Skip to content

Privacy policy

This policy explains which personal data is processed as part of the Paco service, why, on what legal basis, with whom it is shared, how long it is kept and what your rights are, in accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act. It is written to be read in full: every processing operation that actually takes place is listed here, including those that only happen if you switch an option on.

1. Data controller

The data controller is Vesper Holdings, a single-shareholder SAS, Marseille Trade Register 943 254 441, 15B Boulevard Die, 13012 Marseille, France. For any question about your data or to exercise your rights: contact@pacoapp.io. No data protection officer has been appointed; this address is the point of contact.

For the data a customer property entrusts to Paco (reports, mail, its staff's accounts), the property is the controller and Vesper Holdings acts as processor, under the data processing agreement.

2. Data processed

Paco collects only what the service needs. Here is the complete list, by situation.

2.1 Your account

  • Name, email address, password (stored as a hash, never in clear text), language, time zone.
  • Role in the organisation, access scope (which properties you can see), job title and declared trades (skills), tasks assigned to you.
  • Brief preferences: channel (email, WhatsApp or Telegram), hour, days, sections.
  • Consent to receive product news: a box unticked by default, recorded only if you tick it.
  • Acceptance of the terms of use and of this policy when the account is created: the date and time are stored with your account (and also written to the server log).

2.2 Security and abuse prevention

  • The IP address used to create the account, stored encrypted. It is decrypted only by one of the publisher's operators, to check that a sign-up is not fraudulent. A resolution to an approximate city by a third-party service (see section 4) exists but is off by default; it is used only if the operator switches it on for an abuse check. Neither the clear address nor the location is kept.
  • Server logs (IP address, page requested, timestamp) and the session cookie.
  • When you request access: the browser identifier ("user agent") and the IP address, to limit automated submissions.

2.3 Demo or access request

First name, last name, work email address, property, country, number of rooms and the message you write. This data is used only to answer your request and, if you are admitted, to create your invitation.

When you download a free document (brief, checklist, calendar): first name, last name, work email address, property, country and number of properties, to send you the download link. The IP address is encrypted and used only to limit automated submissions. If you tick the box provided, we send you at most two emails on the same subject over the following seven days; reply to either of them and you will receive nothing more.

2.4 Your property

  • Name, address, country, type and classification of the property. While you type the address, the text you enter is sent to an address-completion service (see section 4) to suggest the full address.
  • If you connect your property management system (PMS): the property profile and its room list, as the PMS provides them. The connection token is stored encrypted.

2.5 Compliance data

Inspection reports, certificates and letters uploaded or collected, and their metadata (dates, contractors, findings, deadlines). These documents may contain third parties' personal data: the name of a technician, an inspector, a contractor, or an employee whose work permit is tracked.

2.6 Connected mailbox (inbox scanning), if you connect one

Access tokens for the connected mailbox, stored encrypted. When you first connect it, Paco reads the messages of the last 12 months, then new messages as they arrive: sender, subject, text and attachments. Mail from correspondents you have excluded is never read, and newsletters and consumer mail are set aside before any AI model reads anything. From the rest Paco keeps the emails about safety checks, their attachments and what it extracts from them. Paco never deletes, moves or changes a message in your mailbox.

Paco also sends, from this mailbox, the letters to outside companies described in section 2 of the terms of use, and only in one of three ways:

  1. a person at your organisation read that copy and approved it (in the application, or by answering YES in the chat);
  2. under the standing permission to chase: a manager gave that permission and asked Paco in the chat to chase; the safety check is overdue according to your own documents; the company is on your list with its own address; the daily limit the manager set (3 letters a day unless changed, never more than 10) is not reached; and the permission is not paused;
  3. as an approved letter: a manager read the exact wording of that kind of letter once, approved it, and chose "When you ask Paco" or "Without asking" and which companies; the letter is that wording, word for word, to the address your own documents name when it is sent.

Every letter leaves a record naming the person or the approval that allowed it. A manager can withdraw an approval or a permission, or pause Paco, at any time in Settings or on the "Without asking" page.

Google accounts (Gmail). Paco asks Google for two permissions: gmail.readonly, to read your mail as described above, and gmail.send, to send those letters from your address. It does not ask for permission to delete or modify your mail. Paco's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms:

  • Paco uses what it reads in your Gmail only to find inspection reports, certificates and replies from the companies that do the work, to keep your list of safety checks, and to draft and send the letters described above. It uses it for nothing else.
  • Paco sends a message from your Gmail only in one of the three ways listed above.
  • That data is transferred only to the processors that help provide this service (section 4): the host, the encrypted backup, and the AI provider that reads mail and documents (Mistral AI). The chat model (section 2.9) receives only the summary of your list of safety checks and a letter's facts described there, never an email itself.
  • It is not sold, not used for advertising, and not used to develop, improve or train generalised artificial-intelligence or machine-learning models. Paco does not train any model on it, and its AI providers process it under API terms that exclude training on it.
  • No one at Paco reads it, except with your permission for specific messages (for example to answer a support request), where it is necessary for security (such as investigating abuse), or to comply with the law.

