Privacy policy.
Sabee is operated by Sabee Cloud OU, and this policy explains, in detail, how we collect, use, store, share and protect personal data — both as controller of our own website and commercial contacts, and as processor of guest data uploaded by our customers. Last updated 15 May 2026.
On this page
- 1. Controller identity
- 2. Definitions
- 3. Categories of data we process
- 4. Lawful basis per category
- 5. Purposes of processing
- 6. Retention schedule
- 7. Sub-processors
- 8. International transfers
- 9. Your rights as a data subject
- 10. Automated decision-making
- 11. Cookies
- 12. Children
- 13. Security measures
- 14. Breach notification
- 15. Changes to this policy
- 16. Version and contact
1. Controller identity
Sabee is a trading name of Sabee Cloud OU, a private limited company registered in the Republic of Estonia under registration number 14975208, VAT identifier EE102948371, with its registered office at Rotermanni 8, 10111 Tallinn, Estonia. Throughout this policy, "Sabee", "we", "us" and "our" refer to Sabee Cloud OU. Sabee Cloud OU is the data controller for the categories of personal data described in Section 3 that relate to our own website visitors, prospective customers, current and former customer contacts, suppliers and staff. For guest personal data uploaded by our customers into the Sabee platform, Sabee Cloud OU acts as a data processor, and the customer (the hotel, hostel, aparthotel or multi-property operator) remains the controller. Our supervisory authority is the Andmekaitse Inspektsioon, the Estonian Data Protection Inspectorate, reachable at aki.ee. Nothing in this policy limits the rights you have under the General Data Protection Regulation (EU) 2016/679 ("GDPR") or the Estonian Personal Data Protection Act.
2. Definitions
"Personal data" means any information relating to an identified or identifiable natural person. "Processing" means any operation performed on personal data, including collection, storage, use, disclosure, and deletion. "Controller" means the entity that determines the purposes and means of processing. "Processor" means the entity that processes personal data on behalf of a controller. "Sub-processor" means a further processor engaged by Sabee to assist in delivering the platform. "Customer" means the legal entity that has subscribed to the Sabee platform. "Guest data" means personal data about the customer's own guests, uploaded to or generated within the platform by the customer. "Telemetry" means technical usage and diagnostic data generated automatically by software. "Platform" means the Sabee hotel and hostel management application and all associated services, dashboards, APIs and integrations. These definitions apply consistently across this policy and cross-referenced documents including the Data Processing Addendum and the cookie policy.
3. Categories of data we process
We process several distinct categories of personal data, each with different sources, retention rules and legal treatment. The table below summarises the categories relevant to Sabee's operation of the marketing site and the platform.
| Category | Examples | Source | Role Sabee plays |
|---|---|---|---|
| Account data | Name, work email, role, company, password hash | Provided directly by the user at sign-up or onboarding | Controller |
| Billing data | Billing contact, VAT number, invoice address, payment method token | Provided by the customer; payment tokens generated by our payment processor | Controller |
| Telemetry data | Device type, browser version, feature usage counts, error logs, session duration | Generated automatically by the platform and marketing site | Controller (aggregated), Processor (where tied to guest identity) |
| Cookies and similar technologies | Session identifiers, CSRF tokens, locale and theme preferences | Set by the browser on visit or login | Controller |
| Guest data uploaded by the customer | Guest name, contact details, ID/passport numbers, stay history, preferences, payment tokens | Entered or imported by the customer, or synced from OTAs and channel managers | Processor |
| PMS operational data | Rates, availability, housekeeping tasks, folios, reports, internal notes | Generated by the customer's use of the platform | Processor (where it contains identifiable staff or guest information) |
Where Sabee acts as processor for guest data and PMS operational data, our processing is governed exclusively by the customer's documented instructions and by the Data Processing Addendum, not by this policy's controller-facing provisions.
4. Lawful basis per category
Under GDPR Article 6, each category of processing we carry out as controller relies on one or more of the following lawful bases:
- Performance of a contract (Art 6(1)(b)) — account data and billing data, processed to create your account, deliver the subscription you selected, and issue invoices.
