Data processing agreement
Processing your bookers' data
When people book your rooms and desks, you decide what happens with their details; we store and handle them for you, only as needed to run Booking. This agreement (GDPR Article 28) is part of our terms of service.
Last updated 6 October 2026
Parties
- Controller: the organisation that uses FloorKite ("you").
- Processor: Zumrut Labs, Business ID [Y-tunnus], Helsinki, Finland ("we"). Contact: [privacy e-mail address].
The agreement applies for as long as we process personal data for you, and ends when that data has been deleted or returned.
What is processed
- Whose data: people who book or request your spaces, and people who ask for a link to their bookings.
- Which data: name, email address, phone number (if given), what was booked and when, number of people, purpose and notes, cancellation reasons, payment status and amounts (no card details – those stay with Stripe), and technical data such as IP addresses in short-lived logs.
- Why: to take, show and answer bookings and requests, prevent double bookings, send confirmations, handle payments and refunds, and keep the service secure.
- How long: bookings are deleted automatically 24 months after they end; you can delete them sooner. Other data as described in the privacy notice.
No special categories of personal data are needed. Please don't ask people to write such data (for example about health) in the purpose or note fields.
Our commitments
- We process the data only on your documented instructions – which are these terms, your settings in FloorKite and what you do in it – unless the law requires otherwise; then we tell you first, where allowed.
- Everyone at our end with access to the data is bound to confidentiality.
- We don't use your bookers' data for our own purposes, don't sell it and don't use it for advertising.
- We tell you if we think an instruction breaks data protection law.
Security
- All traffic is encrypted (HTTPS); data is stored encrypted at rest by our hosting provider.
- Logins use one-time links; only hashes of login links, sessions and invitations are stored.
- Each organisation's data is kept apart; only your team can see your bookings. Other visitors only ever see that a time is taken.
- Links that give access to a booking are signed and can't be guessed; links to someone's list of bookings expire after 7 days.
- Public forms are protected against abuse with rate limits and a bot check; pages are served with strict security headers.
- Backups are kept by our hosting provider; old data is deleted on schedule.
Subprocessors
You allow us to use these providers. We bind each of them to data protection obligations at least as strict as ours, and stay responsible for them.
- Cloudflare, Inc. – hosting, database, file storage, bot check. Data stored in the EU.
- Resend – sending emails (confirmations, links).
- Stripe Payments Europe, Ltd. – payments, when you take them. For card data Stripe acts as its own controller under its own terms.
- Anthropic, PBC – only if you use "Draft rooms with AI": the floor plan image you upload is sent for analysis. It shouldn't contain personal data.
We'll tell you at least 30 days before adding or replacing a subprocessor. If you object for a good reason and we can't find a solution, you may end the service and get back fees paid in advance for the remaining time.
Transfers outside the EU
Where a subprocessor handles data outside the EU/EEA, the transfer is protected with the safeguards the GDPR requires – the EU–US Data Privacy Framework where the provider is certified, otherwise the European Commission's standard contractual clauses.
Helping you
- People's rights: if someone asks us about their data from your bookings, we pass the request to you. FloorKite lets you find, export (CSV) and delete bookings; we help with anything beyond that.
- Assessments and authorities: we give you the information you reasonably need for data protection impact assessments and contacts with the supervisory authority.
- Audits: we answer reasonable questions about how we protect data, and allow audits by you or an auditor you choose, with reasonable notice and at your cost, once a year at most unless there's been a breach.
Personal data breaches
If we become aware of a breach affecting your data, we tell you without undue delay and within 48 hours, with what we know: what happened, which data and people are likely affected, the likely consequences, and what we're doing about it. We help you with notifying the authority and the people concerned.
At the end
When you stop using FloorKite, you can download your bookings for 30 days. After that we delete the personal data we hold for you, including copies, within 90 days from backups – unless the law requires us to keep something, in which case we keep it safe and only for that.