Privacy Policy

Last updated: November 2025

GDPR Compliant | EU & Malta Data Protection

Your Privacy Rights Under GDPR

Room4Rent is committed to protecting your personal data in accordance with the EU General Data Protection Regulation (GDPR) and Malta's Data Protection Act. You have rights over your data, and we respect those rights.

1. Data Controller

Room4Rent operates as the data controller for personal information collected through our platform. We are based in Malta and operate in accordance with EU and Maltese data protection laws.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Name and email address
  • Phone number (if you choose to provide it)
  • Account credentials

2.2 Listing Information

When you create a property listing, we collect and process:

  • Property details (description, location, price, features)
  • Property images you upload
  • Contact information you choose to display publicly

We may review and moderate listing content (including images) to enforce our platform rules and remove or restrict content that we consider inappropriate, unlawful, or harmful to other users or to Room4Rent. Such moderation is carried out under our legitimate interest in keeping the platform safe and compliant.

⚠️ Public Information Notice

Contact details you include in listings (phone numbers, email addresses) will be publicly visible to all platform visitors. Only include information you are comfortable sharing publicly.

2.3 Technical Information

We automatically collect:

  • IP address and browser information
  • Device type and operating system
  • Usage data and navigation patterns
  • Cookies and similar tracking technologies (see Cookie Policy below)

3. How We Use Your Data

We process your personal data for the following purposes under GDPR Article 6:

  • Contractual necessity: To provide the platform service and manage your account
  • Legitimate interest: To improve user experience and platform functionality
  • Legal obligation: To comply with Maltese and EU laws
  • Consent: For cookies and optional features (where required)

4. Data Sharing and Third Parties

✓ We Do NOT Sell Your Data

Room4Rent does not sell, rent, or trade your personal information to third parties for marketing purposes.

Third-Party Service Providers

We use third-party services for essential platform operations:

  • Hosting providers: For database and application hosting (may be located within or outside the EU)
  • Authentication services: For secure account management
  • Analytics providers: For platform improvement (anonymized when possible)

⚠️ Third-Party Data Processing

When we use third-party hosting or service providers, your data may be processed by these entities. While we select reputable providers and take reasonable precautions, we cannot guarantee absolute security when data is stored or processed by third parties.

Room4Rent is not liable for data breaches, unauthorized access, or security incidents that occur at the third-party level.

5. Cookies and Tracking

Room4Rent uses cookies and similar technologies to provide essential functionality and improve your experience.

Cookie Types We Use:

Essential Cookies (Required)

Necessary for authentication, security, and basic platform functionality. These cannot be disabled as they are essential for the platform to work.

Functional Cookies

Remember your preferences and settings to enhance user experience (e.g., language preferences, display settings).

Analytics Cookies

Help us understand how users interact with the platform to improve functionality. We anonymize this data where possible.

You can manage cookie preferences in your browser settings. Note that disabling essential cookies will prevent you from using certain platform features.

6. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy or as required by law:

  • Active account data: Retained while your account is active
  • Deleted accounts: Personal data removed within 30 days (unless legal retention required)
  • Listings: Archived data may be retained for platform integrity and fraud prevention

7. Your GDPR Rights

Under GDPR and Malta's Data Protection Act, you have the following rights:

Right to Access

Request a copy of the personal data we hold about you

Right to Rectification

Request correction of inaccurate personal data

Right to Erasure ("Right to be Forgotten")

Request deletion of your personal data (subject to legal obligations)

Right to Restriction

Request limitation of processing in certain circumstances

Right to Data Portability

Receive your data in a structured, commonly used format

Right to Object

Object to processing based on legitimate interests

Right to Withdraw Consent

Withdraw consent for processing where consent was the legal basis

To exercise any of these rights, please contact us through the information provided on this page. We will respond to your request within 30 days as required by GDPR.

8. Data Security

We implement reasonable technical and organizational measures to protect your personal data, including:

  • Encrypted data transmission (HTTPS/SSL)
  • Secure authentication and password protection
  • Regular security assessments
  • Limited access to personal data on a need-to-know basis

⚠️ Security Disclaimer

While we implement security measures, no system is completely secure. We cannot guarantee absolute security of your data and are not liable for unauthorized access, data breaches, or security incidents beyond our reasonable control, including those occurring at third-party service providers.

9. International Data Transfers

Some of our third-party service providers may be located outside the European Economic Area (EEA). When we transfer data outside the EEA, we ensure appropriate safeguards are in place, such as:

  • EU Standard Contractual Clauses
  • Adequacy decisions by the European Commission
  • Privacy Shield certification (where applicable)

10. Children's Privacy

Our platform is not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such information, please contact us so we can promptly delete it.