Legal

Privacy
Policy.

How BaltIQ processes personal data, Google user data, hotel guest information and AI-assisted content on behalf of hotels and hospitality businesses, operated by BaltIQ Novum OÜ, Tallinn, Estonia.

Last updated

14 September 2026

Operator

BaltIQ Novum OÜ
Registry code 17557215
K. Kärberi tn 37, Lasnamäe linnaosa,
Tallinn, Harju maakond, 13919, Estonia
edward@baltiqnovum.com

Who we are

BaltIQ is operated by BaltIQ Novum OÜ, a private limited company registered in the Republic of Estonia under registry code 17557215. Our registered address is K. Kärberi tn 37, Lasnamäe linnaosa, Tallinn, Harju maakond, 13919, Estonia. You can reach us by email at edward@baltiqnovum.com and through our website at https://baltiqnovum.com/.

BaltIQ is a business-to-business software-as-a-service and AI platform designed primarily for hotels, hotel groups, serviced apartments and other hospitality businesses.

Scope of this Privacy Policy

This Privacy Policy covers the BaltIQ website, the BaltIQ platform, authorised users of customer organisations, and the integrations and other services we provide.

It is important to distinguish between two different roles BaltIQ may have:

BaltIQ Novum OÜ acts as a data controller when we process personal data for our own purposes, such as managing website visitors, business contacts, prospective customers and account administration.

BaltIQ acts as a data processor on behalf of a hotel or other customer when we process hotel guest data, reservation data, communications and operational information supplied through connected systems. In those cases, the customer hotel generally determines the purposes and means of processing its guest data and remains responsible for having an appropriate lawful basis for that processing.

Categories of personal data

Depending on the services and integrations used, BaltIQ may process the following categories of personal data:

Contact and account information, including name, email address, phone number, organisation, job role and account credentials.

Reservation and stay details, including room type, dates of stay, booking information, guest preferences, communication history and message content.

Customer service requests, complaints and other operational information provided by or on behalf of a customer.

Google account identifiers and OAuth-related information when a user connects a Google account.

Google Business Profile information and reviews where the customer has authorised access.

Technical data such as IP address, browser and device information, logs and security information.

Other data intentionally provided by a customer, authorised user or guest through the platform or connected systems.

We do not collect categories of personal data that are not reasonably necessary for the operation of the service.

How and why we use personal data

Personal data may be processed in order to:

Provide and operate the BaltIQ platform;

Authenticate users and maintain secure access;

Connect and maintain authorised integrations with third-party systems;

Retrieve and display relevant hotel and guest information;

Assist hotel staff with guest communications;

Generate AI-assisted drafts, summaries, classifications and operational insights;

Maintain guest and customer profiles on behalf of customers;

Provide customer support;

Maintain security, prevent abuse and troubleshoot errors;

Comply with applicable legal obligations;

Improve the reliability and functionality of the service using appropriately limited data.

Google API Services User Data

When a user connects a Google account to BaltIQ, BaltIQ only accesses Google data after the user has granted OAuth permission through Google's authorisation flow.

Depending on the permissions selected and the functionality enabled, BaltIQ may access data necessary for features such as:

Reading relevant Gmail messages associated with hotel operations and guest communication;

Displaying or processing relevant email content inside BaltIQ;

Creating AI-assisted email drafts for review by hotel staff;

Sending emails only when authorised by the user and permitted by the selected workflow;

Accessing authorised Google Business Profile information and reviews;

Maintaining the connection using OAuth tokens.

BaltIQ uses Google user data only to provide or improve the user-facing features requested by the user or customer. BaltIQ does not sell Google user data. BaltIQ does not use Google user data for advertising. BaltIQ does not transfer Google user data to third parties except where necessary to provide the requested service, comply with law, protect security, or where the user or customer has authorised such processing.

BaltIQ does not allow humans to read Google user data except where necessary for security, support requested by the user, compliance with applicable law, or where the user has explicitly authorised such access.

