Privacy policy
Ultimo aggiornamento November 2025
Reservation Diary by CATz Soft LTD
Introduction
CATz Soft LTD (“COMPANY,” “we,” “us,” or “our”) understands that your privacy is important to you. We are committed to protecting the privacy of your personally-identifiable information as you use our Reservation Diary service and website. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
By using our Service, you consent to the terms described in the most recent version of this Privacy Policy. You should also read our Terms of Service to understand the general rules about your use of the Service. “You,” “your,” “visitor,” or “user” means the individual or entity accessing this Service.
Our Role Under GDPR
CATz Soft LTD operates under the General Data Protection Regulation (GDPR) (EU) 2016/679. Depending on the context, we act in different capacities:
As Data Controller
We act as a Data Controller for the personal data of our direct customers (restaurant owners, managers, and staff who register for and use Reservation Diary). This includes account registration data, billing information, and communications with us. As Data Controller, we determine the purposes and means of processing this personal data and are directly responsible for ensuring GDPR compliance for this data.
As Data Processor
We act as a Data Processor for the personal data of restaurant guests (end-users who make reservations). The restaurant collects this guest data and is the Data Controller. We process it solely on the restaurant’s behalf and according to their instructions, through the Service (including the reservation API, dashboard, plugin, hosted booking form, or other channels we provide). This guest data includes names, contact information, reservation details, and any notes or preferences recorded.
As a Data Processor, we:
- Process personal data only on documented instructions from the Data Controller (our restaurant customers)
- Ensure that persons authorized to process the personal data have committed themselves to confidentiality
- Take all measures required pursuant to Article 32 of GDPR (security of processing)
- Assist the Data Controller in responding to requests from data subjects exercising their rights
- Assist the Data Controller in ensuring compliance with obligations related to security, breach notification, and data protection impact assessments
- Delete or return all personal data at the end of the service relationship, at the choice of the Data Controller
- Make available all information necessary to demonstrate compliance and allow for audits
Personal Data We Collect
Data from Restaurant Customers (Data Controller capacity)
When you register for Reservation Diary, we collect:
- Business name and contact information
- Account holder name and email address
- Billing and payment information
- Website and business details
- Communications and support requests
Data from Restaurant Guests (Data Processor capacity)
The restaurant collects guest data. On the restaurant’s behalf, as Data Processor, we process:
- Guest names and contact information (email, phone number)
- Reservation details (date, time, party size, special requests)
- Dining preferences and notes
- Reservation history
Legal Basis for Processing (Article 6 GDPR)
We process personal data based on the following legal grounds:
- Contract Performance: Processing necessary for the performance of our contract with you (providing the Reservation Diary service).
- Legitimate Interests: Processing necessary for our legitimate interests (improving our Service, preventing fraud, ensuring security) where these are not overridden by your rights.
- Legal Obligation: Processing necessary for compliance with legal obligations (tax records, responding to legal requests).
- Consent: Where you have given explicit consent for specific processing activities (marketing communications).
Your Rights Under GDPR
If you are located in the European Economic Area (EEA), you have the following rights regarding your personal data:
- Right of Access: You have the right to request copies of your personal data.
- Right to Rectification: You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
- Right to Erasure: You have the right to request that we erase your personal data, under certain conditions.
- Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data, under certain conditions.
- Right to Object: You have the right to object to our processing of your personal data, under certain conditions.
- Right to Data Portability: You have the right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.
- Right to Withdraw Consent: Where processing is based on consent, you have the right to withdraw that consent at any time.
For Restaurant Guests
If you are a restaurant guest and wish to exercise your rights regarding data processed through Reservation Diary, please contact the restaurant directly as they are the Data Controller for your information. The restaurant will work with us to fulfill your request.
To exercise any of these rights, please contact us at info@reservationdiary.eu. We will respond to your request within one month.
Cookies and Tracking Technologies
We use cookies and similar tracking technologies to collect and use personal information about you. A cookie is a text file that is placed on your device by a web server. Cookies are uniquely assigned to you, and can only be read by a web server in the domain that issued the cookie to you.
