Back to home

Privacy Policy

This policy describes how HITECH GROUP processes users’ personal data in accordance with applicable data protection rules, in particular Regulation (EU) 2016/679 of 27 April 2016 (the “GDPR”), applicable since 25 May 2018, and French Act No. 78-17 on information technology, files and freedoms, as amended.

This Privacy Policy (the “Policy”) aims to inform users clearly, simply and accurately how HITECH GROUP collects and processes personal data in connection with use of the website https://nexo-hotel.com/en/, and the means available to users to retain control over their data and exercise their rights.

Last update of this Policy: 22 July 2026

Article 1 — Definitions

The terms and expressions below, when used with a capital letter in this Policy, have the following meaning:

“Cookies”
Trackers or connection tokens that enable access to information stored on a visitor’s terminal equipment.
“Recipient”
A natural or legal person that receives personal data, whether or not a third party.
“Personal data”
Any information relating to an identified or identifiable natural person, directly (for example by name) or indirectly, in particular by reference to an identifier such as an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person.
“Data subject”
An identified or identifiable natural person whose personal data are processed.
“Controller”
A natural or legal person which, alone or jointly with others, determines the purposes and means of the processing. In this case, HITECH GROUP is the Controller for personal data arising from the Website and related to the Services.
“Website”
HITECH GROUP’s website accessible at https://nexo-hotel.com/en/
“Service”
All features offered on the Website, including presentation of solutions developed by HITECH GROUP, contact requests, booking a demonstration and, where applicable, access to certain online services.
“Processor”
A natural or legal person that processes personal data on behalf of the Controller.
“Third party”
A natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.
“Processing”
Any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
“User”
Any person who visits, consults or uses the Website and the Services offered on it, whether as a visitor, subscriber or registered user of certain Website services.
“Personal data breach”
A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.

The Website presents the NEXO solution, a conversational assistance platform based on artificial intelligence technologies, intended for hotel establishments and their guests.

The solution notably makes it possible to:

  • Respond to Users’ information requests before, during and after their stay;
  • Assist Users with steps relating to their booking, stay or services offered by the establishment;
  • Provide information about the establishment, its facilities, services, surroundings and available activities;
  • Facilitate exchanges between Users and the establishment through different communication channels (notably website, instant messaging, social networks, telephone or any other compatible channel);
  • Where necessary, route requests to a member of the establishment’s staff.

Article 2 — Controller

HITECH GROUP, a simplified joint-stock company with a sole shareholder (SASU) with share capital of €5,000, registered with the Antibes Trade and Companies Register under number 101 382 752, whose registered office is at 2323 Chemin de Saint-Bernard, 06220 Vallauris, France, may process certain of your personal data in connection with use of the Website and, where applicable, management of the Services.

This Policy exclusively concerns processing carried out in connection with the Website.

In this context, HITECH GROUP acts as Controller within the meaning of the GDPR, meaning that it determines the purposes and essential means of the processing described in this Policy.

When the NEXO solution is used by a hotel establishment, that establishment acts as Controller of its guests’ data, and HITECH GROUP acts as Processor. The terms of such processing are set out in the Data Processing Agreement (DPA), available at https://nexo-hotel.com/en/dpa/.

Article 3 — Categories of data subjects

The categories of data subjects concerned by the processing of personal data are as follows:

  • Website Users (Website visitors, representatives, employees or collaborators of hotel establishments using the Website);
  • Prospects (persons who may be contacted in connection with prospecting and/or who have expressed interest in our offers);
  • Persons contacting our customer service;
  • Where applicable, contacts (natural persons) within our partners and service providers.

Article 4 — Collection of personal data

HITECH GROUP collects and processes personal data notably through the following channels:

  • Collection forms submitted in connection with booking a demo and subscribing to offers;
  • Where applicable, during telephone exchanges (inbound and/or outbound calls), notably in connection with presenting our offers;
  • Where applicable, via links sent by SMS or email enabling confirmation of a request and/or expression of a choice.

HITECH GROUP intends to collect only data strictly necessary for the purposes described in this Policy, in accordance with the minimisation principle.

Provision of certain data may be mandatory to enable HITECH GROUP to process a request, provide a Service or perform a contract. Where applicable, the mandatory nature of information is indicated at the time of collection. Failure to provide certain data may make it impossible to achieve the purposes described in this Policy.

Personal data that may be collected include in particular the following:

  • Contact data: email, phone;
  • Identification data: establishment name, first name, last name, address;
  • Data relating to collection and proof of consent: timestamp, medium and collection method, choice expressed (acceptance/refusal);
  • Subscription-related data: subscription references, billing data, payment status, security logs;
  • Telephone exchange data: dates/times, content of exchanges and, where applicable, recordings;
  • Browsing data: data relating to consultation of the Website (pages viewed, time spent, interactions), technical logs;
  • Financial data (where applicable): IBAN, BIC and, where applicable, bank account proof;
  • Data relating to exercise of rights: requests, exchanges and follow-up.

