MyaGuide Privacy Policy
Document: Privacy Policy
Version: 1.1
Effective Date: 1 June 2026
Last Updated: 12 August 2026
Controller: Van Riemsdijk & Karman S.L. (trading as MyaGuide)
1. Introduction
1.1. This Privacy Policy explains how Van Riemsdijk & Karman S.L. (trading as MyaGuide) ("MyaGuide," "Company," "we," "us," "our"), collects, uses, discloses, and protects Personal Data in connection with the Service.
1.2. This Policy applies to: (a) Customers (hosts, property managers, rental agencies, and hospitality businesses) and their authorized users; and (b) End Users (Guests) who interact with a Digital Guest Guide or with Mya. Where the Company processes Personal Data of End Users on behalf of a Customer, the Company acts as a processor, and the applicable Customer is the controller of that data, as further described in the DPA.
1.3. Capitalized terms not defined in this Policy have the meaning given in the Terms of Service.
1.4. This Policy should be read together with the Cookie Policy, which governs the use of cookies and similar technologies, and the DPA, which governs the Company's processing of Personal Data on behalf of Customers.
2. Who We Are and How to Contact Us
Controller (in respect of Customer account data and the Company's own marketing and administrative activities):
Van Riemsdijk & Karman S.L. (trading as MyaGuide)
MyaGuide is a trading name of Van Riemsdijk & Karman S.L.
Established in Jávea/Xàbia, Spain
NIF/VAT: ESB21983580
Email: mya@myaguide.com
Legal email: mya@myaguide.com
For any question regarding this Policy or the exercise of data protection rights, contact us at the email address above.
3. Categories of Personal Data We Process
3.1. Customer account data
Name, business name, role, email address, phone number, billing address, payment-related identifiers (processed by Stripe; see Section 6), login credentials, and usage data relating to the Account.
3.2. Property and Guide content
Information entered into the Approved Property Guide, which may include property details, house rules, check-in instructions, local recommendations, and Guide-related media. Customer is responsible for ensuring that any Personal Data of third parties included in the Guide (for example, contact details of local service providers) is lawfully included.
3.3. Guest (End User) data
- Identification and contact data provided by or about a Guest in connection with a booking or stay (such as name, language preference, and arrival/departure dates), to the extent input into the Platform by Customer or provided directly by the Guest.
- PIN-protected information: property-specific private information (such as access codes, alarm codes, or Wi-Fi credentials) that is access-restricted by a PIN set by Customer. The Company stores this information in encrypted form and does not access it other than as necessary to provide, secure, or support the Service. Authorized access to this information by an End User is governed by Section 4 of the Security Policy.
- Communications between a Guest and Mya, including chat transcripts, voice inputs (where applicable), and language preferences, processed to provide and improve the AI Concierge function.
3.4. Technical and usage data
Device identifiers, IP address, browser type, log data, and analytics data collected through the Platform and through cookies as described in the Cookie Policy.
3.5. Special category data
The Company does not intentionally collect special categories of Personal Data (as defined under Article 9 GDPR) and asks that Customers and End Users do not submit such data through the Platform unless strictly necessary and lawfully permitted.
4. Purposes, Legal Bases, and Retention
The table below sets out, for each purpose of processing, the categories of Personal Data involved (as described in Section 3), the applicable legal basis under the GDPR, and the applicable retention approach. Retention periods stated here are indicative; the governing retention rules are set out in full in Section 8.
Purpose | Personal data involved | Legal basis (GDPR Art. 6) | Retention |
|---|---|---|---|
Providing the Service | Account data; Guide content; Guest identification/contact data; PIN-protected information; Mya chat data | Performance of a contract (Art. 6(1)(b)) | For the Subscription Term; Mya chat data per Section 8.3 |
Billing and subscription administration | Account data; payment-related identifiers | Performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) | Subscription Term, plus the statutory accounting/tax retention period |
Security and fraud prevention | Technical and usage data; Account data | Legitimate interests (Art. 6(1)(f)) | Limited period proportionate to the risk addressed, or longer where needed to resolve an active incident |
Product improvement | Technical and usage data (aggregated/anonymized) | Legitimate interests (Art. 6(1)(f)) | Anonymized data may be retained indefinitely; identifiable usage data per Section 8.1 |
Communicating with Customer | Account data | Performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) | Subscription Term and a reasonable period thereafter |
Marketing communications | Account contact data | Consent (Art. 6(1)(a)) or legitimate interests, depending on jurisdiction | Until opt-out or withdrawal of consent |
Legal compliance | Account data; other data as relevant to the specific request | Legal obligation (Art. 6(1)(c)) | As required by the applicable legal obligation |
Where Personal Data of a Guest is processed to deliver the Digital Guest Guide or Mya's responses, the Company processes that data as a processor on behalf of the Customer; the applicable legal basis for that processing is determined and held by the Customer as controller, subject to the terms of the DPA.
