BE-A Privacy Policy

Publication date: 1 October 2026

1. Who we are

BE-A is a software service by FLAE ROBOTICS a.s., Company ID (IČO) 21631671, VAT ID CZ21631671, registered office Pujmanové 1753, Nusle, 140 00 Prague, Czech Republic (“FLAE”, “we”). Contact for all privacy questions: info@flaerobotics.ai.

This policy covers the BE-A service. Our websites have their own privacy policies.

2. What BE-A does, and who is responsible for which data

BE-A helps hotels answer their guests. A hotel connects its own communication channels to BE-A: its e-mail inbox, its WhatsApp Business phone number, its phone line, and in some hotels an avatar screen in the lobby. BE-A shows guest messages to the hotel’s reception staff, prepares replies with artificial intelligence, and can look up availability and make bookings in the hotel’s reservation system.

Data

Who decides how it is used (controller)

FLAE’s role

Messages, calls and booking data of hotel guests

the hotel

FLAE processes the data only on the hotel’s behalf and on its written instructions, under a data processing agreement

Accounts of hotel staff who use BE-A, and contact details of our business customers

FLAE

controller

If you are a hotel guest, the hotel’s own privacy policy tells you why the hotel uses your data. Questions about a stay or a booking go to the hotel. You can also contact us; see sections 8 and 12.

Our data processing agreement with each hotel is part of the BE-A Terms of Service: https://be-a.ai/pdf/terms-of-service-and-dpa-en.pdf.

3. Data about hotel guests

3.1 What data BE-A receives

  • E-mail: the sender’s name and e-mail address, the content of the message, and attachments.
  • WhatsApp: the guest’s WhatsApp phone number and profile name, the content of messages between the guest and the hotel (including photos and documents the guest sends), and technical data about each message: time, delivery and read status, and error codes from WhatsApp.
  • Phone calls: the caller’s phone number, a recording of what the caller says, and a written transcript of the call. If reception takes over the call, that part of the call is transcribed too.
  • Avatar in the hotel: what the guest says to the avatar screen.
  • Bookings: the name, contact details, dates of stay, room and price that are needed to check availability or to create or change a booking in the hotel’s reservation system.
  • Online check-in, if the hotel uses it: the details that the law requires the hotel to collect from its guests, read from the identity document that the guest sends: name, date of birth, sex, nationality, document type, number, issuing country and expiry date. BE-A sends them to the hotel’s reservation system and keeps them, and the photo of the document, with the conversation.

BE-A never asks for payment card numbers and never sends them to a reservation system. If a guest writes or says card details anyway, they stay in the message or call transcript until they are deleted.

3.2 WhatsApp in particular

BE-A receives WhatsApp data from Meta’s WhatsApp Business Platform only for the phone numbers that a hotel has connected to BE-A. It does not receive a guest’s contacts, other chats, or any data from the guest’s Facebook or Instagram account. Meta Platforms Ireland Ltd operates WhatsApp; its own terms and privacy policy apply to the guest’s use of WhatsApp.

3.3 What BE-A uses guest data for

  • to show guest messages and calls to the hotel’s reception staff;
  • to prepare replies with artificial intelligence. Staff check a reply before it is sent, except for the topics for which the hotel has allowed automatic replies;
  • to look up availability and to create or change bookings when the guest asks for it;
  • to send the hotel’s own WhatsApp message templates, for example a welcome message or a check-in reminder before arrival;
  • to find and fix faults in the service.

BE-A does not sell guest data, does not use it for advertising, and does not use one hotel’s guest data for another hotel. BE-A makes no decision with legal effect about a guest on its own; reception staff handle anything that BE-A cannot answer.

3.4 Artificial intelligence

BE-A uses AI models from Microsoft (Azure OpenAI Service) in data centres in Germany and Sweden. Under Microsoft’s terms, Microsoft does not use this data to train its models.

