Last updated: 2 October 2026
Privacy policy
Stay OS is supplied by Stay Management AS, organisation number 936 174 832. When a customer uses the service, that customer is normally the controller for rental, employment and property operations. Stay Management AS processes that data on the customer’s instructions as processor. Stay Management AS is controller for its own customer relationships, account administration and service security. When Stay Management AS is itself the landlord or employer, it is also responsible for that processing.
What we collect
- Tenants
- Names and contact details, home and tenancy, household participants, messages, reported problems, photos, deliberately recorded voice notes, visit arrangements, entry permissions, feedback, signed documents and payment information where that service is used.
- Property managers
- Names, email, phone, organisation, role and permissions, sign-in activity, actions, decisions, notes and communications.
- Workers
- Names, contact details, language, employer affiliation, assignments, work time, visit outcomes, expenses, photos, deliberately recorded voice notes and access events. The location trail defaults off. If enabled after written worker consultation, it records a location or unavailable-location outcome every ten minutes while the page is visible during 07–18 Oslo time, outside breaks.
- Vendors
- Company and representative details, organisation numbers, trades and qualification documents, identity and signing status, offer responses, estimates, work, invoices and correspondence.
- Owners
- Contact and company details, ownership relationships, approvals, reports, contracts and invoices. National identity numbers are collected through a separate secure identity process when a selected service requires them.
- Applicants
- Contact details, application answers, preferences, messages, documents, viewing appointments and assessments derived for follow-up. Identity verification, credit information and signing evidence are processed through their relevant workflows. Deliberately recorded voice and transcripts may be retained with the application.
Data comes from you, customer staff, other authorised participants and connected services. Uploads may contain metadata such as time and GPS location. National identity numbers, credit information and data revealing health or other special categories need separate grounds and restricted access. Avoid unnecessary sensitive information in free text or images.
Purposes and legal bases
Data is used for applications and leases, communication, maintenance, planning, evidence, billing inputs and secure operations. The customer determines the basis for its processing. Applicable bases include contract or pre-contract steps (GDPR Article 6(1)(b)), legal obligation (c), legitimate interests in property operations and security following a balancing assessment (f), and consent where the workflow requires it (a). Contract grounds apply only where the data subject is party to the contract. Worker data and monitoring need a separate assessment; an employer cannot simply rely on consent for monitoring.
Models and audio
Selected text, images and audio may be sent to model and speech services for drafts, translation, reading images and receipts, transcription and application assessments. Identifiable data may be included; there is no general anonymisation before these calls. Model outputs can be wrong. The maintenance agent prepares proposals for staff review. Applicant scores and recommendations support follow-up; you can request human review and contest the result. Maintenance calls are not recorded. Leads and Communications telephone calls may be recorded when enabled: the PM must acknowledge call authority and that the recipient will receive the required recording notice before the conversation. This is the PM acknowledgement, not a captured recipient consent. Video viewings may be recorded and transcribed after the participant consent choice; participants can join without recording. The host waits for that choice or joins without recording. Voice notes you deliberately choose to record are a separate action.
Recipients and storage
Data is shared with authorised customer managers and with tenants, workers, vendors and owners within the case or agreement they may access. The service providers below may process data when the relevant feature is configured. Regions and transfer grounds must be confirmed in deployment settings and provider agreements; the code alone does not establish that all processing stays in the EEA. The list is not evidence of signed agreements.
Vercel
- Purpose
- Hosting and temporary import storage
- Data
- Requests, IP addresses, sessions, operational logs and uploaded import files
- Location
- Region is account and deployment dependent. Not established by code; confirmation required.
- Transfer basis
- Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
- When used
- When the platform is deployed with this provider.
Neon
- Purpose
- PostgreSQL database
- Data
- Database contacts, applications, tenancies, cases, messages and operational evidence
- Location
- Region is account and deployment dependent. Not established by code; confirmation required.
- Transfer basis
- Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
- When used
- When the platform is deployed with this provider.
Cloudflare R2
- Purpose
- Private object storage
- Data
- Documents, photos, metadata, audio and derivatives
- Location
- Region is account and deployment dependent. Not established by code; confirmation required.
- Transfer basis
- Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
- When used
- When the platform is deployed with this provider.
