Back to site
Terms and Conditions Privacy Policy Cookie Policy DPA

Data Processing Agreement (DPA)

Version 1.0 — Last updated: April 30, 2026

This Data Processing Agreement forms an integral part of the agreement between the business customer and QUANTEMI S.R.L. for use of the Rezervatio.AI services and applies whenever Rezervatio.AI processes personal data on behalf of that customer.

1. Parties and definitions

Controller: the business customer using Rezervatio.AI and determining the purposes and means of processing its callers' and end customers' personal data.

Processor: QUANTEMI S.R.L., Romanian company, Tax ID 54694424, Trade Registry no. J2026031979003, registered office at Str. Liniștii no. 8, Năvodari, Constanța County, Romania, operating Rezervatio.AI.

The terms “personal data”, “processing”, “data subject”, “personal data breach” and “supervisory authority” have the meanings assigned by Regulation (EU) 2016/679 (“GDPR”).

2. Subject matter, duration and purpose of processing

2.1 Subject matter

Rezervatio.AI processes callers' and end customers' personal data solely to provide automated booking services through an AI voice agent, including receiving calls, transcribing conversations, understanding requests, saving reservations, sending SMS confirmations and synchronising information with the Controller's dashboard.

2.2 Duration

Processing takes place for the duration of the service agreement and thereafter only to the extent required by the Controller's documented instructions, applicable retention rules or legal obligations.

2.3 Categories of data and data subjects

The categories of data subjects, personal data, operations and purposes are described in Annex I.

2.4 Health data (Art. 9 GDPR)

The Controller acknowledges that, in medical contexts, callers may spontaneously disclose health information. The voice agent is configured not to actively request such information. The Controller is responsible for identifying a valid condition under Art. 9 GDPR and issuing any required instructions and notices.

3. Processor obligations (Rezervatio.AI)

Rezervatio.AI shall:

4. Controller obligations

The Controller shall:

5. Sub-processors (Art. 28(2) and (4) GDPR)

5.1 General authorisation

The Controller grants general written authorisation for the sub-processors listed in Annex III. Rezervatio.AI remains responsible for ensuring that each sub-processor is bound by data-protection obligations materially equivalent to those in this DPA.

5.2 Notice of changes

We will notify the Controller at least 30 days before adding or replacing a sub-processor, by email to the account address and through a dashboard notice.

5.3 Right to object

The Controller may raise a reasoned data-protection objection during the notice period. The parties will seek a reasonable solution; if none is available, either party may terminate the affected service.

5.4 Chain of obligations

Rezervatio.AI shall impose the same material data-protection obligations on each sub-processor and remains accountable to the Controller for the sub-processor's performance.

6. International data transfers

Where personal data is transferred outside the European Economic Area, Rezervatio.AI uses an applicable Chapter V GDPR mechanism, including an adequacy decision, the EU-US Data Privacy Framework for participating organisations, or the European Commission's Standard Contractual Clauses, together with supplementary safeguards where appropriate.

7. Data-subject rights

Rezervatio.AI assists the Controller, taking into account the nature of processing, through:

The Controller remains responsible for assessing and responding to each request within the statutory time limit.

8. Audit and compliance

8.1 Documentation

Rezervatio.AI maintains documentation on security measures, authorised sub-processors and relevant processing operations and will provide appropriate compliance information on request.

8.2 Audit

The Controller may request a compliance audit with at least 30 days' written notice, no more than once per year unless a security incident or supervisory authority requires otherwise. Audits must protect other customers' confidentiality and the security of the service. Reasonable costs may be charged where permitted by law and agreed in advance.

9. End of the agreement

Upon termination, Rezervatio.AI shall:

10. Liability

Each party's liability for GDPR infringements is governed by Art. 82 GDPR. As between the parties, each party bears fines, sanctions and damages arising from its own infringements. General contractual liability limits are those stated in the Terms and Conditions.

11. Amendments

This DPA may be amended by written agreement. Rezervatio.AI may notify minor changes that do not reduce the level of protection at least 30 days in advance. Material changes affecting the Controller's rights require acceptance or another valid contractual mechanism.

12. Governing law and jurisdiction

This DPA is governed by Romanian law and GDPR. Disputes shall first be addressed amicably and, failing resolution, submitted to the competent Romanian courts, without prejudice to data subjects' rights and supervisory-authority powers.

Annex I — Processing details

ItemDescription
Data subjectsCallers, end customers, patients, restaurant guests, salon or vehicle-service customers, and the Controller's authorised staff
Personal dataName, phone number, optional email, audio-conversation content and transcript, booking details (date, time, party size, service and notes), and technical call data (duration and quality)
Special-category dataHealth information that a caller may disclose spontaneously in a medical context; the Controller determines the applicable Art. 9 condition
Nature of processingCollection, recording, transcription, structuring, storage, transmission, deletion and anonymisation
PurposeProviding and supporting the automated booking and communication service
DurationFor the term of the service and any applicable documented retention period

Annex II — Technical and organisational measures (Art. 32 GDPR)

Technical measures

Organisational measures

Incident notification

Rezervatio.AI will notify the Controller without undue delay after becoming aware of a personal data breach affecting data processed on the Controller's behalf and will provide available information necessary for the Controller's obligations under Arts. 33 and 34 GDPR.

Annex III — Authorised sub-processors

Sub-processorLocationPurposeTransfer mechanism
Hetzner Online GmbHGermany, EUPrimary infrastructure, backend services and database hostingEEA processing
Cloudflare Inc.United States / global infrastructureSecurity, DDoS and abuse protection, content deliveryDPF and/or SCCs, as applicable
Scaleway SASFrance, EUTransactional and operational emailEEA processing
Telnyx LLCUnited States; services also available in the EEA depending on configurationTelephone numbers, call routing and SMSDPF and/or SCCs, as applicable
ElevenLabs Inc.United States / infrastructure under the applicable configurationConversation processing for the AI voice agentDPF and/or SCCs, as applicable

Provider compliance information: ElevenLabs · Telnyx · Cloudflare.

Contact

QUANTEMI S.R.L.
Data protection: privacy@rezervatio.ai
General contact: contact@rezervatio.ai

Last updated: April 30, 2026 — Version 1.0