Privacy Policy
Version: 2026-07-11 (last updated 11 July 2026)
This notice explains how Auctores Technologies OÜ (“we”, “us”) handles personal data when business users use the Auctores service and connect third-party tools (e.g., PMS) to generate overbooking recommendations and related outputs.
1. Controller & Contact
Auctores Technologies OÜ
Registry code: 17394351
Register: Estonian Commercial Register
Registered address: Harju maakond, Tallinn, Kesklinna linnaosa, Ahtri tn 12, 15551, Estonia
Contact person: E-Residency Hub OÜ, registry code 14249878
Email: leo@auctores.ai
2. Where We Act as Controller vs Processor
- Controller: account/admin user data (e.g., name, email, role), authentication data, billing/contact data, and essential service logs.
- Processor (on your behalf): operational data from connected third-party tools that is necessary to generate recommendations and outputs (as described in your contract/DPA).
If required, we provide a Data Processing Addendum (DPA) under Art. 28 GDPR that describes sub-processors, security measures, and instructions.
3. Purposes & Legal Bases (Art. 6 GDPR)
- Provide the service & connectors (operate integrations; compute recommendations; deliver outputs) — Art. 6(1)(b).
- Security & abuse prevention (access control, audit logs, incident response) — Art. 6(1)(f).
- Support & troubleshooting (handle your requests, fix issues) — Art. 6(1)(b)/(f).
- Legal obligations (e.g., accounting or retention duties, if applicable) — Art. 6(1)(c).
4. Personal Data We Process
- Account & contact data: name, email, company, role, authentication identifiers.
- Connector data: provider name, scopes/permissions granted, connection metadata, and access tokens stored encrypted.
- Customer content from connected tools (processor role): operational records necessary to compute outputs (exact categories depend on your configuration and connected systems).
- Technical logs: timestamps, request IDs, success/error codes, and event metadata necessary for security and reliability.
Avoid sending special-category data (Art. 9 GDPR) through connectors unless strictly necessary and lawful.
5. Security
- Encryption: data is protected with encryption in transit (TLS) and encryption at rest where supported by our providers.
- Secrets: connector secrets/tokens are stored encrypted and accessed only when necessary for authorized API calls.
- Access controls: role-based access, least privilege, and logging/monitoring for production systems.
6. Data Location & International Transfers
Auctores configures its primary production infrastructure in European locations. The deployed locations and infrastructure jurisdictions currently used for the Service are:
- Supabase: Central EU in Frankfurt, Germany (
eu-central-1), for the primary database, authentication, and related storage services. - Railway: EU West in Amsterdam, the Netherlands (
europe-west4), for application hosting and backend execution. - Google Cloud Platform: an Auctores-selected European location for encryption and key-management services. Auctores does not make a narrower country-level representation where the applicable GCP resource is configured as a European regional or multi-regional resource.
- MailerSend: its current DPA identifies a data centre in Belgium for transactional email processing.
These deployment locations are subject to the laws of Germany, the Netherlands, the applicable European GCP location, Belgium, and EU law. Some providers, their corporate entities, support personnel, or subprocessors may also be subject to non-EEA jurisdictions. If personal data is transferred outside the EEA/UK, Auctores uses an applicable lawful transfer mechanism, including the European Commission's Standard Contractual Clauses where required, together with supplementary measures appropriate to the transfer.
To prevent international governmental access to or transfer of personal or non-personal data held in the EU where that access or transfer would conflict with EU or applicable Member State law, Auctores uses European deployment regions, encryption in transit and at rest, least-privilege access controls, confidentiality obligations, access logging and monitoring, data minimisation, and contractual security and transfer obligations with its providers. Auctores assesses legally binding access requests, limits any disclosure to what is legally required, and, where legally permitted and reasonably available, challenges or seeks review of requests that conflict with applicable EU law and informs the affected Customer.
7. Processors & Sub-processors
We use service providers under GDPR-compliant processing terms. This list may be updated as the Service evolves:
- Supabase — database, authentication, and storage.
- Google Cloud Platform — encryption and key management.
- Railway — application hosting and backend execution.
- MailerSend — transactional email delivery.
- Stripe Payments Europe — subscription billing, payment, tax, and invoice processing. Stripe is not intended to receive PMS reservation or guest data from Auctores.
The DPA includes the formal subprocessor list for Customer Personal Data processed by Auctores on the Customer's behalf. Stripe is listed here for Auctores account and billing processing and is not treated as a subprocessor of PMS reservation data unless the Service's data flow changes.
8. Retention
Account data is retained for the duration of your account and as needed for legitimate business purposes and legal compliance. Connector credentials are stored while a connection is active and deleted upon disconnection or account deletion. Minimal operational logs are kept for up to 180 days for security and troubleshooting unless legal obligations require longer.
When active data is deleted, provider-managed backup or disaster-recovery copies may remain isolated from ordinary use until they are overwritten or expire under the provider's documented backup cycle. Auctores does not use those residual copies for normal processing and, if a backup is restored, will reapply completed Customer deletion requests. Billing, tax, contract, consent, and security evidence is retained only for the applicable legal or claims period and with access restricted to the relevant purpose.
9. Your Rights
Depending on your situation and applicable law, you may request access, rectification, erasure, restriction, portability, or object to processing. You can contact us at leo@auctores.ai.
You also have the right to lodge a complaint with a supervisory authority. In Estonia, this is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), and you may also complain with your local EU/EEA authority where applicable.
10. Cookies & Local Storage
We use essential cookies/local storage required to run the Service (e.g., session/security). If we add analytics or marketing cookies in the future, we will update this notice and, where required, request consent.
11. Automated Decision-Making
The Service generates recommendations based on your configured parameters and connected systems. We do not intend to make decisions with legal or similarly significant effects about individuals solely by automated means within the meaning of Art. 22 GDPR. Auto Apply is disabled by default and an authorised business user decides whether to enable automated PMS write-back.
12. Changes
We may update this notice from time to time. Material changes will be reflected here and, when appropriate, communicated to account administrators.