Sb Sabee
Legal · Privacy

Privacy policy.

Sabee is operated by Sabee Cloud OU, and this policy explains, in detail, how we collect, use, store, share and protect personal data — both as controller of our own website and commercial contacts, and as processor of guest data uploaded by our customers. Last updated 15 May 2026.

1. Controller identity

Sabee is a trading name of Sabee Cloud OU, a private limited company registered in the Republic of Estonia under registration number 14975208, VAT identifier EE102948371, with its registered office at Rotermanni 8, 10111 Tallinn, Estonia. Throughout this policy, "Sabee", "we", "us" and "our" refer to Sabee Cloud OU. Sabee Cloud OU is the data controller for the categories of personal data described in Section 3 that relate to our own website visitors, prospective customers, current and former customer contacts, suppliers and staff. For guest personal data uploaded by our customers into the Sabee platform, Sabee Cloud OU acts as a data processor, and the customer (the hotel, hostel, aparthotel or multi-property operator) remains the controller. Our supervisory authority is the Andmekaitse Inspektsioon, the Estonian Data Protection Inspectorate, reachable at aki.ee. Nothing in this policy limits the rights you have under the General Data Protection Regulation (EU) 2016/679 ("GDPR") or the Estonian Personal Data Protection Act.

2. Definitions

"Personal data" means any information relating to an identified or identifiable natural person. "Processing" means any operation performed on personal data, including collection, storage, use, disclosure, and deletion. "Controller" means the entity that determines the purposes and means of processing. "Processor" means the entity that processes personal data on behalf of a controller. "Sub-processor" means a further processor engaged by Sabee to assist in delivering the platform. "Customer" means the legal entity that has subscribed to the Sabee platform. "Guest data" means personal data about the customer's own guests, uploaded to or generated within the platform by the customer. "Telemetry" means technical usage and diagnostic data generated automatically by software. "Platform" means the Sabee hotel and hostel management application and all associated services, dashboards, APIs and integrations. These definitions apply consistently across this policy and cross-referenced documents including the Data Processing Addendum and the cookie policy.

3. Categories of data we process

We process several distinct categories of personal data, each with different sources, retention rules and legal treatment. The table below summarises the categories relevant to Sabee's operation of the marketing site and the platform.

CategoryExamplesSourceRole Sabee plays
Account dataName, work email, role, company, password hashProvided directly by the user at sign-up or onboardingController
Billing dataBilling contact, VAT number, invoice address, payment method tokenProvided by the customer; payment tokens generated by our payment processorController
Telemetry dataDevice type, browser version, feature usage counts, error logs, session durationGenerated automatically by the platform and marketing siteController (aggregated), Processor (where tied to guest identity)
Cookies and similar technologiesSession identifiers, CSRF tokens, locale and theme preferencesSet by the browser on visit or loginController
Guest data uploaded by the customerGuest name, contact details, ID/passport numbers, stay history, preferences, payment tokensEntered or imported by the customer, or synced from OTAs and channel managersProcessor
PMS operational dataRates, availability, housekeeping tasks, folios, reports, internal notesGenerated by the customer's use of the platformProcessor (where it contains identifiable staff or guest information)

Where Sabee acts as processor for guest data and PMS operational data, our processing is governed exclusively by the customer's documented instructions and by the Data Processing Addendum, not by this policy's controller-facing provisions.

4. Lawful basis per category

Under GDPR Article 6, each category of processing we carry out as controller relies on one or more of the following lawful bases:

  • Performance of a contract (Art 6(1)(b)) — account data and billing data, processed to create your account, deliver the subscription you selected, and issue invoices.
  • Legitimate interests (Art 6(1)(f)) — telemetry data, processed to keep the platform secure, diagnose faults, and improve reliability; also used for aggregated product analytics, always balanced against your right to privacy.
  • Legal obligation (Art 6(1)(c)) — billing records retained for statutory accounting and tax purposes, and any data we are required to disclose to a competent authority.
  • Consent (Art 6(1)(a)) — marketing communications where consent is the applicable basis, and any non-essential cookie category should one ever be introduced. Consent can be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.

For guest data and PMS operational data processed as processor, the lawful basis is determined by the customer as controller; Sabee's role is limited to processing under instruction, and we do not independently select a lawful basis for that category.

5. Purposes of processing

We process personal data for the following purposes: (a) service provision — operating the platform, authenticating users, and delivering the features included in the customer's subscription; (b) security — detecting and preventing fraud, abuse, intrusion attempts and unauthorised access; (c) billing — generating invoices, processing payments, and reconciling accounts through our payment processor; (d) compliance — meeting our statutory obligations under Estonian and EU law, including accounting retention and responses to lawful requests from authorities; (e) product analytics — understanding aggregated usage patterns to prioritise engineering work, always on an aggregated or pseudonymised basis wherever the purpose permits; and (f) communications — responding to support requests, sending service notices, and, where you have consented, sending product updates and marketing content. We do not process personal data for any purpose incompatible with the purpose for which it was originally collected, and we do not use guest data uploaded by customers for our own marketing or analytics purposes under any circumstances.

6. Retention schedule

We retain personal data only for as long as necessary for the purposes described above, or as required by law. The table below sets out our standard retention periods.

