Atryo

Privacy policy

Last updated: 3 October 2026

This policy explains which personal data Atryo processes, why and for how long, under EU Regulation 2016/679 (GDPR).

1. Controller

The data controller is Atryo. Contact us from the Contact page on atryo.io for any request about your data.

2. Data we process

Identity and contacts: name, email, verified phone number, related unit or stay.

Access: personal codes (stored only hashed), attempt logs, passwordless sessions.

Services: requests, proposals, times, notes, photos attached to requests and problem reports, reviews.

Payments: payment status, amounts and hold/release/refund movements. Card data is handled only by the payment provider, never by Atryo. For providers: payout details (account holder, IBAN, tax data).

Conversations: messages with Atryo Concierge on WhatsApp and requests sent through connected AI assistants.

3. Why we process it

To provide the service (contract): access, bookings, held payments, notifications at every step, dispute handling.

Legal obligations: accounting and tax for payment movements.

Legitimate interest: security, abuse prevention, service improvement.

4. Who sees your data

The provider sees the place, your name and role (resident or guest); your phone number only after the request is accepted. Your email is never shared.

Photos in a problem report are visible to you, the provider concerned and the Atryo team reviewing the dispute.

The place's management company or agency/host receives help requests you hand over to a person via the Concierge.

Technical processors (hosting, email delivery, WhatsApp Business, payment provider, AI models) process data on our behalf under GDPR-compliant agreements.

5. WhatsApp Concierge and AI assistants

The Concierge only recognises verified numbers. Conversations are used to propose services: nothing is booked without your explicit approval.

When you write to Atryo on WhatsApp and send the code from your management company or host, we save your number and link it to your residence or stay: this is how we give you access to the services you ask for (legal basis: performance of the service). No separate consent is needed and we do not use your number for marketing.

We process: phone number, name, linked place (residence and unit, or villa and stay dates) and messages with the Concierge. They are seen by the Atryo team and the place's management company or agency; a provider sees your phone only after accepting your request. Meta (WhatsApp) provides the messaging channel.

If you write from a number that never sends a valid code, we store no name or contact: only encrypted attempts for abuse protection remain, deleted after 30 days.

You can write "delete my data" in the chat: the saved conversation is deleted immediately and the Atryo team removes your number's link.

If you connect an AI assistant (e.g. Claude or ChatGPT) via MCP, you authorise access from your account and the assistant only sees data for your residence or active stay. You can revoke the connection at any time. Atryo does not use your data to train models.

6. Retention

When a stay ends the guest account is not deleted: name, contacts, past stays, requests, bookings and Wallet credit remain so you can find them again and use your cashback on Atryo (legal basis: performance of the service). Access to villa services ends with the stay.

You can ask for your account to be deleted at any time: we remove your profile and contacts and keep only the payment records required by law. Unused Wallet credit lapses on deletion.

If an account is inactive for 24 months with no available credit, we delete it after notifying you.

WhatsApp conversation memory lasts 24 hours; code attempts are deleted after 30 days.

Photos from requests and problem reports are kept as long as needed to handle the service and any dispute, then deleted.

Payment movements are kept for the period required by tax law (10 years).

7. Your rights

You can request access, rectification, erasure, restriction, portability and object to processing. You can manage notification preferences in the app. You may lodge a complaint with your data protection authority.