STAVELLO← Back

Terms of Service

Effective: 19 July 2026 · Stavello (stavello.com)

These Terms of Service ("Terms") govern access to and use of the Stavello platform at stavello.com (the "Service"), operated by Stavello ("Stavello", "we", "us" or "our"). They form a binding agreement between us and the organisation that opens an account (the "Customer", "you"). Effective 19 July 2026.

1. Acceptance of these Terms

By creating an account, signing an order form, or accessing or using the Service, you agree to these Terms on behalf of the organisation you represent, and you confirm you have authority to bind that organisation. If you do not agree, do not use the Service.

These Terms incorporate, by reference, our Privacy Policy and — where we process personal data on your behalf — our Data Processing Agreement. The Data Processing Agreement contains the data-processor terms required by applicable law (including the Article 28(3) GDPR clauses and its annexes). Together these documents form the entire agreement between you and us for the Service. If there is a conflict on a data-processing matter, the Data Processing Agreement prevails.

2. The Service

Stavello is a cloud booking, operations and customer-relationship platform for service businesses and hospitality operators. Depending on your plan and configuration, the Service may include:

  • Booking and scheduling for appointments, activities and stays
  • Point-of-sale, billing and invoicing, with payment collection through third-party payment providers
  • Staff and workforce records, rostering and related operational tools
  • Customer / guest relationship records and communications
  • An AI concierge assistant (the "AI Butler") that helps answer guest questions, draft messages, translate, and summarise information
  • Activity-specific intake such as registration and questionnaire forms (for example, a dive medical questionnaire used by a resort dive centre)

The Service is delivered as software-as-a-service. It may be presented under a Customer's own brand (white-label), in which case the underlying platform remains ours and these Terms continue to govern your use of it.

We may improve, change or add features over time. We will not materially degrade the core functionality of a paid plan during a paid term. If we reasonably must — for example, to address a security, legal, or third-party-provider constraint — we will give you reasonable prior notice, and you may terminate the affected plan and receive a pro-rata refund of prepaid, unused fees for that plan.

3. Eligibility, accounts and security

  • You must be a business or organisation (or an individual acting for one), and legally able to enter into a contract. The Service is not intended for consumers signing up in a personal capacity.
  • You are responsible for the accuracy of your account information and for all activity under your account and user logins.
  • You must keep credentials confidential, use strong authentication, and promptly notify us at privacy@stavello.com of any suspected unauthorised access.
  • You are responsible for the acts and omissions of your personnel and any users you invite (including managers and staff), as if they were your own.

We apply technical and organisational safeguards described in our Privacy Policy and Data Processing Agreement, but security is shared: your own account hygiene and access controls are essential to keeping data safe.

4. Your responsibilities as data controller

For personal data about your own end guests, clients and staff that you put into or collect through the Service, you are the data controller and we are your processor, acting on your documented instructions. This is a critical division of responsibility.

You are responsible for having a valid lawful basis for the personal data you process through the Service — and, for special-category data such as the dive medical questionnaire (health data), for obtaining the explicit consent that GDPR Article 9 and applicable sensitive-personal-data rules require. You must also provide your guests, clients and staff with their own privacy notice describing how their data is used.

  • You determine what personal data to collect, why, and for how long, within the limits of applicable law.
  • You must give your data subjects the information and, where required, obtain the consents they are entitled to before their data enters the Service.
  • You must handle their data-subject requests (access, correction, erasure and others) as controller, with our support as processor.
  • Our processing of that data on your behalf is governed by the Data Processing Agreement, which contains the data-processor terms required by applicable law (including the GDPR Article 28(3) clauses and its annexes), and which sets out the sub-processors, international transfers and safeguards, security measures, breach-notification cooperation, and how deletion, erasure and return currently work — including where certain safety, medical or financial records must be retained.

We are an independent controller only for a limited set of data — your account-holder details, billing and subscription records, platform security logs, and platform-level analytics — as described in the Privacy Policy.

5. Subscription and payment

  • Fees, billing frequency and the billing currency for your plan are set out in your order form or in-product plan selection. Currency is presented according to the brand and market you sign up under.
  • Unless your order form says otherwise, subscriptions renew automatically for successive terms of the same length until cancelled.
  • You may cancel renewal before the end of the then-current term; cancellation takes effect at the end of that term.
  • We may change fees. We will give you reasonable advance notice before a price change takes effect, and a change will not apply to a term you have already paid for.
  • Fees are exclusive of taxes; you are responsible for applicable taxes other than those on our net income.
  • Except where required by law or expressly stated in your order form, fees are non-refundable and there are no refunds or credits for partial periods.

