Steganomos Back to Homepage

Privacy Policy

Last updated: Março 23, 2026

Disclaimer: This Privacy Policy is provided for informational purposes and describes our data practices in plain language. It does not constitute legal advice. If you have specific legal questions about your rights or our obligations, we recommend consulting a qualified legal professional.

This Privacy Policy describes how rapidbounce ("we", "us", "our", or the "Company"), operating the Steganomos platform ("Steganomos", the "Platform", or the "Service"), collects, uses, stores, shares, and protects personal data. Steganomos is an AI-powered property management platform designed for hotels and accommodation providers, accessible at https://steganomos.com.

rapidbounce is a company registered in Athens, Greece, and serves as the Data Controller for all personal data processed through the Platform. We are committed to compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and all applicable data protection laws.

By accessing or using Steganomos, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of this policy, please discontinue use of the Platform.

Table of Contents

  1. Definitions
  2. Data Controller
  3. Personal Data We Collect
  4. Legal Bases for Processing
  5. How We Use Your Data
  6. AI and Automated Processing
  7. Data Sharing and Sub-Processors
  8. Data Residency and International Transfers
  9. Data Retention
  10. Data Security
  11. Your Rights Under GDPR
  12. Cookies and Tracking Technologies
  13. Children's Privacy
  14. Third-Party Links
  15. Changes to This Policy
  16. Contact Information

1. Definitions

For the purposes of this Privacy Policy:

  • "Personal Data" means any information relating to an identified or identifiable natural person.
  • "Data Subject" means the individual to whom the Personal Data relates (e.g., a property owner, staff member, or guest).
  • "Data Controller" means the entity that determines the purposes and means of processing Personal Data - in this case, rapidbounce.
  • "Data Processor" means an entity that processes Personal Data on behalf of the Data Controller.
  • "Sub-Processor" means a third-party service provider engaged by us to assist in processing Personal Data.
  • "Property" means a hotel, accommodation, or hospitality business managed through the Platform.
  • "Guest" means an individual who makes a reservation or communicates with a Property through the Platform.

2. Data Controller

The Data Controller responsible for processing your Personal Data is:

rapidbounce
Athens, Greece
Email: achilleas@karydis.com
Website: https://steganomos.com

As a company with fewer than 250 employees, we are not required to appoint a Data Protection Officer (DPO) under Article 37 of the GDPR. However, all data protection inquiries may be directed to the email address above, and we will respond within the timeframes prescribed by applicable law.

3. Personal Data We Collect

We collect and process different categories of Personal Data depending on your role and interaction with the Platform:

3.1 Property Owner and Staff Data

Data Category Examples Purpose
Identity data Full name, business name, MHTE registration number Account creation, regulatory compliance
Contact data Email address, phone number, business address Account management, communication, support
Authentication data Hashed passwords, session tokens Secure access to the Platform
Business data Property details, room configurations, rate settings, financial reports Service delivery, revenue management
Billing data Invoice details, transaction history (payment card data is processed exclusively by Stripe and never stored by us) Billing, tax compliance

3.2 Guest Data

Data Category Examples Purpose
Identity data Full name, nationality Reservation management, legal obligations
Contact data Email address, phone number Reservation confirmations, guest communication
Reservation data Check-in/check-out dates, room type, special requests, booking channel Service fulfillment
Communication data Emails, WhatsApp messages, web chat transcripts with the Property Guest support, AI-assisted response generation
Payment data Transaction amounts and status (card details are processed by Stripe and never stored on our servers) Payment processing, refunds

3.3 AI-Generated Data

When guest communications are processed through our AI pipeline, the following derived data may be generated:

  • Sentiment analysis scores (numeric values reflecting perceived tone)
  • Suggested replies for Property staff review
  • Language detection results
  • Topic classification labels
  • Knowledge base matches

This data is generated to assist Property staff and is always subject to human review before any outbound communication is sent to guests. See Section 6 for more details on AI processing.