Article 5 — Purposes and legal bases

The purposes for which your personal data are collected are as follows:

ProcessingData concernedLegal basis
Demo / contact request via the WebsiteIdentification and contact dataPre-contractual measures
Management and operation of the ServicesSubscription-related dataContract performance
Customer relationship / customer service (requests, complaints, termination, support)Identification and contact data; telephone exchange dataContract performance
Improvement of Services, security and User experience (statistics, feedback, optimisation)Browsing dataLegitimate interest
Management of telephone exchanges and, where applicable, call recording for quality control / validationTelephone exchange dataLegitimate interest
Website administration and security (maintenance, fraud prevention, technical logs)Browsing dataLegitimate interest
Management of cookies used solely for audience measurement or anonymous statisticsBrowsing dataLegitimate interest
Litigation and pre-litigation managementIdentification and contact data; telephone exchange data; subscription-related dataLegitimate interest
Advanced personalisation, profiling, marketing (where applicable)Consent collection and proof dataConsent
Commercial prospecting (marketing communications)Contact dataLegitimate interest
Compliance with legal and regulatory obligationsData relating to exercise of rightsLegal obligations
Retention for limitation and accounting purposesFinancial dataLegal obligations

Personal data are never used for purposes incompatible with those described above.

In accordance with Article 6 GDPR, each processing activity relies on an identified legal basis, and no special categories of data (sensitive data within the meaning of Article 9 GDPR) are processed in the standard operation of the Services.

Article 6 — Retention periods

HITECH GROUP processes personal data only for as long as necessary to achieve the purposes for which they were collected, including to meet any legal or accounting requirement.

To determine these periods, HITECH GROUP takes into account the following:

  • The quantity, nature and sensitivity of the personal data;
  • The risk of harm arising from a potential data breach;
  • The purposes for which the personal data are processed;
  • Whether those purposes can be achieved by other means;
  • Applicable legal requirements.

At the end of the active retention period, certain data may be kept in intermediate archiving, with restricted access, notably for evidentiary purposes (complaints and disputes) and/or to comply with applicable legal obligations.

Data subject to an archiving obligation under a legislative or regulatory provision will be archived under the conditions set out in the applicable text(s).

Upon expiry of the applicable periods, data are deleted or anonymised, unless a legal obligation or evidentiary need applies.

Article 7 — Recipients

HITECH GROUP ensures that only authorised persons may access your personal data, within the limits of their roles.

HITECH GROUP may share certain data with Third parties only where necessary to achieve the purposes described in this Policy.

HITECH GROUP implements appropriate measures to ensure that such Third parties provide sufficient confidentiality and security guarantees and, where applicable, frames these relationships with GDPR-compliant contractual commitments.

HITECH GROUP may also disclose your personal data where required by law or to respond to a request from a competent authority.

Data may notably be disclosed to the following categories of Recipients:

  • Authorised internal departments of HITECH GROUP (subscription, customer service, administration, accounting, compliance);
  • IT service providers (hosting and data storage, maintenance, security, CRM, billing);
  • AI model providers (automated natural language processing);
  • Communication sending providers (email, SMS, newsletters);
  • Payment providers (where applicable);
  • Prospecting providers / call centres;
  • External providers and advisors (for example: lawyers, experts, auditors);
  • Administrative, judicial or regulatory authorities, where required by law.

Each Processor is bound by an agreement compliant with Article 28 GDPR. An up-to-date detailed list is available on request at privacy@nexo-hotel.com.

Article 8 — Data transfers

Data are primarily hosted in France with OVHcloud (European Union).

However, certain third-party providers may operate outside the European Union. In that case, HITECH GROUP ensures that such transfers are framed by appropriate safeguards under the GDPR, notably:

  • Where the destination country is covered by an adequacy decision of the European Commission (Article 45 GDPR); or
  • Failing that, by signing standard contractual clauses adopted by the European Commission (Article 46 GDPR) and, where applicable, implementing supplementary measures in accordance with recommendations of the European Data Protection Board.

HITECH GROUP also ensures that the providers concerned offer sufficient confidentiality and security guarantees and that their practices comply with GDPR requirements.

Article 9 — Cookies

HITECH GROUP uses Cookies and other trackers to ensure the proper functioning of the Website, improve your experience and, where applicable, measure audience and offer personalised content.

Some Cookies are strictly necessary for the Website to function, while others require your prior consent, which you may withdraw at any time.

For more information on the nature of Cookies deposited, their purposes and how to configure them, please consult our Cookie Policy at nexo-hotel.com/en/cookies/.

Article 10 — Data subject rights

Under applicable law, every data subject has the following rights: access, rectification, erasure, restriction, portability, objection, withdrawal of consent, providing directives on the use of personal data after death, and lodging a complaint with the CNIL.

HITECH GROUP will respond within one (1) month of receiving your request (extendable by two (2) months in complex cases).

Where there is reasonable doubt as to your identity, HITECH GROUP may request proof of identity.

