OpenHospi is the controller within the meaning of Art. 4(7) GDPR for the processing of your personal data. OpenHospi is a free, open-source platform where students in the Netherlands can find and list rooms. For privacy questions, contact us at privacy@openhospi.nl. OpenHospi has not designated a data protection officer, as this is not required under Art. 37 GDPR given the nature and scale of our processing activities.
2. Privacy contact
For all privacy and data protection inquiries, contact privacy@openhospi.nl. We handle your request free of charge and respond within one month of receipt, in accordance with Art. 12(3) GDPR. For complex or numerous requests, we may extend this period by a further two months. We will inform you of any such extension within one month of receipt of the request, together with the reasons for the delay.
3. Data we collect
We collect the following categories of personal data, in accordance with the principle of data minimisation (Art. 5(1)(c) GDPR):
Profile data: name, email address, date of birth, gender, study programme, educational institution, bio, lifestyle tags, preferred city, available from date, maximum rent, photos
Housing data: room listings with addresses, coordinates, rent price, room details and photos
Communication data: end-to-end encrypted chat messages (content is unreadable by OpenHospi)
Application data: personal message and application status
Session data: IP address and user agent for security purposes
Push notification tokens: for delivery of notifications to your device
Calendar subscription token: a unique, secret link that allows your calendar application to access your hospi event schedule. This link does not require authentication and can be revoked at any time from your settings
Consent records: your cookie and privacy preferences, timestamps and privacy policy version
We do not collect special categories of personal data as referred to in Art. 9(1) GDPR (including data revealing racial or ethnic origin, political opinions, religious beliefs, health or sexual orientation). If you voluntarily share such data in your profile or messages, we process it on the basis of Art. 9(2)(e) GDPR (manifestly made public by the data subject).
5. How we use your data
We use your data solely to provide the OpenHospi platform, in accordance with the purpose limitation principle (Art. 5(1)(b) GDPR): matching students with rooms, facilitating communication between seekers and hosts, managing the housing application process, and calendar synchronisation. When you subscribe to your hospi calendar, we serve your event details (titles, dates, times, locations) through a private URL. Calendar applications (Google Calendar, Apple Calendar, Outlook) periodically request this URL to keep your calendar up to date. We do not sell your data, use it for advertising, profile you for marketing purposes, or share it with third parties except as described in this policy.
6. Obligation to provide personal data
Profile data (name, email address, study information) is contractually required to use the platform (Art. 13(2)(e) GDPR). Without this data, no account can be created and the platform cannot function. The provision of this data is a contractual requirement, not a statutory obligation. You are free not to create an account if you do not wish to provide this data.
7. Legal basis
We process your data on the following legal grounds (Art. 6 GDPR). See our Legal Basis Overview page for a complete breakdown per processing activity.
Performance of a contract (Art. 6(1)(b) GDPR): profile, housing, applications, chat; necessary for the performance of the contract
Legitimate interests (Art. 6(1)(f) GDPR): session security (IP logging), platform safety (moderation reports). We have balanced these interests against your rights and freedoms and determined that the processing is necessary and proportionate
Legal obligation (Art. 6(1)(c) GDPR): consent records (demonstrating valid consent in accordance with Art. 7 GDPR)
You may withdraw your consent at any time via Settings > Privacy. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal (Art. 7(3) GDPR).
8. Data sharing & processors
We share your data only with the following parties, all located within the EU/EEA. All processors operate under data processing agreements pursuant to Art. 28 GDPR. See our Data Processors page for details.
Supabase (Dublin, Ireland): database and file storage (processor)
Vercel (Dublin, Ireland): web hosting and edge functions (processor)
Upstash (Ireland): rate limiting via Redis (processor)
Institutional SSO provider (GÉANT, Netherlands): student verification (independent controller, not a processor within the meaning of Art. 28 GDPR)
Sentry (Frankfurt, Germany): crash reporting and error monitoring (processor). No personal data collected
Expo/EAS (US): mobile app builds, over-the-air updates, and distribution (processor). No personal data collected, only app code and bundles are processed
9. International transfers
All your data is stored and processed within the European Economic Area (EEA). We do not transfer personal data to third countries or international organisations. The provisions on transfers (Art. 44 to 49 GDPR) therefore do not apply. All our infrastructure providers are based in Ireland, the Netherlands, or Germany. Note: Sentry's internal organisational metadata (developer accounts, project configurations (no end-user data)) may be replicated to the US per Sentry's infrastructure. This does not affect end-user privacy as no user data is involved.