3.4 Usage and Technical Data

  • IP address, browser type, operating system, device type
  • Pages visited, features used, timestamps of interactions
  • Referral sources and session duration
  • Error logs and performance data

4. Legal Bases for Processing

Under the GDPR, we process Personal Data only when we have a valid legal basis. The following table outlines the legal bases we rely upon:

Processing Activity Legal Basis (GDPR Article)
Providing the Platform and its features to Property owners Performance of a contract (Art. 6(1)(b))
Processing guest reservations and communications Performance of a contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f))
AI-assisted analysis of guest messages Legitimate interests (Art. 6(1)(f)) - improving service quality and response times
Sending transactional emails (e.g., reservation confirmations) Performance of a contract (Art. 6(1)(b))
Sending marketing communications Consent (Art. 6(1)(a))
Maintaining financial records and tax compliance Legal obligation (Art. 6(1)(c))
Website analytics and performance monitoring Legitimate interests (Art. 6(1)(f))
Fraud prevention and platform security Legitimate interests (Art. 6(1)(f))
Responding to legal requests from authorities Legal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, we have conducted balancing tests to ensure our interests do not override the fundamental rights and freedoms of Data Subjects. You may request details of these assessments by contacting us.

5. How We Use Your Data

We use the Personal Data we collect for the following purposes:

  • Service delivery: Creating and managing Property accounts, processing reservations, synchronizing availability and rates, generating invoices, and facilitating guest communication across email, WhatsApp, and web chat channels.
  • AI-powered assistance: Analyzing guest messages to generate suggested replies, performing sentiment analysis, detecting languages, and matching incoming queries against the Property's knowledge base. All AI outputs are reviewed by staff before being sent to guests.
  • Revenue management: Providing rate recommendations, competitor analysis, occupancy forecasting, and performance analytics to help Properties optimize their pricing strategy.
  • Payment processing: Facilitating payments between guests and Properties through our integration with Stripe. We do not store credit card numbers, CVVs, or other sensitive payment credentials on our servers.
  • Customer support: Responding to your inquiries, troubleshooting issues, and providing technical assistance.
  • Platform improvement: Analyzing usage patterns, identifying bugs, and developing new features to enhance the Platform.
  • Legal compliance: Maintaining records as required by Greek tax law, responding to lawful requests from regulatory authorities, and enforcing our Terms of Service.
  • Security: Detecting and preventing unauthorized access, fraud, and other malicious activities through rate limiting, web application firewall rules, and monitoring.

We do not sell, rent, or trade your Personal Data to any third party for marketing or advertising purposes.

6. AI and Automated Processing

Steganomos incorporates artificial intelligence to help Property staff respond to guest communications more efficiently. We are committed to transparent and responsible use of AI. This section explains how AI processes your data.

6.1 What the AI Does

  • Analyzes incoming guest messages (email, WhatsApp, web chat) to understand intent, detect language, and assess sentiment.
  • Generates suggested reply drafts for Property staff to review, edit, and approve before sending.
  • Matches guest inquiries against the Property's knowledge base to provide accurate, context-aware responses.
  • Classifies conversations by topic and urgency to help staff prioritize their workload.

6.2 Privacy Safeguards in AI Processing

  • PII masking: Before any guest message is sent to an AI model, personally identifiable information (such as names, email addresses, phone numbers, and payment references) is detected and masked using Microsoft Presidio, an open-source PII detection library. The AI model receives only the masked version of the message.
  • Safety screening: All AI-generated outputs are screened through Google Cloud Model Armor before being presented to staff. This safety layer filters for harmful, inappropriate, or policy-violating content.
  • Human-in-the-loop: AI-generated replies are always presented as drafts. No message is sent to a guest without explicit action by an authorized staff member. High-confidence replies may be sent automatically only when the Property has explicitly enabled this feature in their AI settings.
  • Semantic caching: To reduce redundant AI calls and improve response times, we maintain a semantic cache of anonymized query-response pairs. This cache is automatically invalidated when the Property's knowledge base changes.
  • No model training: Your data is not used to train or fine-tune the underlying AI models. We use commercially licensed AI services (Google Gemini and Anthropic Claude) under terms that prohibit the use of customer data for model training.

6.3 Automated Decision-Making

The Platform does not make any decisions with legal or similarly significant effects on individuals based solely on automated processing. AI outputs serve as recommendations for human staff. Guests have the right to contest any communication they receive and to request human review by contacting the Property directly or by reaching out to us at the contact details provided in Section 16.

7. Data Sharing and Sub-Processors

We share Personal Data only with third-party service providers ("Sub-Processors") who are necessary for the operation of the Platform. Each Sub-Processor is bound by a Data Processing Agreement (DPA) and is required to process data only as instructed by us.

