General Data Protection Regulation (GDPR) Compliance

Last updated: June 5, 2025

Introduction

At ReservationsOS, we are committed to protecting the privacy and security of your personal data. This GDPR Policy explains how we collect, use, and protect your personal information in accordance with the General Data Protection Regulation (GDPR).

This policy applies to all personal data processed by CODEX AI SRL, operating as ReservationsOS.

Data Controller

CODEX AI SRL (ReservationsOS) is the data controller for the personal information we process. We are registered in Romania with company registration number J2024043625002 and CUI 50929706.

You can contact us regarding data protection matters at:

What Personal Data We Collect

We may collect and process the following categories of personal data:

  • Identity Data: Name, title, company name
  • Contact Data: Email address, telephone number, business address
  • Technical Data: IP address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform
  • Usage Data: Information about how you use our website and services

How We Collect Your Personal Data

We collect personal data through:

  • Direct interactions when you contact us through our website, email, or phone
  • Automated technologies or interactions through cookies and similar technologies
  • Third parties or publicly available sources

How We Use Your Personal Data

We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:

  • To provide you with information about our services
  • To respond to your inquiries
  • To perform the contract we are about to enter into or have entered into with you
  • Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests
  • Where we need to comply with a legal or regulatory obligation

Legal Basis for Processing

We rely on the following legal bases for processing your personal data:

  • Consent: Where you have given us explicit consent to process your personal data
  • Contract: Where processing is necessary for the performance of a contract with you
  • Legal Obligation: Where processing is necessary for compliance with a legal obligation
  • Legitimate Interests: Where processing is necessary for our legitimate interests or those of a third party

Data Retention

We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process the data, and whether we can achieve those purposes through other means.

Your Rights Under GDPR

Under the GDPR, you have the following rights:

  • Right to Access: You have the right to request copies of your personal data.
  • Right to Rectification: You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
  • Right to Erasure: You have the right to request that we erase your personal data, under certain conditions.
  • Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data, under certain conditions.
  • Right to Object to Processing: You have the right to object to our processing of your personal data, under certain conditions.
  • Right to Data Portability: You have the right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.

If you make a request, we have one month to respond to you. If you would like to exercise any of these rights, please contact us at .

Data Security

We have implemented appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorized way, altered, or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors, and other third parties who have a business need to know.

We have procedures in place to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

International Transfers

We may transfer your personal data to countries outside the European Economic Area (EEA). Whenever we transfer your personal data out of the EEA, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:

  • We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission.
  • Where we use certain service providers, we may use specific contracts approved by the European Commission which give personal data the same protection it has in Europe.

Changes to This GDPR Policy

We may update this GDPR Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.

We encourage you to review this GDPR Policy periodically to stay informed about how we are protecting your personal data.

Contact Us

If you have any questions about this GDPR Policy or our data practices, please contact us at: