Privacy Policy
How StayClean handles personal data: purposes, legal bases, retention, international transfers, security, artificial intelligence and individual rights.
Version dated 16 September 2026.
1. Purpose, scope and responsible entity
This policy sets out the framework for processing personal data through StayClean websites, applications, customer and provider workspaces, application programming interfaces, support tools and operational services. It covers visitors, prospects, customers, company representatives, independent professionals, authorised team members and people whose information is provided to organise a job.
StayClean Global Services OÜ is an Estonian private limited company registered under number 17490333, with its registered office at Harju maakond, Tallinn, Kesklinna linnaosa, Tornimäe tn 5, 10145, Estonia. Data-related requests may be sent to william.rudent@stayclean.io or to the registered office, marked for data protection. This contact does not represent an announcement that a formal data protection officer has been appointed.
2. Allocation of responsibilities
StayClean acts as controller where it determines the purposes and essential means of account management, its own invoicing, security, abuse prevention, support and commercial relationships. The legal basis is assessed for each purpose rather than assigned indiscriminately to the entire platform.
Where StayClean processes information exclusively on a business customer's behalf and under its instructions, it acts as processor. An agreement complying with Article 28 GDPR must specify instructions, data categories, security measures, subprocessors, assistance and return or deletion arrangements. This policy does not replace that agreement. Property managers, cleaning businesses and payment providers may be controllers for their own processing; their legal status depends on their actual activities.
3. Identification and account information
Depending on the service used, data includes names, business contact details, language, account identifiers, role, company, billing address, registration, tax information, service areas, availability and necessary professional credentials. Permissions, invitations, contractual acceptances and sensitive changes may be recorded.
Mandatory fields are identified in the relevant process. Failure to provide them may prevent account creation, a legitimate verification, invoicing or performance of a job. Optional information, particularly for marketing, must not be made artificially necessary for an unrelated service.
4. Operational, financial and technical information
Operations may require property addresses, calendars and booking references, instructions, access information, tasks, timings, assignments, reports, incidents, photographs, videos and completion evidence. Movement or proximity information is processed only within the scope explained in section 14.
Financial data may include invoices, amounts, commissions, refunds, payout details and payment references and statuses. Identification required by a financial provider is also subject to that provider's obligations. The presence of a payment interface does not mean that StayClean receives complete payment-card information.
Technical data includes, depending on enabled features, IP addresses, browser and device information, connection logs, application events, errors, timestamps and tracking preferences. Logs must not unnecessarily contain passwords, access secrets or complete private content.
5. Sources and data minimisation
Information comes from the individual, their account administrator, customers or professionals involved in a job, authorised integrations, technical providers and, for certain business contacts, lawfully consulted public sources. Public availability does not authorise unrestricted reuse.
A person supplying information must have a valid basis and provide required notices. StayClean retains its own transparency obligations, including for indirect collection. Guest names, personal documents and private-life information must not be imported where booking references and dates are sufficient.
6. Purposes and legal bases
Creating an account and performing a contract entered into directly with an individual may rely on Article 6(1)(b) GDPR. Managing corporate representatives, necessary coordination, reasonable service improvement and fraud prevention may rely on legitimate interests following an assessment of necessity, proportionality and the rights concerned.
Accounting, lawful responses to authorities and applicable tax duties rely on legal obligation. Non-essential tracking and communications requiring prior permission rely on consent. Targeted retention of material needed for litigation may rely on the defence of rights and legitimate interests. A contract with a company does not, by itself, justify every processing activity involving its workers, guests or contractors.
7. Recipients and permissions
Access is restricted to persons and organisations needing information for the relevant purpose: authorised StayClean personnel, account administrators, the customer and provider assigned to a job, technical suppliers, outsourced support, payment providers, advisers, insurers where a claim requires it, and legally competent authorities.
Membership of the provider network does not confer access to all properties or records. Access codes, identity evidence and financial data require specific permissions. Confidentiality commitments, processing agreements and access controls must reflect the activities actually entrusted to each recipient.
8. Hosting and distributed infrastructure
The technical arrangements communicated by StayClean involve several suppliers, including Amazon Web Services (AWS), Vultr, DigitalOcean and Railway, for computing, storage, networking, deployment and application operations, depending on the component. The architecture seeks continuity through distribution, replication, redundancy and recovery capability within the environments actually deployed.
Containerised application layers, load-balancing mechanisms and any content delivery networks do not guarantee absolute availability. International reach does not mean that every record is copied to every continent or that public assets and private databases follow identical routes. Regions, support access and backup destinations must be documented for the relevant processing activity.