Microsoft accounts (Outlook, Microsoft 365). Paco asks Microsoft for Mail.Read (read your mail), Mail.Send (send the letters above), offline_access (keep access without you signing in again) and User.Read (your account's name and address). The same rules apply: the same uses only, the same three ways of sending, no sale, no advertising, no model training, and no human reading except as above.

Signing in with Google. If you choose “Continue with Google” on the sign-in page, Paco asks Google only for your account's email address and name (openid, email, profile), to sign you in to a Paco account that already uses that address. It reads no Gmail this way, keeps no Google token afterwards, and creates no account.

You can revoke Paco's access at any time from your Google or Microsoft account's security settings or from Paco's own settings; the stored tokens are then deleted.

2.7 WhatsApp and Telegram, if you link a number or choose that channel

Phone number, messages exchanged with Paco, photos and documents sent through that channel. For Telegram, the chat identifier. These messages pass through the channel's provider (see section 4) and are kept in your account.

2.8 Proof photos and reports

When a manager or an employee sends a photo to prove that a job was done or to report an issue, Paco reads the information the file already contains (EXIF metadata): capture date and time, GPS coordinates and camera model, where present. Only if the sender ticks the box provided, the browser's location is attached. These elements are shown to the manager who validates the proof, with a link to a map, to check that the photo matches the place and time claimed. The sender may decline the box; the photo is then accepted without a location. Photos must show the equipment or the place, not people.

2.9 Assistant and the chat model

The questions you ask the assistant (on the site or over WhatsApp) and its answers are kept in your account so the conversation can continue. To answer, an AI provider (see section 4) receives your question, your recent conversation history and a snapshot of your property's list of safety checks: their names, statuses and dates, property names and the names of the companies. It never receives a whole document, nor your name, nor your email address. The same chat model writes the "Overview" summaries and, when Paco words a letter to a company, receives that letter's facts: the company's name, the property's name and address, the safety check, its dates and reference, and the problems the inspector noted.

The chat model is chosen per organisation. For an organisation subject to the GDPR (an establishment in the European Economic Area or the United Kingdom, or an establishment whose country is not yet set), it is Mistral AI, in the European Union, and Anthropic's model is not used. For an organisation whose establishments are all outside that area, it is Anthropic's Claude, in the United States, by default, and an administrator can switch it to Mistral AI in Settings.

Reading mail and documents is always done by Mistral AI, whatever the organisation: an email's sender, subject, text and attachment names are sent to it to recognise mail about safety checks, the content of reports and certificates to extract dates, companies and the problems noted, and the text of a problem your staff report to sort it.

2.10 What Paco does not collect

No special-category data within the meaning of Article 9 GDPR (health, opinions, biometric data, etc.) is requested or needed. Card details never reach Paco: they are entered on Stripe's payment page (section 2.11). No audience measurement or advertising profiling tool is used.

2.11 Billing, if your organisation subscribes

The organisation's billing name, billing email address, postal address and VAT number, the subscription's status and the invoices are processed with Stripe (section 4). Paco keeps the subscription's status and Stripe's references to match payments to the organisation. Card details are entered on Stripe's payment page, go directly to Stripe and never reach Paco.

3. Purposes and legal bases

PurposeDataLegal basis (GDPR)
Providing the service: account, register of duties, reading documents, tasks, briefs2.1, 2.4, 2.5Performance of the contract (art. 6.1.b)
Answering a demo or access request2.3Pre-contractual steps (art. 6.1.b)
Sending a free document you asked for2.3Your request (art. 6.1.b)
Sending two follow-up emails after a download2.3Consent, through the box you tick (art. 6.1.a), withdrawable at any time
Helping the property meet its regulatory obligations2.5Legitimate interest / customer's legal obligation (art. 6.1.f / 6.1.c)
Reading a connected mailbox2.6Your explicit action of connecting it (art. 6.1.a), withdrawn by disconnecting the mailbox
Exchanging over WhatsApp or Telegram2.7Your explicit choice of the channel (art. 6.1.a), withdrawable at any time
Checking the integrity of a proof photo (file metadata)2.8The property's legitimate interest (art. 6.1.f) and performance of the contract
Attaching the browser's location to a photo2.8Consent, through the box ticked at each upload (art. 6.1.a)
Answering questions asked of the assistant2.9Performance of the contract (art. 6.1.b)
Sending letters to outside companies and messages to the team, as the organisation instructed2.6, 2.9Performance of the contract (art. 6.1.b)
Billing the subscription and keeping invoices2.11Performance of the contract (art. 6.1.b) and legal accounting obligations (art. 6.1.c)
Sending product news2.1Consent (art. 6.1.a), withdrawable at any time
Security, abuse and fraud prevention, logging2.2Legitimate interest (art. 6.1.f)
Proving acceptance of the terms of use2.1Legitimate interest (art. 6.1.f)