OpenRouter
- Purpose
- Model routing for drafts, translation and evidence reading
- Data
- Selected text, images and document content that may contain personal data
- Location
- Region is account and deployment dependent. Not established by code; confirmation required.
- Transfer basis
- Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
- When used
- Only when the integration or relevant feature is configured and used.
Anthropic, OpenAI, Google, xAI, DeepSeek, Mistral
- Purpose
- Models selected through OpenRouter
- Data
- The selected content in the model call; the actual inference route needs confirmation
- Location
- Region is account and deployment dependent. Not established by code; confirmation required.
- Transfer basis
- Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
- When used
- Through the selected model route in OpenRouter. Model and actual inference provider may change; confirm the allowed route before use.
LINK Mobility
- Purpose
- Inbound and outbound SMS
- Data
- Phone numbers, message content, links and delivery metadata
- Location
- Region is account and deployment dependent. Not established by code; confirmation required.
- Transfer basis
- Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
- When used
- Only when the integration or relevant feature is configured and used.
Resend
- Purpose
- Inbound and outbound email
- Data
- Email addresses, messages, links, attachments and delivery metadata
- Location
- Region is account and deployment dependent. Not established by code; confirmation required.
- Transfer basis
- Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
- When used
- Only when the integration or relevant feature is configured and used.
Zadarma
- Purpose
- Telephony and call connection
- Data
- Phone numbers, extensions, call timing and status. Maintenance calls are not recorded. Enabled Leads and Communications calls may be recorded with PM acknowledgement of call authority and the required recipient notice; recordings enter private custody
- Location
- Region is account and deployment dependent. Not established by code; confirmation required.
- Transfer basis
- Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
- When used
- Only when the integration or relevant feature is configured and used.
ElevenLabs
- Purpose
- Speech to text and deliberate voice notes
- Data
- Audio, transcripts, language and metadata
- Location
- Speech transcription can use an EU endpoint after EU contract confirmation. Other audio paths use the standard endpoint. Confirm region per feature.
- Transfer basis
- Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
- When used
- Only when the integration or relevant feature is configured and used.
Idura
- Purpose
- BankID and document signing
- Data
- Identity and signature details, contracts and signing evidence
- Location
- Region is account and deployment dependent. Not established by code; confirmation required.
- Transfer basis
- Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
- When used
- Only when the integration or relevant feature is configured and used.
Keyhole
- Purpose
- Tenancy security and related identity workflow
- Data
- Contact and identity details, lease and security or claim data
- Location
- Region is account and deployment dependent. Not established by code; confirmation required.
- Transfer basis
- Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
- When used
- Only when the integration or relevant feature is configured and used.
Sentry
- Purpose
- Error monitoring
- Data
- Errors, stack traces and filtered technical request metadata
- Location
- Region is account and deployment dependent. Not established by code; confirmation required.
- Transfer basis
- Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
- When used
- Only when the integration or relevant feature is configured and used.
Daily
- Purpose
- Video viewings
- Data
- Participant names, viewing metadata and audio/video. Video viewings may be recorded and transcribed after the participant consent choice; the participant and host can join without recording
- Location
- Region is account and deployment dependent. Not established by code; confirmation required.
- Transfer basis
- Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
- When used
- Only when the integration or relevant feature is configured and used.
Google Workspace / Google OAuth
- Purpose
- Optional sign-in, calendar and Meet imports
- Data
- Account identity, OAuth access, appointment metadata and selected meeting transcripts
- Location
- Region is account and deployment dependent. Not established by code; confirmation required.
- Transfer basis
- Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
- When used
- Only when the integration or relevant feature is configured and used.
Upstash / Vercel KV
- Purpose
- Optional rate limiting
- Data
- Derived client or IP keys, counters and expiry times
- Location
- Region is account and deployment dependent. Not established by code; confirmation required.
- Transfer basis
- Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
- When used
- Only when the integration or relevant feature is configured and used.
Dun & Bradstreet / Bisnode
- Purpose
- Credit assessment
- Data
- Identity, national identity number and credit information when the credit workflow is used
- Location
- Region is account and deployment dependent. Not established by code; confirmation required.
- Transfer basis
- Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
- When used
- Only when the integration or relevant feature is configured and used.
Parallel
- Purpose
- Property and market research
- Data
- Address and search context and publicly available listing information
- Location
- Region is account and deployment dependent. Not established by code; confirmation required.
