Back to site
Terms and Conditions Privacy Policy Cookie Policy GDPR

Privacy Policy

Version 2.0 — Last updated: April 30, 2026

This Privacy Policy describes how QUANTEMI S.R.L. ("Rezervatio", "we") collects, uses, stores, shares and protects personal data, in accordance with the General Data Protection Regulation (GDPR — EU Regulation 2016/679), Romanian Law no. 190/2018 and applicable legislation.

This policy applies to Users (business owners using the platform), End Customers (persons who call and interact with the AI voice agent), and Rezervatio Book app users (customers who make reservations directly through our mobile app).

1. Identity of the Controller / Processor

Name: QUANTEMI S.R.L.
Tax ID (CUI): 54694424
Trade Registry No.: J2026031979003
Registered office: Năvodari, Jud. Constanța, Str. Liniștii nr. 8
General email: contact@rezervatio.ai
Data protection email (DPO): privacy@rezervatio.ai
Website: www.rezervatio.ai

1.1 GDPR Roles

ContextRezervatio RoleExplanation
User data (account, billing)Data ControllerRezervatio decides the purpose and means of processing the User's account data
End Customer data (reservations, calls)Data ProcessorRezervatio processes End Customer data on behalf of and in accordance with the instructions of the User (the controller)

1.2 Data-protection contact

For questions about data protection or to exercise your GDPR rights, contact privacy@rezervatio.ai. We respond within a maximum of 30 days under Art. 12(3) GDPR.

2. Personal Data We Collect

2.1 User Data (business owners) — Rezervatio as Controller

CategorySpecific DataPurposeLegal Basis
Account and authenticationFirst name, last name, email address, password (cryptographic hash)Account creation, authentication, communicationPerformance of contract — Art. 6(1)(b)
Business dataBusiness name, address, phone, email, business sector, Tax ID (optional)AI agent configuration, service personalizationPerformance of contract — Art. 6(1)(b)
Operational configurationOperating hours, zones, tables/seats, agent preferences, custom messagesProper operation of the reservation servicePerformance of contract — Art. 6(1)(b)
Billing dataCard data (processed exclusively by a certified payment processor — Rezervatio does not store card numbers), billing address, Tax IDPayment processing, invoicingPerformance of contract — Art. 6(1)(b) + Legal obligation — Art. 6(1)(c)
Usage dataMinutes consumed, number of calls, dashboard activity logsBilling, statistics, service improvementPerformance of contract — Art. 6(1)(b) + Legitimate interest — Art. 6(1)(f)
Technical dataIP address, browser type, operating system, pages accessedSecurity, troubleshooting, fraud preventionLegitimate interest — Art. 6(1)(f)

2.2 End Customer Data (callers) — Rezervatio as Processor

CategorySpecific DataPurposeLegal Basis (of the User)
Reservation dataFirst name, last name, phone number (caller ID), email (optional), number of personsCreating, managing and confirming the reservationLegitimate interest of the business — Art. 6(1)(f) or Consent — Art. 6(1)(a)
PreferencesFood allergies, special occasions, special requests, preferred zonePersonalizing the experience, food safetyLegitimate interest — Art. 6(1)(f) / Consent — Art. 6(1)(a)
Voice dataVoice in real-time (processed via streaming, not stored as audio file on Rezervatio servers), text transcript of the conversationUnderstanding and processing the reservation request via the AI agentLegitimate interest — Art. 6(1)(f)
Call metadataCaller phone number (caller ID), called number, call duration, date and time, session identifierBilling the User, statistics, technical support, auditPerformance of contract with the User — Art. 6(1)(b) + Legitimate interest — Art. 6(1)(f)
Important regarding voice data: The conversation is processed through ElevenLabs so that the AI voice agent can operate. Rezervatio.AI does not retain the audio file or full transcript in its own database; it may retain call metadata and an operational summary. The voice provider may process and temporarily retain audio, transcripts and technical data under the service configuration, contractual agreement and its own privacy policy. Retention details may be requested at privacy@rezervatio.ai.
Important — special-category data (Art. 9 GDPR): In the context of medical clinics or dental practices, phone conversations or bookings made with healthcare providers may incidentally reveal health information (symptoms, reason for visit). The AI voice agent is instructed not to explicitly request such data — in particular, it no longer asks about allergies. If the caller mentions it on their own initiative, it is processed strictly for managing the reservation and benefits from the same security measures as all other data.

