Before your adviser asks
Frequently asked questions.
Who is legally responsible if the AI tells a resident something incorrect?+
You are — the host answers for whatever leaves your WhatsApp number, exactly as you would for something said by a new member of your team. That is why the system has three layers: (1) the AI answers ANCHORED to your handbook and to your approved FAQs, which are injected separately and with priority, and it is explicitly instructed never to invent a rule or a fact; (2) if a question isn't covered, it says so and escalates instead of improvising; (3) faced with health, safeguarding, money, press or anything legal it stops improvising altogether: it acknowledges receipt and hands the case to a phone. And you keep control: you see every reply, you can correct it, pause the AI or take over the conversation whenever you want.
Are you GDPR compliant? Where is the data stored?+
Data is stored in the EU (Ireland) and the functions run in Dublin, next to the database. The AI model runs in the US: that transfer is covered by Standard Contractual Clauses and the provider does NOT train on your data. Each centre is isolated: every record carries its account's mark and every query is filtered by it; where the browser sends an identifier, we check that it is yours and reject it if it isn't. We have a verifier that deliberately tries to cross two centres and is required to fail: we run it before every release. We sign a DPA. Erasure and rectification per resident, from the dashboard and immediately; for access and portability we export the centre's history in CSV/JSON.
Do you use our data to train AI models?+
NO. Messages are processed through the model provider's API (covered by Standard Contractual Clauses) and are NOT used to train any model — neither by that provider nor by us. They are not sold, not shared and they go nowhere else. We do analyse conversations to improve Bedel, but only looking for PATTERNS (what gets asked a lot, what fails) and after stripping phone numbers, room numbers and the real names of your people from the text. And any conversation that triggered an escalation (crisis, report, health, safeguarding) is EXCLUDED from that analysis permanently.
Can our WhatsApp be banned for using this?+
No. We use Meta's OFFICIAL WhatsApp Business Cloud API — the only supported route, and the one any professional solution uses. Unlike the unofficial methods (whatsapp-web, baileys…), which do cause permanent bans, the official API carries no such risk. On top of that, every incoming message is cryptographically verified (X-Hub-Signature-256 signature) to guarantee it comes from Meta and not from an impostor.
Our filter or antivirus blocks or mangles your website. Is that normal?+
Yes, and it is neither a fault of Bedel nor of your IT team: network filters and antivirus products (Sophos, Fortinet…) classify every site by its content, and with a new domain they haven't catalogued yet they fall back to automatic rules. Because bedel.es describes the confidential reporting channel required by Spanish Act 3/2022, some filters can read that wrongly and block the site or strip its styles (it shows up «raw») as a precaution. To confirm it in 30 seconds: open bedel.es on a phone using mobile data, not on a college laptop — it will look perfect. The fix is for your IT team to allow the bedel.es domain in the filter and antivirus, including the console that manages the laptops and not only the Wi-Fi (the laptop's antivirus filters wherever it goes, mobile data included); it's a two-minute change. In parallel, we have the domain going through classification as a business site on the main lists so it stops happening anywhere.
What if a resident is in crisis or in an emergency?+
First, the important part: Bedel does not monitor anyone and knows nothing that hasn't been written to it. It only reads the message that arrives. When that message contains unmistakable signs of serious risk — a health crisis, a serious injury, fire or gas — it is classified as such by deterministic code, not by the model's judgement. Ambiguous ones («I can't take this any more») are judged by a second AI layer looking at the context, so a leaking pipe doesn't set off an emergency alarm. When it does fire, the AI stops improvising: it sends a FIXED text, written by us, with the official Spanish emergency numbers (112 general emergencies · 024 suicidal ideation · 016 gender violence), and the alert goes out WITHIN THE SAME MESSAGE, not in a later process, to the phones of Management, Reception and Security, with retry, plus an email. If it reached no phone at all, the bot does not lie to the resident: it says so and gives them 112. The AI never attempts therapy and never minimises. And we say it plainly: Bedel does not go looking for anything. If the resident doesn't write it, for the system it does not exist — there are no cameras, no sensors and nobody watching. That is why your own protocols and 112 remain the primary route, and Bedel says so in the message itself.
Do you provide the confidential reporting channel required by Spanish Act 3/2022?+
Yes. Each centre gets its own link to a confidential mailbox where a resident can report any safeguarding or community problem, anonymously if they wish. The most serious situations are flagged URGENT automatically. The body is stored encrypted (AES-256-GCM) with the key held outside the database, and every access is logged with user, IP and time. The alert reaches Management by WhatsApp and email WITHOUT the content: to read it you have to enter the dashboard, and that leaves a trace. You set the retention period (1 to 10 years) and the system destroys the record on its own. This is the CHANNEL that Spanish Act 3/2022 requires you to have; the protocol and the community committee remain yours — we give you the piece you are missing, and the audit trail.
How does it handle maintenance and incidents?+
A resident reports it on WhatsApp («the shower in 204 is broken», with a photo if needed) and the AI creates the ticket, classifies it and assigns it on its own to the right role. If it isn't urgent, ONE phone is notified (rotating shifts), not the whole group. If it is urgent, everyone is notified — and the first to press «I'll take it» owns it: the bot tells the rest «so-and-so is on it, no need to go up». The technician accepts, says when they'll come («I'll drop by Thursday»), flags delays, talks to the resident without giving out their number, and closes with a PHOTO of the repair, all from their own WhatsApp. And note what a technician cannot do alone: close a job as «not applicable». Management validates that from their phone. Every morning the system reviews what is still open, warns about what is about to breach and escalates what already has.
