Terms and Conditions Privacy Policy Cookie Policy GDPR

Privacy Policy

Version 2.1 — Last updated: September 15, 2026

This Privacy Policy describes how QUANTEMI S.R.L. ("Rezervatio", "we") collects, uses, stores, shares and protects personal data, in accordance with the General Data Protection Regulation (GDPR — EU Regulation 2016/679), Romanian Law no. 190/2018 and applicable legislation.

This policy applies to Users (business owners using the platform), End Customers (persons who call and interact with the AI voice agent), and Rezervatio Book app users (customers who make reservations directly through our mobile app).

1. Identity of the Controller / Processor

Name: QUANTEMI S.R.L.
Tax ID (CUI): 54694424
Trade Registry No.: J2026031979003
Registered office: Năvodari, Jud. Constanța, Str. Liniștii nr. 8
General email: contact@rezervatio.ai
Data protection email (DPO): privacy@rezervatio.ai
Website: www.rezervatio.ai

1.1 GDPR Roles

Rezervatio is controller for Book accounts and personal features, website visitors and demos. The selected business is a separate controller for the booked service, its customers and staff. Rezervatio acts as processor when hosting and managing this data in Business, including bookings, messages, photos and calls, under the business’s instructions and the DPA.

ContextRezervatio RoleExplanation
User data (account, billing)Data ControllerRezervatio decides the purpose and means of processing the User's account data
End Customer data (reservations, calls)Data ProcessorRezervatio processes End Customer data on behalf of and in accordance with the instructions of the User (the controller)

1.2 Data-protection contact

For questions or rights requests: privacy@rezervatio.ai. We respond without undue delay and within one month of receiving the request under Article 12(3) GDPR. Complexity or the number of requests may justify two additional months; we explain the extension during the first month.

2. Personal Data We Collect

2.1 User Data (business owners) — Rezervatio as Controller

CategorySpecific DataPurposeLegal Basis
Account and authenticationFirst name, last name, email address, password (cryptographic hash)Account creation, authentication, communicationPerformance of contract — Art. 6(1)(b)
Business dataBusiness name, address, phone, email, business sector, Tax ID (optional)AI agent configuration, service personalizationPerformance of contract — Art. 6(1)(b)
Operational configurationOperating hours, zones, tables/seats, agent preferences, custom messagesProper operation of the reservation servicePerformance of contract — Art. 6(1)(b)
Billing dataCard data (processed exclusively by a certified payment processor — Rezervatio does not store card numbers), billing address, Tax IDPayment processing, invoicingPerformance of contract — Art. 6(1)(b) + Legal obligation — Art. 6(1)(c)
Usage dataMinutes consumed, number of calls, dashboard activity logsBilling, statistics, service improvementPerformance of contract — Art. 6(1)(b) + Legitimate interest — Art. 6(1)(f)
Technical dataIP address, browser type, operating system, pages accessedSecurity, troubleshooting, fraud preventionLegitimate interest — Art. 6(1)(f)

2.2 End Customer Data (callers) — Rezervatio as Processor

Health data: allergies, symptoms or the medical reason for an appointment may fall under Article 9 GDPR. Spontaneous disclosure does not remove this protection. Processing requires an Article 6 basis, an Article 9 condition and safeguards established by the controller, with instructions and contractual coverage for that workflow. The agent does not actively request sensitive data. Do not use the service for diagnosis, triage or emergencies.

CategorySpecific DataPurposeLegal Basis (of the User)
Reservation dataFirst name, last name, phone number (caller ID), email (optional), number of personsCreating, managing and confirming the reservationLegitimate interest of the business — Art. 6(1)(f) or Consent — Art. 6(1)(a)
PreferencesFood allergies, special occasions, special requests, preferred zonePersonalizing the experience, food safetyThe business establishes an Article 6 basis and an Article 9 condition for health data.
Voice dataVoice in real-time (processed via streaming, not stored as audio file on Rezervatio servers), text transcript of the conversationUnderstanding and processing the reservation request via the AI agentLegitimate interest — Art. 6(1)(f)
Call metadataCaller phone number (caller ID), called number, call duration, date and time, session identifierBilling the User, statistics, technical support, auditPerformance of contract with the User — Art. 6(1)(b) + Legitimate interest — Art. 6(1)(f)
Important regarding voice data: The conversation is processed through ElevenLabs so that the AI voice agent can operate. Rezervatio.AI does not retain the audio file or full transcript in its own database; it may retain call metadata and an operational summary. The voice provider may process and temporarily retain audio, transcripts and technical data under the service configuration, contractual agreement and its own privacy policy. Retention details may be requested at privacy@rezervatio.ai.
Important — special-category data (Art. 9 GDPR): In the context of medical clinics or dental practices, phone conversations or bookings made with healthcare providers may incidentally reveal health information (symptoms, reason for visit). The AI voice agent is instructed not to explicitly request such data — in particular, it no longer asks about allergies. If the caller mentions it on their own initiative, it is processed strictly for managing the reservation and benefits from the same security measures as all other data.

