Privacy Policy

Last updated: April 25, 2026

KozyHost S.L. · Calle Aragón 3, Sotogrande 11310, Cádiz, Spain

1. Introduction

KozyHost S.L. ("we," "us," or "our") operates the KozyHost platform (kozyhost.com), a multi-tenant SaaS platform for the hospitality and retail industries. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform, including our back-office tools, storefronts, and integrations with third-party services.

This policy complies with the General Data Protection Regulation (GDPR), the Spanish Ley Orgánica 3/2018 (LOPDGDD), and the Ley 34/2002 de Servicios de la Sociedad de la Información (LSSI-CE).

2. Data Controller & Data Processor Roles

KozyHost S.L. as Data Processor: When vendors use the platform to manage their customer data (reservations, orders, customer profiles), KozyHost S.L. acts as a data processor under GDPR Article 28. Vendors are the data controllers for their customers' personal data.

KozyHost S.L. as Data Controller: For vendor account data, staff information, billing details, and platform usage data, KozyHost S.L. acts as the data controller.

Vendors are responsible for providing their own privacy notices to their customers and for ensuring that their use of customer data through the platform complies with applicable data protection laws.

3. Information We Collect

3.1 Information You Provide

  • Account registration data (name, email, phone number)
  • Business information (vendor name, address, tax ID, business type)
  • Payment and billing details
  • Staff information (name, email, phone, role, employment details)
  • Content you create (menus, products, posts, media, legal pages)
  • Customer reservation data (name, email, phone, booking preferences)
  • Communications with our support team

3.2 Information from Third-Party Services

When you connect third-party accounts (Google Business Profile, Facebook, Instagram, WhatsApp), we receive:

  • OAuth access tokens (stored encrypted using AES-256-GCM)
  • Business page/account identifiers and names
  • Reviews and ratings from connected profiles
  • Page insights and analytics (when authorized)

We do not access your personal social media feed, private messages, or contact lists. We only request permissions necessary for business page management.

3.3 Automatically Collected Information

  • Device and browser information (type, version, operating system)
  • IP address and approximate geographic location
  • Usage patterns and interaction data
  • Session cookies for authentication and security

4. Legal Basis for Processing

We process personal data under the following legal bases (GDPR Article 6):

  • Contractual necessity (Art. 6(1)(b)): Processing necessary to provide the Service, manage accounts, and fulfill subscription agreements
  • Legitimate interest (Art. 6(1)(f)): Platform security, fraud prevention, service improvement, and analytics
  • Consent (Art. 6(1)(a)): Marketing communications, non-essential cookies, and optional AI features
  • Legal obligation (Art. 6(1)(c)): Tax compliance, regulatory reporting, and data breach notifications

5. How We Use Your Information

  • Provide, operate, and maintain the platform and its features
  • Process transactions, manage subscriptions, and handle billing
  • Sync and display reviews from connected platforms
  • Publish posts to connected social media accounts on your behalf
  • Sync menus and business information to Google Business Profile
  • Send transactional emails (activation, password reset, booking confirmations)
  • Process AI-assisted tasks (document analysis, content generation, translation)
  • Improve our services, develop new features, and fix bugs
  • Ensure platform security, detect fraud, and prevent abuse
  • Comply with legal obligations and respond to lawful requests

6. Marketing Communications

We may send you marketing communications about new features, promotions, or service updates only if you have explicitly opted in to receive such communications (GDPR Article 6(1)(a)).

  • You may opt in to marketing during registration or from your account settings
  • Every marketing email includes a one-click unsubscribe link
  • You may withdraw consent at any time without affecting the lawfulness of prior processing
  • We do not sell or share your email address with third parties for their marketing purposes
  • Transactional emails (password resets, billing notifications, security alerts) are not considered marketing and will always be sent

7. Data Storage & Security

Your data is stored on secure servers within the European Union. We implement industry-standard security measures including:

  • AES-256-GCM encryption for sensitive credentials (OAuth tokens, API keys, payment credentials)
  • Argon2id password hashing with per-user salts
  • TLS 1.2/1.3 encryption for all data in transit
  • Role-based access control (RBAC) with per-vendor data isolation
  • Regular security assessments and vulnerability monitoring
  • Automated database backups with encrypted storage
  • Multi-factor authentication support for administrative accounts

8. Third-Party Integrations & Sub-Processors

8.1 Google Business Profile

We use Google's API to sync menus, manage reviews, and update business information. Your Google credentials are stored encrypted and can be disconnected at any time. See Google's Privacy Policy.

8.2 Meta (Facebook & Instagram)

We use Meta's Graph API to publish posts and manage business pages. We request only permissions necessary for page management. See Meta's Privacy Policy.