Types of Cookies We Use
- Essential Cookies: Required for the operation of our Service. They enable core functionality such as security, network management, and account access.
- Functional Cookies: Enable us to remember choices you make and provide enhanced, personalized features.
- Analytics Cookies: Help us understand how visitors interact with our Service by collecting and reporting information anonymously.
You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of the Service may become inaccessible or not function properly.
How We Use Your Information
We may use the information we collect for the following purposes:
- To provide, operate, and maintain the Reservation Diary Service
- To process transactions and send related information, including purchase confirmations and invoices
- To respond to your comments, questions, and provide customer support
- To send you technical notices, updates, security alerts, and administrative messages
- To communicate with you about products, services, offers, and events (with your consent where required)
- To monitor and analyze trends, usage, and activities in connection with our Service
- To detect, investigate, and prevent fraudulent transactions and other illegal activities
- To improve, personalize, and expand our Service
Sharing of Your Information
We do not sell, trade, or rent your personal information to third parties. We may share your information in the following circumstances:
- Service Providers: We may share your information with third-party vendors who perform services on our behalf, such as payment processing, data analysis, email delivery, hosting services, and customer service. These providers have access to your personal data only to perform these tasks and are obligated to protect your information.
- Legal Requirements: We may disclose your information where required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency).
- Business Transfers: In connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business by another company.
- Protection of Rights: We may disclose your information to protect our rights, property, or safety, or that of our users or others.
International Data Transfers
Your information may be transferred to and processed in countries other than the country in which you are resident. These countries may have data protection laws that are different from the laws of your country. However, we have taken appropriate safeguards to require that your personal information will remain protected in accordance with this Privacy Policy and GDPR requirements. This includes implementing Standard Contractual Clauses approved by the European Commission where necessary.
Data Retention
We retain personal data for as long as necessary to fulfill the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements. For restaurant customer accounts, we retain data for the duration of the business relationship and for a period thereafter as required by applicable laws.
Guest reservation data we process as Data Processor is stored for six months, after which we delete or anonymize it. A copy may also remain on the restaurant’s own systems for as long as that restaurant keeps it; that copy is under the restaurant’s control.
Data Security
We have implemented appropriate technical and organizational measures designed to secure your personal information from accidental loss and from unauthorized access, use, alteration, and disclosure. These measures include encryption of data in transit and at rest, regular security assessments, access controls, and staff training.
Despite these precautions, we cannot guarantee that unauthorized persons will not obtain access to your personal information. In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and, where required, notify affected individuals without undue delay.
Sub-processors
We engage certain third-party sub-processors to assist in providing the Reservation Diary Service. These sub-processors process personal data on our behalf and are bound by data processing agreements that comply with GDPR requirements. A list of our current sub-processors is available upon request. We will notify our customers of any intended changes to sub-processors, giving them the opportunity to object.
Links to Third-Party Sites
Our Service may contain links to other sites that are not operated by us. If you click on a third-party link, you will be directed to that third party’s site. We strongly advise you to review the Privacy Policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
Children’s Privacy
Our Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children under 16. If you are a parent or guardian and you are aware that your child has provided us with personal data, please contact us. If we become aware that we have collected personal data from a child under 16 without verification of parental consent, we will take steps to remove that information from our servers.
Data Processing Agreement
Restaurant customers who use Reservation Diary to process guest personal data may request a Data Processing Agreement (DPA) that sets out the terms under which we process personal data on their behalf. This DPA includes all provisions required under Article 28 of the GDPR. To request a DPA, please contact us at info@reservationdiary.eu.
Right to Lodge a Complaint
If you believe that our processing of your personal data infringes data protection laws, you have the right to lodge a complaint with a supervisory authority. For CATz Soft LTD, the lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the “Last Updated” date. For material changes, we will provide notice via email or through the Service. You are advised to review this Privacy Policy periodically for any changes.
Contact Information
If you have any questions about this Privacy Policy or our data practices, or if you wish to exercise your data protection rights, please contact us at:
CATz Soft LTD
Data Controller
Email: info@reservationdiary.eu
Website: https://reservationdiary.eu