4. Data about hotels and hotel staff

  • Staff accounts: name, work e-mail address, role, and a record of actions in BE-A (for example, who sent which reply). We use it to provide the service, to secure it, and to support the hotel. Legal basis: performance of our contract with the hotel, and our legitimate interest in a secure service.
  • Connecting a WhatsApp Business account: when a hotel connects its account through Meta’s signup flow, BE-A receives the identifiers of the hotel’s WhatsApp Business account and phone number, and an access key that lets BE-A send and receive messages for that account. The person who connects the account logs in to Facebook in Meta’s own window. BE-A does not receive that person’s Facebook password and does not store any data from their Facebook profile.
  • Business contacts and billing: names, e-mail addresses and phone numbers of our contacts at the hotel, and invoicing data. Legal basis: our contract, and our legal obligations for accounting.

5. Service providers

We use these providers to run BE-A. Each of them has a contract with us that limits how they may use the data. This table is also the current list of approved sub-processors that Annex B of our data processing agreement refers to.

Provider

What it does

Where it processes data

Microsoft Ireland Operations Ltd (Microsoft Azure)

hosting, database, file storage, AI models, and speech-to-text for Czech and Slovak calls

European Union: Ireland, Germany, Sweden

LangChain, Inc. (LangSmith)

technical logs of AI processing, used to find and fix faults

EU region (the Netherlands); the company is in the USA

Meta Platforms Ireland Ltd

WhatsApp Business Platform

see Meta’s own policy

Twilio Ireland Limited, with Twilio Inc.

connects phone calls to BE-A: phone numbers, call duration, call audio

USA

ElevenLabs

turns BE-A’s replies into speech, and the caller’s speech into text for languages other than Czech and Slovak

USA

The hotel’s own e-mail provider and reservation system are chosen by the hotel. BE-A connects to them on the hotel’s instructions.

6. Transfers outside the European Union

BE-A stores guest data in the European Union. Three providers can process some data in the United States:

  • LangChain, Inc.: under the European Commission’s Standard Contractual Clauses, which are part of LangChain’s data processing addendum.
  • Twilio: Twilio Inc. is certified under the EU–US Data Privacy Framework, and Twilio also has Binding Corporate Rules approved by EU data protection authorities.
  • ElevenLabs: certified under the EU–US Data Privacy Framework.

7. How long we keep data

  • Raw technical notifications from WhatsApp: deleted after 30 days.
  • Recordings of what callers say: deleted after 30 days.
  • Technical logs of AI processing (LangSmith): deleted after 180 days.
  • Backups: deleted after 30 days.
  • Conversations, transcripts and booking requests: kept for as long as the hotel uses BE-A, unless the hotel or the guest asks for deletion earlier. When the contract with the hotel ends, the hotel has 30 days to take its data out of BE-A. After that we delete it, and the last backups are deleted 30 days later.
  • Staff accounts: until the hotel removes the account or the contract ends.

8. How to ask for deletion of your data

You can ask us to delete your data at any time. You do not need a BE-A account for this.

  1. Send an e-mail to info@flaerobotics.ai with the subject “Delete my data”.
  2. Tell us the hotel you contacted, and the e-mail address or phone number you used.
  3. We confirm that the request comes from you. For a WhatsApp number, we can send a code to that number.
  4. We delete your conversations, messages, recordings and attachments from BE-A within 30 days, and we tell the hotel. We then confirm the deletion to you.

You can also send the request to the hotel. The hotel can pass it to us. The hotel’s own systems (for example its reservation system) are outside BE-A; the hotel answers for them.

9. Your other rights

You have the right to access your data, to correct it, to restrict or object to its processing, and to receive it in a portable format. For data that the hotel controls, we help the hotel answer your request.

You have the right to complain to the supervisory authority: Úřad pro ochranu osobních údajů (Office for Personal Data Protection), Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, www.uoou.cz.

10. Security

Connections to BE-A are encrypted. Data is stored in Microsoft Azure data centres in the European Union. Only authorised FLAE staff can access it, and only when they need it to run or support the service. Access keys and passwords that hotels give to BE-A are stored encrypted.

11. Changes to this policy

We publish every new version on this page and change the date at the top. We tell our hotel customers about important changes before they take effect.

12. Contact

FLAE ROBOTICS a.s., Pujmanové 1753, Nusle, 140 00 Prague, Czech Republic. E-mail: info@flaerobotics.ai.

© FLÆ Robotics 2026

Copyright FLÆ Robotics 2024

© FLÆ Robotics 2024

Privacy policy