Privacy Policy
GetRoomly AB ("we," "our," "us," or "GetRoomly") operates a visual technology platform that lets end users visualize furniture and room modifications. This policy describes how we collect, use, store, and protect personal data when you interact with our services, including our browser-based widget, our website, and related services (collectively, the "Services").
We are committed to protecting your privacy and being transparent about how we process your personal data. This policy applies to everyone who uses our Services, including shoppers using the widget and business partners integrating our technology.
2. Contact information
Data controller:
GetRoomly AB
Sweden
Email: legal@getroomly.ai
3. What data we process
Shoppers using the widget
- Technical data: IP address, timestamp, retailer site, product viewed, and a temporary session reference. The IP address is used solely to apply usage limits (50 generations per week) and prevent abuse. We do not combine it with any other information that identifies you, and it is deleted after 7 days.
- Interaction data: actions you take within the widget, such as product views and rendering requests.
- Generated content: images you create using the widget are stored for quality-validation purposes, as described in Section 5.
Retailers and business partners
- Name, business email, role and phone number.
- Billing and contract information.
- Messages you send us.
Data we do not collect
GetRoomly does not knowingly collect sensitive categories of personal data, such as health information, racial or ethnic origin, political opinions, religious beliefs, genetic or biometric data, or data concerning sexual orientation, unless you explicitly provide it and we have obtained appropriate consent for its processing.
4. Legal basis and purposes
| Purpose | Applies to | Legal basis |
|---|---|---|
| Provide core widget functionality | Shoppers | Contract / Legitimate interest |
| Apply usage limits and prevent abuse | Shoppers | Legitimate interest |
| Give retailers usage statistics (renders, cart adds) | Retailers | Contract |
| Respond to inquiries | Retailers & visitors | Contract / Legitimate interest |
| Quality validation and service improvement | Shoppers | Legitimate interest |
| Comply with legal obligations | All | Legal obligation |
5. Image storage for quality validation
When you use the widget, the room photo you upload and the generated result are stored in secure cloud storage for up to 14 days. This retention serves an internal quality-assurance purpose, letting our team evaluate how the service performs across different room types, products, and usage scenarios during the pilot phase.
These images are stored securely with restricted access and are automatically deleted after 14 days. The stored data consists only of your uploaded room photo and the generated result, no additional personal information is attached to these files.
We do not train AI models, and your data is never used to train or fine-tune our AI provider's models either, this is confirmed under our agreement with them. We may review aggregated generation results to refine the instructions (prompts) we send to the AI model, which does not change or train the model itself. We may also analyze aggregated service logs, error patterns, and performance data from our own systems to improve platform reliability and features.
6. How long we keep your data
| Data type | Retention period |
|---|---|
| Technical data (IP address only) | 7 days |
| Account data (retailers and business partners) | Duration of relationship + 1 year |
| Generated images (room photos and results) | 14 days |
| Billing and invoice records | 7 years (Swedish accounting law) |
| Support inquiries and messages | As long as needed to resolve your inquiry |
7. Security and privacy by design
Your data is protected in accordance with the General Data Protection Regulation (GDPR) and equivalent international data protection standards. We implement organizational and technical safeguards, including:
- Encryption in transit (HTTPS/TLS) and at rest for sensitive data.
- Restricted access controls and role-based permissions.
- Automatic deletion of data after the retention periods described above.
- EU data residency for our servers, database, and image storage.
- Regular security assessments and compliance monitoring.
We work continuously to ensure our handling of personal data complies with applicable data protection legislation in every region in which we operate.
7.1 Data breach notification
In the event of a confirmed data breach affecting personal data, we will:
- Notify affected retailers and business partners without undue delay.
- Notify the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) within 72 hours of becoming aware of the breach, if it poses a high risk.
Notifications will describe the nature of the breach, the data affected, likely consequences, and measures taken.
8. Your rights
Under GDPR, you have the right to:
- Access: request a copy of the personal data we hold about you.
- Erasure: request deletion of your personal data, subject to applicable legal requirements.
- Restriction: request that we limit how we use your data.
- Portability: request your data in a portable format.
- Objection: object to certain processing activities.
To exercise any of these rights, contact us at legal@getroomly.ai. If you used the widget on a retailer's site, you can also contact that retailer directly, we will help them answer your request.
Complaints: you can complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), www.imy.se, or to the data protection authority where you live.
9. Data sharing and recipients
We do not sell or rent your personal data to anyone. We may share data with:
- Service providers: cloud infrastructure and payment providers that help us operate our Services, under data processing agreements.
- Business partners: retailers integrating our widget receive aggregated usage statistics, never personal data.
- Legal requirements: when required by law, court order, or regulatory authority.
Subprocessors: a current list of our subprocessors is available on request, contact legal@getroomly.ai.
10. International data transfers
Personal data is processed primarily within the European Union. Our servers, database, and image archive are hosted in the EU. Where transfers occur outside the EEA, for instance the AI processing step that generates the preview image, we rely on the EU–US Data Privacy Framework and Standard Contractual Clauses (SCCs) to ensure adequate safeguards. You can request a copy of the applicable transfer mechanisms by contacting legal@getroomly.ai.
11. Third-party links and integrations
Our Services may contain links to or integrations with third-party websites and services. We are not responsible for the privacy practices, content, or security of those third parties. We encourage you to review their privacy policies before engaging with them.
12. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. For material changes, we will give at least 30 days' advance notice by posting the updated policy with a revised effective date and, where required by law, by emailing retailers. Continued use of the Services after the effective date constitutes acceptance of the revised policy.
13. Contact us
If you have questions, concerns, or requests regarding this Privacy Policy, please contact us at:
GetRoomly AB
Sweden