Privacy Policy
Version 2.1 — Last updated: September 15, 2026
This Privacy Policy describes how QUANTEMI S.R.L. ("Rezervatio", "we") collects, uses, stores, shares and protects personal data, in accordance with the General Data Protection Regulation (GDPR — EU Regulation 2016/679), Romanian Law no. 190/2018 and applicable legislation.
This policy applies to Users (business owners using the platform), End Customers (persons who call and interact with the AI voice agent), and Rezervatio Book app users (customers who make reservations directly through our mobile app).
1. Identity of the Controller / Processor
Tax ID (CUI): 54694424
Trade Registry No.: J2026031979003
Registered office: Năvodari, Jud. Constanța, Str. Liniștii nr. 8
General email: contact@rezervatio.ai
Data protection email (DPO): privacy@rezervatio.ai
Website: www.rezervatio.ai
1.1 GDPR Roles
Rezervatio is controller for Book accounts and personal features, website visitors and demos. The selected business is a separate controller for the booked service, its customers and staff. Rezervatio acts as processor when hosting and managing this data in Business, including bookings, messages, photos and calls, under the business’s instructions and the DPA.
| Context | Rezervatio Role | Explanation |
|---|---|---|
| User data (account, billing) | Data Controller | Rezervatio decides the purpose and means of processing the User's account data |
| End Customer data (reservations, calls) | Data Processor | Rezervatio processes End Customer data on behalf of and in accordance with the instructions of the User (the controller) |
1.2 Data-protection contact
For questions or rights requests: privacy@rezervatio.ai. We respond without undue delay and within one month of receiving the request under Article 12(3) GDPR. Complexity or the number of requests may justify two additional months; we explain the extension during the first month.
2. Personal Data We Collect
2.1 User Data (business owners) — Rezervatio as Controller
| Category | Specific Data | Purpose | Legal Basis |
|---|---|---|---|
| Account and authentication | First name, last name, email address, password (cryptographic hash) | Account creation, authentication, communication | Performance of contract — Art. 6(1)(b) |
| Business data | Business name, address, phone, email, business sector, Tax ID (optional) | AI agent configuration, service personalization | Performance of contract — Art. 6(1)(b) |
| Operational configuration | Operating hours, zones, tables/seats, agent preferences, custom messages | Proper operation of the reservation service | Performance of contract — Art. 6(1)(b) |
| Billing data | Card data (processed exclusively by a certified payment processor — Rezervatio does not store card numbers), billing address, Tax ID | Payment processing, invoicing | Performance of contract — Art. 6(1)(b) + Legal obligation — Art. 6(1)(c) |
| Usage data | Minutes consumed, number of calls, dashboard activity logs | Billing, statistics, service improvement | Performance of contract — Art. 6(1)(b) + Legitimate interest — Art. 6(1)(f) |
| Technical data | IP address, browser type, operating system, pages accessed | Security, troubleshooting, fraud prevention | Legitimate interest — Art. 6(1)(f) |
2.2 End Customer Data (callers) — Rezervatio as Processor
Health data: allergies, symptoms or the medical reason for an appointment may fall under Article 9 GDPR. Spontaneous disclosure does not remove this protection. Processing requires an Article 6 basis, an Article 9 condition and safeguards established by the controller, with instructions and contractual coverage for that workflow. The agent does not actively request sensitive data. Do not use the service for diagnosis, triage or emergencies.
| Category | Specific Data | Purpose | Legal Basis (of the User) |
|---|---|---|---|
| Reservation data | First name, last name, phone number (caller ID), email (optional), number of persons | Creating, managing and confirming the reservation | Legitimate interest of the business — Art. 6(1)(f) or Consent — Art. 6(1)(a) |
| Preferences | Food allergies, special occasions, special requests, preferred zone | Personalizing the experience, food safety | The business establishes an Article 6 basis and an Article 9 condition for health data. |
| Voice data | Voice in real-time (processed via streaming, not stored as audio file on Rezervatio servers), text transcript of the conversation | Understanding and processing the reservation request via the AI agent | Legitimate interest — Art. 6(1)(f) |
| Call metadata | Caller phone number (caller ID), called number, call duration, date and time, session identifier | Billing the User, statistics, technical support, audit | Performance of contract with the User — Art. 6(1)(b) + Legitimate interest — Art. 6(1)(f) |
2.5 Demo Call (unauthenticated visitor)
When you initiate a demo call from the homepage ("Call me" form):
| Category | Specific Data | Source |
|---|---|---|
| Call identification | Phone number, IP address, timestamp | Visitor (manual input) |
| Anti-abuse | Temporary OTP code (SMS, valid 10 minutes), Cloudflare Turnstile token | Generated automatically to verify number ownership |
Legal basis: explicit consent (Art. 6(1)(a) GDPR). You grant permission by pressing "Call me" and entering the OTP code received via SMS.
