Your data, handled with care.
MOMI is built by MOMI AI S.r.l.. Three policies cover how we treat personal data: the website you're on now, the hotels that license MOMI, and the WhatsApp assistant your hotel connects for guests. Pick whichever applies below.
- Registered office
- Via Luigi Galvani 24, 20124 Milano (MI), Italy
- VAT · Codice Fiscale
- IT14583970968 · 14583970968
Privacy Policy
How we handle your data when you visit momi-ai.com, contact us, or request a demo.
Last updated 22 July 2026
Who we are
This privacy policy is issued by MOMI AI S.r.l. ("MOMI", "we", "us"), an Italian innovative startup with registered office at Via Luigi Galvani 24, 20124 Milano (MI), Italy. VAT number: IT14583970968 · Tax ID (Codice Fiscale): 14583970968.
We are the data controller for the personal data processed through this website (momi-ai.com) and through any direct interaction you have with us (contact forms, calculators, email).
What this policy covers
This policy explains how we handle personal data when you visit our website, contact us, or request a demo or proposal. It does not cover personal data processed inside the MOMI product on behalf of our hotel customers (for example, hotel guest conversations on WhatsApp). For that processing, MOMI acts as a data processor and the hotel is the controller; the relationship is governed by a separate Data Processing Agreement signed with each hotel.
Information we collect
We collect information in three ways:
a) Information you give us. When you fill in a form on this site (contact, savings calculator, partner enquiry) we collect the fields you submit: name, email, phone, hotel name, room count, country, and any free-text message.
b) Information we collect automatically. When you browse the site we collect technical data through server logs and cookies: IP address, browser type and version, device, referring URL, pages viewed, approximate location (city level), date and time of visit.
c) Information from third parties. If you contact us via LinkedIn or our partners refer you, we receive the contact information you have made available on those platforms.
Why we process your data, and on what legal basis
We process your data for the following purposes:
- To respond to your enquiry (contact form, demo request, partner enquiry) — legal basis: steps prior to entering a contract (Art. 6(1)(b) GDPR).
- To provide the savings calculator — legal basis: your consent (Art. 6(1)(a) GDPR), withdrawable at any time.
- To send commercial communications and updates if you opt in — legal basis: consent (Art. 6(1)(a) GDPR), withdrawable via the unsubscribe link in every email.
- To operate, secure, and improve the website (analytics, abuse prevention, error tracking) — legal basis: our legitimate interest (Art. 6(1)(f) GDPR) in running a functioning website.
- To comply with legal obligations (tax, accounting, responding to authorities) — legal basis: legal obligation (Art. 6(1)(c) GDPR).
Providing the data is not a statutory or contractual requirement. If you choose not to provide it, we simply cannot reply to your enquiry or send you the materials you asked for.
AI and automated processing
MOMI builds AI systems for hotels. We are transparent about how AI is used in connection with this website and our services:
- This website does not run automated decisions about you that produce legal or similarly significant effects (Art. 22 GDPR). The savings calculator returns an indicative figure only and does not affect any contract or your rights.
- We do not train AI models on the personal data you submit through this site. Form submissions are used to reply to you, not as training material.
- Inside our product, the AI assistant interacts with hotel guests on behalf of the hotel. That processing is governed by the hotel's own privacy notice and the Data Processing Agreement signed between the hotel and MOMI.
How long we keep your data
- Contact and demo enquiries: kept for up to 24 months from the last interaction, then deleted unless a commercial relationship begins.
- Marketing list (newsletter, opt-in updates): kept until you unsubscribe or object, and in any case no longer than 36 months from your last interaction with us.
- Server logs and analytics: kept for up to 12 months for security and performance, in aggregated or pseudonymous form.
- Accounting and tax records: kept for the period required by Italian law (currently 10 years).
Who we share your data with
We share data only with the people and providers we genuinely need to operate the site and respond to you. We never sell your data.