4. Recipients and processors

Your data is never sold. It is accessible only to the publisher's authorised staff and to the following processors, who act on instruction and under data processing agreements. Rows marked "if you switch it on" only concern accounts that chose the option.

ProcessorRoleDataCountry and safeguards
Hetzner Online GmbHServer hosting: database, documents, mailAllGermany (EU)
Backblaze, Inc.Nightly backup copy, encrypted on Paco's server before it is uploaded, so Backblaze cannot read it; a deletion schedule for these copies is being put in placeAll (encrypted)Stored in the EU (Amsterdam, Netherlands); Backblaze, Inc. is a United States company — standard contractual clauses
Resend, Inc.Sending the service's emails from noreply@pacoapp.io: acknowledgements, invitations, password resets, briefsEmail address, name, message contentUnited States — standard contractual clauses
Mistral AIReading mail and documents (recognising mail about safety checks, extracting dates, companies and problems noted), for every organisation; chat model (assistant, "Overview" summaries, wording of letters) for organisations subject to the GDPR and for any organisation that chooses it. On the paid tier Paco uses, Mistral does not train on customer inputs or outputs; it retains them for 30 rolling days for abuse monitoring only (Zero Data Retention is a higher Mistral plan Paco does not currently take)Email sender, subject, text and attachments; document content; question, recent conversation memory, register snapshot and letter factsFrance (EU)
Anthropic, PBCChat model (assistant, "Overview" summaries, wording of letters), by default for organisations whose establishments are all outside the GDPR area; an administrator can switch to Mistral AI. Never used for an organisation subject to the GDPR, nor to read mail or documentsThe typed question, the recent conversation memory, a register snapshot (names of safety checks, statuses, dates, properties, companies) and a letter's facts; never a whole document or email, nor the person's name or emailUnited States — standard contractual clauses
Stripe Payments Europe, Ltd.Card payment, subscription and invoices, only if your organisation subscribes. Stripe acts as an independent controller for the payment itself, under its own termsBilling name, email, address, VAT number, payment status; card numbers go to Stripe onlyIreland (EU)
Twilio Inc.WhatsApp channel (sending and receiving messages), if you link a numberPhone number, messages, photos sentUnited States — standard contractual clauses
Telegram Messenger Inc.Receiving the brief over Telegram, only if that channel is enabled and you choose it (not enabled at present)Chat identifier, brief contentOutside the EU — only on your explicit choice of that channel (art. 49.1.a)
Sentry (Functional Software, Inc.)Technical error monitoringNo personal data (sending of identifying data disabled)EU data region
Komoot GmbH (Photon service)Address completion while you enter the propertyThe address as you type itGermany (EU) — OpenStreetMap map data
ipwho.isMay be used, only if the operator switches it on, to resolve a sign-up IP address to an approximate city during an abuse check. Off by defaultThe IP address aloneUnited States — the IP address is sent with no other identifier; no result is kept
DuckDuckGo, Inc.Web search for other companies that do a kind of work, only when a manager asks Paco to look for oneA search phrase naming the kind of work and the town; no personal dataUnited States — no personal data is sent
Google LLC / Microsoft CorporationAccess to your own Gmail / Outlook mailbox, if you connect it (OAuth): reading it, and sending the letters described in section 2.6Access tokens, emails read and sentEU / United States — standard contractual clauses
Mews SystemsProperty management system, if you connect itProperty profile, room listCzechia (EU)
Cloudbeds, Inc.Property management system, if you connect itProperty profile, room listUnited States — standard contractual clauses

For customer properties, these processors and the conditions of their involvement are set out in the data processing agreement, which provides 30 days' notice before any addition.

