Mizumi Privacy Policy

Effective Date: April 14, 2026
Last Updated: September 12, 2026
Version: 2.1

This Privacy Policy explains how Mizumi AI Inc. ("Mizumi", "we", "us", or "our") collects, uses, discloses, and protects information when you use our platform, websites, applications, APIs, embedded widgets, voice services, and related tools (collectively, the "Services"). It also describes the sub-processors we engage to deliver the Services and your rights regarding your personal data.

1. Introduction

Mizumi is an AI-powered guest communication and property management platform that enables hotels and other hospitality operators to manage omnichannel guest interactions, automate routine inquiries, take payments, and integrate with their existing Property Management Systems (PMS).

This Policy explains how Mizumi collects, uses, and protects information across our hotel staff portal, embedded guest widget, integrations, and APIs.

Mizumi acts in two distinct capacities depending on the data:

By using the Services, you agree to the practices described in this Privacy Policy. Hotel guests should also refer to the privacy notice provided by the hotel they are staying with, who is the data controller for their information.

2. Roles & Responsibilities

PartyRoleDescription
HotelData ControllerDetermines the purposes and means of processing guest and staff data
MizumiData ProcessorProcesses personal data on the hotel's documented instructions
Sub-processorsSub-processorsThird-party services engaged by Mizumi to deliver the platform

Hotels retain full control over guest data and are responsible for ensuring lawful bases exist for processing (e.g., legitimate interest, contract performance, consent).

3. Information We Collect

3.1 Hotel Guest Data

CategoryData ElementsPurpose
IdentityFirst name, last name, title, date of birth, nationality, preferred languageGuest profile management, personalisation
ContactEmail address, mobile phone number (used for SMS and messaging-app delivery), additional phone numbers, postal address (street, city, state, postal code)Guest communications, booking confirmations, SMS notifications
BookingCheck-in/check-out dates, room type, rate, number of guests (including children and ages), source channel, special requestsReservation management, PMS synchronisation
CommunicationFull message history across all channels (WhatsApp, web chat, email, SMS, Facebook, Instagram, Zalo, WeChat), conversation metadataOmnichannel guest support, AI response generation
PaymentPayment amount, currency, payment method type, payment status, tokenised payment referencePayment facilitation (raw card data is never stored by Mizumi)
Profile metadataGuest classification (VIP, repeat, first-time, corporate), total stays, lifetime value, marketing consent flag, guest tags and notesSegmentation, personalised service
Device & networkIP address, derived geolocation (country, region), browser fingerprintFraud prevention, analytics, channel detection
DocumentsUploaded files (e.g., ID documents, booking confirmations)Identity verification at the hotel's request

3.2 Hotel Staff Data

CategoryData ElementsPurpose
IdentityName, email addressAccount management, authentication
AccessRole, permissions, property assignmentsAccess control
ActivityConversation assignments, action logs, anonymisation audit recordsOperational accountability

3.3 Data NOT Stored by Mizumi

4. How We Use Information

We use collected information to:

4.1 SMS / Text Message Communications

When a hotel uses the Services to send SMS, MMS, or messaging-app texts to a guest, Mizumi processes the guest's mobile phone number to deliver those messages. SMS and MMS messages are dispatched through Twilio (see Section 8.5); WhatsApp Business messages are dispatched through Twilio and/or Meta. Categories of messages may include: reservation confirmations and reminders, pre-arrival and in-stay service messages, guest support replies, payment links and receipts, post-stay follow-ups, and — where the hotel has obtained the required prior consent — marketing or promotional messages.

Message frequency varies based on the hotel's communications and the guest's interactions. Standard message and data rates may apply from the recipient's mobile carrier; Mizumi and the hotel are not responsible for carrier charges. Recipients may opt out of further non-transactional SMS at any time by replying STOP to a message from the hotel's sending number, and may request help by replying HELP. Opt-out requests are honoured at the sending-number / short-code level by the underlying carrier. Mobile phone numbers are retained as part of the guest profile for the period described in Section 9 (Data Retention) and are never sold or shared with third parties for their own marketing purposes.

5. How We Share Information

We do not sell your personal information.

We share information only as described below:

5.1 Sub-processors and Service Providers

Trusted vendors who assist with hosting, infrastructure, AI processing, payment, messaging, analytics, security, and communication. The complete list is provided in Section 8 (Sub-processors).

5.2 Hotel-Authorised Integrations

When you (or the hotel you are interacting with) authorise Mizumi to connect with systems such as a PMS, channel manager, CRM, or payment gateway, we share only the data required for that integration to operate.

5.3 Legal Requirements

We may disclose information if required by law, court order, subpoena, or governmental request, or when we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Mizumi, our customers, or the public.

5.4 Business Transfers

In connection with a merger, acquisition, financing, reorganisation, bankruptcy, or sale of all or a portion of Mizumi's assets, information may be transferred as part of the transaction, subject to confidentiality protections and to this Privacy Policy.

