Legal
Data Processing Agreement
Version 1.0 · Last updated · 17 August 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between Vabumi OÜ (“Vabumi”, “we”, “us”) and the organisation using the Vabumi platform (the “Customer”, “you”). It sets out the terms on which Vabumi processes personal data on your behalf, as required by Article 28 of the EU General Data Protection Regulation (GDPR).
This DPA is incorporated by reference into our Terms of Service and applies automatically when you accept them — no separate signature is required. If your organisation needs a countersigned copy, see §13.
1Roles and scope
For the personal data you and your team enter into the Service to run your properties (“Customer Personal Data”), you are the controller and Vabumi is the processor. This DPA governs that processing.
For a narrower set of data Vabumi processes for its own purposes — creating and securing accounts, billing, responding to enquiries, and running the website — Vabumi is an independent controller. That processing is described in our Privacy Policy and is outside this DPA.
The subject matter, duration, nature and purpose of the processing, the categories of data subjects and the categories of personal data are set out in Annex I.
2Definitions
“GDPR”, “controller”, “processor”, “data subject”, “personal data”, “processing”, “personal data breach” and “supervisory authority” have the meanings given in Regulation (EU) 2016/679. “Data Protection Law” means the GDPR, the UK GDPR, the Swiss FADP and any national law implementing or supplementing them, as applicable to the Customer. “Sub-processor” means a third party engaged by Vabumi to process Customer Personal Data. “Agreement” means the Terms of Service or any signed order form or master agreement between the parties, together with this DPA.
3Processing on documented instructions
Vabumi will process Customer Personal Data only on your documented instructions, including with regard to transfers to a third country, unless required to do so by EU or Member State law — in which case Vabumi will inform you before processing, unless that law prohibits it on important grounds of public interest.
Your instructions are: the Agreement, this DPA, your use of the Service’s features and settings, and any further written instructions agreed between us. Vabumi will immediately inform you if, in its opinion, an instruction infringes Data Protection Law.
4Confidentiality
Vabumi ensures that every person it authorises to process Customer Personal Data has committed to confidentiality or is under an appropriate statutory obligation of confidentiality, and processes the data only on Vabumi’s instructions. Access is limited to personnel who need it to operate, support or secure the Service.
5Security
Vabumi implements and maintains the technical and organisational measures set out in Annex II, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk to the rights and freedoms of natural persons (GDPR Article 32). Vabumi may update those measures from time to time, provided the updates do not materially reduce the overall level of protection.
6Sub-processors
You give Vabumi general written authorisation to engage the sub-processors listed in Annex III. Vabumi imposes on each sub-processor, by written contract, data-protection obligations that are no less protective than those in this DPA, and remains fully liable to you for the performance of each sub-processor’s obligations.
Vabumi will publish any intended addition or replacement of a sub-processor in Annex III on this page and notify your organisation’s administrators by email at least 30 days before the new sub-processor processes Customer Personal Data. You may object on reasonable, data-protection-related grounds within that period. If we cannot resolve the objection, either party may terminate the affected part of the Service, and you will receive a pro-rata refund of any prepaid fees for the terminated part.
Sub-processors engaged only for Vabumi’s own controller processing (see §1) are disclosed in the Privacy Policy and are not subject to this notice procedure.
7AI processing and no-training commitment
Some features of the Service send Customer Personal Data — including free-text task content and staff voice recordings — to third-party AI providers for transcription, extraction, classification and translation. For every AI provider in Annex III, Vabumi uses business or API terms under which the provider does not use Customer Personal Data to train or improve its models, and Vabumi will not enable any setting or programme that would allow it to. The providers, what they receive, and their retention terms are:
- OpenAI — receives The text of tasks and notes submitted to AI features, and staff voice notes as audio.. OpenAI does not use API inputs or outputs to train or improve its models. API content is retained for up to 30 days for abuse monitoring, then deleted; zero-data-retention is available on approval and will be adopted when granted.
- Anthropic — receives The text of tasks submitted for triage; and, on our own side, enquiry, meeting and account notes.. Anthropic does not train models on API inputs or outputs under its Commercial Terms. Inputs and outputs are deleted within 30 days unless flagged for policy enforcement or retention is required by law.
