How RoomCare handles your data.
This policy explains what personal data RoomCare collects, why, and how it is protected — across our mobile app, web dashboard, API and this website. Effective date: 16 September 2026.
Who this policy is for, and who we are
“RoomCare”, “we”, “us” or “our” means Almaware S.r.l., registered at Via Camozzi 111, 24121 Bergamo (BG), Italy (VAT no. IT03779610165). RoomCare provides a voice-first maintenance-reporting platform for hotels and vacation-rental operators, made up of a mobile app (iOS and Android), a web dashboard at app.roomcare.app, an API at api.roomcare.app, and this marketing website at roomcare.app (together, the “Service”). This policy applies to all of them.
Staff at a hotel or vacation-rental operator walk through rooms, record a short voice note and take photos in the mobile app. Our AI transcribes the recording, splits it into a list of issues, and matches the photos to those issues; maintenance staff then see the resulting report in the app, on the web dashboard, or as a PDF.
Because RoomCare is a business-to-business product, this policy describes two different situations, explained in full in the next section: data about the organizations and people who buy and administer RoomCare (where we are the controller), and data that a customer organization uploads about its own operations and staff to run its business (where we are a processor acting on that organization’s instructions).
Who is responsible for your data
GDPR asks every organization handling personal data to know whether it is acting as a “controller” (deciding why and how data is processed) or a “processor” (processing data on someone else’s instructions). RoomCare is both, depending on the data in question.
When RoomCare is the controller
We are the controller for data about the customer organization’s account and its administrators: sign-up details, admin and member contact information used to manage the account, billing and relationship communications, enquiries submitted through this marketing site, and support emails you send us. We decide why and how this data is processed, and this policy governs it directly.
When RoomCare is the processor
When a customer organization (a hotel or vacation-rental operator, the “Customer”) uses RoomCare to run its own maintenance operations, the data it uploads and generates — voice recordings, photos, transcripts, room and property data, reports, issues, comments, and its own staff’s member accounts — belongs to that Customer. The Customer is the data controller of that data; RoomCare processes it only on the Customer’s documented instructions, under a data processing agreement pursuant to Article 28 GDPR (available on request at privacy@roomcare.app).
If you are a guest, an employee of one of our Customers, or otherwise a person whose data appears inside a report, and you have a question about that data, please contact the relevant Customer organization directly — they control it, and we act only on their instructions. RoomCare assists Customers in responding to such requests as required by GDPR Article 28.
Data we process
Account data
Name, email address, hashed password, role, organization name, and preferred language.
Voice recordings & transcripts
The audio you record when reporting a room issue, and the text transcript our AI generates from it.
Photos
Images captured or attached to document a maintenance issue.
Room & property data
Room codes and names, property details, and the attributes a Customer configures for its own registry.
Reports, issues & comments
The list of issues our AI extracts from a report, their status and assignment, and any comments maintenance staff add.
Technical data
IP address and request logs kept on our servers, and session tokens used to keep you signed in.
Permissions the mobile app requests
- Microphone — to record the voice note describing an issue.
- Camera — to photograph the issue you’re reporting.
- Photo library — to attach an existing photo instead of taking a new one.
We do not request access to your location, your contacts, or any advertising identifier. The app contains no third-party analytics or crash-reporting SDK, and it does not track you across other apps or websites.
How we use your data, and on what legal basis
- To provide the Service — capturing, transcribing and structuring reports, and displaying them in the app, dashboard and PDF — necessary to perform our contract with the Customer organization (GDPR Art. 6(1)(b)).
- To administer accounts and relationships — responding to sign-ups, enquiries and support requests, and sending transactional emails such as account confirmation, password resets, invitations and notifications — necessary to perform our contract or our legitimate interest in running the Service (Art. 6(1)(b)/(f)).
- To keep the Service secure — enforcing tenant isolation, detecting abuse, and maintaining logs for troubleshooting — our legitimate interest in protecting the Service and its users (Art. 6(1)(f)).
- To comply with the law — where we are required to keep or disclose records (Art. 6(1)(c)).
