Privacy Policy
Last updated: July 28, 2026
1. Introduction
Welcome to Vidimo. This Privacy Policy explains how Nuage ("we", "our", or "us") collects, uses, and shares information in connection with our B2B SaaS property management tool, Vidimo.
Vidimo serves as a unified operations hub for hospitality professionals. Our role under data protection law depends on the type of data:
- Guest data processed on behalf of customers (e.g., guest messages, booking details, contact information): Our customers (Property Managers and Hosts) are the Data Controllers and Nuage acts as a Data Processor.
- Account, billing, and platform-integration data (e.g., customer account details, payment information, and credentials or metadata provided to us directly by integration partners such as Meta — including Meta user IDs, WhatsApp Business Account identifiers, access tokens, and app secrets): Nuage is the Data Controller.
2. Data We Collect
Customer Data
We collect information from our customers when they register for an account, including name, business name, email address, payment information, and details about staff members they invite to the platform.
Guest Data
On behalf of our customers, we process data related to their guests. This includes messages originating from platforms like WhatsApp, Airbnb, and Booking.com, as well as booking details, contact information, and special requests. Where a guest sends a voice message, we also process an automated transcription of the recording.
Identity documents
Where a customer uses our check-in features, we process identity-document data that guests provide: document type and number, a national or personal identification number where the document carries one, date and place of birth, sex, nationality, issuing country, expiry date, and country and address of residence. The document is read on the guest's own device and we do not store images or scans of it. We store the resulting data. Because a guest or a staff member can re-submit to correct a detail, each submission is also kept as its own dated record, noting whether it came from the guest's check-in link or from a staff member in the app, so that a later correction never erases what was captured before.
Statutory guest registration
Several countries require accommodation providers to report guest stays to a public authority. Where a customer uses this feature, we transmit the legally prescribed guest data to the competent authority on that customer's behalf, for example AJPES in Slovenia and the Alloggiati Web service of the Polizia di Stato in Italy.
3. How We Use Data
We use the data we collect to provide, maintain, and improve the Vidimo platform, including our unified inbox, translation services, and task management features.
AI Usage Clause
Vidimo utilizes Artificial Intelligence to suggest responses and assist with common questions. We explicitly state that we do not use customer or guest data to train core AI models. Model requests are routed through the Vercel AI Gateway to providers such as OpenAI and Anthropic, and each request carries a zero-data-retention instruction, so the content is not retained by those providers or used to train their models.
There is one exception, and we state it plainly: automated transcription of voice messages. No speech-to-text provider currently available to us offers a zero-data-retention attestation, so audio sent for transcription is not covered by the guarantee above. We do not use it to train models, and we will move transcription under the same guarantee as soon as an attested provider is available to us.
4. WhatsApp & Meta Integration
Vidimo operates as a WhatsApp Tech Provider under Meta's Embedded Signup program. This allows our customers to connect their WhatsApp Business accounts to the Vidimo platform.
When facilitating communication via the WhatsApp Business API, we process messages securely and in strict compliance with the WhatsApp Business Terms of Service. We do not use WhatsApp message data for any purpose other than providing the unified inbox service to our customers.
For Platform Data that Meta shares with us directly through the Embedded Signup flow and the WhatsApp Business API — including Meta user IDs, email addresses, WhatsApp Business Account identifiers, phone-number IDs, access tokens, and app secrets — Nuage is the Data Controller. This data is used solely to provision, operate, and secure our customers' WhatsApp integrations, and is not shared with third parties except the subprocessors listed on our Subprocessors page.
5. Data Sharing & Third Parties
We use trusted third-party service providers, also called subprocessors, to help operate Vidimo. These include providers for hosting, database, storage, messaging, transactional email, payments, support, error monitoring, and AI-assisted features.
These providers may process personal data only as needed to provide services to Vidimo or our customers. A current list of subprocessors is available at our Subprocessors page.
6. Data Retention
We follow standard SaaS retention: customer data is retained while the account is active and deleted within 30 days after account deletion, unless we are legally required to retain limited records for tax, accounting, security, dispute-resolution, or booking/compliance purposes. Where required, those limited records may be retained for up to 7 years.
7. User & Guest Rights (GDPR)
Under the GDPR and other applicable privacy laws, individuals have rights regarding their personal data, including the right to access, correct, or delete their information.
For Guests: Because we process guest data on behalf of Property Managers (who are the Data Controllers), guests wishing to exercise their data privacy rights must contact the Property Manager directly. We will assist our customers in responding to such requests.
8. Cookies & Tracking
We use essential cookies to operate the Vidimo platform (such as keeping you logged in). On our marketing site and guest portal we also use Vercel Web Analytics to understand how visitors move through the pages. It is cookieless: it sets no identifier on your device and does not track you across sites. It records page views, not the information you enter, so nothing you submit during check-in reaches it. You can manage your cookie preferences through your browser settings.
9. Requests from Public Authorities
From time to time, Nuage may receive requests from public authorities (including law enforcement, regulators, and national-security bodies) to disclose personal data. We handle such requests under the following principles:
- Legality review. Every request is reviewed to confirm it is issued by a competent authority, has a valid legal basis, and is sufficiently specific. We do not disclose data in response to informal or voluntary requests.
- Right to challenge. Where a request appears unlawful, overbroad, or inconsistent with the GDPR or other applicable law, we will challenge or seek to narrow it, including through legal counsel where appropriate.
- Data minimization. We disclose only the minimum personal data strictly necessary to comply with a valid request, and we object to requests for bulk or unspecified data.
- Documentation. We document each request received, the legal reasoning applied, the personnel involved, and our response, and we retain those records for audit purposes.
- Customer notice. Where we are legally permitted to do so, we will notify affected customers before disclosing their data so they may seek appropriate remedies.
We publish aggregate information about the volume of such requests we receive whenever we are legally permitted to do so.
10. Contact Information
If you have any questions about this Privacy Policy or our data practices, please contact us at:
Nuage16 pl. des Quinconces
33000, Bordeaux
FRANCE
Email: privacy@vidimo.app