Where does a hotel guest's WhatsApp message actually go?
A guest's WhatsApp message to a hotel that uses an AI assistant makes four stops: Meta, which delivers it; the vendor's servers, which store the conversation and look up the…
Mushon Nachmani
vGuest
A guest's WhatsApp message to a hotel that uses an AI assistant makes four stops: Meta, which delivers it; the vendor's servers, which store the conversation and look up the answer; an AI model provider, which generates the reply; and Meta again on the way back. The question a data-protection officer is really asking is not "where is it stored" but "where is it stored, and where else does it go", and the honest answer names a country for each stop.
This post walks that path for vGuest, using only what our published GDPR page states, and then turns it into the questions to put to any vendor. Across the 190+ properties we run, 97% of guest conversations arrive on WhatsApp (vGuest portfolio data, August 2026), so this is the path most hotel guest data takes.
Who is responsible for the data at each stop
Under the GDPR the hotel is the data controller of its guests' personal data, and vGuest acts as a data processor on the hotel's behalf. Every party further down the path is a sub-processor, engaged by the processor to do one job. That structure matters more than any single location: it decides who gives the instructions, who must be notified of changes, and whose contract governs each transfer.
Meta sits in the same structure. The WhatsApp Business Data Processing Terms (Meta, last updated 22 August 2025, read 18 September 2026) state that WhatsApp "shall only Process Personal Information in accordance with your instructions as set out in the Business Terms and these Data Processing Terms". Meta is a party to every WhatsApp message a hotel sends or receives, whichever vendor is in the middle.
Stop one: Meta delivers the message
A guest's message reaches the hotel's WhatsApp Business number through Meta Platforms Ireland Ltd., whose purpose in our sub-processor list is WhatsApp Business Platform message delivery, with a stated location of EU / Global. The safeguard listed is Standard Contractual Clauses, and the list draws one line worth quoting: only message content transits Meta, never internal hotel notes or tickets.
That line is the practical distinction between what a guest writes and what a hotel writes about the guest. The staff note that says "returning guest, complained about the pool last year" is not a WhatsApp message and does not travel this path. Whether that is true of another vendor is a question, not an assumption.
Stop two: the conversation record is stored in Frankfurt
All of vGuest's production infrastructure, application servers, databases and message queues, runs in Google Cloud region europe-west3 in Frankfurt, Germany, through Google Cloud EMEA (Google Ireland Ltd.). The conversation record, the guest profile and the requests are stored there, encrypted in transit with TLS 1.2 or higher and at rest with AES-256.
This is the stop most vendors mean when they say "EU-hosted", and it is a true and useful statement. It is also only one stop. A record can be stored in Frankfurt and still be processed elsewhere, which is why "stored" and "processed" need separate answers.
Stop three: the reply is generated in the United States
The step that generates the AI assistant's reply runs with AI model providers, OpenAI, Anthropic, Google and xAI, in the United States. The safeguards our list states for that transfer are Standard Contractual Clauses or the EU-US Data Privacy Framework, and enterprise API terms with no training on customer data.
This is the stop other vendors' pages tend to leave out, and it is the one a data-protection officer should press on. Generating a reply means the model provider processes the guest's message. The honest description is therefore: stored in the EU, processed in the United States for the reply, under a named transfer mechanism and a named no-training term. A vendor who can only give you the first half has not answered.
Stop four: media, connectors and the way back
Two further sub-processors appear on our list. Amazon Web Services stores public media files, the CDN-served images, in the United States under Standard Contractual Clauses, and holds no guest conversation data. PMS and telephony connectors, such as Optima, Mews or Twilio, handle reservation sync and voice or payment callbacks only where the hotel has enabled them; their location varies by provider, they are engaged only on the hotel's instruction, and they are listed in the hotel's DPA.
The reply then travels back through Meta to the guest. Where a transfer outside the EEA occurs anywhere on this path, our GDPR page states it is covered by the European Commission's Standard Contractual Clauses (2021/914) and/or the EU-US Data Privacy Framework, and that hotels are notified at least 30 days before any sub-processor change.
What the hotel can do with the data, and how fast
The controls a hotel has over guest data are as much part of the path as the locations. Our GDPR page states that a hotel can export a guest's full record, profile, conversation history and requests, in CSV or JSON at any time; permanently delete a guest's data via the dashboard or API, completed within 30 days of the request; and correct guest profile data and recorded preferences at any time. Marketing messages go only to guests with recorded consent, and opt-outs are honoured automatically by all campaign workflows. A guest can also request deletion directly through our data deletion page.
