Privacy
Privacy Policy
Last updated · 17 August 2026
This policy explains what personal data Vabumi OÜ (“Vabumi”, “we”, “us”) collects, why we collect it, and the rights you have over it. It applies to our website and to the Vabumi maintenance and operations platform (the “Service”).
1Who we are
Vabumi OÜ, a company registered in Estonia (registry code 17426329) with its registered office at Järvevana tee 9, 11314, Kesklinna linnaosa, Tallinn, Harju maakond, Estonia, is the data controller for the personal data described in this policy: website visitors, account holders, billing, and the people who contact us.
For the operational data your organisation and its staff enter into the Service, your organisation is the controller and Vabumi processes it on your organisation’s behalf under our Data Processing Agreement. The sub-processor list in section 5 applies to both.
For any privacy question or to exercise your rights, contact us at [email protected].
2Data we collect
We collect the following categories of personal data:
- Account data — name, work email, organisation, role, and authentication identifiers when you or your employer create an account.
- Operational data — the tasks, routines, notes, photos, voice memos, and other content you and your team enter to run your properties. This may incidentally include personal data about staff or guests that you choose to record.
- Usage data — log data, device and browser information, and product analytics about how the Service is used.
- Communications — messages you send us, demo bookings, and support requests.
3How we use your data
We use personal data to:
- provide, operate, secure, and improve the Service;
- authenticate users and enforce per-tenant access controls;
- respond to enquiries, bookings, and support requests;
- send service-related and, where permitted, occasional product communications;
- comply with legal obligations and protect against misuse or fraud.
4Legal bases (GDPR Article 6)
We rely on the following lawful bases:
- Contract — to deliver the Service to you or your organisation.
- Legitimate interests — to secure, maintain, and improve the Service and to communicate with prospective customers, balanced against your rights.
- Consent — for non-essential analytics or marketing where required; you may withdraw consent at any time.
- Legal obligation — where processing is required by law.
5Sharing and sub-processors
We do not sell personal data. We share it only with service providers who process it on our behalf under data-processing agreements. The sub-processors we currently use, what each receives, where it processes, and the transfer mechanism relied on are listed below. This is the same list published in Annex III of our Data Processing Agreement, rendered from one source so the two cannot differ. Vendor terms were last checked on 17 August 2026.
- SupabaseSupabase, Inc.
Database hosting, user authentication, and storage of files and photos you upload.
- Data received
- All account and operational data, including uploaded photos and voice recordings.
- Processing location
- Zurich, Switzerland (AWS eu-central-2) — the project region we chose for every environment. API request logs pass through Supabase's Cloudflare edge.
- Transfer mechanism
- Switzerland holds an EU adequacy decision. Supabase's DPA incorporates the EU, UK and Swiss Standard Contractual Clauses for any access from outside the EEA (Supabase is not DPF-certified).
- Terms
- supabase.com/legal/dpa
- RailwayRailway Corporation
Application hosting and compute for the Service.
- Data received
- All data in transit through the API and web servers, and server logs.
- Processing location
- Amsterdam, the Netherlands (europe-west4) for every service and environment. Railway's control plane and support access are in the United States.
- Transfer mechanism
- EU Standard Contractual Clauses or the EU-US Data Privacy Framework, as provided in Railway's DPA.
- Terms
- railway.com/legal/dpa
- StripeStripe Payments Europe, Ltd. (Ireland) with Stripe, Inc. (United States)
Payment and subscription billing.
- Data received
- Billing contact name, email, organisation, and payment details entered on Stripe's own checkout.
- Processing location
- United States (Stripe, Inc.), contracted through Stripe's Irish entity.
- Transfer mechanism
- EU-US Data Privacy Framework certification, with the EU Standard Contractual Clauses as fallback, as provided in Stripe's DPA.
- Terms
- stripe.com/legal/dpa
- OpenAIOpenAI Ireland Ltd (contracting entity for the EEA)AI · no training
AI features: extracting and classifying tasks from the text you enter, translation, and transcribing voice notes.
- Data received
- The text of tasks and notes submitted to AI features, and staff voice notes as audio.
- Processing location
- United States (API compute is not pinned to a region on our current terms).
