Terms and Conditions Privacy Policy Cookie Policy DPA

Data Processing Agreement (DPA)

Version 1.0 — Last updated: September 15, 2026

This Data Processing Agreement forms an integral part of the agreement between the business customer and QUANTEMI S.R.L. for use of the Rezervatio.AI services and applies whenever Rezervatio.AI processes personal data on behalf of that customer.

1. Parties and definitions

Controller: the business customer using Rezervatio.AI and determining the purposes and means of processing its callers' and end customers' personal data.

Processor: QUANTEMI S.R.L., Romanian company, Tax ID 54694424, Trade Registry no. J2026031979003, registered office at Str. Liniștii no. 8, Năvodari, Constanța County, Romania, operating Rezervatio.AI.

The terms “personal data”, “processing”, “data subject”, “personal data breach” and “supervisory authority” have the meanings assigned by Regulation (EU) 2016/679 (“GDPR”).

2. Subject matter, duration and purpose of processing

2.1 Subject matter

Under the Controller’s instructions, Rezervatio.AI processes its customers’ and staff data for telephone and digital bookings, Business administration, messages, attached photos, notifications and settings. Rezervatio’s own account and personal Book processing is described separately in the Privacy Policy.

2.2 Duration

Processing takes place for the duration of the service agreement and thereafter only to the extent required by the Controller's documented instructions, applicable retention rules or legal obligations.

2.3 Categories of data and data subjects

The categories of data subjects, personal data, operations and purposes are described in Annex I.

2.4 Health data (Art. 9 GDPR)

Health data: allergies, symptoms or the medical reason for an appointment may fall under Article 9 GDPR. Spontaneous disclosure does not remove this protection. Processing requires an Article 6 basis, an Article 9 condition and safeguards established by the controller, with instructions and contractual coverage for that workflow. The agent does not actively request sensitive data. Do not use the service for diagnosis, triage or emergencies.

3. Processor obligations (Rezervatio.AI)

Rezervatio.AI shall:

4. Controller obligations

The Controller shall:

5. Sub-processors (Art. 28(2) and (4) GDPR)

5.1 General authorisation

The Controller grants general written authorisation for the sub-processors listed in Annex III. Rezervatio.AI remains responsible for ensuring that each sub-processor is bound by data-protection obligations materially equivalent to those in this DPA.

5.2 Notice of changes

We will notify the Controller at least 30 days before adding or replacing a sub-processor, by email to the account address and through a dashboard notice.

5.3 Right to object

The Controller may raise a reasoned data-protection objection during the notice period. The parties will seek a reasonable solution; if none is available, either party may terminate the affected service.

5.4 Chain of obligations

Rezervatio.AI shall impose the same material data-protection obligations on each sub-processor and remains accountable to the Controller for the sub-processor's performance.

6. International data transfers

Where personal data is transferred outside the European Economic Area, Rezervatio.AI uses an applicable Chapter V GDPR mechanism, including an adequacy decision, the EU-US Data Privacy Framework for participating organisations, or the European Commission's Standard Contractual Clauses, together with supplementary safeguards where appropriate.

7. Data-subject rights

Rezervatio.AI assists the Controller, taking into account the nature of processing, through:

The Controller remains responsible for assessing and responding to each request within the statutory time limit.

8. Audit and compliance

8.1 Documentation

Rezervatio.AI maintains documentation on security measures, authorised sub-processors and relevant processing operations and will provide appropriate compliance information on request.

8.2 Audit

The Controller may request a compliance audit with at least 30 days' written notice, no more than once per year unless a security incident or supervisory authority requires otherwise. Audits must protect other customers' confidentiality and the security of the service. Reasonable costs may be charged where permitted by law and agreed in advance.

9. End of the agreement

Upon termination, Rezervatio.AI shall:

10. Liability

Contractual limits do not restrict Article 82 GDPR data-subject rights, authority powers or Rezervatio’s Article 28(4) responsibility for sub-processors.

Each party's liability for GDPR infringements is governed by Art. 82 GDPR. As between the parties, each party bears fines, sanctions and damages arising from its own infringements. General contractual liability limits are those stated in the Terms and Conditions.

11. Amendments

This DPA may be amended by written agreement. Rezervatio.AI may notify minor changes that do not reduce the level of protection at least 30 days in advance. Material changes affecting the Controller's rights require acceptance or another valid contractual mechanism.

12. Governing law and jurisdiction

This DPA is governed by Romanian law and GDPR. Disputes shall first be addressed amicably and, failing resolution, submitted to the competent Romanian courts, without prejudice to data subjects' rights and supervisory-authority powers.

Annex I — Processing details

ItemDescription
Data subjectsCallers, end customers, patients, restaurant guests, salon or vehicle-service customers, and the Controller's authorised staff
Personal dataName, phone number, optional email, audio-conversation content and transcript, booking details (date, time, party size, service and notes), and technical call data (duration and quality)
Special-category dataHealth information that a caller may disclose spontaneously in a medical context; the Controller determines the applicable Art. 9 condition
Nature of processingCollection, recording, transcription, structuring, storage, transmission, deletion and anonymisation
PurposeProviding and supporting the automated booking and communication service
DurationFor the term of the service and any applicable documented retention period

Annex II — Technical and organisational measures (Art. 32 GDPR)

Technical measures

Organisational measures

Incident notification

Rezervatio.AI will notify the Controller without undue delay after becoming aware of a personal data breach affecting data processed on the Controller's behalf and will provide available information necessary for the Controller's obligations under Arts. 33 and 34 GDPR.

Annex III — Authorised sub-processors

Sub-processorLocationPurposeTransfer mechanism
Hetzner Online GmbHGermany, EUPrimary infrastructure, backend services and database hostingEEA processing
Cloudflare Inc.United States / global infrastructureSecurity, DDoS and abuse protection, content deliveryDPF and/or SCCs, as applicable
Scaleway SASFrance, EUTransactional and operational emailEEA processing
Telnyx LLCUnited States; services also available in the EEA depending on configurationTelephone numbers, call routing and SMSDPF and/or SCCs, as applicable
ElevenLabs Inc.United States / infrastructure under the applicable configurationConversation processing for the AI voice agentDPF and/or SCCs, as applicable

Provider compliance information: ElevenLabs · Telnyx · Cloudflare.

Contact

QUANTEMI S.R.L.
Data protection: privacy@rezervatio.ai
General contact: contact@rezervatio.ai

Last updated: September 15, 2026 — Version 1.0