H

Privacy Policy

HavAway — Virtual concierge

Last updated: June 2026

1. Data controller

The controller for personal data collected via HavAway is:

Quentin Moreaux
Cannes, France
Contact: privacy@havaway.com

[À COMPLÉTER APRÈS IMMATRICULATION : dénomination sociale + SIREN + adresse du siège]

2. Nature of the service

HavAway is a virtual assistant powered by artificial intelligence (Claude model, developed by Anthropic). It is made available to guests staying in the apartment to assist them during their stay. You are interacting with an artificial intelligence, not a human being.

3. Data collected

When you identify yourself (welcome form linked to your booking):

• First and last name
• Stay dates (check-in and check-out)
• Country of origin and preferred language
• Number of guests (if provided)

During your exchanges with the assistant:

• The content of your messages
• The date and time of each conversation
• The number of messages exchanged
• The type of device used (mobile, desktop)

No email or phone number is collected automatically. If you voluntarily share such information in your messages, it will be included in the conversation history.

4. Purposes of processing

Data is collected exclusively to:

• Improve the quality of the service and the assistant's responses
• Identify frequent guest questions
• Allow the host to better understand their guests' needs

5. Legal basis

Two legal bases apply depending on the data concerned:

Performance of a contract (GDPR Article 6.1.b) for identification data (first name, last name, stay dates, country, language, number of guests): this data is necessary to provide the concierge service linked to your booking.
Consent (GDPR Article 6.1.a) for messages exchanged with the assistant: collected before any use of the chat via an information notice, and withdrawable at any time.

6. Data retention

Conversations: 90 days maximum from the last message, automatic deletion thereafter.
Guest identification data: 90 days from creation, automatic deletion thereafter.
Guest session cookie: 90 days maximum (see section 10).

7. Processors and hosting

Anthropic (San Francisco, USA): provider of the Claude artificial intelligence model. Messages are transmitted to the Anthropic API to generate responses. Anthropic commits to not using API data to train its models.
Vercel (USA): website hosting
Upstash (servers in Frankfurt, Germany — EU): conversation storage

Data transfers outside the EU are governed by the European Commission's Standard Contractual Clauses (SCCs).

8. Your rights

In accordance with the GDPR, you have the following rights:

Right of access: obtain a copy of your data
Right to rectification: correct inaccurate data
Right to erasure: request the deletion of your data
Right to restriction of processing: request the temporary suspension of a processing operation
Right to data portability: receive your data in a structured, commonly used and machine-readable format
Right to object: object to the processing of your data
Right to withdraw consent: at any time, without affecting the lawfulness of prior processing

To exercise these rights, contact us by email at privacy@havaway.com, or via the HavAway concierge by asking the assistant to forward your request. You will receive a response within a maximum of one month.

9. AI Transparency (AI Act — EU Regulation 2024/1689)

In accordance with Article 50 of the European Regulation on Artificial Intelligence:

• HavAway is an artificial intelligence system in the "limited risk" category
• Responses are generated automatically by a language model (Claude, Anthropic)
• The assistant may make mistakes — critical information must be verified with the host
• No decision with legal effect is made by this system

10. Cookies

HavAway does not use any advertising cookies or third-party trackers. Only the following mechanisms, strictly necessary for the service, are used:

Guest session cookie (havaway_guest_*): opaque identification pointer, set after submission of the welcome form. Attributes: httpOnly, SameSite=Lax, duration 90 days. Purpose: avoid asking you for your information on each visit, and maintain access to the concierge throughout your stay.
Host session cookie (havaway_session): used only for owner authentication in the administration area. Does not concern guests.
Local storage (localStorage): storage of your AI consent, to avoid asking for it on each message.

These mechanisms are strictly necessary for the operation of the service. In accordance with the ePrivacy Directive and CNIL guidelines, they do not require prior opt-in consent: information alone is sufficient (this section).

11. Complaint

If you believe your rights are not being respected, you may file a complaint with the French data protection authority, the CNIL (Commission Nationale de l'Informatique et des Libertés): www.cnil.fr

← Back