2.5 Demo Call (unauthenticated visitor)

When you initiate a demo call from the homepage ("Call me" form):

CategorySpecific DataSource
Call identificationPhone number, IP address, timestampVisitor (manual input)
Anti-abuseTemporary OTP code (SMS, valid 10 minutes), Cloudflare Turnstile tokenGenerated automatically to verify number ownership

Legal basis: explicit consent (Art. 6(1)(a) GDPR). You grant permission by pressing "Call me" and entering the OTP code received via SMS.

Sub-processors: the same as for the entire platform — see section 5 (Telnyx for telephony/SMS, ElevenLabs for AI voice processing, and Cloudflare for Turnstile bot protection).

The voice conversation is processed through ElevenLabs. Rezervatio.AI does not retain the audio file or full transcript in its own database; it may retain call metadata and an operational summary. The provider may temporarily process and retain audio, transcripts and technical information according to its configuration, contractual terms and privacy policy.

Demo-specific retention: phone number and IP are automatically deleted after 7 days (strict period for abuse prevention — multiple calls to third-party numbers). OTP codes expire in 10 minutes and are cleaned up after 24 hours.

Your rights: you can request immediate deletion of the number used by emailing privacy@rezervatio.ai. Data is deleted within 72 hours.

2.3 Data collected from Rezervatio Book app users

Users who create an account in the Rezervatio Book mobile app to book directly (without a phone call):

CategorySpecific data
Account identificationPhone number (OTP login); name is required at first login; email (if you sign in with Google or Apple)
Own reservationsHistory of reservations made via the app, status, notes
Reservation messagesContent of messages exchanged with the business in connection with a reservation. Deleted when the account is deleted. Basis: performance of the contract (Art. 6(1)(b)).
FavoritesBusinesses / specialists saved as favorites
Push notificationsPush notification token / notification identifier generated by the device operating system, used solely for reservation-related notifications; can be disabled anytime in settings. Basis: consent (Art. 6(1)(a)).
LocationOn-device only (if you grant access), to display the map and nearby businesses — it is not transmitted to or stored on our servers.
CameraCamera access is used only to scan a business QR code (quick booking). The image is processed on-device; it is not transmitted to or stored on our servers.
CalendarIf you choose "Add to calendar", the reservation is written as an event to your device calendar. This is a strictly local operation; we do not access or store your calendar data.
Usage dataLogin IP addresses, device, operating system
ConsentsAcceptance by continued use (Terms + Privacy Policy); the app does not record versions/date/IP — unlike the business dashboard account, where consents are recorded with versioning.

2.4 Data collected automatically from website visitors

When you visit rezervatio.ai, we collect the minimum technical information needed for operation, security and aggregate analysis: an IP address transformed using a rotating daily cryptographic hash, browser and operating-system type, pages visited and referrer. Cloudflare may set the essential _cf_bm security cookie, and the browser stores interface preferences such as theme, language and cookie choice.

We do not use Google Analytics, Facebook Pixel or other advertising-tracking services on the presentation website.

3. Legal Basis for Processing (Art. 6 GDPR)

Legal BasisGDPR ArticleApplicability
Performance of contractArt. 6(1)(b)Providing services to Users under the chosen subscription; processing reservations
Legitimate interestArt. 6(1)(f)Service improvement, fraud prevention, security, aggregated statistics, technical support
ConsentArt. 6(1)(a)Marketing communications (newsletter, promotions) — optional, with the possibility of withdrawal at any time
Legal obligationArt. 6(1)(c)Tax and accounting compliance (retention of invoices for 10 years per the Tax Code), responding to authority requests

4. How We Use the Data

We use personal data exclusively for:

We DO NOT use data for: automated profiling with legal effects, sale to third parties, behavioural advertising, exclusively automated decision-making with significant impact.

