Legal · Privacy

Your data, handled with care.

MOMI is built by MOMI AI S.r.l.. Three policies cover how we treat personal data: the website you're on now, the hotels that license MOMI, and the WhatsApp assistant your hotel connects for guests. Pick whichever applies below.

Registered office
Via Luigi Galvani 24, 20124 Milano (MI), Italy
VAT · Codice Fiscale
IT14583970968 · 14583970968
Last updated 22 July 2026

Privacy Policy

How we handle your data when you visit momi-ai.com, contact us, or request a demo.

Last updated 22 July 2026

Who we are

This privacy policy is issued by MOMI AI S.r.l. ("MOMI", "we", "us"), an Italian innovative startup with registered office at Via Luigi Galvani 24, 20124 Milano (MI), Italy. VAT number: IT14583970968 · Tax ID (Codice Fiscale): 14583970968.

We are the data controller for the personal data processed through this website (momi-ai.com) and through any direct interaction you have with us (contact forms, calculators, email).

What this policy covers

This policy explains how we handle personal data when you visit our website, contact us, or request a demo or proposal. It does not cover personal data processed inside the MOMI product on behalf of our hotel customers (for example, hotel guest conversations on WhatsApp). For that processing, MOMI acts as a data processor and the hotel is the controller; the relationship is governed by a separate Data Processing Agreement signed with each hotel.

Information we collect

We collect information in three ways:

a) Information you give us. When you fill in a form on this site (contact, savings calculator, partner enquiry) we collect the fields you submit: name, email, phone, hotel name, room count, country, and any free-text message.

b) Information we collect automatically. When you browse the site we collect technical data through server logs and cookies: IP address, browser type and version, device, referring URL, pages viewed, approximate location (city level), date and time of visit.

c) Information from third parties. If you contact us via LinkedIn or our partners refer you, we receive the contact information you have made available on those platforms.

Why we process your data, and on what legal basis

We process your data for the following purposes:

  • To respond to your enquiry (contact form, demo request, partner enquiry) — legal basis: steps prior to entering a contract (Art. 6(1)(b) GDPR).
  • To provide the savings calculator — legal basis: your consent (Art. 6(1)(a) GDPR), withdrawable at any time.
  • To send commercial communications and updates if you opt in — legal basis: consent (Art. 6(1)(a) GDPR), withdrawable via the unsubscribe link in every email.
  • To operate, secure, and improve the website (analytics, abuse prevention, error tracking) — legal basis: our legitimate interest (Art. 6(1)(f) GDPR) in running a functioning website.
  • To comply with legal obligations (tax, accounting, responding to authorities) — legal basis: legal obligation (Art. 6(1)(c) GDPR).

Providing the data is not a statutory or contractual requirement. If you choose not to provide it, we simply cannot reply to your enquiry or send you the materials you asked for.

Cookies and similar technologies

This site does not currently use cookies for analytics, advertising, or tracking. We use only your browser's local storage to remember your language preference (English or Italian) so you don't have to set it on every visit. This stays on your device and is never sent to us or to third parties.

If we add analytics or other cookies in the future, we will publish a Cookie Policy and ask for your consent through a banner before any non-essential cookie is set.

AI and automated processing

MOMI builds AI systems for hotels. We are transparent about how AI is used in connection with this website and our services:

  • This website does not run automated decisions about you that produce legal or similarly significant effects (Art. 22 GDPR). The savings calculator returns an indicative figure only and does not affect any contract or your rights.
  • We do not train AI models on the personal data you submit through this site. Form submissions are used to reply to you, not as training material.
  • Inside our product, the AI assistant interacts with hotel guests on behalf of the hotel. That processing is governed by the hotel's own privacy notice and the Data Processing Agreement signed between the hotel and MOMI.

How long we keep your data

  • Contact and demo enquiries: kept for up to 24 months from the last interaction, then deleted unless a commercial relationship begins.
  • Marketing list (newsletter, opt-in updates): kept until you unsubscribe or object, and in any case no longer than 36 months from your last interaction with us.
  • Server logs and analytics: kept for up to 12 months for security and performance, in aggregated or pseudonymous form.
  • Accounting and tax records: kept for the period required by Italian law (currently 10 years).