8.3 Sub-Processors

We use the following categories of sub-processors:

  • Infrastructure hosting (EU-based servers)
  • Email delivery services (transactional and marketing)
  • Payment processing gateways (Redsys, Stripe, etc.)
  • AI processing (self-hosted models for document analysis and content generation)

All sub-processors are bound by data processing agreements ensuring GDPR compliance.

9. International Data Transfers

Your data is stored and processed within the European Economic Area (EEA). We do not transfer personal data to countries outside the EEA unless:

  • The destination country has an adequacy decision from the European Commission
  • Appropriate safeguards are in place (Standard Contractual Clauses)
  • You have explicitly consented to the transfer
  • The transfer is necessary for the performance of a contract (e.g., publishing to US-based social media platforms at your request)

10. Data Sharing

We do not sell your personal data. We may share information with:

  • Service providers: hosting, email delivery, payment processing — bound by data processing agreements
  • Connected platforms: Google, Meta, WhatsApp — only data you explicitly authorize
  • Legal requirements: when required by law, regulation, court order, or legal process
  • Business transfers: in connection with a merger, acquisition, or sale of assets, with prior notification

11. AI Processing & Automated Decisions

The platform uses AI-powered features for document processing, content generation, translation, and business intelligence. Regarding AI processing:

  • AI models are self-hosted within our infrastructure — your data is not sent to external AI providers
  • AI processing is used to assist, not to make autonomous decisions with legal or significant effects
  • No purely automated decision-making (as defined in GDPR Article 22) is performed without human oversight
  • You may opt out of AI-assisted features at any time from your account settings
  • AI-generated content (including legal documents) must be reviewed by the user before publication

12. Data Breach Notification

In accordance with GDPR Article 33, in the event of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, KozyHost S.L. will:

  • Notify the relevant supervisory authority (Agencia Española de Protección de Datos) within 72 hours
  • Notify affected data subjects without undue delay when the breach is likely to result in a high risk (GDPR Article 34)
  • Notify affected vendors (as data controllers) to enable them to fulfill their own notification obligations
  • Document the breach, its effects, and the remedial actions taken

13. Your Rights

Under GDPR and the LOPDGDD, you have the right to:

  • Access your personal data (Art. 15)
  • Rectify inaccurate or incomplete data (Art. 16)
  • Request erasure ("right to be forgotten") (Art. 17)
  • Restrict processing of your data (Art. 18)
  • Data portability — receive your data in a structured, machine-readable format (Art. 20)
  • Object to processing based on legitimate interest (Art. 21)
  • Withdraw consent at any time without affecting the lawfulness of prior processing (Art. 7(3))
  • Disconnect third-party integrations from the platform settings
  • Lodge a complaint with the Agencia Española de Protección de Datos (www.aepd.es)

To exercise your rights, contact us at privacy@kozyhost.com. We will respond within 30 days as required by law.

14. Data Retention

We retain your data according to the following schedule:

  • Active accounts: Data is retained for as long as your account is active
  • Deleted accounts: Personal data (name, email, phone, address) is purged within 30 days of account deletion
  • Disconnected integrations: Associated tokens and data are deleted within 30 days
  • Billing records: Anonymized transaction records are retained for the legally required period (6 years under Spanish tax law)
  • Audit logs: Security and access logs are retained for 12 months
  • Backups: Data may persist in encrypted backups for up to 90 days after deletion

15. Cookies

We use the following categories of cookies:

  • Essential cookies: Required for authentication, session management, and security. These cannot be disabled.
  • Analytics cookies: Used to understand usage patterns and improve the Service. Only enabled with your consent.

We do not use third-party advertising or tracking cookies. You can manage cookie preferences through the cookie consent banner displayed on your first visit, or through your browser settings.

16. Children's Privacy

Our platform is designed for business use and is not directed at individuals under 16 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 16, we will take steps to delete it promptly.

17. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page, updating the "Last updated" date, and sending a notification to your registered email address. Continued use of the Service after changes become effective constitutes acceptance of the updated policy.

18. Data Protection Officer

For questions about this Privacy Policy, to exercise your data protection rights, or to lodge a complaint about our data handling practices, contact our Data Protection Officer:

KozyHost S.L.
Calle Aragón 3, Sotogrande 11310, Cádiz, Spain

DPO Email: privacy@kozyhost.com

Supervisory Authority: Agencia Española de Protección de Datos (AEPD)

Platform: kozyhost.com

Preferências de cookies

Utilizamos cookies para garantir que a plataforma funciona corretamente e para melhorar a sua experiência. Cookies não essenciais só são utilizados com o seu consentimento. Saber mais