Privacy policy
How we process the data of people who visit otello.ai and complete forms on the website. It applies only to the website. The Otello service used by properties is governed by the contractual documents signed during activation.
Data controller
The controller of the data collected through this website is Brots S.r.l., Via Roberto da Sanseverino 95, 38122 Trento (TN), Italy, VAT number IT02570890224. For any request concerning your data, write to info@otello.ai or, by certified email, to brots@pec.it.
What this policy covers
This policy applies solely to the otello.ai website: browsing its pages and the information you submit through forms. It does not apply to the Otello service used by customer properties. That processing is governed by the dedicated privacy notice and agreements, including the DPA, signed during activation.
Data we collect
We collect only the data needed to operate the website and respond to your requests:
- Browsing and security data: IP address, date and time, requested URL, referrer, technical headers, browser type, operating system, request outcome and anti-abuse identifiers derived from IP addresses or email addresses
- Cookies and similar technologies: language preference, consent choice and temporary demo booking confirmation. To document consent, rejection and withdrawal, we also retain a server receipt containing random identifiers, policy versions, categories, action, language and dates, without raw IP, contact data, URLs, referrers or form data. After the relevant consent, Google Analytics 4 processes pseudonymous online identifiers, page views, navigation, visit source, device, browser, approximate geographic area and conversion events, while Google Ads processes click identifiers, attribution and conversions. UTM parameters and click identifiers are also stored in the session after Marketing consent; details are provided in the Cookie policy
- Data submitted through active forms: name, work email, phone number, property or company, type and number of rooms, PMS, objective, topic and message; for demos, also the time slot and technical booking data; for guides and newsletters, also the requested content and subscription choice. Free-text fields must not contain guest data, special categories of data or unnecessary information
How we use data
We use data solely for the following purposes, each with its own legal basis. We do not sell your data or use it for purposes other than those stated.
- To manage contacts, commercial enquiries, guides and demo bookings: performance of your request and pre-contractual measures; for requests from existing customers, performance of the contract may apply. Fields marked as required are necessary to reply or make a booking; without those data, we cannot complete the request
- To send newsletters and promotional communications only with consent, which may be withdrawn at any time without affecting previous processing; downloading a guide is not conditional on subscribing
- To provide, protect and improve the website, prevent abuse and maintain technical records: legitimate interests balanced against users' rights. Measuring use and conversions with Google Analytics 4 requires Analytics consent; attributing campaigns and conversions, creating audiences and any remarketing with Google Ads requires Marketing consent
- To comply with legal obligations and defend rights. We do not make decisions based solely on automated processing that produce legal or similarly significant effects, and we do not sell personal data
Who we share data with
Data is also organised in Brots' internal Partner Portal and CRM, which is not a recipient separate from the controller. Data may be accessed only by authorised personnel and the parties required for each flow: Vercel Inc. for hosting, CDN and website functions; Supabase Pte. Ltd. for the data infrastructure supporting requests and bookings; Google Ireland Limited and Google group companies for Tag Manager, Analytics 4, Ads and Conversion Linker after the relevant consent, as well as the Google Workspace entity applicable to Brots' contract for Calendar and Meet when you book a demo. Google acts as a processor or independent controller depending on the service and applicable terms. Customer Match, enhanced conversions and the transmission of user-provided data are not active without a separate assessment. We may also disclose data to advisers bound by confidentiality and to authorities or other recipients provided for by law. We neither transfer nor sell personal data.
How we protect data
We apply appropriate security measures: data in transit is encrypted using TLS/SSL, access is restricted to authorised staff and we carry out periodic checks on our systems.
How long we retain data
We retain data only for as long as needed for the purposes for which it was collected:
- Contact and demo requests, including appointments and related operational records: no more than 24 months from the last relevant interaction; requests for a guide without newsletter subscription: no more than 12 months. A new relevant interaction restarts the period. If a contractual relationship begins, the necessary data follow the terms of the relationship documents, which are separate from this policy
- Newsletter: until consent is withdrawn and in any event no longer than 24 months from the last relevant interaction or confirmation, unless renewed. Evidence of consent, withdrawal and the minimum suppression list may be retained, without promotional use, for up to 10 years for compliance and the defence of rights
- Pseudonymous cookie-choice receipts: 24 months from server receipt. The deletion deadline is stored with each receipt and expired records are removed by the retention process; the local choice record lasts six calendar months
- Google Tag Manager: standard HTTP logs for up to 14 days. Google Analytics 4: user and event data in explorations for up to 14 months to support annual seasonal comparisons; aggregate reports may remain available for longer. Google Ads: conversion and campaign data according to the configured windows and platform retention periods; cookies and identifiers follow the durations in the Cookie policy. Withdrawal stops new optional collection and removes related first-party cookies where they can be technically identified
- Ordinary logs: no more than 30 days; isolated security events: no more than 12 months, or longer only when required for an incident or proceeding. Backups: deletion or overwriting within 90 days of primary removal. Accounting or contractual documents: 10 years when required by law; in the event of a dispute, only relevant data remain until it is resolved
Your rights
You may request access, rectification, erasure, restriction, portability where applicable, object to processing based on legitimate interests and withdraw consent by writing to the controller's contact details. We respond without undue delay and normally within one month; in complex cases, the deadline may be extended by a further two months, and we will inform you within the first month. If you believe that processing breaches applicable law, you may lodge a complaint with the Italian Data Protection Authority.
Transfers outside the EU
Vercel and some Supabase and Google companies or subprocessors may process data in the United States, Singapore or other countries listed in their current disclosures. The website database's primary region is configured in Frankfurt, but support, the global network, service control and subprocessors may involve access from outside the EEA. Depending on the circumstances, transfers rely on an adequacy decision, the EU-US Data Privacy Framework for certified entities or the European Commission's standard contractual clauses, with supplementary measures where necessary. You may request information and a copy or description of the applicable safeguards by writing to info@otello.ai.
Updates
Any changes to this policy are published on this page with the date it was last updated. Previous versions are available on request.