Who we share your data with

We share data only with the people and providers we genuinely need to operate the site and respond to you. We never sell your data.

  • Our team at MOMI (founders, sales, engineering) — strictly on a need-to-know basis.
  • Service providers acting as data processors under a written contract (Art. 28 GDPR): cloud hosting, email delivery, analytics, customer relationship management. The current list is available on request at info@momi-ai.com and is published in our cookie policy where relevant.
  • Public authorities when required by law (tax, judicial, regulatory).

International data transfers

We prefer service providers based in the EU/EEA. Where a provider is established outside the EEA (for example, certain US-based cloud or AI services), the transfer is protected by the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, an adequacy decision (such as the EU–US Data Privacy Framework). You can request a copy of the safeguards in place by writing to info@momi-ai.com.

How we protect your data

We apply technical and organisational measures appropriate to the risk: encryption in transit (TLS), encryption at rest, role-based access control, principle of least privilege, regular backups, security logging, and prompt patching of dependencies. In the event of a personal data breach affecting your data, we will notify the Garante within 72 hours and inform you when required by Art. 34 GDPR.

Your rights

Under the GDPR you have the following rights regarding your personal data:

  • Access — to know whether we process your data and obtain a copy.
  • Rectification — to correct inaccurate or incomplete data.
  • Erasure ("right to be forgotten") — to ask us to delete your data, subject to legal limits.
  • Restriction of processing — to limit how we use your data in specific cases.
  • Portability — to receive your data in a structured, machine-readable format and have it transmitted to another controller.
  • Objection — to object to processing based on our legitimate interest, including direct marketing at any time.
  • Withdraw consent — at any time, without affecting the lawfulness of processing carried out before withdrawal.
  • Not be subject to a fully automated decision with legal or significant effects (Art. 22 GDPR). As noted in Section 6, this site does not run such decisions.

In the limited cases set out by Italian law (Art. 2-undecies of Legislative Decree 196/2003), some of these rights may be restricted — for example where exercising them would prejudice the confidentiality obligations we owe to others or an authority's investigation.

How to exercise your rights

Email us at info@momi-ai.com with the right you want to exercise. We reply within 30 days (extendable by two further months for complex requests, with notice). We may need to verify your identity before acting on the request, to protect your data from someone impersonating you. For erasure specifically, step-by-step instructions are published at momi-ai.com/data-deletion.

Keeping recipients up to date

If we correct, delete, or restrict your data, we pass that change on to each recipient we previously shared it with, unless doing so proves impossible or would involve disproportionate effort (Art. 19 GDPR). On request, we will also tell you who those recipients are.

Right to complain to the Garante

If you believe we have not handled your data correctly, you may file a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome — or with the supervisory authority of the EU country where you live or work.

Right to a judicial remedy

Independently of any complaint to a supervisory authority, you have the right to an effective judicial remedy if you consider that your rights under the GDPR have been breached (Art. 79 GDPR). Proceedings may be brought before the courts of the EU country where MOMI is established or where you habitually reside.

Children

This website and our services are aimed at hoteliers and business contacts. We do not knowingly collect data from children under 16. If you believe a child has submitted data, please contact us and we will delete it.

Changes to this policy

When we update this policy, we change the "last updated" date at the top of the page and, for material changes, notify you via email if we have your address or via a notice on the site.

Contact us

For any privacy question, write to info@momi-ai.com. We do not currently have a designated Data Protection Officer; we will appoint one if and when our processing volume requires it under Art. 37 GDPR.

Questions about your data?

Write to us and we'll help you access, correct, or delete your data — or answer anything else about how MOMI handles it.

MOMI AI S.r.l.
Via Luigi Galvani 24, 20124 Milano (MI), Italy
VAT IT14583970968 · Codice Fiscale 14583970968