Privacy Policy · Roomzor
Effective: 2026-10-06 · Last updated: 2026-10-06 · English
1. Controller and contact
Operator and data controller: Roomzor; legal form: KB Sole Trader — TODO_LEGAL_CONFIG: confirm proprietor and registered legal form; registered address: TODO_LEGAL_CONFIG: full registered address (Hungary, EU supplied); tax number: 888 88 88 — TODO_LEGAL_CONFIG: verify supplied test value; registration number: 666 66 66 — TODO_LEGAL_CONFIG: verify supplied test value; registering authority: Hungary, RA — TODO_LEGAL_CONFIG: identify registering authority. Contact: support@roomzor.com. DPO: TODO_LEGAL_CONFIG: confirm whether a DPO is appointed.
Entries marked TODO_LEGAL_CONFIG await operator confirmation. This document describes the current test installation and features that may be enabled later.
2. Sources and roles
You provide account details and project content. Workspace owners and colleagues may provide invitations, contractor details, comments or project information about you. The application generates authentication, activity and security records. We provide this notice for both direct and indirect collection; invited people receive a link to this notice before joining.
For account administration and platform security the operator acts as controller. For personal information a business customer places in private project content, the parties must document their controller/processor roles and, where applicable, an Article 28 processing agreement. TODO_LEGAL_CONFIG: finalize the customer processing agreement before business production use.
3. Processing purposes and retention
Accounts and authentication
| Data | Purpose | Legal basis | Retention | Recipients |
|---|---|---|---|---|
| E-mail, display name, password hash, account ID, confirmation/reset tokens, login timestamps and lockout state | Create and secure your account; password recovery | Performance of the user contract; legitimate interest in preventing abuse | Until account closure, then deletion normally within 14 days, subject to lawful exceptions | Operator; configured transactional mail provider |
Projects, teams and client portal
| Data | Purpose | Legal basis | Retention | Recipients |
|---|---|---|---|---|
| Plans, project address, uploaded documents/photos/GLB models, team membership, invitations, comments, guest names, approvals, tasks, notifications and shared links | Provide planning, storage, collaboration, exports, rendering and explicitly requested sharing | Performance of the user contract; where a business customer supplies third-party data, processing on its documented instructions | Account/workspace lifecycle; archived projects are deleted automatically 7 days after archiving; expired/revoked shares 30 days; exports are not stored (they are made when you ask and downloaded at once); the short note that an export was made 1 day; optional render pictures according to admin retention | Operator; invited workspace members; anyone you give a valid share/portal link and password |
Security and operational records
| Data | Purpose | Legal basis | Retention | Recipients |
|---|---|---|---|---|
| Account/workspace IDs, IP address, user agent, actions, request path, correlation ID, error type/message and restricted stack traces | Prevent abuse, investigate failures and establish accountability | Legitimate interests in secure operation and resolving disputes; interests balanced against limited retention and access | Security/audit events 180 days; application/error/mail-file records 30 days; completed jobs 90 days | Restricted platform administrators; local hosting |
Contract acceptance
| Data | Purpose | Legal basis | Retention | Recipients |
|---|---|---|---|---|
| User ID, terms version, privacy notice version, effective date and server acceptance timestamp; creator agreements separately may include a network hash | Record the terms you actively accepted | Performance of the user contract; legitimate interest in proving contractual terms | Contract lifecycle plus applicable limitation/recordkeeping period; TODO_LEGAL_CONFIG: confirm exact post-contract evidence period | Operator; authorities/courts where lawfully required |
Support and rights requests
| Data | Purpose | Legal basis | Retention | Recipients |
|---|---|---|---|---|
| Contact details, message, account identifier, necessary verification and correspondence | Answer support requests, complaints and privacy requests | Contract performance; legal obligation for statutory requests; legitimate interest in handling correspondence | 1 year after support closure; legal holds only where necessary | Operator; TODO_LEGAL_CONFIG: support mailbox operator and contract |
Payments and subscriptions, when enabled
| Data | Purpose | Legal basis | Retention | Recipients |
|---|---|---|---|---|
| Workspace/user ID, e-mail, order lines/amount/currency, subscription and Stripe customer/session/payment references; creator payout details if enabled | Collect payment, deliver purchases, manage renewals/refunds and keep required records | Contract performance and applicable tax/accounting obligations | Applicable statutory accounting period; payment webhook payloads have separate admin retention; TODO_LEGAL_CONFIG: confirm records and period | Stripe when configured; operator; tax authorities where required |
Optional Google Analytics and Google Ads
| Data | Purpose | Legal basis | Retention | Recipients |
|---|---|---|---|---|
