AI CONCIERGE · LEGAL

Privacy Policy

How AI Concierge handles personal data submitted through the showroom, founding-client application, referral feature and demo conversations.

Controller

The controller is Darren Boyle, NIE / tax identification Y5860707E, trading as AI Concierge, at Urb. Angel de Miraflores Bloque 4, 3b, C. Geranio 35, 29649 Las Lagunas de Mijas, Málaga. Privacy enquiries may be sent to concierge@ai.darrenboyle.com or by telephone on +34 641 87 88 73.

Data we may process

Why we use it

Legal bases

Depending on the context, processing may rely on steps requested prior to entering a contract, legitimate interests in operating and securing the demonstration and administering requested referrals, compliance with legal obligations, and consent where consent is legally required. We do not treat a referral alone as blanket consent for unrelated marketing.

AI and service providers

Messages and related context may be processed by configured AI, hosting, email, messaging, database and infrastructure providers acting as processors or independent providers as applicable. Production customers may also connect CRM, WhatsApp/Meta, booking, property or other systems. The exact production data flow depends on the implementation selected for that customer.

Google user data

AI Concierge may request access to Google services only when an authorised user deliberately connects a Google account. The requested access is used to provide the following user-facing features:

Mailbox message content and metadata are fetched from Google while the authorised mailbox page is being used and are not imported into the AI Concierge database. OAuth connection credentials are encrypted at rest. Google user data is not sold, used for advertising or transferred for unrelated purposes. Access can be withdrawn by disconnecting the integration in AI Concierge or revoking access in the user’s Google Account settings.

Retention

Application and referral records are retained for as long as reasonably necessary to administer the request, referral or resulting commercial relationship and to meet legal/accounting requirements. Demo conversation and operational logs may be retained where reasonably necessary for product operation, conversation continuity, security, testing and troubleshooting. Retention periods may differ for contracted customer implementations and should be defined in the applicable customer/data-processing arrangements.

Your rights

Where the GDPR applies, you may have rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent where processing relies on consent. You may also complain to the competent supervisory authority, including Agencia Española de Protección de Datos (AEPD) where applicable.

Local storage and cookies

The web chat uses session-scoped browser storage only where technically necessary to maintain conversation continuity during the browser session. Conversation content is stored server-side in the database, not in browser storage. The core widget does not use advertising or marketing cookies by default.

Referrals and third-party email addresses

If you refer someone, submit only a genuine professional contact you reasonably believe would expect the introduction. Recording a referral does not itself authorise indiscriminate marketing to that person. We may use the email to administer the referral and contact them only where a lawful basis permits.