Data Processing Agreement (DPA)
Version 1.0 — Last updated: April 30, 2026
This Data Processing Agreement forms an integral part of the agreement between the business customer and QUANTEMI S.R.L. for use of the Rezervatio.AI services and applies whenever Rezervatio.AI processes personal data on behalf of that customer.
1. Parties and definitions
Controller: the business customer using Rezervatio.AI and determining the purposes and means of processing its callers' and end customers' personal data.
Processor: QUANTEMI S.R.L., Romanian company, Tax ID 54694424, Trade Registry no. J2026031979003, registered office at Str. Liniștii no. 8, Năvodari, Constanța County, Romania, operating Rezervatio.AI.
The terms “personal data”, “processing”, “data subject”, “personal data breach” and “supervisory authority” have the meanings assigned by Regulation (EU) 2016/679 (“GDPR”).
2. Subject matter, duration and purpose of processing
2.1 Subject matter
Rezervatio.AI processes callers' and end customers' personal data solely to provide automated booking services through an AI voice agent, including receiving calls, transcribing conversations, understanding requests, saving reservations, sending SMS confirmations and synchronising information with the Controller's dashboard.
2.2 Duration
Processing takes place for the duration of the service agreement and thereafter only to the extent required by the Controller's documented instructions, applicable retention rules or legal obligations.
2.3 Categories of data and data subjects
The categories of data subjects, personal data, operations and purposes are described in Annex I.
2.4 Health data (Art. 9 GDPR)
The Controller acknowledges that, in medical contexts, callers may spontaneously disclose health information. The voice agent is configured not to actively request such information. The Controller is responsible for identifying a valid condition under Art. 9 GDPR and issuing any required instructions and notices.
3. Processor obligations (Rezervatio.AI)
Rezervatio.AI shall:
- process personal data only on the Controller's documented instructions, including regarding international transfers, unless Union or Member State law requires otherwise;
- ensure that authorised persons are bound by confidentiality;
- implement appropriate technical and organisational measures under Art. 32 GDPR;
- assist the Controller with data-subject requests through available platform functions and documented support channels;
- assist with security, breach notification, impact assessments and prior consultations, taking into account the nature of processing;
- make available information reasonably necessary to demonstrate compliance and allow audits under section 8;
- notify the Controller if, in its opinion, an instruction infringes GDPR or other applicable data-protection law.
4. Controller obligations
The Controller shall:
- have a valid legal basis under Art. 6 GDPR for all processing it instructs Rezervatio.AI to perform;
- inform data subjects under Arts. 13 and 14 GDPR, particularly that calls are handled and processed by an AI agent;
- configure the platform correctly using the available schedule, service and operational options and keep user accounts secure;
- respond directly to data-subject requests in its capacity as Controller, using the tools made available by the platform;
- notify Rezervatio.AI of complaints, authority requests or other matters requiring Processor assistance.
5. Sub-processors (Art. 28(2) and (4) GDPR)
5.1 General authorisation
The Controller grants general written authorisation for the sub-processors listed in Annex III. Rezervatio.AI remains responsible for ensuring that each sub-processor is bound by data-protection obligations materially equivalent to those in this DPA.
5.2 Notice of changes
We will notify the Controller at least 30 days before adding or replacing a sub-processor, by email to the account address and through a dashboard notice.
5.3 Right to object
The Controller may raise a reasoned data-protection objection during the notice period. The parties will seek a reasonable solution; if none is available, either party may terminate the affected service.
5.4 Chain of obligations
Rezervatio.AI shall impose the same material data-protection obligations on each sub-processor and remains accountable to the Controller for the sub-processor's performance.
6. International data transfers
Where personal data is transferred outside the European Economic Area, Rezervatio.AI uses an applicable Chapter V GDPR mechanism, including an adequacy decision, the EU-US Data Privacy Framework for participating organisations, or the European Commission's Standard Contractual Clauses, together with supplementary safeguards where appropriate.
7. Data-subject rights
Rezervatio.AI assists the Controller, taking into account the nature of processing, through:
- data export (Arts. 15 and 20 GDPR), through platform functions and/or on request, in a structured format;
- account deletion (Art. 17 GDPR), available in the dashboard with a 7-day access-restoration grace period;
- deletion or anonymisation under the retention policy and the Controller's documented instructions;
- versioned consent records where the platform records consent.
The Controller remains responsible for assessing and responding to each request within the statutory time limit.
