Skip to content
Vedom home

Privacy policy

Draft: awaiting review by counsel. Items marked [CONFIRM] are not final.

Last updated: [CONFIRM date]

1. Who is responsible

The controller for this website is [CONFIRM: full legal name], sole proprietor trading as Vedom, [CONFIRM: address]. Contact: hello@opmise.com.

2. What this policy covers

This policy covers visitors to opmise.com and people who contact us. When hotels use the Vedom product, the hotel is the controller for its guests’ and staff’s data and Vedom is its processor; please read your hotel’s privacy notice.

3. Visiting this website

Our hosting provider (Cloudflare) processes technical data such as your IP address, browser type and the pages requested, to deliver the site and keep it secure. Legal basis: our legitimate interest in a secure, working website (Art. 6(1)(f) GDPR). [CONFIRM log retention and Cloudflare transfer mechanism]

4. Cookies and analytics

This website sets no cookies and uses no analytics or advertising trackers. Fonts are served from our own domain. If we add analytics later, it will only run after you opt in, and this policy will be updated first.

5. Contacting us

If you email us, we use your details to answer you and, if you ask for it, to arrange a demo. Legal basis: steps before a contract at your request (Art. 6(1)(b) GDPR) and our legitimate interest in answering business enquiries (Art. 6(1)(f) GDPR). [CONFIRM retention period and email provider]

6. Waitlist and founding pilot programme

What we collect. Your work email address, the option you chose (running a hotel, building hotel software or following along) and the page you signed up on. If you choose to answer the optional questions after confirming: for hotels, the hotel’s name, number of rooms, PMS, country, your role and a one-line note; for software builders, your company, what you build and which APIs matter to you; and how you heard about Vedom. When you sign up and when you confirm, we also record the date and time, the version of the consent text you saw, the page language, and a coded (keyed hash) form of your IP address and your browser type, so we can prove that you asked to join.

Why and on what basis. To send you emails about Vedom: a monthly build update, launch news and an invitation to apply for our founding pilot programme (targeting early 2027), or, if you build hotel software, news about the API. We use the optional answers to decide, as people, which hotels to invite first and to plan the API. Legal basis: your consent (Art. 6(1)(a) GDPR; Art. 130 Italian Privacy Code; for recipients in Germany also §7(2) UWG, in Austria §174 TKG 2021, in Switzerland Art. 3(1)(o) UWG). We keep the proof of your consent on the basis of our legitimate interest in being able to show that our emails were requested (Art. 6(1)(f) GDPR). [CONFIRM]

Double opt-in. We only add you after you open the link in our confirmation email and press “Confirm”. That email contains nothing else.

Voluntary. Signing up is voluntary, and so is every question after it. Without an email address we can’t add you to the list.

Who processes it for us. Cloudflare (hosting of this website and the sign-up form), Neon (our database, stored in Frankfurt, Germany) and Postmark (sending the emails). They act on our instructions under data processing agreements. We don’t sell or share your details with anyone else, and we don’t use them for advertising profiles.

Transfers outside the EU. Postmark (ActiveCampaign, LLC) and Cloudflare, Inc. are US companies. Postmark sends and stores email data in the USA, and Cloudflare’s network may process your request outside the EU. Neon’s parent is a US company. Where data reaches or may be accessed from the USA, we rely on the EU–US Data Privacy Framework (for Swiss visitors, the Swiss–US Data Privacy Framework) where the provider is certified, and otherwise on the EU Standard Contractual Clauses. Country involved: the USA. [CONFIRM per provider]

How long we keep it. Unconfirmed sign-ups: deleted after 7 days. Confirmed sign-ups: until you unsubscribe or the waitlist ends, at the latest 24 months after our last email to you. When you unsubscribe we delete you from the list at once. We keep a minimal record (email address, the dates of sign-up, confirmation and unsubscribe, and the consent-text version) for 3 years, only to prove your consent if challenged, and then delete it. [CONFIRM periods]

Your rights. You can withdraw your consent at any time, without giving a reason, with the unsubscribe link in every email or by writing to hello@opmise.com. Withdrawal doesn’t affect emails sent before. You also have the rights listed under “Your rights”, and you can complain to a supervisory authority (in Italy the Garante per la protezione dei dati personali; in Switzerland the FDPIC).

No automated decisions. We don’t make decisions about you based solely on automated processing.

7. Your rights

You have the right to access, correct, erase and restrict the use of your data, to data portability and to object to processing based on legitimate interest (Arts. 15–21 GDPR). Write to hello@opmise.com. You may also complain to a supervisory authority, for Italy the Garante per la protezione dei dati personali. [CONFIRM]