Your hotel is the controller
Your hotel determines the purposes and means of processing guest data, including any consents that are required.
Security & Data
This page restates what our privacy policy already says, plus the controls that are actually built into the product — nothing more.
Roles & data
Your hotel determines the purposes and means of processing guest data, including any consents that are required.
Qure Whispr acts as a data processor for messages exchanged between your hotel and your guests — we don't decide why the data is processed, your hotel does.
Phone numbers, message content, message timestamps, language and intent classification metadata, and hotel/conversation identifiers — nothing unrelated to guest–hotel communication.
In the product
| Control | What it does |
|---|---|
| Per-property role-based access | Each person's access is scoped to the properties they're assigned to in the console. |
| Staff takeover pauses the AI | The moment a team member takes over a conversation, the AI stops answering until it's handed back. |
| Grounded answers | Whispr answers from your hotel's own knowledge; when the answer isn't there, it says so instead of inventing one. |
| Freshness cutoff | A message that has gone stale isn't answered automatically — it's handed to a person. |
| Confidence thresholds | Each decision has a confidence threshold; below it, Whispr asks or hands over instead of acting on a guess. |
AI processing
Whispr uses OpenAI's API for part of its AI work. This is what each part receives, as implemented today — no more, no less.
| Step | What it receives, and where it runs |
|---|---|
| Message classification | Runs on Whispr's own model inside Whispr. OpenAI is consulted only when that model is unsure, with the message and a short recent history. |
| Documents and knowledge search | When you upload a document, OpenAI processes its text to extract and normalise its structure (menus, hours, services); the searchable index, embeddings and ranking are built inside Whispr, and the guest list from your PMS is not indexed. Passages retrieved from your documents are then part of what OpenAI receives when it answers a question. |
| Answering | OpenAI receives the guest's question and recent conversation as written, the retrieved passages from your hotel knowledge, your hotel's name and local time. |
| Reservation details | OpenAI receives the guest's messages and the details collected so far — including, for identified guests, the name and room number from their stay record. |
| Translation and voice notes | Staff-alert and inbox translation send the guest's message text; WhatsApp voice notes are sent as audio for transcription. |
| Personal details in messages | Whatever a guest types — a name, a room number, a phone number — travels as written. Whispr does not redact it. |
The application, its database, cache and document storage run on Huawei Cloud in Türkiye. That says where Whispr runs; the table above says what leaves it for AI processing. The two are not the same, and we don't blur them.
Meta & WhatsApp
Messages sent via WhatsApp are processed through Meta Platforms, Inc.'s WhatsApp Business Platform, under Meta's own terms and privacy policy. Qure Whispr does not control how Meta processes them.
Once a WhatsApp session window closes, a new message to a guest can only be sent using a template Meta has reviewed and approved.
Scope
What we can state today
What we are still documenting
Questions
Your hotel, as the data controller. Qure Whispr processes it on your hotel's behalf and instructions.
Guests should direct access, correction, or deletion requests to the hotel they communicated with, since the hotel is the controller.
Deletion requests are handled through your hotel together with us — write to legal@qureai.net. We don't yet offer a self-serve export tool.
Read the full detail in our privacy policy.
Privacy Policy →Bring your channels, your service flows, and your questions. We shape every demo around how your property actually operates.