Sub-processors: the same as for the entire platform — see section 5 (Telnyx for telephony/SMS, ElevenLabs for AI voice processing, and Cloudflare for Turnstile bot protection).
The voice conversation is processed through ElevenLabs. Rezervatio systems may retain metadata, transcripts/summaries and booking results; the voice provider manages the audio file. Provider audio/transcript retention is configured to 30 days with periodic deletion. For details about a call: privacy@rezervatio.ai.
Demo-specific retention: demo requests are cleaned after 30 days; OTP codes expire in 10 minutes and related records are cleaned after 24 hours.
Your rights: request deletion of demo data at privacy@rezervatio.ai. We handle the request without undue delay, within the time limit and conditions in section 8.
2.3 Data collected from Rezervatio Book app users
Users who create an account in the Rezervatio Book mobile app to book directly (without a phone call):
| Category | Specific data |
|---|---|
| Account identification | Phone number (OTP login); name is required at first login; email (if you sign in with Google or Apple) |
| Own reservations | History of reservations made via the app, status, notes |
| Reservation messages | Content of messages exchanged with the business in connection with a reservation. Deleted when the account is deleted. Basis: performance of the contract (Art. 6(1)(b)). |
| Favorites | Businesses / specialists saved as favorites |
| Push notifications | Device token and content needed to deliver notifications about bookings and selected features. Notifications can be disabled in settings. Device permission does not automatically authorise marketing; any required marketing consent is obtained separately. |
| Location | Optional, with device permission: coordinates are transmitted to search for nearby businesses and content. You may select a location manually. |
| Camera | The camera can scan a business QR code locally. The camera and photo library, where available, also allow voluntary booking attachments. Selected photos are uploaded when you submit the request and are accessible to the recipient business and authorised participants; they are not published and the whole photo library is not transmitted. |
| Calendar | When you choose “Add to calendar”, the app accesses the calendar list/default calendar to add the booking and can remove the entry on request. Other events are not sent to Rezervatio. Calendar syncing depends on your provider and settings. |
| Usage data | Login IP addresses, device, operating system |
| Consents | Acceptance of the Terms is recorded with the document version and date; the Privacy Policy describes processing. Choices for optional purposes are separate and can be withdrawn. |
2.4 Data collected automatically from website visitors
Optional website visit statistics are sent only after Analytics consent. The function may retain the page, referring domain, country, browser information, a daily hash and the raw IP. The retention routine removes raw IPs older than 30 days; it does not erase the entire statistics history. The hash is pseudonymous, not anonymous. You may withdraw consent through Cookie preferences; see the Cookie Policy. Technical data needed for security and authentication is processed separately.
3. Legal Basis for Processing (Art. 6 GDPR)
Article 6(1)(b) concerns a contract with the data subject; administering company representatives’ relationship and access relies on legitimate interest, Article 6(1)(f). The business establishes the basis for its customers’ data; our B2B contract alone is not that basis. Optional website statistics rely on separate consent, Article 6(1)(a).
| Legal Basis | GDPR Article | Applicability |
|---|---|---|
| Performance of contract | Art. 6(1)(b) | Providing services to Users under the chosen subscription; processing reservations |
| Legitimate interest | Art. 6(1)(f) | Service improvement, fraud prevention, security, aggregated statistics, technical support |
| Consent | Art. 6(1)(a) | Marketing communications (newsletter, promotions) — optional, with the possibility of withdrawal at any time |
| Legal obligation | Art. 6(1)(c) | Tax and accounting compliance (retention of invoices for 5 years under the general rule in Article 25 of the Accounting Law per the Tax Code), responding to authority requests |
4. How We Use the Data
We use personal data exclusively for:
- Service provision — call processing via the AI agent, creation and management of reservations, sending confirmations
- Account administration — authentication, subscription management, billing
- Essential communications — service notifications, Terms changes, security alerts
- Technical support — resolution of issues reported by Users
- Platform improvement — aggregated and anonymized usage analysis to optimize the service
- Security — detection and prevention of fraud, abuse, cyberattacks
- Legal compliance — fulfilment of tax, accounting and reporting obligations
We do not sell personal data or use it for behavioural advertising. Automated booking rules and the right to request human review are described in section 8.7.
