Host Privacy Policy

Issued by: SERVROOM VERTEX AI LIMITED
Company Registration: 821631, Companies Registration Office, Ireland
Registered Address: The Black Church, St. Mary’s Place, Dublin 7, D07 P4AX, Ireland
Contact: [email protected]

Applies to: The ServRoom host dashboard and accounts of hosts, property owners, property managers, providers, vendors, and team members.

1. About This Policy

This Privacy Policy explains how SERVROOM VERTEX AI LIMITED, a private company limited by shares incorporated in Ireland with company number 821631 (“ServRoom”, “we”, “us”), collects, uses, shares, and protects personal data when you create or use a ServRoom business account on the ServRoom platform and dashboard (the “Platform”).
In this Policy, “you” means any person who creates or uses a ServRoom business account or dashboard: hosts, property owners, property managers, providers, vendors, and team members.
For the personal data described in this Policy, ServRoom is the Data Controller. How guest data is handled is described in the Guest Privacy Policy; where you are the controller of guest data, ServRoom processes it on your behalf under the data-processing terms in the Host Terms of Use.
This Policy is designed to comply with the EU General Data Protection Regulation 2016/679 (the “GDPR”) and the Irish Data Protection Act 2018.

2. Personal Data We Collect

  1. Account data. Your full legal name, email address, phone number, password, country and city, and language preference. If you sign up or sign in with Google or Apple, we receive your name and email address from them under their own terms.
  2. Verification data. Documents you provide to verify your account or your business, reviewed as part of account verification.

  3. Business and listing data. Your units and their addresses, your services, items, prices, availability, branding, and the names and phone numbers of providers you register. You are responsible for informing the providers and team members whose details you register, and for giving them a copy of this Policy; we rely on you to do so.

  4. Transaction data. The commercial record of orders and bookings made through the Platform: amounts, statuses, timestamps, and refunds. This record is the basis of your monthly Commission invoice and of our legal reporting. The guest details inside an order are Guest Data, processed on your behalf under the Host Terms of Use.

  5. Tax and reporting information. Information EU law requires us to collect and verify about sellers on digital platforms, such as legal name, primary address, tax identification number, VAT number where available, and business registration details, together with transaction totals. See section 6.

  6. Communications. Messages you exchange with guests through Guest Chat, and your correspondence with us. Your side of Guest Chat is your personal data under this Policy; the guest side is Guest Data, processed on your behalf under the Host Terms of Use.

  7. Technical data. IP address, browser and device type, session timestamps, and interaction logs, recorded automatically to operate and secure the dashboard.

The account, verification, business, and transaction data described in this section is needed to open and operate an account; without it, we cannot provide the Platform or the relevant part of it. Providing tax information is a legal requirement, as described in section 6.

3. Purposes and Legal Bases for Processing

We process your personal data only for the purposes set out below.
Purpose Data used Legal basis (GDPR)
Creating and operating your account and providing the Platform Account, business, listing, and transaction data Article 6(1)(b), performance of a contract
Verifying your account Verification data, account data Article 6(1)(f), legitimate interests in a trusted platform
Invoicing the Commission Transaction data, account data Article 6(1)(b), performance of a contract
Keeping financial and accounting records Transaction data, account data Article 6(1)(c), legal obligation
Collecting, verifying, and reporting seller information to tax authorities (DAC7) Tax and reporting information, transaction totals Article 6(1)(c), legal obligation
Service communications about your account, orders, and the Platform Account data Article 6(1)(b), performance of a contract
Marketing our own services to you, with an opt-out in every message Account data Article 6(1)(f), legitimate interests in promoting our services to our business users
Operating, securing, protecting, and improving the Platform Technical data Article 6(1)(f), legitimate interests in a secure and functional platform
Establishing, exercising, or defending legal claims All categories, as relevant Article 6(1)(f), legitimate interests in protecting our rights
Complying with legal obligations that apply to us All categories, as relevant Article 6(1)(c), legal obligation
We do not sell or rent your personal data.
ServRoom does not use data processed through the Platform to train, fine-tune, or improve any AI model, and does not permit its AI providers to do so.
We do not carry out automated decision-making that produces legal or similarly significant effects for you. Any restriction of an account is reviewed by a person before it takes effect.

4. Marketing

We may send you updates and marketing about ServRoom services relevant to your business. Every marketing message includes an unsubscribe option, and you can opt out at any time without affecting your account. Service messages about your account, orders, and invoices are not marketing and are sent regardless. Where we contact you by email as an individual subscriber, we do so under the conditions of Irish electronic-marketing law: you can opt out when your details are collected and in every message, and we do not send such marketing where more than twelve months have passed since your most recent transaction with us.