BaltIQ's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

AI processing

Certain information submitted to or processed by BaltIQ may be processed by artificial intelligence systems to produce responses, drafts, classifications, summaries, recommendations or operational insights.

AI outputs are intended to assist users and may contain errors. They should be reviewed by appropriately authorised staff before being relied upon or acted upon, particularly for important or sensitive matters.

BaltIQ does not use guest data or Google user data to train general-purpose AI models unless that is explicitly implemented and separately consented to.

BaltIQ does not sell customer or Google data, and does not use such data for unrelated AI training.

Third-party service providers and subprocessors

BaltIQ may rely on third-party infrastructure and technology providers necessary to operate the service. These may include, for example, cloud hosting and database providers, AI and model providers, Google APIs and Google Cloud, property management and hospitality technology providers, email and communications providers, and monitoring and security providers.

Such providers process information only as necessary for their role and subject to appropriate contractual or legal safeguards where applicable.

Data sharing

Personal data may be disclosed in the following circumstances:

To authorised users of the customer organisation;

To service providers and subprocessors that support the operation of the service;

When required by law, regulation, legal process or governmental request;

In connection with security, fraud prevention or protection of rights;

In connection with a corporate transaction, such as a merger or acquisition, where legally permitted;

Based on the user's or customer's instruction or consent.

BaltIQ does not sell personal data.

Legal bases under GDPR

Where BaltIQ Novum OÜ acts as a controller, processing may rely on one or more of the following legal bases: performance of a contract, legitimate interests, compliance with legal obligations, and consent where appropriate.

Where BaltIQ acts as a processor, processing is carried out on the documented instructions of the customer or controller and is governed by the applicable contractual arrangements.

Data retention

Personal data is retained only for as long as reasonably necessary for the purposes described in this Privacy Policy, to fulfil contractual obligations, to maintain security, to resolve disputes and to comply with legal obligations.

Retention periods may vary depending on the type of information and the applicable customer agreement.

OAuth tokens and integration credentials are retained only while needed to maintain the authorised connection, subject to applicable security and deletion procedures.

Security

BaltIQ uses reasonable technical and organisational measures intended to protect personal data against unauthorised access, alteration, disclosure or destruction. No system can guarantee absolute security.

International data transfers

Some service providers may process information outside Estonia or the European Economic Area. Where required, BaltIQ will use legally recognised transfer mechanisms or other appropriate safeguards for international data transfers.

Data subject rights

Depending on applicable law, individuals may have rights including:

The right to access personal data;

The right to correct inaccurate personal data;

The right to request deletion of personal data;

The right to restrict processing;

The right to object to processing;

The right to data portability where applicable;

The right to withdraw consent where processing is based on consent;

The right to lodge a complaint with the competent data protection authority.

For guest data processed on behalf of a hotel, guests may need to contact the relevant hotel or controller directly. BaltIQ will assist the customer where required by the applicable arrangement.

Google account connection and revocation

Users can revoke BaltIQ's access to their Google account at any time through their Google Account permissions or security settings.

Users may also contact BaltIQ to request disconnection or deletion of integration-related information, subject to applicable contractual and legal requirements.

Cookies and technical data

The BaltIQ website and platform may use cookies or similar technologies necessary for authentication, security, preferences and analytics where applicable.

Children

BaltIQ is a business service and is not directed at children. We do not knowingly collect personal data from children.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The current version is published at https://baltiqnovum.com/privacy with its last-updated date. Continued use of BaltIQ after the updated Privacy Policy takes effect constitutes acceptance of the updated terms.

Contact

BaltIQ Novum OÜ Registry code: 17557215 K. Kärberi tn 37, Lasnamäe linnaosa, Tallinn, Harju maakond, 13919, Estonia Email: edward@baltiqnovum.com Website: https://baltiqnovum.com/