Privacy Policy
What data we process, for what purpose, on what legal basis and what rights you have.
Last updated: 2026-09-12
1. Controller
Hunzi Systems GmbH, Mitterstraßweg 17, 82064 Straßlach-Dingharting, Germany. Commercial register: Local Court (Amtsgericht) Munich, HRB 312494. VAT ID: DE462819243. Represented by its Managing Directors: Saghar Ayyaz and M. Mousa Siddiqi.
Email: [email protected]
Please address data-protection requests to this address with the subject "Data protection".
1.1 Data Protection Officer (DPO): why the duty must be assessed
Whether Hunzi Systems must appoint a DPO depends on two independent triggers (§ 38 of the German Federal Data Protection Act, BDSG):
1. Headcount threshold (§ 38(1) sentence 1 BDSG): a DPO is required if, as a rule, at least 20 persons are constantly engaged in automated processing of personal data. Hunzi Systems likely does not meet this threshold.
2. DPIA trigger (§ 38(1) sentence 2 BDSG), regardless of headcount: a DPO is also required if the company carries out processing that is subject to a Data Protection Impact Assessment (DPIA, Art. 35 GDPR). This applies irrespective of how many staff are employed.
A DPIA is required where processing is "likely to result in a high risk" to the rights and freedoms of individuals (Art. 35(1) GDPR). Under the WP29/EDPB criteria, meeting two or more of nine risk factors normally requires a DPIA. Hunzi's voice channel plausibly meets several:
- use of innovative/new technology (AI-based real-time speech processing, automated speech-to-text and reply generation);
- systematic monitoring/processing of communications (ongoing processing of phone calls);
- large-scale processing (potentially many callers across tenants);
- highly personal data (the content of spoken communication; with raw audio, also voice data).
In particular, the 24-hour retention of raw audio for training (see B.4.2) raises the risk profile. It is therefore defensible and prudent to assume that a DPIA is required, which in turn triggers a mandatory DPO appointment via § 38(1) sentence 2 BDSG.
Role note: the Art. 35 DPIA duty falls primarily on the controller (the tenant/hotel). As a processor, Hunzi Systems assists the controller with the DPIA (Art. 28(3)(f)). Whether the § 38 BDSG DPO duty also binds the processor directly is not fully settled; the safe path is to either appoint a DPO or carry out and document the DPIA.
1.2 Competent supervisory authority
For Hunzi Systems as a private-sector entity seated in Bavaria, the competent authority is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach. Phone: +49 (0) 981 53 1300 · Email: [email protected] · Web: https://www.lda.bayern.de. You may also complain to the authority of your habitual residence (Art. 77 GDPR).
A. Website (hunzi.ai): Hunzi Systems as controller
A.1 Server logs: technically necessary access data (IP address, request time, resource, referrer URL, host name, browser/OS); no merging with other sources. Purpose: delivery, stability, security. Legal basis: Art. 6(1)(f) GDPR. Retention: ≤ 14 days, then anonymised/deleted. Hosting: Hetzner Online GmbH, data centres in Germany, Art. 28 DPA. TLS/security: Cloudflare (EU entity). A.2 Contact: data you provide is processed to handle your request (Art. 6(1)(b)/(f)). A.3 Cookies and device storage: the website uses no tracking/analytics/advertising cookies: only strictly necessary storage exempt from consent under § 25(2) no. 2 TDDDG (TTDSG renamed TDDDG on 14 May 2024), so no cookie banner is required. The chat widget sets no cookie (it stores one consent record and one random session id - 12 h sliding, set only after your first message - in local storage); the admin UI uses strictly-necessary login cookies (staff only). See /cookies for the full list and when a banner would become mandatory (analytics, third-party embeds, marketing pixels). The cookieless traffic measurement described in A.5 neither stores information on your device nor accesses any, so § 25 TDDDG does not apply to it. A.4 Operational email: Resend, Inc. (USA; transfer under the EU-US Data Privacy Framework and/or standard contractual clauses, see B.6), operator alerts only.
A.5 Traffic measurement (Cloudflare Web Analytics): For traffic measurement on this website we use Cloudflare Web Analytics. Cloudflare already provides TLS termination, edge routing and denial-of-service protection for hunzi.ai and therefore processes this website's connection data on every request. The measurement adds no new recipient.
The service is cookieless: it sets no cookies and neither stores information on your device nor reads any from it. No cross-site identifier is created that would allow individual visitors to be tracked across websites.