- Our team at MOMI (founders, sales, engineering) — strictly on a need-to-know basis.
- Service providers acting as data processors under a written contract (Art. 28 GDPR): cloud hosting, email delivery, analytics, customer relationship management. The current list is available on request at info@momi-ai.com and is published in our cookie policy where relevant.
- Public authorities when required by law (tax, judicial, regulatory).
International data transfers
We prefer service providers based in the EU/EEA. Where a provider is established outside the EEA (for example, certain US-based cloud or AI services), the transfer is protected by the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, an adequacy decision (such as the EU–US Data Privacy Framework). You can request a copy of the safeguards in place by writing to info@momi-ai.com.
How we protect your data
We apply technical and organisational measures appropriate to the risk: encryption in transit (TLS), encryption at rest, role-based access control, principle of least privilege, regular backups, security logging, and prompt patching of dependencies. In the event of a personal data breach affecting your data, we will notify the Garante within 72 hours and inform you when required by Art. 34 GDPR.
Your rights
Under the GDPR you have the following rights regarding your personal data:
- Access — to know whether we process your data and obtain a copy.
- Rectification — to correct inaccurate or incomplete data.
- Erasure ("right to be forgotten") — to ask us to delete your data, subject to legal limits.
- Restriction of processing — to limit how we use your data in specific cases.
- Portability — to receive your data in a structured, machine-readable format and have it transmitted to another controller.
- Objection — to object to processing based on our legitimate interest, including direct marketing at any time.
- Withdraw consent — at any time, without affecting the lawfulness of processing carried out before withdrawal.
- Not be subject to a fully automated decision with legal or significant effects (Art. 22 GDPR). As noted in Section 6, this site does not run such decisions.
In the limited cases set out by Italian law (Art. 2-undecies of Legislative Decree 196/2003), some of these rights may be restricted — for example where exercising them would prejudice the confidentiality obligations we owe to others or an authority's investigation.
How to exercise your rights
Email us at info@momi-ai.com with the right you want to exercise. We reply within 30 days (extendable by two further months for complex requests, with notice). We may need to verify your identity before acting on the request, to protect your data from someone impersonating you. For erasure specifically, step-by-step instructions are published at momi-ai.com/data-deletion.
Keeping recipients up to date
If we correct, delete, or restrict your data, we pass that change on to each recipient we previously shared it with, unless doing so proves impossible or would involve disproportionate effort (Art. 19 GDPR). On request, we will also tell you who those recipients are.
Right to complain to the Garante
If you believe we have not handled your data correctly, you may file a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome — or with the supervisory authority of the EU country where you live or work.
Right to a judicial remedy
Independently of any complaint to a supervisory authority, you have the right to an effective judicial remedy if you consider that your rights under the GDPR have been breached (Art. 79 GDPR). Proceedings may be brought before the courts of the EU country where MOMI is established or where you habitually reside.
Children
This website and our services are aimed at hoteliers and business contacts. We do not knowingly collect data from children under 16. If you believe a child has submitted data, please contact us and we will delete it.
Changes to this policy
When we update this policy, we change the "last updated" date at the top of the page and, for material changes, notify you via email if we have your address or via a notice on the site.
Contact us
For any privacy question, write to info@momi-ai.com. We do not currently have a designated Data Protection Officer; we will appoint one if and when our processing volume requires it under Art. 37 GDPR.
Hotel Client Privacy Policy
How we handle the personal data of the hotels that license MOMI and the business contacts behind each contract.
Last updated 22 July 2026
Who we are and what this policy covers
This privacy policy is issued by MOMI AI S.r.l. ("MOMI", "we", "us"), an Italian innovative startup with registered office at Via Luigi Galvani 24, 20124 Milano (MI), Italy. VAT number: IT14583970968 · Tax ID (Codice Fiscale): 14583970968.
It explains how we process the personal data of the hotels that license the MOMI service and the business contacts behind each account — the people who sign, manage, and are billed for the contract. For this processing MOMI is the data controller.
