Legal

Privacy Policy

Last updated: September 30, 2026

1. Introduction

Proptonomy AS ("Proptonomy", "we", "us", or "our"), org. no. 836 984 242, Strandgata 52, 6905 Florø, Norway, operates the Proptonomy platform at app.proptonomy.ai. Proptonomy is an AI-assisted operations platform for property management companies. This Privacy Policy explains what personal data we process, why, where it goes, and the rights you have.

2. Our role: controller and processor

Proptonomy processes personal data in two distinct roles:

  • As a controller for the account data of the people who sign up and use the platform (property managers, their staff, and property owners with portal access).
  • As a processor for the data our customers (property management companies) bring into the platform — guest communications, reservations, owner and property records imported from their systems and channels. For that data, the property management company is the controller and we process it on their documented instructions under a Data Processing Agreement (DPA). Our standard DPA, including the current subprocessor list, is published at proptonomy.ai/dpa.

If you are a guest or property owner whose data appears in the platform, your primary contact for privacy matters is the property management company you communicated with — they decide how your data is used. We assist them in answering your requests.

3. Information we process

  • Account information. Name, email address, phone number, and organization details when an account is created for you.
  • Property & organization data. Rental property details, tasks, checklists, knowledge-base content, photos and documents entered by our customers or their property owners (for example through the owner onboarding portal).
  • Guest & owner communications. Messages our customers connect to the platform — email, WhatsApp, Telegram, LINE, Slack and in-app conversations — including sender identifiers (such as phone numbers), message content, and attached media (photos, videos, voice messages).
  • Data synced from property management systems. Reservations, listings, guest records, calendars, and tasks from PMS platforms our customers connect (for example Guesty, Hostaway, Uplisting, Resly, Lodgify, Hybel, KrossBooking, or AndHamlet). Depending on the integration and operation, this can also include stay dates, guest contact details, message threads, financial records, contracts, checklists, maintenance and housekeeping records, channel settings, and access-control information.
  • Email data. When email integrations (Microsoft 365, Gmail) are connected, we access email metadata (subject, sender, date) and content to sync messages into the Proptonomy inbox, and we send replies from the connected mailbox.
  • Usage & log data. Application logs, feature usage, and technical diagnostics used to operate, secure, and improve the service.

4. How we use information

  • To provide and maintain the platform — inboxes, tasks, onboarding, reporting, and PMS synchronization.
  • To provide AI-assisted operations on behalf of our customers: drafting and sending replies, classifying and routing conversations, creating and scheduling tasks, and keeping records up to date (see section 5).
  • To send service-related notifications.
  • To secure the service, prevent abuse, and keep audit records of actions taken in external systems.
  • To improve and optimize the platform.

We do not sell personal data, and we do not use it for advertising. Where we act as controller, our legal bases under GDPR are performance of a contract (Art. 6(1)(b)) and legitimate interests in operating and securing the service (Art. 6(1)(f)). Where we act as processor, our customer is responsible for the legal basis.

5. AI processing

Proptonomy uses large language models (LLMs) to help property management teams handle communications and operations. When the AI assists with a conversation or task, relevant content — such as message text, media, and the property context needed to answer correctly — is processed by third-party AI model providers through our AI gateway (OpenRouter) solely to generate the response for that request. The current model providers are Xiaomi, Alibaba, and Google, reached through OpenRouter rather than directly; the list is kept in our DPA and can change (see section 7). AI-generated messages and notes are visible in the platform, and detailed activity logs of AI actions are kept so that AI behavior can be reviewed.

Proptonomy does not use your data to train AI models, and we do not use it to build advertising profiles. Content is sent to a model provider only to produce the answer for a given request, not to train that provider's models. This is enforced on every request we send: our AI gateway is instructed to route only to providers that do not retain or train on the content, and a provider that will not accept that restriction is not used. The data-handling and retention terms that apply to the AI providers are set out in our Data Processing Agreement (see sections 7 and 8), which also describes where this processing takes place.