- Transfer basis
- Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
- When used
- Only when the integration or relevant feature is configured and used.
OpenStreetMap / Nominatim / Overpass
- Purpose
- Address lookup and maps
- Data
- Search text, addresses, map coordinates and technical browser metadata when using maps
- Location
- Region is account and deployment dependent. Not established by code; confirmation required.
- Transfer basis
- Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
- When used
- Only when the integration or relevant feature is configured and used.
Brønnøysundregistrene, Kartverket / Geonorge, Entur, SSB
- Purpose
- Public company, address, transport and market lookups
- Data
- Organisation numbers, addresses, coordinates and bounded query context
- Location
- Region is account and deployment dependent. Not established by code; confirmation required.
- Transfer basis
- Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
- When used
- Only when the integration or relevant feature is configured and used.
DuckDuckGo
- Purpose
- Product and address information lookup
- Data
- Product descriptions, addresses or search text
- Location
- Region is account and deployment dependent. Not established by code; confirmation required.
- Transfer basis
- Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
- When used
- Only when the integration or relevant feature is configured and used.
Security
The service uses organisation and role access controls, scoped revocable links, access logs and encryption for selected protected fields. It does not encrypt every message or property field at application level. Provider storage encryption and backups must be confirmed in operational agreements.
Retention
This table describes current code, not a promise of deletion. Several data families have no automatic deletion deadline. Where a job is disabled or enforcement is missing, data remains pending authorised review. The customer must agree necessary periods and exit handling before processing external customer data.
- Cases and reports
- Raw tenant reports: a 365-day review and redaction rule. Normalised case facts, decisions and work history have no fixed deletion deadline. Execution needs explicit activation and approved scope.
- Messages and SMS
- Case, job and household conversations have no general age limit. Some raw message families have a 365-day review period. Outbound SMS text has no universal deletion job. Temporary encrypted inbound SMS: 24 hours; inbox metadata: 90 days; this does not delete the canonical conversation.
- Photos and voice notes
- Stored originals, derivatives and confirmed voice notes have no automatic deletion deadline. Work evidence has a 365-day review horizon that does not delete files.
- Call recordings
- Maintenance calls are not recorded. Recordings from enabled Leads and Communications calls and consented video viewings, along with earlier Maintenance recordings, transcripts and private copies, have no general automatic deletion deadline. Deleting a provider copy does not delete the private original.
- Location trail
- Off by default. If enabled, points remain readable for 90 days from the working day’s start. An hourly job removes expired days and points. Policies and receipts without coordinates remain. Deployed execution needs verification.
- Applicant data
- Applications and recognition profiles have different policies. Seasonal archives have a 180-day raw-data grace period before scoped masking; manually hidden applications remain recoverable. Other raw-data rules vary with consent and category. There is no documented universal deletion of all applicant data.
- Logs and audit evidence
- Some evidence has a 730-day policy, but no universal deadline is enforced for all logs. Provider log retention needs confirmation.
- Backups
- The code does not establish a common backup period or automatic backup deletion. Provider settings, restoration and copy expiry need confirmation; deletion from primary storage is not a promise of immediate deletion from backups.
Cookies and local storage
Sign-in and private workflows use necessary session cookies. Language and some display preferences are saved in browser storage. Sentry may receive errors and technical metadata when configured; client session replay and performance tracing are disabled in the current configuration. You can clear browser storage and cookies; that may sign you out and does not erase server records.
Your rights
You may request access, correction, erasure, restriction, portability where applicable, and object to processing based on legitimate interests. You may withdraw consent for future use and request human review of model-assisted assessments. Contact the customer controller first, or contact us so we can route the request to the right controller. We verify identity and scope before disclosure or erasure. Requests are normally handled within one month; lawful extensions are explained. You may complain to Datatilsynet.
The form below accepts applicant access and erasure requests for internal review. For other roles or rights, use the contact link. Access and export for all roles are not fully self-service. Legal documents and necessary security evidence may need retention or restriction rather than erasure.
DatatilsynetContact
State the organisation and which right the request concerns. Do not email national identity numbers, access codes or other secrets. Contact
Rights request
Request access or erasure as an applicant
We store the request for internal review. We verify identity and which data actually exists before sharing or deleting anything.