Last updated: 24 May 2026
Privacy Policy
Workers Stay is operated by Real Estate Ollopa11 Ltd ("Workers Stay", "we", "us"). We run a platform for corporate and short-term housing where property owners can list their homes and companies can book stays for their workforce. We treat your personal data with the same standard of care as the largest companies in our industry, in full compliance with the EU General Data Protection Regulation (GDPR), the UK GDPR and applicable national law. This policy explains what personal data we process, why, on which legal basis, how long we keep it, who we share it with and what rights you have.
1. Data controller and contact
The controller for the processing of your personal data is:
- Real Estate Ollopa11 Ltd (company no. 13697786, incorporated 22 October 2021)
- 128 City Road, London EC1V 2NX, United Kingdom
- Email: privacy@workersstay.com
- General enquiries: contact@workersstay.com
Privacy enquiries, rights requests and incident reports are answered within 30 days as required by Article 12 GDPR. For particularly complex requests we may extend this period by up to two further months and will notify you in writing.
2. EU representative and Privacy lead
As we are established in the United Kingdom but offer services to data subjects in the EU, we have appointed a representative in the Union in accordance with Article 27 GDPR. You can reach our EU representative by writing to privacy@workersstay.com and marking your message "EU Representative".
We are not required to appoint a formal Data Protection Officer (DPO) under Article 37 GDPR, but our Head of Privacy is the dedicated point of contact and can be reached at privacy@workersstay.com.
3. Scope
This policy applies when you:
- visit workersstay.com or any of our sub-domains,
- submit a booking enquiry or contact us via forms or email,
- list a property as an owner,
- enter into an agreement with us as a guest, corporate customer or property owner,
- receive marketing communications from us, or
- interact with our ads on third-party platforms such as Google or Meta.
4. Categories of personal data we process
Depending on your relationship with us, we process the following categories:
- Identity and contact data: name, email, company name, company registration number, billing address.
- Booking data: check-in/check-out dates, number of guests, purpose of stay, project, special requests.
- Contract and payment data: contract terms, invoices, payment method (Workers Stay does not store full card numbers — card data is handled by Stripe), receipts, transaction history.
- Property data for owners: address, photos, pricing, payout bank details, target income.
- Communications: messages via email, WhatsApp and forms, consents, complaints and support tickets.
- Technical data: IP address, device type, browser, operating system, language, referrer, page views, cookies and similar technologies.
- Marketing data: tracking identifiers, ad clicks, audience segments and your responses to campaigns.
- Geographic data: city or region derived from your IP address or provided by you.
We do not intentionally process special categories of personal data (Article 9 GDPR) such as health, ethnic origin, religion or political opinions. If you voluntarily include such information in a free-text field we will delete it as soon as we become aware of it.
5. Sources of personal data
Most data we hold comes directly from you. We may also obtain or supplement it from:
- public registers (company registers; credit checks for large corporate agreements),
- our service providers (e.g. Hospitable for booking sync, Stripe for payment status),
- advertising platforms (Google Ads, Meta) in the form of aggregated conversion and attribution data,
- your employer or travel agent if someone books on your behalf.
6. Purposes and legal bases
We process your personal data only for specific and legitimate purposes. The table below lists each processing activity, its purpose and the legal basis under Article 6 GDPR.
| Activity | Purpose | Legal basis |
|---|---|---|
| Handling booking enquiries and offers | Reply to your enquiry and propose suitable housing. | Contract / pre-contract steps (Art. 6(1)(b)) |
| Confirming and administering bookings | Perform the booking contract. | Contract (Art. 6(1)(b)) |
| Invoicing and accounting | Comply with our statutory accounting obligations. | Legal obligation (Art. 6(1)(c)) |
| Communication during the stay | Make sure your stay goes smoothly. | Contract (Art. 6(1)(b)) |
| Registering and publishing property listings | Enable owners to receive bookings via us. | Contract (Art. 6(1)(b)) |
| Payouts to property owners | Perform the owner agreement. | Contract (Art. 6(1)(b)) + legal obligation (Art. 6(1)(c)) |
| Security, fraud prevention, abuse handling | Protect the platform and block abuse. | Legitimate interest (Art. 6(1)(f)) |
| Service analytics | Improve the product and conversion. | Legitimate interest (Art. 6(1)(f)) or consent (Art. 6(1)(a)) for non-essential cookies |
| Marketing to existing customers | Offer similar services (soft opt-in). | Legitimate interest (Art. 6(1)(f)) — opt-out in every message |
| Marketing via tracking cookies | Show relevant ads. | Consent (Art. 6(1)(a)) |
| Handling rights requests and complaints | Comply with Articles 12–22 GDPR. | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interest we have carried out a balancing test weighing your rights and freedoms against our interest. You can object to such processing at any time as described in section 12.
