Privacy Policy
Version 1.0 · Effective 1 August 2026
This Privacy Policy describes how ItReserve d.o.o. ("ItReserve", "we", "us", "our") collects, uses, stores, and shares personal data when you visit itreserve.org, register an account, purchase a Module Subscription, or otherwise interact with our services. We are committed to protecting your privacy and complying with Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR") as adopted by Montenegro under the Zakon o zaštiti ličnih podataka.
1. Data Controller
The data controller for personal data processed through itreserve.org and associated services is:
- Company: ItReserve d.o.o.
- Registration: CRPS 4-0089267/X
- Tax ID (PIB): 64928153
- Registered address: ul. Vuka Karadžića 3, 81000 Podgorica, Crna Gora
- Director: Aleksa Marković
- Email: support@itreserve.org
- Phone: +382 20 218 735
- Supervisory authority: Agencija za zaštitu ličnih podataka (AZLP), registration 05-030/26-2438
Where ItReserve acts as a processor on behalf of a Customer (for example, accessing that Customer's Reservit guest data), the applicable legal framework is set out in the Data Processing Agreement at itreserve.org/dpa.
2. Legal Basis for Processing
We process personal data only where we have a lawful basis under GDPR Article 6. Depending on the activity, the applicable legal basis is:
| Processing activity | Legal basis (GDPR Art. 6) |
|---|---|
| Creating and managing your account | Art. 6(1)(b) — performance of a contract |
| Processing subscription payments and issuing invoices | Art. 6(1)(b) — performance of a contract; Art. 6(1)(c) — legal obligation (accounting) |
| Activating and operating Modules via Reservit API | Art. 6(1)(b) — performance of a contract |
| Sending transactional emails (activation confirmations, invoices, renewal reminders) | Art. 6(1)(b) — performance of a contract |
| Sending marketing communications about new Modules or offers | Art. 6(1)(a) — consent (opt-in, withdrawable at any time) |
| Security monitoring, fraud prevention, API abuse detection | Art. 6(1)(f) — legitimate interests |
| Compliance with accounting and tax obligations | Art. 6(1)(c) — legal obligation |
| Responding to data-subject rights requests | Art. 6(1)(c) — legal obligation |
Where we rely on legitimate interests (Art. 6(1)(f)), we have carried out a balancing test and concluded that our interests do not override the fundamental rights and freedoms of the individuals concerned. You have the right to object to processing based on legitimate interests at any time.
3. Personal Data We Collect
3.1 Account Data
When you register, we collect your email address, a password (stored as a salted cryptographic hash, never in plain text), your company or property name, country, and any optional contact details you choose to provide. Your name may also be collected if you choose to provide it for invoice personalisation.
3.2 Reservit API Credentials
To activate a Module, you supply a Reservit API Key through the Dashboard. This Key is stored in encrypted form and used solely to authenticate requests to the Reservit API on your behalf. ItReserve does not share API Keys with any third party. You may revoke or rotate your Key at any time through the Dashboard or directly within Reservit.
3.3 Billing and Payment Data
We collect billing address details and, where card payment is used, receive a tokenised payment reference from our payment provider — we never store raw card numbers on ItReserve systems. For bank-transfer customers, we record the sender IBAN and transaction reference as provided on the incoming bank notification. Billing records are retained for 7 years as required by Montenegrin accounting law.
3.4 Usage and Log Data
We automatically collect technical log data when you access the Dashboard or when a Module executes an API call. This includes IP address, browser type and version, pages visited, timestamps, HTTP status codes, and request/response metadata. API execution logs record call volumes, response times, and error states — they do not contain guest personal data from your Reservit system in readable form.
3.5 Communication Data
When you contact support, we retain the content of your messages together with your email address and the date of the communication, for as long as the support case is open plus 12 months. Correspondence may be used to improve our knowledge base and support quality.
3.6 Cookie Data
We use cookies and similar technologies as described in our Cookie Policy at itreserve.org/cookies. Analytics data collected through optional cookies is pseudonymised before storage.
4. How We Use the Data
We use the personal data we collect to: create and manage your account; deliver, activate, and maintain your subscribed Modules; process payments and issue invoices; communicate with you about your account, renewals, and service changes; respond to support requests; detect and prevent fraud, abuse, and security threats; comply with legal obligations including accounting, tax, and data-protection law; and, where you have given consent, send marketing communications about ItReserve products and updates.