9. Transfers outside the European Economic Area
International suppliers may involve processing or access from outside the EEA, including the United States where the configuration or recipient entity so provides. Remote access may constitute a transfer even when primary storage remains in Europe.
Each transfer must use a valid mechanism: an adequacy decision applicable to the recipient and activity, or appropriate safeguards such as standard contractual clauses together with necessary assessments and supplementary measures. Exceptional derogations are not a general authorisation for worldwide replication. Merely using the site does not constitute consent to all transfers. Relevant information about recipients, countries and safeguards may be requested from the stated contact, subject to redactions that do not prevent the exercise of rights.
10. Security and confidentiality
Measures must be proportionate to risk: permission controls, environment separation, secret protection, communications encryption where relevant, logging, updates, backups and incident management. Their design takes account of the sensitivity of property access information, visual evidence and financial data.
Redundancy does not replace backups, access controls or a legal basis. No system excludes every incident. This does not reduce StayClean's statutory security duties. Users must protect their credentials, limit invitations and promptly report suspected compromise.
11. Retention and archiving
Data is retained according to its purpose, demonstrated needs, applicable contractual instructions and legal obligations. The reference schedule under this policy provides for: account information during the relationship followed by selective archiving of necessary evidence; accounting records generally seven years from the end of the relevant financial year where Estonian law requires; prospect records up to three years after the last relevant contact; support cases up to twenty-four months after closure; ordinary security logs up to six months; job evidence up to twelve months; detailed geolocation up to sixty days.
These are reference operational ceilings, not requirements to retain everything. A shorter local period or justified deletion prevails. Extracts needed for a dispute may be isolated until resolution and expiry of the applicable period. Backups scheduled for removal follow a target maximum rotation cycle of ninety days; restoration must reapply relevant deletions. Records maintained by a financial provider are also subject to its own obligations.
12. Automation, artificial intelligence and profiles
Features may analyse instructions, evidence, timings, incidents or messages to suggest assignments, summaries, alerts and quality assessments. Outputs depend on available information and may be inaccurate. Relevant criteria may include availability, service area, job requirements, punctuality and documented compliance.
An automated assistant must be identified and its involvement usefully explained in the relevant process. A solely automated decision producing legal or similarly significant effects on an individual may be implemented only where authorised by law. Required safeguards include, as applicable, meaningful human intervention, an opportunity to express a view and a challenge procedure. A score or alert is not conclusive proof of misconduct.
13. Images, sensitive information and model training
Evidence must focus on what is necessary for the job. Faces, children, identity documents, health information, correspondence and objects unnecessarily revealing private life should be avoided. Excessive content must be capable of restriction, correction or deletion, subject to a lawful retention reason.
The platform is not intended to receive special-category data without necessity and a specific legal condition. A technical content licence does not, by itself, authorise general-purpose model training. Such reuse requires a separate purpose assessment, appropriate information, a legal basis and the necessary commitments from the providers involved.
14. Geolocation, QR and NFC
Location may support navigation, arrival confirmation, assistance or investigation of an incident where these features are enabled and legally justified. Accuracy, recipients and collection periods must be proportionate. QR and NFC scans also create job-related events and do not automatically establish that every task has been completed.
Tracking must not become continuous surveillance outside justified operational periods. A device permission does not replace the legal basis. Consent may be unsuitable in a relationship of dependency; the relevant controller must assess less intrusive alternatives, inform professionals and comply with applicable local employment rules.
15. Integrations and shared reports
Connections to a property management system, calendar, lock, communication tool or other third-party service are limited to necessary permissions. The account holder must be able to revoke a connection; revocation does not automatically erase information already lawfully retained by each party.
Before sharing a report through a link accessible to others, the user must check its scope. Access credentials, detailed routes, identity documents and financial data are not intended for public disclosure. Recipients may forward or copy a link; available restriction and revocation mechanisms should be used.
16. Communications and marketing
Messages necessary for a job, security, invoicing or the contract are separate from marketing. Enabled channels may include email, notifications and other methods offered within the account.
Marketing follows the rules of the relevant country and requires prior consent where applicable. Individuals may object without charge through the indicated mechanism or this policy's contact. A minimal suppression record may be retained to avoid contacting someone who has opted out again.
17. Individual rights
Subject to statutory conditions, you may request access, correction, erasure, restriction and portability of your data and object to certain processing. Consent may be withdrawn at any time without affecting the lawfulness of earlier processing. Objections to direct marketing must be respected.
