MyDiafa
FeaturesEvents automationContact
Start an event

Privacy at MyDiafa

Privacy Notice

Hospitality is personal. This notice explains what MyDiafa remembers, why it is needed, where technology helps, and the choices available to you.

Effective and last updated: July 12, 2026

On this page

Who we are and what this notice coversInformation we collectHow we use informationAI and large language modelsOAuth, Google sign-in, and SSOMaps, places, and location servicesPayments and financial connectionsWhen we disclose informationRetention and deletionSecurity and resilienceYour choices and privacy rightsCookies and service analyticsChildrenInternational data transfersChanges and contact

01

Who we are and what this notice covers

MyDiafa is a hospitality and event-operations service operated by Cloud Motion Technologies LLC (“Cloud Motion,” “MyDiafa,” “we,” “us,” or “our”). This notice explains how we handle personal information when you visit mydiafa.com, create or use a MyDiafa account, participate in an event, communicate with a venue through MyDiafa, or use a connected service.

A venue, restaurant, event host, employer, or other organization may use MyDiafa to manage information on its behalf. In that situation, the organization controls many decisions about its event and guest data, and its own privacy notice may also apply. We process that information to provide the service and follow the organization's authorized instructions. Cloud Motion separately determines how account, security, service-improvement, billing, and website information is handled.

02

Information we collect

The information we collect depends on your relationship with MyDiafa and the features that are enabled. It may include:

  • Identity and account information: name, email address, profile image, authentication identifiers, organization membership, role, permissions, and account preferences.
  • Event and hospitality information: inquiries, proposals, dates, venues, spaces, menus, timelines, guest lists, attendance, accommodations, dietary or allergy details, accessibility needs, and other event-care instructions.
  • Business and relationship information: company, household, vendor, contact, contract, approval, invoice, and authorized-representative information.
  • Communications and content: email, messages, call details, attachments, support requests, notes, feedback, and records of commitments or approvals.
  • Transaction information: pricing, invoices, payment status, refunds, disputes, provider references, bank-connection status, and reconciliation evidence. MyDiafa is designed not to store raw card numbers, card verification codes, or online-banking credentials.
  • Location information: venue, event, delivery, or address information you provide, together with map, place, distance, or routing results when a mapping feature is used.
  • Device and usage information: IP address, browser and device type, pages and features used, timestamps, session and security events, diagnostic data, and cookie or similar identifiers needed to operate and protect the service.
  • AI interaction information: prompts, instructions, source material, generated drafts or summaries, feedback, and records needed to explain or audit an AI-assisted action.

We receive information from you, the organization or host responsible for an event, invited participants, connected providers, and the devices and systems used to access MyDiafa.

03

How we use information

We use personal information to operate and secure MyDiafa; authenticate users; enforce organization roles and event permissions; prepare and manage inquiries, proposals, contracts, events, guest care, communications, payments, and operational follow-up; provide support; maintain audit and reconciliation records; prevent fraud and misuse; comply with law; and improve the reliability and usefulness of the service.

We may also use information to customize what you see, remember authorized preferences, recommend next steps, prepare drafts, organize event details, and make the experience more relevant to your role and event. We do not use private dietary, allergy, accessibility, or accommodation information for advertising.

04

AI and large language models

MyDiafa may use artificial intelligence and large language models, including the Habibi concierge, to personalize the experience and help retrieve, classify, extract, translate, summarize, draft, recommend, and route hospitality work. An AI feature may process the information you provide and authorized information already associated with your account, organization, or event.

We use approved technology providers under service and confidentiality controls when an outside model or tool is needed. MyDiafa's policy is not to permit those providers to train general-purpose models on customer data submitted through the service. We minimize the information sent for each task and do not place provider credentials, raw payment credentials, or unrestricted cross-organization data into model prompts.

AI output can be incomplete or wrong. It does not replace contracts, approved event plans, allergy or safety records, professional advice, or required human approval. MyDiafa is designed so that AI does not independently make legally significant decisions, move money, accept contracts, waive terms, infer protected or sensitive traits, decide privacy requests, or conceal uncertainty. Where an AI, recording, or transcription feature is optional, we provide a human or non-AI path when reasonably available.

05

OAuth, Google sign-in, and SSO

You may be able to sign in through Google OAuth, email authentication, or an enterprise single sign-on provider. These providers send MyDiafa the identity attributes needed to authenticate you, such as your name, email address, profile image, provider account identifier, and authentication status. Enterprise SSO may also provide organization and role-related attributes configured by your administrator.

MyDiafa's Google sign-in requests only the openid, email, and profile scopes. We use that Google user data to identify you, create or connect your MyDiafa account, display your basic profile, protect the service, and maintain your session. Google sign-in does not give MyDiafa access to your Gmail messages, Google Drive files, contacts, or calendar. If an organization administrator separately chooses Connect my Google Calendar, MyDiafa requests calendar event-write access and uses it only to push explicitly selected Diafa events to the administrator-selected calendar; it does not import Google events into Diafa. We do not sell Google user data or use it for advertising. Our use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements where applicable.

Your identity provider controls its own collection and security practices. You can manage or revoke connected-app access from that provider, but revocation may prevent provider-based sign-in.