7. Retention periods
We keep personal data only for as long as necessary to fulfil the purpose for which it was collected:
- Enquiries that do not lead to a booking: up to 18 months, then anonymised or deleted.
- Bookings and customer data: for the duration of the relationship plus 7 years after the last transaction (Swedish Accounting Act, chap. 7 §2).
- Owner agreements: for the duration of the relationship plus 10 years (statutory limitation and accounting requirements).
- Marketing data based on consent: until you withdraw consent or after 24 months of inactivity.
- Security and fraud-prevention logs: 12 months.
- Support tickets and email communication: 36 months after the case is closed.
- Cookies: as specified in our cookie banner and in section 9 below.
8. Recipients and processors
We share your data only with carefully selected service providers who process it on our behalf under a written Data Processing Agreement (DPA) in line with Article 28 GDPR. We never sell personal data. Current processors include:
- Hosting and database: Lovable Cloud / Supabase (EU regions).
- Transactional email: Resend Inc.
- Payments: Stripe Payments Europe Ltd.
- Booking sync: Hospitable.com.
- AI processing of messages: Google (Gemini via Lovable AI Gateway) and OpenAI — message content only, no training on our data.
- Advertising and attribution: Google Ireland Ltd and Meta Platforms Ireland Ltd.
- Digital signing: operated in-house by Workers Stay (johanna@workersstay.com is our signing coordinator).
- WhatsApp messaging: WhatsApp Ireland Ltd.
- Banks and card acquirers for payouts.
- Legal and financial advisors when needed to defend our rights.
We also share data with competent authorities when required by law (e.g. tax authorities, law-enforcement, courts).
10. International transfers
Our production data is stored within the EU/EEA. Some processors (notably AI models and tracking tools) may process data in third countries, primarily the United States. For such transfers we ensure an adequate level of protection through:
- European Commission adequacy decisions (e.g. the EU–U.S. Data Privacy Framework for certified recipients),
- EU Standard Contractual Clauses (SCCs 2021/914) supplemented by technical and organisational measures, and
- the UK International Data Transfer Addendum (UK IDTA) where the transfer falls under the UK GDPR.
A copy of the applicable safeguards can be requested at privacy@workersstay.com.
11. Security
We apply appropriate technical and organisational measures under Article 32 GDPR, including:
- TLS encryption in transit and encryption at rest in the database,
- role-based access control and Row-Level Security on every table containing personal data,
- principle of least privilege for staff and processors,
- access logging and monitoring,
- regular security scans and dependency reviews,
- an incident response and business continuity plan with notification to the supervisory authority within 72 hours of a personal data breach (Article 33 GDPR) and to you directly if the breach is likely to result in a high risk to your rights (Article 34).
12. Your rights
Under the GDPR and UK GDPR you have the following rights:
- Right of access (Art. 15) — receive a copy of the data we hold about you.
- Right to rectification (Art. 16) — have inaccurate data corrected.
- Right to erasure (Art. 17) — where the processing is no longer necessary or you withdraw consent.
- Right to restriction of processing (Art. 18).
- Right to data portability (Art. 20) — receive your data in a structured, machine-readable format.
- Right to object (Art. 21) to processing based on legitimate interest or direct marketing.
- Right not to be subject to automated decision-making (Art. 22) — see section 13.
- Right to withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.
- Right to lodge a complaint with a supervisory authority (see section 16).
To exercise your rights, contact privacy@workersstay.com. We may need to verify your identity before acting on a request. This service is free of charge, but we may charge a reasonable fee or refuse to act on manifestly unfounded or excessive requests (Art. 12(5)).
13. Automated decision-making and profiling
We use AI assistance to reply to simple customer enquiries faster and to match requests with available housing. The final decision to enter into an agreement, set a price or decline a booking is always made by a human at Workers Stay. We do not carry out automated decision-making producing legal effects, or similarly significantly affecting you, within the meaning of Article 22 GDPR.
14. Children
Our service is aimed at businesses and adults. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact privacy@workersstay.com and we will delete it.
15. Changes to this policy
We may update this policy from time to time. Material changes will be communicated through our website or by email in good time before they take effect. The "Last updated" date at the top shows when this policy was last revised. Earlier versions are available on request from privacy@workersstay.com.
16. Complaints
If you believe we have handled your personal data unlawfully, please contact us first — we take your concerns seriously. You always have the right to lodge a complaint with a supervisory authority:
- Sweden: Integritetsskyddsmyndigheten (IMY), Box 8114, SE-104 20 Stockholm, imy@imy.se, imy.se.
- United Kingdom: Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, ico.org.uk.
- Other EU countries: your national data protection authority.