5. Providers and data recipients
We do not sell or rent your data. We use specialised providers that may act as processors, sub-processors or, for certain operations of their own, independent controllers. Their role depends on the service and the applicable contractual terms. When Rezervatio acts as a processor for a business customer, the relevant sub-processors are listed in the DPA.
| Provider | Possible role | Head office / processing regions | Purpose |
|---|---|---|---|
| Hetzner Online GmbH | Processor / sub-processor | Germany, European Union | Hosting the primary infrastructure, backend services and databases managed by Rezervatio |
| Cloudflare Inc. | Processor / sub-processor; controller for certain services of its own | United States / global infrastructure | Security, DDoS and abuse protection, content delivery and traffic management |
| Scaleway SAS | Processor / sub-processor | France, European Union | Transactional and operational emails, including confirmations, invitations and account notices |
| Telnyx LLC | Processor / sub-processor | United States; services also available in the EEA depending on configuration | Telephone numbers, call routing and SMS delivery |
| ElevenLabs Inc. | Processor / sub-processor | United States / infrastructure under the applicable configuration and agreement | Conversation processing for the AI voice agent: speech recognition, voice-response generation and technical transcription |
| Stripe | Processor and/or independent controller, depending on the operation | Ireland / United States, depending on the contracting entity | Payments, subscriptions and fraud prevention when the service is enabled |
| Apple Inc. | Service provider and independent controller for its own operations | United States / global infrastructure | Sign in with Apple and push-notification delivery to Apple devices |
| Google Ireland Limited / Google LLC | Service provider and independent controller for its own operations | Ireland / United States, with global infrastructure | Google sign-in and Android notification delivery through FCM. |
| Expo / 650 Industries, Inc. | Processor | United States / global infrastructure | Relaying Book and Business notifications to Apple/Google; EAS services for app and update distribution. |
Actual processing regions may vary by service and configuration. International transfers use the applicable legal mechanisms described in section 6. The sub-processors used when Rezervatio acts for a business customer are listed in the Data Processing Agreement (DPA).
5.1 Notice of sub-processor changes
The Controller (B2B User) will be notified at least 30 days before the addition or replacement of a sub-processor, in accordance with Art. 28(2) GDPR.
6. International Transfers
Core platform data is hosted in the European Union. Some providers operate globally or in the United States. For those transfers we use an applicable Chapter V GDPR mechanism, including the EU-US Data Privacy Framework for participating organisations and/or the European Commission's Standard Contractual Clauses, together with supplementary safeguards where appropriate. Telnyx offers European processing options; ElevenLabs voice processing currently uses global infrastructure subject to the applicable contractual safeguards.
7. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected or as required by law:
| Data Type | Retention Period | Justification |
|---|---|---|
| User account (active) | For the entire duration of the active account | Necessary for service provision |
| Reservations and related operational data | 12 months after the date of a completed/cancelled/no-show booking; future bookings do not expire before service | Reduction of booking identifiers; deletion of associated messages, history and photos. The business’s own customer records have separate purposes and retention. |
| Call metadata and summaries | 12 months | Deletion or anonymisation under the applicable policy |
| Full audio and transcripts processed by the AI voice provider | 30 days for audio/transcripts, with periodic provider deletion | Deletion under provider settings and procedures; details available on request |
| Technical and security data, including IP addresses and logs | Statistical visits: 90 days, raw IP: 30 days; call sessions/webhooks: 30 days; SMS: 6 months. Other security logs: until incident resolution and expiry of justified need. | Deletion, truncation or anonymisation, as applicable |
| Account after a confirmed deletion request | 7 days (access-restoration grace period) | Afterwards, the active identity is removed and operational data is deleted or anonymised, subject to legal exceptions |
| Consent, export and deletion-request records | Export logs: 12 months; closed deletion requests: 5 years; acceptance/consent history: at most 5 years, retaining the latest status while the account relies on it | Restricted access; deletion when no longer necessary or legally required |
| Billing and tax data | Generally 5 years from 1 July of the year following the financial year; other legal duties may require separate periods | Legal obligation — Tax Code, Accounting Law |
| Demo calls (phone, IP and anti-abuse data) | 30 days | Deletion or anonymisation under the operational procedure |
| Demo OTP codes | Valid for 10 minutes; records cleaned after 24 hours | Invalidation at expiry and subsequent cleanup |
We apply technical and organisational deletion or anonymisation procedures. You may request the criteria applicable to a specific category of data at privacy@rezervatio.ai.
8. Your Rights (Art. 15-22 GDPR)
As a data subject, you have the following rights, exercisable free of charge:
8.1 Right of Access (Art. 15)
The JSON export available in the account can be supplemented on request with photos and other personal data absent from that file, while protecting other people’s rights.
You may request confirmation that we process personal data concerning you and a copy of such data, together with information on the purpose, categories, recipients and retention periods.
8.2 Right to Rectification (Art. 16)
You may request the correction of inaccurate data or completion of incomplete data concerning you, without undue delay.
