PERSONAL DATA PROCESSING NOTICE

Effective date: 10 August 2026

This Personal Data Processing Notice explains how Personal Data submitted through Roomsing websites, applications, Guest interfaces and related services may be processed.

The Roomsing Service is operated by:

SAGNA PROPERTIES LIMITED
Private Limited Company incorporated in the Republic of Cyprus
Company Registration No.: HE 478223

Email: hi@roomsing.com

For more detailed information concerning Personal Data processing, please refer to the Roomsing Privacy Policy available on the Roomsing website.


1. PERSONAL DATA WE MAY PROCESS

Depending on how you interact with Roomsing and which functionality is enabled by the relevant Accommodation Provider, the following Personal Data may be processed:

  • first and last name;
  • telephone number;
  • email address;
  • date of birth;
  • nationality;
  • country of residence;
  • reservation and accommodation information;
  • check-in and check-out information;
  • passport or other identity-document information;
  • an image or copy of an identification document where required for Guest registration;
  • information about accompanying Guests;
  • communications submitted through Roomsing;
  • electronic documents;
  • information relating to electronic signing;
  • digital-access information;
  • IP address;
  • device and browser information;
  • technical, authentication and security logs;
  • other information voluntarily submitted through Roomsing.

Roomsing processes only Personal Data reasonably necessary for the relevant purpose.


2. NO BIOMETRIC DATA PROCESSING

Roomsing does not process biometric data for the purpose of uniquely identifying an individual.

Roomsing does not perform:

  • facial recognition;
  • biometric face matching;
  • creation of facial templates;
  • creation of biometric templates;
  • fingerprint recognition;
  • iris or retina recognition;
  • voiceprint identification;
  • biometric profiling.

Where an image or copy of an identity document is submitted through Roomsing, it is treated as part of the identification document.

Roomsing does not create a biometric template from a photograph contained in an identification document and does not use such photograph for automated biometric identification.


3. NO PROCESSING OF PAYMENTS FROM INDIVIDUAL USERS

Roomsing does not accept, collect, initiate, route, settle or otherwise process payments from individual Users or Guests.

In particular, Roomsing does not process:

  • payment-card details of Guests;
  • bank-account details used by Guests for accommodation payments;
  • Guest payment credentials;
  • payment transactions between a Guest and an Accommodation Provider.

Any payment for accommodation or other services is made outside the Roomsing Service directly to the relevant Accommodation Provider or through an external service selected by that Accommodation Provider.

Roomsing is not a payment service provider and does not act as an intermediary in such transactions.


4. PURPOSES OF PROCESSING

Personal Data may be processed for purposes including:

  • providing access to Roomsing functionality;
  • creating and administering User or Guest interfaces;
  • responding to enquiries;
  • online check-in;
  • Guest registration;
  • processing reservation information;
  • preparing electronic documents;
  • recording electronic signing actions;
  • sending operational notifications relating to a reservation;
  • providing check-in and check-out instructions;
  • providing digital-access credentials;
  • communicating with an Accommodation Provider;
  • AI-assisted Guest communications;
  • providing technical and customer support;
  • maintaining information security;
  • preventing unauthorised access and misuse;
  • maintaining technical and security logs;
  • complying with applicable legal obligations;
  • establishing, exercising or defending legal claims.

5. LEGAL BASIS FOR PROCESSING

Processing of Personal Data through Roomsing does not rely exclusively on consent.

Depending on the circumstances, processing may be based on:

Performance of a contract

Processing may be necessary to provide a service requested by a User or to take steps requested before entering into a contract.

This may apply to:

  • Account functionality;
  • online check-in functionality;
  • Guest communications;
  • electronic documents;
  • digital access;
  • technical support.

Legal basis: Article 6(1)(b) GDPR.

Compliance with a legal obligation

Certain Personal Data may be processed where processing is necessary to comply with applicable legal obligations.

Legal basis: Article 6(1)(c) GDPR.

Legitimate interests

Personal Data may be processed where necessary for legitimate interests such as:

  • securing the Roomsing Service;
  • preventing fraud and misuse;
  • maintaining technical logs;
  • ensuring Service reliability;
  • responding to enquiries;
  • establishing, exercising or defending legal claims;

provided that such interests are not overridden by the rights and freedoms of the individual.

Legal basis: Article 6(1)(f) GDPR.

Consent

Where consent is the appropriate legal basis for optional processing, it will be requested separately.

Legal basis: Article 6(1)(a) GDPR.

Where processing is based on consent, consent may be withdrawn at any time without affecting processing carried out before withdrawal.


6. ROOMSING AND ACCOMMODATION PROVIDERS

Where Roomsing is used in connection with a booking at a hotel, apartment or other accommodation property, the relevant Accommodation Provider normally determines why Guest Personal Data are required.

In such circumstances:

  • the Accommodation Provider normally acts as the Data Controller; and
  • SAGNA PROPERTIES LIMITED / Roomsing normally acts as the Data Processor.

