments, rental type, channel manager used, activity.
- Connection data: IP address, browser, pages visited, timestamp.
- Guest data (processed as processor): surname, first name, phone number, language, stay dates, messages exchanged via WhatsApp and SMS, audio recordings and timestamped transcripts of voice calls.
- Derived analytical data (professional plans with Cortex, processed as processor): satisfaction scores, emotional profiles, extracted signals, behavioural predictions, cross-stay guest history, and free texts produced by the analysis (summaries, quotes taken from messages, preferences, psychological profile). Cortex does not keep the full text of messages. It keeps a copy of the guest's identity in clear text (phone number, first and last name from the booking, language) and, for each registered objection, the phone number in clear text.
- Technical logs: AI model calls, latencies, errors, used to improve the service.
- Other service processing: the dashboard's AI help assistant (customer questions about using the service), the mykonci.com site chat, newsletter sign-up, booking of sales calls, automatic translation of messages exchanged with guests, reading the deposit and reviews already left from the customer's PMS, geocoding of properties and building the neighbourhood guide (nearby shops, transport), and connecting the concierge's WhatsApp Business account (an SMS verification code is received, encrypted, then erased once the connection is established).
Audio recordings and transcripts are accessible to the customer via their dashboard and can be provided or deleted on request at [email protected].
04Processing purposes
- Delivery of the virtual concierge service (WhatsApp/SMS chatbot and voice agent)
- Handling contact and demo requests
- Customer relationship and billing
- Service improvement and usage analysis
- Sending commercial information (with your consent)
- Compliance with our legal obligations
05Cortex: processing specific to professional plans
Professional plans include Cortex, a conversational intelligence engine that analyses conversations between guests and the customer's teams to improve service quality. Cortex analyses SMS and WhatsApp conversations: it receives neither voice calls nor messages from booking platforms. Cortex performs profiling within the meaning of article 4.4 of the GDPR. These specific processing operations are detailed below.
Nature of Cortex processing:
- Real-time emotional analysis (satisfaction score out of 100, frustration detection, etc.)
- Guest psychological profile (assertive, passive, emotional, price-sensitive, etc.)
- Detection and classification of problems by severity (access, equipment, cleanliness, noise, etc.)
- Review prediction (positive, negative, escalation risk, rebooking probability)
- Upsell opportunity detection (late checkout, early check-in, additional services)
- Preventive maintenance (detection of recurring equipment issues)
- Real-time coaching of the customer's teams (action recommendations)
- Cross-stay guest memory (satisfaction history, preferences, past issues)
Legal bases:
- Legitimate interest of the professional customer, as controller (art. 6.1.f GDPR): service quality, security of the properties, customer relationship. It underpins emotional analysis, review predictions, problem detection, preventive maintenance, coaching, cross-stay memory, the psychological profile and upsell detection.
- This legitimate interest is balanced against guest rights and only applied when that balance is respected. The professional customer chooses the legal basis for its processing; MyKonci assists it in this analysis.
Automated decisions within the meaning of article 22 GDPR. Cortex produces recommendations; none of these recommendations, by itself, produces a legal or significant effect on the guest. During the observation phase, Cortex sends no message, neither to guests nor to the customer's team. It can only send a message itself if the owner of the customer's concierge business has enabled the "Let Cortex act" option. The customer can schedule the automatic sending of certain messages (confirmations, reminders, follow-ups): the conversational assistant (chatbot and voice agent) then replies to guests on its own, without prior human validation of each message, unless the customer enables review mode, in which every reply awaits an operator's validation before sending. None of these processes amount to a decision within the meaning of article 22 of the GDPR. The customer remains responsible, within the meaning of the GDPR, for the automations they enable and must provide an opt-out mechanism for the guest.
Right to object to profiling (Art. 21 GDPR). Any guest can object to Cortex profiling. On written request at [email protected] or via the professional customer, the objection is registered by the customer, from their dashboard, for the guest's phone number. It applies as soon as it is registered: later messages are still kept by the platform (legitimately exchanged with the customer's teams) but Cortex ignores them: they are neither analysed, scored nor profiled. The objection does not erase what has already been produced: for that, the guest can request erasure of their data.