6. Third-party integrations

When you or your organization connect a third-party service, we access only the data needed to provide that integration. The OAuth tokens, API keys, and other credentials used to connect are stored on our servers within the EEA and are used only to operate the connection. You can disconnect any integration at any time, which stops our access going forward. In plain terms, here is what each type of integration lets Proptonomy do.

Property management systems (PMS)

A new PMS connection is two-way by default. Your organization's administrators (and Proptonomy platform administrators) can switch it to read-only; ordinary members cannot change the mode, and every change of mode is recorded. Where a write below is marked guarded, it passes through a single checkpoint: it is refused while the connection is read-only or switched off, and every attempt — sent, failed, or blocked — is recorded in an outbound-write audit log (the action, the target, the time, the outcome, who or what initiated it, and the start of the request content, which can include message text). Your organization can review this log inside the platform. Setting up and renewing the webhooks that keep data in sync is allowed in read-only mode. Guest messages are sent either by a member of your team or by the AI within the reply policy your organization sets. Incoming webhook notifications are kept for 48 hours.

Guesty

Connects over Guesty's official API (or the Guesty Marketplace) using credentials you authorize.

We read:

  • Listings and property details, including address, rooms and beds, photos, amenities, prices, custom fields, and access details held on the listing (such as Wi-Fi and house manual)
  • Owners and ownership records
  • Calendars, availability, and the history of calendar blocks
  • Reservations, including guest name, email address, phone number, stay dates, status, and booking amounts (totals and payouts)
  • Guest records, guest conversations, and attached files
  • Tasks and task comments, tags, and reviews
  • Guesty user accounts on your team (name, email address, phone number), to match them to your Proptonomy contacts
  • On request from an administrator in the AI assistant, other records your Guesty account exposes to the API (for example accounting, payout, or owner-statement records)

We can write:

  • Send guest messages, and post internal notes into the Guesty conversation (including copies of messages from your other channels, if you turn that on)
  • Create and update listings you push from Proptonomy — details, amenities, rooms, availability settings, owners and ownership
  • Update tags, and bulk-update check-in/out times and cleaning fees when an administrator asks
  • Block and unblock calendar dates
  • Create and update tasks, including status, assignee, schedule, and comments
  • Reply to reviews, and turn off Guesty's automatic review of a guest
  • Change the check-in or check-out date or time of a guest's own reservation, after the guest confirms the change
  • Other create or update requests an administrator makes through the AI assistant

All guarded. In either mode, Proptonomy never deletes records, unlists or takes listings offline, cancels reservations, or changes payments or refunds in Guesty.

Hostaway

Connects over Hostaway's official API using the account ID and API key you authorize.

We read:

  • Listings: name, address and location, capacity, rooms, and photos
  • Reservations, including the full history: guest name, email address, phone number, guest count, stay dates, status, price, fees, and confirmation code
  • Guest conversations and attachments (copied into Proptonomy's own storage)
  • Calendars and blocked dates, including the calendar note
  • Guest reviews, including private feedback, synchronized nightly

We can write:

  • Send guest messages
  • Block and open calendar dates; when a staff member asks the AI assistant, also set a nightly price or minimum stay
  • Create or update a listing when your team pushes a property: description, house rules, address, capacity, prices and fees, stay rules, check-in times, Wi-Fi details, amenities, and photos
  • Register the webhook that keeps data in sync

All guarded, except webhook registration, which is still recorded in the audit log.

Uplisting

Connects over Uplisting's official API with the API key you authorize; guest messaging uses Uplisting's messaging API, authorized through the AirDNA sign-in that Uplisting uses.

We read:

  • Properties: name, capacity, bedrooms, and bathrooms
  • Bookings from 30 days back to 12 months ahead: guest name, email address, phone number, guest count, stay dates, status, totals, fees, commission, and booking reference
  • Calendars and blocked dates
  • Guest message threads, including enquiries and booking requests

We can write:

  • Send guest messages
  • Block and open calendar dates
  • Register the webhooks that keep data in sync

Calendar changes are guarded. Read-only mode does not currently stop guest messages or webhook set-up on Uplisting, and these are not recorded in the audit log; to stop Proptonomy messaging guests on Uplisting, set the AI reply policy to read-only or disconnect messaging.

