XENIA

Legal

Privacy Policy

Last updated September 24, 2026

This is the Privacy Policy of TALARIA SASU, publisher of XENIA, acting as data controller for the processing relating to its website, the management of its customer accounts, billing, support and inbound business requests. It is published at xenia.khelys.dev/privacy.

It is established in accordance with Regulation (EU) 2016/679 (GDPR) and French Law no. 78-17 of 6 January 1978 on data processing, files and individual liberties, as amended (Loi Informatique et Libertés).

Preamble — distinction from the DPA

This Privacy Policy covers the processing operations for which TALARIA acts as data controller: browsing of the Site, management of user accounts and the customer relationship, billing, inbound business requests and the business relationship, and support.

It does not cover the processing of the personal data of hotels' guests (reviews, bookings) carried out on behalf of the hotels in the course of the Service: for that processing, TALARIA acts as a processor and the hotel (the Customer) is the controller — such processing is governed by the Data Processing Agreement (DPA, Article 28 GDPR).

1. Data controller

TALARIA SASU — R.C.S. Paris 105 647 119 — registered office at 1 rue de Chazelles, 75017 Paris, France — represented by Hermès Coutureau, President. Data protection contact: hermes@khelys.dev. TALARIA has not appointed a data protection officer; the contact above handles all data protection requests.

2. Data collected, purposes and legal bases

Depending on the context, we process the following categories of personal data:

  • Browsing of the Site — connection data (IP address, date/time, browser) and navigation data, for the operation and security of the Site and audience measurement. Legal basis: legitimate interest (Art. 6(1)(f)); consent for non-essential cookies (Art. 6(1)(a)).
  • Contact and demo request forms — name, professional email, hotel or group name, number of hotels, topic and message, to respond to your request. Legal basis: pre-contractual measures taken at your request (Art. 6(1)(b)) / legitimate interest in answering professional enquiries (Art. 6(1)(f)).
  • User account — identity, professional email, role, credentials, hotel(s) attached, for account creation and management and the provision of the Service. Legal basis: performance of the contract (Art. 6(1)(b)).
  • Product analytics (in-app, optional) — if you accept analytics cookies, pages viewed and features used, linked to your account (email, name, role, hotel) to understand and improve the Service. Legal basis: consent (Art. 6(1)(a)), which you can withdraw at any time (Section 6).
  • Support — ticket subject, category, severity, messages and attachments, and the identity of the requester, to handle and follow up support requests. Legal basis: performance of the contract (Art. 6(1)(b)).
  • Billing / accounting — billing details, bank details for direct debit (collected by our payment service provider GoCardless), invoicing and payment history, for billing, debt recovery and accounting obligations. Legal basis: legal obligation (Art. 6(1)(c)) / performance of the contract (Art. 6(1)(b)).
  • Inbound requests and business relationship — professional contact details (name, job title, company, professional email and telephone) of hotel professionals who contact us or are introduced to us, to follow up on their interest in XENIA. Legal basis: legitimate interest (Art. 6(1)(f)). You may object at any time, without giving reasons.

Source of data not collected from you (Article 14 GDPR). We do not buy contact lists and do not use data-enrichment or prospecting tools. Where your professional contact details were given to us by a third party — typically an existing customer or a business contact who recommended XENIA to you — that recommendation is their source; they do not come from publicly accessible sources. We inform you of this, and of your right to object, in our first message and at the latest within one month of receiving your details.

Fields marked as required in our forms are needed to answer your request; without them we cannot respond. Account data is required to provide the Service under the contract. No special-category data (Article 9 GDPR) is requested.

3. Processors and recipients

Data is processed by TALARIA and, for the purposes set out above, by the following providers. Data is never sold or rented to third parties.

  • Processors acting on TALARIA's behalf (each bound by an agreement compliant with Article 28 GDPR): Vercel — hosting of the Site and the application, execution of the contact and demo forms, cookieless audience measurement (United States); Supabase (Supabase Pte. Ltd., Singapore) — database, authentication and storage of support attachments (EU, Frankfurt); Google Workspace (Google Cloud France SARL) — professional mailbox receiving contact and demo requests, support notifications and requests to exercise your rights (EU, with possible transfers to Google LLC, United States); Resend — delivery of emails, including form and support notifications (United States); Discord — internal notification of support tickets: hotel name, category and a short excerpt (United States); Anthropic — AI analysis of support ticket subjects by our internal product tooling, with no training on your data (United States); PostHog (PostHog, Inc.) — product analytics, only with your consent (hosted in the EU, Frankfurt; U.S. provider); Sentry — error monitoring (United States); Pennylane — invoicing and accounting (EU).
  • Independent controllers: GoCardless SAS, a payment institution, for the collection of SEPA direct debits and the related regulatory obligations, and, where card payment is agreed in the Order Form, Stripe. Each applies its own privacy notice.
  • Other recipients: TALARIA's chartered accountant, for statutory accounting purposes; competent authorities, where required by law.