Inside the platform, access is role-based (Admin, Operator, Viewer) with per-hotel tenant isolation; API keys are scoped and least-privilege, session tokens are short-lived and signed; and API access and administrative changes are audit-logged for 90 days. The retention schedule per data category is published in the Privacy Policy. A Data Processing Agreement under Article 28 is available for signature with every hotel customer, and a personal data breach is notified to affected hotels without undue delay and within 72 hours of incident verification.
The questions to put to any vendor
The path above is one vendor's. The questions transfer to all of them, and a good vendor answers each in writing within a day.
1. Where is the conversation record stored? Country and region, not "the cloud". 2. Where does the AI reply get generated, and by which provider? If the answer is "our own models", ask where those run. 3. What leaves the EU, and under which transfer mechanism? Standard Contractual Clauses, the Data Privacy Framework, or something else, per sub-processor. 4. Is any guest data used to train models? Ask for the contractual term, not a reassurance. 5. What does Meta receive? Message content is unavoidable; internal notes and tickets should not be. 6. How do export and erasure work, and how long do they take? A dashboard action and an API call, with a stated deadline. 7. How and when are sub-processor changes notified? A notice period, in the DPA.
Our guide to what works and what breaks in WhatsApp guest communication covers the operational side of the same channel, and the guest messaging guide collects everything we have written on it.
What this post does not tell you
It is not legal advice, and it does not replace a hotel's own data protection impact assessment. It describes vGuest's published position as of September 2026; the GDPR page is the statement of record, and it changes with 30 days' notice when a sub-processor does. It does not describe how WhatsApp encrypts messages between a guest's phone and Meta, because that is Meta's documentation to state, not ours. It does not give retention periods, which live in the Privacy Policy rather than here. And it says nothing about any other vendor's data path, which is exactly why the questions above exist.
One more limit is Meta's, not the vendor's. From 1 October 2026 Meta charges per message for the replies a hotel sends inside the customer service window, which we cover in WhatsApp replies to hotel guests stop being free in October. The data path does not change on that date; the bill for travelling it does.
What to do first
Ask your current vendor, in writing, for two things: the sub-processor list with a country against each entry, and the sentence that says where the AI reply is generated and whether guest data is used for training. If both arrive within a day and match what the vendor's website says, you have a data path you can put in front of your data-protection officer. If either takes a week, you have your answer too.
Common questions
Where is a hotel guest's WhatsApp data stored?
In vGuest's case, the conversation record is stored on Google Cloud in the EU, region europe-west3 in Frankfurt, encrypted in transit and at rest. Storage and processing are different things: the text of a message also transits Meta for delivery and is processed by an AI model provider in the United States to generate the reply. Ask any vendor for both answers, not one.
Does a guest's message leave the EU when a hotel uses an AI assistant?
Parts of it do, and a vendor should say which. On vGuest, the stored record stays in Frankfurt, message content transits Meta for WhatsApp delivery, and the step that generates the AI reply runs with model providers in the United States under Standard Contractual Clauses or the EU-US Data Privacy Framework. Public media files are held on Amazon Web Services in the United States and contain no conversation data.
Is guest conversation data used to train AI models?
vGuest's published sub-processor list states that its AI model providers are engaged under enterprise API terms with no training on customer data. That is the wording to look for from any vendor: a named provider, a named contractual term, and the phrase no training, in writing.
What does Meta see when a guest messages a hotel on WhatsApp?
Meta delivers the message, so message content passes through Meta Platforms Ireland regardless of which vendor the hotel uses. vGuest's sub-processor list states that only message content transits Meta, never internal hotel notes or tickets. Meta's own Business Data Processing Terms say WhatsApp processes personal information only in accordance with the business's instructions.
How is a guest's data deleted from a hotel messaging platform?
On vGuest, a hotel can permanently delete a guest's data from the dashboard or by API, completed within 30 days of the request, and a guest can ask directly through the data deletion page. A hotel can also export a guest's full record, profile, conversation history and requests, as CSV or JSON at any time.
Keep reading
All articles190+ properties · 6 countries
See it answering your guests
Bring your own property. We will show you what the assistant does with your real questions, in your languages, on WhatsApp.