8. Audit and compliance
8.1 Documentation
Rezervatio.AI maintains documentation on security measures, authorised sub-processors and relevant processing operations and will provide appropriate compliance information on request.
8.2 Audit
The Controller may request a compliance audit with at least 30 days' written notice, no more than once per year unless a security incident or supervisory authority requires otherwise. Audits must protect other customers' confidentiality and the security of the service. Reasonable costs may be charged where permitted by law and agreed in advance.
9. End of the agreement
Upon termination, Rezervatio.AI shall:
- provide the Controller, on request, with a copy of personal data being processed, in a structured format and within the agreed or legally required period;
- return, delete or anonymise personal data processed on the Controller's behalf, at the Controller's choice, subject to technical feasibility and applicable legal obligations;
- retain only data required by law, including applicable tax and compliance records, with access restricted to those purposes;
- provide confirmation that the request has been completed, at the Controller's request.
10. Liability
Each party's liability for GDPR infringements is governed by Art. 82 GDPR. As between the parties, each party bears fines, sanctions and damages arising from its own infringements. General contractual liability limits are those stated in the Terms and Conditions.
11. Amendments
This DPA may be amended by written agreement. Rezervatio.AI may notify minor changes that do not reduce the level of protection at least 30 days in advance. Material changes affecting the Controller's rights require acceptance or another valid contractual mechanism.
12. Governing law and jurisdiction
This DPA is governed by Romanian law and GDPR. Disputes shall first be addressed amicably and, failing resolution, submitted to the competent Romanian courts, without prejudice to data subjects' rights and supervisory-authority powers.
Annex I — Processing details
| Item | Description |
|---|---|
| Data subjects | Callers, end customers, patients, restaurant guests, salon or vehicle-service customers, and the Controller's authorised staff |
| Personal data | Name, phone number, optional email, audio-conversation content and transcript, booking details (date, time, party size, service and notes), and technical call data (duration and quality) |
| Special-category data | Health information that a caller may disclose spontaneously in a medical context; the Controller determines the applicable Art. 9 condition |
| Nature of processing | Collection, recording, transcription, structuring, storage, transmission, deletion and anonymisation |
| Purpose | Providing and supporting the automated booking and communication service |
| Duration | For the term of the service and any applicable documented retention period |
Annex II — Technical and organisational measures (Art. 32 GDPR)
Technical measures
- TLS 1.2 or later for data in transit;
- primary infrastructure and database hosted in the European Union; global providers and transfers are described in Annex III;
- OTP authentication and limited-duration session tokens;
- firewall, DDoS and bot protection;
- least-privilege and need-to-know access controls;
- encrypted daily backups with controlled retention;
- security monitoring and procedures for pseudonymisation, anonymisation and deletion according to the data category and purpose;
- logical tenant isolation.
Organisational measures
- administrative access limited to the minimum necessary personnel and logging of relevant security and administrative operations;
- confidentiality obligations, internal security and incident-response policies, and periodic risk assessments;
- assistance to the Controller in assessing whether a DPIA is required and, where applicable, in carrying it out;
- an internal incident register under Art. 33(5) GDPR.
Incident notification
Rezervatio.AI will notify the Controller without undue delay after becoming aware of a personal data breach affecting data processed on the Controller's behalf and will provide available information necessary for the Controller's obligations under Arts. 33 and 34 GDPR.
Annex III — Authorised sub-processors
| Sub-processor | Location | Purpose | Transfer mechanism |
|---|---|---|---|
| Hetzner Online GmbH | Germany, EU | Primary infrastructure, backend services and database hosting | EEA processing |
| Cloudflare Inc. | United States / global infrastructure | Security, DDoS and abuse protection, content delivery | DPF and/or SCCs, as applicable |
| Scaleway SAS | France, EU | Transactional and operational email | EEA processing |
| Telnyx LLC | United States; services also available in the EEA depending on configuration | Telephone numbers, call routing and SMS | DPF and/or SCCs, as applicable |
| ElevenLabs Inc. | United States / infrastructure under the applicable configuration | Conversation processing for the AI voice agent | DPF and/or SCCs, as applicable |
Provider compliance information: ElevenLabs · Telnyx · Cloudflare.
Contact
Data protection: privacy@rezervatio.ai
General contact: contact@rezervatio.ai
Last updated: April 30, 2026 — Version 1.0
EU · Data protection under GDPR