Legal

Data Processing Agreement

Version 1.0 · Last updated · 17 August 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between Vabumi OÜ (“Vabumi”, “we”, “us”) and the organisation using the Vabumi platform (the “Customer”, “you”). It sets out the terms on which Vabumi processes personal data on your behalf, as required by Article 28 of the EU General Data Protection Regulation (GDPR).

This DPA is incorporated by reference into our Terms of Service and applies automatically when you accept them — no separate signature is required. If your organisation needs a countersigned copy, see §13.

1Roles and scope

For the personal data you and your team enter into the Service to run your properties (“Customer Personal Data”), you are the controller and Vabumi is the processor. This DPA governs that processing.

For a narrower set of data Vabumi processes for its own purposes — creating and securing accounts, billing, responding to enquiries, and running the website — Vabumi is an independent controller. That processing is described in our Privacy Policy and is outside this DPA.

The subject matter, duration, nature and purpose of the processing, the categories of data subjects and the categories of personal data are set out in Annex I.

2Definitions

“GDPR”, “controller”, “processor”, “data subject”, “personal data”, “processing”, “personal data breach” and “supervisory authority” have the meanings given in Regulation (EU) 2016/679. “Data Protection Law” means the GDPR, the UK GDPR, the Swiss FADP and any national law implementing or supplementing them, as applicable to the Customer. “Sub-processor” means a third party engaged by Vabumi to process Customer Personal Data. “Agreement” means the Terms of Service or any signed order form or master agreement between the parties, together with this DPA.

3Processing on documented instructions

Vabumi will process Customer Personal Data only on your documented instructions, including with regard to transfers to a third country, unless required to do so by EU or Member State law — in which case Vabumi will inform you before processing, unless that law prohibits it on important grounds of public interest.

Your instructions are: the Agreement, this DPA, your use of the Service’s features and settings, and any further written instructions agreed between us. Vabumi will immediately inform you if, in its opinion, an instruction infringes Data Protection Law.

4Confidentiality

Vabumi ensures that every person it authorises to process Customer Personal Data has committed to confidentiality or is under an appropriate statutory obligation of confidentiality, and processes the data only on Vabumi’s instructions. Access is limited to personnel who need it to operate, support or secure the Service.

5Security

Vabumi implements and maintains the technical and organisational measures set out in Annex II, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk to the rights and freedoms of natural persons (GDPR Article 32). Vabumi may update those measures from time to time, provided the updates do not materially reduce the overall level of protection.

6Sub-processors

You give Vabumi general written authorisation to engage the sub-processors listed in Annex III. Vabumi imposes on each sub-processor, by written contract, data-protection obligations that are no less protective than those in this DPA, and remains fully liable to you for the performance of each sub-processor’s obligations.

Vabumi will publish any intended addition or replacement of a sub-processor in Annex III on this page and notify your organisation’s administrators by email at least 30 days before the new sub-processor processes Customer Personal Data. You may object on reasonable, data-protection-related grounds within that period. If we cannot resolve the objection, either party may terminate the affected part of the Service, and you will receive a pro-rata refund of any prepaid fees for the terminated part.

Sub-processors engaged only for Vabumi’s own controller processing (see §1) are disclosed in the Privacy Policy and are not subject to this notice procedure.

7AI processing and no-training commitment

Some features of the Service send Customer Personal Data — including free-text task content and staff voice recordings — to third-party AI providers for transcription, extraction, classification and translation. For every AI provider in Annex III, Vabumi uses business or API terms under which the provider does not use Customer Personal Data to train or improve its models, and Vabumi will not enable any setting or programme that would allow it to. The providers, what they receive, and their retention terms are:

  • OpenAI — receives The text of tasks and notes submitted to AI features, and staff voice notes as audio.. OpenAI does not use API inputs or outputs to train or improve its models. API content is retained for up to 30 days for abuse monitoring, then deleted; zero-data-retention is available on approval and will be adopted when granted.
  • Anthropic — receives The text of tasks submitted for triage; and, on our own side, enquiry, meeting and account notes.. Anthropic does not train models on API inputs or outputs under its Commercial Terms. Inputs and outputs are deleted within 30 days unless flagged for policy enforcement or retention is required by law.