It is expressly acknowledged that these rights may be subject to limitations provided for by applicable law, notably where necessary to comply with a legal obligation or to establish, exercise or defend legal claims.

10.1 Right of access

You may obtain information from HITECH GROUP about the personal data processed. You also have the right to access your personal data by requesting a copy of the personal data concerning you.

10.2 Right to rectification

You may request measures to correct personal data that are inaccurate or incomplete.

10.3 Right to erasure (“right to be forgotten”)

You may request erasure or deletion of your personal data, for example where there is no compelling reason for HITECH GROUP to continue using them or where their use is unlawful.

10.4 Right to restrict processing

You have the right to restrict or prevent further use of your personal data. Restriction results in temporary suspension of use of the data, except for storage, with restricted access.

10.5 Right to data portability

You have the right to retrieve and reuse certain personal data. This right applies only to personal data you provided, that HITECH GROUP processes with your consent and for contract performance, and that are processed by automated means.

Where applicable, HITECH GROUP will provide a copy of such data in a structured, commonly used and machine-readable format (where technically possible). HITECH GROUP may also transmit them directly to another Controller where technically possible.

10.6 Right to object

You may object to certain types of processing, on grounds relating to your particular situation, at any time, insofar as such processing is based on legitimate interests pursued by HITECH GROUP.

HITECH GROUP may continue to process such personal data if it can demonstrate that the processing is justified by compelling legitimate grounds or if necessary for the establishment, exercise or defence of legal claims.

Where your data are processed for prospecting purposes, you may object at any time without having to justify a particular situation.

10.7 Right to withdraw consent

Where HITECH GROUP processes your personal data on the basis of consent, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before such withdrawal.

10.8 Right to provide directives on use of personal data after death

You have the right to provide HITECH GROUP with instructions on the management (such as retention, erasure and disclosure) of your data after your death. These instructions may be modified and/or revoked at any time.

10.9 Right to lodge a complaint with the CNIL

In the event of a complaint and dissatisfaction with HITECH GROUP’s response, or if you consider that the processing of your personal data does not comply with applicable data protection law, you may lodge a complaint with the competent data protection supervisory authority. The Commission Nationale de l'Informatique et des Libertés (CNIL) is the data protection authority in France.

It may be contacted at: CNIL — 3 place de Fontenoy, TSA 80715 — 75334 Paris Cedex 07, France

Where personal data are processed in connection with use of the Services within a hotel, these rights should primarily be exercised with the hotel (controller). HITECH GROUP provides technical assistance to the hotel to respond.

For data collected via the Website, or for any data protection questions, you may contact us at: privacy@nexo-hotel.com

Article 11 — Artificial intelligence and transparency

The Website presents the NEXO solution based on a conversational artificial intelligence system intended to respond to Users’ requests.

In accordance with the European Artificial Intelligence Act (Regulation (EU) 2024/1689), users of the solution are informed that they are interacting with an artificial intelligence system, not a human operator.

Responses are generated automatically from information provided by the user. Although HITECH GROUP implements measures intended to ensure the quality and reliability of responses, they may contain errors or approximations and cannot replace, where necessary, intervention by a member of the establishment’s staff.

Information shared in exchanges with the assistant may contain personal data. Personal data processing carried out when hotel establishments use this solution is performed under the responsibility of the establishment concerned, in accordance with the DPA concluded with it, available at https://nexo-hotel.com/en/dpa/.

Article 12 — Data security

HITECH GROUP ensures that your personal data are processed securely and confidentially, including where certain operations are carried out by Processors.

To that end, HITECH GROUP implements appropriate technical, organisational and physical measures (encryption in transit and at rest, access control, logging, backups) to prevent in particular loss, unauthorised access, disclosure, alteration or accidental destruction of personal data.

These measures are adapted according to the sensitivity of the personal data processed and the level of risk presented by the processing or its implementation. HITECH GROUP notably limits access to personal data to authorised persons only and selects providers offering sufficient security and confidentiality guarantees.

In the event of a personal data breach, HITECH GROUP will apply the procedures required by applicable law and inform data subjects where required.

Article 13 — Third-party websites and links

The Website may contain hyperlinks to other websites operated by Third parties.

This Policy applies only to personal data collected by HITECH GROUP in connection with use of the Website and its Services.

HITECH GROUP has no control over third-party websites accessible via these links and cannot be held responsible for their data protection practices.

We invite you to consult the privacy policy of each third-party website you visit.

Article 14 — Changes to this Privacy Policy

HITECH GROUP reserves the right to amend this Policy, notably in the event of changes to regulations on the processing of personal data.

When this Policy is amended, HITECH GROUP will inform you by any means it deems appropriate.

HITECH GROUP nevertheless invites you to consult this Policy regularly to stay informed of how your personal data are protected and processed.

Any question relating to this Policy or to the processing of personal data may be sent to privacy@nexo-hotel.com

Data protection contact: privacy@nexo-hotel.com