Last updated: 2 October 2026

Privacy policy

Stay OS is supplied by Stay Management AS, organisation number 936 174 832. When a customer uses the service, that customer is normally the controller for rental, employment and property operations. Stay Management AS processes that data on the customer’s instructions as processor. Stay Management AS is controller for its own customer relationships, account administration and service security. When Stay Management AS is itself the landlord or employer, it is also responsible for that processing.

What we collect

Tenants
Names and contact details, home and tenancy, household participants, messages, reported problems, photos, deliberately recorded voice notes, visit arrangements, entry permissions, feedback, signed documents and payment information where that service is used.
Property managers
Names, email, phone, organisation, role and permissions, sign-in activity, actions, decisions, notes and communications.
Workers
Names, contact details, language, employer affiliation, assignments, work time, visit outcomes, expenses, photos, deliberately recorded voice notes and access events. The location trail defaults off. If enabled after written worker consultation, it records a location or unavailable-location outcome every ten minutes while the page is visible during 07–18 Oslo time, outside breaks.
Vendors
Company and representative details, organisation numbers, trades and qualification documents, identity and signing status, offer responses, estimates, work, invoices and correspondence.
Owners
Contact and company details, ownership relationships, approvals, reports, contracts and invoices. National identity numbers are collected through a separate secure identity process when a selected service requires them.
Applicants
Contact details, application answers, preferences, messages, documents, viewing appointments and assessments derived for follow-up. Identity verification, credit information and signing evidence are processed through their relevant workflows. Deliberately recorded voice and transcripts may be retained with the application.

Data comes from you, customer staff, other authorised participants and connected services. Uploads may contain metadata such as time and GPS location. National identity numbers, credit information and data revealing health or other special categories need separate grounds and restricted access. Avoid unnecessary sensitive information in free text or images.

Purposes and legal bases

Data is used for applications and leases, communication, maintenance, planning, evidence, billing inputs and secure operations. The customer determines the basis for its processing. Applicable bases include contract or pre-contract steps (GDPR Article 6(1)(b)), legal obligation (c), legitimate interests in property operations and security following a balancing assessment (f), and consent where the workflow requires it (a). Contract grounds apply only where the data subject is party to the contract. Worker data and monitoring need a separate assessment; an employer cannot simply rely on consent for monitoring.

Models and audio

Selected text, images and audio may be sent to model and speech services for drafts, translation, reading images and receipts, transcription and application assessments. Identifiable data may be included; there is no general anonymisation before these calls. Model outputs can be wrong. The maintenance agent prepares proposals for staff review. Applicant scores and recommendations support follow-up; you can request human review and contest the result. Maintenance calls are not recorded. Leads and Communications telephone calls may be recorded when enabled: the PM must acknowledge call authority and that the recipient will receive the required recording notice before the conversation. This is the PM acknowledgement, not a captured recipient consent. Video viewings may be recorded and transcribed after the participant consent choice; participants can join without recording. The host waits for that choice or joins without recording. Voice notes you deliberately choose to record are a separate action.

Recipients and storage

Data is shared with authorised customer managers and with tenants, workers, vendors and owners within the case or agreement they may access. The service providers below may process data when the relevant feature is configured. Regions and transfer grounds must be confirmed in deployment settings and provider agreements; the code alone does not establish that all processing stays in the EEA. The list is not evidence of signed agreements.

  • Vercel

    Purpose
    Hosting and temporary import storage
    Data
    Requests, IP addresses, sessions, operational logs and uploaded import files
    Location
    Region is account and deployment dependent. Not established by code; confirmation required.
    Transfer basis
    Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
    When used
    When the platform is deployed with this provider.
  • Neon

    Purpose
    PostgreSQL database
    Data
    Database contacts, applications, tenancies, cases, messages and operational evidence
    Location
    Region is account and deployment dependent. Not established by code; confirmation required.
    Transfer basis
    Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
    When used
    When the platform is deployed with this provider.
  • Cloudflare R2

    Purpose
    Private object storage
    Data
    Documents, photos, metadata, audio and derivatives
    Location
    Region is account and deployment dependent. Not established by code; confirmation required.
    Transfer basis
    Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
    When used
    When the platform is deployed with this provider.
  • OpenRouter

