Privacy Policy
This policy explains how Paris Butler (“we”, “us”) handles personal data on the Paris Butler website, its product demo and its hotel discovery form. We process personal data in line with the EU General Data Protection Regulation (GDPR) and French data protection law.
1. Who is responsible
The controller for the data described here is Mehdi Mechkak, a sole trader (entrepreneur individuel) trading as Paris Butler, Paris, France. Contact: flowarchitect.agency@gmail.com.
When a hotel uses Paris Butler with its own guests, that hotel is the controller of its guests’ data and Paris Butler acts as its processor under a separate data processing agreement. This policy covers our own website and demo.
2. What we collect and why
| Where | Data | Purpose | Legal basis |
|---|---|---|---|
| Hotel discovery form and discovery-call request | Name, role, business email, phone, hotel name, website, city, and your answers about your hotel’s operations | Preparing and following up on a business consultation you asked for | Steps taken at your request before a contract; your consent (checkbox) |
| Concierge chat and demo | The messages you type, the name and language you enter, and a random session identifier | Answering your messages and demonstrating the product | Our legitimate interest in demonstrating the product; your request |
| Demo service and room enquiry forms | Name, email, phone, dates, party size and notes | Recording the demonstration enquiry | Your consent (checkbox) |
| Technical data | IP address and request details, processed by our hosting provider | Security, abuse prevention (including rate limiting) and keeping the service running | Our legitimate interest in a secure service |
Please do not enter sensitive information (health, payment card details, identity documents) in the chat or forms. We do not sell personal data and do not use it for advertising.
3. Automated assistant
Chat replies are written by an AI model. They are generated from the hotel’s own information and are not decisions about you. Any booking or request is confirmed by a person.
4. Who processes the data for us
- Cloudflare — hosting of the website and the chat service, and storage of enquiries and chat records (database located in Western Europe).
- Airtable — storage of hotel discovery form submissions.
- Groq — the AI model that writes chat replies (receives your message and the conversation context).
- ScrapingBee — web search for venue recommendations (receives the search wording, not your name).
- Calendly — if you choose to book a call; its own privacy policy applies.
- Google Fonts and jsDelivr — deliver fonts and code libraries to your browser, which shares your IP address with them.
- Meta (WhatsApp) and Twilio — only when a hotel connects Paris Butler to those messaging channels.
Some of these providers are based in, or process data in, the United States. Where that happens, transfers rely on the EU–US Data Privacy Framework or the European Commission’s Standard Contractual Clauses.
5. How long we keep it
- Discovery form and business contact details: up to 3 years after our last contact with you.
- Demo chats and demo enquiries: up to 12 months.
- Technical and security logs: kept by our hosting provider for a short period, typically a few days.
6. Cookies and local storage
We do not use advertising or analytics cookies. The site stores two small preferences in your browser: your chosen language (conciergeflow-locale) and, on the demo, your light or dark theme (lumiere-demo-theme). These are strictly necessary for the features you choose and are never sent to us.
If you sign in to the private product demo, a session cookie (cf_demo_session) keeps you signed in for up to 8 hours. It is strictly necessary for that sign-in and holds no personal data.
7. Your rights
You can ask to access, correct, delete or export your data, to restrict or object to its use, and to withdraw consent at any time (this does not affect processing before withdrawal). Write to flowarchitect.agency@gmail.com; we answer within one month. You can also complain to the French data protection authority, the CNIL.
8. Security
Data is sent over encrypted connections. Access to the systems is restricted, provider keys are kept on the server only, and automated abuse is limited.
9. Changes
We will update this page if our practices change and show the new date at the top.