Data controller and contact
Marhala AI Ltd is the data controller for personal data collected via our websites, products and direct communications. The company is registered in England & Wales with company number 17161138 and is registered with the UK Information Commissioner's Office under reference ZC148626.
Our registered office is 128 City Road, London, EC1V 2NX, United Kingdom. For routine commercial enquiries please email [email protected]; for privacy, data protection or subject access matters addressed to the Data Protection Officer (DPO) or data controller, contact [email protected].
Lawful bases for processing
Under UK GDPR and the Data Protection Act 2018 we process personal information on one or more of the following lawful bases: contractual necessity where we are preparing or delivering an agreement with you; legitimate interests pursued by Marhala AI or a trusted third party where those interests are not overridden by your rights; compliance with a legal or regulatory obligation; and, in limited circumstances, explicit consent that you can withdraw at any time.
Where we rely on legitimate interests we conduct an internal balancing assessment and keep a record of the processing purpose, the interest relied upon and the safeguards applied. A summary of our legitimate interest assessments is available on written request.
Categories of personal data we process
Marhala AI processes a variety of data depending on whether you are a website visitor, a prospective customer, a contracted customer, a staff user of our tenant platform, or an end consumer interacting with a hotel or travel agent site operated on our platform.
- Identity and contact details: name, email address, phone number, postal address, company name, job title and role.
- Website and device data: approximate geolocation, IP address (stored in hashed or truncated form where possible), user-agent string, pages visited, referrer URL, language preference and cookie/device identifiers.
- Enquiry and CRM data: subject lines, message content, lead source (for example WEBSITE_INQUIRY or MANUAL_LEAD), enquiry type, detected lead category such as Wedding enquiry, Private event, Corporate event, Reservations, Room booking or General enquiry, assigned staff member, resolution notes and audit history.
- Product usage and configuration: tenant branding and customization, staff user roles (Superuser, Admin, DPO, Events Manager, Weddings Manager, Sales Director, General Manager, Reception Manager, Reservations Manager, Revenue Analytics, Marketing Manager and Staff), permission grants, login sessions, screen routes, audit logs, API tokens and feature entitlements.
- AI service data: customer chatbot conversations, visitor inquiries routed to LLM providers, WhatsApp Business conversations, automatic transcription, intent detection, confidence score, emotion score, AI-generated summaries and analysis saved into CRM or contacts.
- Payments and billing: billing contact, company details, purchase order references, payment receipts and invoicing information. Financial card data is processed exclusively by our payment processor (Stripe) and never stored directly on Marhala AI systems.
- Documents and marketing assets: uploaded files, document metadata, scheduled social media posts, campaign templates, review responses and uploaded photographs.
How personal data is used
We use personal data to respond to enquiries, arrange product demonstrations, prepare proposals, deliver contracted services including CRM, website hosting, lead processing, AI messaging and reporting, send operational notifications, invoice for services, ensure security of tenant accounts, detect fraud or misuse, maintain audit and compliance records, and improve product performance and reliability.
Where we provide a hosted tenant platform, personal data belonging to end consumers of our hotel and travel-agent customers (for example guests submitting contact forms) is processed strictly in accordance with the agreed customer instructions and under the direction of the customer tenant controller, not as an independent controller. Our customer contracts set out those processing responsibilities, sub-processor lists, retention periods and technical/organisational security measures.
UK GDPR customer rights and how to exercise them
If you are located in the United Kingdom or your data is processed as part of a UK-based service, you have specific rights under UK GDPR including the rights of access, rectification, erasure (the "right to be forgotten"), data portability, restriction of processing, objection to processing and, where processing is based on consent, the right to withdraw that consent without affecting the lawfulness of processing before withdrawal.
Within the Marhala AI tenant platform these rights are supported through built-in data subject request (DSR) tooling: customer staff with the DPO role or appropriate permissions can search customers across CRM, guests, contacts and bookings, generate a structured personal data export for the customer, perform a documented erasure that preserves audit logs in line with UK law, and review an immutable GDPR audit log of every search, export and erasure performed.