Vabumi does not itself train models on Customer Personal Data. Where a provider offers a shorter retention or zero-data-retention option for API customers, Vabumi will adopt it and reflect the change in Annex III.

8Assistance to the controller

Taking into account the nature of the processing, Vabumi will assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to data-subject requests under Chapter III of the GDPR. If a data subject contacts Vabumi directly about Customer Personal Data, Vabumi will refer the request to you without undue delay and will not respond on your behalf unless you instruct it to.

Vabumi will also assist you, taking into account the nature of the processing and the information available to it, in meeting your obligations under GDPR Articles 32 to 36 (security, breach notification, data-protection impact assessments and prior consultation).

9Personal data breach

Vabumi will notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Information may be provided in phases as it becomes available. Vabumi will cooperate with you and take reasonable steps to contain and remediate the breach.

10International transfers and data location

Vabumi hosts and processes Customer Personal Data in the locations stated in Annex I. Where a sub-processor processes Customer Personal Data outside the European Economic Area, the transfer is made under a lawful transfer mechanism: an EU adequacy decision (including for Switzerland and, for organisations certified under the EU-US Data Privacy Framework, the United States), or the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914) as incorporated in Vabumi’s agreement with that sub-processor. The mechanism relied on for each sub-processor is stated in Annex III.

Where you are established in the United Kingdom or Switzerland, the applicable UK Addendum or Swiss amendments to the Standard Contractual Clauses are deemed incorporated to the extent required.

11Deletion and return

During the term of the Agreement you can export Customer Data through the Service or by request. On termination or expiry, Vabumi will, at your choice, return or delete all Customer Personal Data — and will in any event delete it within 90 days of termination, unless EU or Member State law requires longer storage of specific records. In that case Vabumi will retain only the records so required, for only as long as required, and will continue to protect them under this DPA. Deletion from backups follows the backup rotation cycle of the hosting provider.

12Audit and information

Vabumi will make available to you all information necessary to demonstrate compliance with Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. Audits are limited to once per twelve months (more often following a personal data breach or where required by a supervisory authority), on at least 30 days’ written notice, during business hours, at your cost, and subject to reasonable confidentiality obligations. Vabumi will first satisfy audit requests through written responses and any available third-party assessment reports; on-site inspection is reserved for where those are insufficient.

13Term, precedence, liability, and signature

This DPA takes effect when you accept the Terms of Service or otherwise begin using the Service, and remains in force for as long as Vabumi processes Customer Personal Data on your behalf. In case of conflict, this DPA prevails over the Agreement with respect to the processing of personal data. Each party’s liability under this DPA is subject to the limitations and exclusions in the Agreement, except where Data Protection Law does not permit them to be limited. This DPA is governed by the law that governs the Agreement — the laws of Estonia unless otherwise agreed in writing.

Countersigned copy. Acceptance of the Terms of Service is recorded per organisation and is sufficient to bind both parties to this DPA. If your procurement or legal process requires a countersigned copy, print this page, complete the block below, and send it to [email protected]. Vabumi will countersign and return it. Filling in the block below does not change the terms above.

Customer (controller)

Organisation
Name and title
Signature
Date

Vabumi OÜ (processor)

