PRIVACY POLICY

Effective date: 10 August 2026

This Privacy Policy explains how SAGNA PROPERTIES LIMITED, operating the Roomsing Service, processes and protects Personal Data.

The Service is operated by:

SAGNA PROPERTIES LIMITED
Private Limited Company incorporated in the Republic of Cyprus
Company Registration No.: HE 478223

Email: hi@roomsing.com

For the purposes of this Privacy Policy, “Roomsing”, “we”, “us” and “our” refer to SAGNA PROPERTIES LIMITED.

 


1. SCOPE

This Privacy Policy applies to Personal Data processed in connection with:

  • the Roomsing website;
  • Roomsing web applications;
  • Guest accounts and interfaces;
  • online check-in;
  • Guest registration;
  • electronic documents;
  • electronic signing;
  • digital access;
  • smart-lock integrations;
  • reservation functionality;
  • PMS and CRM integrations;
  • Guest notifications;
  • AI-assisted Guest communications;
  • customer and technical support;
  • services provided to Accommodation Providers.

This Policy does not govern independent processing carried out by third parties acting as separate Data Controllers.


2. DEFINITIONS

Personal Data means information relating to an identified or identifiable natural person.

Data Subject means the individual to whom Personal Data relate.

User means an individual accessing or using Roomsing.

Guest means an individual using or intending to use accommodation services provided by an Accommodation Provider.

Accommodation Provider means a hotel, apartment operator, property-management company or other organisation using Roomsing.

Controller means the person or organisation determining the purposes and means of processing Personal Data.

Processor means an organisation processing Personal Data on behalf of a Controller.

GDPR means Regulation (EU) 2016/679.


3. OUR ROLE

Roomsing may act either as a Data Controller or Data Processor depending on the processing activity.

3.1. Roomsing as Controller

SAGNA PROPERTIES LIMITED normally acts as Controller where it independently determines the purposes and means of processing.

This may include Personal Data relating to:

  • visitors to the Roomsing website;
  • Roomsing business customers;
  • representatives of Accommodation Providers;
  • business partners;
  • persons contacting Roomsing directly;
  • Account administration;
  • Service security;
  • customer support;
  • legally permitted marketing activities.

3.2. Roomsing as Processor

Where an Accommodation Provider uses Roomsing to process Guest Personal Data, the Accommodation Provider normally acts as Controller and SAGNA PROPERTIES LIMITED normally acts as Processor.

In such circumstances Roomsing may process Personal Data for:

  • online check-in;
  • Guest registration;
  • reservation synchronisation;
  • electronic documents;
  • electronic signing;
  • Guest notifications;
  • digital access;
  • smart-lock functionality;
  • Guest communication;
  • AI-assisted communication;
  • PMS and CRM synchronisation;
  • technical support.

Roomsing processes such data in accordance with documented instructions from the relevant Accommodation Provider and the applicable contractual arrangements.


4. DATA WE MAY PROCESS

The exact categories depend on the Roomsing functionality used.

Roomsing applies the principle that Personal Data should be adequate, relevant and limited to what is necessary for the relevant purpose.


5. IDENTIFICATION INFORMATION

We may process:

  • first name;
  • last name;
  • middle name, where applicable;
  • date of birth;
  • nationality;
  • country of residence;
  • gender where required by applicable Guest-registration requirements;
  • other identification information required for the relevant Guest-registration purpose.

6. IDENTITY DOCUMENT INFORMATION

Where Roomsing is used for online check-in or Guest registration, we may process:

  • passport or identity-document number;
  • document type;
  • issuing country;
  • issuing authority;
  • issue date;
  • expiry date;
  • textual information contained in the document;
  • image, scan or copy of the document.

Roomsing may technically extract or structure textual information contained in an identity document where necessary to facilitate Guest registration.


7. NO BIOMETRIC DATA PROCESSING

Roomsing does not process biometric data for the purpose of uniquely identifying an individual.

Roomsing does not:

  • perform facial recognition;
  • perform biometric face matching;
  • create facial templates;
  • create biometric templates;
  • analyse facial geometry for identification;
  • perform fingerprint recognition;
  • perform iris or retina recognition;
  • use voiceprints for identification;
  • create biometric identification profiles.