- Purpose: aggregated evaluation of page views and traffic sources, to improve our website's content and discoverability.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest). Our legitimate interest is to understand the reach and use of our website without identifying, profiling, or tracking individual visitors across sites. Because the measurement is cookieless, creates no cross-site identifier and involves no additional recipient, competing interests of visitors do not outweigh this interest.
- Consent: not required. Because the service neither accesses nor stores any information on your device, § 25 TDDDG does not apply to it; no cookie banner is required for this service.
- Right to object: you may object to this processing at any time, on grounds relating to your particular situation, under Art. 21(1) GDPR (see section C of this notice).
B. Hunzi service: Hunzi Systems as processor
B.1 Role: Hunzi is a multi-tenant AI assistant that businesses ("tenant", e.g. hotels) use to communicate with their end-customers (voice, chat widget, WhatsApp). For end-customer content the tenant is the controller; Hunzi Systems is the processor (Art. 28 GDPR). End-customers should address data-protection requests primarily to the relevant tenant.
B.2 Data categories: identifiers (session ID, E.164 phone number, booking ref.); communication content (chat, attachments, button replies, voice utterances + transcripts, logged tool calls); verification data (last name); voice recordings (B.4); tenant-staff identifiers (Keycloak sub, email, role). No special categories (Art. 9 GDPR).
B.3 Purposes & legal bases:
| Processing | Purpose | Legal basis |
|---|---|---|
| Operating the assistant | Handling requests on the tenant's behalf | Tenant instruction; Art. 6(1)(b)/(f) (controller = tenant) |
| Identity verification | Prevent unauthorized access | Art. 6(1)(f) |
| Audit logging | Security, abuse prevention, evidence | Art. 6(1)(c)/(f) |
| Quality voice capture (sample, B.4.1) | Debugging/quality | Art. 6(1)(f) |
| 24h raw audio for training (B.4.2) | Improve speech recognition & synthesis | Art. 6(1)(a), consent |
| Call recording for playback by the hotel (B.4.3, only when switched on) | Following up and handling the request | Art. 6(1)(f) |
B.4 Voice processing (phone channel). B.4.1 Quality assurance: at call start, callers are told the call may be recorded for quality and are pointed to this notice; they may object by hanging up. From a sample (≤ 10%) or on detected issues, audio, transcripts and a stage timeline are stored for 7 days, accessible only to a small, audited group of Hunzi Systems staff. Legal basis: Art. 6(1)(f). Note on § 201 of the German Criminal Code (confidentiality of the spoken word): real-time transcription is treated as recording. B.4.2 Voluntary 24h retention for training (in preparation): at call start we ask separately and explicitly whether we may keep the raw audio for 24 hours to improve the system. Stored only on active consent ("yes"); with no/unclear/no answer, no training recording is kept and the call continues normally. Legal basis: Art. 6(1)(a), withdrawable at any time. Retention: max 24 hours from call start, then auto-deleted. Purpose limitation (Art. 5(1)(b)): separate from quality assurance. Consenting to QA is not consent to training. B.4.3 Call recording for playback by the hotel: when the hotel switches this on, every phone call is stored as an audio file (caller and assistant) on Hunzi Systems servers in the EU, so the hotel's staff can play it back in the admin area. Callers are told at call start that the call is recorded. If a caller asks during the call not to be recorded, the audio file is not stored and the call continues normally. Legal basis: Art. 6(1)(f). Retention: 30 days from the call, and never longer than the conversation it belongs to (B.7); the audio file is then deleted automatically, and an erasure request (Art. 17) removes it at once. Recipients: the hotel's staff only; no additional sub-processor.
B.5 Recipients / sub-processors (Art. 28 DPAs in place or to be concluded):
Text/platform services (Phase 1, listed in the DPA): Hetzner Online GmbH (hosting/database, Germany) · Hetzner Online GmbH Storage Box (backup target for encrypted database backups, being set up; Germany) · Google Cloud EMEA Ltd (Vertex AI - all LLM inference, text and voice, plus output moderation via Vertex AI Safety Filters; europe-west1, Belgium) · Meta Platforms Ireland Ltd. (WhatsApp, Instagram Direct and Facebook Messenger delivery, EU) · Cloudflare (EU entity; TLS/edge/DDoS) · Resend, Inc. (operator email only, US provider; transfer under the EU-US Data Privacy Framework and/or standard contractual clauses, see B.6).