We do not sell personal data to third parties. We do not use your data for automated individual decision-making that produces significant legal effects on you.
5. Data Retention Periods
| Category | Retention period |
|---|---|
| Active subscriber account data | Duration of subscription + 3 years after cancellation |
| Inactive accounts (no purchase) | 2 years from last login, then deleted |
| Reservit API Keys | Duration of subscription + 90 days (then permanently deleted) |
| API execution logs | 90 days from the date of the log entry |
| Billing records and invoices | 7 years from the invoice date (legal obligation) |
| Support communications | 12 months after case closure |
| Marketing consent records | Until consent is withdrawn + 1 year for evidence of consent |
| Security/fraud logs | 12 months |
At the end of each retention period, data is securely deleted or irreversibly anonymised.
6. Sub-Processors
We engage the following categories of sub-processors to help deliver our services. Each sub-processor is bound by a data processing agreement and subject to appropriate safeguards:
| Sub-processor category | Purpose | Data shared |
|---|---|---|
| Payment provider | Card payment processing and fraud screening | Billing address, tokenised card reference, order amount |
| Transactional email service | Delivery of activation confirmations, invoices, support replies | Email address, first name (if provided), email content |
| Cloud infrastructure provider | Hosting of the Dashboard, Module runtime, and encrypted data storage | All account and log data stored within the platform |
We will notify Customers by email before adding any new sub-processor that processes personal data on their behalf, and provide an opportunity to object within 14 days. The current sub-processor list is maintained at itreserve.org/dpa.
7. Data Subject Rights
Under GDPR and Montenegrin data-protection law, you have the following rights with respect to your personal data:
- Right of access (Art. 15 GDPR): You may request a copy of the personal data we hold about you.
- Right to rectification (Art. 16 GDPR): You may ask us to correct inaccurate or incomplete data.
- Right to erasure (Art. 17 GDPR): You may request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, you have withdrawn consent, or we have no other legal basis. This right does not apply to data we are required to retain by law (e.g. billing records).
- Right to restriction (Art. 18 GDPR): You may ask us to restrict processing of your data in certain circumstances while a dispute is resolved.
- Right to data portability (Art. 20 GDPR): Where processing is based on your consent or on contract performance, and is carried out by automated means, you may request your data in a structured, commonly used, machine-readable format.
- Right to object (Art. 21 GDPR): You may object at any time to processing based on legitimate interests, including profiling. You may also opt out of marketing communications at any time by clicking "Unsubscribe" in any marketing email or by contacting support.
- Right to lodge a complaint: You have the right to lodge a complaint with the AZLP or any competent data-protection authority in your country of residence.
To exercise any of these rights, send your request to support@itreserve.org with the subject "Data Subject Request" and include enough information to verify your identity. We will respond within 30 days. Complex or high-volume requests may be extended by a further 60 days, with notification.
8. Cross-Border Transfers
ItReserve stores data on servers located within the European Economic Area (EEA) or in countries with an adequacy decision from the European Commission. Where any transfer to a third country is necessary, we apply appropriate safeguards — such as Standard Contractual Clauses approved by the European Commission — and document those safeguards in our sub-processor agreements. Details of transfer safeguards are available on request.
9. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, ItReserve will notify the AZLP within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33. Where the breach is likely to result in a high risk to affected individuals, we will also notify those individuals without undue delay, providing sufficient information for them to take protective action. Records of all breaches, including those not subject to mandatory notification, are maintained in our internal incident register.
10. AZLP Contact Details
The Montenegrin supervisory authority for personal data protection is:
- Agencija za zaštitu ličnih podataka (AZLP)
- Kralja Nikole 2, 81000 Podgorica, Crna Gora
- Website: azlp.me
ItReserve is registered with AZLP under registration number 05-030/26-2438. You have the right to lodge a complaint with the AZLP if you believe we have processed your personal data unlawfully.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will notify registered account holders by email at least 14 days before the revised policy takes effect. The "Effective" date at the top of this page always reflects the current version. We encourage you to review this page periodically.
12. Contact Us
For any privacy-related queries, requests, or concerns, please contact:
- Email: support@itreserve.org
- Post: ItReserve d.o.o., ul. Vuka Karadžića 3, 81000 Podgorica, Crna Gora
- Phone: +382 20 218 735
We aim to respond to all privacy enquiries within 5 business days and to formally complete data-subject requests within 30 calendar days.