What if a parent asks about their adult child?+
We give them nothing. And we don't decide that on the resident's behalf: we ask THEM. They get a WhatsApp with two buttons — «✅ Yes, I authorise it» / «❌ I don't know them» — and until they say yes, we don't even confirm to the parent that they live here (confirming it would already be personal data). If they have no WhatsApp or don't reply within 24 hours, the case goes to your team and you decide by hand. And even once a family member is authorised, there are things they still cannot do: they don't see their child's parcels, they can't cancel their meals and they can't touch their record — that is locked BY CODE to the resident themselves. This covers Spanish data-protection law and your institutional liability.
Can residents ask for their data to be deleted? (right to erasure)+
Yes, and it isn't a pretend deletion. It happens IMMEDIATELY from the dashboard, not at the legal deadline: their messages, conversations and phone number are genuinely deleted — including those from before they were registered, which are found by number — plus dining hall, cleaning, allergens, mailbox, presence and family contacts. Incidents are NOT destroyed (they are the building's maintenance history): they are ANONYMISED, striking their name and number from the text. And a record remains of what was deleted and when, which is exactly what the Spanish data protection authority will ask you for. If something could not be deleted, we don't pretend otherwise: the deletion is aborted and we tell you. Your team runs it from the dashboard; there is no self-service for the resident.
Could the AI reply to the university rector, a manager or a supplier by mistake?+
The AI answers anyone who writes to your number — exactly as your reception would. There are no allow-lists and nobody has to be registered first: if a supplier writes, they get helped. What it does NOT do is give a resident's personal data to anyone but that resident (it escalates that to you), or decide anything about money, rules or exceptions: that goes to you. And if a number is bothering you, you mute it from the dashboard and the AI stops answering it.
How many languages does it handle?+
The AI recognises the language of the last message and answers in it, using your handbook. We have tested it in Spanish, English, French, Italian, German and Portuguese; the model handles quite a few more, but we only promise what we have tested. While the AI is answering, each person gets their own language and you always read Spanish. If you take over a conversation, you write directly — we don't translate there.
Can residents tell that it's an AI?+
If they ask «are you a bot?», the AI says so: it is forbidden to lie about that. In every other message it answers naturally. And we'll flag something your adviser is going to ask about: Article 50 of the European AI Act requires informing people PROACTIVELY that they are interacting with an AI system, not only when they ask. That is why we recommend announcing it when you give the number to residents, and we do not treat compliance as settled just because the bot tells the truth when asked.
Does it adapt to the tone of each house? A hall of residence is not a coliving space+
It doesn't adapt by itself — that is why the tone is chosen. In «hall of residence» mode the AI uses an institutional, formal register: you tell it about your traditions — the resident scholarship, exam vigils, the chapter, the awarding of the sash — and it respects them to the letter, with no slang and no misplaced emoji. In a student residence or a coliving space the register is closer and more direct, which is how their people speak. You choose it, and you can change it whenever you want.
Is it complicated to set up? Who configures it?+
We set it up WITH you: we load your handbook, define roles and categories and connect WhatsApp, in one guided session. But after that you do NOT depend on us for day-to-day changes, which is where this kind of thing always breaks. The dashboard has a chat where you write in plain language — «night-time repairs go to the caretaker», «Pepe is away from 1 to 15 August», «dinner is 20:30 to 21:45» — and it shows you exactly what it is going to change BEFORE saving it. If it is missing someone's phone number, it tells you and does NOT save: without a phone, that alert would reach nowhere. And a traffic light warns you about false coverage — the role that looks covered but has no real phone behind it.
What does the pilot look like and what's our risk?+
We propose a free development pilot, one to three months, with no cost and no lock-in, to adapt the tool to how your house actually works. If it brings you no value by the end, you export all the data and walk away having risked nothing. And before letting it loose on 200 residents, you can run the whole thing in the sandbox: the SAME engine as production — it creates real tickets, alerts the right role, the technician gets their card with buttons, accepts, sets a date and closes — but without sending a single real WhatsApp. Our aim is to build it hand in hand with a reference centre.
There's no staff at the weekend. Is my head housekeeper's phone going to buzz on a Sunday?+
No, not unless you want it to. You turn on weekend mode and choose the window (Friday 20:00 → Monday 08:00, for example). During that time, alerts that CAN wait don't go out: the ticket is still created, the resident gets their reference and an honest sentence — «this is logged and won't be lost: the team will see it Monday at 8:00; if it can't wait, tell me and I'll alert whoever is on duty NOW». On Monday each person gets THEIR list, not everyone's: maintenance gets their repairs, the housekeeper gets her cleaning jobs, and Management gets the overall picture. Anything SERIOUS breaks the silence exactly as it would on a Tuesday: a leak, a smell of gas, the lift, someone locked out of their room. And a crisis doesn't even go through that logic. It ships switched off: you turn it on.
How do we cancel?+
An email — no forms, no «let us win you back». We export all your data in JSON/CSV and delete it. If you want to leave, the only thing we ask is to know why, so we can improve.