8.3 Right to Erasure — "Right to be Forgotten" (Art. 17)
Rezervatio Book users can request deletion in the app under Settings → Account → Delete account; business owners can do so in the dashboard under Account → Delete account. Following confirmation, there is a 7-day grace period during which access may be restored through a unique link. Afterwards, the active identity and operational data are deleted or anonymised according to purpose and applicable obligations. Tax, security or audit records may be retained where required by law or the defence of rights. Data already anonymised cannot be restored.
8.4 Right to Restriction of Processing (Art. 18)
You may request the limitation of processing if: you contest the accuracy of the data; the processing is unlawful but you do not want deletion; we need the data for the establishment/exercise of a right in court; you have objected to the processing (pending verification).
8.5 Right to Data Portability (Art. 20)
You may request your data in a structured, commonly used and machine-readable format (JSON) by contacting privacy@rezervatio.ai, and you have the right to transmit such data to another controller. We respond within the legal time limit (one month, Art. 12(3) GDPR).
8.6 Right to Object (Art. 21)
You may object at any time to processing based on legitimate interest (Art. 6(1)(f)), including profiling. We will cease processing unless we demonstrate compelling legitimate grounds.
8.7 Right not to be Subject to an Automated Decision (Art. 22)
Availability and business rules can automatically produce confirmations or refusals. Whether Article 22 GDPR applies depends on the actual effects on the person. You may challenge the data or outcome and request human review from the business, or contact privacy@rezervatio.ai for Rezervatio’s own functions.
8.8 Right to Withdraw Consent (Art. 7(3))
In case of processing based on consent, you may withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
8.9 Exercising Your Rights
Response time: maximum 30 calendar days from receipt of the request (extendable by 60 days in complex cases, with notification)
Identification: We may request identity verification to prevent unauthorized access to data
Cost: Free. In case of repetitive or excessive requests, we may charge a reasonable fee or refuse the request, in accordance with Art. 12(5) GDPR.
We respond without undue delay and within one month of receiving the request under Article 12(3) GDPR. Complexity or the number of requests may justify two additional months; we explain the extension during the first month. You may contact privacy@rezervatio.ai directly. For data processed on a business’s behalf, we assist and direct the request to that business.
8.10 Right to lodge a complaint
You may lodge a complaint with ANSPDCP or with the data-protection authority in the Member State of your habitual residence or workplace.
9. Data Security (Art. 32 GDPR)
We implement appropriate technical and organizational measures, in accordance with Art. 32 GDPR, including:
9.1 Technical Measures
- Encryption in transit via modern TLS protocols for all data transfers
- Secure password storage via robust cryptographic hash functions
- Database-level isolation via row-level security mechanisms
- Network protection — firewall, DDoS protection and rate limiting
- Automatic backup daily, encrypted, with disaster recovery plan
- Restricted administrative access — access limited to authorised personnel.
- Modern authentication — OTP, password or Apple/Google depending on the flow, with limited-duration session tokens.
- Active monitoring — secure logging and incident response
The complete technical details regarding security measures are available to active B2B customers under the Data Processing Agreement (DPA) and may be presented in the context of security audits with prior notice.
9.2 Organizational Measures
- Data minimization principle — we collect only data strictly necessary
- Storage limitation principle — automatic deletion upon expiry of the retention period
- Role-based access — access limited to the data necessary for each function
- Confidentiality — all collaborators with access to data have contractual confidentiality obligations
- Incident procedures — documented security incident response plan
- Periodic review — annual evaluation of security measures
10. Notification of Security Incidents (Art. 33-34 GDPR)
In the event of a personal data security breach:
- We will notify the National Supervisory Authority (ANSPDCP) within a maximum of 72 hours of becoming aware of the incident, unless the breach is unlikely to result in a risk to individuals' rights
- When acting as processor, we will notify the affected Controller without undue delay after becoming aware of a breach affecting data processed on its behalf
- If the breach is likely to result in a high risk to individuals' rights, we will directly inform the affected data subjects
- We will document each incident, the measures taken and the outcomes in our internal incident register
11. Cookies and Similar Technologies
For detailed information regarding the use of cookies and localStorage, please consult the Cookie Policy.
12. Changes to the Privacy Policy
This policy may be updated periodically. The date of the last update is displayed at the top of the document. Significant changes will be communicated by email to registered Users, a visible banner on the platform and publication on this page.
13. Right to Lodge a Complaint
If you consider that the processing of your personal data infringes GDPR, you have the right to lodge a complaint with the supervisory authority:
Address: B-dul G-ral. Gheorghe Magheru no. 28-30, Sector 1, postal code 010336, Bucharest, Romania
Phone: +40.318.059.211 / +40.318.059.212
Email: anspdcp@dataprotection.ro
Website: www.dataprotection.ro
14. Contact
Data Protection Officer (DPO): privacy@rezervatio.ai
General contact: contact@rezervatio.ai
Website: www.rezervatio.ai
Last updated: September 15, 2026 — Version 2.1