Card payments are entered on a payment provider's hosted checkout (Stripe; and, where offered, a hosted local gateway such as FPX). Raw card numbers never reach our servers — we store only a payment token and customer reference. Your use of a payment provider is also subject to that provider's terms.

6. Acceptable use

You agree not to, and not to permit anyone to:

  • Use the Service in violation of any applicable law, including data-protection, consumer, anti-spam or export laws;
  • Upload personal data you have no lawful basis to process, or use the Service to collect sensitive data without the required explicit consent;
  • Send unlawful, misleading, or unsolicited communications to guests, clients or staff through the Service;
  • Infringe intellectual-property or privacy rights, or upload malicious code;
  • Probe, scan, or attempt to breach the Service's security, circumvent tenant isolation, or access data belonging to another customer;
  • Reverse-engineer, resell, or provide the Service to a third party except as expressly permitted;
  • Impose an unreasonable load, or use automated means to extract data beyond documented interfaces.

We may investigate suspected violations and take action, including limiting a feature or suspending access, as described in Section 13.

7. Customer data ownership and licence

As between you and us, you own the data you and your users submit to the Service, and the data your guests, clients and staff submit through surfaces you operate ("Customer Data"). We do not sell Customer Data and we do not use it to build advertising profiles.

You grant us a worldwide, non-exclusive licence to host, store, process, transmit, display and adapt Customer Data solely as needed to provide, secure, maintain and support the Service on your behalf, and as instructed by you. This licence is coextensive with the processing described in the Data Processing Agreement and ends when the data is deleted or returned, subject to the retention points below.

We may create and use fully anonymised and aggregated statistics — data that cannot, alone or in combination, re-identify you, your guests, your clients or your staff — to operate, secure and improve the Service. We do not use special-category data (such as the dive medical questionnaire) or identity documents (passport, national ID, or certification scans) for this purpose. Where this draws on data we process on your behalf, it is authorised only as an instructed processing purpose in the Data Processing Agreement; we do not assert it unilaterally here, and if the Data Processing Agreement does not permit it, we will not do it.

8. AI features

The Service includes AI-assisted features, including the AI Butler concierge, translation, and document parsing. These features are powered by a third-party AI provider (Anthropic), which operates in the United States.

To provide these features, we share with the AI provider a limited set of operational data — for example, a guest's name, villa/room number and departure date and time, the names of divers whose medical screening is complete, a binary medical-clearance outcome (that one or more items were answered "yes", or that no conditions were flagged — never the underlying answers), and any free text a user types into the AI chat. Because a binary clearance outcome is tied to a named, identifiable guest, we treat it as health-related information and limit it accordingly.

The raw, structured answers to the dive medical questionnaire are never sent to the AI provider — they remain in our own database. The AI provider does not use data sent through its API to train its models, and it offers zero or limited data retention. The precise, current list of what is and is not shared with the AI provider is maintained in the Privacy Policy.

AI outputs may be incomplete, inaccurate or out of date. They are informational only and are not professional, medical, legal or financial advice. For any safety-critical decision — for example, clearing a guest as medically fit to dive — a qualified human must review the underlying information and make the decision. You must not rely on an AI output as the sole basis for a safety, health or eligibility decision.

You are responsible for how you configure and use AI features and for any action you take on the basis of an AI output.

9. Intellectual property

The Service, including all software, interfaces, and our brand assets and documentation, is owned by us or our licensors and is protected by intellectual-property laws. We grant you a limited, non-exclusive, non-transferable, revocable right to access and use the Service during your subscription, solely for your internal business operations and subject to these Terms. All rights not expressly granted are reserved. Where the Service is delivered under your brand, your own brand assets remain yours; that arrangement does not transfer ownership of the platform to you.

If you send us feedback or suggestions, we may use them without restriction or obligation to you.

10. Third-party services and sub-processors

The Service relies on third-party sub-processors and integrations — including database and storage hosting, payment processing, email delivery, application hosting, and the AI provider — listed and described in the Privacy Policy and Data Processing Agreement. Those providers operate under their own terms and privacy practices, and some process data across borders; the transfers and their safeguards (including Standard Contractual Clauses or an equivalent mechanism) are disclosed in the Privacy Policy.