No mixing between customers. Analyses specific to one customer are never used to improve the service for another customer. Cortex's log of calls to AI models keeps no message text. No customer data is used to train or fine-tune external AI models (OpenAI or any other provider). Real conversations may be used to check the quality of the chatbot's replies (internal evaluation benchmarks).
06Legal basis
Processing operations are based on:
- Performance of a contract (delivery of the service)
- Your consent (commercial prospecting)
- Our legitimate interest (service improvement, security)
- Compliance with legal obligations
07Retention period
Data is kept for the period strictly necessary for the purposes for which it was collected, in line with CNIL guidance:
- User account data (name, email, profile): for the whole contract duration, then 3 years after the last active-base contact for commercial management (commercial prescription).
- Chatbot conversations (WhatsApp & SMS): for the contract duration, then 24 months beyond for evidence and service improvement, unless early deletion is requested.
- Call audio recordings: for the contract duration, then 6 months beyond, unless early deletion is requested by the customer or the guest concerned.
- Call transcripts: for the contract duration, then 24 months beyond, unless early deletion is requested by the customer or the guest concerned.
- Cortex scores, profiles and derived analyses: 24 months after the last activity of the stay concerned, then automatic erasure. Registered objections (phone number) are kept as long as the customer exists, so that the refusal remains respected. Aggregated figures, which do not identify any guest, are kept as long as the customer exists.
- Cross-stay guest memory: each remembered stay is erased 24 months after its last activity, then the guest record itself once no data about them remains.
- Product-improvement technical logs (pseudonymised): 12 months maximum.
- Billing data and accounting records: 10 years from the closing of the relevant financial year (article L.123-22 of the French Commercial Code).
- Connection and security logs: 12 months (CNIL recommendation and LCEN obligations).
- Prospect data (contact forms without subscription): 3 years from the prospect's last contact.
- Cookies: 6 months for the consent cookie; durations set by Google for analytics cookies (up to 2 years). See the Cookies page for detail.
- Data archived for potential litigation: duration of the applicable legal statute of limitations.
At the end of these periods, data is either permanently deleted or irreversibly anonymised for statistical purposes. The customer can at any time request a shorter retention period via their account settings or by written request.
08Hosting and security
Data is hosted within the European Union, with Hetzner Online GmbH (Germany, Gunzenhausen and Falkenstein sites). Hetzner is a European GDPR-compliant host.
Technical and organisational measures:
- Encryption at rest (AES-256) on databases and storage systems.
- Encryption in transit (TLS 1.3) on all communications (API, dashboard, integrations).
- Centralised key and secret management, annual rotation, logged access.
- Encrypted backups with geographic replication within the EU.
- Strict tenant isolation: every customer has a dedicated identifier; all requests are filtered at the application level. On Cortex's analysis database, row-level security (PostgreSQL Row-Level Security) is also applied: the database itself only lets the rows of the customer concerned be read or written. This additional protection is not applied to the platform's other databases. Within normal operation of the Service, no customer can access another customer's data.
- Data access logs: every access to conversations (customer operator or authorised MyKonci support employee) is logged (identity, date, resource, IP address). These logs are kept for 12 months and are accessible by the administrator customer on request.
Data breach notification (art. 33-34 GDPR): in case of an incident affecting personal data, MyKonci commits to notifying the customer concerned within 48 hours of detection, with a first preliminary report. A full report is provided within 7 days.
09Your rights
Under the GDPR, you have the following rights:
- Right of access to your data
- Right to rectification
- Right to erasure
- Right to restriction of processing
- Right to portability
- Right to object, including to profiling performed by Cortex
- Right to withdraw your consent at any time
Guest access right: any guest can request a full export of their data (messages, recordings, scores, profiles, predictions about them) within 30 days, in JSON format. Written request at [email protected] with proof of identity, or via the professional customer acting as controller.
Routing of guest requests. For guest data, MyKonci acts as processor for the professional or individual customer (controller). Guest requests are in principle addressed to the controller. When a request is received directly by MyKonci, it is handled within GDPR time limits and the controller is informed. MyKonci may, depending on the nature of the request, pass it on to the controller, who remains the final decision-maker.