- Legitimate interests (Art 6(1)(f)) — telemetry data, processed to keep the platform secure, diagnose faults, and improve reliability; also used for aggregated product analytics, always balanced against your right to privacy.
- Legal obligation (Art 6(1)(c)) — billing records retained for statutory accounting and tax purposes, and any data we are required to disclose to a competent authority.
- Consent (Art 6(1)(a)) — marketing communications where consent is the applicable basis, and any non-essential cookie category should one ever be introduced. Consent can be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.
For guest data and PMS operational data processed as processor, the lawful basis is determined by the customer as controller; Sabee's role is limited to processing under instruction, and we do not independently select a lawful basis for that category.
5. Purposes of processing
We process personal data for the following purposes: (a) service provision — operating the platform, authenticating users, and delivering the features included in the customer's subscription; (b) security — detecting and preventing fraud, abuse, intrusion attempts and unauthorised access; (c) billing — generating invoices, processing payments, and reconciling accounts through our payment processor; (d) compliance — meeting our statutory obligations under Estonian and EU law, including accounting retention and responses to lawful requests from authorities; (e) product analytics — understanding aggregated usage patterns to prioritise engineering work, always on an aggregated or pseudonymised basis wherever the purpose permits; and (f) communications — responding to support requests, sending service notices, and, where you have consented, sending product updates and marketing content. We do not process personal data for any purpose incompatible with the purpose for which it was originally collected, and we do not use guest data uploaded by customers for our own marketing or analytics purposes under any circumstances.
6. Retention schedule
We retain personal data only for as long as necessary for the purposes described above, or as required by law. The table below sets out our standard retention periods.
| Data category | Retention period | Basis for period |
|---|---|---|
| Website analytics (aggregated) | 26 months | Legitimate interest in trend analysis |
| Sales enquiries and unconverted leads | 24 months after last contact | Legitimate interest in following up |
| Account data (active customers) | Duration of subscription | Contractual necessity |
| Billing and accounting records | Contract term plus 7 years | Estonian Accounting Act statutory minimum |
| Telemetry and application logs | 90 days raw, 13 months aggregated | Security investigation window, then anonymised trend data |
| Support tickets | 36 months after closure | Legitimate interest in service history |
| Marketing consent records | Duration of consent plus 2 years | Evidentiary requirement for consent proof |
| Guest data (processor role) | As instructed by the customer; deleted within 30 days of contract termination | Data Processing Addendum |
7. Sub-processors
To deliver Sabee reliably, we engage a limited number of specialist sub-processors, each bound by a data processing agreement consistent with GDPR Article 28. The current list is:
| Sub-processor | Function | Location |
|---|---|---|
| AWS (Amazon Web Services), Frankfurt region | Primary infrastructure hosting | European Union |
| Cloudflare | CDN, DNS and DDoS protection | EU edge network / global |
| Stripe | Payment processing | EU / United States (SCC-covered) |
| Postmark | Transactional email delivery | United States (SCC-covered) |
| Zendesk | Customer support ticketing | European Union |
| Fathom Analytics | Privacy-respecting website analytics | European Union |
| Twilio | SMS notifications and verification | United States (SCC-covered) |
| HubSpot | Marketing communications and CRM | European Union |
| Datadog | Application performance monitoring | United States / EU region (SCC-covered) |
| Loggly | Centralised log aggregation | United States (SCC-covered) |
| Sentry | Error tracking and crash diagnostics | United States / EU region (SCC-covered) |
| Segment | Internal event routing between systems | United States (SCC-covered) |
We give at least 30 days' notice of any new sub-processor engagement or replacement to customers who have an active Data Processing Addendum, and provide an objection mechanism as described in that document. An up-to-date version of this list is always available on this page, superseding any cached or printed copy.
