Legal documents
Your privacy is our starting point, not a legal box to tick. TogetherROOM was designed with privacy at the core of its architecture: we collect only what is strictly necessary, store as little as possible, and never sell your data to third parties for commercial purposes.
The Controller of the personal data collected through the togetherroom.com website is:
For any matter relating to privacy or to exercising your rights, write directly to info@togetherroom.com. We undertake to respond within 30 days of receiving your request.
In this pre-launch phase, we collect the data you voluntarily provide when joining the waitlist:
| Data | Purpose | Required |
|---|---|---|
| Email address | Send launch updates and confirm sign-up | Yes |
| Chosen role (Tenant / Host) | Personalize communications and internal statistics | Yes |
| Preferred language (IT/EN/ES) | Send communications in your language | No (default IT) |
| City of interest | Notify you when the service is available in your area | No |
| Anonymous hash of the IP | Fraud and spam prevention — not reversible to the original IP | Automatic |
Like any website, our servers automatically log anonymous technical access data (system logs). This data contains no personally identifiable information and is kept for a maximum of 30 days for security purposes.
We use Umami Analytics, a cookieless tool that collects no personal data, installs no cookies and does not track users across sessions. The statistics produced (pages visited, country of origin, device type) are aggregated and anonymous only.
The processing of your data is based on the following legal bases under Art. 6 of the GDPR:
| Processing | Legal basis | GDPR reference |
|---|---|---|
| Managing waitlist sign-up and sending the confirmation email | Consent of the data subject | Art. 6(1)(a) |
| Sending launch update emails | Consent of the data subject | Art. 6(1)(a) |
| IP hash for fraud prevention | Legitimate interest of the Controller | Art. 6(1)(f) |
| Technical system logs | Legitimate interest (system security) | Art. 6(1)(f) |
You may withdraw your consent at any time without affecting the lawfulness of processing carried out before the withdrawal. To do so, use the unsubscribe link in every email or write to info@togetherroom.com.
| Data category | Retention period | Reason |
|---|---|---|
| Waitlist data (email, role, language, city) | Until the platform opens, max 24 months from collection | Purpose of the waitlist |
| Deletion logs (anonymous hashes) | 36 months | Proof of GDPR compliance |
| Technical system logs | 30 days | System security |
| Cookie preferences (localStorage) | 6 months (browser-side) | Consent management |
If you request deletion of your data before expiry, we proceed within 30 days of the request. Deletion is immediate via the link in the confirmation emails.
TogetherROOM relies on the following third-party providers, appointed as Data Processors under Art. 28 GDPR:
| Provider | Service | Location | Data processed |
|---|---|---|---|
| Neon Database | PostgreSQL database (cloud) | EU — Frankfurt | All waitlist data |
| Render.com | Web app and backend hosting | USA — SCC | Technical logs, HTTP requests |
| Brevo (Sendinblue) | Transactional email delivery | FR — EU | Email, language |
| ALTCHA | Anti-bot form protection (proof-of-work) | Self-hosted — no cookies | Browser session data (anonymous) |
| Umami Software | Cookieless analytics | USA | Anonymous aggregated data only |
| Google Fonts API | Web typography fonts | USA — SCC | IP (CSS request only, no cookie) |
Personal data is never sold, transferred or exchanged with third parties for commercial or marketing purposes.
Some of our providers are based outside the European Union (USA). Transfers take place in full compliance with the GDPR through:
The main database (Neon) and the backend (Render EU) process data on European servers (Frankfurt, Germany). Waitlist data never leaves the EU.
TogetherROOM does not carry out profiling of users nor automated decision-making within the meaning of Art. 22 GDPR. Waitlist data is not used to build behavioral profiles, is not shared with advertising platforms and does not feed any targeting systems.
As a data subject under the GDPR, you have the following rights, which you can exercise at any time by writing to info@togetherroom.com:
We respond to all requests within 30 days of receipt. For complex requests, the deadline may be extended by a further 60 days, with a reasoned notice.
Italian Data Protection Authority: www.garanteprivacy.it — Piazza Venezia 11, 00187 Rome — 06 696771
We adopt appropriate technical and organizational measures to protect your personal data from unauthorized access, loss, destruction or disclosure:
In the event of a personal data breach posing a risk to your rights, we will notify the competent authorities within 72 hours and inform you without undue delay, as required by Art. 34 GDPR.
This Privacy Policy may be updated to reflect regulatory, technical or organizational changes. The updated version will always be available on this page with the "Last updated" date at the top.
For substantial changes affecting your rights, we will send an email notice to waitlist subscribers before the changes take effect.
To exercise your rights or for any question about how we handle your personal data:
Email: info@togetherroom.com
Response times: 5 business days for ordinary requests · 30 days for formal GDPR requests