Privacy policy
How Reserviq processes personal data on the marketing website (Spain / GDPR).
Last updated: 9 August 2026.
0. Scope (read this first)
This policy applies only to:
- the Reserviq marketing website (
reserviq.appand equivalent public routes), and - processing where Reserviq acts as controller (e.g. demo/contact requests and, if you accept, web analytics).
It is not the product SaaS data-processing agreement and does not replace:
- the customer service agreement / terms, or
- the Art. 28 GDPR data processing agreement (DPA) covering guest and lodging-operations data, executed with the service agreement (not published on this site).
If you are a customer (hotel, apartment, rural stay, etc.) using the product for check-in, MIR or other features: you are generally the controller of your guests’ and your organisation’s staff data; Reserviq acts as processor under the contract and DPA. This page does not expand that processing.
Privacy contact: [email protected].
1. Controller (marketing site)
- Trading name: Reserviq
- Email: [email protected]
- Website: https://reserviq.app
Company identification (Spanish LSSI): full legal name, tax ID and registered address will be published in this section when available and may be requested meanwhile at the email above. We do not invent corporate details in this document.
No Data Protection Officer is appointed at this time; requests are handled at the email above.
2. Data we process (Reserviq as controller)
2.1 Contact / demo form
We may process: name, email, company/property and message.
Current form status: submission may be provisional (technical/test logging, no production CRM). If you provide data, we will use it only to handle your request or for technical testing — not for automated advertising and not sold to third parties for commercial purposes.
When the channel is wired to a CRM or similar tool, the primary purpose (handling your request) remains unless we inform you of a material change here.
2.2 Email
If you write to [email protected], we process content needed to reply.
2.3 Cookies and analytics (consent only)
If you accept on the cookie banner, we may load Google Tag Manager (GTM-WHVK4LVT or another container we indicate) and tags configured in that container (typically measurement / Analytics).
If you reject, we do not load Tag Manager or related analytics tags. The site still works.
We may store your cookie preference in the browser (e.g. localStorage) as an essential technical measure.
We do not currently operate first-party advertising cookies. If the GTM container later includes advertising/remarketing tags, they will run only with consent, and we will update this policy and the banner.
2.4 Data this policy does not cover as Reserviq controller
Guest data, MIR reports, bookings, product staff credentials and other SaaS data processed for the customer are governed by the contract + DPA, not this page.
3. Purposes and legal bases
- Handle contact / demo requests — GDPR Art. 6(1)(b) (pre-contractual steps at your request) and, where applicable, 6(1)(f) (legitimate interest in answering B2B enquiries), balanced against your rights.
- Site security and abuse prevention — GDPR Art. 6(1)(f).
- Web analytics via GTM / Analytics — GDPR Art. 6(1)(a) (consent); withdrawable at any time.
- Legal obligations applicable to Reserviq — GDPR Art. 6(1)(c).
We do not make automated decisions with legal effects about you based on marketing-site use.
Commercial communications: only if requested or another valid basis exists. You may object or withdraw consent at any time.
4. Retention
- Contact / demo: up to 12 months from the last relevant interaction on that request, unless a contract follows (then the contract applies), legal retention applies, or you validly request earlier erasure.
- Cookie preference: while stored on your device or until you clear/change it.
- Minimal technical logs (if any): only as needed for security and diagnostics.
5. Recipients
Access only as needed by:
- Hosting / infrastructure and site tooling vendors under contract.
- Google (Tag Manager / Analytics or other container tags), only if you accepted analytics cookies.
- Professional advisers under confidentiality where needed.
- Public authorities where legally required.
We do not sell personal data.
6. International transfers
Some vendors (notably Google) may process data outside the EEA. Where that happens, GDPR safeguards apply (e.g. standard contractual clauses or other valid measures).
7. Rights
You may exercise access, rectification, erasure, objection, restriction and portability where applicable, and withdraw consent without affecting prior lawful processing, by emailing [email protected].
We will respond within the legal timeframe (generally one month).
You may also complain to the Spanish Data Protection Agency (AEPD): www.aepd.es, or your local supervisory authority.
8. Security
We apply reasonable technical and organisational measures proportionate to marketing-site risk (access control, HTTPS, minimisation). No system is 100% secure; please do not send specially sensitive data via the contact form.
9. Children
The site is not directed at children under 14. We do not knowingly collect their data. If you become aware of a case, contact us for erasure.
10. Product customers (clarification only)
For guest and lodging-operations data:
- The customer determines purposes and essential means → controller.
- Reserviq processes data to provide the service → processor, under documented instructions and the DPA.
- Lodging / MIR compliance and accuracy of data sent to authorities remain the customer’s responsibility.
- SaaS warranties, retention, sub-processors and security are set in the contract/DPA — not this marketing policy.
11. Changes
We may update this policy. The “last updated” date shows the current version. Material changes will appear here. Continued use after publication means you are aware of the current version; where consent is required for a change, we will ask again.