These specifications apply to the Student Housing mobile application and the student-housing.app website (together, the "Service"), operated by TINT TECH S.R.L., hereinafter referred to as "the Controller". The Controller's registration details are set out in the Legal Notice.
The Controller processes the personal data of users of the Service in compliance with Regulation (EU) 2016/679 (the "GDPR") and Law No. 190/2018 on measures implementing the GDPR, and has adopted technical and organizational measures appropriate to this purpose.
These specifications inform data subjects of the categories of personal data processed, the purposes and legal grounds of processing, the persons to whom such data may be disclosed, the duration of processing, and the rights available to data subjects in connection with their use of the Service.
For any request, complaint, or clarification regarding the processing of personal data, data subjects may contact the Controller at contact@tinttechhub.com.
The Controller processes personal data collected through two components of the Service:
a) The website. In connection with the waitlist form available on the website, the Controller processes: the email address, provided voluntarily by the data subject; the IP address, processed automatically and temporarily for the purpose of preventing abusive or repeated submissions; and standard technical log data generated by the hosting infrastructure (browser type, pages accessed). The website does not use analytics or advertising cookies.
b) The mobile application. Following the creation of an account, the Controller processes the following categories of data, according to the functions used by the data subject:
The purposes for which personal data is processed are:
Processing carried out for the creation and administration of the account, and for the provision of the functions described above, is based on the performance of the contract concluded with the data subject upon account creation (Article 6(1)(b) GDPR); such data is necessary for the provision of the corresponding function, and refusal to provide it results in the impossibility of using that function.
Processing of optional data — such as lifestyle preferences, the institutional email address, camera and photo library access, device location, and the waitlist email address — is based on the data subject's consent (Article 6(1)(a) GDPR), which may be withdrawn at any time without affecting the lawfulness of processing carried out prior to withdrawal.
Processing carried out for the prevention of abuse, the handling of reports, and technical diagnosis is based on the Controller's legitimate interest (Article 6(1)(f) GDPR) in maintaining the security and proper operation of the Service, an interest which has been balanced against the fundamental rights of data subjects. The Controller does not sell personal data to third parties.
The application displays advertisements through the Google AdMob network, in order to support the free provision of the Service. In this context, the device's advertising identifier and other technical device signals may be processed for the purpose of ad selection, including personalized advertising, where permitted by the settings of the operating system. On iOS, the device advertising identifier is used for personalized advertising only if permitted through the App Tracking Transparency prompt.
Data subjects may, at any time, restrict the processing of their advertising identifier from the privacy settings of their device (on iOS: Settings → Privacy & Security → Tracking; on Android: Settings → Privacy → Ads). Restricting this setting does not remove advertisements from the application but limits their personalization.
Certain features, such as translating listing text and identifying its language, run entirely on the data subject's device using an on-device machine-learning model. Content processed this way is not transmitted to the Controller or to any third party for that purpose; the only network activity involved is a one-time download of the on-device model itself.
For the purposes described in Section III, the Controller discloses personal data to:
The Controller may also disclose personal data where required by law, in order to enforce the terms applicable to the Service, or in order to protect the rights, safety, or property of the Controller, its users, or third parties. If the Controller is involved in a merger, acquisition, or sale of assets, personal data may be transferred to the party involved in that transaction, subject to the commitments made in these specifications.
The providers referred to in Section VI may process and store personal data outside of the data subject's country of residence, including in the United States. Where such processing entails a transfer of personal data outside the European Economic Area, the Controller relies on the transfer safeguards implemented by its providers and recognized under the GDPR, such as the EU-U.S. Data Privacy Framework or the standard contractual clauses adopted by the European Commission.
The email address submitted through the waitlist is retained until the launch of the Service and the creation of an account by the data subject, or until the data subject requests its deletion, whichever occurs first. IP addresses processed for the prevention of abuse are retained for approximately one hour.
Account and profile data is retained for the duration of the account's existence. Upon deletion of the account, the Controller deletes the profile, listings, and associated photographs, and deletes or anonymizes the remaining personal data (including correspondence and group memberships) within 30 days, except to the extent that retention of certain data is required for compliance with legal obligations, the resolution of disputes, or the enforcement of the Controller's agreements.
Technical and diagnostic data is retained by the infrastructure provider for a limited period, not exceeding 90 days, for the purpose described in Section III.
Users of the Service, in their capacity as data subjects, have the following rights, exercised in accordance with the GDPR:
Requests concerning the exercise of these rights may be addressed to the Controller at contact@tinttechhub.com and will be answered within the time limits provided by the GDPR. A complete, pillar-by-pillar description of these rights is set out in the GDPR Compliance page.
Passwords are stored exclusively by the authentication provider, in hashed form, and are not accessible to the Controller. Data is encrypted in transit and at rest by the infrastructure provider. Access to personal data within the Service's database is restricted by rules corresponding to each category of data — for example, only the participants in a conversation may access its content — with the exception of data which, by the nature of the corresponding function, is intended to be visible to other users, as described in Section II.
No method of electronic storage or transmission is entirely secure. In the event of a personal data breach affecting the rights of data subjects, the Controller will notify the affected data subjects and the competent supervisory authority without undue delay, in accordance with the GDPR.
The Service is intended for university students and other adults. The Controller does not knowingly collect personal data from persons under the age of 16, or such higher age of consent as may apply under the law of the data subject's habitual residence. Where the Controller becomes aware that an account has been created by, or contains data of, a person below the applicable age, the account will be deactivated and the associated data deleted. Parents or legal guardians who believe that a child has provided personal data to the Controller may submit a request to contact@tinttechhub.com.
The Controller may amend these specifications as the Service evolves, in particular where new functions requiring the processing of additional categories of data are introduced. Amendments take effect upon publication on this page, together with an updated "Last updated" date. Amendments materially affecting the purposes or legal grounds of processing, or the rights of data subjects, will additionally be communicated to users by electronic means before taking effect; where such amendments concern processing based on consent, the Controller will request renewed consent where required by law.
Requests, complaints, or clarifications regarding the processing of personal data may be addressed to the Controller at contact@tinttechhub.com.