Privacy
Privacy notice
This notice primarily describes processing connected with the public website hestix.it. Use of the Hestix platform may involve additional processing depending on the enabled features and the contractual relationship with the customer.
Scope of this notice
The public website at https://hestix.it is a predominantly static information website. It is separate from the application available at https://app.hestix.it.
This page is not a Data Processing Agreement, does not provide an exhaustive account of SaaS processing and does not replace the agreements that apply between Hestix and each customer.
Data controller
The data controller for the public website hestix.it is Cartolibreria Pieroni di A. & S. Sanguigni & C. s.a.s., Via Palermo 5/7, 04019 Terracina (LT), Italy, VAT no. 00557040599, REA LT-59473. Privacy requests may be sent to the certified email address (PEC) 5703@pec.aruba.it. Hestix is the brand and project through which the controller presents the platform.
Purposes and legal basis
Technical browsing data may be needed to deliver the website, keep it secure and diagnose faults. The website introduces no profiling, advertising or analytics measurement purpose.
For technical processing necessary to protect the security, integrity and proper delivery of the website, processing is based, where applicable, on the controller's legitimate interest in protecting the service and its infrastructure. Any additional processing is governed by the purpose and legal basis relevant to that activity.
Technical logs and security
The project configures security headers and uses a Content Security Policy that restricts website resources to the hestix.it origin. Ordinary HTTP logs may nevertheless exist at Apache, proxy or hosting level.
Technical logs are accessible only to authorised persons and infrastructure providers involved in delivering and securing the service and are retained for the period necessary for the relevant technical and security purposes.
Links to external services
An ordinary external link is not an embed or tracker. The website links to app.hestix.it for login but does not preload its SDKs, frames or resources while a user visits the public page.
When a user chooses to open an external service, they leave the public website context and the terms and privacy information of the selected service also apply from that point. Email links on the website open the visitor's own mail client and load no third-party resources.
Demo requests and contact
The verified version has no contact form, no lead endpoint and the public website neither collects nor sends enquiry data. The demo access calls to action open the visitor's own email client with a message prefilled to info@hestix.it: the website does not record the request and the message is sent by the visitor from their own client.
If a contact channel handled directly by the website is introduced, for example a form or an endpoint, this notice must be updated before activation with the relevant data, purposes, legal basis, recipients and retention.
Hestix SaaS and the public website
The Login link leads to https://app.hestix.it. Authentication, customer data, bookings, guests, conversations, access, compliance workflows and other capabilities belong to the application context, not to the technical processing of the static website described here.
The public page may explain general product principles, but it does not define privacy roles, customer instructions, subprocessors or contractual terms for the platform.
How Hestix uses artificial intelligence
The documented architectural direction separates verifiable results from AI interpretation: data → Hestix logic → deterministic result → optional AI → interpretation. For financial data, KPIs, margins, occupancy, ADR, RevPAR, OTB/Pace and similar values, AI is not described as the source of the number.
In short: “Hestix calculates the numbers. AI helps you understand them.” This responsibility is distinct from operational automations, which follow product rules and configuration.
Data minimisation in AI features
The stated principle is to provide AI features only with the context necessary for the specific task and not to include personal data or special categories where they are not needed.
For Financial Control and OTB/Pace, AI interpretation is designed to work on previously calculated results, KPIs, aggregates, unit data and the information needed for the analysis, without requiring guest-identifying data where it is not relevant to the purpose.
This principle does not mean that every AI feature processes numbers only: conversational features may require conversation text and relevant operational context. Hestix applies data minimisation according to the specific task.
Conversational AI, Knowledge and Human Review
Conversational features may naturally require processing conversation text, Approved Knowledge, relevant operational context and, where necessary for the response, guest context. The context provided should be limited to what the requested feature needs.
Knowledge, conversation and operational context have separate roles. Conversation Learning may identify signals or candidates, but it does not mean uncontrolled self-training: where provided by the product, a person reviews what may become Approved Knowledge. The website does not claim that private conversations automatically become public or shared Knowledge.
AI providers and automated decisions
Some AI features may use external technology services. The related processing depends on the enabled feature and application context; this public-website notice does not attribute specific retention, location or contractual guarantees to a provider where they do not apply generally.
The website distinguishes deterministic calculation, AI interpretation, Human Review and configured automation. It does not conclude, without application and legal analysis, whether automated decisions with legal or similarly significant effects exist.
Retention, recipients and transfers
The website does not store cookies, consent preferences or demo requests in its own database. Ordinary infrastructure logs may be processed by authorised persons and providers required to deliver, secure and maintain the service, for the period necessary for those purposes.
Any processing involving external providers or international transfers is assessed in relation to the service actually used and the safeguards that apply.
Data subject rights
Where and to the extent provided by applicable law, a data subject may request access, rectification, erasure, restriction, objection and portability, and may withdraw any consent without affecting earlier processing.
A complaint may also be lodged with the competent supervisory authority; in Italy, the Garante per la protezione dei dati personali.
How to exercise your rights
To exercise data-protection rights or request information about processing, the controller may be contacted through the certified email address (PEC) 5703@pec.aruba.it.
Changes to this notice
This notice will be updated when website behaviour, contact channels, technologies or relevant contractual and infrastructure facts change. Changes must precede the activation of new processing that requires notice or consent.
Last updated: 14 September 2026