Privacy

Privacy Policy

Last updated · 17 August 2026

This policy explains what personal data Vabumi OÜ (“Vabumi”, “we”, “us”) collects, why we collect it, and the rights you have over it. It applies to our website and to the Vabumi maintenance and operations platform (the “Service”).

1Who we are

Vabumi OÜ, a company registered in Estonia (registry code 17426329) with its registered office at Järvevana tee 9, 11314, Kesklinna linnaosa, Tallinn, Harju maakond, Estonia, is the data controller for the personal data described in this policy: website visitors, account holders, billing, and the people who contact us.

For the operational data your organisation and its staff enter into the Service, your organisation is the controller and Vabumi processes it on your organisation’s behalf under our Data Processing Agreement. The sub-processor list in section 5 applies to both.

For any privacy question or to exercise your rights, contact us at [email protected].

2Data we collect

We collect the following categories of personal data:

  • Account data — name, work email, organisation, role, and authentication identifiers when you or your employer create an account.
  • Operational data — the tasks, routines, notes, photos, voice memos, and other content you and your team enter to run your properties. This may incidentally include personal data about staff or guests that you choose to record.
  • Usage data — log data, device and browser information, and product analytics about how the Service is used.
  • Communications — messages you send us, demo bookings, and support requests.

3How we use your data

We use personal data to:

  • provide, operate, secure, and improve the Service;
  • authenticate users and enforce per-tenant access controls;
  • respond to enquiries, bookings, and support requests;
  • send service-related and, where permitted, occasional product communications;
  • comply with legal obligations and protect against misuse or fraud.

4Legal bases (GDPR Article 6)

We rely on the following lawful bases:

  • Contract — to deliver the Service to you or your organisation.
  • Legitimate interests — to secure, maintain, and improve the Service and to communicate with prospective customers, balanced against your rights.
  • Consent — for non-essential analytics or marketing where required; you may withdraw consent at any time.
  • Legal obligation — where processing is required by law.

5Sharing and sub-processors

We do not sell personal data. We share it only with service providers who process it on our behalf under data-processing agreements. The sub-processors we currently use, what each receives, where it processes, and the transfer mechanism relied on are listed below. This is the same list published in Annex III of our Data Processing Agreement, rendered from one source so the two cannot differ. Vendor terms were last checked on 17 August 2026.

  • SupabaseSupabase, Inc.

    Database hosting, user authentication, and storage of files and photos you upload.

    Data received
    All account and operational data, including uploaded photos and voice recordings.
    Processing location
    Zurich, Switzerland (AWS eu-central-2) — the project region we chose for every environment. API request logs pass through Supabase's Cloudflare edge.
    Transfer mechanism
    Switzerland holds an EU adequacy decision. Supabase's DPA incorporates the EU, UK and Swiss Standard Contractual Clauses for any access from outside the EEA (Supabase is not DPF-certified).
    Terms
    supabase.com/legal/dpa
  • RailwayRailway Corporation

    Application hosting and compute for the Service.

    Data received
    All data in transit through the API and web servers, and server logs.
    Processing location
    Amsterdam, the Netherlands (europe-west4) for every service and environment. Railway's control plane and support access are in the United States.
    Transfer mechanism
    EU Standard Contractual Clauses or the EU-US Data Privacy Framework, as provided in Railway's DPA.
    Terms
    railway.com/legal/dpa
  • StripeStripe Payments Europe, Ltd. (Ireland) with Stripe, Inc. (United States)

    Payment and subscription billing.

    Data received
    Billing contact name, email, organisation, and payment details entered on Stripe's own checkout.
    Processing location
    United States (Stripe, Inc.), contracted through Stripe's Irish entity.
    Transfer mechanism
    EU-US Data Privacy Framework certification, with the EU Standard Contractual Clauses as fallback, as provided in Stripe's DPA.
    Terms
    stripe.com/legal/dpa
  • OpenAIOpenAI Ireland Ltd (contracting entity for the EEA)AI · no training

    AI features: extracting and classifying tasks from the text you enter, translation, and transcribing voice notes.