6. Data Storage & Infrastructure

6.1 Cloud Infrastructure

All Mizumi production infrastructure is hosted on Amazon Web Services (AWS) in the USA.

ComponentTechnologyRegion
Primary databaseAWS RDSUSA
File and asset storageAWS S3USA
Content deliveryAWS CloudFront CDNGlobal edge network
Message queuingAWS SQSUSA
Email deliveryAWS SES and SendGrid (Twilio Inc.)USA
AuthenticationAWS CognitoUSA
Secrets managementAWS SSM Parameter Store / Secrets ManagerUSA
Static site hosting (this site)Cloudflare PagesGlobal edge network

6.2 Data Isolation

Mizumi operates a multi-tenant, property-scoped architecture. Data belonging to one hotel cannot be accessed by another hotel's users.

7. Security Practices

7.1 Encryption

LayerImplementation
Encryption at restAWS KMS field-level encryption applied to sensitive columns in PostgreSQL; separate KMS keys per environment
Encryption in transitTLS 1.2 or higher enforced for all API, WebSocket, and CDN connections
Credential storageAll third-party integration credentials (PMS tokens, payment keys, messaging tokens) are encrypted with KMS before database storage
Authentication tokensJSON Web Tokens (JWT) signed and validated via JWKS; short-lived access tokens

7.2 Access Control

7.3 Payment Card Data

Mizumi uses Datatrans SecureFields (and equivalent tokenisation provided by other configured processors) for PCI-compliant payment form handling. Card data is tokenised client-side and transmitted directly to the payment processor; raw card numbers never pass through Mizumi servers. Mizumi stores only a tokenised payment reference returned by the processor.

7.4 Monitoring & Logging

8. Sub-processors

Mizumi engages the following third-party sub-processors to deliver the Services. Each sub-processor is bound by contractual obligations requiring them to apply equivalent data protection standards. Only sub-processors corresponding to features your hotel has configured will receive data; for example, a hotel that has not enabled WeChat does not transmit data to Tencent.

8.1 Core Infrastructure

Sub-processorServiceData ProcessedLocation
Amazon Web Services (AWS)Cloud infrastructure (compute, database, storage, queuing, email, identity, CDN, key management, monitoring)All platform dataUSA
Cloudflare, Inc.DNS, edge network, and static site hosting (legal.mizumi.ai, chat.mizumi.ai)Public website request metadataUSA / Global edge
SendGrid (Twilio Inc.)Transactional email delivery for guest notifications and administrative communicationsRecipient email address, message contentUSA

8.2 AI & Language Models

Sub-processorServiceData ProcessedLocation
OpenAI, L.L.C.Large language model (GPT-4.1 series) for AI-powered guest responses, query classification, and knowledge retrievalGuest messages, conversation contextUSA
Google LLC (Gemini API)Alternative/backup LLM providerGuest messages, conversation contextUSA
LangSmith (LangChain, Inc.)LLM observability and tracingLLM inputs/outputs for debuggingUSA
No training on guest data. Mizumi does not use guest messages to train third-party models. LLM interactions are governed by the enterprise data processing agreements held with OpenAI and Google, which prohibit training on customer data unless explicitly opted in.

8.3 Property Management System (PMS) Integrations

Sub-processorServiceData ProcessedLocation
Mews SystemsPMS integration — guest profiles, bookings, rates, room inventory synchronisationGuest PII, booking dataCzech Republic / USA
CloudbedsPMS integration — guest profiles, bookingsGuest PII, booking dataUSA
Smile PMSPMS integrationGuest PII, booking dataVietnam

PMS integrations are hotel-configured. A hotel only shares data with PMS providers it has actively connected. Mizumi acts as an intermediary, not an independent data source.

8.4 Payment Processors

Mizumi supports multiple payment gateways depending on the hotel's region and configuration. Only the payment processors activated by the hotel will process guest payment data.

Sub-processorServiceData ProcessedLocation
Datatrans AGPCI-compliant payment tokenisation (SecureFields)Payment card data (tokenised)Switzerland
Stripe, Inc.Credit/debit card processingPayment dataUSA
VNPayVietnamese payment gatewayPayment dataVietnam
OnePayPayment processingPayment dataVietnam
MoMo (M_Service)Vietnamese mobile walletPayment dataVietnam
ZaloPay (VNG Corporation)Vietnamese digital paymentPayment dataVietnam
PayPal Holdings, Inc.Global payment processingPayment dataUSA
Square (Block, Inc.)Point-of-sale / payment processingPayment dataUSA

8.5 Messaging & Communication Channels

Mizumi routes guest messages through third-party channel providers. Only channels that the hotel has activated are used.

