Version 1.0 · Last updated: 6 July 2026
reservaIA is a service of Julià Carboneras Girgas, tax ID (NIF) 40355527A, with registered address at Calle Tramuntana, 30, 17134 La Tallada d'Empordà (Girona), Spain. Privacy contact: gdpr@reservaia.app.
When you write to the WhatsApp, Instagram or other channel of a business that uses reservaIA, your data belongs to that business (restaurant, salon, clinic…): it decides what it is used for. reservaIA only handles that data on its instructions and in order to provide it with the service, under a contract that requires us to do so (Art. 28 GDPR). To exercise your rights over that data, contact the business; we will assist it in responding to you.
For the contact and billing data of our clients (businesses) and the data of those who write to us or visit this website, the controller is reservaIA.
| Purpose | Lawful basis |
|---|---|
| Handling conversations and managing bookings or appointments on behalf of the business | Performance of the relationship between the business and its customer (Art. 6(1)(b) GDPR): the business handles the booking or enquiry you ask it for, and reservaIA does so on its behalf |
| Providing, billing and supporting the service for our clients | Performance of a contract (Art. 6(1)(b)) |
| Security, abuse prevention and service improvement (aggregated metrics) | Legitimate interest (Art. 6(1)(f)) |
| Tax and accounting obligations | Legal obligation (Art. 6(1)(c)) |
Messages are processed using artificial intelligence models in order to understand the enquiry and generate the response. Our AI providers only handle the data in order to provide the service, under contracts that require them to. Data is not sold, is not used for advertising and is not used to train AI models. For sensitive enquiries (for example, allergies or allergens), the assistant is configured to refer the matter to a person at the business.
We do not disclose data to third parties other than the providers necessary to deliver the service, with whom we have contracts requiring them to handle it solely for that purpose (Art. 28 GDPR), by category:
Where any of these providers is located outside the European Economic Area, the transfer is covered by the European Commission's standard contractual clauses and/or by the EU-U.S. Data Privacy Framework.
Conversations and booking data are kept for as long as the business's relationship with reservaIA lasts, in accordance with its instructions and configuration, and are deleted or returned to the business upon termination of the service. Billing data is kept for the applicable statutory periods (tax and commercial legislation).
You may exercise your rights of access, rectification, erasure, objection, restriction and portability by writing to gdpr@reservaia.app. If your data comes from your conversation with the assistant of a business, the controller is the business: we will redirect you and assist it in responding to you. You may also lodge a complaint with the Spanish Data Protection Agency (AEPD) (aepd.es).
We apply appropriate technical and organisational measures: encryption in transit, encryption of integration credentials, per-client access control (multi-tenant architecture) and the principle of least access.
The service is not aimed at children under 14 and we do not knowingly process their data.
We will publish any update here, indicating the date of the version. If the change is relevant for client businesses, we will also notify them directly.