2.5 Demo Call (unauthenticated visitor)

When you initiate a demo call from the homepage ("Call me" form):

CategorySpecific DataSource
Call identificationPhone number, IP address, timestampVisitor (manual input)
Anti-abuseTemporary OTP code (SMS, valid 10 minutes), Cloudflare Turnstile tokenGenerated automatically to verify number ownership

Legal basis: explicit consent (Art. 6(1)(a) GDPR). You grant permission by pressing "Call me" and entering the OTP code received via SMS.

Sub-processors: the same as for the entire platform — see section 5 (Telnyx for telephony/SMS, ElevenLabs for AI voice processing, and Cloudflare for Turnstile bot protection).

The voice conversation is processed through ElevenLabs. Rezervatio systems may retain metadata, transcripts/summaries and booking results; the voice provider manages the audio file. Provider audio/transcript retention is configured to 30 days with periodic deletion. For details about a call: privacy@rezervatio.ai.

Demo-specific retention: demo requests are cleaned after 30 days; OTP codes expire in 10 minutes and related records are cleaned after 24 hours.

Your rights: request deletion of demo data at privacy@rezervatio.ai. We handle the request without undue delay, within the time limit and conditions in section 8.

2.3 Data collected from Rezervatio Book app users

Users who create an account in the Rezervatio Book mobile app to book directly (without a phone call):

CategorySpecific data
Account identificationPhone number (OTP login); name is required at first login; email (if you sign in with Google or Apple)
Own reservationsHistory of reservations made via the app, status, notes
Reservation messagesContent of messages exchanged with the business in connection with a reservation. Deleted when the account is deleted. Basis: performance of the contract (Art. 6(1)(b)).
FavoritesBusinesses / specialists saved as favorites
Push notificationsDevice token and content needed to deliver notifications about bookings and selected features. Notifications can be disabled in settings. Device permission does not automatically authorise marketing; any required marketing consent is obtained separately.
LocationOptional, with device permission: coordinates are transmitted to search for nearby businesses and content. You may select a location manually.
CameraThe camera can scan a business QR code locally. The camera and photo library, where available, also allow voluntary booking attachments. Selected photos are uploaded when you submit the request and are accessible to the recipient business and authorised participants; they are not published and the whole photo library is not transmitted.
CalendarWhen you choose “Add to calendar”, the app accesses the calendar list/default calendar to add the booking and can remove the entry on request. Other events are not sent to Rezervatio. Calendar syncing depends on your provider and settings.
Usage dataLogin IP addresses, device, operating system
ConsentsAcceptance of the Terms is recorded with the document version and date; the Privacy Policy describes processing. Choices for optional purposes are separate and can be withdrawn.

2.4 Data collected automatically from website visitors

Optional website visit statistics are sent only after Analytics consent. The function may retain the page, referring domain, country, browser information, a daily hash and the raw IP. The retention routine removes raw IPs older than 30 days; it does not erase the entire statistics history. The hash is pseudonymous, not anonymous. You may withdraw consent through Cookie preferences; see the Cookie Policy. Technical data needed for security and authentication is processed separately.

3. Legal Basis for Processing (Art. 6 GDPR)

Article 6(1)(b) concerns a contract with the data subject; administering company representatives’ relationship and access relies on legitimate interest, Article 6(1)(f). The business establishes the basis for its customers’ data; our B2B contract alone is not that basis. Optional website statistics rely on separate consent, Article 6(1)(a).

Legal BasisGDPR ArticleApplicability
Performance of contractArt. 6(1)(b)Providing services to Users under the chosen subscription; processing reservations
Legitimate interestArt. 6(1)(f)Service improvement, fraud prevention, security, aggregated statistics, technical support
ConsentArt. 6(1)(a)Marketing communications (newsletter, promotions) — optional, with the possibility of withdrawal at any time
Legal obligationArt. 6(1)(c)Tax and accounting compliance (retention of invoices for 5 years under the general rule in Article 25 of the Accounting Law per the Tax Code), responding to authority requests

4. How We Use the Data

We use personal data exclusively for:

We do not sell personal data or use it for behavioural advertising. Automated booking rules and the right to request human review are described in section 8.7.

