1. Controller
The controller for this website and for HelloJonny processing carried out on our own responsibility is:
76467 Bietigheim
Germany
2. Roles in data processing
HelloJonny is provided by accommodation providers such as vacation rentals, holiday homes and hotels for their guests. The data protection role may differ depending on the processing activity:
- Accommodation / host: For content, processes and guest data processed on behalf of the accommodation, the respective accommodation or its operator is generally the controller.
- AIFlow Consulting / HelloJonny: Where we process data on behalf of the accommodation, we act as a processor on the basis of an agreement under Art. 28 GDPR. For our own technical operations, security and website processes, we may ourselves be the controller.
If you use HelloJonny as a guest of a particular accommodation and have a specific privacy request relating to your stay, the accommodation may also be the appropriate contact.
3. What data may be processed?
| Data category | Examples | Purpose |
|---|---|---|
| Technical data | IP address, timestamps, browser/device information, server logs | Service delivery, error analysis, abuse and security prevention |
| Session data | Session ID, property reference, language, timestamps | Associating the chat with the stay and technical service delivery |
| Chat content | Questions, answers, service requests | Handling the request and providing the concierge service |
| Optional uploads | Photos submitted with damage reports | Documenting and forwarding a specific issue |
| Optional location data | Location shared by the user or a location entered manually | Local recommendations, navigation, pharmacies, restaurants, activities |
| Voice input | Audio/transcription data when voice input is enabled | Converting the spoken question into text |
We follow the principle of data minimisation. Please do not provide personal or sensitive data that is not necessary for your request.
4. Purposes and legal bases
Personal data is processed only where there is a legal basis for doing so. Depending on the use case, the following legal bases may in particular apply:
- Art. 6(1)(b) GDPR: where processing is necessary to provide requested functions or to perform a contract or take pre-contractual steps.
- Art. 6(1)(f) GDPR: for legitimate interests such as secure technical operation, error analysis, abuse prevention and improving reliability, provided that these are not overridden by the interests of the data subject.
- Art. 6(1)(a) GDPR: where consent is required and obtained, for example for optional, non-essential functions.
- Art. 6(1)(c) GDPR: where processing or retention is required by law.
5. Chat, AI processing and answers
Chat messages are processed to understand the request, access stored accommodation information and generate a response. Depending on the function, external AI or infrastructure providers may be used as processors or sub-processors.
Chat content should be limited to what is necessary for the request. Particularly sensitive data – such as health data, payment information, identity document data, passwords or intimate/private content – should not be entered unless this is explicitly and strictly required for a service process offered.
AI-generated answers may be incorrect or incomplete. For safety-critical, medical, legal or emergency matters, HelloJonny is not a substitute for qualified professionals or emergency services.
6. Voice input, photos and location
Voice input
If you use voice input, voice data is processed to convert speech into text. Any storage beyond this may only take place where it is necessary for the relevant purpose and is communicated transparently.
Photos / damage reports
For optional photo uploads, submitted images are processed to handle and document the reported matter. Where possible, please photograph only the relevant object or damage and avoid identifiable people, documents or other private information.
Location
Location data is used only if you actively share it or enter a location and use a location-based function. Without location sharing, the accuracy of local recommendations may be limited.
7. Anonymous and pseudonymous analysis
We may analyse usage and quality data to improve HelloJonny, identify common questions, analyse errors and optimise functions. Where possible, such analyses are anonymised so that individuals can no longer be identified.
Where full anonymisation is not technically or professionally possible, data is pseudonymised as far as possible and limited to what is necessary. Personal chat content is not stored indefinitely merely because it could be useful for analysis.
8. Recipients and service providers
Depending on the function enabled, service providers from the following categories may be used to operate HelloJonny:
- Hosting and infrastructure providers
- AI/language model and transcription providers
- Mapping, routing, weather, event or local information services
- Email, notification and automation services
- Monitoring, security and error-analysis services
Where required, data processing agreements under Art. 28 GDPR are concluded with processors. The providers and recipients listed in the final privacy notice must match the actual production configuration of HelloJonny.
9. Transfers to third countries
For individual technical service providers, processing outside the European Union or European Economic Area cannot be completely excluded. A transfer will take place only where the requirements of Art. 44 et seq. GDPR are met, for example on the basis of an adequacy decision or appropriate safeguards such as EU Standard Contractual Clauses.
10. Cookies and local storage
The website may use technically necessary storage mechanisms. For example, your selected light/dark display preference is stored locally in the browser. These functions serve the display you requested and are not used to create an advertising profile.
If non-essential analytics, marketing or tracking technologies are used in the future, they will be used only in accordance with the applicable consent requirements. In Germany, access to or storage of information on end devices is subject in particular to Section 25 TDDDG.
11. Deletion and retention period
We store personal data only for as long as it is required for the relevant purpose or where statutory retention obligations apply. The GDPR does not prescribe one blanket number of days for all such data; purpose limitation and storage limitation are key factors.
- Chat/session data: is deleted or effectively anonymised once it is no longer required to support the stay, handle open matters and provide the intended service, unless legal grounds or unresolved legal/damage cases require longer retention.
- Damage reports: may need to be retained for longer while a damage case is being handled, documented or a claim is being clarified.
- Technical logs: are retained only for an appropriate period for security, error analysis and abuse prevention.
- Fully anonymised statistical data: is no longer personal data under the GDPR and may be used for product and quality analysis for a longer period.
To be finalised before publication: a specific internal retention period should be documented and technically implemented for each relevant data category.
12. Your data protection rights
Where the statutory requirements are met, data subjects have in particular the following rights:
- Access to personal data being processed (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability, where applicable (Art. 20 GDPR)
- Objection to certain processing (Art. 21 GDPR)
- Withdrawal of consent with effect for the future
- Complaint to a competent data protection supervisory authority
Requests can be sent to info@aiflow-con.de. Depending on the processing activity, the relevant accommodation provider may also be the appropriate contact.
13. Data security
We take appropriate technical and organisational measures to protect personal data against loss, manipulation, unauthorised access or unlawful processing. Depending on the system and processing activity, these measures include access restrictions, encryption in transit, authorisation concepts, logging and regular technical review.
14. Minors
As a guest service, HelloJonny is not specifically directed at children for the independent collection of personal data. Parents and guardians should ensure that minors do not enter or upload unnecessary personal or sensitive data.
15. Changes to this privacy policy
We may update this privacy policy if functions, technical processing, service providers or legal requirements change. The version published on this page at the relevant time applies.
Last updated: September 2026

