GDPR & data processing
Privacy and data security come first at Hospi Housing. Here's how we handle personal data within our partnerships.
GDPR compliance
All data processing by Hospi Housing complies with the General Data Protection Regulation (GDPR). This means:
- we only process data that's genuinely necessary for the purpose
- data subjects are informed about the processing
- data is stored securely
- we don't keep data longer than necessary
- data subjects can exercise their rights (access, correction, deletion)
Data processing agreement
For every partnership, we sign a data processing agreement. This documents:
- which personal data is processed
- for what purpose
- how the data is secured
- how long it's retained
- what happens in the event of a data breach
What data do we process?
Within a partnership, we process:
- Host data: name, contact details, address, room information
- Tenant data: name, contact details, profile, preferences
- Match data: which hosts and tenants are paired together
Anonymised data (for reports) cannot be traced back to individuals.
Data breaches
In the unlikely event of a data breach, we follow our breach protocol:
- Immediate notification to the affected partner
- Notification to the Data Protection Authority (if required)
- Informing affected individuals
- Taking measures to prevent recurrence