Privacy Policy (GDPR)
How Rezervato processes personal data, what rights you have, and who to contact.
Last updated: July 3, 2026
How Rezervato processes personal data, what rights you have, and who to contact.
Last updated: July 3, 2026
The controller of personal data is:
Roman Khapenkov
sole trader operating under the Trade Licensing Act (Czech Republic)
Company ID (IČO): 06261035
Registered address: Poznaňská 434/35, Bohnice, 181 00 Prague 8
Registered in the Trade Register.
Contact email for questions about personal data: info@rezervato.cz
Rezervato has not appointed a Data Protection Officer (DPO), as this is not a legal requirement given the scope and nature of our processing. For any questions about personal data, including exercising your rights, please contact the email address above.
We distinguish our processing based on the capacity in which you interact with Rezervato.
| Data category | Purpose | Legal basis |
|---|---|---|
| Name, email, phone, business name and address | Setting up and managing your account, communication, support | Performance of a contract (Art. 6(1)(b)) |
| Billing details, company/tax ID, payment history | Issuing invoices, accounting | Compliance with a legal obligation (Art. 6(1)(c)) |
| Email (if you’ve given consent) | Sending news and tips (newsletter) | Consent (Art. 6(1)(a)), can be withdrawn at any time |
| App usage data (logs, IP address) | Security, bug fixing, abuse prevention | Legitimate interest (Art. 6(1)(f)) |
We process the name, phone number, email, and any booking note (e.g. allergies, party size) you provide when booking on behalf of, and under the instructions of, that restaurant, in order to accept, confirm, and remind you of your booking. In this relationship, the restaurant is the controller of your data and Rezervato is the processor – see the “I’m a guest of a restaurant” section below for more.
When you visit our website, we process technical data (IP address, browser type, pages visited) via cookies and similar technologies, including Google tools (Google Ads, Google Analytics) and Meta (Meta Pixel), for traffic measurement, advertising, and remarketing. See the “Cookies” section below for details.
If you’re a HoReCa business whose contact details (typically a work email) we hold in our database for the purpose of reaching out with the Rezervato offer, we process this data based on legitimate interest (direct marketing between businesses, Art. 6(1)(f) and Section 7(3) of the Act on Certain Information Society Services). You can unsubscribe from such communications at any time via the link in the email or by messaging info@rezervato.cz.
If you booked a table at a specific restaurant through Rezervato, your personal data (name, contact details, booking note) is processed on behalf of that restaurant, which is the controller of that data. Rezervato only processes this data for the restaurant on a purely technical basis, under a data processing agreement (Art. 28 GDPR).
You should therefore exercise your rights (access, correction, deletion, etc.) primarily with the restaurant where you made the booking – as the data controller, it is obliged to handle your request. If you can’t contact the restaurant, or you’re not sure which restaurant to contact, write to us at info@rezervato.cz and we’ll help point you in the right direction.
To operate Rezervato, we use the following processors / service providers, with whom we have data processing agreements in place under Art. 28 GDPR:
Some of these providers may process data outside the European Union (typically in the US). In such cases, the transfer is safeguarded by Standard Contractual Clauses approved by the European Commission, or another appropriate mechanism under Art. 46 GDPR.
We do not sell or share your personal data with third parties for their own marketing purposes.
These retention periods reflect our current practice; if they change in the future, we’ll update this page.
With respect to your personal data, you have the right to:
You can exercise your rights by emailing info@rezervato.cz. We will respond to your request within 30 days at the latest.
Data transferred between your browser and our servers is encrypted (HTTPS/TLS). Only authorized employees/collaborators have access to data within the application, and only to the extent necessary for their tasks. We never store payment data on our own servers – its processing is handled entirely by the Stripe payment gateway, which is PCI DSS certified. We regularly review the application’s security through security testing.
The rezervato.cz website uses cookies to ensure the site functions properly, to measure traffic, and to show relevant advertising. Specifically, we use:
We only use cookies that aren’t strictly necessary with your consent. We’re currently preparing a cookie banner on the website where you’ll be able to grant or withdraw consent for analytics and advertising cookies (Google Analytics, Meta Pixel) at any time. Until it launches, you can also manage cookie settings directly in your browser.
We may update this policy from time to time, for example in connection with legislative changes or the expansion of Rezervato’s services. We will inform you of any significant changes on the website or by email. The current version is always available on this page.
Write to us at info@rezervato.cz – we’ll get back to you as soon as possible.
Contact usWe use cookies to help our website work effectively and to understand how you interact with it. Choose which categories of cookies you allow below.
Nezbytné cookies vyžadované pro správné fungování webu. Tyto nelze zakázat.
Cookies, které si pamatují vaše volby ke zlepšení vašeho zážitku.
Cookies, které nám pomáhají pochopit, jak návštěvníci s webem pracují.
Cookies používané k doručování relevantní reklamy a měření výkonu kampaní.