    Purpose
    Model routing for drafts, translation and evidence reading
    Data
    Selected text, images and document content that may contain personal data
    Location
    Region is account and deployment dependent. Not established by code; confirmation required.
    Transfer basis
    Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
    When used
    Only when the integration or relevant feature is configured and used.
  • Anthropic, OpenAI, Google, xAI, DeepSeek, Mistral

    Purpose
    Models selected through OpenRouter
    Data
    The selected content in the model call; the actual inference route needs confirmation
    Location
    Region is account and deployment dependent. Not established by code; confirmation required.
    Transfer basis
    Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
    When used
    Through the selected model route in OpenRouter. Model and actual inference provider may change; confirm the allowed route before use.
  • LINK Mobility

    Purpose
    Inbound and outbound SMS
    Data
    Phone numbers, message content, links and delivery metadata
    Location
    Region is account and deployment dependent. Not established by code; confirmation required.
    Transfer basis
    Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
    When used
    Only when the integration or relevant feature is configured and used.
  • Resend

    Purpose
    Inbound and outbound email
    Data
    Email addresses, messages, links, attachments and delivery metadata
    Location
    Region is account and deployment dependent. Not established by code; confirmation required.
    Transfer basis
    Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
    When used
    Only when the integration or relevant feature is configured and used.
  • Zadarma

    Purpose
    Telephony and call connection
    Data
    Phone numbers, extensions, call timing and status. Maintenance calls are not recorded. Enabled Leads and Communications calls may be recorded with PM acknowledgement of call authority and the required recipient notice; recordings enter private custody
    Location
    Region is account and deployment dependent. Not established by code; confirmation required.
    Transfer basis
    Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
    When used
    Only when the integration or relevant feature is configured and used.
  • ElevenLabs

    Purpose
    Speech to text and deliberate voice notes
    Data
    Audio, transcripts, language and metadata
    Location
    Speech transcription can use an EU endpoint after EU contract confirmation. Other audio paths use the standard endpoint. Confirm region per feature.
    Transfer basis
    Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
    When used
    Only when the integration or relevant feature is configured and used.
  • Idura

    Purpose
    BankID and document signing
    Data
    Identity and signature details, contracts and signing evidence
    Location
    Region is account and deployment dependent. Not established by code; confirmation required.
    Transfer basis
    Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
    When used
    Only when the integration or relevant feature is configured and used.
  • Keyhole

    Purpose
    Tenancy security and related identity workflow
    Data
    Contact and identity details, lease and security or claim data
    Location
    Region is account and deployment dependent. Not established by code; confirmation required.
    Transfer basis
    Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
    When used
    Only when the integration or relevant feature is configured and used.
  • Sentry

    Purpose
    Error monitoring
    Data
    Errors, stack traces and filtered technical request metadata
    Location
    Region is account and deployment dependent. Not established by code; confirmation required.
    Transfer basis
    Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
    When used
    Only when the integration or relevant feature is configured and used.
  • Daily

    Purpose
    Video viewings
    Data
    Participant names, viewing metadata and audio/video. Video viewings may be recorded and transcribed after the participant consent choice; the participant and host can join without recording
    Location
    Region is account and deployment dependent. Not established by code; confirmation required.
    Transfer basis
    Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
    When used
    Only when the integration or relevant feature is configured and used.
  • Google Workspace / Google OAuth

    Purpose
    Optional sign-in, calendar and Meet imports
    Data
    Account identity, OAuth access, appointment metadata and selected meeting transcripts
    Location
    Region is account and deployment dependent. Not established by code; confirmation required.
    Transfer basis
    Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
    When used
    Only when the integration or relevant feature is configured and used.
  • Upstash / Vercel KV

    Purpose
    Optional rate limiting
    Data
    Derived client or IP keys, counters and expiry times
    Location
    Region is account and deployment dependent. Not established by code; confirmation required.
    Transfer basis
    Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
    When used
    Only when the integration or relevant feature is configured and used.
  • Dun & Bradstreet / Bisnode

    Purpose
    Credit assessment
    Data
    Identity, national identity number and credit information when the credit workflow is used
    Location
    Region is account and deployment dependent. Not established by code; confirmation required.
    Transfer basis
    Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
    When used
    Only when the integration or relevant feature is configured and used.
  • Parallel

    Purpose
    Property and market research
    Data
    Address and search context and publicly available listing information
    Location
    Region is account and deployment dependent. Not established by code; confirmation required.
    Transfer basis
    Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
    When used
    Only when the integration or relevant feature is configured and used.
  • OpenStreetMap / Nominatim / Overpass

