Whispr by Qure Technology

Security & Data

What we can state today about how your data is handled.

This page restates what our privacy policy already says, plus the controls that are actually built into the product — nothing more.

Roles & data

Who does what with guest data.

Your hotel is the controller

Your hotel determines the purposes and means of processing guest data, including any consents that are required.

Whispr is the processor

Qure Whispr acts as a data processor for messages exchanged between your hotel and your guests — we don't decide why the data is processed, your hotel does.

What we process

Phone numbers, message content, message timestamps, language and intent classification metadata, and hotel/conversation identifiers — nothing unrelated to guest–hotel communication.

In the product

Controls built into the product.

Controls built into Whispr today
ControlWhat it does
Each person's access is scoped to the properties they're assigned to in the console.
The moment a team member takes over a conversation, the AI stops answering until it's handed back.
Whispr answers from your hotel's own knowledge; when the answer isn't there, it says so instead of inventing one.
A message that has gone stale isn't answered automatically — it's handed to a person.
Each decision has a confidence threshold; below it, Whispr asks or hands over instead of acting on a guess.

AI processing

What runs inside Whispr, and what is sent to OpenAI.

Whispr uses OpenAI's API for part of its AI work. This is what each part receives, as implemented today — no more, no less.

AI processing steps and the data each one receives
StepWhat it receives, and where it runs
Runs on Whispr's own model inside Whispr. OpenAI is consulted only when that model is unsure, with the message and a short recent history.
When you upload a document, OpenAI processes its text to extract and normalise its structure (menus, hours, services); the searchable index, embeddings and ranking are built inside Whispr, and the guest list from your PMS is not indexed. Passages retrieved from your documents are then part of what OpenAI receives when it answers a question.
OpenAI receives the guest's question and recent conversation as written, the retrieved passages from your hotel knowledge, your hotel's name and local time.
OpenAI receives the guest's messages and the details collected so far — including, for identified guests, the name and room number from their stay record.
Staff-alert and inbox translation send the guest's message text; WhatsApp voice notes are sent as audio for transcription.
Whatever a guest types — a name, a room number, a phone number — travels as written. Whispr does not redact it.

Hosting is a separate fact

The application, its database, cache and document storage run on Huawei Cloud in Türkiye. That says where Whispr runs; the table above says what leaves it for AI processing. The two are not the same, and we don't blur them.

Meta & WhatsApp

How WhatsApp messages travel.

Meta's WhatsApp Business Platform

Messages sent via WhatsApp are processed through Meta Platforms, Inc.'s WhatsApp Business Platform, under Meta's own terms and privacy policy. Qure Whispr does not control how Meta processes them.

Templates outside the 24-hour window

Once a WhatsApp session window closes, a new message to a guest can only be sent using a template Meta has reviewed and approved.

Scope

What we can state today, and what we're still documenting.

What we can state today

  • Roles: your hotel is the controller, Qure Whispr is the processor.
  • The categories of data processed for guest–hotel messaging.
  • That WhatsApp messages pass through Meta's WhatsApp Business Platform.
  • That retention periods vary depending on hotel configuration.
  • That subprocessors include Meta, cloud infrastructure providers, and AI service providers.
  • Hosting: the application, database, cache and document storage run on Huawei Cloud in Türkiye (per our deployment documentation).
  • AI processing: which steps use OpenAI's API and what each one receives — the table above. Personal details a guest types are not redacted before they are sent.

What we are still documenting

  • A named subprocessor list with contract references — available on request.
  • The AI provider's data-retention setting on our account — being documented; until then we make no retention claim for data sent to OpenAI.
  • Default retention periods per data category — being documented; today retention follows hotel configuration.

Questions

Questions about data handling

Who owns the data?

Your hotel, as the data controller. Qure Whispr processes it on your hotel's behalf and instructions.

How do guests exercise their rights?

Guests should direct access, correction, or deletion requests to the hotel they communicated with, since the hotel is the controller.

Can our hotel export or delete guest data?

Deletion requests are handled through your hotel together with us — write to legal@qureai.net. We don't yet offer a self-serve export tool.

Read the full detail in our privacy policy.

Privacy Policy

See Whispr working on your hotel's real scenarios.

Bring your channels, your service flows, and your questions. We shape every demo around how your property actually operates.