Not every right is absolute: a retention duty or defence of a legal claim may justify limited continued storage. A reasoned response must explain any refusal and available remedies. Where StayClean acts as processor, it forwards or assists the request with the relevant controller without obstructing its exercise.
18. Requests and response periods
Write to william.rudent@stayclean.io identifying the account and request. Additional identity evidence is requested only where there is reasonable doubt and only proportionately; do not send a complete sensitive identity document without being asked.
A response is provided without undue delay and normally within one month of receipt. An extension of two further months may be necessary because of complexity or the number of requests, with reasons communicated within the first month. Exercise is normally free, subject only to statutory exceptions, including manifestly unfounded or excessive requests.
19. Authorities and remedies
You may complain to a competent data protection authority, including that of your habitual residence, workplace or the location of the alleged infringement. In Estonia: Andmekaitse Inspektsioon (AKI), Tatari 39, 10134 Tallinn; info@aki.ee; official website aki.ee.
An Estonian registered office does not require you to waive access to another competent authority, court proceedings or legally available compensation. Lead supervisory authority competence depends on GDPR criteria, not merely the registered address.
20. Personal data breaches
Where an incident may affect personal data, StayClean must assess its nature, scope and risks, contain its effects and document the response. Notifications to controllers, authorities and affected people are made under statutory conditions and deadlines, including the seventy-two-hour period applicable to certain authority notifications following awareness.
Security considerations may temporarily limit disclosure of technical details but do not permit withholding information legally owed to affected individuals.
21. Children and tracking technologies
Operational accounts are intended for adults with the necessary legal capacity. Anyone registering team members must verify their authority. Information about children incidentally present at a property must not be collected without necessity and appropriate safeguards.
Cookies, local storage, SDKs and similar technologies are addressed separately in the cookie policy. Accepting commercial terms does not constitute acceptance of optional tracking.
22. Changes and legal interaction
This policy is reviewed when services, purposes, recipients or safeguards change. Material changes require appropriate notice and, where necessary, fresh consent before the relevant processing. They cannot retrospectively legalise unlawful collection.
Estonian law and applicable European legislation provide the reference framework without excluding mandatory territorial rules. This notice operates alongside the terms of use, terms of sale, cookie policy and processing agreements without restricting statutory rights.
Version dated 16 September 2026.
1. Purpose, scope and responsible entity
This policy sets out the framework for processing personal data through StayClean websites, applications, customer and provider workspaces, application programming interfaces, support tools and operational services. It covers visitors, prospects, customers, company representatives, independent professionals, authorised team members and people whose information is provided to organise a job.
StayClean Global Services OÜ is an Estonian private limited company registered under number 17490333, with its registered office at Harju maakond, Tallinn, Kesklinna linnaosa, Tornimäe tn 5, 10145, Estonia. Data-related requests may be sent to william.rudent@stayclean.io or to the registered office, marked for data protection. This contact does not represent an announcement that a formal data protection officer has been appointed.
2. Allocation of responsibilities
StayClean acts as controller where it determines the purposes and essential means of account management, its own invoicing, security, abuse prevention, support and commercial relationships. The legal basis is assessed for each purpose rather than assigned indiscriminately to the entire platform.
Where StayClean processes information exclusively on a business customer's behalf and under its instructions, it acts as processor. An agreement complying with Article 28 GDPR must specify instructions, data categories, security measures, subprocessors, assistance and return or deletion arrangements. This policy does not replace that agreement. Property managers, cleaning businesses and payment providers may be controllers for their own processing; their legal status depends on their actual activities.
3. Identification and account information
Depending on the service used, data includes names, business contact details, language, account identifiers, role, company, billing address, registration, tax information, service areas, availability and necessary professional credentials. Permissions, invitations, contractual acceptances and sensitive changes may be recorded.
Mandatory fields are identified in the relevant process. Failure to provide them may prevent account creation, a legitimate verification, invoicing or performance of a job. Optional information, particularly for marketing, must not be made artificially necessary for an unrelated service.
4. Operational, financial and technical information
Operations may require property addresses, calendars and booking references, instructions, access information, tasks, timings, assignments, reports, incidents, photographs, videos and completion evidence. Movement or proximity information is processed only within the scope explained in section 14.
Financial data may include invoices, amounts, commissions, refunds, payout details and payment references and statuses. Identification required by a financial provider is also subject to that provider's obligations. The presence of a payment interface does not mean that StayClean receives complete payment-card information.