    Data received
    The text of tasks and notes submitted to AI features, and staff voice notes as audio.
    Processing location
    United States (API compute is not pinned to a region on our current terms).
    Transfer mechanism
    EU Standard Contractual Clauses (2021/914), incorporated in OpenAI's Data Processing Addendum.
    Training and retention
    OpenAI does not use API inputs or outputs to train or improve its models. API content is retained for up to 30 days for abuse monitoring, then deleted; zero-data-retention is available on approval and will be adopted when granted.
    Terms
    openai.com/policies/data-processing-addendum/
  • AnthropicAnthropic Ireland, Limited (contracting entity for the EEA)AI · no training

    AI features: triaging and categorising tasks, and structuring the enquiry and meeting records we keep about prospective customers.

    Data received
    The text of tasks submitted for triage; and, on our own side, enquiry, meeting and account notes.
    Processing location
    United States (API).
    Transfer mechanism
    EU Standard Contractual Clauses (2021/914), incorporated in Anthropic's Data Processing Addendum.
    Training and retention
    Anthropic does not train models on API inputs or outputs under its Commercial Terms. Inputs and outputs are deleted within 30 days unless flagged for policy enforcement or retention is required by law.
    Terms
    www.anthropic.com/legal/data-processing-addendum
  • TwilioTwilio Ireland Limited (contracting entity for the EEA) / Twilio Inc.

    WhatsApp messaging between the Service and your team, including any media sent in those messages.

    Data received
    Staff phone numbers, message content, and media (photos, voice notes) exchanged over WhatsApp.
    Processing location
    United States. Twilio's Ireland region does not support WhatsApp, so WhatsApp traffic is processed in the US.
    Transfer mechanism
    EU-US Data Privacy Framework certification (Twilio Inc.), Twilio's Binding Corporate Rules, and the EU Standard Contractual Clauses, as provided in Twilio's Data Protection Addendum.
    Terms
    www.twilio.com/en-us/legal/data-protection-addendum
  • Meta PlatformsWhatsApp Ireland Limited (Meta Platforms)

    The WhatsApp Business Cloud API, used alongside Twilio to deliver WhatsApp messages.

    Data received
    Staff phone numbers and the messages and media routed through WhatsApp.
    Processing location
    Meta data centres in the EU and the United States; message content is held for at most 30 days.
    Transfer mechanism
    EU-US Data Privacy Framework certification and the EU Standard Contractual Clauses, under WhatsApp's Business Data Processing Terms and Data Transfer Addendum.
    Terms
    www.whatsapp.com/legal/business-data-processing-terms
  • Twilio SendGridTwilio Inc.

    Transactional email such as invitations, password resets, and notifications.

    Data received
    Recipient name and email address, and the content of the notification.
    Processing location
    United States.
    Transfer mechanism
    EU Standard Contractual Clauses (and DPF where Twilio Inc. is the recipient), as provided in Twilio's Data Protection Addendum, which covers SendGrid.
    Terms
    www.twilio.com/en-us/legal/data-protection-addendum
  • SentryFunctional Software, Inc. (dba Sentry)

    Error monitoring and diagnostics. When an error occurs in your browser this may include a recording of the screen on which it happened, with text and media masked.

    Data received
    Error reports with user identifier, browser and device details, request metadata, and — on error only — a masked replay of the affected screen, retained by Sentry for at most 90 days.
    Processing location
    European Union (Frankfurt) — our Sentry organisation is on the EU data region. Account and organisation settings may be stored in the US.
    Transfer mechanism
    Data is stored in the EU. Sentry is DPF-certified and its DPA incorporates the EU Standard Contractual Clauses for support access from the United States.
    Terms
    sentry.io/legal/dpa/
  • DiscordDiscord Inc. / Discord Netherlands B.V.

    Internal routing of website enquiries and demo requests to our team, and hosting of team calls we record.

    Data received
    Enquiry and demo-request details you send us, and the audio of calls held on our Discord server. Discord does not itself store the content of voice calls.
    Processing location
    United States.
    Transfer mechanism
    Discord acts as an independent controller under its Developer Terms; transfers rest on the EU Standard Contractual Clauses (Module One) and Discord's DPF certification. There is no processor DPA with Discord.
    Terms
    support-dev.discord.com/hc/en-us/articles/8562894815383
  • ResendResend, Inc.

