R RoomRota
How it works Features Pricing Contact
Sign in Set up your centre

Terms of Service

Last updated: 2026-08-28. Includes Schedule 1 — Data Processing Terms, our GDPR Article 28 processing agreement.

These terms govern your use of RoomRota, a room-booking service operated by Built-By-Bobby (“we”, “us”), by the community centre or organisation that signs up (“you”, “the Centre”). They are separate from the Terms of Hire between a Centre and the people who book its rooms.

1. What RoomRota is

RoomRota is software that lets the Centre publish a booking page, take bookings, manage recurring hires, and optionally accept card payments. RoomRota is a tool you use to run your own bookings — we are not a party to the hire contract between you and your hirers, and we are not the organiser, owner, or operator of your premises or events.

2. Your responsibilities

You are the data controller for the bookings you collect, and we are your processor. The terms on which we process that data for you are set out in Schedule 1 (Data Processing Terms) at the end of this page, which forms part of these terms and is the written contract required by Article 28 of the GDPR. You do not need to sign anything separate. You are responsible for the accuracy of your pricing and availability, for your own Terms of Hire and Privacy Notice shown to hirers, and for complying with the laws that apply to running your centre.

3. Payments and money

Card payments are optional. If you enable them, they run through your own Stripe account, which you connect during setup and for which you accept Stripe’s Connected Account Agreement directly with Stripe. This means:

  • You are the merchant of record. Payments settle directly to your bank account. RoomRota never holds, receives, or controls your funds.
  • You are responsible for refunds, chargebacks, disputes, and any negative balance on your Stripe account, in accordance with your agreement with Stripe. RoomRota is not liable for these.
  • The non-refundable booking fee and your cancellation policy are set out in your own Terms of Hire and shown to hirers before they pay.

4. Subscription and fees

RoomRota is free to set up and comes with a 30-day free trial, with no card required. Paid plans begin only when you choose to subscribe: €50 billed monthly, €135 billed every 3 months, or €499 billed yearly. Each subscription renews automatically for the same billing period until cancelled. You can cancel future renewal at any time; access continues until the end of the period already paid for. Except where the law requires otherwise, fees already paid are not refundable. Fees are exclusive of any VAT that may apply.

What happens if a subscription goes unpaid is set out in section 5 below.

5. If a subscription goes unpaid

We would rather remind you than switch anything off, and we know a centre run by a committee may need to wait for a meeting before it can authorise a payment. So nothing happens immediately, and every step is preceded by an email to your registered address on the day it takes effect. Counting from the day payment first becomes overdue:

  • Days 1–14. Nothing changes. Your booking page and your admin both work as normal. We email you.
  • Day 15. Your admin panel is locked. Your public booking page stays live and keeps taking bookings.
  • Day 31. Your public booking page stops accepting new bookings. It remains readable.
  • Day 60. Your public booking page is replaced by your centre’s contact details.

Bookings already in your calendar are never cancelled, hidden from the people who made them, or deleted at any stage, including recurring bookings. The people who booked your rooms can always still see and cancel their own bookings, whatever the state of your subscription. None of your data is deleted for non-payment.

Paying restores everything immediately and in full, from any stage. Nothing on your public pages tells your hirers or the public that the cause is a billing matter.

If a payment fails for a reason you did not intend — an expired card, a bank block — contact us and we will work it out with you rather than run the clock down.

6. Availability

We work to keep RoomRota available and backed up, but we provide the service “as is” and do not guarantee uninterrupted availability. We may carry out maintenance and will try to minimise disruption.

7. Your data and ending the service

Your data remains yours. You can export your bookings at any time (CSV) from your admin dashboard. You may close your account at any time; the exact windows for exporting and for deletion are set out in Schedule 1, section H, and we keep only what the law requires us to keep. We may suspend or end an account that misuses the service; for non-payment, the stages in section 5 apply.

8. Our liability

Nothing in these terms limits liability that cannot be limited by law (such as for death or personal injury caused by negligence, or fraud). Subject to that, we are not liable for your hirers’ bookings, for payment disputes between you and Stripe or your hirers, or for indirect or consequential loss; and our total liability to you in any 12-month period is limited to the fees you paid us in that period.

9. Changes and governing law

We may update these terms; the “last updated” date shows when, and we will notify you of material changes by email. These terms are governed by the laws of Ireland and subject to the exclusive jurisdiction of the Irish courts.

Questions about these terms: [email protected].


Schedule 1 — Data Processing Terms

This Schedule forms part of the Terms of Service above. It is the written contract required by Article 28(3) of the GDPR, and it takes effect when you accept the Terms at sign-up — there is nothing separate for you to sign. If you need to show your committee, your funder, or your insurer that you have a data-processing agreement with your booking provider, this is it, and you can link them straight to it.

It covers the data your hirers give you, where you are the controller and we are your processor. It does not cover your own administrator account data — there we are the controller, and our Privacy Policy explains what we do. Where this Schedule and the rest of the Terms disagree on a data-protection question, this Schedule wins.