Lodgify

Connects over Lodgify's official API using the API key you authorize.

We read:

  • Properties: name, description, address and location, and room types
  • Bookings: guest name, email address, phone number, guest counts, stay dates, and totals
  • Availability calendars
  • Guest conversations

We can write:

  • Send guest messages on the booking thread
  • Close and reopen nights on the availability calendar (properties with a single room type)
  • Register the webhooks that keep data in sync

Calendar changes are guarded; guest messages are not blocked by read-only mode. Proptonomy does not modify bookings or property details in Lodgify.

Resly

Connects over Resly's official API using the account ID and API key you authorize.

We read:

  • Room types, including address and photos
  • Reservations: guest name, email address, phone number, guest counts, stay dates, arrival time, channel reference, and totals

We can write:

  • Register the webhooks that keep data in sync

Proptonomy does not send messages through Resly or change reservations, rates, or availability in Resly.

KrossBooking

KrossBooking has no API keys, so we sign in with the hotel ID, username, and password your administrator provides, using the interface shipped with KrossBooking's own application. That interface is not fully published and can change if KrossBooking changes it. The password and hotel ID are encrypted at rest; the username and the resulting access token are stored in the protected integration record, restricted by organization-scoped access controls, and never returned through the integrations API.

We read:

  • Rooms (each becomes a property) and room types: name, capacity, bedrooms, bathrooms, size, address and location, check-in/out times, amenities, and photo links
  • Owners: name, company, email address, phone number, and which rooms they own (never tax codes, birth data, or identity documents)
  • Reservations: stay dates, guest name, email address, phone number, guest count, arrival/departure time, totals and currency, status, channel, and booking reference
  • Guest message threads, message content, and attached files (copied into Proptonomy's own storage); messages are not marked as read
  • Calendar blocks, from 30 days back to 12 months ahead
  • Your message templates, stored as internal-only knowledge for your team and the AI
  • On demand, a reservation's online check-in status and guest portal links

We can write:

  • Send guest messages on the reservation's thread
  • Create and cancel calendar blocks on a unit, never over nights held by a reservation

All guarded. Proptonomy platform administrators can also use a fixed, allow-listed set of other KrossBooking operations for support; these pass the same checkpoint and audit log. Proptonomy does not change reservations, rates, channel settings, payments, or documents in KrossBooking.

KrossBooking may require a six-digit code sent by email. During connection and token renewal, Proptonomy can search recent inbound KrossBooking verification messages already synchronized into the same organization's Proptonomy inbox, extract the code, and submit it. We do not copy the email into another organization or store a separate copy of the code. If no matching code is found within the short polling window, the administrator must enter it manually. If your KrossBooking account sends event notifications to Proptonomy, we process the event name, delivery metadata, and identifiers included, and use them only to fetch the current record from KrossBooking.

Hybel

Hybel has no public API, so the connection signs in with the account login you provide.

We read:

  • Properties and tenancies: tenant names, rent, outstanding amounts, and start and end dates
  • Contracts
  • Conversations, attachments, and the profile pictures shown in them
  • Maintenance requests

We can write:

  • Send messages to tenants
  • Post your team's internal notes as landlord comments, if your organization turns on note syncing
  • Switch between the Hybel accounts the login has access to

Read-only mode does not apply to Hybel. Proptonomy does not change properties, contracts, or maintenance requests in Hybel.

AndHamlet

Signs in with the administrator email and password you provide.

We read:

  • Houses: address, description, price, shares, and images
  • House managers and share owners: name, email address, and phone number
  • Stays: dates, guests, status, type, and the booking owner's contact details

Read-only. Proptonomy does not write anything to AndHamlet.

