Privacy Policy

Resivo Ltd – Privacy Policy for End-Customers of Our Business Partners

Last updated: 6 August 2025

1. Who we are

Resivo Ltd ("Resivo", "we", "us", "our") provides AI-powered telephone and online reservation services on behalf of various businesses including restaurants, cafés, salons, and similar service providers (our "Business Partners").

For most of the personal information described below Resivo acts as a "data processor" – we handle your data strictly on your Business Partner's instructions. In a few narrow cases (service analytics, fraud prevention, product improvement) we act as an independent "data controller".

Resivo Ltd is registered in England and Wales under company number 16543892.

Contact our Data Protection Officer (DPO) at [email protected] or +44 (0)23 8202 0540.

2. The legal framework we follow

We process personal data in accordance with:

  • the UK GDPR and Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025;
  • the Privacy and Electronic Communications Regulations 2003 (PECR); and
  • any local data-protection laws that apply where the venue is located.

3. What data we collect & why

CategoryExamplesPurpose & Lawful Basis*
Call dataCaller ID, audio recording, transcribed text, call timestamp, unique call IDPerform the booking contract with your venue; legitimate interest in quality assurance & fraud prevention
Reservation detailsName, party size, booking date/time, dietary notes, accessibility or allergy requestsPerform contract; protect vital interests where allergies disclosed
Payment / deposit infoLast 4 digits of card, Stripe/GoCardless token, fee amountPerform contract & comply with financial regulations
SMS & email logsConfirmation / reminder texts, sender, recipient, delivery statusPerform contract; legitimate interest in service monitoring
Device & usage data (website/widget)IP address, browser type, cookies, interaction logsLegitimate interest in security & analytics; consent for non-essential cookies
Service analytics (aggregated)Call duration, abandonment rate, booking conversionOur legitimate interest in improving and reporting on the service

*Where we rely on consent (e.g. marketing texts) you can withdraw it at any time.

4. How we collect your data

  • You speak with our AI voice agent or one of our human fail-over staff.
  • You enter details in a Business Partner's online or walk-in booking widget powered by Resivo.
  • The venue staff add or amend your reservation in their Resivo dashboard.
  • Our payment partner (Stripe or GoCardless) processes any booking fee or deposit.

5. Who we share data with

RecipientReason
Your Business PartnerTo confirm, modify or cancel your reservation
Telecoms & cloud providers (e.g. Twilio, Amazon Web Services)Secure call processing & hosting
Payment processors (Stripe, GoCardless)Collection of deposits / booking fees
SMS gatewaysSending confirmations & reminders
Professional advisers (lawyers, accountants, insurers)Compliance & defence of legal claims
Regulators or law-enforcementWhere legally required

All suppliers are bound by data-processing contracts that meet UK GDPR standards.

6. International transfers

Your data may be stored or accessed outside the UK/EU (e.g. Amazon AWS eu-west-1 backup in Dublin and fail-over in US-East). We use one or more of the following safeguards:

  • UK International Data Transfer Agreements (IDTAs) or EU Standard Contractual Clauses;
  • UK Information Commissioner-approved certifications;
  • Adequacy decisions where available.

7. Data retention

Data typeDefault retention*
Call recordings & transcripts90 days (unless your venue's plan includes longer history)
Caller & reservation metadata12 months after the booking date
Payment tokens & invoices7 years (HMRC compliance)
SMS / email delivery logs12 months
Aggregated, anonymised analyticsIndefinite

*Venues on "Starter", "Growth" or "Scale" plans may access 7-day, 21-day or unlimited logs respectively; older data is archived or deleted automatically.

8. Security measures

  • Encryption in transit (TLS 1.2+) and at rest (AES-256).
  • Role-based access; multi-factor authentication for staff.
  • Quarterly penetration testing; 24 × 7 monitoring & alerting.
  • Incident-response plan aligned to ICO guidance.

9. Your rights

You can, at no cost:

  • Access the personal data we hold;
  • Rectify inaccurate or incomplete data;
  • Erase data in certain circumstances;
  • Restrict or object to processing;
  • Port data to another provider;
  • Withdraw consent where processing is consent-based;
  • Complain to the ICO (ico.org.uk) or your local data-protection authority.

To exercise any right, email [email protected] with your request and enough information to identify you and the relevant booking.

10. Children

Our service is not intended for individuals under 16. If we learn we have collected personal data from a child without verified parental consent, we will delete it promptly.

11. Changes to this policy

We may update this notice to reflect legal, technical or business changes. Significant changes will be highlighted on the Resivo website or notified to Business Partners for onward communication to their customers.

12. Contact us

Questions, concerns or requests?

Data Protection Officer

Email: [email protected]

Tel: +44 (0)23 8202 0540

Thank you for trusting Resivo to power a smoother booking experience.