← Back to Moiloo Wifi

Moiloo Wifi legal

GDPR & Data Protection

This page describes Moiloo Wifi's approach to the EU and UK General Data Protection Regulation and is intended to help venue operators understand their responsibilities.

Last updated: September 1, 2026

1. Our role under the GDPR

For account, billing, support, and website information, Moiloo Wifi generally acts as a controller because we decide how that information is used to provide and operate our business.

For personal information a venue collects from guests through a Moiloo Wifi portal, the venue generally acts as the controller and Moiloo Wifi acts as a processor. We process that information on the venue's documented instructions and provide tools to help the venue manage its obligations.

2. Venue operator responsibilities

  • Determine the purpose and lawful basis for collecting guest information.
  • Provide a clear, accessible privacy notice before or at the point of collection.
  • Collect only information that is necessary for the stated purpose.
  • Obtain and record consent where consent is the appropriate legal basis, including for marketing.
  • Configure retention, access, and portal settings appropriately.
  • Respond to guest rights requests and maintain records of processing where required.

3. Processing instructions and data minimization

Moiloo Wifi processes guest data to provide the features selected by the venue, including portal access, guest records, analytics, exports, and communications configured by the venue. Venue operators should not submit sensitive personal data unless the Service and their documented instructions specifically support it.

4. Data subject requests

Venue operators should send guest access, correction, deletion, restriction, portability, or objection requests to the venue that collected the data. We provide reasonable assistance to help venues respond, including locating, exporting, correcting, or deleting data where our systems support the request.

If you are unable to identify the relevant venue or are making a request about your direct relationship with Moiloo Wifi, contact privacy@moiloo.com. We may verify your identity and ask for information needed to route the request correctly.

5. Data processing terms and subprocessors

Where GDPR applies to guest data, the parties should have appropriate data processing terms in place. Those terms describe the subject matter, duration, nature, purpose, categories of data, and responsibilities for the processing. Service providers that support the platform may process data as subprocessors under appropriate contractual obligations.

Contact us if you need to discuss a data processing agreement or current service-provider information for your account.

6. Security and incident support

We maintain reasonable technical and organizational safeguards designed to protect personal data. If we become aware of a personal data incident affecting information processed for a venue, we will provide notice and reasonable cooperation as required by applicable law and our agreement with that venue.

7. International transfers

Personal data may be processed outside the European Economic Area or the United Kingdom. When a restricted transfer occurs, we use a lawful transfer mechanism and appropriate safeguards as required by applicable data protection law.

8. Contact our privacy team

For GDPR questions, data subject requests relating to Moiloo Wifi, or data processing agreement requests, contact privacy@moiloo.com. This page is general information and is not legal advice; venue operators should obtain advice appropriate to their own activities and jurisdictions.

Questions about this page? Contact privacy@moiloo.com.