Privacy Policy
ReserveWithIt d.o.o. — Version 2.1 — Last updated: 1 June 2024
1. Introduction and scope
This Privacy Policy explains how ReserveWithIt d.o.o. ("ReserveWithIt", "we", "us") collects, uses, stores, and transfers personal data in connection with the ReserveWithIt extension shop at reservewithit.org and all associated modules and services ("Service").
We are committed to protecting your privacy and processing your personal data in accordance with: the EU General Data Protection Regulation (GDPR) 2016/679; the Montenegrin Law on Personal Data Protection (Zakon o zaštiti podataka o ličnosti, ZZPL); and applicable national implementing legislation.
This policy applies to: (a) hotel operators and businesses purchasing ReserveWithIt modules ("Customers"); and (b) hotel guests whose data may be processed by ReserveWithIt modules on behalf of Customer hotels (as described in Section 7).
2. Personal data we collect about Customers
2.1 Account registration data: When you purchase a module, we collect your name, email address, company/property name, billing country, and VAT number (if provided). This is necessary to create and manage your account and deliver the Service.
2.2 API credentials: You provide Reservit API keys and API endpoint URLs to connect our modules to your Reservit account. These credentials are stored encrypted (AES-256) and are processed solely to enable module functionality.
2.3 Payment data: We collect minimal billing data necessary to generate invoices (name, company, country, VAT number). Actual payment card processing is handled by our payment partner. ReserveWithIt does not store card numbers, CVV codes or full card data.
2.4 Usage and log data: We collect logs of API calls made to third-party systems on your behalf, module activation events, error logs, and platform access events. This data is used for service quality monitoring, debugging, and security purposes.
2.5 Communication data: When you contact us by email or through the contact form, we collect your name, email address, and the content of your communication. This is used solely to respond to your enquiry.
2.6 Cookie data: We use cookies as described in the Cookie Policy at reservewithit.org/cookies.
3. Legal bases for processing
| Processing activity | Legal basis |
|---|---|
| Account creation and management | Performance of contract (Art. 6(1)(b) GDPR) |
| Module delivery and API connectivity | Performance of contract (Art. 6(1)(b) GDPR) |
| Billing and invoicing | Performance of contract + legal obligation (Art. 6(1)(b)+(c) GDPR) |
| Security monitoring and fraud prevention | Legitimate interests (Art. 6(1)(f) GDPR) |
| Product improvement and analytics | Legitimate interests (Art. 6(1)(f) GDPR) |
| Marketing communications (existing customers) | Legitimate interests (Art. 6(1)(f) GDPR / soft opt-in) |
| Marketing communications (prospects) | Consent (Art. 6(1)(a) GDPR) |
| Guest data processed as processor | Customer's legal basis (data processor role) |
4. Data retention periods
| Data category | Retention period | Justification |
|---|---|---|
| Account and billing data | 7 years after account closure | Legal and accounting obligations |
| API call logs | 12 months rolling | Debugging and security monitoring |
| Support communications | 3 years after closure of ticket | Legitimate interests — dispute resolution |
| Module usage analytics | 24 months aggregated | Product improvement, legitimate interests |
| Marketing consent records | Until consent withdrawn + 3 years | Compliance record |
| Cookie consent records | 13 months | ePrivacy Directive compliance |
| Guest data (processed as processor) | Per Customer instruction — default 30 days | DPA obligation |
5. Data sharing and sub-processors
5.1 We share personal data only to the extent necessary to provide the Service and only with parties who have provided appropriate data protection guarantees.
5.2 Current sub-processors and recipients:
| Recipient | Role | Location | Transfer mechanism |
|---|---|---|---|
| Cloud infrastructure provider (Hetzner) | Hosting and data storage | EU (Germany) | Intra-EEA — no transfer |
| Mailgun Technologies | Transactional email delivery | EU (Ireland) | Intra-EEA — no transfer |
| Stripe (payment partner) | Payment processing | EU (Ireland) | Intra-EEA — no transfer |
| Reservit SAS (via API) | Data retrieved on Customer's behalf | France (EU) | Intra-EEA — no transfer |
5.3 We do not sell personal data to third parties. We do not share personal data with advertisers or marketing platforms without explicit consent.
6. International transfers
6.1 ReserveWithIt d.o.o. is incorporated in Montenegro. Montenegro has received an EU adequacy decision (Decision 2012/484/EU) confirming that it provides an adequate level of protection for personal data. Transfers from the EU to ReserveWithIt d.o.o. therefore do not require additional safeguards under GDPR Art. 46.
6.2 All primary data processing infrastructure is located within the EEA. Where sub-processors outside the EEA are used, Standard Contractual Clauses (SCCs) approved by the European Commission are in place.
7. Guest data — ReserveWithIt as data processor
Certain ReserveWithIt modules (in particular Guest Portal and CRM Link) retrieve and process personal data about hotel guests on behalf of Customer hotels. In this context, ReserveWithIt acts as a data processor and the Customer hotel acts as the data controller. The processing is governed by the Data Processing Agreement (DPA) available at reservewithit.org/dpa, which forms part of the contract between ReserveWithIt and each Customer.
Guest data processed as a processor is: (a) used solely to deliver the contracted module functionality; (b) not used for ReserveWithIt's own marketing or analytics; (c) deleted or returned to the Customer within 30 days of contract termination; and (d) never shared with third parties except as instructed by the Customer or required by law.
8. Your rights as a data subject
Under GDPR and applicable Montenegrin law, you have the following rights in relation to your personal data:
- Right of access (Art. 15): Request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): Request correction of inaccurate data.
- Right to erasure (Art. 17): Request deletion of your data, subject to legal retention obligations.
- Right to restriction of processing (Art. 18): Request that we temporarily stop processing your data.
- Right to data portability (Art. 20): Receive your data in a machine-readable format.
- Right to object (Art. 21): Object to processing based on legitimate interests.
- Right to withdraw consent: Where processing is based on consent, withdraw consent at any time without affecting prior processing.
- Right to lodge a complaint: Lodge a complaint with the Agencija za zaštitu ličnih podataka (AZLP) or the supervisory authority of your EU member state of habitual residence.
To exercise any of these rights, contact us at support@reservewithit.org with subject line "Data Subject Request". We will respond within 30 days and may require identity verification before fulfilling certain requests.
9. Security
We implement technical and organisational measures appropriate to the risk, including: AES-256 encryption for API credentials at rest; TLS 1.3 for all data in transit; access controls limiting staff access to personal data on a need-to-know basis; regular security reviews; automated anomaly detection; and incident response procedures.
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay and in any case within 72 hours of becoming aware of the breach.
10. Contact and complaints
Data protection enquiries: support@reservewithit.org
Supervisory authority (Montenegrin): Agencija za zaštitu ličnih podataka (AZLP), Kralja Nikole 2, 81000 Podgorica, Crna Gora, reg. 05-030/26-2241
EU residents may also contact the supervisory authority in their member state of habitual residence.