Last updated: 18 August 2026
Version 2.0.
This policy is issued by BUTLER AI LIMITED (United Kingdom), company number 17113449, operating the Butler AI product ("Butler AI", "we", "us").
"Butler AI" is the product and trading name of BUTLER AI LIMITED. See our Legal Notice.
Roles: For Guest stay, chat, PMS, and in-stay request data processed for a hotel, the hotel is the controller and Butler AI is the processor. For our website, demos, marketing, billing contacts, and our own account security, Butler AI is the controller. If you are a Guest, many requests should be made to the hotel first.
This Privacy Policy explains how personal data is collected, used, disclosed, and safeguarded in connection with the Butler AI hospitality platform and heybutler.io (the "Service"). It should be read with our Terms of Service.
We process personal data under UK GDPR, the Data Protection Act 2018, and, where applicable, EU GDPR and other local laws. If those laws conflict with this policy, the law prevails.
When you visit our sites, book a demo, or create a hotel account, we may collect:
Hotels (Customers) instruct us to process Guest and operational data, which may include:
The hotel determines the purposes of this processing. We process it to provide the Service to that hotel, including generating AI Output. We do not independently decide to market to Guests using hotel-held Guest data except on the hotel's documented instructions.
The Service is not directed at children. Hotels may still process family-stay information. We do not seek special-category data (such as health or religion). If a Guest or hotel submits it (for example accessibility or allergen notes), the hotel must have a lawful basis and we process it only as processor on the hotel's instructions. We may delete or restrict such data where we reasonably believe continued processing is unlawful.
Lawful bases include contract, legitimate interests, consent (where required), and legal obligation. We use controller data to:
On hotel instructions we use Guest and operations data to:
We may create aggregated statistics that do not identify individuals, and use those as controller for Service improvement.
Guest messages and requests are shared with the hotel that deployed the Service. That is the purpose of the product.
We use vetted providers under contract, which may include:
They may process data only as needed to provide their service to us. Hotels authorise these categories as described in the Terms. Material changes will be reflected in this policy or notified to Customers.
We may disclose data if required by law, court order, or regulator, or to protect rights, safety, and the Service. In a merger, acquisition, or asset sale, data may transfer to a successor bound to appropriate protections. We do not sell personal data.
Controller data is kept as long as needed for the purposes above, including statutory accounting periods (typically up to six years for financial records in the UK) and limitation periods for legal claims.
Processor (hotel) data is retained for the subscription and any post-termination period in the Terms or DPA, then deleted or returned on written request except where we must retain copies for security, backups (for a limited backup cycle), or law. Hotels are responsible for setting operational retention that matches their own policies.
We implement technical and organisational measures appropriate to the risk, which may include encryption in transit, access controls, authentication, logging, and staff confidentiality. No method of transmission or storage is completely secure. We do not warrant absolute security. Customers must protect Staff User credentials and configure the Service responsibly.
Depending on your location and our role, you may have rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent where processing is based on consent.
Guests: For stay and chat data processed for a hotel, contact that hotel (the controller). We will redirect or assist the hotel as processor. We may not be able to fulfil a request that would violate the hotel's instructions or another person's rights.
Website and account contacts: Email privacy@heybutler.io. We may need to verify your identity. We will respond within the period required by law.
You may complain to the UK Information Commissioner's Office (ico.org.uk) or, if you are in the EEA, your local supervisory authority. We would appreciate the chance to address concerns first.
Data may be processed in the UK, EEA, United States, or other countries where our providers operate. Where a transfer from the UK or EEA requires a safeguard, we use mechanisms such as the UK International Data Transfer Addendum, EU Standard Contractual Clauses, and provider addenda. "Consent by using the Service" is not our transfer mechanism for restricted transfers.
The Service generates automated Output (replies, classifications, suggestions). Hotels are expected to apply human oversight for decisions that significantly affect Guests (charges, refusals of service, safety). We do not use Guest data we process for hotels to make independent legal or similarly significant decisions about Guests for our own purposes.
We use cookies and similar technologies. Essential cookies are required for the Service. Analytics, functionality, and targeting cookies are used where permitted, including consent where required. You can control cookies in your browser; blocking some cookies may limit features.
Messaging apps, PMS vendors, payment providers, and linked websites have their own privacy terms. We are not responsible for their practices. Enabling an integration is an instruction to share relevant data with that provider.
We may update this policy by posting a new version and changing the date above. Material changes will be notified to Customers where reasonably practicable. Continued use after the effective date constitutes awareness of the updated policy. Controller processing that requires fresh consent will be handled accordingly.
Data-protection contact for BUTLER AI LIMITED:
BUTLER AI LIMITED
Privacy:privacy@heybutler.io
Legal:legal@heybutler.io
Support:support@heybutler.io
Address:12 The Copper Building, Kingfisher Way, Cambridge, England, CB2 8BL
See our Terms of Service for processor terms, liability, and acceptable use.
If you are a California resident, you may have rights to know, delete, and correct personal information and to non-discrimination under US state law, to the extent it applies to us. We do not sell or share personal information as those terms are typically defined for cross-context behavioural advertising, except as cookie tools you consent to may involve. Submit requests to privacy@heybutler.io. We may decline requests that we cannot verify or that conflict with our role as a service provider / processor for a hotel.