5. Transfers outside the European Union

Your documents, your register, your mail and, for an organisation subject to the GDPR, the assistant are hosted and processed in the European Union (Germany and France; the encrypted backup copy in the Netherlands). The following may leave the EU, or involve a company established outside it, and this policy says so rather than implying otherwise:

  • the encrypted backup copy: stored in the EU, with a United States company (Backblaze) that cannot read it;
  • the sending of the service's emails (Resend, United States);
  • the chat model (Anthropic, United States), only for organisations whose establishments are all outside the GDPR area and that have not switched to Mistral AI; for an organisation subject to the GDPR the chat model is Mistral AI, in France;
  • a web search for other companies (DuckDuckGo, United States), which carries no personal data;
  • the services you switch on yourself: WhatsApp (Twilio), Telegram, a Google or Microsoft mailbox, the Cloudbeds PMS.

Each of these transfers is covered by the safeguards of Chapter V GDPR, first and foremost the European Commission's standard contractual clauses, or by your explicit choice when you switch a channel on. Fonts are hosted on this site: no public page sends your IP address to Google to display them.

6. Retention periods

DataPeriod
Account and preferencesFor as long as you use the service, then deleted or anonymised within 12 months of closure
Documents, register, tasks and proofsWhile the account is open, then 12 months after closure. The property remains responsible for the periods its own regulations impose; Paco is not its legal archive
Connected mailboxWhile the mailbox stays connected; tokens deleted on disconnection
WhatsApp and Telegram messages, conversations with the assistantAs the account
Sign-up IP address (encrypted)As the account
Demo or access request12 months after the last reply, or until the account it led to is created
Download of a free document12 months after the download or the last exchange
Server logs12 months
Backup copiesKept encrypted in the EU; an automatic deletion schedule is being put in place
Billing data and invoicesFor as long as the account, then 10 years for invoices and accounting records (French Commercial Code, art. L123-22)
Inputs and outputs sent to Mistral AI (document reading and the assistant)Retained by Mistral for 30 rolling days for abuse monitoring on the paid tier Paco uses; not used to train their models. Paco itself keeps no separate copy of those prompts beyond what the account already holds
Consent to product newsUntil withdrawn, then 3 years as proof

7. Security

Measures in place: encryption in transit (HTTPS/TLS), password hashing, encryption of mailbox credentials, PMS tokens and the sign-up IP address, strict separation of data between organisations (multi-tenant isolation), restricted access, hosting in the European Union and backups encrypted before they leave the server.

8. Your rights

Under the GDPR you have the following rights: access, rectification, erasure, restriction of processing, objection, portability of your data, the right to withdraw your consent at any time (without retroactive effect), and the right to give instructions about your data after your death.

Two of these rights can be exercised directly in the application, without writing to us, from Settings › Account, free of charge and whatever the state of your organisation's subscription:

  • "Download my data" gives you a copy of your data in a common format (access and portability);
  • "Delete my account" closes the account and starts the deletion described in section 6 (erasure).

For the other rights, or if you prefer to write to us: contact@pacoapp.io. Proof of identity may be requested. Consent to product news is withdrawn by a simple email to the same address; no news is sent without it. You may also lodge a complaint with the CNIL (Commission nationale de l'informatique et des libertés - www.cnil.fr, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France).

If your account was created by your employer, the employer is the controller for the data it asked you to place there; we pass your request on to the property when it is the one that has to answer it.

9. Artificial intelligence

Paco uses artificial-intelligence models to read documents and to answer the questions asked of the assistant. The assistant's answers are generated automatically and may be inaccurate or incomplete; they are an aid, not legal advice. No decision producing legal effects on you is taken in a fully automated way: every date and every duty the service proposes is presented for a manager to verify. Your data is not used to train the providers' models.

10. United States

The service is hosted in Germany. Mail and documents are always read by Mistral AI, in France. For a hotel whose establishments are all in the United States, or elsewhere outside the GDPR area, the chat model is Anthropic's Claude, in the United States, by default; an administrator can switch it to Mistral AI in Settings (section 2.9).

We do not sell personal information and we do not share it for cross-context behavioural advertising, as those words are used in the California Consumer Privacy Act. We do not claim that the CCPA applies to us today: that statute applies to a business that meets a revenue, volume or sale threshold we have not met.

Access, correction or deletion requests: use the self-service controls described in section 8, or write to contact@pacoapp.io. The hotel remains responsible for the mailbox and documents it connects or uploads, including personal data of its own staff or contractors.

11. Cookies

Cookie use is detailed in our cookie policy.

12. Changes

This policy may be updated; the date of the last update appears at the top of the page. The addition of a processor is announced to customer properties with the notice period set out in the data processing agreement.