Buy any 3 modules — save 10% · New: ItReserve PMS Bridge now available

Privacy Policy

Version 1.0 · Effective 1 August 2026

This Privacy Policy describes how ItReserve d.o.o. ("ItReserve", "we", "us", "our") collects, uses, stores, and shares personal data when you visit itreserve.org, register an account, purchase a Module Subscription, or otherwise interact with our services. We are committed to protecting your privacy and complying with Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR") as adopted by Montenegro under the Zakon o zaštiti ličnih podataka.

1. Data Controller

The data controller for personal data processed through itreserve.org and associated services is:

  • Company: ItReserve d.o.o.
  • Registration: CRPS 4-0089267/X
  • Tax ID (PIB): 64928153
  • Registered address: ul. Vuka Karadžića 3, 81000 Podgorica, Crna Gora
  • Director: Aleksa Marković
  • Email: support@itreserve.org
  • Phone: +382 20 218 735
  • Supervisory authority: Agencija za zaštitu ličnih podataka (AZLP), registration 05-030/26-2438

Where ItReserve acts as a processor on behalf of a Customer (for example, accessing that Customer's Reservit guest data), the applicable legal framework is set out in the Data Processing Agreement at itreserve.org/dpa.

2. Legal Basis for Processing

We process personal data only where we have a lawful basis under GDPR Article 6. Depending on the activity, the applicable legal basis is:

Processing activityLegal basis (GDPR Art. 6)
Creating and managing your accountArt. 6(1)(b) — performance of a contract
Processing subscription payments and issuing invoicesArt. 6(1)(b) — performance of a contract; Art. 6(1)(c) — legal obligation (accounting)
Activating and operating Modules via Reservit APIArt. 6(1)(b) — performance of a contract
Sending transactional emails (activation confirmations, invoices, renewal reminders)Art. 6(1)(b) — performance of a contract
Sending marketing communications about new Modules or offersArt. 6(1)(a) — consent (opt-in, withdrawable at any time)
Security monitoring, fraud prevention, API abuse detectionArt. 6(1)(f) — legitimate interests
Compliance with accounting and tax obligationsArt. 6(1)(c) — legal obligation
Responding to data-subject rights requestsArt. 6(1)(c) — legal obligation

Where we rely on legitimate interests (Art. 6(1)(f)), we have carried out a balancing test and concluded that our interests do not override the fundamental rights and freedoms of the individuals concerned. You have the right to object to processing based on legitimate interests at any time.

3. Personal Data We Collect

3.1 Account Data

When you register, we collect your email address, a password (stored as a salted cryptographic hash, never in plain text), your company or property name, country, and any optional contact details you choose to provide. Your name may also be collected if you choose to provide it for invoice personalisation.

3.2 Reservit API Credentials

To activate a Module, you supply a Reservit API Key through the Dashboard. This Key is stored in encrypted form and used solely to authenticate requests to the Reservit API on your behalf. ItReserve does not share API Keys with any third party. You may revoke or rotate your Key at any time through the Dashboard or directly within Reservit.

3.3 Billing and Payment Data

We collect billing address details and, where card payment is used, receive a tokenised payment reference from our payment provider — we never store raw card numbers on ItReserve systems. For bank-transfer customers, we record the sender IBAN and transaction reference as provided on the incoming bank notification. Billing records are retained for 7 years as required by Montenegrin accounting law.

3.4 Usage and Log Data

We automatically collect technical log data when you access the Dashboard or when a Module executes an API call. This includes IP address, browser type and version, pages visited, timestamps, HTTP status codes, and request/response metadata. API execution logs record call volumes, response times, and error states — they do not contain guest personal data from your Reservit system in readable form.

3.5 Communication Data

When you contact support, we retain the content of your messages together with your email address and the date of the communication, for as long as the support case is open plus 12 months. Correspondence may be used to improve our knowledge base and support quality.

3.6 Cookie Data

We use cookies and similar technologies as described in our Cookie Policy at itreserve.org/cookies. Analytics data collected through optional cookies is pseudonymised before storage.

4. How We Use the Data

We use the personal data we collect to: create and manage your account; deliver, activate, and maintain your subscribed Modules; process payments and issue invoices; communicate with you about your account, renewals, and service changes; respond to support requests; detect and prevent fraud, abuse, and security threats; comply with legal obligations including accounting, tax, and data-protection law; and, where you have given consent, send marketing communications about ItReserve products and updates.