This policy is separate from our , which covers visitors to momi-ai.com, and from the , which covers the guest conversations we handle on your behalf.
Why we process your data
We process your data for the following purposes:
- To enter into and perform the service agreement — setting up your account, providing the AI service, and handling administration, technical assistance, and operational support.
- To meet accounting, tax, and legal obligations arising from the contractual relationship.
- To send commercial communications, service updates, and information about MOMI to current and prospective business customers.
Legal basis for processing
- Performance of the service agreement you signed (Art. 6(1)(b) GDPR) — for setting up and running the service.
- Compliance with a legal obligation (Art. 6(1)(c) GDPR) — for accounting, tax, and statutory record-keeping.
- Our legitimate interest in promoting our services to business customers (Art. 6(1)(f) GDPR, Recital 47) — for commercial communications. You can object at any time, as explained below.
Data we process
We process ordinary personal data (Art. 4 GDPR) about your business contacts: name and professional role, work email and phone number, and details of the company you represent. We do not process special categories of data (Art. 9 GDPR).
International data transfers
We prefer to keep data within the European Union. Where a transfer outside the EU is strictly necessary, we only rely on providers offering adequate safeguards under Arts. 45-46 GDPR (such as an adequacy decision or the European Commission's Standard Contractual Clauses). You can request a copy of the safeguards in place by writing to info@momi-ai.com.
How long we keep your data
- Contract, administrative, accounting and tax data: kept for the duration of the contract and, in any case, no longer than 10 years after it ends, as required by Italian law (Arts. 2220 and 2946 of the Civil Code).
- Commercial communications: kept until you object or, if there is no interaction, for up to 36 months from your last contact.
Your rights
Under the GDPR you may exercise the following rights by contacting us directly:
- Access (Art. 15 GDPR) — to know whether we process your data and obtain a copy.
- Rectification (Art. 16 GDPR) — to correct inaccurate or incomplete data.
- Erasure (Art. 17 GDPR) — to have your data deleted, subject to legal limits.
- Restriction (Art. 18 GDPR) — to limit how we use your data in specific cases.
- Portability (Art. 20 GDPR) — to receive your data in a structured, machine-readable format.
- Objection (Art. 21 GDPR) — to object to processing based on our legitimate interest, including direct marketing at any time.
- Withdraw consent (Art. 7 GDPR) — at any time, without affecting the lawfulness of processing carried out before withdrawal.
To exercise any of these, email us at info@momi-ai.com. In the limited cases set out by Italian law (Art. 2-undecies of Legislative Decree 196/2003), some of these rights may be restricted.
Right to object
You have the right to object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(e) or (f) GDPR — including direct marketing. When you object to marketing, we stop. For other processing, we stop unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is needed to establish, exercise, or defend a legal claim (Art. 21 GDPR).
Keeping recipients up to date
If we correct, delete, or restrict your data, we pass that change on to each recipient we previously shared it with, unless doing so proves impossible or would involve disproportionate effort (Art. 19 GDPR). On request, we will also tell you who those recipients are.
Security breaches
We report any personal data breach to the Italian Garante and, where it is likely to pose a high risk to your rights and freedoms, to you, in line with Arts. 33 and 34 GDPR.
Complaints and judicial remedies
If you believe we have processed your data in breach of the GDPR, you may lodge a complaint with the Garante per la protezione dei dati personali — in the EU country where you habitually reside or work, or where the alleged breach took place (Art. 77 GDPR).
Independently of any such complaint, you also have the right to an effective judicial remedy (Art. 79 GDPR), before the courts of the EU country where MOMI is established or where you habitually reside.
WhatsApp Service Privacy Policy
How data is handled inside the MOMI AI assistant your hotel connects to WhatsApp.