    Delivery of email sent from our published contact addresses.

    Data received
    Recipient email address and message content for mail we send you. Retained 30 days.
    Processing location
    United States (all account data and logs), sending region EU.
    Transfer mechanism
    EU-US Data Privacy Framework certification and the EU Standard Contractual Clauses, as provided in Resend's DPA.
    Terms
    resend.com/legal/dpa
  • FastmailFastmail Pty Ltd (Australia)

    Receipt and storage of email sent to and from our published contact addresses.

    Data received
    Email you send to our contact addresses, and our replies.
    Processing location
    Amsterdam, the Netherlands (primary mail storage), with a resilient replica, backups and logs in the United States.
    Transfer mechanism
    EU Standard Contractual Clauses, as provided in Fastmail's DPA.
    Terms
    www.fastmail.com/policies/dpa/
  • GroqGroq, Inc. (Groq UK Ltd contracts for the EEA)AI · no training

    Transcription of calls and meetings we record.

    Data received
    The audio of our own team and prospect calls, for transcription.
    Processing location
    United States.
    Transfer mechanism
    EU Standard Contractual Clauses, incorporated in Groq's Customer Data Processing Addendum.
    Training and retention
    Groq is not permitted to use inputs or outputs for training or fine-tuning, and by default does not retain inference content; abuse logs are kept up to 30 days. Zero-data-retention is available as a self-serve setting.
    Terms
    console.groq.com/docs/legal/customer-data-processing-addendum
  • LangfuseLangfuse GmbHAI · no training

    Monitoring of our own AI agents, which records the content sent to and returned by our AI providers.

    Data received
    The prompts and responses of the AI agents that draft our enquiry replies and account notes.
    Processing location
    European Union — Langfuse Cloud EU region, Ireland (AWS eu-west-1).
    Transfer mechanism
    Data is processed in the EEA; Langfuse's DPA incorporates the EU Standard Contractual Clauses for any support access from outside it.
    Training and retention
    Langfuse does not train or fine-tune models on client data. Retention is configurable per project and set by us.
    Terms
    langfuse.com/dpa

Sub-processors change as the Service evolves. We keep this list current and update it here whenever a processor is added or removed; for processors that handle your organisation’s operational data, the DPA gives organisation administrators 30 days’ notice by email before a new one is engaged.

We may also disclose data where required by law or to protect our rights, and in connection with a merger, acquisition, or asset sale.

6International transfers

Our production database, authentication and file storage run in Zurich, Switzerland (Supabase), and our application servers run in Amsterdam, the Netherlands (Railway). Switzerland is covered by an EU adequacy decision. Where a sub-processor processes personal data outside the European Economic Area, we rely on an adequacy decision or on the European Commission’s Standard Contractual Clauses; the mechanism for each sub-processor is stated in section 5.

7Retention

We keep personal data for as long as your account is active and as needed to provide the Service, then for the period required to meet legal, accounting, or reporting obligations. Operational data is deleted or returned in line with your organisation’s agreement with us.

8Your rights

Subject to applicable law, you have the right to:

  • access the personal data we hold about you;
  • request correction of inaccurate data;
  • request erasure of your data;
  • restrict or object to certain processing;
  • data portability;
  • withdraw consent where processing is based on consent.

To exercise these rights, contact [email protected]. You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or your local supervisory authority. Where we act as a processor on behalf of your organisation, please direct requests to that organisation.

9Security

We use technical and organisational measures including encryption in transit, tenant-level isolation (row-level security), access controls, and monitoring. No system is perfectly secure, but we work continuously to protect your data.

10Cookies

We use strictly necessary cookies to operate the Service (for example, to keep you signed in) and, where you consent, analytics cookies to understand product usage. You can control cookies through your browser settings.

11Children

The Service is intended for business use and is not directed at children. We do not knowingly collect personal data from children.

12Changes to this policy

We may update this policy from time to time. Material changes will be posted on this page with a revised “last updated” date.

Questions about this policy or our data practices can be sent to the contact below.

Contact

Legal entity
Vabumi OÜ
Registry code
17426329
Legal address
Järvevana tee 9, 11314, Kesklinna linnaosa, Tallinn, Harju maakond, Estonia