Operations and pricing tools

  • Breezeway — we read properties, task templates, tasks, comments, photos, reservations, and team members, and we create and update tasks, comments, attachments, assignments, and task status.
  • Chekin — we read each reservation's guest registration link and registration status, and the names and form and police-report status of its registered guests. We do not read identity documents, and we write nothing to Chekin.
  • Enso Connect — we read listings, guidebook content, boarding passes, upsells, and guest records. When your team asks, we can switch listings on or off, send a boarding pass or message, and take guest check-in actions such as skipping ID upload, waiving fees, or releasing check-in.
  • PriceLabs and Wheelhouse — we read listings, prices, settings, and reservations with revenue. When your team asks, we can change price limits or settings and set or remove date-specific prices.

Messaging channels

For WhatsApp, Telegram, LINE, and Slack, on the number or account you connect we read:

  • Incoming messages
  • Attached media — photos, video, files, and voice messages

We also send replies on your behalf. Each channel is authorized with its own access token or bot token.

Email

For Microsoft 365 and Gmail, with your OAuth consent we read:

  • Message content
  • Message metadata — subject, sender, and date

We sync these into the Proptonomy inbox and send replies on your behalf. The access you grant covers reading mail and sending mail on the connected mailbox. For Microsoft 365 only, we may also save a reply into the mailbox as a draft for someone on your team to review and send, and a connection may include shared mailboxes you specifically authorize. You can revoke this at any time from your Microsoft or Google account, or by disconnecting the integration.

For Gmail we request only gmail.readonly (read messages) and gmail.send (send a reply). We never create drafts, delete, label, or otherwise modify anything in your mailbox.

Google API Services Limited Use

Proptonomy's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Concretely, Gmail data is used only to provide and improve the inbox and reply features described above. We do not sell it, we do not transfer it except as needed to provide those features or where required by law, we do not use it for advertising, and we do not use it to train generalized AI or machine-learning models. Humans do not read it except with your explicit consent, to resolve a support issue you raise, for security purposes, or where the law requires it.

Who we share, transfer, or disclose Google user data with

Data obtained through Google APIs (the content, metadata, and attachments of messages in a connected Gmail mailbox) is shared, transferred, or disclosed only to the following parties, and only for the purposes stated:

  • People in your own organization. Users of the Proptonomy account that connected the mailbox can read and reply to those messages in the shared inbox. That is the purpose of the integration.
  • Hetzner Online GmbH (Germany and Finland, EEA) — hosting and storage. Synced messages and attachments are held in the Proptonomy database and object storage that Hetzner operates for us. Hetzner does not access the content.
  • OpenRouter, Inc. (USA), and through it the AI model providers it routes to (currently models from Xiaomi, Alibaba, and Google) — AI features. When our assistant drafts a reply, summarizes a thread, or answers a question about a conversation, the message content needed for that request is sent to a model provider solely to generate that response, and not to train or improve that provider's models. See section 5.
  • Law enforcement or regulators — only where we are legally required to disclose, and only to the extent required.

We share Google user data with no one else. In particular we do not sell it, do not share it with data brokers, advertising networks, or analytics providers, and do not transfer it to any other third party for their own purposes. If we ever add or replace a provider that would handle Google user data, we notify affected customers in advance as described in section 7.

We do not use Google Workspace API data, including Gmail message content and metadata, to develop, improve, or train generalized or non-personalized artificial intelligence or machine-learning models. We never use it as training data ourselves, and every AI request we make is sent with an instruction that restricts routing to providers that do not retain or train on the content we send them.

Connected third-party services are independent and also process your data under their own terms. The specific providers involved are listed in our Data Processing Agreement (see section 7).