Last updated 26 June 2026
Who we are and what this policy covers
This privacy policy is issued by MOMI AI S.r.l. ("MOMI", "we", "us"), an Italian innovative startup with registered office at Via Luigi Galvani 24, 20124 Milano (MI), Italy. VAT number: IT14583970968 · Tax ID (Codice Fiscale): 14583970968.
It explains how personal data is processed through the MOMI AI assistant operating on WhatsApp ("the Service") — the AI concierge that hotels connect to their WhatsApp Business Account, via the WhatsApp Business Cloud API, to communicate with their guests. MOMI operates its own Meta Business account and links each hotel's WhatsApp Business Account to a MOMI-managed number.
This policy is separate from our , which covers visitors to momi-ai.com.
Our role: data controller and data processor
- Guest conversation data (messages exchanged between a hotel and its guests): the hotel is the data controller and MOMI acts as a data processor on the hotel's behalf, under a signed Data Processing Agreement. We process this data only on the hotel's documented instructions.
- Account, configuration, billing, security and log data relating to the hotels and staff who use MOMI: here MOMI is the data controller.
Data we process
- Guest data (as processor): WhatsApp phone number, WhatsApp profile name, message content (text, images, audio, documents you send), timestamps, delivery and read status, and conversation metadata.
- Hotel and staff account data (as controller): name, work email, phone, hotel name, login credentials, and Service configuration.
- Technical data: IP address, device and application identifiers, and server logs.
Why we process your data
- To deliver and route WhatsApp messages between a hotel and its guests.
- To generate AI assistant responses on the hotel's behalf.
- To operate, secure and improve the Service (reliability, abuse prevention, error tracking).
- To comply with legal obligations (tax, accounting, responses to authorities).
AI processing and sub-processors
To generate replies, guest messages may be processed by AI providers acting as our sub-processors under data-processing agreements:
- Mistral AI — EU-hosted; data stays within the EEA.
- DeepSeek — run on EU-hosted infrastructure; data stays within the EEA.
- Anthropic — United States; protected by SCCs / EU–US Data Privacy Framework.
- OpenAI — United States; protected by SCCs / EU–US Data Privacy Framework.
We contract these providers to use the data only to provide the Service, and where each provider offers the option, we opt out of having your data used to train their models.
International data transfers
We prefer providers based in the EU/EEA. Where a provider is established outside the EEA (for example, Anthropic and OpenAI in the United States), the transfer is protected by the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the EU–US Data Privacy Framework. You can request a copy of the safeguards in place by writing to info@momi-ai.com.
How long we keep data
- Guest conversation data: retained only as long as necessary to provide the Service and on the hotel's documented instructions under the Data Processing Agreement; deleted when no longer needed or on the hotel's request.
- Account data: kept for the duration of the hotel's relationship with MOMI, then deleted or archived in line with applicable legal retention periods.
- Server logs: kept for up to 12 months for security and performance.
Your rights and how to delete your data
Under the GDPR you have the right to access, rectify, erase, restrict, port, and object, and to withdraw consent at any time.
To request deletion of your data: message the hotel you were in contact with (the data controller), or email us at info@momi-ai.com. Where MOMI acts as processor, we will action your request or forward it to the controlling hotel without undue delay. Step-by-step instructions are published at momi-ai.com/data-deletion. You may also complain to the Garante per la protezione dei dati personali or your local supervisory authority.
How we protect your data
We apply technical and organisational measures appropriate to the risk: encryption in transit (TLS) and at rest, role-based access control, principle of least privilege, regular backups, security logging, and prompt patching. In the event of a personal data breach affecting your data, we notify the relevant authority within 72 hours and inform you when required by Art. 34 GDPR.
Children
The Service is provided in a hospitality context and is not directed at children under 16. We do not knowingly process data from children. If you believe a child has provided data, contact us and we will delete it.
Changes and contact
When we make material changes we update the "last updated" date at the top of this page. For any privacy question, write to info@momi-ai.com.
Write to us and we'll help you access, correct, or delete your data — or answer anything else about how MOMI handles it.