Privacy Policy
Version 2.0 — Last updated: April 30, 2026
This Privacy Policy describes how QUANTEMI S.R.L. ("Rezervatio", "we") collects, uses, stores, shares and protects personal data, in accordance with the General Data Protection Regulation (GDPR — EU Regulation 2016/679), Romanian Law no. 190/2018 and applicable legislation.
This policy applies to Users (business owners using the platform), End Customers (persons who call and interact with the AI voice agent), and Rezervatio Book app users (customers who make reservations directly through our mobile app).
1. Identity of the Controller / Processor
Tax ID (CUI): 54694424
Trade Registry No.: J2026031979003
Registered office: Năvodari, Jud. Constanța, Str. Liniștii nr. 8
General email: contact@rezervatio.ai
Data protection email (DPO): privacy@rezervatio.ai
Website: www.rezervatio.ai
1.1 GDPR Roles
| Context | Rezervatio Role | Explanation |
|---|---|---|
| User data (account, billing) | Data Controller | Rezervatio decides the purpose and means of processing the User's account data |
| End Customer data (reservations, calls) | Data Processor | Rezervatio processes End Customer data on behalf of and in accordance with the instructions of the User (the controller) |
1.2 Data-protection contact
For questions about data protection or to exercise your GDPR rights, contact privacy@rezervatio.ai. We respond within a maximum of 30 days under Art. 12(3) GDPR.
2. Personal Data We Collect
2.1 User Data (business owners) — Rezervatio as Controller
| Category | Specific Data | Purpose | Legal Basis |
|---|---|---|---|
| Account and authentication | First name, last name, email address, password (cryptographic hash) | Account creation, authentication, communication | Performance of contract — Art. 6(1)(b) |
| Business data | Business name, address, phone, email, business sector, Tax ID (optional) | AI agent configuration, service personalization | Performance of contract — Art. 6(1)(b) |
| Operational configuration | Operating hours, zones, tables/seats, agent preferences, custom messages | Proper operation of the reservation service | Performance of contract — Art. 6(1)(b) |
| Billing data | Card data (processed exclusively by a certified payment processor — Rezervatio does not store card numbers), billing address, Tax ID | Payment processing, invoicing | Performance of contract — Art. 6(1)(b) + Legal obligation — Art. 6(1)(c) |
| Usage data | Minutes consumed, number of calls, dashboard activity logs | Billing, statistics, service improvement | Performance of contract — Art. 6(1)(b) + Legitimate interest — Art. 6(1)(f) |
| Technical data | IP address, browser type, operating system, pages accessed | Security, troubleshooting, fraud prevention | Legitimate interest — Art. 6(1)(f) |
2.2 End Customer Data (callers) — Rezervatio as Processor
| Category | Specific Data | Purpose | Legal Basis (of the User) |
|---|---|---|---|
| Reservation data | First name, last name, phone number (caller ID), email (optional), number of persons | Creating, managing and confirming the reservation | Legitimate interest of the business — Art. 6(1)(f) or Consent — Art. 6(1)(a) |
| Preferences | Food allergies, special occasions, special requests, preferred zone | Personalizing the experience, food safety | Legitimate interest — Art. 6(1)(f) / Consent — Art. 6(1)(a) |
| Voice data | Voice in real-time (processed via streaming, not stored as audio file on Rezervatio servers), text transcript of the conversation | Understanding and processing the reservation request via the AI agent | Legitimate interest — Art. 6(1)(f) |
| Call metadata | Caller phone number (caller ID), called number, call duration, date and time, session identifier | Billing the User, statistics, technical support, audit | Performance of contract with the User — Art. 6(1)(b) + Legitimate interest — Art. 6(1)(f) |
2.5 Demo Call (unauthenticated visitor)
When you initiate a demo call from the homepage ("Call me" form):
| Category | Specific Data | Source |
|---|---|---|
| Call identification | Phone number, IP address, timestamp | Visitor (manual input) |
| Anti-abuse | Temporary OTP code (SMS, valid 10 minutes), Cloudflare Turnstile token | Generated automatically to verify number ownership |
Legal basis: explicit consent (Art. 6(1)(a) GDPR). You grant permission by pressing "Call me" and entering the OTP code received via SMS.
Sub-processors: the same as for the entire platform — see section 5 (Telnyx for telephony/SMS, ElevenLabs for AI voice processing, and Cloudflare for Turnstile bot protection).