5. Providers and data recipients

We do not sell or rent your data. We use specialised providers that may act as processors, sub-processors or, for certain operations of their own, independent controllers. Their role depends on the service and the applicable contractual terms. When Rezervatio acts as a processor for a business customer, the relevant sub-processors are listed in the DPA.

ProviderPossible roleHead office / processing regionsPurpose
Hetzner Online GmbHProcessor / sub-processorGermany, European UnionHosting the primary infrastructure, backend services and databases managed by Rezervatio
Cloudflare Inc.Processor / sub-processor; controller for certain services of its ownUnited States / global infrastructureSecurity, DDoS and abuse protection, content delivery and traffic management
Scaleway SASProcessor / sub-processorFrance, European UnionTransactional and operational emails, including confirmations, invitations and account notices
Telnyx LLCProcessor / sub-processorUnited States; services also available in the EEA depending on configurationTelephone numbers, call routing and SMS delivery
ElevenLabs Inc.Processor / sub-processorUnited States / infrastructure under the applicable configuration and agreementConversation processing for the AI voice agent: speech recognition, voice-response generation and technical transcription
StripeProcessor and/or independent controller, depending on the operationIreland / United States, depending on the contracting entityPayments, subscriptions and fraud prevention when the service is enabled
Apple Inc.Service provider and independent controller for its own operationsUnited States / global infrastructureSign in with Apple and push-notification delivery to Apple devices
Google Ireland Limited / Google LLCService provider and independent controller for its own operationsIreland / United States, with global infrastructureGoogle sign-in and Android notification delivery through FCM.
Expo / 650 Industries, Inc.ProcessorUnited States / global infrastructureRelaying Book and Business notifications to Apple/Google; EAS services for app and update distribution.

Actual processing regions may vary by service and configuration. International transfers use the applicable legal mechanisms described in section 6. The sub-processors used when Rezervatio acts for a business customer are listed in the Data Processing Agreement (DPA).

5.1 Notice of sub-processor changes

The Controller (B2B User) will be notified at least 30 days before the addition or replacement of a sub-processor, in accordance with Art. 28(2) GDPR.

6. International Transfers

Core platform data is hosted in the European Union. Some providers operate globally or in the United States. For those transfers we use an applicable Chapter V GDPR mechanism, including the EU-US Data Privacy Framework for participating organisations and/or the European Commission's Standard Contractual Clauses, together with supplementary safeguards where appropriate. Telnyx offers European processing options; ElevenLabs voice processing currently uses global infrastructure subject to the applicable contractual safeguards.

7. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected or as required by law:

Data TypeRetention PeriodJustification
User account (active)For the entire duration of the active accountNecessary for service provision
Reservations and related operational data12 months after the date of a completed/cancelled/no-show booking; future bookings do not expire before serviceReduction of booking identifiers; deletion of associated messages, history and photos. The business’s own customer records have separate purposes and retention.
Call metadata and summaries12 monthsDeletion or anonymisation under the applicable policy
Full audio and transcripts processed by the AI voice provider30 days for audio/transcripts, with periodic provider deletionDeletion under provider settings and procedures; details available on request
Technical and security data, including IP addresses and logsStatistical visits: 90 days, raw IP: 30 days; call sessions/webhooks: 30 days; SMS: 6 months. Other security logs: until incident resolution and expiry of justified need.Deletion, truncation or anonymisation, as applicable
Account after a confirmed deletion request7 days (access-restoration grace period)Afterwards, the active identity is removed and operational data is deleted or anonymised, subject to legal exceptions
Consent, export and deletion-request recordsExport logs: 12 months; closed deletion requests: 5 years; acceptance/consent history: at most 5 years, retaining the latest status while the account relies on itRestricted access; deletion when no longer necessary or legally required
Billing and tax dataGenerally 5 years from 1 July of the year following the financial year; other legal duties may require separate periodsLegal obligation — Tax Code, Accounting Law
Demo calls (phone, IP and anti-abuse data)30 daysDeletion or anonymisation under the operational procedure
Demo OTP codesValid for 10 minutes; records cleaned after 24 hoursInvalidation at expiry and subsequent cleanup

We apply technical and organisational deletion or anonymisation procedures. You may request the criteria applicable to a specific category of data at privacy@rezervatio.ai.