7.1 List of Sub-Processors

Sub-Processor Purpose Data Location
Google Cloud Platform (Google LLC) Cloud infrastructure, database hosting, serverless compute, AI services (Vertex AI, Gemini), analytics (BigQuery), task scheduling EU (europe-west1, Belgium)
Anthropic (Anthropic PBC) AI text analysis and response generation (Claude models) United States (with EU Standard Contractual Clauses)
Stripe (Stripe, Inc.) Payment processing, Stripe Connect Express accounts for Properties EU infrastructure; certified PCI DSS Level 1
Mailgun (Sinch Email) Transactional and operational email delivery EU
Meta Platforms (Meta Platforms, Inc.) WhatsApp Business messaging channel EU/US (Meta's data processing terms apply)
WebHotelier (WebHotelier Technologies Ltd.) Reservation synchronization and channel management EU
Freshdesk (Freshworks, Inc.) Customer support ticketing (being migrated to in-house solution) EU/US
Google Analytics (Google LLC) Website traffic analytics and user behavior analysis EU
Google Tag Manager (Google LLC) Tag management for analytics and marketing scripts EU

7.2 When We May Disclose Data

Beyond our Sub-Processors, we may disclose Personal Data in the following limited circumstances:

  • Legal obligations: When required by Greek or EU law, court order, or governmental regulation.
  • Protection of rights: When necessary to protect the rights, property, or safety of rapidbounce, our users, or the public.
  • Business transfers: In connection with a merger, acquisition, or sale of assets, in which case the acquiring entity will be bound by the terms of this Privacy Policy.
  • With your consent: In any other circumstance where we have obtained your explicit prior consent.

8. Data Residency and International Transfers

All primary data processing and storage occurs within the European Union, specifically in the europe-west1 (Belgium) region of Google Cloud Platform. This includes our databases, application servers, AI processing infrastructure, task queues, and analytics pipelines.

In limited cases, data may be processed by Sub-Processors with infrastructure outside the EU (e.g., Anthropic Claude for AI text analysis). Where such transfers occur, we ensure that appropriate safeguards are in place, including:

  • EU Standard Contractual Clauses (SCCs) as approved by the European Commission.
  • Adequacy decisions by the European Commission, where applicable (e.g., the EU-US Data Privacy Framework).
  • Data Processing Agreements that contractually bind the Sub-Processor to GDPR-equivalent protections.

Additionally, before any guest message content is sent to AI models that may be processed outside the EU, personally identifiable information is masked (see Section 6.2), reducing the sensitivity of any data that crosses jurisdictional boundaries.

9. Data Retention

We retain Personal Data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. The following retention periods apply:

Data Type Retention Period Basis
Guest messages (email, WhatsApp, web chat) 90 days from creation GDPR data minimization principle (Art. 5(1)(e))
AI-generated suggestions and sentiment scores 90 days (aligned with message retention) GDPR data minimization
Property owner account data Duration of the contractual relationship plus 12 months Contractual necessity and legitimate interests
Reservation data Duration of the contractual relationship plus up to 5 years Greek tax law and regulatory requirements
Financial records and invoices Up to 10 years Greek tax law (Art. 13 of the Greek Tax Procedures Code)
Usage analytics and logs 26 months Platform improvement and security
Cookie data See Section 12 (varies by cookie type) Consent or legitimate interests

Message deletion is automated via a scheduled task that runs weekly and removes messages older than the 90-day retention period. Anonymized or aggregated data that cannot be used to identify individuals may be retained indefinitely for analytical purposes.

10. Data Security

We implement appropriate technical and organizational measures to protect Personal Data against unauthorized access, alteration, disclosure, or destruction. These measures include:

10.1 Technical Measures

  • Encryption in transit: All data transmitted between users and the Platform is encrypted using TLS 1.2 or higher.
  • Encryption at rest: All data stored in Google Cloud databases is encrypted at rest using AES-256 encryption managed by Google Cloud.
  • Web Application Firewall (WAF): Google Cloud Armor protects the Platform against common web threats, including SQL injection, cross-site scripting (XSS), remote code execution, and protocol attacks.
  • Rate limiting: API endpoints are protected by rate limiting (300 requests per minute per IP address) to prevent abuse.
  • Access control: Role-based access controls ensure that users can only access data relevant to their Properties and assigned permissions.
  • Secret management: API keys, tokens, and credentials are stored in Google Cloud Secret Manager and are never hardcoded or exposed in application code.
  • Ingress restrictions: Production services accept traffic only through the load balancer; direct access to backend services is blocked.