5. Providers and data recipients

We do not sell or rent your data. We use specialised providers that may act as processors, sub-processors or, for certain operations of their own, independent controllers. Their role depends on the service and the applicable contractual terms. When Rezervatio acts as a processor for a business customer, the relevant sub-processors are listed in the DPA.

ProviderPossible roleHead office / processing regionsPurpose
Hetzner Online GmbHProcessor / sub-processorGermany, European UnionHosting the primary infrastructure, backend services and databases managed by Rezervatio
Cloudflare Inc.Processor / sub-processor; controller for certain services of its ownUnited States / global infrastructureSecurity, DDoS and abuse protection, content delivery and traffic management
Scaleway SASProcessor / sub-processorFrance, European UnionTransactional and operational emails, including confirmations, invitations and account notices
Telnyx LLCProcessor / sub-processorUnited States; services also available in the EEA depending on configurationTelephone numbers, call routing and SMS delivery
ElevenLabs Inc.Processor / sub-processorUnited States / infrastructure under the applicable configuration and agreementConversation processing for the AI voice agent: speech recognition, voice-response generation and technical transcription
StripeProcessor and/or independent controller, depending on the operationIreland / United States, depending on the contracting entityPayments, subscriptions and fraud prevention when the service is enabled
Apple Inc.Service provider and independent controller for its own operationsUnited States / global infrastructureSign in with Apple and push-notification delivery to Apple devices
Google Ireland Limited / Google LLCService provider and independent controller for its own operationsIreland / United States, with global infrastructureGoogle Sign-In; Android notification delivery will be documented when that service is enabled
Expo / 650 Industries, Inc.ProcessorUnited States / global infrastructureRelaying Rezervatio Book push notifications to the device platform's delivery service

Actual processing regions may vary by service and configuration. International transfers use the applicable legal mechanisms described in section 6. The sub-processors used when Rezervatio acts for a business customer are listed in the Data Processing Agreement (DPA).

5.1 Notice of sub-processor changes

The Controller (B2B User) will be notified at least 30 days before the addition or replacement of a sub-processor, in accordance with Art. 28(2) GDPR.

6. International Transfers

Core platform data is hosted in the European Union. Some providers operate globally or in the United States. For those transfers we use an applicable Chapter V GDPR mechanism, including the EU-US Data Privacy Framework for participating organisations and/or the European Commission's Standard Contractual Clauses, together with supplementary safeguards where appropriate. Telnyx offers European processing options; ElevenLabs voice processing currently uses global infrastructure subject to the applicable contractual safeguards.

7. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected or as required by law:

Data TypeRetention PeriodJustification
User account (active)For the entire duration of the active accountNecessary for service provision
Reservations and related operational dataFor the account term and thereafter as necessary for the purpose, legal obligations or defence of rightsDeletion or anonymisation, as applicable
Call metadata and summariesAs necessary to provide and support the service, maintain security and resolve incidentsDeletion or anonymisation under the applicable policy
Full audio and transcripts processed by the AI voice providerAccording to the provider configuration and applicable contractual agreementDeletion under provider settings and procedures; details available on request
Technical and security data, including IP addresses and logsAs necessary for abuse prevention, security and incident investigationDeletion, truncation or anonymisation, as applicable
Account after a confirmed deletion request7 days (access-restoration grace period)Afterwards, the active identity is removed and operational data is deleted or anonymised, subject to legal exceptions
Consent, export and deletion-request recordsAs necessary to demonstrate compliance and defend legal rightsRestricted access; deletion when no longer necessary or legally required
Billing and tax data10 yearsLegal obligation — Tax Code, Accounting Law
Demo calls (phone, IP and anti-abuse data)A short period limited to abuse prevention and securityDeletion or anonymisation under the operational procedure
Demo OTP codesValid for 10 minutes; related technical data is retained only as necessary for securityInvalidation at expiry and subsequent cleanup

We apply technical and organisational deletion or anonymisation procedures. You may request the criteria applicable to a specific category of data at privacy@rezervatio.ai.