8. Your Rights (Art. 15-22 GDPR)

As a data subject, you have the following rights, exercisable free of charge:

8.1 Right of Access (Art. 15)

The JSON export available in the account can be supplemented on request with photos and other personal data absent from that file, while protecting other people’s rights.

You may request confirmation that we process personal data concerning you and a copy of such data, together with information on the purpose, categories, recipients and retention periods.

8.2 Right to Rectification (Art. 16)

You may request the correction of inaccurate data or completion of incomplete data concerning you, without undue delay.

8.3 Right to Erasure — "Right to be Forgotten" (Art. 17)

Rezervatio Book users can request deletion in the app under Settings → Account → Delete account; business owners can do so in the dashboard under Account → Delete account. Following confirmation, there is a 7-day grace period during which access may be restored through a unique link. Afterwards, the active identity and operational data are deleted or anonymised according to purpose and applicable obligations. Tax, security or audit records may be retained where required by law or the defence of rights. Data already anonymised cannot be restored.

8.4 Right to Restriction of Processing (Art. 18)

You may request the limitation of processing if: you contest the accuracy of the data; the processing is unlawful but you do not want deletion; we need the data for the establishment/exercise of a right in court; you have objected to the processing (pending verification).

8.5 Right to Data Portability (Art. 20)

You may request your data in a structured, commonly used and machine-readable format (JSON) by contacting privacy@rezervatio.ai, and you have the right to transmit such data to another controller. We respond within the legal time limit (one month, Art. 12(3) GDPR).

8.6 Right to Object (Art. 21)

You may object at any time to processing based on legitimate interest (Art. 6(1)(f)), including profiling. We will cease processing unless we demonstrate compelling legitimate grounds.

8.7 Right not to be Subject to an Automated Decision (Art. 22)

Availability and business rules can automatically produce confirmations or refusals. Whether Article 22 GDPR applies depends on the actual effects on the person. You may challenge the data or outcome and request human review from the business, or contact privacy@rezervatio.ai for Rezervatio’s own functions.

8.8 Right to Withdraw Consent (Art. 7(3))

In case of processing based on consent, you may withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal.

8.9 Exercising Your Rights

Contact: privacy@rezervatio.ai
Response time: maximum 30 calendar days from receipt of the request (extendable by 60 days in complex cases, with notification)
Identification: We may request identity verification to prevent unauthorized access to data
Cost: Free. In case of repetitive or excessive requests, we may charge a reasonable fee or refuse the request, in accordance with Art. 12(5) GDPR.

We respond without undue delay and within one month of receiving the request under Article 12(3) GDPR. Complexity or the number of requests may justify two additional months; we explain the extension during the first month. You may contact privacy@rezervatio.ai directly. For data processed on a business’s behalf, we assist and direct the request to that business.

8.10 Right to lodge a complaint

You may lodge a complaint with ANSPDCP or with the data-protection authority in the Member State of your habitual residence or workplace.

9. Data Security (Art. 32 GDPR)

We implement appropriate technical and organizational measures, in accordance with Art. 32 GDPR, including:

9.1 Technical Measures

The complete technical details regarding security measures are available to active B2B customers under the Data Processing Agreement (DPA) and may be presented in the context of security audits with prior notice.

9.2 Organizational Measures

10. Notification of Security Incidents (Art. 33-34 GDPR)

In the event of a personal data security breach:

11. Cookies and Similar Technologies

For detailed information regarding the use of cookies and localStorage, please consult the Cookie Policy.

12. Changes to the Privacy Policy

This policy may be updated periodically. The date of the last update is displayed at the top of the document. Significant changes will be communicated by email to registered Users, a visible banner on the platform and publication on this page.

13. Right to Lodge a Complaint

If you consider that the processing of your personal data infringes GDPR, you have the right to lodge a complaint with the supervisory authority:

National Supervisory Authority for Personal Data Processing (ANSPDCP)
Address: B-dul G-ral. Gheorghe Magheru no. 28-30, Sector 1, postal code 010336, Bucharest, Romania
Phone: +40.318.059.211 / +40.318.059.212
Email: anspdcp@dataprotection.ro
Website: www.dataprotection.ro

14. Contact

QUANTEMI S.R.L.
Data Protection Officer (DPO): privacy@rezervatio.ai
General contact: contact@rezervatio.ai
Website: www.rezervatio.ai

Last updated: September 15, 2026 — Version 2.1