Roomsing processes Personal Data in accordance with the Accommodation Provider’s documented instructions and applicable data-protection law.

Where SAGNA PROPERTIES LIMITED independently determines the purposes and means of processing, it may act as Data Controller.


7. IDENTITY DOCUMENTS

An Accommodation Provider may request passport or identity-document information where necessary for Guest registration, check-in or compliance with applicable law.

Roomsing may provide the technical means through which such information is:

  • submitted;
  • transmitted;
  • stored;
  • structured;
  • made available to the relevant Accommodation Provider.

The Accommodation Provider is responsible for determining which Guest information it requires and the appropriate legal basis for collecting such information.


8. ELECTRONIC COMMUNICATIONS

Personal Data may be used to send operational communications necessary for the relevant Service, including:

  • reservation information;
  • online check-in links;
  • check-in instructions;
  • digital-access information;
  • access codes;
  • service messages;
  • check-out information;
  • security notifications;
  • responses to Guest requests.

Such operational communications are not marketing communications.


9. MARKETING

Acceptance of this Notice, completion of online check-in or use of Roomsing does not automatically constitute consent to receive optional marketing communications.

Where consent is required for marketing, it will be requested separately.

For example:

☐ I would like to receive news and promotional communications from Roomsing by email.

Such consent must be optional.

Marketing consent may be withdrawn at any time.

Refusal to consent to marketing does not prevent a User from using Roomsing functionality that does not require such consent.


10. SERVICE PROVIDERS

Personal Data may be provided to service providers where reasonably necessary to operate Roomsing.

Depending on the functionality used, recipients may include:

  • hosting and cloud providers;
  • PMS providers;
  • CRM providers;
  • booking-system providers;
  • email and SMS providers;
  • communication platforms;
  • smart-lock providers;
  • access-control providers;
  • IT providers;
  • information-security providers;
  • other technical service providers required to operate Roomsing.

Roomsing does not sell Personal Data.


11. INTERNATIONAL DATA TRANSFERS

Where Personal Data are transferred outside the European Economic Area, an appropriate lawful transfer mechanism will be used where required by applicable law.

Such mechanisms may include:

  • a European Commission adequacy decision;
  • Standard Contractual Clauses approved by the European Commission;
  • another lawful transfer mechanism permitted under GDPR.

12. RETENTION

Personal Data are not stored indefinitely merely because a User has interacted with Roomsing.

Personal Data are retained only for as long as reasonably necessary for the relevant purpose.

Retention periods may depend on:

  • the relevant Roomsing functionality;
  • instructions of the Accommodation Provider;
  • applicable Guest-registration requirements;
  • security requirements;
  • applicable limitation periods;
  • legal obligations.

Where Roomsing acts as Data Processor, retention may be determined by the relevant Accommodation Provider in accordance with applicable law.

When Personal Data are no longer required, they will be deleted, anonymised or otherwise handled in accordance with applicable legal and contractual requirements.


13. SECURITY

Roomsing implements appropriate technical and organisational measures designed to protect Personal Data against:

  • unauthorised access;
  • unlawful use;
  • accidental disclosure;
  • alteration;
  • loss;
  •  

Measures may include:

  • access controls;
  • authentication;
  • encryption;
  • secure network communications;
  • logging;
  • monitoring;
  • backup procedures;
  • role-based access restrictions;
  • incident-response procedures.

14. YOUR RIGHTS

Subject to applicable law, an individual may have the right to:

  • request access to Personal Data;
  • request correction;
  • request deletion where applicable;
  • request restriction of processing;
  • object to certain processing;
  • receive eligible Personal Data in a portable format;
  • withdraw consent where processing is based on consent;
  • object to direct marketing;
  • lodge a complaint with a competent supervisory authority.

Where Roomsing acts solely as Processor, a request may be referred to the relevant Accommodation Provider.

Requests concerning processing for which SAGNA PROPERTIES LIMITED acts as Controller may be sent to:

hi@roomsing.com


15. APPLICABLE DATA PROTECTION LAW

Personal Data are processed in accordance with applicable data-protection legislation, including:

  • Regulation (EU) 2016/679 (General Data Protection Regulation — GDPR); and
  • Law 125(I)/2018 of the Republic of Cyprus on the Protection of Natural Persons with regard to the Processing of Personal Data and the Free Movement of such Data, as amended from time to time.

16. SUPERVISORY AUTHORITY

Where SAGNA PROPERTIES LIMITED acts as the relevant Data Controller and Cyprus is the competent jurisdiction, the competent supervisory authority is:

Office of the Commissioner for Personal Data Protection
Republic of Cyprus

A Data Subject may also have the right to lodge a complaint with another competent EU or EEA supervisory authority in accordance with applicable law.


17. CONTACT DETAILS

SAGNA PROPERTIES LIMITED

Company Registration No.: HE 478223

Email: hi@roomsing.com

© 2026 SAGNA PROPERTIES LIMITED / Roomsing.