To exercise these rights, write to our data protection contact at [email protected]. We reply to any request within a maximum of one month (Art. 12 GDPR). You can also lodge a complaint with the CNIL (France) or any competent supervisory authority.
10Sub-processors
To operate our services, we rely on the following sub-processors. The up-to-date list is appended to the DPA provided to each customer.
- Hetzner Online GmbH (Germany, EU). Primary server and data hosting. No transfer outside the EU.
- OpenAI Ireland Ltd / OpenAI, L.L.C. (Ireland / United States). Natural language processing: chatbot, voice agent, message translation, PMS message triage, dashboard help assistant, embeddings, Cortex, internal evaluation benchmarks. DPA signed. For data from the European Economic Area, the DPA provides that transfers made by OpenAI Ireland outside the EEA rely on standard contractual clauses (SCC) or on a European Commission adequacy decision.
- Stripe Payments Europe, Ltd. (Ireland, EU). Customer payment processing. DPA in place.
- Twilio Ireland Limited (Ireland / United States). SMS, WhatsApp Business, voice telephony transport and identity verification (telephony KYC). DPA in place, SCC and DPF.
- Retell AI, Inc. or equivalent (United States). Conversational voice platform for the voice agent (if enabled): temporary hosting of call audio and transcripts. DPA in place, SCC.
- Meta Platforms Ireland Ltd (Ireland / United States). Connection of the concierge's WhatsApp Business account and transport of WhatsApp messages. SCC.
- Cloudflare, Inc. (United States, infrastructure that can be located in the EU). Storage of identity documents (KYC), photos, data exports and PDF invoices, as well as database backups. SCC; a move to EU-jurisdiction storage zones is underway.
- Resend (United States). Sending of production transactional emails. SCC.
- Migadu Mail Services (SA) (Switzerland). Mail relay (MX) and fallback for transactional emails. Switzerland benefits from an adequacy decision from the European Commission (no SCC needed).
- Functional Software, Inc. (Sentry) (United States). Tracking of technical errors and platform performance, without deliberately identifying personal data. SCC.
- Google Ireland Ltd (Ireland / United States). Site audience measurement (Google Analytics, with your consent), booking of sales calls (Google Calendar), and fallback geocoding (Google Maps Places). SCC and DPF.
- Base Adresse Nationale (French State) and OpenStreetMap (France / EU). Geocoding of properties and the neighbourhood guide. Public data, no personal data transmitted, no transfer outside the EU.
Every sub-processor is bound by a data processing agreement (DPA) compliant with article 28 of the GDPR. Any change in the list of sub-processors is subject to prior notice to the customer, with a motivated right to object within 30 days in line with article 28.2 of the GDPR.
11Data transfers outside the EU
MyKonci's primary hosting is located within the European Union. Some data may nonetheless be transferred outside the EU via the sub-processors mentioned above that are established or operate outside the EU (notably OpenAI, Twilio, Retell AI, Meta, Cloudflare, Resend, Sentry, Google). These transfers are framed by:
- The EU-US Data Privacy Framework (DPF) for certified sub-processors;
- The European Commission's Standard Contractual Clauses;
- Additional measures (encryption, pseudonymisation) when necessary.
12End of contract and reversibility
At the end of the contract, the customer can choose (in line with the DPA):
- Full export of their data (JSON format and SQL dump) within 30 days;
- Or permanent deletion within 30 days;
- Purge of backups containing customer data within 90 days maximum.
A deletion certificate can be provided on request.
13Audits (professional customers)
Professional customers can audit MyKonci's GDPR compliance, up to once a year, with 30 days' notice. The audit is performed, at the customer's choice, by standard written questionnaire or by on-site visit / videoconference on motivated request. On-site audit costs are borne by the customer. MyKonci will eventually provide an independent audit report that may be used in place of an individual audit.
14Changes to this policy
This privacy policy may be updated to reflect legal, regulatory, technical or organisational changes. Any substantial change is notified to customers by email and/or via the dashboard at least 30 days before it takes effect. The date of last update is indicated at the top of this page. Previous versions are archived and available on request at [email protected].
15Contact
For any question regarding this privacy policy, write to our data protection contact at [email protected]. For any general question, [email protected].