Vabumi does not itself train models on Customer Personal Data. Where a provider offers a shorter retention or zero-data-retention option for API customers, Vabumi will adopt it and reflect the change in Annex III.
8Assistance to the controller
Taking into account the nature of the processing, Vabumi will assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to data-subject requests under Chapter III of the GDPR. If a data subject contacts Vabumi directly about Customer Personal Data, Vabumi will refer the request to you without undue delay and will not respond on your behalf unless you instruct it to.
Vabumi will also assist you, taking into account the nature of the processing and the information available to it, in meeting your obligations under GDPR Articles 32 to 36 (security, breach notification, data-protection impact assessments and prior consultation).
9Personal data breach
Vabumi will notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Information may be provided in phases as it becomes available. Vabumi will cooperate with you and take reasonable steps to contain and remediate the breach.
10International transfers and data location
Vabumi hosts and processes Customer Personal Data in the locations stated in Annex I. Where a sub-processor processes Customer Personal Data outside the European Economic Area, the transfer is made under a lawful transfer mechanism: an EU adequacy decision (including for Switzerland and, for organisations certified under the EU-US Data Privacy Framework, the United States), or the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914) as incorporated in Vabumi’s agreement with that sub-processor. The mechanism relied on for each sub-processor is stated in Annex III.
Where you are established in the United Kingdom or Switzerland, the applicable UK Addendum or Swiss amendments to the Standard Contractual Clauses are deemed incorporated to the extent required.
11Deletion and return
During the term of the Agreement you can export Customer Data through the Service or by request. On termination or expiry, Vabumi will, at your choice, return or delete all Customer Personal Data — and will in any event delete it within 90 days of termination, unless EU or Member State law requires longer storage of specific records. In that case Vabumi will retain only the records so required, for only as long as required, and will continue to protect them under this DPA. Deletion from backups follows the backup rotation cycle of the hosting provider.
12Audit and information
Vabumi will make available to you all information necessary to demonstrate compliance with Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. Audits are limited to once per twelve months (more often following a personal data breach or where required by a supervisory authority), on at least 30 days’ written notice, during business hours, at your cost, and subject to reasonable confidentiality obligations. Vabumi will first satisfy audit requests through written responses and any available third-party assessment reports; on-site inspection is reserved for where those are insufficient.
13Term, precedence, liability, and signature
This DPA takes effect when you accept the Terms of Service or otherwise begin using the Service, and remains in force for as long as Vabumi processes Customer Personal Data on your behalf. In case of conflict, this DPA prevails over the Agreement with respect to the processing of personal data. Each party’s liability under this DPA is subject to the limitations and exclusions in the Agreement, except where Data Protection Law does not permit them to be limited. This DPA is governed by the law that governs the Agreement — the laws of Estonia unless otherwise agreed in writing.
Countersigned copy. Acceptance of the Terms of Service is recorded per organisation and is sufficient to bind both parties to this DPA. If your procurement or legal process requires a countersigned copy, print this page, complete the block below, and send it to [email protected]. Vabumi will countersign and return it. Filling in the block below does not change the terms above.
Customer (controller)
- Organisation
- Name and title
- Signature
- Date
Vabumi OÜ (processor)
- Organisation
- Name and title
- Signature
- Date
Annex IDetails of the processing
- Subject matter
- Provision of the Vabumi maintenance and operations platform: task and routine management, housekeeping and service-day planning, spatial and room records, working-time records, team communication (including WhatsApp), and the AI features that support them.
- Duration
- For the term of the Agreement, plus the deletion period in §11.
- Nature and purpose
- Hosting, storage, retrieval, display, transmission, transcription, extraction and classification of content the Customer and its staff enter, in order to operate the Customer's properties. Vabumi does not process Customer Personal Data for its own purposes beyond operating, securing and supporting the Service.
- Categories of data subjects
- The Customer's employees, contractors and other staff who use the Service or are referred to in it (housekeepers, technicians, supervisors, managers, administrators); the Customer's suppliers and contacts; and, incidentally, hotel guests or other third parties whose details staff choose to record in free-text fields, photos or voice notes. Vabumi does not carry guest identity from any property-management system — its PMS integrations exchange room status and operational state only.