10. Data retention
We do not retain your data longer than necessary for the purposes for which it was collected, in accordance with the storage limitation principle (Art. 5(1)(e) GDPR):
Profile data, housing listings, and chat messages: retained as long as your account is active
Session IP addresses: anonymised after 30 days
Expired sessions: deleted after 90 days
Report message text: removed 90 days after resolution
Read notifications: deleted after 180 days
Consent record IP addresses: anonymised after 365 days
Account deletion: all data permanently removed via cascading deletes
11. Your rights
Under GDPR, you have the following rights with regard to your personal data. You can exercise these rights via Settings > Privacy, or by contacting privacy@openhospi.nl.
Right of access (Art. 15 GDPR): you have the right to obtain a copy of your personal data, via Settings > Privacy > Data export
Right to rectification (Art. 16 GDPR): you can have inaccurate or incomplete data corrected, via your profile
Right to erasure (Art. 17 GDPR): you can request erasure of your data, via Settings > Delete account
Right to restriction of processing (Art. 18 GDPR): you can request restriction of processing while retaining your data
Notification obligation (Art. 19 GDPR): we notify each recipient to whom personal data have been disclosed of any rectification, erasure, or restriction, unless this proves impossible or involves disproportionate effort
Right to data portability (Art. 20 GDPR): you can receive your data in a structured, commonly used and machine-readable format (JSON or CSV), via Settings > Privacy > Data export. The calendar subscription feed also provides data portability for hospi events in standard iCalendar (ICS) format
Right to object (Art. 21 GDPR): you can object to processing based on legitimate interests
12. Right to lodge a complaint
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) pursuant to Art. 77 GDPR. You may also lodge a complaint with the supervisory authority in your EU member state of habitual residence.
Autoriteit Persoonsgegevens: Postbus 93374, 2509 AJ Den Haag
We use a minimal set of cookies. Essential cookies (session authentication) are strictly necessary for the platform to function and do not require consent. Functional cookies (language preference, sidebar state) require your consent under Dutch telecommunications law (Telecommunicatiewet Art. 11.7a). We do not use tracking cookies or third-party advertising cookies. See our Cookie Policy for full details.
14. End-to-end encryption
All chat messages between students and room hosts are end-to-end encrypted (E2EE) using AES-256-GCM with ECDH key exchange, as an appropriate technical measure within the meaning of Art. 32 GDPR and in implementation of data protection by design (Art. 25 GDPR). This means OpenHospi cannot read the content of your private messages. Encryption keys are stored locally on your device and optionally backed up (encrypted) on our servers.
15. Personal data breaches
In the event of a personal data breach, OpenHospi will notify the Autoriteit Persoonsgegevens without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the breach is unlikely to result in a risk to your rights and freedoms (Art. 33 GDPR). Where the breach is likely to result in a high risk to your rights and freedoms, we will communicate the breach to you without undue delay and in clear and plain language (Art. 34 GDPR). The end-to-end encryption of chat messages limits the impact of any breach on communication data, as the encryption renders the data unintelligible to unauthorised persons (Art. 34(3)(a) GDPR).
16. Children's data
OpenHospi is exclusively accessible via institutional SSO, which requires enrollment at an accredited Dutch educational institution. This means all users are students aged 16 or older, in accordance with Art. 5 UAVG (implementing Art. 8(1) GDPR, which allows member states to set the age threshold at a minimum of 16). We do not knowingly collect personal data from children under 16.
17. Automated individual decision-making
OpenHospi does not use automated individual decision-making, including profiling, as referred to in Art. 22 GDPR. Room matching is entirely manual: users browse listings and submit applications themselves. House members vote on applicants through a manual voting process. No algorithms determine who sees which rooms or who gets accepted.
18. Changes to this policy
We may update this privacy policy from time to time. Significant changes will be communicated via an in-app notification. The 'last updated' date at the top reflects the most recent revision.