Security and data

What the system never does. By design.

The commitments we make to every house, in plain words. They apply to the pilot and to what follows, and they are the same ones we write in your security questionnaire. Nothing here is presented as done before it is.

By design

Six things the system cannot do, because it was not built to do them.

  1. 01Never the reception's main mailbox

    The system is never connected to the reception's main mailbox. It only reads a dedicated address, to which you redirect what concerns the chosen scope. The rest of your mail does not concern it and never reaches it.

  2. 02Never an attachment, never a link

    It never opens an attachment or a link received in a booking mailbox. A suspicious message is quarantined and reported to your team, never processed.

  3. 03No payment card

    It is excluded from any payment card flow. No card number ever passes through it, in any form.

  4. 04Your guests are not our material

    The standard areas cover business contacts, internal documents and operating figures. A seminar request may nonetheless mention an allergy or an accessibility need: the system recognises these as sensitive data, refuses to copy them into a document that does not need them, refuses to place them in memory, and keeps them in Switzerland. Never a password, never an access, never a card.

  5. 05A person validates everything that goes out

    Every item that leaves the house is validated by a person on your team. Purely internal flows, the ones addressed to no one, run on their own and are logged.

  6. 06A journal that belongs to you

    Every action is recorded in a time-stamped, append-only journal: nothing in it is erased, nothing is altered. It can be exported at any time, and it goes with you if you leave.

The technical side, in plain words

What we must be able to prove, not merely claim.

01Named accounts, two-factor authentication

Each person has their own account, protected by two-factor authentication. We know who validated what, and an access is revoked the same day.

02Encryption in transit and at rest

Data is encrypted while it travels and while it is stored, on the database, the documents and the backups.

03Daily backups, restoration tested

A backup every day, kept off the server, and a restoration that is tested and dated. A backup that has never been restored is not one.

04No training on your data

No hotel data is ever used to train a model. Not by us, not by our sub-processors, by contract.

05Your data stays separate

Each house's data is partitioned from that of the others, in the database as in document storage.

06Swiss hosting being deployed

Hosting of the platform and of your data in Switzerland is being deployed. The exact status at the time of your pilot is given to you in writing. We will only announce it as done once it is.

Everything is reversible: you get everything back, you erase everything, there is nothing to uninstall.

The question we are always asked

What becomes of your text when a model reads it.

It is the first concern of any management team, and it is a legitimate one. Here is the full answer, without a reassuring shortcut.

01A model is not a database

It does not store anything. It is a frozen computation: text goes in, text comes out, and what makes up the model does not move an inch along the way. Between two requests it remembers nothing. Your message is not « learnt » because it was read.

02What counts is the contract around it

The real risk is not the model's memory, it is the logs, the retention periods and the provider's own uses. That is contractual, not technical, and it is why we name every provider below rather than speaking of « artificial intelligence » in general.

03Your data stays in Switzerland

Any content that may carry personal data is processed by Swiss inference, at Infomaniak in Geneva. This is not a preference of ours, it is a rule written into the engine, which depends neither on an agent's vigilance nor on a developer's.

04Masking a name is not enough for us

We could replace names with tokens and send the rest elsewhere. We do not. The mapping table would stay with us, so the data would remain personal in our eyes, and the sending would remain a transfer abroad. A masked allergy is still an allergy.

05The American provider sees only figures

We use Anthropic for content that holds no personal data at all: meter readings, product comparisons, food costs. Through the commercial API, whose terms provide that no customer content is used to train a model and that no exchange is retained by default. And if you would rather this provider were not used at your house at all, it is not.

06What you can check for yourself

For each text prepared, the journal records which provider was called and in which country. You do not have to take our word for it: you export the journal and you look.

A word on what we do not promise: no consumer tool gives you these guarantees. Pasting a seminar request into an open assistant from a browser means sending a guest's allergy to the other side of the world, with no contract, no journal and no trace. That is precisely what we were built to replace.

Our sub-processors

Who touches your data, for what purpose, and where.

A sub-processor is a company that processes data on our behalf, and therefore on yours. You are informed in writing before any addition or replacement, and you can object.

  1. Swiss cloud hostTo be confirmed

    RoleHosting of the platform, the database and your documents. Processing in Switzerland.

    Data concernedThe data you entrust to us: redirected messages, documents, drafts, journal, user accounts, measurements.

  2. InfomaniakGeneva, Switzerland

    RoleHosting of the platform, of the database and of your documents. Processing in Switzerland.

    Data concernedThe content of the messages and documents submitted, including the professional contact details of requesters and suppliers, and any passage that would contain sensitive data.

  3. AnthropicUnited States

    RoleReading, extraction and drafting. Inference takes place in Switzerland, on Infomaniak's infrastructure. Requests are not retained and are not used to train any model.

    Data concernedNone. Routing is not an intention, it is a rule of the engine: content not marked free of personal data goes to Switzerland, content marked as such that nonetheless contains a name, an address or a number goes back to Switzerland, and the slightest sensitive data stays in Switzerland whatever happens. Masking a name is not enough in our eyes, and we do not do it to get around the rule.

  4. CalendlyUnited States

    RoleAppointment booking from the contact page, on Calendly's site.

    Data concernedName, e-mail address, time slot and time zone of the person booking a call. On request, the appointment can be arranged by e-mail.

The software we install and operate ourselves gives its publishers no access to your data and is therefore not on this list. The list is updated at every change, with the date.

The contract

The data processing agreement, on request.

The data processing agreement (DPA) that sets out these commitments, the list of sub-processors and the retention periods is available on request, before any pilot. Write to sven@myt-hospitality.ch and you will receive it in writing.

What you can require

  • The exact hosting status, in writing, before your pilot.
  • The up-to-date list of sub-processors, with the date.
  • The full export of your journal and your documents, at any time.
  • The erasure of everything, at the end, if you ask.
  • Our written answers to your supplier security questionnaire.

Get started

Ask us the question that has already disappointed you elsewhere.

You speak to the founder, he replies within twenty-four hours, in writing if you prefer. If MYT is not right for you, we will tell you that too.

Response within 24 hours · Nothing to install · No obligation