8. International transfers
Sabee's primary infrastructure is hosted within the European Union, specifically in the AWS Frankfurt region. Where a sub-processor is located outside the EU/EEA — as noted in the table above — the transfer of personal data to that sub-processor is governed by the European Commission's Standard Contractual Clauses (SCCs), supplemented, where our transfer impact assessment identifies a need, with additional technical and organisational safeguards such as encryption in transit and at rest, minimisation of transferred fields, and contractual commitments to notify us of any government access request. Guest data processed under the Data Processing Addendum is not transferred outside the EU/EEA except through the same SCC-covered sub-processors, and never for purposes outside the delivery of the platform.
9. Your rights as a data subject
If you are located in the European Economic Area, the United Kingdom, or another jurisdiction granting equivalent rights, you have the right to: access the personal data we hold about you; request rectification of inaccurate data; request erasure where one of the applicable grounds under GDPR Article 17 is met; restrict processing in defined circumstances; object to processing carried out under legitimate interests; receive a portable copy of data you provided to us; and withdraw consent at any time where consent is the lawful basis, without affecting past lawfulness. You also have the right to lodge a complaint with the Andmekaitse Inspektsioon or your local supervisory authority. To exercise any of these rights, email privacy@sabee.esesun.com. We verify your identity before actioning a request, and we respond within one calendar month of a verified request under GDPR Article 12(3), extending by up to two further months for complex requests, with notice of any extension given within the first month.
10. Automated decision-making
Sabee does not use automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you, in relation to the personal data we control. Certain platform features (for example, rate suggestions or overbooking alerts) generate recommendations for the customer's own staff, but these recommendations are advisory only, are not applied automatically to a guest's booking or account without a human decision by the customer's staff, and do not fall within the scope of GDPR Article 22.
11. Cookies
The marketing site sets only strictly necessary cookies, described in full in our dedicated cookie policy. The platform itself, once you sign in, sets additional cookies necessary for authentication and session management, also described in that policy. We do not embed third-party advertising or tracking pixels on the marketing site.
12. Children
Sabee is a business-to-business platform intended for hospitality operators and their staff. It is not directed at, and must not be used by, individuals under the age of 16. We do not knowingly collect personal data from anyone under 16 in the capacity of controller. If we become aware that we have inadvertently collected such data, we will delete it promptly. Guest data uploaded by customers may occasionally include minors travelling with a family group; the customer, as controller of that data, is responsible for ensuring a lawful basis exists for processing any such records, consistent with the Data Processing Addendum.
13. Security measures
We apply a layered set of technical and organisational measures to protect personal data, summarised here and described in full detail in Annex II of the Data Processing Addendum. These include encryption of data at rest and in transit, role-based access control, mandatory multi-factor authentication for administrative accounts, network segmentation, continuous monitoring and alerting, regular vulnerability scanning, annual third-party penetration testing, encrypted and tested backups, and a documented incident-response plan. Access to personal data is limited to personnel who require it to perform their role, and all staff undergo data-protection training on joining and annually thereafter.
14. Breach notification
In the event of a personal data breach affecting data for which Sabee is controller, we will assess the risk to affected individuals and, where required under GDPR Article 33, notify the Andmekaitse Inspektsioon without undue delay and, in any event, within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to affected individuals, we will also notify those individuals directly under GDPR Article 34. Where Sabee acts as processor, breach notification to the affected customer is governed by Section 12 of the Data Processing Addendum, which sets a 24-hour internal notification target to the customer.
15. Changes to this policy
We review this policy periodically to reflect changes in our processing activities, our sub-processor list, or applicable law. Material changes are notified to customers by email at least 30 days before taking effect, and a summary of changes is posted on this page. The "last updated" date at the top of this page always reflects the version currently in force; earlier versions are available on request to privacy@sabee.esesun.com.
16. Version and contact
Our Data Protection Officer function can be reached at privacy@sabee.esesun.com, or by post marked for the attention of the DPO at Sabee Cloud OU, Rotermanni 8, 10111 Tallinn, Estonia. Our supervisory authority is the Andmekaitse Inspektsioon (AKI), Tatari 39, 10134 Tallinn, Estonia, aki.ee. For general support, contact support@sabee.esesun.com; for sales enquiries, sales@sabee.esesun.com; for legal correspondence, legal@sabee.esesun.com.
v2.4 Last updated 15 May 2026.