The voice conversation is processed through ElevenLabs. Rezervatio.AI does not retain the audio file or full transcript in its own database; it may retain call metadata and an operational summary. The provider may temporarily process and retain audio, transcripts and technical information according to its configuration, contractual terms and privacy policy.
Demo-specific retention: phone number and IP are automatically deleted after 7 days (strict period for abuse prevention — multiple calls to third-party numbers). OTP codes expire in 10 minutes and are cleaned up after 24 hours.
Your rights: you can request immediate deletion of the number used by emailing privacy@rezervatio.ai. Data is deleted within 72 hours.
2.3 Data collected from Rezervatio Book app users
Users who create an account in the Rezervatio Book mobile app to book directly (without a phone call):
| Category | Specific data |
|---|---|
| Account identification | Phone number (OTP login); name is required at first login; email (if you sign in with Google or Apple) |
| Own reservations | History of reservations made via the app, status, notes |
| Reservation messages | Content of messages exchanged with the business in connection with a reservation. Deleted when the account is deleted. Basis: performance of the contract (Art. 6(1)(b)). |
| Favorites | Businesses / specialists saved as favorites |
| Push notifications | Push notification token / notification identifier generated by the device operating system, used solely for reservation-related notifications; can be disabled anytime in settings. Basis: consent (Art. 6(1)(a)). |
| Location | On-device only (if you grant access), to display the map and nearby businesses — it is not transmitted to or stored on our servers. |
| Camera | Camera access is used only to scan a business QR code (quick booking). The image is processed on-device; it is not transmitted to or stored on our servers. |
| Calendar | If you choose "Add to calendar", the reservation is written as an event to your device calendar. This is a strictly local operation; we do not access or store your calendar data. |
| Usage data | Login IP addresses, device, operating system |
| Consents | Acceptance by continued use (Terms + Privacy Policy); the app does not record versions/date/IP — unlike the business dashboard account, where consents are recorded with versioning. |
2.4 Data collected automatically from website visitors
When you visit rezervatio.ai, we collect the minimum technical information needed for operation, security and aggregate analysis: an IP address transformed using a rotating daily cryptographic hash, browser and operating-system type, pages visited and referrer. Cloudflare may set the essential _cf_bm security cookie, and the browser stores interface preferences such as theme, language and cookie choice.
We do not use Google Analytics, Facebook Pixel or other advertising-tracking services on the presentation website.
3. Legal Basis for Processing (Art. 6 GDPR)
| Legal Basis | GDPR Article | Applicability |
|---|---|---|
| Performance of contract | Art. 6(1)(b) | Providing services to Users under the chosen subscription; processing reservations |
| Legitimate interest | Art. 6(1)(f) | Service improvement, fraud prevention, security, aggregated statistics, technical support |
| Consent | Art. 6(1)(a) | Marketing communications (newsletter, promotions) — optional, with the possibility of withdrawal at any time |
| Legal obligation | Art. 6(1)(c) | Tax and accounting compliance (retention of invoices for 10 years per the Tax Code), responding to authority requests |
4. How We Use the Data
We use personal data exclusively for:
- Service provision — call processing via the AI agent, creation and management of reservations, sending confirmations
- Account administration — authentication, subscription management, billing
- Essential communications — service notifications, Terms changes, security alerts
- Technical support — resolution of issues reported by Users
- Platform improvement — aggregated and anonymized usage analysis to optimize the service
- Security — detection and prevention of fraud, abuse, cyberattacks
- Legal compliance — fulfilment of tax, accounting and reporting obligations
We DO NOT use data for: automated profiling with legal effects, sale to third parties, behavioural advertising, exclusively automated decision-making with significant impact.
5. Providers and data recipients
We do not sell or rent your data. We use specialised providers that may act as processors, sub-processors or, for certain operations of their own, independent controllers. Their role depends on the service and the applicable contractual terms. When Rezervatio acts as a processor for a business customer, the relevant sub-processors are listed in the DPA.