A. What we process, and why

  • Subject matter and duration. Providing the RoomRota booking service to you, for as long as your account is open, plus the deletion period in section H.
  • Nature and purpose. Storing, organising, displaying and transmitting booking data so that you can take and manage room bookings, send confirmations and reminders, and (if you enable it) take payment.
  • Type of personal data. Hirer name, email address, phone number, the booking itself (room, date, time, purpose), any notes you or the hirer add to it, and payment status. Card details never reach our servers — they are entered directly on Stripe.
  • Categories of data subject. People who book rooms at your centre, and anyone you record as a contact for a booking.

RoomRota is not built for special category data (health, religion, trade union membership, and so on) and you should not enter it into booking notes.

B. We act only on your instructions

We process your booking data only on your documented instructions — which are these Terms, this Schedule, and the ordinary use you make of the service through your admin panel. We do not use it for our own purposes, we do not sell it, and we do not use it for advertising or to train anything. If EU or Irish law ever requires us to process it otherwise, we will tell you before we do, unless that law forbids us from telling you. If we think an instruction from you would breach data protection law, we will say so.

C. Confidentiality

Access to your data is limited to the people who need it to run and support the service, each of whom is under a duty of confidentiality that survives the end of their involvement. RoomRota is currently operated by one named individual; if that changes, anyone added is placed under the same written obligation before being given access.

D. How we keep it safe

The measures we have in place (Article 32) are:

  • All traffic to and from the service is encrypted in transit using TLS.
  • The application and database are hosted in the EU (Germany); backups are held in the EU (France).
  • Every centre’s data is separated by a tenant identifier applied to every database query, so one centre cannot read another’s. This is covered by our automated test suite.
  • Administrator passwords are stored only as salted scrypt hashes and are never recoverable in readable form, by us or anyone else.
  • Sign-in is protected by rate limiting and by one-time codes sent to the registered email address.
  • Forms are protected against cross-site request forgery, and the site runs a strict content security policy.
  • The database is backed up continuously to off-site object storage, encrypted in transit and at rest by the storage provider, with a maximum exposure of roughly 30 seconds of data.
  • Card details are handled entirely by Stripe and never touch our servers or our database.

We may change these measures as the service grows, provided the level of protection is not reduced.

E. Sub-processors

You give us general authorisation to engage the sub-processors listed in our Privacy Policy — currently Hetzner (Germany, hosting), Scaleway (France, backups), Stripe (Ireland, payments) and Brevo (France, email). Each is engaged under written terms no less protective than this Schedule, and we remain fully liable to you for what they do.

We will give you at least 30 days’ notice by email before adding or replacing one. If you object on reasonable data-protection grounds, you may cancel without penalty and we will refund any unused prepaid fees.

F. Helping you answer your hirers

Your admin panel lets you find, correct, export (CSV) and delete a hirer’s booking data yourself, which answers most access, correction, portability and erasure requests without needing us at all. If a request needs more than the panel can do, tell us and we will help within a reasonable time, at no charge. If a hirer contacts us directly about data held for your centre, we will not answer on your behalf — we will point them to you and let you know they came to us.

G. If something goes wrong

If we become aware of a personal data breach affecting your data, we will notify you without undue delay, and in any event within 48 hours, by email to your registered address. We will tell you what we know: what happened, the categories and approximate number of people and records involved, the likely consequences, and what we are doing about it — and we will keep you updated as we learn more.

Reporting to the Data Protection Commission within 72 hours, and telling your hirers where that is required, is your decision and your duty as controller. We will give you what you need to make it. We will also help you, so far as we reasonably can and taking account of what we know, with any data protection impact assessment or prior consultation you have to carry out.

H. Getting your data back, and deleting it

You can export your bookings as CSV from your admin panel at any time, including during the wind-down stages in section 5 of the Terms.

When your account ends, you have 30 days in which to export. After that we delete your data from live systems within 30 days, and it ages out of our backups within a further 30 days — so it is gone within 90 days of your account ending, at the latest. If you would rather we deleted it sooner, ask us and we will. We keep only what the law obliges us to keep, such as invoicing records, and we keep those only for that purpose.

I. Audits, and showing our working

On request and free of charge, we will give you the information you reasonably need to satisfy yourself that we are meeting our obligations under Article 28.

If that is not enough, you (or an independent auditor you appoint, who must not be a competitor of ours) may audit us once in any 12-month period, on 30 days’ written notice, during business hours, in a manner that does not disrupt the service, and at your own cost. You may audit more often, and at our cost, if we have suffered a breach affecting your data or a supervisory authority requires it. Anyone carrying out an audit must keep what they see confidential.

J. Sending data outside the EEA

Your booking data is stored in the EU and backed up in the EU. We will not transfer it outside the EEA without a lawful transfer mechanism in place. The one exception today is Stripe, which may transfer limited technical data to the USA under the EU–US Data Privacy Framework and EU Standard Contractual Clauses — and that only applies if you switch card payments on.

K. Liability

Nothing in this Schedule changes the liability position in section 8 of the Terms, and nothing in section 8 limits any liability that the law does not permit us to limit — including liability to a data subject under Article 82 of the GDPR.

Schedule 1 last updated: 2026-08-28.

R RoomRota

Online room booking, built for Irish community centres and halls.

Product How it works Features Pricing The full walkthrough
Get started Set up your centre Contact us
© RoomRota. Made in Ireland for community halls. Privacy · Terms [email protected]