- Categories of personal data
- Identification and contact data (name, work email, phone number, role); authentication identifiers; assignment, task, checklist and routine records; working-time and shift records; photos and voice recordings attached to tasks; WhatsApp messages exchanged with the Service and their media; free-text notes and comments; and usage and audit logs of actions in the Service.
- Special categories of data
- None are required by the Service. Staff may incidentally enter such data in free-text fields; the Customer is responsible for instructing its staff accordingly.
- Data location
- Production database, authentication and file storage: Supabase, hosted in Zurich, Switzerland (Central Europe region). Application servers and background workers: Railway, hosted in Amsterdam, the Netherlands (europe-west4). Switzerland is covered by an EU adequacy decision. Sub-processors' own locations are stated in Annex III.
Annex IITechnical and organisational measures
The measures Vabumi has in place, stated as they are — not as they might one day be:
- Encryption. All traffic between browsers, mobile clients, the API and sub-processors is encrypted in transit (TLS). Data at rest in the production database and file storage is encrypted by the hosting provider (AES-256). Integration credentials and webhook secrets are additionally encrypted at the application layer before storage.
- Tenant isolation. Every customer organisation is a separate tenant. Row-level security policies in the database enforce that a request can only read or write rows belonging to the requester’s organisation, in addition to checks in the application layer.
- Access control and authentication. Users authenticate with short-lived signed tokens issued by the hosting provider’s authentication service; passwords are stored hashed. Access within a tenant is role-based (organisation administrator and member, with configurable roles inside the organisation). Vabumi staff access to production data is restricted to named personnel and used for operation, support and incident response only.
- Logging and monitoring. Application errors are captured in an error-monitoring service; user actions that change data are written to an in-product activity log. Production infrastructure is monitored for availability, with a health endpoint checked on every deployment.
- Backups and recovery. The production database is backed up automatically by the hosting provider on a daily schedule and can be restored to a prior day. Deployments are reproducible from version-controlled source and infrastructure configuration.
- Change management. All code changes go through pull requests with automated tests, linting and type-checking required to pass before merge; database schema changes are versioned migrations applied by the deployment pipeline, never by hand.
- Sub-processor diligence. Each sub-processor in Annex III is engaged under its own data-processing terms, with a transfer mechanism recorded, and AI providers only under no-training terms (§7).
- Organisational. Personnel with production access are bound by confidentiality; access is removed on offboarding. Vabumi maintains an incident-response practice covering detection, containment, notification (§9) and post-incident review.
Vabumi does not currently hold a third-party certification (such as ISO 27001 or SOC 2) and does not claim one. Security questionnaires are answered from the measures above.
Annex IIISub-processors
The sub-processors currently engaged to process Customer Personal Data, what each receives, where it processes, and the transfer mechanism relied on. These rows come from the same source as the full list in the Privacy Policy §5, which additionally names the providers Vabumi uses for its own controller processing (enquiries, our inbox, our meetings). List version 2026-08-17.
- SupabaseSupabase, Inc.
Database hosting, user authentication, and storage of files and photos you upload.
- Data received
- All account and operational data, including uploaded photos and voice recordings.
- Processing location
- Zurich, Switzerland (AWS eu-central-2) — the project region we chose for every environment. API request logs pass through Supabase's Cloudflare edge.
- Transfer mechanism
- Switzerland holds an EU adequacy decision. Supabase's DPA incorporates the EU, UK and Swiss Standard Contractual Clauses for any access from outside the EEA (Supabase is not DPF-certified).
- Terms
- supabase.com/legal/dpa
- RailwayRailway Corporation
Application hosting and compute for the Service.
- Data received
- All data in transit through the API and web servers, and server logs.
- Processing location
- Amsterdam, the Netherlands (europe-west4) for every service and environment. Railway's control plane and support access are in the United States.
- Transfer mechanism
- EU Standard Contractual Clauses or the EU-US Data Privacy Framework, as provided in Railway's DPA.