10.2 Organizational Measures

  • Access to production data is limited to authorized personnel on a need-to-know basis.
  • We maintain audit logs of administrative actions and data access events.
  • We conduct periodic reviews of our security practices and Sub-Processor compliance.

10.3 Breach Notification

In the event of a Personal Data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the competent supervisory authority (the Hellenic Data Protection Authority - HDPA) within 72 hours of becoming aware of the breach, in accordance with Article 33 of the GDPR. Where the breach is likely to result in a high risk, we will also notify the affected Data Subjects without undue delay, in accordance with Article 34 of the GDPR.

11. Your Rights Under GDPR

As a Data Subject, you have the following rights under the GDPR. You may exercise any of these rights by contacting us at achilleas@karydis.com.

Right Description
Right of access (Art. 15) You may request a copy of the Personal Data we hold about you, along with information about how it is processed.
Right to rectification (Art. 16) You may request correction of inaccurate or incomplete Personal Data.
Right to erasure (Art. 17) You may request deletion of your Personal Data where it is no longer necessary for the purposes for which it was collected, or where you withdraw consent. This right is subject to legal retention obligations.
Right to restriction (Art. 18) You may request that we limit the processing of your Personal Data in certain circumstances (e.g., while we verify the accuracy of your data).
Right to data portability (Art. 20) You may request to receive your Personal Data in a structured, commonly used, machine-readable format and to transmit it to another controller.
Right to object (Art. 21) You may object to processing based on legitimate interests, including profiling. You may also object to processing for direct marketing purposes at any time.
Right not to be subject to automated decisions (Art. 22) You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. Steganomos does not make such decisions (see Section 6.3).
Right to withdraw consent (Art. 7(3)) Where processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.

We will respond to all valid requests within 30 days of receipt. In complex cases, or where we receive a high volume of requests, this period may be extended by a further 60 days, in which case we will inform you of the extension and the reasons for it.

If you believe that our processing of your Personal Data infringes the GDPR, you have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA):

Hellenic Data Protection Authority
Kifisias 1-3, 115 23, Athens, Greece
Phone: +30 210 6475600
Website: www.dpa.gr

12. Cookies and Tracking Technologies

The Platform uses cookies and similar technologies to ensure proper functionality, enhance user experience, and collect analytics data. A cookie consent banner is displayed on your first visit, and you may manage your preferences at any time.

12.1 Types of Cookies

Cookie Type Purpose Duration Legal Basis
Strictly necessary Authentication, session management, CSRF protection, security Session or up to 14 days Exempt from consent (ePrivacy Directive Art. 5(3))
Functional Language preferences, UI settings, selected property Up to 12 months Consent
Analytics Google Analytics (page views, session duration, feature usage) Up to 26 months Consent

12.2 Managing Cookies

You may disable or delete cookies through your browser settings at any time. Please note that disabling strictly necessary cookies may impair the functionality of the Platform. Most browsers allow you to:

  • View and delete existing cookies
  • Block all or specific cookies
  • Set preferences for individual websites

For more information on managing cookies, visit www.aboutcookies.org.

13. Children's Privacy

Steganomos is a business-to-business platform designed for hospitality professionals. The Platform is not directed at individuals under the age of 16. We do not knowingly collect Personal Data from children. If we become aware that we have inadvertently collected data from a child under 16, we will take prompt steps to delete such data. If you believe we may have collected data from a minor, please contact us immediately.

14. Third-Party Links

The Platform may contain links to third-party websites or services (for example, booking engines, payment portals, or social media platforms). We are not responsible for the privacy practices or content of these external sites. We encourage you to review the privacy policy of any third-party service before providing your Personal Data.

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other operational reasons. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page.
  • Notify registered users via email or through an in-platform notification where the change materially affects how their data is processed.
  • Where required by law, obtain fresh consent before implementing changes to data processing activities that rely on consent as a legal basis.

We encourage you to review this page periodically to stay informed about how we protect your data.

16. Contact Information

If you have questions about this Privacy Policy, wish to exercise your data protection rights, or have concerns about how we handle your Personal Data, please contact us:

rapidbounce - Data Protection
Athens, Greece
Email: achilleas@karydis.com
Website: https://steganomos.com

We aim to respond to all inquiries within 5 business days and to all formal data protection requests within 30 days, as required by the GDPR.


© 2026 rapidbounce. All rights reserved.
Steganomos is a registered trademark of rapidbounce.

© 2026 Steganomos. All rights reserved.

Privacy Policy Terms of Service