Data categoryRetention periodBasis for period
Website analytics (aggregated)26 monthsLegitimate interest in trend analysis
Sales enquiries and unconverted leads24 months after last contactLegitimate interest in following up
Account data (active customers)Duration of subscriptionContractual necessity
Billing and accounting recordsContract term plus 7 yearsEstonian Accounting Act statutory minimum
Telemetry and application logs90 days raw, 13 months aggregatedSecurity investigation window, then anonymised trend data
Support tickets36 months after closureLegitimate interest in service history
Marketing consent recordsDuration of consent plus 2 yearsEvidentiary requirement for consent proof
Guest data (processor role)As instructed by the customer; deleted within 30 days of contract terminationData Processing Addendum

7. Sub-processors

To deliver Sabee reliably, we engage a limited number of specialist sub-processors, each bound by a data processing agreement consistent with GDPR Article 28. The current list is:

Sub-processorFunctionLocation
AWS (Amazon Web Services), Frankfurt regionPrimary infrastructure hostingEuropean Union
CloudflareCDN, DNS and DDoS protectionEU edge network / global
StripePayment processingEU / United States (SCC-covered)
PostmarkTransactional email deliveryUnited States (SCC-covered)
ZendeskCustomer support ticketingEuropean Union
Fathom AnalyticsPrivacy-respecting website analyticsEuropean Union
TwilioSMS notifications and verificationUnited States (SCC-covered)
HubSpotMarketing communications and CRMEuropean Union
DatadogApplication performance monitoringUnited States / EU region (SCC-covered)
LogglyCentralised log aggregationUnited States (SCC-covered)
SentryError tracking and crash diagnosticsUnited States / EU region (SCC-covered)
SegmentInternal event routing between systemsUnited States (SCC-covered)

We give at least 30 days' notice of any new sub-processor engagement or replacement to customers who have an active Data Processing Addendum, and provide an objection mechanism as described in that document. An up-to-date version of this list is always available on this page, superseding any cached or printed copy.

8. International transfers

Sabee's primary infrastructure is hosted within the European Union, specifically in the AWS Frankfurt region. Where a sub-processor is located outside the EU/EEA — as noted in the table above — the transfer of personal data to that sub-processor is governed by the European Commission's Standard Contractual Clauses (SCCs), supplemented, where our transfer impact assessment identifies a need, with additional technical and organisational safeguards such as encryption in transit and at rest, minimisation of transferred fields, and contractual commitments to notify us of any government access request. Guest data processed under the Data Processing Addendum is not transferred outside the EU/EEA except through the same SCC-covered sub-processors, and never for purposes outside the delivery of the platform.

9. Your rights as a data subject

If you are located in the European Economic Area, the United Kingdom, or another jurisdiction granting equivalent rights, you have the right to: access the personal data we hold about you; request rectification of inaccurate data; request erasure where one of the applicable grounds under GDPR Article 17 is met; restrict processing in defined circumstances; object to processing carried out under legitimate interests; receive a portable copy of data you provided to us; and withdraw consent at any time where consent is the lawful basis, without affecting past lawfulness. You also have the right to lodge a complaint with the Andmekaitse Inspektsioon or your local supervisory authority. To exercise any of these rights, email privacy@sabee.esesun.com. We verify your identity before actioning a request, and we respond within one calendar month of a verified request under GDPR Article 12(3), extending by up to two further months for complex requests, with notice of any extension given within the first month.

10. Automated decision-making

Sabee does not use automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you, in relation to the personal data we control. Certain platform features (for example, rate suggestions or overbooking alerts) generate recommendations for the customer's own staff, but these recommendations are advisory only, are not applied automatically to a guest's booking or account without a human decision by the customer's staff, and do not fall within the scope of GDPR Article 22.

11. Cookies

The marketing site sets only strictly necessary cookies, described in full in our dedicated cookie policy. The platform itself, once you sign in, sets additional cookies necessary for authentication and session management, also described in that policy. We do not embed third-party advertising or tracking pixels on the marketing site.

12. Children

Sabee is a business-to-business platform intended for hospitality operators and their staff. It is not directed at, and must not be used by, individuals under the age of 16. We do not knowingly collect personal data from anyone under 16 in the capacity of controller. If we become aware that we have inadvertently collected such data, we will delete it promptly. Guest data uploaded by customers may occasionally include minors travelling with a family group; the customer, as controller of that data, is responsible for ensuring a lawful basis exists for processing any such records, consistent with the Data Processing Addendum.

13. Security measures

We apply a layered set of technical and organisational measures to protect personal data, summarised here and described in full detail in Annex II of the Data Processing Addendum. These include encryption of data at rest and in transit, role-based access control, mandatory multi-factor authentication for administrative accounts, network segmentation, continuous monitoring and alerting, regular vulnerability scanning, annual third-party penetration testing, encrypted and tested backups, and a documented incident-response plan. Access to personal data is limited to personnel who require it to perform their role, and all staff undergo data-protection training on joining and annually thereafter.

14. Breach notification

In the event of a personal data breach affecting data for which Sabee is controller, we will assess the risk to affected individuals and, where required under GDPR Article 33, notify the Andmekaitse Inspektsioon without undue delay and, in any event, within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to affected individuals, we will also notify those individuals directly under GDPR Article 34. Where Sabee acts as processor, breach notification to the affected customer is governed by Section 12 of the Data Processing Addendum, which sets a 24-hour internal notification target to the customer.

15. Changes to this policy

We review this policy periodically to reflect changes in our processing activities, our sub-processor list, or applicable law. Material changes are notified to customers by email at least 30 days before taking effect, and a summary of changes is posted on this page. The "last updated" date at the top of this page always reflects the version currently in force; earlier versions are available on request to privacy@sabee.esesun.com.

16. Version and contact

Our Data Protection Officer function can be reached at privacy@sabee.esesun.com, or by post marked for the attention of the DPO at Sabee Cloud OU, Rotermanni 8, 10111 Tallinn, Estonia. Our supervisory authority is the Andmekaitse Inspektsioon (AKI), Tatari 39, 10134 Tallinn, Estonia, aki.ee. For general support, contact support@sabee.esesun.com; for sales enquiries, sales@sabee.esesun.com; for legal correspondence, legal@sabee.esesun.com.

v2.4 Last updated 15 May 2026.