    Purpose
    Address lookup and maps
    Data
    Search text, addresses, map coordinates and technical browser metadata when using maps
    Location
    Region is account and deployment dependent. Not established by code; confirmation required.
    Transfer basis
    Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
    When used
    Only when the integration or relevant feature is configured and used.
  • Brønnøysundregistrene, Kartverket / Geonorge, Entur, SSB

    Purpose
    Public company, address, transport and market lookups
    Data
    Organisation numbers, addresses, coordinates and bounded query context
    Location
    Region is account and deployment dependent. Not established by code; confirmation required.
    Transfer basis
    Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
    When used
    Only when the integration or relevant feature is configured and used.
  • DuckDuckGo

    Purpose
    Product and address information lookup
    Data
    Product descriptions, addresses or search text
    Location
    Region is account and deployment dependent. Not established by code; confirmation required.
    Transfer basis
    Agreement and actual access need confirmation. Transfers outside the EEA require a valid basis, such as adequacy or separate transfer clauses with necessary supplementary measures. 2021/915 is not a transfer safeguard.
    When used
    Only when the integration or relevant feature is configured and used.

Security

The service uses organisation and role access controls, scoped revocable links, access logs and encryption for selected protected fields. It does not encrypt every message or property field at application level. Provider storage encryption and backups must be confirmed in operational agreements.

Retention

This table describes current code, not a promise of deletion. Several data families have no automatic deletion deadline. Where a job is disabled or enforcement is missing, data remains pending authorised review. The customer must agree necessary periods and exit handling before processing external customer data.

Cases and reports
Raw tenant reports: a 365-day review and redaction rule. Normalised case facts, decisions and work history have no fixed deletion deadline. Execution needs explicit activation and approved scope.
Messages and SMS
Case, job and household conversations have no general age limit. Some raw message families have a 365-day review period. Outbound SMS text has no universal deletion job. Temporary encrypted inbound SMS: 24 hours; inbox metadata: 90 days; this does not delete the canonical conversation.
Photos and voice notes
Stored originals, derivatives and confirmed voice notes have no automatic deletion deadline. Work evidence has a 365-day review horizon that does not delete files.
Call recordings
Maintenance calls are not recorded. Recordings from enabled Leads and Communications calls and consented video viewings, along with earlier Maintenance recordings, transcripts and private copies, have no general automatic deletion deadline. Deleting a provider copy does not delete the private original.
Location trail
Off by default. If enabled, points remain readable for 90 days from the working day’s start. An hourly job removes expired days and points. Policies and receipts without coordinates remain. Deployed execution needs verification.
Applicant data
Applications and recognition profiles have different policies. Seasonal archives have a 180-day raw-data grace period before scoped masking; manually hidden applications remain recoverable. Other raw-data rules vary with consent and category. There is no documented universal deletion of all applicant data.
Logs and audit evidence
Some evidence has a 730-day policy, but no universal deadline is enforced for all logs. Provider log retention needs confirmation.
Backups
The code does not establish a common backup period or automatic backup deletion. Provider settings, restoration and copy expiry need confirmation; deletion from primary storage is not a promise of immediate deletion from backups.

Cookies and local storage

Sign-in and private workflows use necessary session cookies. Language and some display preferences are saved in browser storage. Sentry may receive errors and technical metadata when configured; client session replay and performance tracing are disabled in the current configuration. You can clear browser storage and cookies; that may sign you out and does not erase server records.

Your rights

You may request access, correction, erasure, restriction, portability where applicable, and object to processing based on legitimate interests. You may withdraw consent for future use and request human review of model-assisted assessments. Contact the customer controller first, or contact us so we can route the request to the right controller. We verify identity and scope before disclosure or erasure. Requests are normally handled within one month; lawful extensions are explained. You may complain to Datatilsynet.

The form below accepts applicant access and erasure requests for internal review. For other roles or rights, use the contact link. Access and export for all roles are not fully self-service. Legal documents and necessary security evidence may need retention or restriction rather than erasure.

Datatilsynet

Contact

State the organisation and which right the request concerns. Do not email national identity numbers, access codes or other secrets. Contact

Rights request

Request access or erasure as an applicant

We store the request for internal review. We verify identity and which data actually exists before sharing or deleting anything.

Request type
Contact method