Where an identification document contains a photograph, that photograph is treated as part of the identification document.

Roomsing does not create a biometric template from such photograph and does not use it for automated biometric identification.


8. CONTACT INFORMATION

Roomsing may process:

  • email address;
  • telephone number;
  • messaging contact details;
  • communication preferences;
  • other contact information voluntarily supplied by the User.

9. RESERVATION AND ACCOMMODATION INFORMATION

Depending on the functionality used, Roomsing may process:

  • reservation number;
  • external booking identifier;
  • Accommodation Provider;
  • accommodation property;
  • room or unit;
  • arrival date;
  • departure date;
  • number of Guests;
  • booking source;
  • booking status;
  • check-in status;
  • check-out status;
  • services associated with the stay;
  • Guest requests;
  • other information relating to the accommodation.

10. DIGITAL ACCESS INFORMATION

Where Roomsing provides digital-access functionality, we may process:

  • access-code identifiers;
  • digital-key information;
  • access-validity period;
  • accommodation-unit identifier;
  • lock or access-point identifier;
  • date and time of access events;
  • technical access logs.

Such information may be exchanged with the relevant smart-lock or access-control provider where necessary to provide the functionality.


11. NO PROCESSING OF INDIVIDUAL PAYMENTS

Roomsing does not accept, collect, initiate, route, settle or otherwise process payments made by individual Users or Guests.

Roomsing does not collect or store Guest payment-card credentials for accommodation payments and does not act as a payment intermediary between a Guest and an Accommodation Provider.

Any payment for accommodation or related services is carried out outside Roomsing directly with the relevant Accommodation Provider or through an external service independently selected by that Accommodation Provider.

Accordingly, Guest payment transactions do not form part of the categories of Personal Data processed by Roomsing under this Privacy Policy.


12. ELECTRONIC DOCUMENTS

Where electronic-document functionality is used, Roomsing may process:

  • Guest registration forms;
  • accommodation-related documents;
  • electronic signatures;
  • document status;
  • date and time of signing;
  • IP address;
  • technical evidence associated with an electronic action.

13. COMMUNICATIONS

Where Roomsing communication functionality is used, Personal Data may be processed through:

  • email;
  • SMS;
  • messaging platforms;
  • Roomsing interfaces;
  • support systems;
  • AI-assisted communication tools.

This may include:

  • the content of a Guest request;
  • responses;
  • relevant communication history;
  • reservation information necessary to respond;
  • information supplied by the Accommodation Provider.

14. TECHNICAL DATA

When a User accesses Roomsing, certain technical information may be processed automatically, including:

  • IP address;
  • browser type;
  • device type;
  • operating system;
  • application version;
  • language settings;
  • session information;
  • date and time of access;
  • functions used;
  • security logs;
  • error logs;
  • authentication events;
  • technical identifiers;
  • cookie information where applicable.

15. SOURCES OF PERSONAL DATA

Personal Data may be obtained:

Directly from the User

For example when the User:

  • creates an Account;
  • completes online check-in;
  • provides identification information;
  • completes a form;
  • signs an electronic document;
  • contacts support;
  • communicates through Roomsing.

From an Accommodation Provider

For example where a hotel or apartment operator provides reservation information to Roomsing.

From integrated systems

These may include:

  • PMS platforms;
  • CRM systems;
  • booking engines;
  • online travel agencies;
  • smart-lock systems;
  • access-control systems;
  • communication systems;
  • other systems integrated with Roomsing.

16. PURPOSES OF PROCESSING

Personal Data may be processed for:

  • providing Roomsing functionality;
  • creating and administering Accounts;
  • online check-in;
  • Guest registration;
  • reservation management and synchronisation;
  • preparing electronic documents;
  • electronic signing;
  • sending operational notifications;
  • providing digital access;
  • providing access credentials;
  • communicating with Guests;
  • providing AI-assisted communications;
  • processing Guest requests;
  • customer and technical support;
  • maintaining information security;
  • preventing unauthorised access;
  • preventing fraud or abuse;
  • maintaining technical logs;
  • troubleshooting;
  • improving Service reliability;
  • fulfilling contractual obligations;
  • complying with applicable law;
  • establishing, exercising or defending legal claims.

