1. Introduction
This policy explains how personal data is processed in Rent Assistant, a property management service for guesthouses, small hotels and apartments. It covers two groups of people: our customers (accommodation providers and the staff they invite) and the guests of those properties, whose data the properties manage in Rent Assistant.
2. Who is responsible for your data
For the data of our customers and their users (accounts, subscriptions, invoices, security logs) we are the controller.
For the data of guests and staff that a property enters in Rent Assistant, the property is the controller. We process that data only on the property's behalf and instructions, as its processor, under the data processing terms in our Terms of Service. Guests should address questions about their stay to the property first.
3. What data we process
Depending on how the service is used, we process:
- Customer account data: name, email address, password (stored only as a hash), language, organisation details you enter (name, address, tax and bank data) and your subscription plan.
- Usage and security data: IP address and browser details when you sign in or out, a log of changes made in your account, and, if you allow browser notifications, a device token for push notifications.
- Guest data entered by a property: name, email, phone, ID or passport number, stay dates, rooms, number of adults and children, meals, special requests and notes, booking source and social media username, payments and invoices.
- Staff data, if a property uses the staff module: name, contact details, position, pay and working hours.
Properties should not enter health data or other special categories of personal data in notes or special requests unless it is necessary for the stay (for example food allergies) and they have a legal basis for it.
4. Why we process data and on what legal basis
We process personal data under the Law on Personal Data Protection of Bosnia and Herzegovina and, where it applies, the EU General Data Protection Regulation (GDPR):
- To provide the service, create and manage accounts and send service emails such as sign-up, password reset and booking emails the property has set up (performance of a contract).
- To issue invoices and keep accounting and tax records (legal obligation).
- To keep the service secure, prevent misuse and investigate incidents, using security logs (legitimate interest).
- To store and display guest and staff data for a property, only as the property instructs (processing on the property's behalf).
We do not sell personal data, do not use it for advertising and do not send marketing messages without your consent.
5. Who receives the data
We use a small number of service providers (sub-processors) who process data only on our instructions:
- Hosting provider: servers located in the European Union, where the database and uploaded files are stored.
- Resend (Resend, Inc., USA): delivery of emails sent by the service.
- Google Firebase Cloud Messaging (Google LLC, USA): delivery of browser push notifications, only for users who allow them.
- Public authorities, when we are legally required to disclose data.
Guest data is visible only to the property that entered it and the users that property has invited. Our authorised staff can access account data only when needed to run and support the service, and are bound by confidentiality.
6. Transfers outside Bosnia and Herzegovina and the EU
Data is stored in the European Union. Email delivery (Resend) and push notifications (Google) involve transfers to the United States. These transfers are made on the basis of standard contractual clauses and the providers' security measures, as permitted by the Law on Personal Data Protection of Bosnia and Herzegovina and the GDPR.
7. How long we keep data
We keep personal data only as long as needed:
- Account and organisation data: while the account is active. When a customer closes the account, we delete or anonymise it within 90 days, except data we must keep by law.
- Guest and staff data: for as long as the property keeps it in its account. The property can delete it at any time; it is deleted with the property's account.
- Invoices and accounting records: for the periods required by accounting and tax laws.
- Security and activity logs: 12 months. Email delivery logs: 90 days. In-app notifications: 30 days. These are deleted automatically.
8. How we protect data
Connections to the service are encrypted (HTTPS), passwords are stored only as hashes, each organisation's data is separated and access within an organisation is limited by roles and permissions. No system is completely secure, but we take reasonable technical and organisational measures appropriate to the risk.
9. Your rights
You have the right to:
- Access: find out whether we process your data and get a copy.
- Rectification: have inaccurate or incomplete data corrected.
- Erasure: have your data deleted, unless we must keep it by law.
- Restriction: have processing limited in certain cases.
- Portability: receive data you gave us in a structured, machine-readable format.
- Objection: object to processing based on legitimate interest.
- Withdraw consent at any time where processing is based on consent, without affecting earlier processing.
We reply within 30 days. Guests should contact the property that holds their booking; if a request reaches us, we forward it to the property and help it respond.
10. Right to lodge a complaint
You can lodge a complaint with the Personal Data Protection Agency of Bosnia and Herzegovina (Agencija za zaštitu ličnih podataka u BiH), www.azlp.ba. Residents of the EU can also contact the data protection authority in their country.
11. Data breaches
If a personal data breach is likely to put people's rights at risk, we notify the Personal Data Protection Agency of Bosnia and Herzegovina without undue delay and, where the law requires it, within 72 hours of becoming aware of it, and we inform the people affected without undue delay. For guest and staff data, we notify the property concerned without undue delay so it can meet its own obligations.
12. Automated decisions
We do not make decisions based solely on automated processing, including profiling, that have legal or similarly significant effects on you.
13. Children
The service is intended for businesses and adults. Customer accounts cannot be created by anyone under 18. Properties may record that a booking includes children, and are responsible for processing that information lawfully.
14. Cookies and browser storage
We do not use cookies or tracking. The browser storage we use is explained in our Cookie policy.
15. Changes to this policy
We will inform customers of material changes by email or in the app at least 30 days before they take effect. The date at the top of this page shows when the policy was last changed.
16. Contact
For questions or requests about personal data, write to us through the contact form.