To exercise any of these rights directly with Marhala AI as controller, email [email protected] with enough detail to identify your data. We will respond without undue delay and, in any event, within one month of receipt, extendable by a further two months for complex or voluminous requests. We may ask for proof of identity before disclosing any personal information.
If you remain dissatisfied with our handling you have the right to lodge a complaint with the Information Commissioner's Office (ICO) in the United Kingdom.
Leads, enquiries and guest CRM data
When an end visitor submits an enquiry form — whether on a Marhala AI-powered hotel/travel-agent website, via the AI customer chatbot, or through a WhatsApp Business conversation initiated by the concierge — the submission is automatically logged into the tenant CRM, assigned a lead identifier, categorised using keyword and context heuristics (for example Wedding enquiry, Rooms, Events, General enquiry) and assigned to the relevant staff team based on configured routing rules.
Website enquiries are also deduplicated by matching email plus subject/recency windows, in order to prevent duplicate records and route follow-up consistently. A duplicate record may refresh the existing lead while preserving the earlier audit history.
If a tenant has enabled AI lead analysis, the submitted enquiry is sent to a language model provider for automatic summarisation, sentiment detection, next-step recommendation and priority ranking. Enquiry content is processed under the controller's instructions and the relevant sub-processor terms.
AI customer chatbot and WhatsApp concierge
Sites that subscribe to the AI customer chatbot embed a floating launcher widget that connects the visiting web browser to our chatbot APIs. In that setting we process the visitor message, their approximate page context, their conversation identifier and, if provided, their name, email address or telephone number they leave when requesting a call back or follow-up reply.
Conversations that are escalated or detected as high priority (bookings, weddings, private events, complaint handling, etc.) may be saved directly into the tenant CRM alongside staff notes and any AI-generated summary. Chat history and metadata are retained as described in the Retention section below.
Tenants using the WhatsApp Business integration process their customer phone numbers and message content through our platform. The originating WhatsApp number, reply threads, media attachments, auto-reply results, intent detection and escalation events are all captured in the tenant conversation log and linked, where appropriate, to the matching CRM or contact record.
International data transfers and sub-processors
Marhala AI is a UK-based company and we design our services to store primary customer and tenant data inside European Economic Area or United Kingdom infrastructure. Where international data transfers are required to deliver contracted services (for example inference hosted by an LLM provider based outside the EEA/UK, backup storage or CDN endpoints for media assets) we rely on appropriate transfer mechanisms recognised under UK GDPR including UK adequacy decisions, UK International Data Transfer Agreements, Binding Corporate Rules where applicable, and supplementary technical and contractual safeguards.
We maintain an up-to-date sub-processor inventory covering AI inference, cloud hosting, database services, email delivery, payment processing, observability, fraud detection and content delivery networks. A copy is available on written request to the DPO.
Security, encryption and tenant isolation
Marhala AI applies a layered approach to technical and organisational security including encrypted transport (HTTPS/TLS) across all services, authenticated API access with short-lived tokens, role-based access control on staff user accounts, mandatory strong password policies and second-factor authentication at staff login where configured.
Customer databases are separated per workspace tenant (tenant isolation) so that one customer's staff, documents, CRM records and lead enquiries cannot be accessed by another customer workspace. Sensitive personal fields within the CRM and leads system are additionally encrypted at column level with tenant-scoped keys. Cross-tenant leakage is prevented at every layer of the application through explicit tenant scoping on queries, permissions checks and audit logging.
Document uploads and media attachments are validated for file type and size, scanned for malware using industry-standard tooling, and stored with object-level access controls. Known personally identifying information within chatbot conversation metadata and outbound support tickets is deliberately minimised before being forwarded to any third-party systems.
Website analytics, cookies and similar technologies
The public Marhala AI website uses Google Analytics to help measure website traffic, understand page usage and improve the site experience. Google Analytics may collect information such as page views, approximate location, device or browser details and interaction data through a Google tag integration on the website. The current Google Analytics measurement ID used on the site is G-7QFC0EYHL8.