4. Transfers outside the European Union

Certain providers are established, or process data, outside the European Union — mainly in the United States, and in Singapore for Supabase's contracting entity (see Section 3). No transfer takes place without one of the safeguards provided for in Chapter V GDPR (Articles 44 to 49):

  • Basis for every transfer — the Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914 of 4 June 2021), in the applicable module, incorporated in each provider's data processing agreement (Article 46(2)(c) GDPR);
  • In addition, where the U.S. provider is certified under the EU-U.S. Data Privacy Framework, the Commission's adequacy decision of 10 July 2023 (Implementing Decision (EU) 2023/1795, Article 45 GDPR). We check certifications on the official DPF List at each review of our provider list. If a certification or the adequacy decision lapses, the transfer remains covered by the Standard Contractual Clauses;
  • Supplementary measures — encryption in transit and at rest, data minimisation and access control, together with a documented transfer impact assessment for the main importers, in line with EDPB Recommendations 01/2020.

You can obtain a copy of these safeguards (the relevant Standard Contractual Clauses) by writing to hermes@khelys.dev.

5. Retention periods

  • Accounts and contractual data: duration of the contractual relationship + 5 years (limitation period, Article 2224 of the French Civil Code / Article L.110-4 of the French Commercial Code);
  • Support tickets and attachments: duration of the contract, then 5 years as evidence (same limitation period);
  • Accounting records and invoices: 10 years (Article L.123-22 of the French Commercial Code);
  • Contact and demo requests, inbound contacts and introductions not followed by a contract: 3 years from the last contact coming from you (CNIL recommendation);
  • Product analytics and session recordings (PostHog): 30 days;
  • Cookies: consent record (xenia_consent) 6 months, after which we ask you again; other cookies 13 months maximum (CNIL guidelines).

6. Cookies and trackers

Under Article 5(3) of the ePrivacy Directive (Article 82 of the French Data Protection Act) and the CNIL guidelines, consent is required to read or write information on your device unless the tracker is strictly necessary to provide a service you explicitly requested, or is used solely for anonymous, cookieless audience measurement that meets the CNIL exemption criteria. Consent, where required, is collected under Articles 6(1)(a) and 7 GDPR.

Our cookie settings group the trackers of the Site and the application in four categories:

  • Strictly necessary — always active. sb-…-auth-token (XENIA, Supabase, EU) keeps you signed in to the application and is deleted when you close the browser; xenia_consent (XENIA, first-party) remembers your cookie choices for 6 months. No consent required; they do not track you.
  • Product analytics — off until you switch it on. PostHog (EU-hosted, Frankfurt): pages viewed, clicks, device type, approximate city, to understand which pages are used and where people get stuck. Trackers: the ph_…_posthog cookie (anonymous visitor ID and session, 1 year) and __ph_opt_in_out_… in local storage (remembers whether analytics is allowed, until you clear it). Data kept 30 days. Requires consent.
  • Session replay — off until you switch it on. An anonymised PostHog recording of how you move through the Site, with everything you type masked; it uses the same ph_…_posthog cookie and requires product analytics. Recordings kept 30 days. Requires consent.
  • Cookieless measurement — no cookie. Vercel Web Analytics and Speed Insights (anonymous page counts and loading speed) and Sentry (error reports). Nothing is stored in your browser, so no consent is needed.

We do not use advertising or targeting cookies, and nothing follows you to other websites. Until you opt in, no PostHog script runs and nothing is stored in your browser beyond the strictly necessary cookies.

A cookie pop-up lets you accept all, reject all (on the same screen, as easily as accepting), or choose per category in the cookie settings (Product analytics, and Session replay which requires Product analytics). Optional categories are off until you switch them on. Closing the pop-up without choosing records nothing and activates nothing optional; we ask you again on your next visit. Your choice is stored for 6 months in the first-party xenia_consent cookie. You can change or withdraw your consent at any time, as easily as you gave it, through the "Cookie settings" link in the footer of every page (and in your account menu in the application). Withdrawal stops PostHog immediately, deletes the PostHog cookies and local-storage entries from your browser, and does not affect the lawfulness of processing carried out before it.

7. Rights of data subjects

In accordance with Articles 15 to 22 GDPR, you have the rights of access, rectification, erasure, restriction and portability, and the right to withdraw your consent at any time where processing is based on consent, without affecting processing carried out before the withdrawal. Under Article 85 of the French Data Protection Act, you may also give instructions on the fate of your data after your death.

Right to object. You may object at any time, on grounds relating to your particular situation, to processing based on our legitimate interest, and at any time and without giving reasons to the use of your data for commercial outreach (Article 21 GDPR).

To exercise your rights, write to hermes@khelys.dev or to TALARIA SASU, 1 rue de Chazelles, 75017 Paris, France. We reply within one month of receipt; this period may be extended by two months for complex or numerous requests, in which case we tell you within the first month. We may ask for proof of identity only where we have reasonable doubts about it.

No automated decision-making. TALARIA does not take any decision producing legal or similarly significant effects about you based solely on automated processing, including profiling (Article 22 GDPR).

You may lodge a complaint with the French data protection authority, the CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 (www.cnil.fr).

8. Security

TALARIA implements appropriate technical and organisational measures (encryption in transit and at rest, access control, tenant isolation) within the meaning of Article 32 GDPR.

Questions? hermes@khelys.dev. See also Legal Notice and Terms of Service.