17. LEGAL BASES

Where SAGNA PROPERTIES LIMITED acts as Controller, processing may be based on one or more of the following legal bases.

Performance of a contract

Processing may be necessary to perform a contract or take steps requested before entering into one.

Article 6(1)(b) GDPR.

Legal obligation

Processing may be necessary to comply with applicable legal obligations.

Article 6(1)(c) GDPR.

Legitimate interests

Processing may be necessary for legitimate interests including:

  • protecting the Roomsing Service;
  • preventing misuse;
  • information security;
  • maintaining Service reliability;
  • handling enquiries;
  • establishing, exercising or defending legal claims.

Such interests will be balanced against the interests, rights and freedoms of the Data Subject.

Article 6(1)(f) GDPR.

Consent

Where consent is the appropriate basis for optional processing, consent will be requested separately.

Article 6(1)(a) GDPR.

Consent may be withdrawn at any time.


18. MARKETING

Acceptance of this Privacy Policy, use of Roomsing or completion of online check-in does not automatically constitute consent to optional marketing.

Where marketing requires consent, such consent will be obtained separately.

A User may withdraw marketing consent at any time.

Withdrawal from marketing does not affect operational communications necessary for a reservation, check-in, digital access, security or requested Service.


19. AI-ASSISTED PROCESSING

Roomsing may provide AI-assisted technology for Guest communications and operational purposes.

Such functionality may process:

  • the Guest’s request;
  • relevant reservation information;
  • communication history;
  • information supplied by the Accommodation Provider.

Roomsing does not use AI functionality for biometric identification of Guests.

Unless otherwise specifically disclosed, Roomsing does not make decisions based solely on automated processing that produce legal effects concerning an individual or similarly significantly affect that individual.


20. DISCLOSURE OF PERSONAL DATA

Roomsing does not sell Personal Data.

Personal Data may be disclosed where necessary to provide Roomsing functionality, comply with documented Controller instructions or fulfil applicable legal obligations.

Recipients may include:

  • Accommodation Providers;
  • cloud and hosting providers;
  • PMS providers;
  • CRM providers;
  • booking-system providers;
  • communication providers;
  • email and SMS providers;
  • smart-lock providers;
  • access-control providers;
  • IT and information-security providers;
  • professional advisers;
  • auditors;
  • governmental, regulatory or judicial authorities where legally required.

21. SUB-PROCESSORS

Where Roomsing acts as Processor, it may use sub-processors where necessary to provide elements of the Service.

Relevant sub-processors are required to be subject to appropriate obligations concerning:

  • confidentiality;
  • data protection;
  • information security;
  • processing instructions;
  • deletion or return of Personal Data where applicable.

22. INTERNATIONAL DATA TRANSFERS

Where Personal Data are transferred outside the European Economic Area, Roomsing will use an appropriate transfer mechanism where required by applicable law.

This may include:

  • a European Commission adequacy decision;
  • Standard Contractual Clauses approved by the European Commission;
  • another lawful transfer mechanism under GDPR.

Supplementary safeguards may be implemented where appropriate.


23. DATA RETENTION

Roomsing does not retain Personal Data indefinitely merely because a User has used the Service.

Personal Data are retained only for as long as reasonably necessary for the applicable purpose.

Retention periods may depend on:

  • the nature of the Service;
  • instructions of the Accommodation Provider;
  • Guest-registration requirements;
  • security requirements;
  • applicable limitation periods;
  • legal obligations.

Where Roomsing acts as Processor, Personal Data will be deleted or returned in accordance with the relevant agreement and documented instructions of the Controller unless continued storage is required by law.


24. IDENTITY DOCUMENT RETENTION

Where an image or copy of an identification document is processed through Roomsing, it should not be retained longer than necessary for the purpose for which it was collected.

Where Roomsing acts as Processor, retention may depend on:

  • documented instructions from the Accommodation Provider;
  • configuration of the Roomsing Service;
  • applicable legal requirements.

Roomsing does not use stored identification documents to create biometric or facial-recognition databases.


