GDPR Compliance
Last updated: July 2026
[REVIEW NEEDED] This page outlines our current practices. Full GDPR compliance should be verified by a qualified legal advisor. Key gaps to address: appoint a Data Protection Officer if required, formalize lawful basis for each processing activity, complete Records of Processing Activities (ROPA), and review OpenAI's sub-processing agreement.
Scope
This page applies to EU/EEA residents. If you are a host or guest in the EU/EEA, the General Data Protection Regulation (GDPR) grants you specific rights regarding your personal data.
Lawful basis for processing
- Contract performance: processing your account data, property data, and billing data is necessary to provide the Service you subscribed to.
- Legitimate interests: usage analytics for service improvement and security monitoring.
- Consent: where required (e.g., optional features), we will obtain explicit consent.
Your rights under GDPR
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: request correction of inaccurate data.
- Right to erasure: request deletion of your personal data.
- Right to restriction: request that we limit processing of your data.
- Right to data portability: receive your data in a machine-readable format.
- Right to object: object to processing based on legitimate interests.
- Right not to be subject to automated decision-making.
To exercise any right, email [email protected]. We will respond within 30 days.
Data transfers
Data may be transferred outside the EEA to the following processors:
- OpenAI (United States): AI processing. OpenAI participates in the EU-US Data Privacy Framework.
- Stripe (United States): Payment processing. Stripe participates in the EU-US Data Privacy Framework.
- Amazon Web Services (United States): File storage (S3). AWS has Standard Contractual Clauses in place.
- MongoDB Atlas: Database hosting. Available in EU regions on request.
[REVIEW NEEDED] Confirm transfer mechanisms with a legal advisor. Ensure SCCs or DPF coverage is verified for each processor.
Data Protection Officer
[REVIEW NEEDED] Determine if a DPO is required based on your processing activities and appoint one if needed.
Contact
GDPR inquiries: [email protected]