- Transfer mechanism
- EU Standard Contractual Clauses (2021/914), incorporated in OpenAI's Data Processing Addendum.
- Training and retention
- OpenAI does not use API inputs or outputs to train or improve its models. API content is retained for up to 30 days for abuse monitoring, then deleted; zero-data-retention is available on approval and will be adopted when granted.
- Terms
- openai.com/policies/data-processing-addendum/
- AnthropicAnthropic Ireland, Limited (contracting entity for the EEA)AI · no training
AI features: triaging and categorising tasks, and structuring the enquiry and meeting records we keep about prospective customers.
- Data received
- The text of tasks submitted for triage; and, on our own side, enquiry, meeting and account notes.
- Processing location
- United States (API).
- Transfer mechanism
- EU Standard Contractual Clauses (2021/914), incorporated in Anthropic's Data Processing Addendum.
- Training and retention
- Anthropic does not train models on API inputs or outputs under its Commercial Terms. Inputs and outputs are deleted within 30 days unless flagged for policy enforcement or retention is required by law.
- Terms
- www.anthropic.com/legal/data-processing-addendum
- TwilioTwilio Ireland Limited (contracting entity for the EEA) / Twilio Inc.
WhatsApp messaging between the Service and your team, including any media sent in those messages.
- Data received
- Staff phone numbers, message content, and media (photos, voice notes) exchanged over WhatsApp.
- Processing location
- United States. Twilio's Ireland region does not support WhatsApp, so WhatsApp traffic is processed in the US.
- Transfer mechanism
- EU-US Data Privacy Framework certification (Twilio Inc.), Twilio's Binding Corporate Rules, and the EU Standard Contractual Clauses, as provided in Twilio's Data Protection Addendum.
- Terms
- www.twilio.com/en-us/legal/data-protection-addendum
- Meta PlatformsWhatsApp Ireland Limited (Meta Platforms)
The WhatsApp Business Cloud API, used alongside Twilio to deliver WhatsApp messages.
- Data received
- Staff phone numbers and the messages and media routed through WhatsApp.
- Processing location
- Meta data centres in the EU and the United States; message content is held for at most 30 days.
- Transfer mechanism
- EU-US Data Privacy Framework certification and the EU Standard Contractual Clauses, under WhatsApp's Business Data Processing Terms and Data Transfer Addendum.
- Terms
- www.whatsapp.com/legal/business-data-processing-terms
- Twilio SendGridTwilio Inc.
Transactional email such as invitations, password resets, and notifications.
- Data received
- Recipient name and email address, and the content of the notification.
- Processing location
- United States.
- Transfer mechanism
- EU Standard Contractual Clauses (and DPF where Twilio Inc. is the recipient), as provided in Twilio's Data Protection Addendum, which covers SendGrid.
- Terms
- www.twilio.com/en-us/legal/data-protection-addendum
- SentryFunctional Software, Inc. (dba Sentry)
Error monitoring and diagnostics. When an error occurs in your browser this may include a recording of the screen on which it happened, with text and media masked.
- Data received
- Error reports with user identifier, browser and device details, request metadata, and — on error only — a masked replay of the affected screen, retained by Sentry for at most 90 days.
- Processing location
- European Union (Frankfurt) — our Sentry organisation is on the EU data region. Account and organisation settings may be stored in the US.
- Transfer mechanism
- Data is stored in the EU. Sentry is DPF-certified and its DPA incorporates the EU Standard Contractual Clauses for support access from the United States.
- Terms
- sentry.io/legal/dpa/
- DiscordDiscord Inc. / Discord Netherlands B.V.
Internal routing of website enquiries and demo requests to our team, and hosting of team calls we record.
- Data received
- Enquiry and demo-request details you send us, and the audio of calls held on our Discord server. Discord does not itself store the content of voice calls.
- Processing location
- United States.
- Transfer mechanism
- Discord acts as an independent controller under its Developer Terms; transfers rest on the EU Standard Contractual Clauses (Module One) and Discord's DPF certification. There is no processor DPA with Discord.
- Terms
- support-dev.discord.com/hc/en-us/articles/8562894815383
- ResendResend, Inc.
Delivery of email sent from our published contact addresses.
