Privacy policy

Last updated 13 September 2026.

1. Who we are

Salisea is operated by Samir Caus, trading as SaliSea, at c/o POSTFLEX PFX-744-129, Emsdettener Straße 10, 48268 Greven, Germany (“Salisea”, “we”, “us”).

For privacy questions or requests, contact privacy@salisea.com.

2. Scope and our role

This policy applies to salisea.com, Salisea accounts, the owner workspace, support, and connected services.

We act as a controller for account, security, support, service-improvement, and billing data. This means we decide why and how that data is processed.

For guest inquiries, messages, bookings, property operations, and related guest data, the accommodation operator normally acts as controller and Salisea acts as processor.

Accommodation operators are responsible for their own privacy notices, legal bases, instructions, and responses to guest requests. Our processing of their guest data is governed by our Data Processing Agreement.

3. Data we collect

Depending on how you use Salisea, we may process:

  • account data, including name, email address, password hash, role, verification status, language, and authentication-provider identifiers;
  • legal and billing profile data, including customer type, legal name, billing address, legal and tax countries, tax identification number, optional VAT identification number, and VAT-validation state;
  • workspace data, including organization, team, property, unit, address, classification, availability, calendar, booking, financial, and operational records;
  • guest data, including names, contact details, inquiry content, stay dates, party details, booking information, payment-request details, and communication history;
  • email data, including sender, recipient, subject, message body, headers, routing data, delivery status, and the original email file;
  • AI data, including submitted message content, extracted fields, confidence values, translations, prompts, draft replies, model identifiers, and review actions;
  • integration data, including calendar feed URLs, OAuth grants, notification preferences, Telegram identifiers, and Google Places requests;
  • technical data, including IP address, browser and device information, timestamps, security events, logs, cookies, and session identifiers;
  • support data, including messages, attachments, troubleshooting information, and feedback you send to us.

We do not intentionally collect special-category data. Do not place identity documents, health data, or other sensitive information in free-text fields unless a specific Salisea feature clearly requests it.

Tax identifiers are private account data. We make them available only to authorised account users and use them for compliance, contracts, billing, and invoicing; they are not included on public accommodation pages.

4. Where data comes from

We receive data directly from users, their team members, guests, forwarded emails, connected calendars, authentication providers, integrations, and the devices used to access Salisea.

An accommodation operator may provide guest data without the guest interacting directly with Salisea. In that case, the operator is responsible for informing the guest as required by law.

5. Why we process data

We process personal data to:

  • create accounts, authenticate users, maintain sessions, and recover access;
  • provide property, availability, inquiry, booking, calendar, notification, and communication features;
  • receive, route, store, organize, translate, and respond to accommodation inquiries;
  • run optional AI-assisted extraction, classification, translation, and reply drafting;
  • connect services selected by the user, such as Google, calendar feeds, email, MCP clients, or Telegram;
  • secure Salisea, prevent abuse, diagnose failures, maintain audit records, and enforce our terms;
  • respond to support requests and communicate essential service information;
  • administer plans, invoices, taxes, and payments if paid plans are enabled;
  • meet legal obligations and establish, exercise, or defend legal claims.

6. Legal bases

Where Salisea acts as controller, we rely on:

  • contract, when processing is needed to create an account or provide requested services;
  • legitimate interests, for security, fraud prevention, support, service reliability, and proportionate product improvement;
  • legal obligation, where tax, accounting, regulatory, or lawful-request rules apply;
  • consent, for optional processing that legally requires it, which can be withdrawn at any time.

Where we act as processor for an accommodation operator, we process guest data on that operator’s documented instructions. The operator determines the applicable legal basis.

7. Authentication and cookies

Email-and-password accounts use a securely hashed password. We do not store the readable password.

If you choose Google sign-in, Google provides authentication information such as your name, email address, provider account identifier, and verification status.

Salisea uses essential cookies for secure sessions, authentication, CSRF protection, and language preference. These cookies are required for the requested service and are not used for behavioural advertising.

The current public site does not use third-party advertising or behavioural analytics cookies. If that changes, this policy and any required consent controls must be updated before activation.

8. Email and inquiry processing

Users may forward a copy of a guest inquiry to a Salisea property inbox. Salisea stores the original email and a normalized copy so the user can review, organize, and respond to it.

Email content can contain personal data supplied by the guest or inserted by a booking channel. Users must configure forwarding lawfully and must not forward unrelated or excessive mailbox content.

When a user approves an outgoing reply, Salisea may send it through the configured email provider and retain delivery, threading, and audit information.

