Skip to main content

Compliance & Data Protection

Stayoa is fully GDPR compliant and committed to treating your data according to the highest data protection standards.

GDPR Compliance

The General Data Protection Regulation (GDPR) is the most comprehensive data protection regulation in the history of the European Union. Stayoa is fully compliant with all GDPR requirements:

  • Lawfulness: We only process data on a legal basis
  • Purpose limitation: Data is only used for specified purposes
  • Data minimization: We only collect the most necessary data
  • Accuracy: We keep data current and correct
  • Storage limitation: Data is only stored as long as necessary
  • Integrity and confidentiality: Technical and organizational measures for protection
  • Accountability: We document all data processing operations

Your Rights under GDPR

As a data subject, you have comprehensive rights:

  • Right of access (Art. 15 GDPR): You can request information about your stored data
  • Right to rectification (Art. 16 GDPR): You can request correction of incorrect data
  • Right to erasure (Art. 17 GDPR): You can request deletion of your data ("Right to be forgotten")
  • Right to restriction (Art. 18 GDPR): You can request restriction of processing
  • Data portability (Art. 20 GDPR): You can receive your data in a structured format
  • Right to object (Art. 21 GDPR): You can object to processing
  • Withdrawal of consent (Art. 7 GDPR): You can withdraw given consents at any time

To exercise these rights, please contact us via our contact form or by email. We process your request within 30 days.

Data Processing

We process personal data exclusively for the following purposes:

  • Provision and operation of the Stayoa platform
  • Management of user accounts and properties
  • Processing of bookings and payments
  • Communication with users and guests
  • Fulfillment of legal obligations
  • Improvement of our services (with consent)

Data Sharing

We only share your personal data with third parties if:

  • You have given explicit consent
  • Sharing is necessary to fulfill a contract (e.g., to payment service providers)
  • We are legally obligated to do so
  • We have legitimate interests and your interests do not outweigh them

We work with the following trusted partners:

  • Stripe: For secure payment processing (PCI-DSS Level 1 certified)
  • Hosting Partner: For secure data hosting in the EU
  • Email Service Provider: For sending transaction emails

International Data Transfer

Your data is primarily stored and processed in the European Union (EU) and the European Economic Area (EEA). If data is transferred outside the EU/EEA:

  • We only use certified services with adequate data protection measures
  • We use Standard Contractual Clauses (SCCs) according to GDPR
  • We ensure that recipients guarantee adequate data protection

Data Retention

We only store your personal data for as long as necessary for the stated purposes:

  • User accounts: Until account termination plus legal retention periods
  • Booking data: At least 10 years after contract end (tax law retention obligation)
  • Marketing consents: Until withdrawal of consent
  • Log data: Maximum 90 days

Right to Complain

If you believe we are not processing your data properly, you have the right to file a complaint with a supervisory authority. In Germany, this is:

The Federal Commissioner for Data Protection and Freedom of Information
Graurheindorfer Str. 153, 53117 Bonn
www.bfdi.bund.de

Contact

For questions about data processing or to exercise your rights, please contact us:

Email: contact@stayoa.app
Or via our contact form