Technical data includes, depending on enabled features, IP addresses, browser and device information, connection logs, application events, errors, timestamps and tracking preferences. Logs must not unnecessarily contain passwords, access secrets or complete private content.
5. Sources and data minimisation
Information comes from the individual, their account administrator, customers or professionals involved in a job, authorised integrations, technical providers and, for certain business contacts, lawfully consulted public sources. Public availability does not authorise unrestricted reuse.
A person supplying information must have a valid basis and provide required notices. StayClean retains its own transparency obligations, including for indirect collection. Guest names, personal documents and private-life information must not be imported where booking references and dates are sufficient.
6. Purposes and legal bases
Creating an account and performing a contract entered into directly with an individual may rely on Article 6(1)(b) GDPR. Managing corporate representatives, necessary coordination, reasonable service improvement and fraud prevention may rely on legitimate interests following an assessment of necessity, proportionality and the rights concerned.
Accounting, lawful responses to authorities and applicable tax duties rely on legal obligation. Non-essential tracking and communications requiring prior permission rely on consent. Targeted retention of material needed for litigation may rely on the defence of rights and legitimate interests. A contract with a company does not, by itself, justify every processing activity involving its workers, guests or contractors.
7. Recipients and permissions
Access is restricted to persons and organisations needing information for the relevant purpose: authorised StayClean personnel, account administrators, the customer and provider assigned to a job, technical suppliers, outsourced support, payment providers, advisers, insurers where a claim requires it, and legally competent authorities.
Membership of the provider network does not confer access to all properties or records. Access codes, identity evidence and financial data require specific permissions. Confidentiality commitments, processing agreements and access controls must reflect the activities actually entrusted to each recipient.
8. Hosting and distributed infrastructure
The technical arrangements communicated by StayClean involve several suppliers, including Amazon Web Services (AWS), Vultr, DigitalOcean and Railway, for computing, storage, networking, deployment and application operations, depending on the component. The architecture seeks continuity through distribution, replication, redundancy and recovery capability within the environments actually deployed.
Containerised application layers, load-balancing mechanisms and any content delivery networks do not guarantee absolute availability. International reach does not mean that every record is copied to every continent or that public assets and private databases follow identical routes. Regions, support access and backup destinations must be documented for the relevant processing activity.
9. Transfers outside the European Economic Area
International suppliers may involve processing or access from outside the EEA, including the United States where the configuration or recipient entity so provides. Remote access may constitute a transfer even when primary storage remains in Europe.
Each transfer must use a valid mechanism: an adequacy decision applicable to the recipient and activity, or appropriate safeguards such as standard contractual clauses together with necessary assessments and supplementary measures. Exceptional derogations are not a general authorisation for worldwide replication. Merely using the site does not constitute consent to all transfers. Relevant information about recipients, countries and safeguards may be requested from the stated contact, subject to redactions that do not prevent the exercise of rights.
10. Security and confidentiality
Measures must be proportionate to risk: permission controls, environment separation, secret protection, communications encryption where relevant, logging, updates, backups and incident management. Their design takes account of the sensitivity of property access information, visual evidence and financial data.
Redundancy does not replace backups, access controls or a legal basis. No system excludes every incident. This does not reduce StayClean's statutory security duties. Users must protect their credentials, limit invitations and promptly report suspected compromise.
11. Retention and archiving
Data is retained according to its purpose, demonstrated needs, applicable contractual instructions and legal obligations. The reference schedule under this policy provides for: account information during the relationship followed by selective archiving of necessary evidence; accounting records generally seven years from the end of the relevant financial year where Estonian law requires; prospect records up to three years after the last relevant contact; support cases up to twenty-four months after closure; ordinary security logs up to six months; job evidence up to twelve months; detailed geolocation up to sixty days.
These are reference operational ceilings, not requirements to retain everything. A shorter local period or justified deletion prevails. Extracts needed for a dispute may be isolated until resolution and expiry of the applicable period. Backups scheduled for removal follow a target maximum rotation cycle of ninety days; restoration must reapply relevant deletions. Records maintained by a financial provider are also subject to its own obligations.
12. Automation, artificial intelligence and profiles
Features may analyse instructions, evidence, timings, incidents or messages to suggest assignments, summaries, alerts and quality assessments. Outputs depend on available information and may be inaccurate. Relevant criteria may include availability, service area, job requirements, punctuality and documented compliance.
