Skip to content

Տվյալների մշակման համաձայնագիր

GDPR-ի 28-րդ հոդվածի պայմանագիրը Ձեր և Roomi-ի միջև. հյուրերի տվյալները Ձերն են, Դուք վերահսկիչն եք, մենք՝ մշակողը։ Այստեղ գրված է, թե ով ինչի համար է պատասխանատու։

Կարգավիճակ՝ նախագիծ, դեռ ուժի մեջ չէ · Այս փաստաթուղթը հրապարակված է անգլերեն։

Նախագիծ։ Դեռ ուժի մեջ չէ։

Այս փաստաթուղթը դեռ չի ստուգվել իրավաբանի կողմից և ոչ մեկին չի պարտավորեցնում։ Այն հրապարակված է, որպեսզի տեսնեք, թե Roomi-ն ինչպես է մտադիր վարվել ձեր տվյալների հետ։ Հարցերն ու առարկությունները սպասում ենք Telegram-ով։

1. When this agreement applies

This Data Processing Agreement (“DPA”) applies whenever you use Roomi to handle personal data of other people - your guests, your cleaners, your colleagues - and the EU General Data Protection Regulation applies to that handling. It forms part of the Terms of Service and takes precedence over them on anything to do with personal data.

The parties are you, the account holder (the controller), and Individual Entrepreneur Vladimir Shinkarenko, ID 305852495, 8 Kukuri Gogiashvili Lane, floor 3, apt. 44, Saburtalo, Tbilisi, Georgia (the processor, “Roomi”).

2. Who decides what

You decide which guests you host, which data you collect from them and how long you need it. We process that data only to run the service you signed up for and only on your instructions, which are given through the way you use the product and through this agreement. If we ever believe an instruction breaks data protection law, we will tell you and may refuse to carry it out.

For our own customer data - your name, your email, your billing details, the technical logs of your account - we are the controller, and the Privacy Policy explains what we do with it.

3. What we process for you

  • Subject matter: running a property management system - calendar, bookings, guest communication, cleaning, smart locks and reporting.
  • Duration: for as long as your account is open, plus the deletion period in section 8.
  • Categories of people: your guests, your staff and cleaners, and anyone who writes to you through a connected channel.
  • Categories of data: names, contact details, booking dates and amounts, messages, and - only if you choose to collect them - identity documents and arrival details.

Identity documents deserve a warning. Passport and ID scans are sensitive, several countries require you to collect them, and it is your call whether to use that part of Roomi at all. If you do, keep them only as long as your local law makes you.

4. Confidentiality

Access to your data is limited to the people who operate the service, each of them bound by confidentiality and each with access only to what their work requires. We do not read your guest conversations for any purpose other than fixing a problem you reported or answering a legal demand we cannot refuse.

5. Security

We apply the measures set out in the Privacy Policy: encryption in transit and at rest, row-level access rules in the database so one account cannot reach another’s data, restricted administrative access, and logging of changes to bookings and properties so that an accidental deletion can be traced and undone.

No system is immune. If personal data you entrusted to us is breached, we will tell you without undue delay and in any case within 48 hours of becoming aware, with what we know, what we are doing and what we cannot yet answer - so that you can meet your own 72-hour deadline under Art. 33 GDPR.

6. Sub-processors

You give us general authorisation to use sub-processors. The current list, with what each one does and where the data sits, is published in section 5 of the Privacy Policy and kept up to date there.

Each sub-processor is bound by data protection obligations no weaker than those in this agreement, and we remain fully liable to you for what they do. Before adding or replacing one we will announce it on that page and by email at least 30 days in advance. If you object on reasonable data protection grounds, tell us within those 30 days: we will look for a workable alternative, and if there is none you may terminate the affected part of the service and get back the unused portion of anything you have paid.

7. International transfers

Our infrastructure runs in Singapore, and some sub-processors are in the United States. Those transfers rely on the European Commission’s Standard Contractual Clauses with additional technical safeguards. Section 7 of the Privacy Policy says it plainly, including what is not inside the EEA today.

8. Deletion and return

You can export your bookings at any time from inside the product. When you close your account we delete the data within 30 days - the delay exists so that an accidental deletion can be reversed - except for records we are required to keep for accounting or tax purposes, which are kept in isolation for the statutory period and then deleted.

9. Helping you with your obligations

If a guest asks you for a copy of their data, or asks you to delete it, the product gives you what you need to answer: guest records, booking history and messages are visible and removable from your account. Where you cannot do it yourself, write to us and we will help within the time the GDPR gives you. We also give you the information you reasonably need for a data protection impact assessment or a consultation with your supervisory authority.

10. Audits

On request we provide the information needed to demonstrate compliance with Art. 28 GDPR. If that is not enough for your regulator, we will agree a proportionate audit: once a year, at a reasonable time, at your cost, and without giving anyone access to another customer’s data.

11. Signing it

This DPA applies automatically when you use Roomi under the GDPR - you do not have to sign anything. If your own compliance requires a signed copy with your company details, ask us on Telegram and you will get one.

See also: Privacy Policy, Terms of Service, Cookie Policy.