Privacy Policy
Last updated: 27 April 2026
This policy explains what personal data HOLM AI collects, why we collect it, how we protect it, and the rights you have over it. We've tried to keep it plain. If anything is unclear, email us at legal@useholm.com.
1. Who we are
HOLM AI is operated by AI STUDIO 10, LLC, a Florida limited liability company, which is the data controller for the personal data described in this policy. Our principal place of business is 830 Brickell Plaza, Miami, FL 33131.
You can reach our privacy team at privacy@useholm.com.
2. What personal data we collect
We collect only what we need to provide the service. The main categories are:
- Account data — name, email, company, role and authentication credentials.
- Operator data — listing information, policies, team members and billing details.
- Guest data — names, contact details, messages, ID verification records (if enabled), stay information. Processed on behalf of operators.
- Usage data — how the platform is used, including logs, device information and diagnostics.
- Payment data — handled by our payment processor. We do not store full card numbers.
3. Why we collect it
We process personal data to:
- Provide HOLM’s features — guest comms, field ops, finance, guest experience, growth and AI supervision.
- Authenticate users, bill for the service and prevent misuse.
- Improve and secure the platform with product analytics and operational monitoring.
- Meet our legal obligations, including fraud prevention, tax reporting and responding to lawful requests.
Legal bases under the UK GDPR / EU GDPR include: contract (to deliver the service), legitimate interests (to operate and improve the service responsibly), consent (where required) and compliance with legal obligations.
4. AI processing
HOLM uses AI models to assist with guest communication, field operations, finance and governance. All AI actions are bound by per-property policies set by the operator, logged, and reversible.
Where possible, we route AI workloads to providers offering data-residency options within the EU. Guest messages and operational data are processed for the specific purpose of running the service and are not used to train third-party foundation models.
6. How long we keep data
We retain personal data only for as long as needed to provide the service and meet our legal obligations. When an account is closed, personal data is deleted or anonymised according to our retention schedule, typically within 90 days of closure, subject to statutory retention requirements for tax and accounting records.
7. Your rights
You have rights over your personal data, including access, rectification, erasure, restriction, portability and objection. You can also withdraw consent where we rely on it and lodge a complaint with your data protection authority.
To exercise any of these rights, email privacy@useholm.com. We respond within one month.
8. Security
HOLM is built with per-tenant isolation at the database level, AES-256 encryption at rest, TLS 1.3 in transit, and strict access controls. We hold SOC 2 Type II and undergo regular penetration testing. Our security practices are detailed in our DPA.
9. International transfers
We host customer data in the EU by default. Where we transfer personal data outside the EEA or UK, we rely on appropriate safeguards such as Standard Contractual Clauses and the UK International Data Transfer Addendum.
10. Changes to this policy
We’ll update this policy from time to time. Material changes are announced at least 30 days in advance via email to account admins and on this page.