7. Subprocessors

We use a small number of service providers to run the platform. The main categories are:

  • Hetzner Online GmbH (Germany/Finland, EEA) — server hosting and object storage for the platform, its database, and uploaded files.
  • OpenRouter, Inc. (USA) — AI gateway routing content to large language model providers (currently models from Xiaomi, Alibaba, and Google) for the AI features described in section 5.
  • Messaging and email providers — the channels your organization chooses to connect (for example Meta/WhatsApp, Telegram, LINE, Slack, Microsoft 365, Google, and Mailgun for transactional email). These process messages as independent services under their own terms.
  • Property management systems — the PMS platforms your organization connects (for example Guesty, Hostaway, Uplisting, Resly, Lodgify, Hybel, KrossBooking, and AndHamlet), and the operations and pricing tools it connects (for example Breezeway, Enso Connect, PriceLabs, and Wheelhouse).

The complete, current subprocessor list is part of our Data Processing Agreement.

If we add or replace a subprocessor that handles customer data — including a change to which AI model providers we route to — we will notify affected customers in advance, as set out in our DPA, so they have an opportunity to review and object before the change takes effect.

8. International transfers

The platform, its database, and stored files are hosted within the European Economic Area (EEA). Some subprocessors process data outside the EEA. In particular, our AI gateway (OpenRouter) is based in the United States, and the AI model providers it routes to (currently models from Xiaomi, Alibaba, and Google) process content on infrastructure in the United States and, potentially, other third countries. Depending on your configuration, connected messaging and email services may also process data outside the EEA. Where a transfer outside the EEA takes place, we rely on appropriate safeguards under GDPR Chapter V, such as the EU Standard Contractual Clauses or an adequacy decision, as set out in our DPA.

9. Data storage & security

Data is stored on access-controlled servers within the EEA (our infrastructure provider is Hetzner, in Finland and Germany). We implement appropriate technical and organizational measures to protect data both in transit and at rest, including:

  • Encryption of all traffic in transit (TLS).
  • Encryption at rest of sensitive credentials and secrets — the API keys and client secrets used to connect your integrations.
  • Role-based and organization-scoped access controls, with separation between customer organizations.
  • Audit logging of automated writes to connected property management systems (see section 6).
  • Regular backups with point-in-time recovery and a standby replica in a second EEA data centre, so data can be restored after a failure.
  • Access to production data restricted to authorized personnel who need it to operate the service.

10. Data retention, export & deletion

We retain data for as long as the customer relationship is active or as needed to provide the service.

Export. You can export your organization's conversations and messages from the platform at any time in a portable format (JSON or CSV). If you need a broader export before leaving, we will provide your organization's data on request as set out in our DPA.

Return and deletion on exit. When an organization leaves the platform, we make its data available for export and then return and/or delete it in line with the DPA — ordinarily within 30 days of the request. Individual users may request deletion of their account and associated personal data at any time. Residual copies in server backups are removed as backups rotate.

11. Data breach notification

If we become aware of a personal data breach affecting data we process on behalf of a customer, we will notify that customer without undue delay after becoming aware of it, within the timeframe committed in our Data Processing Agreement, and provide the information they need to meet their own obligations under GDPR Articles 33 and 34. Where we act as controller (for account data), we notify the relevant supervisory authority — in Norway, Datatilsynet — and affected individuals where the law requires it.

12. Your rights

Under GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your data.
  • Object to or restrict processing of your data.
  • Data portability.
  • Withdraw consent at any time, where processing is based on consent.

To exercise these rights, contact us at hello@proptonomy.ai— or, if your data was brought into the platform by a property management company (for example as a guest), contact that company as the controller; we will assist them. You also have the right to lodge a complaint with a supervisory authority. In Norway this is Datatilsynet (datatilsynet.no).

13. Cookies & local storage

The platform does not use advertising or third-party analytics cookies. We use strictly necessary browser storage (such as your sign-in session and interface preferences) to make the application work.

14. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by the "Last updated" date at the top of this page, and customers will be notified of significant changes.

15. Contact us

Proptonomy AS (org. no. 836 984 242), Strandgata 52, 6905 Florø, Norway. If you have questions about this Privacy Policy or our data practices, contact us at hello@proptonomy.ai.

PrivacyTermsDPA