Legal

Privacy

Last updated 30 September 2026

Version 1.0. Effective 30 September 2026. This policy explains how FOSIA LTD, trading as Hodi ("Hodi", "we"), handles personal data on hodistay.com and any channel we add. It is part of our Terms.

1. Who is responsible

FOSIA LTD (Kigali, Rwanda) is the controller of the personal data we collect to run accounts, bookings, safety and the Platform. Our data protection contact is our privacy contact at info@hodistay.com. When a Host receives a Traveller's details for a stay, the Host becomes an independent controller of those details and answers for how it uses them.

2. The data we handle

  • Account data: email address, name, phone number, language, and for Hosts and Agencies the business name, city, profile, licence details, team members' emails and roles.
  • What you ask and say: your search requests and messages to Hodi (dates, budget, area, guests, preferences), your messages to a Host through Hodi, and, if you use them, voice recordings and photos you send.
  • Booking data: requests, confirmations, dates, prices, payment status and references, cancellation and dispute records, reviews and stay reports.
  • Host content: listings, photos (location data is removed), videos, calendars and calendar links, prices, rules, guest book entries, owner details and statements for Agencies, billing records.
  • What Hodi remembers: preferences and suggestions kept to personalise your use. You can see and erase them in your account.
  • Technical data: browser and device information, IP address, security and error logs, and a random session identifier stored in your browser.
  • Location: only if you use "near me" and your browser lets us, and only to answer that request.
  • Measurement: audience and campaign data collected with cookies and similar tools, only after you accept them (see section 9).
  • Team activity: what our staff do in the admin tools is logged for security and audit.

We record how much AI a use costs (counts), not the content, to control costs.

3. Why we use it, and on what basis

  • To create and run your account and to find, request, confirm and manage stays: to perform our contract with you.
  • To keep the Platform safe and to prevent fraud, abuse and circumvention of fees: our legitimate interest in a safe and sustainable service, and legal duties.
  • To provide support, resolve disputes, keep records, invoice and account for tax: contract, legal duty and legitimate interest.
  • To improve and measure the service, in aggregate and with limits: our legitimate interest, and your consent where the law or the tool requires it (analytics, marketing).
  • To send booking messages, reminders you turn on and, if you agreed, invitations to return: contract, and your consent for optional messages. You can withdraw consent at any time.
  • To comply with the law and requests from authorities: legal duty.

Where the law of your country requires a different basis, we apply that one.

4. Who sees it

  • The Host or Traveller you book with. A Host sees your name and, once the stay is confirmed, your email and phone. Before confirmation, contact details are hidden on both sides.
  • Our team, when needed for support, safety and quality, limited by role and logged.
  • Service providers who work for us under contract and process data only on our instructions: hosting and infrastructure, email and messaging, payment and billing, maps and location, measurement, and AI providers that help us understand requests and write replies. We keep a register of providers and will share the names of those that handle your data when you ask.
  • A Host's own AI assistant, if the Host connects one through Hodi MCP. It can read that Host's places, bookings and guest book, with travellers' first names only. Travellers' contact details are never sent to it.
  • Authorities, courts and advisers when the law requires or to protect rights, and a buyer or successor of our business under the same protection.

We do not sell personal data. We do not let AI providers train their models on your content: we use them through commercial interfaces whose terms exclude training on our data, and we do not use consumer chat applications for user data. Providers may keep inputs for a limited period to detect abuse.

5. AI and automated decisions

Hodi uses AI to understand requests, rank places, draft listings and answer questions. A person reviews listings before they go live and confirms bookings. We do not take a decision that has a legal or similarly significant effect on you based only on automated processing. Automatic answers a Host has switched on, such as replying to price offers within the Host's limits, are the Host's own setting. You can ask for a person to look at any decision that concerns you.

6. Where data goes

Some of our providers, including AI and infrastructure providers, are outside Rwanda, and some of your data may be processed there. We transfer or store data outside Rwanda only as the law allows and with the authorisations and safeguards it requires. If you live in the European Economic Area, the United Kingdom or another region with transfer rules, we use the lawful transfer tools those rules require.

7. How long we keep it

  • Account data: while your account is open, then deleted or anonymised within 90 days, except what we must keep.
  • Conversations that did not lead to a booking: 12 months, then deleted or anonymised.
  • Booking, payment and invoice records: 7 years, or as the law requires.
  • Security and audit logs: 12 months.
  • Data we must keep for a dispute or a legal claim: until it ends.

You can ask for earlier deletion; we will tell you if we must keep something and why.

8. Your rights

You may ask to access, correct, export or delete your data, to restrict or object to some uses, to withdraw consent, and to ask that a person review an automated result. Use your account (History, What Hodi remembers, Delete account) or write to info@hodistay.com. We answer within 30 days. We may need to check who you are first. You may also complain to the data protection authority: in Rwanda the National Cyber Security Authority (NCSA); if you live elsewhere, the authority of your country.

9. Cookies and similar tools

We use a small set of essential items to make the Platform work: a random session identifier, your language and your cookie choice. Measurement and marketing tools (audience statistics and advertising measurement) load only after you accept them in the banner, and you can change your mind at any time from the link in the footer. Our aggregate usage statistics that identify no one do not need a cookie.

10. Security

We protect data with measures suited to the risk, including encryption in transit, limited access by role, one-time codes stored only in hashed form, separated access for staff and Hosts, and activity logs. No system is perfectly secure. If a breach puts you at risk and the law requires notice, we will tell you and the authority as required.

11. Children

Hodi is for people aged 18 and over. We do not knowingly collect data from children. If you think a child has given us data, write to info@hodistay.com.

12. Changes

We may update this policy. For a material change we will give notice before it applies, and each version is dated. Earlier versions are available on request.

13. Contact

FOSIA LTD, trading as Hodi, Kigali, Rwanda, info@hodistay.com.