5. How We Use Trusted Live Sources
5.1. To answer certain End User queries (for example, regarding nearby restaurants or services), the Platform may query Trusted Live Sources such as Google Places and, in future, TripAdvisor or other comparable providers.
5.2. Queries to Trusted Live Sources may include limited contextual information (such as a Property's general location) but the Company does not transmit PIN-protected information or Guide content to Trusted Live Sources for this purpose beyond what is strictly necessary to perform the query.
5.3. Information returned by a Trusted Live Source is presented to the End User with attribution to that source. The Company is not responsible for the accuracy of third-party data obtained from Trusted Live Sources, which may change at any time at its source.
6. Disclosure of Personal Data
We disclose Personal Data to the following categories of recipients, each acting under appropriate contractual safeguards:
(a) Processors providing infrastructure and software services to the Company, including hosting/cloud infrastructure providers, AI model providers used to formulate Mya's responses, customer support tooling, and analytics providers.
(b) Stripe, for payment processing.
(c) Trusted Live Sources, to the limited extent described in Section 5.
(d) Professional advisors (legal, accounting, audit) where necessary.
(e) Authorities, where required by applicable law, regulation, or valid legal process.
(f) A successor entity, in the event of a merger, acquisition, or sale of assets, subject to continued protection of Personal Data under this Policy or an equivalent standard.
A current list of categories of sub-processors is maintained in the DPA Annex and is available on request.
We do not sell Personal Data.
7. International Transfers
7.1. Personal Data may be transferred to, and processed in, countries outside the European Economic Area ("EEA"), including where a sub-processor (such as a hosting or AI model provider) operates outside the EEA.
7.2. Where such a transfer occurs, the Company relies on an appropriate transfer mechanism recognized under applicable Data Protection Laws, such as the European Commission's Standard Contractual Clauses, an adequacy decision, or another lawful transfer mechanism, as further described in the DPA.
8. Data Retention
8.1. The Company retains Personal Data for as long as necessary to provide the Service and for the duration of the Subscription Term, and thereafter for the period necessary to comply with legal, accounting, or reporting obligations, resolve disputes, and enforce the Agreement.
8.2. Upon termination of the Agreement, Customer Content (including Guide content and associated Guest data) is handled in accordance with the data return/deletion provisions of the DPA.
8.3. Chat transcripts between Guests and Mya are retained for a limited period to support quality assurance, abuse prevention, and Service improvement, after which they are deleted or anonymized, except where retention is required by law or necessary to resolve an active dispute.
9. Data Subject Rights
Subject to applicable Data Protection Laws (including the GDPR, where applicable), individuals have the right to:
(a) access the Personal Data we hold about them;
(b) request rectification of inaccurate data;
(c) request erasure of their data, subject to applicable exceptions;
(d) request restriction of, or object to, certain processing;
(e) request data portability, where applicable;
(f) withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing before withdrawal; and
(g) lodge a complaint with a competent data protection supervisory authority, including the Agencia Española de Protección de Datos (AEPD) or the supervisory authority of their place of residence or work.
To exercise these rights, contact us at the email address in Section 2. Where a request relates to data for which a Customer is the controller (such as Guest data within a Digital Guest Guide), we will direct the request to the relevant Customer or assist the Customer in responding, consistent with the DPA.
10. Security
We implement technical and organizational measures designed to protect Personal Data, including encryption of PIN-protected information, access controls, and the other measures described in the Security Policy. No method of transmission or storage is completely secure; further detail and limitations are set out in the Security Policy.
11. Children
The Service is not directed to children, and we do not knowingly collect Personal Data from children. Where a Guest under the age of majority interacts with a Digital Guest Guide as part of a family stay, the data minimization and PIN-protection principles described in this Policy apply equally.
12. Cookies and Similar Technologies
The Platform uses cookies and similar technologies as described in the Cookie Policy, which forms part of this Policy by reference.
13. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified by email or in-Account notice, with the updated version published with a new effective date.
14. Contact
Van Riemsdijk & Karman S.L. (trading as MyaGuide)
MyaGuide is a trading name of Van Riemsdijk & Karman S.L.
Established in Jávea/Xàbia, Spain
NIF/VAT: ESB21983580
Email: mya@myaguide.com
Legal email: mya@myaguide.com