- To measure this website’s traffic — using cookieless, self-hosted analytics with no personal profiles — our legitimate interest in understanding aggregate site usage (Art. 6(1)(f)).
Who we share data with
We use a small number of specialist providers to run the Service. We do not sell personal data, and we do not share it with anyone for their own marketing purposes.
- Hetzner Online GmbH (Germany, EU) — hosts our application servers, PostgreSQL database and S3-compatible object storage.
- Amazon Web Services EMEA (Amazon SES, eu-west-1 Ireland, EU) — delivers transactional email: account confirmation, password reset, invitations and notifications.
- OpenRouter, Inc. (USA) — routes the AI requests for speech-to-text, report structuring and photo matching. See below for detail.
- Self-hosted Umami (analytics.almaware.net) — cookieless website analytics for roomcare.app, with no personal profiles.
Through OpenRouter, audio recordings and their transcript text are sent primarily to Microsoft MAI-Transcribe-2, hosted on Microsoft Azure in the United States, for speech-to-text, and — if that service is unavailable — as a fallback to OpenAI’s Whisper (large-v3-turbo) model. The transcript and the report’s photos are then sent to Google Gemini (currently Gemini 2.5 Flash), which splits the transcript into a list of issues, matches each photo to the issue it shows and, where needed, translates the report. We use these providers under their commercial API terms, only to deliver the Service, and we do not allow them to use the data for their own purposes, such as training their models.
International data transfers
OpenRouter, Microsoft Azure’s United States region, OpenAI and Google may process data outside the European Economic Area. Those transfers rely on the European Commission’s Standard Contractual Clauses and, where the recipient is certified, on the EU-US Data Privacy Framework. Hetzner and Amazon Web Services EMEA process and store data inside the EU, so no such transfer occurs for that hosting and email infrastructure.
Data retention
- Data is kept for as long as the customer organization’s account is active.
- An organization’s owner can permanently delete the organization and all of its data at any time, from the mobile app (Settings → Delete account). This immediately and permanently erases the organization’s reports together with their audio and photo media, its rooms and properties, all member accounts, sessions and pending invitations.
- Individual members (other than the owner) are removed from an organization by that organization’s owner or manager.
- Password-reset links expire after 60 minutes and can only be used once.
- RoomCare can apply an automatic media-retention limit of 365 days to report audio and photos; it is not currently enabled.
- Backups are made daily and each copy is kept for 90 days, then permanently deleted, so data erased from the Service also disappears from backups within 90 days.
Security
- HTTPS everywhere
- Passwords are hashed, never stored in plain text
- Tenant isolation enforced in the application and by database row-level security
Your rights under GDPR
Subject to the conditions in Articles 15 to 22 GDPR, you have the right to request access to, correction of, erasure of, or a copy of your personal data, to restrict or object to how it is processed, and to not be subject to a decision based solely on automated processing.
To exercise these rights over data for which RoomCare is the controller — your account or relationship data described above — contact us at privacy@roomcare.app. We have not appointed a Data Protection Officer, as our processing does not require one under Article 37 GDPR.
If your data appears inside a report as part of a customer organization’s use of RoomCare — where RoomCare is a processor — please direct your request to that organization; it controls the data and we act only on its instructions. We will assist the organization with any such request it forwards to us.
You also have the right to lodge a complaint with a supervisory authority, in particular the Italian Data Protection Authority (Garante per la protezione dei dati personali, www.garanteprivacy.it), or with the supervisory authority of your own EU member state of residence.
Children’s privacy
The Service is a business tool for hospitality staff and is not directed at, or knowingly used to collect data from, children under 16.
Automated decision-making
Our AI structures a voice recording into a list of issues to help your maintenance team work faster; it does not make any automated decision that produces legal or similarly significant effects about a person; people on your team decide what to do with each issue.
Changes to this policy
We may update this policy from time to time, for example as the Service or the providers behind it change. We will post the revised version here with a new effective date, and where a change is material we will make reasonable efforts to let account administrators know directly.
Contact us
Data controller: Almaware S.r.l., Via Camozzi 111, 24121 Bergamo (BG), Italy (VAT no. IT03779610165).
Privacy questions or requests: privacy@roomcare.app