Sub-processorServiceData ProcessedLocation
Meta Platforms, Inc. (WhatsApp / Facebook / Instagram)Messaging channel delivery and receiptGuest messages, metadataUSA
Twilio Inc.SMS and WhatsApp Business API deliveryGuest phone numbers, message contentUSA
Zalo (VNG Corporation)Vietnamese messaging channelGuest messages, metadataVietnam
WeChat (Tencent Holdings Ltd.)Chinese messaging channelGuest messages, metadataChina

8.6 Maps & Geolocation

Sub-processorServiceData ProcessedLocation
Google Maps (Google LLC)Property location display in guest-facing widgetHotel address dataUSA
Baidu Maps (Baidu, Inc.)Property location display (China-region widget)Hotel address dataChina

8.7 Analytics & Product Monitoring

Sub-processorServiceData ProcessedLocation
PostHog, Inc.Product analytics, session replay (hotel staff portal only)Staff usage patterns, anonymised interaction eventsUSA
FingerprintJS, Inc.Browser fingerprinting for session identification and fraud signalsBrowser fingerprint hash (guest widget)USA

PostHog is used in the hotel staff portal only. Session replay is configured with privacy controls: all text inputs are masked, DoNotTrack settings are respected, and network payloads are masked for sensitive headers.

9. Data Retention

Guest and booking data is retained for the duration of the hotel's active subscription with Mizumi, plus a reasonable post-termination period sufficient to complete any outstanding legal or financial obligations, unless otherwise agreed in writing. Data may be anonymised and aggregated for analytics or product improvement.

10. Your Rights

Depending on your jurisdiction, you may have the right to:

Hotel guests should generally direct these requests to the hotel they interacted with, since the hotel is the data controller. Mizumi will assist hotels in fulfilling such requests.

10.1 Guest Anonymisation (GDPR / Right to Erasure)

Mizumi includes a built-in guest anonymisation workflow:

10.2 Data Subject Access Requests (DSAR)

Mizumi provides a dedicated DSAR workflow:

To exercise rights directly with Mizumi (for example, where Mizumi is the controller of your data as a hotel customer or website visitor), contact [email protected].

11. International Data Transfers

Mizumi's production infrastructure is located in the United States.

Mizumi relies on the following transfer mechanisms:

Hotels in the European Economic Area (EEA), United Kingdom, or other jurisdictions with data transfer restrictions should ensure their Data Processing Agreement with Mizumi includes appropriate transfer documentation.

Vietnam-specific: For Vietnamese hotels, Mizumi uses Vietnam-based sub-processors (VNPay, MoMo, ZaloPay, Zalo) where applicable to minimise cross-border data transfers for payment and messaging.

12. Cookies & Similar Technologies

We use cookies and similar technologies to:

You may adjust your browser settings to block or delete cookies, though some features may not function properly without them. The Mizumi guest widget honours DoNotTrack signals for analytics.

13. Children's Privacy

Mizumi is not intended for individuals under the age of 16, and we do not knowingly collect personal information directly from children. Hotels may, in the ordinary course of operating their property, record the ages of children associated with a booking (e.g., for room capacity purposes). Such information is processed on the hotel's instruction.

14. Hotel Obligations as Data Controller

As the data controller, the hotel is responsible for:

  1. Lawful basis — Ensuring a valid legal basis exists for collecting and processing guest personal data via the Mizumi platform
  2. Privacy notice — Informing guests that their data may be processed by the Mizumi platform (e.g., in the hotel's privacy policy and at check-in)
  3. Marketing consent — Obtaining appropriate consent before using Mizumi to send marketing messages to guests
  4. Third-party channels — Ensuring the hotel's use of Meta (WhatsApp/Instagram), Zalo, WeChat, and other activated channels complies with those platforms' terms of service and applicable privacy law
  5. PMS configuration — Ensuring the hotel has the right to share guest data from its PMS with Mizumi as part of any integration
  6. DSAR handling — Responding to guest data requests; Mizumi provides tooling to assist but the hotel remains the responsible party

15. Data Processing Agreement (DPA)

Hotels using Mizumi in a capacity that involves processing personal data of EU/EEA residents (or residents of other jurisdictions with similar requirements) should execute a Data Processing Agreement with Mizumi.

The DPA governs:

To request a DPA, contact your Mizumi account representative or email [email protected].

16. Sub-processor Updates

Mizumi will provide 30 days' advance notice of any material changes to the sub-processor list (additions or replacements that may affect the protection of personal data). Hotels that have signed a DPA may object to new sub-processors during this notice period.

17. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify hotel customers of material changes through the platform or via email and will update the "Last Updated" date at the top of this page.

18. Contact Us

PurposeContact
Data processing and privacy inquiries[email protected]
Security incidents[email protected]
DPA requests[email protected]
General support[email protected]

Mizumi AI Inc.
8 The Green, Suite B
Dover, Delaware 19901, USA


This Privacy Policy is provided for informational and contractual purposes and does not constitute legal advice. Hotels should seek independent legal counsel regarding their own data protection obligations.