8. Your Rights (Art. 15-22 GDPR)

As a data subject, you have the following rights, exercisable free of charge:

8.1 Right of Access (Art. 15)

You may request confirmation that we process personal data concerning you and a copy of such data, together with information on the purpose, categories, recipients and retention periods.

8.2 Right to Rectification (Art. 16)

You may request the correction of inaccurate data or completion of incomplete data concerning you, without undue delay.

8.3 Right to Erasure — "Right to be Forgotten" (Art. 17)

Rezervatio Book users can request deletion in the app under Settings → Account → Delete account; business owners can do so in the dashboard under Account → Delete account. Following confirmation, there is a 7-day grace period during which access may be restored through a unique link. Afterwards, the active identity and operational data are deleted or anonymised according to purpose and applicable obligations. Tax, security or audit records may be retained where required by law or the defence of rights. Data already anonymised cannot be restored.

8.4 Right to Restriction of Processing (Art. 18)

You may request the limitation of processing if: you contest the accuracy of the data; the processing is unlawful but you do not want deletion; we need the data for the establishment/exercise of a right in court; you have objected to the processing (pending verification).

8.5 Right to Data Portability (Art. 20)

You may request your data in a structured, commonly used and machine-readable format (JSON) by contacting privacy@rezervatio.ai, and you have the right to transmit such data to another controller. We respond within the legal time limit (one month, Art. 12(3) GDPR).

8.6 Right to Object (Art. 21)

You may object at any time to processing based on legitimate interest (Art. 6(1)(f)), including profiling. We will cease processing unless we demonstrate compelling legitimate grounds.

8.7 Right not to be Subject to an Automated Decision (Art. 22)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similar. Our AI agent processes reservation requests but does not make decisions with significant legal effects on data subjects.

8.8 Right to Withdraw Consent (Art. 7(3))

In case of processing based on consent, you may withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal.

8.9 Exercising Your Rights

Contact: privacy@rezervatio.ai
Response time: maximum 30 calendar days from receipt of the request (extendable by 60 days in complex cases, with notification)
Identification: We may request identity verification to prevent unauthorized access to data
Cost: Free. In case of repetitive or excessive requests, we may charge a reasonable fee or refuse the request, in accordance with Art. 12(5) GDPR.

End Customers (persons making reservations): since the User (the business) is the controller of your data, please first address the respective business. If you do not receive a satisfactory response within 30 days, you may contact us directly at privacy@rezervatio.ai.

8.10 Right to lodge a complaint

You may lodge a complaint with ANSPDCP or with the data-protection authority in the Member State of your habitual residence or workplace.

9. Data Security (Art. 32 GDPR)

We implement appropriate technical and organizational measures, in accordance with Art. 32 GDPR, including:

9.1 Technical Measures

The complete technical details regarding security measures are available to active B2B customers under the Data Processing Agreement (DPA) and may be presented in the context of security audits with prior notice.

9.2 Organizational Measures

10. Notification of Security Incidents (Art. 33-34 GDPR)

In the event of a personal data security breach:

11. Cookies and Similar Technologies

For detailed information regarding the use of cookies and localStorage, please consult the Cookie Policy section of this page.

12. Changes to the Privacy Policy

This policy may be updated periodically. The date of the last update is displayed at the top of the document. Significant changes will be communicated by email to registered Users, a visible banner on the platform and publication on this page.

13. Right to Lodge a Complaint

If you consider that the processing of your personal data infringes GDPR, you have the right to lodge a complaint with the supervisory authority:

National Supervisory Authority for Personal Data Processing (ANSPDCP)
Address: B-dul G-ral. Gheorghe Magheru no. 28-30, Sector 1, postal code 010336, Bucharest, Romania
Phone: +40.318.059.211 / +40.318.059.212
Email: anspdcp@dataprotection.ro
Website: www.dataprotection.ro

14. Contact

QUANTEMI S.R.L.
Data Protection Officer (DPO): privacy@rezervatio.ai
General contact: contact@rezervatio.ai
Website: www.rezervatio.ai

Last updated: April 30, 2026 — Version 2.0