Last updated: 16 August 2026 · RoomFlow (roomflow.cc), operated from Sweden · [email protected]
This DPA forms part of the RoomFlow Terms of Service between RoomFlow (“Processor”) and the Customer (“Controller”). It implements Article 28 GDPR.
RoomFlow processes personal data of the Controller’s guests solely to provide the booking and property-management service. The Customer is controller; RoomFlow is processor. Duration: the term of the subscription plus the deletion period in §9.
Storage, organization and transmission of reservation data: creating and managing bookings, check-in/out, guest folios and charges, direct-booking page operation, synchronization of bookings with connected OTA channels via the channel manager, and — where the Controller uses the TM30 feature — preparation of statutory immigration notifications.
Data subjects: the Controller’s guests and prospective guests. Data categories: name, email, phone, nationality/language where provided by the booking source, stay dates, room/bed assignment, booking source and reference, charges and payment status, and free-text notes the Controller records. Where the Controller uses the TM30 immigration-reporting feature: additionally passport number, nationality code, gender and (optionally) date of birth, processed exclusively to fulfil the Controller’s legal reporting obligation to the Thai Immigration Bureau and subject to restricted staff access. No payment-card numbers are processed or stored by RoomFlow. The Controller agrees not to place special-category (sensitive) data in free-text fields.
RoomFlow processes guest data only on the Controller’s documented instructions — given through the software’s normal operation and this DPA — unless EU or member-state law requires otherwise, in which case RoomFlow informs the Controller before processing (unless the law forbids it). RoomFlow will flag instructions it believes infringe the GDPR.
Persons authorized to process the data are bound by confidentiality obligations.
Technical and organizational measures include: TLS encryption in transit; passwords hashed (bcrypt); signed, httpOnly session cookies with server-side revocation; role-based access and per-property tenant isolation (housekeeping roles cannot access guest identity documents); EU data hosting (database in AWS eu-west-1 via Supabase); restricted and authenticated administrative/diagnostic endpoints; rate limiting on public endpoints; routine security review of changes. Measures may evolve but will not materially decrease in protection.
The Controller authorizes these sub-processors: Supabase (database, EU), Vercel (hosting), Channex.io (OTA channel synchronization), Resend (transactional email delivery — recipient name, email address and message content) and Cloudflare (bot protection on public forms — visitor IP address). RoomFlow will give at least 14 days’ notice before adding or replacing sub-processors, giving the Controller the right to object on reasonable data-protection grounds; RoomFlow remains liable for its sub-processors’ performance.
Taking into account the nature of processing, RoomFlow assists the Controller: (a) with data-subject requests (access, erasure, portability, etc.) — via the product’s export functions or on request to [email protected]; (b) with security, breach notification, and impact-assessment duties under Articles 32–36. In case of a personal-data breach affecting the Controller’s guest data, RoomFlow notifies the Controller without undue delay after becoming aware, with the information needed for the Controller’s 72-hour notification to the authority.
On termination of the service, RoomFlow will, at the Controller’s choice, return guest data in a portable format and/or delete it within 30 days, except where EU/member-state law requires longer retention. Deletion requests may be initiated via the data-deletion page or [email protected].
RoomFlow makes available the information reasonably necessary to demonstrate compliance with Article 28, and allows audits by the Controller or its mandated auditor — normally satisfied by RoomFlow’s written security documentation; on-site audits require 30 days’ notice, at the Controller’s cost, at most once per year, and must not endanger other customers’ data.
Primary data storage is in the EU. Where a sub-processor processes data outside the EU/EEA, RoomFlow ensures a valid transfer mechanism (adequacy decision or Standard Contractual Clauses).
Questions about these documents: [email protected]. Material changes are announced by email or in-app notice before they take effect.