25. SECURITY

Roomsing implements appropriate technical and organisational measures designed to protect Personal Data against:

  • unauthorised access;
  • unlawful processing;
  • accidental loss;
  • disclosure;
  • alteration;
  •  

Measures may include:

  • access controls;
  • authentication;
  • role-based permissions;
  • secure network communications;
  • encryption;
  • logging;
  • monitoring;
  • backup procedures;
  • incident-response procedures;
  • confidentiality requirements;
  • vulnerability management;
  • secure deletion procedures.

26. PERSONAL DATA BREACHES

Where SAGNA PROPERTIES LIMITED acts as Controller, Personal Data breaches will be assessed and managed in accordance with applicable law.

Where Roomsing acts as Processor, it will notify the relevant Controller without undue delay after becoming aware of a Personal Data breach affecting data processed on behalf of that Controller.


27. DATA SUBJECT RIGHTS

Subject to applicable law, Data Subjects may have the right to:

  • obtain information regarding processing;
  • access Personal Data;
  • request correction;
  • request deletion;
  • request restriction;
  • object to certain processing;
  • object to direct marketing;
  • receive eligible Personal Data in a portable format;
  • withdraw consent;
  • lodge a complaint with a competent supervisory authority.

These rights may be subject to conditions and exceptions under applicable law.


28. EXERCISING YOUR RIGHTS

Where SAGNA PROPERTIES LIMITED acts as Controller, requests may be submitted to:

hi@roomsing.com

Roomsing may request reasonable information to verify the identity of the person making the request.

Where Roomsing acts solely as Processor, Roomsing may refer the request to the relevant Accommodation Provider and assist that Provider as required.


29. PERSONAL DATA OF OTHER PERSONS

If a User provides Personal Data relating to another person, including an accompanying Guest, the User should only provide such information where authorised or otherwise legally permitted.

Users should not submit another person’s identity documents or Personal Data without appropriate authority or legal basis.


30. CHILDREN

Where Personal Data relating to a minor are processed in connection with accommodation, the relevant Accommodation Provider is responsible for determining the appropriate lawful basis and complying with applicable requirements relating to minors.

Roomsing does not use Personal Data relating to minors for targeted advertising.


31. COOKIES

Roomsing may use strictly necessary technologies required for:

  • website operation;
  • security;
  • authentication;
  • session management;
  • User-requested functionality.

Where consent is required for optional analytics or marketing technologies, such technologies will not be activated until the required consent has been provided.

Users should be able to reject optional cookies and modify or withdraw their preferences where applicable.


32. THIRD-PARTY SERVICES

Roomsing may contain links to or integrations with third-party services.

Where a third party independently determines the purposes and means of its processing, that third party acts as a separate Controller and its own privacy terms apply.


33. CHANGES TO THIS PRIVACY POLICY

Roomsing may update this Privacy Policy where reasonably necessary because of:

  • changes to Roomsing functionality;
  • changes in processing activities;
  • new integrations;
  • legal or regulatory requirements;
  • security developments.

The current version will be published on the Roomsing website together with its effective date.

Where required by applicable law, material changes will be communicated through appropriate means.


34. APPLICABLE DATA PROTECTION LAW

Personal Data are processed in accordance with applicable data-protection legislation, including:

  • Regulation (EU) 2016/679 (General Data Protection Regulation — GDPR); and
  • Law 125(I)/2018 of the Republic of Cyprus on the Protection of Natural Persons with regard to the Processing of Personal Data and the Free Movement of such Data, as amended from time to time.

35. SUPERVISORY AUTHORITY

A Data Subject has the right to lodge a complaint with a competent data-protection supervisory authority.

Where SAGNA PROPERTIES LIMITED acts as the relevant Controller and Cyprus is the competent jurisdiction, the competent supervisory authority is:

Office of the Commissioner for Personal Data Protection
Republic of Cyprus

A Data Subject may also have the right to lodge a complaint with another competent EU or EEA supervisory authority in accordance with applicable law.


36. CONTACT DETAILS

SAGNA PROPERTIES LIMITED

Company Registration No.: HE 478223

Email: hi@roomsing.com

© 2026 SAGNA PROPERTIES LIMITED / Roomsing.