Privacy Policy
1. Data controller
The data controller is YRD SOLUTIONS S.R.L., with registered office in Constanta, Soseaua Mangaliei no. 57, Block SM1, Entrance B, 1st floor, Apt. 50, Constanta county, Romania, tax ID 50377628, Trade Register no. J13/2265/16.07.2024, EUID ROONRC.J13/2265/2024.
For personal data requests, contact us at Legal@rezerva.online.
2. Data we process
- Identity data: first name, last name, business name.
- Contact data: email, phone number, address if provided.
- Business fiscal and legal data: legal form, fiscal country, trading or legal name, address, CUI/CIF, company number and VAT number when provided or required.
- Operational data: bookings, selected services, internal notes.
- Account data: credentials, technical tokens, access roles.
- Commercial data: plans, payments, invoices, transaction history.
- Technical data: IP address, security logs, browser or device information.
3. Purposes and legal bases
- Providing the platform services, for contract performance.
- Account management, authentication and security, based on legitimate interest and, where applicable, legal obligations.
- Payment processing, billing and tax compliance.
- Preparing data required for fiscal documents, including future invoicing integrations, when the business enables or requests those features.
- Operational communications, including confirmations, appointment notifications and transactional messages.
- Defending rights in case of disputes or fraud.
4. Recipients and processors
To operate the services, we may share data with infrastructure and service providers on a need-to-know basis.
These providers act as processors or separate controllers depending on the nature of the service and their own terms.
- payment processors, including Stripe;
- cloud infrastructure and hosting, including Vercel;
- database and authentication services, including Supabase;
- transactional messaging providers, including Meta WhatsApp Cloud API and SMSLink;
- technical providers involved in operating the application.
5. International transfers
Some data may be transferred outside the EEA through global providers. In such cases, we apply appropriate safeguards, such as standard contractual clauses and technical or organizational protections, in accordance with GDPR.
6. Retention period
We retain data only for as long as necessary for the purposes for which it was collected, plus the periods required by law, such as tax, accounting or legal defence periods.
7. Data subject rights
Under applicable law, you have the right of access, rectification, erasure, restriction, objection, portability, and the right to withdraw consent when processing is based on consent.
You also have the right to lodge a complaint with the competent supervisory authority.
8. Data security
We apply reasonable technical and organizational measures to protect data, including access control, authentication, logging and infrastructure security. No method of transmission or storage can guarantee absolute security.
9. Children's data
The services are not directed to minors under the age required by law for digital consent. If we learn that data has been collected improperly, we will take steps to delete or restrict it.
10. Changes to this policy
We may update this policy periodically to reflect legal, technical or operational changes. The version published on the website is the applicable version.
11. Contact
For GDPR rights requests or any question about this policy: Legal@rezerva.online.