What this policy covers
This policy covers treema.app and the Treema platform. It sets out what we collect, why we hold it, who else touches it, and how to reach us about any of it.
Two kinds of data run through Treema and they are not the same. Data about the people who use the product — your general manager, your receptionists, your housekeepers — is data we hold as controller, and this policy governs it. Data your hotel puts into its workspace about guests and operations is data we process on your instructions, as your processor; your own guest privacy notice governs that, and the Terms of Service say so.
What we collect
Account data: names, work email addresses, roles, the property or group a member belongs to, and sign-in records.
Workspace content: what your team puts into Treema — guest conversations and profiles, tasks and checklists, shift and cleaning records, internal chats, department procedures, storefront orders, property and asset records, and the activity log that tracks who changed what.
Usage data: how the product is used — pages opened, features used, device and browser type, approximate location derived from an IP address, and diagnostics when something breaks.
Billing data: company name, billing address, plan, and invoice history. Card details go straight to our payment processor and do not reach our systems.
Enquiries: what you send us when you book a walkthrough, use the contact form, or email us.
Why we process it
To run the service and keep it working; to sign members in and secure their accounts; to let the agents do the work they were switched on for — triaging guest messages, drafting replies, assigning tasks, retrieving the right procedure with its citation; to support you when you ask; to bill you; to diagnose faults and improve the product; and to meet our own legal obligations.
Where the law requires a legal basis, ours is the contract with you, our legitimate interest in running and securing a service you asked for, your consent where we have asked for it, and compliance with law.
What we do not do
We do not sell your data and we do not share it with advertisers. We do not use the contents of your workspace — guest conversations, procedures, operational records — to train models for anyone else. Our staff do not look inside your workspace except when you ask us to, or when we have to in order to fix a fault or answer a legal obligation, and that access is logged.
Who processes it with us
We use a short list of providers to run Treema: cloud hosting and storage, model providers for the agent features, transactional email, payment processing, scheduling for the booking calendar, and error monitoring. Each is bound by a data processing agreement and may act only on our instructions. Write to hello@treema.app and we will tell you the current list and where each provider stores data.
Where it lives and how long we keep it
Data is encrypted in transit and at rest, and each workspace's content is kept separate from every other. We hold workspace content for as long as the account is open, and for a limited period afterwards so that an account can be restored and so we can meet legal, tax and accounting obligations. After that it is deleted or de-identified, and backups age out on their own schedule.
Security
Access to production systems is limited to the people who need it and is logged. We use encryption, access control and monitoring proportionate to the data we hold, and we revisit them as the product grows. No system is perfectly secure; if a breach affects your data we will tell you, and the relevant authority where the law requires it.
We do not hold a third-party security certification today. If your procurement process needs one, ask us where we have got to rather than assuming.
Your rights
Depending on where you are, you may have the right to ask for a copy of the personal data we hold about you, to have it corrected or erased, to object to or restrict how we use it, and to withdraw consent you have given. You may also complain to your local data protection authority.
There is no self-serve download in the product. Write to hello@treema.app and a person will handle the request; we may need to confirm who you are before we act on it.
If the request concerns data your hotel holds about a guest, the hotel is the controller of that data. Send it to them, and we will support them in answering it.
Cookies
The site and the product set the cookies they need to work: signing you in, holding your session, remembering your theme and the notices you have dismissed. We do not run advertising trackers. If we add product analytics, this policy will say what we collect and why before it starts.
Children
Treema is a tool for hotel staff. It is not aimed at children and we do not knowingly collect their personal data. If you believe a workspace holds data that should not be there, write to hello@treema.app and we will remove it.
Changes
We update this policy when the way we handle data changes. The current version and its date sit at the top of this page, and where a change is material we tell workspace owners before it takes effect.
Contact
Write to hello@treema.app. Postal correspondence: Private Company "TREEMA TECH LTD", Innovation Hub, DIFC, Dubai, UAE (License number: CL10409). Data protection enquiries go to the same address.