An automated assistant must be identified and its involvement usefully explained in the relevant process. A solely automated decision producing legal or similarly significant effects on an individual may be implemented only where authorised by law. Required safeguards include, as applicable, meaningful human intervention, an opportunity to express a view and a challenge procedure. A score or alert is not conclusive proof of misconduct.
13. Images, sensitive information and model training
Evidence must focus on what is necessary for the job. Faces, children, identity documents, health information, correspondence and objects unnecessarily revealing private life should be avoided. Excessive content must be capable of restriction, correction or deletion, subject to a lawful retention reason.
The platform is not intended to receive special-category data without necessity and a specific legal condition. A technical content licence does not, by itself, authorise general-purpose model training. Such reuse requires a separate purpose assessment, appropriate information, a legal basis and the necessary commitments from the providers involved.
14. Geolocation, QR and NFC
Location may support navigation, arrival confirmation, assistance or investigation of an incident where these features are enabled and legally justified. Accuracy, recipients and collection periods must be proportionate. QR and NFC scans also create job-related events and do not automatically establish that every task has been completed.
Tracking must not become continuous surveillance outside justified operational periods. A device permission does not replace the legal basis. Consent may be unsuitable in a relationship of dependency; the relevant controller must assess less intrusive alternatives, inform professionals and comply with applicable local employment rules.
15. Integrations and shared reports
Connections to a property management system, calendar, lock, communication tool or other third-party service are limited to necessary permissions. The account holder must be able to revoke a connection; revocation does not automatically erase information already lawfully retained by each party.
Before sharing a report through a link accessible to others, the user must check its scope. Access credentials, detailed routes, identity documents and financial data are not intended for public disclosure. Recipients may forward or copy a link; available restriction and revocation mechanisms should be used.
16. Communications and marketing
Messages necessary for a job, security, invoicing or the contract are separate from marketing. Enabled channels may include email, notifications and other methods offered within the account.
Marketing follows the rules of the relevant country and requires prior consent where applicable. Individuals may object without charge through the indicated mechanism or this policy's contact. A minimal suppression record may be retained to avoid contacting someone who has opted out again.
17. Individual rights
Subject to statutory conditions, you may request access, correction, erasure, restriction and portability of your data and object to certain processing. Consent may be withdrawn at any time without affecting the lawfulness of earlier processing. Objections to direct marketing must be respected.
Not every right is absolute: a retention duty or defence of a legal claim may justify limited continued storage. A reasoned response must explain any refusal and available remedies. Where StayClean acts as processor, it forwards or assists the request with the relevant controller without obstructing its exercise.
18. Requests and response periods
Write to william.rudent@stayclean.io identifying the account and request. Additional identity evidence is requested only where there is reasonable doubt and only proportionately; do not send a complete sensitive identity document without being asked.
A response is provided without undue delay and normally within one month of receipt. An extension of two further months may be necessary because of complexity or the number of requests, with reasons communicated within the first month. Exercise is normally free, subject only to statutory exceptions, including manifestly unfounded or excessive requests.
19. Authorities and remedies
You may complain to a competent data protection authority, including that of your habitual residence, workplace or the location of the alleged infringement. In Estonia: Andmekaitse Inspektsioon (AKI), Tatari 39, 10134 Tallinn; info@aki.ee; official website aki.ee.
An Estonian registered office does not require you to waive access to another competent authority, court proceedings or legally available compensation. Lead supervisory authority competence depends on GDPR criteria, not merely the registered address.
20. Personal data breaches
Where an incident may affect personal data, StayClean must assess its nature, scope and risks, contain its effects and document the response. Notifications to controllers, authorities and affected people are made under statutory conditions and deadlines, including the seventy-two-hour period applicable to certain authority notifications following awareness.
Security considerations may temporarily limit disclosure of technical details but do not permit withholding information legally owed to affected individuals.
21. Children and tracking technologies
Operational accounts are intended for adults with the necessary legal capacity. Anyone registering team members must verify their authority. Information about children incidentally present at a property must not be collected without necessity and appropriate safeguards.
Cookies, local storage, SDKs and similar technologies are addressed separately in the cookie policy. Accepting commercial terms does not constitute acceptance of optional tracking.
22. Changes and legal interaction
This policy is reviewed when services, purposes, recipients or safeguards change. Material changes require appropriate notice and, where necessary, fresh consent before the relevant processing. They cannot retrospectively legalise unlawful collection.
Estonian law and applicable European legislation provide the reference framework without excluding mandatory territorial rules. This notice operates alongside the terms of use, terms of sale, cookie policy and processing agreements without restricting statutory rights.