Switching and data portability
Your data, on your way out
If you move to another provider, move to your own systems, or simply want your data, this page tells you exactly how — what you can take, in what format, how long you have, and what it costs. It costs nothing.
This page is the switching and porting information we publish under Article 26 of Regulation (EU) 2023/2854 (the EU Data Act), and it is the page section 17 of our terms and conditions refers to. It describes what Vivestay can do today, not what it may do later.
How to start
Write to hello@vivestay.com. Tell us whether you are exporting, moving to another provider, moving to your own systems, or asking us to erase your data. That is the whole procedure — there is no form to complete and no notice you must serve first.
You may also simply export the data yourself at any time using the interface described below, without telling us anything.
What you can take
Your exportable data — what you and your guests put into Vivestay, what the service produced from it, and the metadata needed to make sense of it:
- your organisation and its settings;
- your properties and their configuration, including compliance settings;
- your users, their roles, and the record of invitations and membership changes;
- your reservations and stays;
- your guest registration records, including the audit history of who entered or amended each field and when;
- your reporting tasks, their submissions and their outcomes;
- your integration connections and their sync history;
- your legal acceptances;
- your billing records.
What you cannot take, and why
Our software and source code, our internal configuration, our security-sensitive internals, credentials belonging to us or to a third party, our operational and diagnostic records about running the platform, and anything a third party licenses to us. None of it is your data, and withholding it does not slow your switching down.
We do not promise to reproduce Vivestay at another provider. What we owe you is your data and reasonable help moving it — not a working copy of our service somewhere else. If you are moving to another compliance product, the work of configuring it is theirs and yours, not ours.
Format, structures and interface
Exportable data is available as JSON, over HTTPS, from our authenticated REST interface at app.vivestay.com. It is available to every customer on the same terms and there is no charge for using it.
Each category above is a resource collection, and each is retrieved from its own endpoint — for example organisations, properties, reservations, stays, registration sessions and their audit records, reporting tasks, integration connections and their sync runs, and legal acceptances. Collections are paged. Access uses an API client that an administrator of your organisation can create in the console, under the same permissions that govern the rest of your account.
The authoritative structure of a resource is the JSON that endpoint returns. A machine-readable description of the interface is published at app.vivestay.com/openapi.json as supporting technical documentation. It is useful, and it is not exhaustive: it is maintained by hand and does not yet describe every route. Where it is silent, ask us — we will give you the field-level structure of any exportable resource in writing, and we will not treat a gap in that document as a reason you cannot have your data.
Standards. No common specification or harmonised standard for accommodation-compliance data has been published in the European Commission’s central repository. There is therefore none for us to conform to today. If one is published, we will support it within the period the law allows, and this page will say so.
Known limitations
Stated plainly, because finding them out mid-migration is worse:
- There is no one-click download. Export is per resource collection through the interface above, or an export we produce for you on request. There is no single archive file and no export screen in the console.
- Results are paged. A large account is retrieved in pages rather than in one response.
- Access is authenticated. You need an active account or an API client, which is why exporting before you close your organisation is much easier than afterwards.
- Data already erased cannot be exported. Guest registration records are deleted at the end of their retention period, and a record that has been erased is gone for everyone, including you.
- We do not import. Vivestay has no inbound migration from another provider — no importer, no adapter, no wizard. This page is about leaving, and about getting your data out.
How long it takes, and how long you have
These periods are the ones in section 17 of our terms and conditions:
- Notice. You do not have to give notice before starting, and we never require more than one month.
- Transition. Up to 30 calendar days from your request, during which we keep the service running as it was and help you get your data out. You may extend it once, for a period you consider appropriate. If we cannot finish in 30 days for technical reasons we will tell you why within 14 working days and propose a longer period of up to seven months.
- Retrieval. Your exportable data stays retrievable for at least 30 calendar days after the transition ends, or after your organisation is closed, whichever is later. You may agree a longer period with us.
- Erasure. After the retrieval period we erase your exportable data, except where the law requires one of us to keep it. Guest registration records under a statutory retention period are the ordinary case. We will never use data we are legally obliged to keep as a reason to delay or refuse your switching.
If you have already closed your organisation
Closing an organisation removes access for every user and every API key immediately, so you cannot fetch anything yourself afterwards. Your data is not deleted. Write to hello@vivestay.com within the retrieval period, from an address we can verify against the account, and we will produce the export for you.
What it costs
Nothing. There is no switching fee, no export fee, no early-termination penalty for switching, and no charge for the help described on this page. Your ordinary subscription fees for the period you are still using the service are unaffected.
Where Vivestay runs, and protection against foreign government access
This section is the information Article 28 of the EU Data Act requires us to publish and keep current. It concerns non-personal data held in the Union in particular, though the measures described apply to everything we hold.
The jurisdiction our infrastructure is subject to
The information and communications technology infrastructure used to deliver Vivestay and this website is operated within the European Economic Area (EEA), and is subject to the jurisdiction of the EEA state in which it is operated. We do not move customer data outside that footprint to make our own operations easier, and any restricted international transfer would require an appropriate Chapter V mechanism to be in place first.
This statement is deliberately made at EEA level rather than naming a single Member State or a particular facility. Vivestay is infrastructure-portable: we may move workloads between EEA locations for resilience, capacity or cost, and a disclosure tied to one site would either constrain that or go out of date without anyone noticing — which is the opposite of the “keep current” duty this section exists to satisfy. The commitment that matters is the one stated above: the footprint stays inside the EEA. If that ever ceases to be true, this page changes before it happens.
What we do to prevent unlawful international government access
A general description, as the Regulation asks for — not an architecture description, which would weaken the protection it is meant to demonstrate:
- Technical. Traffic is encrypted in transit and secrets are held encrypted at rest under managed keys. Separation between customer organisations is enforced at the database level rather than only in application code. Access to production systems is limited to named accounts, and significant actions leave an immutable audit record. We minimise personal data in operational logs and do not intentionally record guest-registration identity or document content in ordinary application logs; technical metadata such as the network address a request came from may be processed where that is necessary to operate and secure the service, and is covered by the connection-data section of our privacy policy.
- Organisational. No government or authority has standing, routine or direct access to Vivestay systems or data, and none is provided with a facility for it. Any request from an authority is handled by named staff and assessed before anything is disclosed: whether the requesting body has jurisdiction over us, whether the request is lawful and binding on us, and whether complying would conflict with Union or Member State law. Where it would, we do not comply voluntarily — we challenge or refuse the request through the routes available to us. We disclose no more than a lawful and binding request actually compels.
- Contractual. Under our data processing agreement we process personal data only on the customer’s documented instructions, and where a law requires us to process it otherwise we inform the customer before doing so unless that law prohibits it. Any party we engage to process data on a customer’s behalf is bound by written terms imposing equivalent obligations, and those obligations flow down. No restricted international transfer takes place without an appropriate Chapter V mechanism in place first.
If a request ever results in a disclosure, we will tell the affected customer to the fullest extent the law allows us to.
Questions
Write to hello@vivestay.com. If you are evaluating Vivestay and want to see the shape of an export before you commit, ask — we would rather show you.