Organisation
Name and title
Signature
Date

Annex IDetails of the processing

Subject matter
Provision of the Vabumi maintenance and operations platform: task and routine management, housekeeping and service-day planning, spatial and room records, working-time records, team communication (including WhatsApp), and the AI features that support them.
Duration
For the term of the Agreement, plus the deletion period in §11.
Nature and purpose
Hosting, storage, retrieval, display, transmission, transcription, extraction and classification of content the Customer and its staff enter, in order to operate the Customer's properties. Vabumi does not process Customer Personal Data for its own purposes beyond operating, securing and supporting the Service.
Categories of data subjects
The Customer's employees, contractors and other staff who use the Service or are referred to in it (housekeepers, technicians, supervisors, managers, administrators); the Customer's suppliers and contacts; and, incidentally, hotel guests or other third parties whose details staff choose to record in free-text fields, photos or voice notes. Vabumi does not carry guest identity from any property-management system — its PMS integrations exchange room status and operational state only.
Categories of personal data
Identification and contact data (name, work email, phone number, role); authentication identifiers; assignment, task, checklist and routine records; working-time and shift records; photos and voice recordings attached to tasks; WhatsApp messages exchanged with the Service and their media; free-text notes and comments; and usage and audit logs of actions in the Service.
Special categories of data
None are required by the Service. Staff may incidentally enter such data in free-text fields; the Customer is responsible for instructing its staff accordingly.
Data location
Production database, authentication and file storage: Supabase, hosted in Zurich, Switzerland (Central Europe region). Application servers and background workers: Railway, hosted in Amsterdam, the Netherlands (europe-west4). Switzerland is covered by an EU adequacy decision. Sub-processors' own locations are stated in Annex III.

Annex IITechnical and organisational measures

The measures Vabumi has in place, stated as they are — not as they might one day be:

  • Encryption. All traffic between browsers, mobile clients, the API and sub-processors is encrypted in transit (TLS). Data at rest in the production database and file storage is encrypted by the hosting provider (AES-256). Integration credentials and webhook secrets are additionally encrypted at the application layer before storage.
  • Tenant isolation. Every customer organisation is a separate tenant. Row-level security policies in the database enforce that a request can only read or write rows belonging to the requester’s organisation, in addition to checks in the application layer.
  • Access control and authentication. Users authenticate with short-lived signed tokens issued by the hosting provider’s authentication service; passwords are stored hashed. Access within a tenant is role-based (organisation administrator and member, with configurable roles inside the organisation). Vabumi staff access to production data is restricted to named personnel and used for operation, support and incident response only.
  • Logging and monitoring. Application errors are captured in an error-monitoring service; user actions that change data are written to an in-product activity log. Production infrastructure is monitored for availability, with a health endpoint checked on every deployment.
  • Backups and recovery. The production database is backed up automatically by the hosting provider on a daily schedule and can be restored to a prior day. Deployments are reproducible from version-controlled source and infrastructure configuration.
  • Change management. All code changes go through pull requests with automated tests, linting and type-checking required to pass before merge; database schema changes are versioned migrations applied by the deployment pipeline, never by hand.
  • Sub-processor diligence. Each sub-processor in Annex III is engaged under its own data-processing terms, with a transfer mechanism recorded, and AI providers only under no-training terms (§7).
  • Organisational. Personnel with production access are bound by confidentiality; access is removed on offboarding. Vabumi maintains an incident-response practice covering detection, containment, notification (§9) and post-incident review.

Vabumi does not currently hold a third-party certification (such as ISO 27001 or SOC 2) and does not claim one. Security questionnaires are answered from the measures above.

Annex IIISub-processors

The sub-processors currently engaged to process Customer Personal Data, what each receives, where it processes, and the transfer mechanism relied on. These rows come from the same source as the full list in the Privacy Policy §5, which additionally names the providers Vabumi uses for its own controller processing (enquiries, our inbox, our meetings). List version 2026-08-17.

  • SupabaseSupabase, Inc.

    Database hosting, user authentication, and storage of files and photos you upload.

    Data received
    All account and operational data, including uploaded photos and voice recordings.
    Processing location
    Zurich, Switzerland (AWS eu-central-2) — the project region we chose for every environment. API request logs pass through Supabase's Cloudflare edge.
    Transfer mechanism
    Switzerland holds an EU adequacy decision. Supabase's DPA incorporates the EU, UK and Swiss Standard Contractual Clauses for any access from outside the EEA (Supabase is not DPF-certified).
    Terms
    supabase.com/legal/dpa
  • RailwayRailway Corporation

    Application hosting and compute for the Service.

    Data received
    All data in transit through the API and web servers, and server logs.
    Processing location
    Amsterdam, the Netherlands (europe-west4) for every service and environment. Railway's control plane and support access are in the United States.
    Transfer mechanism
    EU Standard Contractual Clauses or the EU-US Data Privacy Framework, as provided in Railway's DPA.
    Terms
    railway.com/legal/dpa
  • OpenAIOpenAI Ireland Ltd (contracting entity for the EEA)AI · no training

    AI features: extracting and classifying tasks from the text you enter, translation, and transcribing voice notes.

