Homni.Channel

Privacy policy

Last updated

Homni.Channel is a WhatsApp guest-messaging service for hotels, serviced apartments and short-term rental operators. It is provided by Soulasia, Jalan Perak, 50450 Kuala Lumpur, Malaysia. This policy explains what personal data the service handles, why, and what you can do about it.

Who is responsible for the data

Two kinds of business are involved, and they have different roles.

  • The operator is the hotel or rental business a guest is staying with or writing to. The operator decides why and how its guests' data is used. It is the controller of that data.
  • Soulasia, as the provider of Homni.Channel, handles that data on the operator's behalf and on its instructions. We are the processor.

Soulasia is itself the controller in three cases: for guests of Soulasia's own properties, for the sign-in accounts of staff who use Homni.Channel, and for people who write to us about the service.

If you are a guest and want to know what a property holds about you, the property you stayed with is the right place to ask first. You can also write to us at tech@soulasia.com.my and we will pass your request to that operator and help it respond.

What is processed

About guests

  • WhatsApp messages between the guest and the operator's number: text, and any photos, documents or other files sent in either direction.
  • The guest's WhatsApp phone number and WhatsApp profile name.
  • Reservation details from the operator's connected property management system (Cloudbeds): guest name, phone number, booking reference, property, unit, stay dates and booking status.
  • Housekeeping requests the guest makes in the conversation.
  • Notes, summaries and translations of the conversation produced for the operator's staff.

About the operator's staff

  • Email address, display name and role.
  • A password, stored only as a one-way hash, and the secret for the authenticator app used for two-factor sign-in.
  • Sign-in sessions, and the IP address and browser of sign-in attempts.
  • An audit log of actions taken in the account: who did what, when and from which IP address.
  • The messages staff send to guests.

About visitors to this website

This website sets no cookies and runs no analytics or advertising scripts. Its fonts are loaded from Google Fonts, so your browser contacts Google when a page opens. If you email us, we receive what you write and your email address.

What it is used for

  • Answering the guest's messages, by the AI assistant or by the operator's staff.
  • Recognising the guest's reservation so answers fit the stay.
  • Sending the operator's service messages about a stay, such as a welcome at check-in.
  • Passing housekeeping requests to the operator's team.
  • Showing conversations to the operator's staff, including translations and summaries.
  • Improving that operator's own knowledge base when its staff flag a wrong answer.
  • Keeping the service secure and working: signing staff in, recording actions, finding and fixing faults.

We do not sell personal data. We do not use it for advertising. One operator's knowledge base is never used to answer another operator's guests. We do not train AI models on personal data.

How the AI assistant uses messages

To write a reply, the service sends the recent conversation, the operator's knowledge base and, where the guest has been recognised, the relevant reservation details to an AI model provider (Anthropic). The same provider is used to produce conversation summaries, translations for staff, and draft corrections to the knowledge base. Guests can ask for a person at any point, and the operator's staff can take over any conversation.

Other companies involved

We use these providers to run the service. Each receives only what its part of the service needs.

  • Meta (WhatsApp Business Platform)Delivers messages and files between guests and the operator's WhatsApp number. The operator holds its own WhatsApp Business account with Meta.
  • AnthropicAI model provider. Receives conversation text, images sent by guests, knowledge base content and reservation context in order to generate replies, summaries, translations and suggested knowledge base edits.
  • RenderHosting for the application and its database, in Singapore.
  • CloudbedsThe operator's property management system. Homni.Channel reads reservation data from it using a connection the operator authorises. It does not write to it.
  • ResendSends account emails to staff, such as invitations and password resets. Receives the staff member's email address.
  • TelegramOnly if the operator turns on housekeeping dispatch. Housekeeping tasks (the unit and the request) are posted to the operator's own Telegram group.
  • SentryError monitoring. Receives technical error reports. Request bodies, headers and cookies are removed before a report is sent.
  • Have I Been PwnedWhen a staff member sets a password, the first five characters of its hash are checked against a list of leaked passwords. The password itself and the person's identity are not sent.

The application and its database are hosted in Singapore. Some of the providers above process data in other countries.

How long data is kept

  • Conversations, guest phone numbers and names, housekeeping tasks, summaries and translations: no automatic time limit is applied. They are kept until the operator asks us to delete them.
  • The link between a phone number and a reservation: copied from the operator's Cloudbeds account and refreshed from it. It exists for as long as the reservation carries that phone number there.
  • Stored copies of photos and files: removed after about 90 days. The record that a file was sent stays in the conversation.
  • Technical logs of AI requests (phone number, model, size and timing, not the message text): removed after about 90 days.
  • Retrieval-measurement log (the text of a guest's question next to the phone number, used to measure how well the assistant finds the right knowledge): no automatic time limit is applied. It is kept until deleted on request.
  • Knowledge-base correction drafts and test cases made from a conversation (they can quote guest messages and carry the phone number): no automatic time limit is applied. They are kept until deleted on request.
  • Records of failed booking verification attempts: removed after about 7 days.
  • Records of failed staff sign-in attempts: removed after about 24 hours.
  • Staff sign-in sessions: expire after 24 hours.
  • Staff accounts: kept until the operator's admin removes the user or the operator asks us to.
  • Audit log: cannot be edited or deleted, by design, so that it stays a reliable record. It is kept for as long as the service runs.
  • Backups and provider logs: kept by our hosting and monitoring providers for the periods those providers set.

How it is protected

  • Each operator has its own account, with its own WhatsApp number, knowledge base, staff and settings. An operator's staff see only their own account's conversations. Soulasia's platform administrators can open an operator's account to set it up and support it; changes they make there are recorded in the audit log.
  • Every staff member signs in with a password and a two-factor code. Passwords are stored as one-way hashes and checked against known leaked passwords.
  • Access keys for connected services (the operator's Cloudbeds connection and WhatsApp access token) are encrypted in the database.
  • Staff roles limit who can manage users, knowledge and settings.
  • Actions in an account are recorded in an audit log that cannot be altered.
  • Per-unit details such as door codes are released only to a guest whose booking has been verified.
  • Connections to the service are encrypted in transit.

No system is perfectly secure. If we learn of a breach affecting an operator's data, we will tell that operator without undue delay.

Your rights

You can ask to see the personal data held about you, to have it corrected, or to have it deleted. You can also ask that it no longer be processed.

  • Guests: ask the property you stayed with, or write to us and we will pass the request to it. For Soulasia's own properties, write to us directly.
  • Operators and their staff: write to us from the email address on your account.

We answer within 30 days. The steps for deletion are on the data deletion page.

Contact

Soulasia
Jalan Perak, 50450 Kuala Lumpur, Malaysia
Phone +60 12-342 3834
Email tech@soulasia.com.my

Changes to this policy

When this policy changes, we update this page and the date at the top. Operators are told about changes that affect how their guests' data is handled.