We also use first-party cookies and similar storage technologies for essential functionality including session state, CSRF tokens, temporary feature flags and user interface preferences. Non-essential cookies (analytics or advertising cookies) are only set where the site presents a consent banner and the user has given their consent. You can disable cookies at any time through your browser settings.
Branded email, notifications and marketing
We send transactional and operational email messages using the configured tenant branding, including logo, primary colour and tenant display name, so that emails from our platform appear consistent with the hotel's or travel agent's own stationery. Example transactional messages include new-lead notifications to staff, thank-you confirmation emails to the guest who submitted an enquiry, booking confirmations and automated replies triggered by an out-of-hours schedule.
For any direct commercial marketing from Marhala AI (including newsletters, product updates, event invitations or partner promotions) we will only send marketing communications on an opt-in basis or where we have a legitimate business interest after a genuine commercial discussion, and every marketing email includes an easy one-click unsubscribe or opt-out mechanism.
Retention periods
Marhala AI does not keep personal data for longer than is necessary for the purpose for which it was collected, or for any longer required by law or regulation. The following indicative retention schedule applies unless a longer period is required or authorised by a signed customer agreement or specific law.
- Website enquiries and lead records: retained for a minimum of the active commercial relationship plus six years after the last meaningful contact in order to satisfy commercial, tax and evidentiary retention requirements, or shorter if requested through a valid erasure request.
- Staff user accounts, login sessions and permission audit logs: retained for the duration of the staff member's access plus 12 months after account deactivation, after which non-legal fields are minimised or deleted.
- Customer chatbot and WhatsApp Business conversation history: retained in line with the tenant workspace retention policy, defaulting to 36 months for active customer workspace records and longer only for audit/compliance purposes.
- GDPR audit logs and immutable access records: retained for a minimum of six years as evidence of compliance, regardless of customer erasure requests, as required under UK GDPR accountability obligations.
- Transactional finance, billing and tax records: retained for at least six years from the end of the relevant UK accounting period.
Children, special category data and criminal offence data
Marhala AI products and websites are not directed at children under the age of 13 and we do not knowingly collect, process or store personal information about individuals under 13 without verifiable parental consent. If you become aware that a child under 13 has submitted personal data to us, please contact [email protected] and we will take prompt steps to delete that information.
Special category personal data (racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for uniquely identifying a natural person, health data, or data concerning sex life or sexual orientation) and criminal offence, conviction or misconduct data are only processed where necessary for the performance of our obligations under employment, social security or social protection law, or under another UK GDPR condition with appropriate safeguards recorded. Wherever possible we design our products so that customers do not pass such data into general CRM fields or general enquiry message boxes without a documented lawful condition.
Automated decision making and profiling
Most of our processing is not automated in a way that produces legal or similarly significant effects on a data subject. However, we do make limited use of automated scoring for the narrow purposes of lead categorisation (e.g. assigning Wedding enquiry vs Room booking), spam or fraud detection on incoming web forms, AI-powered suggested next-steps for staff members and priority ranking for the front-desk staff inbox.
These automated steps are either a necessary part of entering into or performing a contract with the customer, or are carried out with explicit consent, and are never the sole basis of a decision that would produce legal or similarly significant effects on an individual. Staff users always have the ability to override an AI category assignment, edit a detected lead priority, dismiss an AI-suggested next-step or reassign an automated routing decision through the CRM user interface. Where we use automated detection on incoming messages we also keep a record of the manual staff override where it occurs.
Complaints, updates and contacting the DPO
We review and update this privacy policy from time to time to reflect changes in our processing activities, new product features, legal or regulatory requirements, or decisions affecting our sub-processor arrangements. Material changes will be posted on this page with an updated effective date and, where appropriate, we may notify customers or website visitors through an in-product notice or by email.
If you have a privacy concern, complaint or query, or wish to escalate a matter to the Data Protection Officer, please write to [email protected] or to Marhala AI Ltd, Data Protection Officer, 128 City Road, London, EC1V 2NX, United Kingdom. We will acknowledge receipt without undue delay and investigate in accordance with our internal DSR and complaint handling procedures.