| Only consented categories: browser/cookie identifiers, public page location, device/network data and interaction data | Measure public-page visits or advertising effectiveness | Your prior, freely chosen consent | Roomzor choice 180 days; analytics cookies configured to 180 days; Ads identifiers generally up to 90 days; provider account retention must be confirmed before enablement | Google only when a valid ID is configured, installation is production and you enable the corresponding category |
Optional integrations and marketplace
| Data | Purpose | Legal basis | Retention | Recipients |
|---|---|---|---|---|
| Creator identity/business/contact details, legal acceptances, listings, moderation reports/appeals, encrypted payout bank details; API-key hashes, webhook endpoints/delivery metadata; admin image-to-3D source images | Provide the optional feature requested by a workspace or administrator | Contract performance; legitimate interest in moderation/security; legal obligations where relevant | Feature-specific lifecycle; staging/webhook/API records use configured maintenance periods; TODO_LEGAL_CONFIG: payout and moderation retention | Workspace recipients; configured webhook recipients; Stripe Connect or Meshy only if separately enabled |
Retention periods above are the configured deployment targets and operational rules. Account closure and support cleanup are handled through the documented manual process. Shared material may belong to another workspace and must be reviewed for that workspace’s rights. Mandatory financial records and narrowly scoped legal holds may survive closure. Backups rotate for 30 days; deleted data is not put back into active use during recovery.
4. Hosting and service providers
Hosting: Local Linux test server; OVH EU is the stated production hosting provider (contract and region to be confirmed). The current database is PostgreSQL, storage is local disk and transactional e-mail is written to restricted local files. There is no configured public CDN, remote font service, social login or separate external error monitor in this installation. Inter fonts and 3D libraries are served locally.
Stripe, Stripe Connect, Google Analytics, Google Ads, Meshy, SMTP and S3 adapters are optional features, not evidence that those providers receive data now. Before enabling one, the operator must confirm its contracting entity, processing agreement, regions, subprocessors and retention. Customer-selected signed webhook receivers receive only the configured event payloads. Product links take you to an independent website when you choose to open them.
5. International transfers
The local test installation processes application data on the operator’s Linux server. The stated production host is OVH in the EU; the exact legal entity and location remain to be confirmed. We do not promise that all optional providers process data only in the EEA. Google, Stripe or Meshy may involve processing outside the EEA if enabled.
TODO_LEGAL_CONFIG: document each destination, recipient, current adequacy decision where applicable, or standard contractual clauses and supplementary safeguards before enabling transfers. Contact support@roomzor.com to request information about applicable safeguards. Optional trackers remain disabled on this test installation.
6. Your rights and requests
You may request access, correction, erasure, restriction, portability and, where applicable, object to processing based on legitimate interests. You may withdraw optional cookie consent at any time using Cookie settings; withdrawal does not affect earlier lawful processing. We may retain only information for which an exception lawfully applies.
Use Account settings to correct your display name and download the account export. The export covers the listed account information; request the complete access or portability package, an e-mail correction, account closure or other rights at support@roomzor.com. We verify identity using proportionate evidence, normally the account e-mail. We respond within one month; any lawful extension and its reason will be communicated within that month. No fee is charged unless legally permitted.
7. Complaints and judicial remedies
You may complain to the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), 1055 Budapest, Falk Miksa utca 9–11.; postal address: 1363 Budapest, Pf. 9.; official contact and submission information. Follow the authority’s current submission channels. You may also complain to the supervisory authority in your habitual residence, workplace or place of the alleged infringement, and seek a judicial remedy.
8. Security, children and automated decisions
Implemented measures include HTTPS on the test reverse proxy, ASP.NET Core Identity password hashing and login lockout, protected authentication tokens, CSRF protection, server-side authorization and workspace access filters, rate limits, restrictive browser headers and restricted administrative access. Backups and log cleanup are operational tasks. These measures do not amount to a guarantee against every incident.
Roomzor is not directed at minors. Do not upload unnecessary sensitive information or personal documents. We do not use the current installation for decisions about individuals producing legal or similarly significant effects. Plan entitlement checks and moderation assist service operation; a person may review disputed restrictions through support. Optional image-to-3D generation produces design assets, not decisions about people.
9. Changes and contact
Material changes are notified in the application or by transactional e-mail. Updated terms require active acceptance before purchases. Privacy notices explain processing and are not bundled with marketing consent. Contact support@roomzor.com for any question about this notice.