We are not responsible for the independent acts of a generic third-party service or integration that operates outside our control and outside our processing of personal data on your behalf. This exclusion does NOT apply to our data-protection sub-processors: except as set out in the Data Processing Agreement, we remain responsible for ensuring our sub-processors are bound by data-protection obligations equivalent to ours, and we remain liable for their acts and omissions in processing personal data on your behalf to the same extent as for our own.

11. Disclaimers and limitation of liability

The Service is provided "as is" and "as available". To the fullest extent permitted by law, we disclaim all warranties, express or implied, including merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that the Service will be uninterrupted, error-free, or that it will meet every requirement.

General cap. To the maximum extent permitted by law: (a) neither party is liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, revenue, goodwill or data; and (b) each party's total aggregate liability arising out of or relating to the Service or these Terms will not exceed the total fees you paid to us for the Service in the twelve (12) months before the event giving rise to the claim.

Data-protection and security super-cap. By way of a limited exception to the general cap above, each party's total aggregate liability for breach of its data-protection or security obligations under these Terms or the Data Processing Agreement will not exceed two (2) times the total fees paid in the twelve (12) months before the event giving rise to the claim. This super-cap replaces — it does not stack on top of — the general cap for such claims.

Nothing in these Terms excludes or limits liability that cannot be excluded or limited under applicable law — for example, liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or a statutory liability owed directly to a data subject that cannot be contracted out of. These limits apply even if a limited remedy fails of its essential purpose.

12. Indemnity

You will defend, indemnify and hold us harmless from third-party claims, damages, and reasonable costs (including legal fees) arising from: (a) your Customer Data or your use of the Service in breach of these Terms or applicable law; (b) your processing of personal data without a valid lawful basis or required consent, or your failure to provide required privacy notices to your guests, clients or staff; or (c) your infringement of a third party's rights. We will notify you of the claim and reasonably cooperate, and you will control the defence.

However, we may, at our option, participate in or assume control of the defence of any claim (or any part of it) to the extent it alleges a data-protection or security breach by us, involves a data-protection regulator, or could affect our own conduct or compliance posture. You will not settle any claim in a way that admits fault on our part, imposes any obligation or payment on us, or affects our regulatory standing, without our prior written consent.

13. Suspension, termination and exit

  • Either party may terminate for material breach not cured within a reasonable notice period, or as otherwise stated in your order form.
  • We may suspend or limit access without prior notice where necessary to protect the Service, other customers, or data subjects — for example, a security threat, non-payment, or a serious acceptable-use violation — and will restore access once the cause is resolved where practicable.
  • On termination, your right to use the Service ends and any outstanding fees for the paid term remain due.

Data on exit: for a limited period after termination, you may request export or return of your Customer Data via privacy@stavello.com, and we will provide it in a commonly used electronic format. Deletion of Customer Data following exit is handled under the Data Processing Agreement and the Privacy Policy, which explain honestly how deletion currently works and which safety, medical and financial records may be retained where law or a legitimate interest (including duty-of-care and dive-safety obligations) requires.

14. Governing law and disputes

These Terms, and any dispute arising out of or relating to them or the Service, are governed by the laws of Malaysia, with the courts of Malaysia having exclusive jurisdiction, and the parties submit to the exclusive jurisdiction of the courts specified there, without regard to conflict-of-laws rules. Nothing in this section deprives a data subject or a party of any mandatory protection or forum available under applicable data-protection law.

15. Changes to these Terms

We may update these Terms from time to time. For material changes we will give reasonable advance notice — by in-product notice or email to your account contact — before they take effect. Your continued use of the Service after the effective date of a change means you accept the updated Terms. If you do not accept a material change, you may cancel renewal as described in Section 5.

16. Contact

Questions about these Terms, or requests relating to data and privacy, can be sent to privacy@stavello.com. The operating entity is Stavello, based in Malaysia.

ItemDetail
Service / brandStavello — stavello.com
Operating entityStavello
Place of establishmentMalaysia
Governing law & courtsthe laws of Malaysia, with the courts of Malaysia having exclusive jurisdiction
Privacy & legal contactprivacy@stavello.com
Incorporated by referencePrivacy Policy · Data Processing Agreement
Effective date19 July 2026