Guests may also submit an availability request from a public accommodation page. On the Free plan, Salisea sends the request to the verified host by email and does not add it to the host’s managed Salisea inbox. The guest’s message and contact details remain only in a transient delivery payload, which is redacted after delivery or a final delivery failure. We retain a short-lived technical record containing the property, delivery status, time, and a one-way request fingerprint for abuse prevention and aggregate measurement.

On Direct and higher plans, the request is stored in the host’s Salisea workspace so the host can manage its status and convert it into a hold or booking. AI processing is applied only where the account has Host features, including an active Host trial.

9. AI-assisted features

If enabled for the workspace, Salisea may send inquiry text and relevant property context to Cloudflare Workers AI for extraction, language detection, translation, and reply drafting.

AI output can be incomplete or incorrect. It is presented as an aid for human review. AI cannot independently confirm a booking, create a hold, take payment, or send a guest reply without an authorized user action.

We do not use guest or customer content to train our own general-purpose AI models. Provider handling is governed by the applicable service agreement and data-processing terms.

Cloudflare Workers AI processes requests on Cloudflare’s network. We store the inquiry and AI result in the Salisea workspace according to the retention periods below. Cloudflare states that it does not use Workers AI customer content to train AI models or improve Cloudflare or third-party services without explicit consent.

10. Analytics and logs

Salisea currently uses operational logs and privacy-light Cloudflare Analytics Engine events to protect, operate, troubleshoot, and understand use of the service. Public-page events contain event names, property-account identifiers, route and general traffic-source labels, but not guest names, email addresses, phone numbers, messages, precise IP addresses, or persistent browser identifiers.

We do not currently use a third-party product-analytics or advertising provider. Before adding one, we will update this policy and introduce consent controls where required.

11. Service providers and subprocessors

We use providers only where needed to operate Salisea.

  • Cloudflare: hosting, content delivery, security, Workers, D1, R2, KV, Queues, Email Routing, and optional Workers AI.
  • Cloudflare Email Service: account verification, password-reset messages, notifications, inquiry replies, and inbound email routing.
  • Google: optional Google authentication and Google Places address search.
  • Telegram: optional owner notifications when a user connects the Salisea bot.

12. International transfers

Cloudflare and optional integration providers may process data outside the European Economic Area. Where required, transfers are protected by an adequacy decision, including the EU–US Data Privacy Framework where applicable, or the European Commission’s Standard Contractual Clauses.

13. Retention

We keep personal data only as long as needed for the purposes described above, legal obligations, dispute resolution, and security.

Unless a longer period is legally required or agreed with the customer, the intended production periods are:

  • account data: while the account is active, then 30 days, after which it is deleted or anonymised, except where retention is required by law or necessary to resolve a dispute;
  • workspace data, including normalized inquiries, bookings, and guest communications: while the account is active, then 90 days after account termination;
  • original email files and attachments: up to 90 days after receipt;
  • AI inputs, outputs, translations, and audit records: while the account is active, then 90 days after account termination;
  • security and operational logs: up to 7 days.
  • Free-plan public-inquiry delivery and abuse-prevention records: up to 7 days; transient email payloads are redacted after delivery or final failure.

Users must not rely on Salisea as their only legally required record or backup.

14. Security

We use measures designed to protect data, including encrypted transport, secure cookies, access controls, scoped tokens, password hashing, audit records, and restricted production secrets.

No system is completely secure. Users must protect their credentials, restrict team access, secure forwarding rules, and notify us promptly of suspected unauthorized access.

15. Your rights

Subject to the GDPR and applicable law, you may have rights to access, correct, erase, restrict, or receive your data, and to object to certain processing.

You may withdraw consent where processing relies on consent. Withdrawal does not affect processing performed before withdrawal.

Send requests to privacy@salisea.com. We may need to verify your identity before responding.

If your request concerns data controlled by an accommodation operator, contact that operator first. We will assist the operator as required by our processing agreement.

You may complain to the Croatian Personal Data Protection Agency (AZOP) or another competent supervisory authority in your country.

16. Children

Salisea accounts are not intended for children. Guest data about minors may appear in booking records only when provided lawfully by an accommodation operator for a legitimate accommodation purpose.

17. Changes

We may update this policy when the service, providers, or law changes. We will publish the new date and provide additional notice where a change materially affects users’ rights.

18. Contact

  • Controller pursuant to Article 4(7) GDPR: Samir Caus, trading as SaliSea
  • Address: c/o POSTFLEX PFX-744-129, Emsdettener Straße 10, 48268 Greven, Germany
  • Privacy email: privacy@salisea.com