PRIVACY POLICY
Transparency, data protection, and privacy guidelines for Roomey Living residents and visitors
GENERAL DATA PROTECTION REGULATION (GDPR) & PRIVACY POLICY
1. General Information & Scope
Roomey Living, S.L. (hereinafter 'Roomey Living' or 'we') is committed to protecting the privacy and personal data of its website visitors, applicants, residents (colivers), and business partners. This Privacy Policy details how we collect, process, store, and safeguard your personal information in compliance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
2. Identification of the Data Controller
The entity responsible for processing your personal data collected through the website roomeyliving.com and associated services is:
3. What Personal Data Do We Process and for What Purposes?
We collect different categories of personal data depending on your interaction with Roomey Living:
| Data Category | Collected Data | Processing Purpose |
|---|---|---|
| Browsing Data | IP address, browser type, operating system, visit duration, pages viewed, referrer URL. | Technical operation of the website, security monitoring, analytics, and experience optimization. |
| Contact & Inquiries | Name, email address, phone number, preferred coliving location, move-in date, messages. | Responding to user inquiries, scheduling room viewings, and providing coliving information. |
| Coliving Applications | Full name, passport/ID number, nationality, date of birth, proof of income/employment contract, university enrollment, emergency contact. | Evaluating candidate eligibility, background verification, tenant screening, and lease drafting. |
| Lease Management & Billing | Bank account details, IBAN, payment history, deposit records, utility usage, signature audit trail. | Execution and management of the lease agreement, invoicing, deposit administration, legal compliance. |
| Newsletter & Marketing | Name, email address, housing preferences, marketing communication consent logs. | Sending updates on available coliving spaces, community news, events, and special promotional offers. |
4. What is the Lawful Basis for Processing Your Data?
Our legal ground for processing your personal data relies on the following legal bases under Article 6 of the GDPR:
Contract Fulfillment (Art. 6.1.b GDPR):
Processing is necessary for pre-contractual steps (evaluating applications, booking verification) and executing the coliving lease agreement.
Legal Obligations (Art. 6.1.c GDPR):
Compliance with tax laws, accounting rules, anti-money laundering regulations (AML/FT), and tenant registry requirements.
Legitimate Interest (Art. 6.1.f GDPR):
Protecting site security, preventing fraudulent applications, managing property maintenance, and conducting direct marketing to existing clients.
Consent (Art. 6.1.a GDPR):
Sending non-essential marketing communications, newsletters, and setting non-essential analytical/advertising cookies.
5. How Long Do We Keep Your Data?
Personal data is retained only for as long as necessary to fulfill the purpose for which it was collected or to satisfy statutory retention obligations:
- •Inquiries & General Requests: Retained for up to 1 year following the last interaction.
- •Unsuccessful Application Data: Deleted within 6 months after selection process closure, unless express consent for future openings is granted.
- •Coliver Contractual & Billing Records: Retained for the full lease duration plus 5 years (civil liability) and 6 years (Spanish Commercial Code). Tax records kept for 10 years.
- •Marketing & Newsletter Data: Processed until consent is revoked or an opt-out request is received.
6. To Whom Do We Disclose Your Data?
Roomey Living does not sell or rent your personal data to third parties. We only transfer data under strict confidentiality agreements to:
- •Authorized Service Providers & Data Processors: IT hosting providers, cloud services, payment gateways, electronic signature software (e.g. Signaturit), CRM software, and accounting platforms.
- •Property Owners & Property Managers: Information strictly required for lease execution, maintenance coordination, and building access control.
- •Public Authorities & Law Enforcement: When required by mandatory legal provisions, court orders, or tax authorities.
7. International Data Transfers
Our primary servers and service providers operate within the European Economic Area (EEA). If any service provider transfers personal data outside the EEA, Roomey Living ensures that appropriate safeguards are implemented, such as European Commission Standard Contractual Clauses (SCCs) or adequacy decisions.
8. What Are Your Rights and How Can You Exercise Them?
Under Articles 15 to 22 of the GDPR, you hold the following rights regarding your personal data:
- Right of Access: Obtain confirmation on whether we process your personal data and access a copy.
- Right to Rectification: Request correction of inaccurate or incomplete personal data.
- Right to Erasure ('Right to be Forgotten'): Request deletion of your data when no longer needed or consent is withdrawn.
- Right to Restriction of Processing: Request temporary suspension of data processing under specific statutory conditions.
- Right to Data Portability: Receive your personal data in a structured, commonly used, machine-readable format.
- Right to Object: Object to processing based on legitimate interest or direct marketing purposes.
- Right to Withdraw Consent: Revoke previously granted consent at any time without affecting prior lawful processing.
To exercise any of these rights, please submit a written request accompanied by a copy of your national identity document (ID or passport) to privacy@roomeyliving.com or by postal mail to Roomey Living, S.L., Provença 339, 08037 Barcelona, Spain.
If you consider your data protection rights violated, you also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es.
9. Technical and Organizational Security Measures
Roomey Living implements state-of-the-art technical, physical, and administrative security measures to protect your personal data against unauthorized access, loss, destruction, or alteration. These measures include SSL/TLS encryption for online data transmission, strict user access controls, firewall architecture, regular backups, and periodic vulnerability audits.
10. Modifications to this Privacy Policy
Roomey Living reserves the right to modify this Privacy Policy to reflect changes in regulatory standards or organizational procedures. Any updates will be published immediately on this page with an updated revision date.