Privacy Policy

Last updated: 18 August 2026

Version 2.0.

Who is responsible for your data

This policy is issued by BUTLER AI LIMITED (United Kingdom), company number 17113449, operating the Butler AI product ("Butler AI", "we", "us").

Company Name
BUTLER AI LIMITED
Company Number
17113449
Registered Office
12 The Copper Building, Kingfisher Way, Cambridge, England, CB2 8BL

"Butler AI" is the product and trading name of BUTLER AI LIMITED. See our Legal Notice.

Roles: For Guest stay, chat, PMS, and in-stay request data processed for a hotel, the hotel is the controller and Butler AI is the processor. For our website, demos, marketing, billing contacts, and our own account security, Butler AI is the controller. If you are a Guest, many requests should be made to the hotel first.

1. Introduction

This Privacy Policy explains how personal data is collected, used, disclosed, and safeguarded in connection with the Butler AI hospitality platform and heybutler.io (the "Service"). It should be read with our Terms of Service.

We process personal data under UK GDPR, the Data Protection Act 2018, and, where applicable, EU GDPR and other local laws. If those laws conflict with this policy, the law prevails.

2. Information we collect

2.1 Data we control (website, sales, accounts)

When you visit our sites, book a demo, or create a hotel account, we may collect:

  • Contact and company details (name, email, phone, job title, property name)
  • Account credentials and authentication identifiers
  • Billing and invoice details (processed via payment providers where used)
  • Support correspondence and call or meeting notes
  • Device, log, and approximate location data (IP address, browser, pages viewed)
  • Cookie and similar identifiers as described in section 10

2.2 Data we process for hotels (Guest and operations data)

Hotels (Customers) instruct us to process Guest and operational data, which may include:

  • Guest contact details, room or reservation identifiers, stay dates
  • Messages, service requests, preferences, feedback, and chat history
  • Loyalty or VIP flags supplied by the hotel
  • Staff user names, roles, and activity in the dashboard
  • Integration payloads from PMS and other hotel systems

The hotel determines the purposes of this processing. We process it to provide the Service to that hotel, including generating AI Output. We do not independently decide to market to Guests using hotel-held Guest data except on the hotel's documented instructions.

2.3 Special category and children's data

The Service is not directed at children. Hotels may still process family-stay information. We do not seek special-category data (such as health or religion). If a Guest or hotel submits it (for example accessibility or allergen notes), the hotel must have a lawful basis and we process it only as processor on the hotel's instructions. We may delete or restrict such data where we reasonably believe continued processing is unlawful.

3. How we use information

3.1 As controller

Lawful bases include contract, legitimate interests, consent (where required), and legal obligation. We use controller data to:

  • Operate the website, demos, and Customer accounts
  • Bill, collect fees, and keep accounting records
  • Provide support and security, prevent fraud and abuse
  • Improve products using aggregated or de-identified analytics
  • Send service notices; send marketing only where permitted (you may opt out)
  • Comply with law and enforce our Terms

3.2 As processor

On hotel instructions we use Guest and operations data to:

  • Deliver messaging, requests, concierge, and staff workflows
  • Generate AI Output for that hotel
  • Maintain logs for security, debugging, and dispute assistance to the hotel
  • Meet the hotel's configured retention and channel settings

We may create aggregated statistics that do not identify individuals, and use those as controller for Service improvement.

4. How we share information

4.1 Hotels

Guest messages and requests are shared with the hotel that deployed the Service. That is the purpose of the product.

4.2 Subprocessors and suppliers

We use vetted providers under contract, which may include:

  • Cloud hosting and storage
  • Communications and messaging channels
  • AI / large-language-model providers (for inference)
  • Payment, analytics, error-monitoring, and support tools

They may process data only as needed to provide their service to us. Hotels authorise these categories as described in the Terms. Material changes will be reflected in this policy or notified to Customers.

4.3 Legal and corporate

We may disclose data if required by law, court order, or regulator, or to protect rights, safety, and the Service. In a merger, acquisition, or asset sale, data may transfer to a successor bound to appropriate protections. We do not sell personal data.

5. Retention

Controller data is kept as long as needed for the purposes above, including statutory accounting periods (typically up to six years for financial records in the UK) and limitation periods for legal claims.

Processor (hotel) data is retained for the subscription and any post-termination period in the Terms or DPA, then deleted or returned on written request except where we must retain copies for security, backups (for a limited backup cycle), or law. Hotels are responsible for setting operational retention that matches their own policies.

6. Security

We implement technical and organisational measures appropriate to the risk, which may include encryption in transit, access controls, authentication, logging, and staff confidentiality. No method of transmission or storage is completely secure. We do not warrant absolute security. Customers must protect Staff User credentials and configure the Service responsibly.

7. Your rights

Depending on your location and our role, you may have rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent where processing is based on consent.

Guests: For stay and chat data processed for a hotel, contact that hotel (the controller). We will redirect or assist the hotel as processor. We may not be able to fulfil a request that would violate the hotel's instructions or another person's rights.

Website and account contacts: Email privacy@heybutler.io. We may need to verify your identity. We will respond within the period required by law.

You may complain to the UK Information Commissioner's Office (ico.org.uk) or, if you are in the EEA, your local supervisory authority. We would appreciate the chance to address concerns first.

8. International transfers

Data may be processed in the UK, EEA, United States, or other countries where our providers operate. Where a transfer from the UK or EEA requires a safeguard, we use mechanisms such as the UK International Data Transfer Addendum, EU Standard Contractual Clauses, and provider addenda. "Consent by using the Service" is not our transfer mechanism for restricted transfers.

9. Automated decision-making and AI

The Service generates automated Output (replies, classifications, suggestions). Hotels are expected to apply human oversight for decisions that significantly affect Guests (charges, refusals of service, safety). We do not use Guest data we process for hotels to make independent legal or similarly significant decisions about Guests for our own purposes.

10. Cookies and similar technologies

We use cookies and similar technologies. Essential cookies are required for the Service. Analytics, functionality, and targeting cookies are used where permitted, including consent where required. You can control cookies in your browser; blocking some cookies may limit features.

11. Third-party sites and channels

Messaging apps, PMS vendors, payment providers, and linked websites have their own privacy terms. We are not responsible for their practices. Enabling an integration is an instruction to share relevant data with that provider.

12. Changes

We may update this policy by posting a new version and changing the date above. Material changes will be notified to Customers where reasonably practicable. Continued use after the effective date constitutes awareness of the updated policy. Controller processing that requires fresh consent will be handled accordingly.

13. Contact

Data-protection contact for BUTLER AI LIMITED:

BUTLER AI LIMITED

Privacy:privacy@heybutler.io

Legal:legal@heybutler.io

Support:support@heybutler.io

Address:12 The Copper Building, Kingfisher Way, Cambridge, England, CB2 8BL

See our Terms of Service for processor terms, liability, and acceptable use.

14. Additional notices for certain regions

If you are a California resident, you may have rights to know, delete, and correct personal information and to non-discrimination under US state law, to the extent it applies to us. We do not sell or share personal information as those terms are typically defined for cross-context behavioural advertising, except as cookie tools you consent to may involve. Submit requests to privacy@heybutler.io. We may decline requests that we cannot verify or that conflict with our role as a service provider / processor for a hotel.