06

Maps, places, and location services

If Google Maps Platform or another mapping provider is enabled, MyDiafa may send addresses, place searches, map interactions, approximate device location if you allow it, and related technical information to that provider to display maps, suggest places, calculate distance or routing, and support event logistics. Google's Terms of Service and Privacy Policy apply to Google Maps features. Do not use map fields to submit private information that is not needed for the location task.

07

Payments and financial connections

When payment features are enabled, Stripe or another approved payment provider may collect payment-method, identity, device, transaction, and fraud-prevention information directly through provider-controlled components. We receive status, amount, payer, provider reference, refund, dispute, and reconciliation information needed to manage the event transaction.

If you choose to connect a financial account through Plaid or another bank-data provider, that provider may collect account credentials and retrieve the account, balance, ownership, or transaction information you authorize. MyDiafa receives only the information and connection tokens needed for the feature you selected. We do not ask you to place online-banking credentials into MyDiafa fields or AI prompts. Plaid's End User Privacy Policy also applies when Plaid is used. You can disconnect a financial connection, although we may retain transaction and authorization evidence required for accounting, security, disputes, or law.

08

When we disclose information

We disclose personal information only as reasonably needed for the purposes described in this notice:

  • to the organization, venue, host, planner, guest, vendor, or authorized collaborator involved in the event, according to permissions and the purpose of the information;
  • to service providers that support hosting, authentication, databases, communications, email, AI, maps, payments, financial connections, voice, documents, monitoring, analytics, security, support, or professional services;
  • at your direction or with your consent, including when you connect a third-party account or ask us to send information;
  • to comply with law, legal process, or lawful government requests; enforce agreements; investigate fraud or security incidents; or protect people, rights, property, and the service; and
  • as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of the business, subject to appropriate confidentiality and notice requirements.

Depending on the enabled feature, providers may include Cloudflare, Supabase, Postmark, Google, KaizenIS identity and Voice Engine services, Stripe, Plaid, communications providers, approved AI/model providers, accounting or calendar providers, and enterprise identity providers. A provider is given only the access needed for the enabled service and remains subject to its own terms and privacy notice.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising, and we do not use event-care information for targeted advertising.

09

Retention and deletion

We keep information for as long as needed to provide the service, fulfill the purpose for which it was collected, follow an organization's configured retention period, protect the service, resolve disputes, maintain required transaction and audit evidence, and satisfy legal obligations. Retention varies by data type and relationship.

MyDiafa's default product direction is to delete or de-identify named dietary, allergy, accessibility, and accommodation details after the event-care retention period unless the person chooses to save a preference, an incident or dispute requires retention, a legal hold applies, or an authorized organization rule requires a different period. Backups and provider systems may retain residual copies for a limited period before deletion is completed.

10

Security and resilience

We use administrative, technical, and organizational safeguards designed to protect information, including tenant and role boundaries, encryption in transit, restricted secrets, private storage, expiring access, audit evidence, provider authentication, and incident-response controls. No system can guarantee absolute security. Protect your credentials, use only authorized accounts, and notify us promptly if you believe an account or event link has been compromised.

11

Your choices and privacy rights

Depending on your location and relationship with MyDiafa, you may have rights to know or access information, correct it, delete it, receive a portable copy, withdraw consent, object to or restrict certain processing, limit certain uses of sensitive information, or appeal a decision. You will not receive discriminatory treatment for exercising a privacy right.

If information was provided to MyDiafa by a venue, employer, host, or other organization, please contact that organization first. We will assist it with a verified request when we act on its behalf. You may also contact us directly. We may need to verify your identity and authority before completing a request, and applicable law may permit or require us to retain some records.

California residents may request the categories and specific pieces of personal information collected, the sources and purposes, and the categories of recipients; request correction or deletion; and exercise any applicable rights to opt out of sale or sharing or limit use of sensitive information. Because MyDiafa does not sell personal information or share it for cross-context behavioral advertising, we do not currently offer a sale/share opt-out mechanism.

12

Cookies and service analytics

MyDiafa uses cookies and similar technologies needed for authentication, session continuity, security, preferences, and reliable operation. We may use limited analytics to understand performance and feature use. If we introduce non-essential advertising or analytics cookies that require consent, we will provide the required notice and controls before using them.

13

Children

MyDiafa is not directed to children under 18, and children may not create an account on their own. An adult host or organization may provide limited information about a minor when reasonably necessary to plan or safely fulfill an event. We ask that they provide only what is necessary and manage the information on the minor's behalf.

14

International data transfers

Cloud Motion and its providers may process information in the United States and other countries where they operate. Those countries may have different privacy laws. Where required, we use contractual and other safeguards for cross-border transfers.

15

Changes and contact

We may update this notice as MyDiafa, its providers, and legal requirements evolve. We will post the revised notice with a new effective date and provide additional notice or consent when required for a material new use of previously collected information.

For privacy questions or requests, email hello@mydiafa.com with the subject “Privacy request.” You may also use the MyDiafa contact page. Please do not send passwords, raw payment credentials, bank credentials, or unnecessary sensitive records by email.

Cloud Motion Technologies LLC
Operator of MyDiafa
mydiafa.com

A practical promise

Hospitality depends on discretion. MyDiafa is designed to use information only for an authorized purpose, keep consequential decisions visible, and provide a human path when automation is not appropriate.

MyDiafaHospitality at your fingertips · mydiafa.com
FeaturesEvents automationContactPrivacyTerms
© 2026 Cloud Motion Technologies LLC