| Provider | Possible role | Head office / processing regions | Purpose |
|---|---|---|---|
| Hetzner Online GmbH | Processor / sub-processor | Germany, European Union | Hosting the primary infrastructure, backend services and databases managed by Rezervatio |
| Cloudflare Inc. | Processor / sub-processor; controller for certain services of its own | United States / global infrastructure | Security, DDoS and abuse protection, content delivery and traffic management |
| Scaleway SAS | Processor / sub-processor | France, European Union | Transactional and operational emails, including confirmations, invitations and account notices |
| Telnyx LLC | Processor / sub-processor | United States; services also available in the EEA depending on configuration | Telephone numbers, call routing and SMS delivery |
| ElevenLabs Inc. | Processor / sub-processor | United States / infrastructure under the applicable configuration and agreement | Conversation processing for the AI voice agent: speech recognition, voice-response generation and technical transcription |
| Stripe | Processor and/or independent controller, depending on the operation | Ireland / United States, depending on the contracting entity | Payments, subscriptions and fraud prevention when the service is enabled |
| Apple Inc. | Service provider and independent controller for its own operations | United States / global infrastructure | Sign in with Apple and push-notification delivery to Apple devices |
| Google Ireland Limited / Google LLC | Service provider and independent controller for its own operations | Ireland / United States, with global infrastructure | Google Sign-In; Android notification delivery will be documented when that service is enabled |
| Expo / 650 Industries, Inc. | Processor | United States / global infrastructure | Relaying Rezervatio Book push notifications to the device platform's delivery service |
Actual processing regions may vary by service and configuration. International transfers use the applicable legal mechanisms described in section 6. The sub-processors used when Rezervatio acts for a business customer are listed in the Data Processing Agreement (DPA).
5.1 Notice of sub-processor changes
The Controller (B2B User) will be notified at least 30 days before the addition or replacement of a sub-processor, in accordance with Art. 28(2) GDPR.
6. International Transfers
Core platform data is hosted in the European Union. Some providers operate globally or in the United States. For those transfers we use an applicable Chapter V GDPR mechanism, including the EU-US Data Privacy Framework for participating organisations and/or the European Commission's Standard Contractual Clauses, together with supplementary safeguards where appropriate. Telnyx offers European processing options; ElevenLabs voice processing currently uses global infrastructure subject to the applicable contractual safeguards.
7. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected or as required by law:
| Data Type | Retention Period | Justification |
|---|---|---|
| User account (active) | For the entire duration of the active account | Necessary for service provision |
| Reservations and related operational data | For the account term and thereafter as necessary for the purpose, legal obligations or defence of rights | Deletion or anonymisation, as applicable |
| Call metadata and summaries | As necessary to provide and support the service, maintain security and resolve incidents | Deletion or anonymisation under the applicable policy |
| Full audio and transcripts processed by the AI voice provider | According to the provider configuration and applicable contractual agreement | Deletion under provider settings and procedures; details available on request |
| Technical and security data, including IP addresses and logs | As necessary for abuse prevention, security and incident investigation | Deletion, truncation or anonymisation, as applicable |
| Account after a confirmed deletion request | 7 days (access-restoration grace period) | Afterwards, the active identity is removed and operational data is deleted or anonymised, subject to legal exceptions |
| Consent, export and deletion-request records | As necessary to demonstrate compliance and defend legal rights | Restricted access; deletion when no longer necessary or legally required |
| Billing and tax data | 10 years | Legal obligation — Tax Code, Accounting Law |
| Demo calls (phone, IP and anti-abuse data) | A short period limited to abuse prevention and security | Deletion or anonymisation under the operational procedure |
| Demo OTP codes | Valid for 10 minutes; related technical data is retained only as necessary for security | Invalidation at expiry and subsequent cleanup |
We apply technical and organisational deletion or anonymisation procedures. You may request the criteria applicable to a specific category of data at privacy@rezervatio.ai.
8. Your Rights (Art. 15-22 GDPR)
As a data subject, you have the following rights, exercisable free of charge:
8.1 Right of Access (Art. 15)
You may request confirmation that we process personal data concerning you and a copy of such data, together with information on the purpose, categories, recipients and retention periods.
8.2 Right to Rectification (Art. 16)
You may request the correction of inaccurate data or completion of incomplete data concerning you, without undue delay.
8.3 Right to Erasure — "Right to be Forgotten" (Art. 17)
Rezervatio Book users can request deletion in the app under Settings → Account → Delete account; business owners can do so in the dashboard under Account → Delete account. Following confirmation, there is a 7-day grace period during which access may be restored through a unique link. Afterwards, the active identity and operational data are deleted or anonymised according to purpose and applicable obligations. Tax, security or audit records may be retained where required by law or the defence of rights. Data already anonymised cannot be restored.