- Terms
- railway.com/legal/dpa
- OpenAIOpenAI Ireland Ltd (contracting entity for the EEA)AI · no training
AI features: extracting and classifying tasks from the text you enter, translation, and transcribing voice notes.
- Data received
- The text of tasks and notes submitted to AI features, and staff voice notes as audio.
- Processing location
- United States (API compute is not pinned to a region on our current terms).
- Transfer mechanism
- EU Standard Contractual Clauses (2021/914), incorporated in OpenAI's Data Processing Addendum.
- Training and retention
- OpenAI does not use API inputs or outputs to train or improve its models. API content is retained for up to 30 days for abuse monitoring, then deleted; zero-data-retention is available on approval and will be adopted when granted.
- Terms
- openai.com/policies/data-processing-addendum/
- AnthropicAnthropic Ireland, Limited (contracting entity for the EEA)AI · no training
AI features: triaging and categorising tasks, and structuring the enquiry and meeting records we keep about prospective customers.
- Data received
- The text of tasks submitted for triage; and, on our own side, enquiry, meeting and account notes.
- Processing location
- United States (API).
- Transfer mechanism
- EU Standard Contractual Clauses (2021/914), incorporated in Anthropic's Data Processing Addendum.
- Training and retention
- Anthropic does not train models on API inputs or outputs under its Commercial Terms. Inputs and outputs are deleted within 30 days unless flagged for policy enforcement or retention is required by law.
- Terms
- www.anthropic.com/legal/data-processing-addendum
- TwilioTwilio Ireland Limited (contracting entity for the EEA) / Twilio Inc.
WhatsApp messaging between the Service and your team, including any media sent in those messages.
- Data received
- Staff phone numbers, message content, and media (photos, voice notes) exchanged over WhatsApp.
- Processing location
- United States. Twilio's Ireland region does not support WhatsApp, so WhatsApp traffic is processed in the US.
- Transfer mechanism
- EU-US Data Privacy Framework certification (Twilio Inc.), Twilio's Binding Corporate Rules, and the EU Standard Contractual Clauses, as provided in Twilio's Data Protection Addendum.
- Terms
- www.twilio.com/en-us/legal/data-protection-addendum
- Meta PlatformsWhatsApp Ireland Limited (Meta Platforms)
The WhatsApp Business Cloud API, used alongside Twilio to deliver WhatsApp messages.
- Data received
- Staff phone numbers and the messages and media routed through WhatsApp.
- Processing location
- Meta data centres in the EU and the United States; message content is held for at most 30 days.
- Transfer mechanism
- EU-US Data Privacy Framework certification and the EU Standard Contractual Clauses, under WhatsApp's Business Data Processing Terms and Data Transfer Addendum.
- Terms
- www.whatsapp.com/legal/business-data-processing-terms
- Twilio SendGridTwilio Inc.
Transactional email such as invitations, password resets, and notifications.
- Data received
- Recipient name and email address, and the content of the notification.
- Processing location
- United States.
- Transfer mechanism
- EU Standard Contractual Clauses (and DPF where Twilio Inc. is the recipient), as provided in Twilio's Data Protection Addendum, which covers SendGrid.
- Terms
- www.twilio.com/en-us/legal/data-protection-addendum
- SentryFunctional Software, Inc. (dba Sentry)
Error monitoring and diagnostics. When an error occurs in your browser this may include a recording of the screen on which it happened, with text and media masked.
- Data received
- Error reports with user identifier, browser and device details, request metadata, and — on error only — a masked replay of the affected screen, retained by Sentry for at most 90 days.
- Processing location
- European Union (Frankfurt) — our Sentry organisation is on the EU data region. Account and organisation settings may be stored in the US.
- Transfer mechanism
- Data is stored in the EU. Sentry is DPF-certified and its DPA incorporates the EU Standard Contractual Clauses for support access from the United States.
- Terms
- sentry.io/legal/dpa/
Questions about this DPA, or requests for a countersigned copy, can be sent to the contact below.
Contact
- Legal entity
- Vabumi OÜ
- Registry code
- 17426329
- Legal address
- Järvevana tee 9, 11314, Kesklinna linnaosa, Tallinn, Harju maakond, Estonia
- [email protected]