Privacy Policy
StayWise Software — Property Management System
1. Who We Are
Soft Care Concept EOOD operates StayWise Software at staywisesoftwarepms.com. We are a company registered in Bulgaria providing a cloud-based Property Management System (PMS) to hotels and hospitality businesses.
For data protection queries, contact our Data Controller representative at: staywisesoftware@gmail.com
2. What Data We Collect
We collect and process two categories of data:
| Category | Examples | Legal Basis |
|---|---|---|
| Hotel account data | Company name, contact name, email, phone, address | Contract performance |
| Billing data | Subscription plan, payment records (card processing by Stripe — raw card numbers not stored) | Contract + Legal obligation |
| Usage data | Login timestamps, features used, error logs | Legitimate interest |
| Guest data (on behalf of hotel) | Name, email, phone, nationality, ID details, booking info, payment references | Data Processor (hotel is Controller) |
StayWise acts as a Data Processor for guest data. The hotel is the Data Controller responsible for obtaining guest consent under GDPR.
3. Legal Basis for Processing (GDPR Article 6)
- Contract performance — processing your subscription data to deliver the service (Art. 6(1)(b))
- Legal obligation — invoicing and tax records (Art. 6(1)(c))
- Legitimate interests — security logs, abuse prevention (Art. 6(1)(f))
- Consent — analytics cookies, marketing emails (Art. 6(1)(a))
4. How We Use Your Data
- Providing and improving StayWise services
- Sending service emails (invoices, downtime notices, security alerts)
- Customer support
- Legal compliance (tax records, regulatory requirements)
We do NOT sell your data.
We do NOT use hotel guest data for our own marketing purposes.
5. Data Sharing
We share data only with the following sub-processors. All processors are bound by GDPR-compliant Data Processing Agreements.
| Processor | Purpose | Location | Privacy Policy |
|---|---|---|---|
| Supabase | Database infrastructure | EU (Frankfurt) | supabase.com/privacy |
| Stripe | Payment processing | EU/US (SCCs) | stripe.com/privacy |
| Netlify | Hosting infrastructure | EU/US (SCCs) | netlify.com/privacy |
| Email provider | Transactional emails only | EU | — |
We do not share personal data with any other third parties unless required by law or court order.
6. Data Retention
- Active account data: retained while subscription is active
- After cancellation: 30 days available for data export, then permanently deleted
- Invoice and billing records: 5 years (Bulgarian accounting and tax law requirement)
- Backup retention: 30 days rolling
7. Your Rights under GDPR
You have the following rights regarding your personal data:
Access (Art. 15)
Obtain a copy of your personal data we hold.
Rectification (Art. 16)
Correct inaccurate or incomplete data.
Erasure (Art. 17)
"Right to be forgotten" — request deletion.
Restriction (Art. 18)
Limit how we process your data.
Portability (Art. 20)
Receive your data in a machine-readable format.
Object (Art. 21)
Object to processing based on legitimate interests.
You also have the right to lodge a complaint with your local supervisory authority.
To exercise your rights: staywisesoftware@gmail.com
Response time: within 30 days
Bulgarian Supervisory Authority
Комисия за защита на личните данни (КЗЛД)
www.cpdp.bg · kzld@cpdp.bg · +359 2 915 3 518
9. Security
- In transit: all data encrypted using TLS 1.2 or higher
- At rest: database encrypted using AES-256
- Row-level security: each hotel account can only access its own data — enforced at the database level
- Infrastructure: Supabase hosted in EU region (Frankfurt)
- Reviews: regular internal security audits
10. Children
StayWise is a B2B service intended for hotel operators and hospitality businesses. It is not directed at, and we do not knowingly collect personal data from, children under the age of 16.
11. Changes to This Policy
We will notify registered account holders by email at least 30 days before making material changes to this Privacy Policy. Minor clarifications may be made without notice. The "last updated" date at the top of this page reflects the most recent revision.
12. Contact
For any privacy-related questions or requests, please contact us:
For a full list of your rights as a data subject, see gdpr.eu .
© 2026 Soft Care Concept EOOD. All rights reserved.