We do not sell personal data to third parties. We do not use your data for automated individual decision-making that produces significant legal effects on you.

5. Data Retention Periods

CategoryRetention period
Active subscriber account dataDuration of subscription + 3 years after cancellation
Inactive accounts (no purchase)2 years from last login, then deleted
Reservit API KeysDuration of subscription + 90 days (then permanently deleted)
API execution logs90 days from the date of the log entry
Billing records and invoices7 years from the invoice date (legal obligation)
Support communications12 months after case closure
Marketing consent recordsUntil consent is withdrawn + 1 year for evidence of consent
Security/fraud logs12 months

At the end of each retention period, data is securely deleted or irreversibly anonymised.

6. Sub-Processors

We engage the following categories of sub-processors to help deliver our services. Each sub-processor is bound by a data processing agreement and subject to appropriate safeguards:

Sub-processor categoryPurposeData shared
Payment providerCard payment processing and fraud screeningBilling address, tokenised card reference, order amount
Transactional email serviceDelivery of activation confirmations, invoices, support repliesEmail address, first name (if provided), email content
Cloud infrastructure providerHosting of the Dashboard, Module runtime, and encrypted data storageAll account and log data stored within the platform

We will notify Customers by email before adding any new sub-processor that processes personal data on their behalf, and provide an opportunity to object within 14 days. The current sub-processor list is maintained at itreserve.org/dpa.

7. Data Subject Rights

Under GDPR and Montenegrin data-protection law, you have the following rights with respect to your personal data:

  • Right of access (Art. 15 GDPR): You may request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16 GDPR): You may ask us to correct inaccurate or incomplete data.
  • Right to erasure (Art. 17 GDPR): You may request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, you have withdrawn consent, or we have no other legal basis. This right does not apply to data we are required to retain by law (e.g. billing records).
  • Right to restriction (Art. 18 GDPR): You may ask us to restrict processing of your data in certain circumstances while a dispute is resolved.
  • Right to data portability (Art. 20 GDPR): Where processing is based on your consent or on contract performance, and is carried out by automated means, you may request your data in a structured, commonly used, machine-readable format.
  • Right to object (Art. 21 GDPR): You may object at any time to processing based on legitimate interests, including profiling. You may also opt out of marketing communications at any time by clicking "Unsubscribe" in any marketing email or by contacting support.
  • Right to lodge a complaint: You have the right to lodge a complaint with the AZLP or any competent data-protection authority in your country of residence.

To exercise any of these rights, send your request to support@itreserve.org with the subject "Data Subject Request" and include enough information to verify your identity. We will respond within 30 days. Complex or high-volume requests may be extended by a further 60 days, with notification.

8. Cross-Border Transfers

ItReserve stores data on servers located within the European Economic Area (EEA) or in countries with an adequacy decision from the European Commission. Where any transfer to a third country is necessary, we apply appropriate safeguards — such as Standard Contractual Clauses approved by the European Commission — and document those safeguards in our sub-processor agreements. Details of transfer safeguards are available on request.

9. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, ItReserve will notify the AZLP within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33. Where the breach is likely to result in a high risk to affected individuals, we will also notify those individuals without undue delay, providing sufficient information for them to take protective action. Records of all breaches, including those not subject to mandatory notification, are maintained in our internal incident register.

10. AZLP Contact Details

The Montenegrin supervisory authority for personal data protection is:

  • Agencija za zaštitu ličnih podataka (AZLP)
  • Kralja Nikole 2, 81000 Podgorica, Crna Gora
  • Website: azlp.me

ItReserve is registered with AZLP under registration number 05-030/26-2438. You have the right to lodge a complaint with the AZLP if you believe we have processed your personal data unlawfully.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will notify registered account holders by email at least 14 days before the revised policy takes effect. The "Effective" date at the top of this page always reflects the current version. We encourage you to review this page periodically.

12. Contact Us

For any privacy-related queries, requests, or concerns, please contact:

  • Email: support@itreserve.org
  • Post: ItReserve d.o.o., ul. Vuka Karadžića 3, 81000 Podgorica, Crna Gora
  • Phone: +382 20 218 735

We aim to respond to all privacy enquiries within 5 business days and to formally complete data-subject requests within 30 calendar days.