MyaGuide, AI guest guides and virtual concierge
How it WorksPricingAgenciesHostsDemoLoginStart with MyaGuide
Legal Center

MyaGuide Legal

Security Policy

Technical and organizational measures for platform and data protection.

Effective Date
1 June 2026
Last Updated
12 August 2026

MyaGuide Security Policy

Document: Security Policy

Version: 1.1

Effective Date: 1 June 2026

Last Updated: 12 August 2026

1. Purpose and Scope

1.1. This Security Policy describes the technical and organizational measures implemented by Van Riemsdijk & Karman S.L. (trading as MyaGuide) ("Company") to protect the confidentiality, integrity, and availability of the Platform and Personal Data processed through it.

1.2. This Policy is incorporated into, and forms part of, the Terms of Service and the DPA. Capitalized terms not defined here have the meaning given in the Terms of Service.

1.3. This Policy describes the measures in place as of the effective date and may be updated as the Company's security program evolves, provided that updates will not materially decrease the overall level of protection during an active Subscription Term without Customer's prior notice.

2. Organizational Measures

2.1. The Company maintains internal policies governing access to systems and data, applies the principle of least privilege to employee and contractor access, and limits access to Personal Data, including PIN-protected guest information, to personnel with a legitimate need to know.

2.2. Personnel and contractors with access to Personal Data are subject to confidentiality obligations.

2.3. The Company maintains an internal process for reviewing and approving the engagement of new Sub-processors, consistent with the DPA.

3. Technical Measures

3.1. Encryption in transit. Data transmitted between End Users, Customers, and the Platform is encrypted using industry-standard transport encryption (TLS).

3.2. Encryption at rest. PIN-protected guest information and other sensitive Personal Data are stored encrypted at rest.

3.3. Access controls. Access to production systems and data stores is restricted through authentication and role-based access controls. PIN-protected information is additionally access-restricted at the application layer, such that it is disclosed to an End User only upon entry of the applicable PIN.

3.4. Network and application security. The Company applies reasonable, industry-standard controls to protect the Platform against common web application threats, and reviews its configuration (including transport security and HTTP security headers) on an ongoing basis as part of its security program.

3.5. Logging and monitoring. The Company maintains logging and monitoring processes designed to detect anomalous or unauthorized activity affecting the Platform.

3.6. Change management. Changes to production systems follow an internal review process intended to reduce the risk of unintended security impact.

3.7. Backups. The Company maintains backup processes designed to support recovery of Customer Content in the event of data loss, consistent with the Support & Service Policy.

4. PIN-Protected Information — Authorized Access

4.1. PIN-protected information within the Approved Property Guide (such as access codes, alarm codes, or Wi-Fi credentials) is disclosed to an End User only upon entry of the PIN applicable to the relevant Property and stay.

4.2. Customer controls the issuance, content, and rotation of PINs and is responsible for ensuring that a PIN is shared only with the intended End User(s) for the relevant stay, and for promptly changing a PIN where Customer has reason to believe it has been disclosed to an unintended recipient.

4.3. The Company is not responsible for disclosure of PIN-protected information resulting from a PIN that Customer, or an End User to whom the PIN was properly disclosed, has shared with an unauthorized third party.

4.4. Customer should treat PINs with the same care as any other access credential, including avoiding embedding a PIN in a public or easily guessable location.

5. Incident Response

5.1. The Company maintains an internal process for identifying, triaging, containing, and remediating security incidents affecting the Platform.

5.2. In the event of a confirmed Personal Data breach, the Company will notify affected Customers without undue delay, consistent with Section 8 of the DPA, and will provide information reasonably available to assist Customer in meeting its own legal notification obligations, including to supervisory authorities and affected individuals where applicable.

5.3. The Company will take reasonable steps, proportionate to the nature and severity of the incident, to remediate the underlying cause and to prevent recurrence.

6. Responsible Disclosure of Vulnerabilities

6.1. The Company welcomes good-faith reports of suspected security vulnerabilities. Reports should be sent to mya@myaguide.com with sufficient detail to allow reproduction of the issue.

6.2. Individuals reporting a vulnerability in good faith, without accessing, modifying, or exfiltrating data beyond what is strictly necessary to demonstrate the issue, without conducting testing prohibited under Section 2.4 of the Acceptable Use Policy (which requires prior written authorization for security testing), and without publicly disclosing the vulnerability until the Company has had a reasonable opportunity to assess and remediate it (coordinated disclosure), will not be pursued for that report by the Company.

6.3. The Company will acknowledge receipt of a good-faith vulnerability report and will use reasonable efforts to assess and, where appropriate, remediate the issue in a timeframe proportionate to its severity.

7. Sub-processor Security

7.1. The Company requires Sub-processors that process Personal Data to maintain technical and organizational measures that are no less protective than those described in this Policy, consistent with Section 5 of the DPA.

8. Customer Responsibilities

8.1. Customer is responsible for safeguarding its own Account credentials, for configuring PIN protection appropriately for sensitive Guide content, and for promptly notifying the Company of any suspected unauthorized access to its Account, in accordance with Section 4.4 of the Terms of Service. See also Section 4 of this Policy regarding PIN issuance and authorized access.

9. Relationship to Other Documents

This Policy should be read together with the DPA (Section 4.3 and Annex 3), the Privacy Policy (Section 10), and the Acceptable Use Policy (Section 2.4 and Section 5).

10. Contact

Security reports and questions: mya@myaguide.com

Van Riemsdijk & Karman S.L. (trading as MyaGuide)

Established in Jávea/Xàbia, Spain · NIF/VAT: ESB21983580

Legal documents
TermsPrivacyCookiesAcceptable UseAI TransparencySupport & ServiceDPA
MyaGuide, AI guest guides and virtual concierge

Mya, your AI Guest Concierge for holiday rentals, built to save time and improve every guest stay.

CompanyAbout MyaGuideMyaGuide for Good ♡Contact
ResourcesPartner Program
LegalLegal Center
© 2026 MyaGuide. All rights reserved.