    Data received
    The text of tasks and notes submitted to AI features, and staff voice notes as audio.
    Processing location
    United States (API compute is not pinned to a region on our current terms).
    Transfer mechanism
    EU Standard Contractual Clauses (2021/914), incorporated in OpenAI's Data Processing Addendum.
    Training and retention
    OpenAI does not use API inputs or outputs to train or improve its models. API content is retained for up to 30 days for abuse monitoring, then deleted; zero-data-retention is available on approval and will be adopted when granted.
    Terms
    openai.com/policies/data-processing-addendum/
  • AnthropicAnthropic Ireland, Limited (contracting entity for the EEA)AI · no training

    AI features: triaging and categorising tasks, and structuring the enquiry and meeting records we keep about prospective customers.

    Data received
    The text of tasks submitted for triage; and, on our own side, enquiry, meeting and account notes.
    Processing location
    United States (API).
    Transfer mechanism
    EU Standard Contractual Clauses (2021/914), incorporated in Anthropic's Data Processing Addendum.
    Training and retention
    Anthropic does not train models on API inputs or outputs under its Commercial Terms. Inputs and outputs are deleted within 30 days unless flagged for policy enforcement or retention is required by law.
    Terms
    www.anthropic.com/legal/data-processing-addendum
  • TwilioTwilio Ireland Limited (contracting entity for the EEA) / Twilio Inc.

    WhatsApp messaging between the Service and your team, including any media sent in those messages.

    Data received
    Staff phone numbers, message content, and media (photos, voice notes) exchanged over WhatsApp.
    Processing location
    United States. Twilio's Ireland region does not support WhatsApp, so WhatsApp traffic is processed in the US.
    Transfer mechanism
    EU-US Data Privacy Framework certification (Twilio Inc.), Twilio's Binding Corporate Rules, and the EU Standard Contractual Clauses, as provided in Twilio's Data Protection Addendum.
    Terms
    www.twilio.com/en-us/legal/data-protection-addendum
  • Meta PlatformsWhatsApp Ireland Limited (Meta Platforms)

    The WhatsApp Business Cloud API, used alongside Twilio to deliver WhatsApp messages.

    Data received
    Staff phone numbers and the messages and media routed through WhatsApp.
    Processing location
    Meta data centres in the EU and the United States; message content is held for at most 30 days.
    Transfer mechanism
    EU-US Data Privacy Framework certification and the EU Standard Contractual Clauses, under WhatsApp's Business Data Processing Terms and Data Transfer Addendum.
    Terms
    www.whatsapp.com/legal/business-data-processing-terms
  • Twilio SendGridTwilio Inc.

    Transactional email such as invitations, password resets, and notifications.

    Data received
    Recipient name and email address, and the content of the notification.
    Processing location
    United States.
    Transfer mechanism
    EU Standard Contractual Clauses (and DPF where Twilio Inc. is the recipient), as provided in Twilio's Data Protection Addendum, which covers SendGrid.
    Terms
    www.twilio.com/en-us/legal/data-protection-addendum
  • SentryFunctional Software, Inc. (dba Sentry)

    Error monitoring and diagnostics. When an error occurs in your browser this may include a recording of the screen on which it happened, with text and media masked.

    Data received
    Error reports with user identifier, browser and device details, request metadata, and — on error only — a masked replay of the affected screen, retained by Sentry for at most 90 days.
    Processing location
    European Union (Frankfurt) — our Sentry organisation is on the EU data region. Account and organisation settings may be stored in the US.
    Transfer mechanism
    Data is stored in the EU. Sentry is DPF-certified and its DPA incorporates the EU Standard Contractual Clauses for support access from the United States.
    Terms
    sentry.io/legal/dpa/

Questions about this DPA, or requests for a countersigned copy, can be sent to the contact below.

Contact

Legal entity
Vabumi OÜ
Registry code
17426329
Legal address
Järvevana tee 9, 11314, Kesklinna linnaosa, Tallinn, Harju maakond, Estonia