- Data received
- Recipient email address and message content for mail we send you. Retained 30 days.
- Processing location
- United States (all account data and logs), sending region EU.
- Transfer mechanism
- EU-US Data Privacy Framework certification and the EU Standard Contractual Clauses, as provided in Resend's DPA.
- Terms
- resend.com/legal/dpa
- FastmailFastmail Pty Ltd (Australia)
Receipt and storage of email sent to and from our published contact addresses.
- Data received
- Email you send to our contact addresses, and our replies.
- Processing location
- Amsterdam, the Netherlands (primary mail storage), with a resilient replica, backups and logs in the United States.
- Transfer mechanism
- EU Standard Contractual Clauses, as provided in Fastmail's DPA.
- Terms
- www.fastmail.com/policies/dpa/
- GroqGroq, Inc. (Groq UK Ltd contracts for the EEA)AI · no training
Transcription of calls and meetings we record.
- Data received
- The audio of our own team and prospect calls, for transcription.
- Processing location
- United States.
- Transfer mechanism
- EU Standard Contractual Clauses, incorporated in Groq's Customer Data Processing Addendum.
- Training and retention
- Groq is not permitted to use inputs or outputs for training or fine-tuning, and by default does not retain inference content; abuse logs are kept up to 30 days. Zero-data-retention is available as a self-serve setting.
- Terms
- console.groq.com/docs/legal/customer-data-processing-addendum
- LangfuseLangfuse GmbHAI · no training
Monitoring of our own AI agents, which records the content sent to and returned by our AI providers.
- Data received
- The prompts and responses of the AI agents that draft our enquiry replies and account notes.
- Processing location
- European Union — Langfuse Cloud EU region, Ireland (AWS eu-west-1).
- Transfer mechanism
- Data is processed in the EEA; Langfuse's DPA incorporates the EU Standard Contractual Clauses for any support access from outside it.
- Training and retention
- Langfuse does not train or fine-tune models on client data. Retention is configurable per project and set by us.
- Terms
- langfuse.com/dpa
Sub-processors change as the Service evolves. We keep this list current and update it here whenever a processor is added or removed; for processors that handle your organisation’s operational data, the DPA gives organisation administrators 30 days’ notice by email before a new one is engaged.
We may also disclose data where required by law or to protect our rights, and in connection with a merger, acquisition, or asset sale.
6International transfers
Our production database, authentication and file storage run in Zurich, Switzerland (Supabase), and our application servers run in Amsterdam, the Netherlands (Railway). Switzerland is covered by an EU adequacy decision. Where a sub-processor processes personal data outside the European Economic Area, we rely on an adequacy decision or on the European Commission’s Standard Contractual Clauses; the mechanism for each sub-processor is stated in section 5.
7Retention
We keep personal data for as long as your account is active and as needed to provide the Service, then for the period required to meet legal, accounting, or reporting obligations. Operational data is deleted or returned in line with your organisation’s agreement with us.
8Your rights
Subject to applicable law, you have the right to:
- access the personal data we hold about you;
- request correction of inaccurate data;
- request erasure of your data;
- restrict or object to certain processing;
- data portability;
- withdraw consent where processing is based on consent.
To exercise these rights, contact [email protected]. You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or your local supervisory authority. Where we act as a processor on behalf of your organisation, please direct requests to that organisation.
9Security
We use technical and organisational measures including encryption in transit, tenant-level isolation (row-level security), access controls, and monitoring. No system is perfectly secure, but we work continuously to protect your data.
10Cookies
We use strictly necessary cookies to operate the Service (for example, to keep you signed in) and, where you consent, analytics cookies to understand product usage. You can control cookies through your browser settings.
11Children
The Service is intended for business use and is not directed at children. We do not knowingly collect personal data from children.
12Changes to this policy
We may update this policy from time to time. Material changes will be posted on this page with a revised “last updated” date.
Questions about this policy or our data practices can be sent to the contact below.
Contact
- Legal entity
- Vabumi OÜ
- Registry code
- 17426329
- Legal address
- Järvevana tee 9, 11314, Kesklinna linnaosa, Tallinn, Harju maakond, Estonia
- [email protected]