5. Who We Share Data With

  1. Guests. A guest staying at one of your units sees the information you configure for that unit: the services, items, prices, instructions, and branding available there.
  2. Providers and team members. Where you work with a provider on an order, the details of that order needed to fulfil it are available to that provider. Providers and team members you register see the name of your business or account and the service information you assign to them.

  3. Service providers to ServRoom. We use selected cloud hosting, infrastructure, AI, and email and notification providers to run the Platform. They act as processors, handle personal data only under our instructions, and are bound by data-protection agreements.
  4. Tax authorities. Seller information and transaction totals are reported to the Irish Revenue Commissioners under EU law, as described in section 6.

  5. Professional advisers and legal disclosure. We may share data with our professional advisers, and disclose it where required by applicable law, regulation, court order, or a competent authority.

6. Tax Reporting (DAC7)

Under Council Directive (EU) 2021/514 (“DAC7”), as implemented in Ireland, ServRoom is legally required to collect and verify certain information about sellers earning consideration on the Platform, and to report it annually to the Irish Revenue Commissioners, who exchange it with the tax authorities of other EU Member States.
The reported information includes your identification details (such as legal name, primary address, tax identification number, VAT number where available, and business registration number), your financial account identifier where we hold one, and the consideration and number of relevant transactions per quarter. We will request any required information from you; providing it is a legal requirement, and EU rules require us to restrict or close accounts of sellers who do not provide it after reminders.
Because this reporting is a legal obligation, your consent is not required for it, and you will receive a copy of the information reported about you. Tax and reporting data is retained for as long as the law requires, regardless of account closure or deletion requests.

7. International Transfers

The Platform’s data is hosted on infrastructure located in the United States. Where personal data is transferred outside the European Economic Area, the transfer is carried out under an appropriate GDPR safeguard: an adequacy decision or certification under the EU-U.S. Data Privacy Framework, alongside Standard Contractual Clauses maintained as a documented fallback, or Standard Contractual Clauses directly, as applicable to the specific provider. You can request a copy of the applicable safeguard using the contact details in section 12.

8. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, and no longer than required by applicable law.
  • Account, verification, business and listing, and communications data is retained for the life of your account, then deleted or anonymised within a short period after closure, except where the law requires longer retention.
  • Transaction, invoicing, and tax and reporting data is retained for the periods required by financial, tax, and platform-reporting law, regardless of account closure.
  • Technical data is retained for a short operational period for security and troubleshooting, then deleted or aggregated.

9. Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, loss, or destruction, including encryption of data in transit, access controls, network protections, and logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Cookies and Similar Technologies

The host dashboard currently uses only strictly necessary cookies and local storage, such as those needed to keep you signed in and to remember your language. These do not require consent. We do not currently use advertising or analytics cookies on the dashboard. If we introduce analytics or other non-essential technologies in the future, we will update this Policy and, where required, ask for your consent first.

11. Your Rights

Subject to the conditions in the GDPR, you have the right to access your personal data, to have it rectified or erased, to restrict or object to its processing, and to receive it in a portable format.

Some rights are limited where we are legally required to keep or report data, for example under tax and platform-reporting law.
To exercise any of these rights, contact us using the details in section 12. We may need to verify your identity, and we will respond within one month, extendable where the law allows.

Your right to object. Where processing is based on legitimate interests, you have the right to object at any time, on grounds relating to your particular situation, by contacting us using the details in section 12. The processing will then stop unless there are compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is needed for legal claims. You also have the right to object at any time to the processing of your data for direct marketing, and we will stop.

12. Contact and Complaints

For any question, request, or complaint about this Policy or how your personal data is handled, contact:
SERVROOM VERTEX AI LIMITED
The Black Church, St. Mary’s Place, Dublin 7, D07 P4AX, Ireland
Email: [email protected]
We have not appointed a Data Protection Officer, as one is not required at our current scale. The contact point for all data-protection matters is [email protected].
If you are not satisfied with our response, you have the right to lodge a complaint with the Irish Data Protection Commission (www.dataprotection.ie) or with the data protection supervisory authority of the EEA country where you live or work.

13. Changes to This Policy

We may update this Policy from time to time to reflect changes in the Platform, our practices, or applicable law. The updated version will be published on the Platform. Where a change is material, we will notify account holders at least 15 days before it takes effect, in line with the Host Terms of Use.