Additional channels and tools (only where the relevant tenant enables them, or tenant-specific): Telegram FZ-LLC (Telegram channel - opt-in only, off by default for EU tenants; Dubai, UAE - third country; the contractual safeguards (Art. 28 GDPR contract, transfer tool) are currently being formalized, see B.6) · Microsoft Ireland Operations Ltd. (connection to the tenant's own Microsoft 365 support mailbox via OAuth; mailbox content stays in the tenant's M365 tenancy; EU Data Boundary) · Google Ireland Ltd. ((a) the tenant's own Gmail/Workspace support mailbox via OAuth, EU data region; (b) Places API for the staff-only hotel-onboarding search - public business-listing data only, no guest data) · Mistral AI SAS (knowledge-base embeddings; proposed, not yet engaged; Paris, France).
Voice services (phone channel): the authoritative list is the sub-processor table in our Data Processing Agreement: Telnyx (telephony - SIP connection/phone number, call answering; in use; contractual follow-up on EU-region pinning and transfer basis in progress) · speech-to-text (STT): intended vendor Google Cloud "Chirp 3" (EU); currently in fact Gladia - the vendor declares processing in "Europe/USA", and the Art. 28 GDPR contract is currently being formalized, see B.6 · Cartesia AI, Inc. (speech synthesis/TTS; US provider; the pinning to the EU endpoint api-eu.cartesia.ai is currently being verified, see B.6) · Google Cloud Vertex AI (voice LLM / reply generation plus output moderation, europe-west1, see the Google Cloud entry above). LiveKit (SFU, SIP gateway, agents worker) is self-hosted on Hetzner (Germany) and is not a sub-processor. Deepgram and ElevenLabs are not engaged; any further engagement requires a DPA, EU-region pinning and 30-day prior tenant notice.
Guest transactional email (Phase B, only where the hotel/Tenant enables Hunzi-sent email; otherwise the hotel's own PMS, e.g. ibelsa, emails you and Hunzi is not involved): Scaleway SAS (Transactional Email; Paris, France, fr-par). Used to send you the payment link and the booking confirmation. Your address is stored by Hunzi only as a salted hash; the email body is not retained by Hunzi.
B.6 International transfers: processing takes place principally in the EU/EEA. Exceptions:
- Resend, Inc. (US): operator alerts to Hunzi staff only; transfer under the EU-US Data Privacy Framework and/or standard contractual clauses.
- Telegram FZ-LLC (UAE): only where a tenant expressly enables the opt-in Telegram channel; the contractual safeguards for this transfer are currently being formalized.
- Cartesia AI, Inc. (US): speech synthesis; the EU-endpoint pinning is currently being verified; until confirmed, processing in the US cannot be ruled out.
- Gladia (speech-to-text, see B.5): the vendor declares processing in "Europe/USA"; contract formalization is in progress.
B.7 Retention overview: conversations/messages/tool calls/tickets/ WhatsApp dedup: 90 days (tenant-configurable 7–3650); audit logs: 365 days then pseudonymized; quality voice captures: 7 days; training raw audio (on consent): max 24 hours (in preparation); call recordings for playback (B.4.3): 30 days, never longer than the conversation; backups: target state 30 days, encrypted, EU (backup currently being set up).
C. Your rights
You have the rights to access (Art. 15), rectification (16), erasure (17), restriction (18), portability (20), withdrawal of consent (Art. 7(3), esp. B.4.2; lawfulness of prior processing unaffected), and complaint to a supervisory authority (Art. 77, e.g. BayLDA, § 1.2, or the authority of your residence). For requests about a tenant's assistant, address the tenant first; Hunzi Systems supports the tenant technically (export/erase implemented).
⚠️ Right to object in particular situations and to direct marketing (Art. 21 GDPR)
WHERE PROCESSING OF YOUR PERSONAL DATA IS BASED ON ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, TO THAT PROCESSING; THIS ALSO APPLIES TO PROFILING BASED ON THOSE PROVISIONS. IF YOU OBJECT, WE WILL NO LONGER PROCESS THE AFFECTED DATA UNLESS WE DEMONSTRATE COMPELLING LEGITIMATE GROUNDS THAT OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES TO ESTABLISH, EXERCISE OR DEFEND LEGAL CLAIMS (ART. 21(1) GDPR). WHERE DATA IS PROCESSED FOR DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME; AFTER OBJECTION THE DATA WILL NO LONGER BE USED FOR THAT PURPOSE (ART. 21(2) GDPR).
D. No automated individual decisions
No automated decision with legal effect (Art. 22 GDPR); sensitive actions go through a confirmation/verification step.