8.4 Right to Restriction of Processing (Art. 18)
You may request the limitation of processing if: you contest the accuracy of the data; the processing is unlawful but you do not want deletion; we need the data for the establishment/exercise of a right in court; you have objected to the processing (pending verification).
8.5 Right to Data Portability (Art. 20)
You may request your data in a structured, commonly used and machine-readable format (JSON) by contacting privacy@rezervatio.ai, and you have the right to transmit such data to another controller. We respond within the legal time limit (one month, Art. 12(3) GDPR).
8.6 Right to Object (Art. 21)
You may object at any time to processing based on legitimate interest (Art. 6(1)(f)), including profiling. We will cease processing unless we demonstrate compelling legitimate grounds.
8.7 Right not to be Subject to an Automated Decision (Art. 22)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similar. Our AI agent processes reservation requests but does not make decisions with significant legal effects on data subjects.
8.8 Right to Withdraw Consent (Art. 7(3))
In case of processing based on consent, you may withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
8.9 Exercising Your Rights
Response time: maximum 30 calendar days from receipt of the request (extendable by 60 days in complex cases, with notification)
Identification: We may request identity verification to prevent unauthorized access to data
Cost: Free. In case of repetitive or excessive requests, we may charge a reasonable fee or refuse the request, in accordance with Art. 12(5) GDPR.
End Customers (persons making reservations): since the User (the business) is the controller of your data, please first address the respective business. If you do not receive a satisfactory response within 30 days, you may contact us directly at privacy@rezervatio.ai.
8.10 Right to lodge a complaint
You may lodge a complaint with ANSPDCP or with the data-protection authority in the Member State of your habitual residence or workplace.
9. Data Security (Art. 32 GDPR)
We implement appropriate technical and organizational measures, in accordance with Art. 32 GDPR, including:
9.1 Technical Measures
- Encryption in transit via modern TLS protocols for all data transfers
- Secure password storage via robust cryptographic hash functions
- Database-level isolation via row-level security mechanisms
- Network protection — firewall, DDoS protection and rate limiting
- Automatic backup daily, encrypted, with disaster recovery plan
- Restricted administrative access — multi-factor authentication and unauthorized access detection mechanisms
- Modern authentication — limited-duration tokens and MFA support
- Active monitoring — secure logging and incident response
The complete technical details regarding security measures are available to active B2B customers under the Data Processing Agreement (DPA) and may be presented in the context of security audits with prior notice.
9.2 Organizational Measures
- Data minimization principle — we collect only data strictly necessary
- Storage limitation principle — automatic deletion upon expiry of the retention period
- Role-based access — access limited to the data necessary for each function
- Confidentiality — all collaborators with access to data have contractual confidentiality obligations
- Incident procedures — documented security incident response plan
- Periodic review — annual evaluation of security measures
10. Notification of Security Incidents (Art. 33-34 GDPR)
In the event of a personal data security breach:
- We will notify the National Supervisory Authority (ANSPDCP) within a maximum of 72 hours of becoming aware of the incident, unless the breach is unlikely to result in a risk to individuals' rights
- When acting as processor, we will notify the affected Controller without undue delay after becoming aware of a breach affecting data processed on its behalf
- If the breach is likely to result in a high risk to individuals' rights, we will directly inform the affected data subjects
- We will document each incident, the measures taken and the outcomes in our internal incident register
11. Cookies and Similar Technologies
For detailed information regarding the use of cookies and localStorage, please consult the Cookie Policy section of this page.
12. Changes to the Privacy Policy
This policy may be updated periodically. The date of the last update is displayed at the top of the document. Significant changes will be communicated by email to registered Users, a visible banner on the platform and publication on this page.
13. Right to Lodge a Complaint
If you consider that the processing of your personal data infringes GDPR, you have the right to lodge a complaint with the supervisory authority:
Address: B-dul G-ral. Gheorghe Magheru no. 28-30, Sector 1, postal code 010336, Bucharest, Romania
Phone: +40.318.059.211 / +40.318.059.212
Email: anspdcp@dataprotection.ro
Website: www.dataprotection.ro
14. Contact
Data Protection Officer (DPO): privacy@rezervatio.ai
General contact: contact@rezervatio.ai
Website: www.rezervatio.ai
Last updated: April 30, 2026 — Version 2.0
EU · Data protection under GDPR