Welcome to ReceptionGO.
ReceptionGO is a cloud-based Software-as-a-Service (SaaS) platform designed to help hotels, hostels, guesthouses, apartments, campsites, vacation rentals, and other accommodation providers manage guest registration, online self check-in, identity verification, payments, communication, and compliance with applicable legal obligations.
Protecting personal data is one of our highest priorities. We are committed to processing personal information fairly, lawfully, transparently, and securely in accordance with:
This Privacy Policy explains:
This Privacy Policy applies to all users of ReceptionGO, including:
By accessing or using ReceptionGO, you acknowledge that you have read this Privacy Policy.
ReceptionGO is operated by:
Active line d.o.o. Podlimbarskega ulica 43 1000 Ljubljana Slovenia
VAT ID (SI): SI30336465
Email: [email protected] (or another designated privacy contact) Website: https://receptiongo.com
Throughout this Privacy Policy:
refer to Active line d.o.o.
This Privacy Policy applies to:
This Privacy Policy also applies to personal information collected:
This Privacy Policy does not apply to:
Such services are governed by their own privacy policies.
ReceptionGO may act either as a Data Processor or as a Data Controller, depending on the specific processing activity.
4.1 ReceptionGO as Data Processor
When providing the Service to accommodation providers, ReceptionGO generally acts as a Data Processor on behalf of the Customer.
Examples include:
In these situations:
The relationship between the Customer and ReceptionGO with respect to personal data processing is governed by a separate Data Processing Agreement (DPA), except where processing is required by applicable law.
4.2 ReceptionGO as Data Controller
ReceptionGO acts as an independent Data Controller when processing information relating to:
For these activities, ReceptionGO independently determines the purposes and means of processing.
For purposes of this Privacy Policy:
Account means a ReceptionGO customer account.
Accommodation Provider means any hotel, hostel, apartment, guesthouse, campsite, resort or other business using ReceptionGO.
Customer means the accommodation provider subscribing to ReceptionGO.
Guest means an individual staying or intending to stay at an accommodation provider using ReceptionGO.
Personal Data means any information relating to an identified or identifiable natural person.
Processing means any operation performed on personal data, including collection, recording, storage, organisation, transmission, consultation, deletion or destruction.
Controller has the meaning defined by GDPR.
Processor has the meaning defined by GDPR.
KYC means Know Your Customer identity verification.
Self Check-in means ReceptionGO's digital guest registration process.
Platform means ReceptionGO cloud services.
Services means all software and services provided by ReceptionGO.
Third Party Services means services integrated into ReceptionGO, including payment providers, identity verification providers, smart lock systems and booking platforms.
The categories of information collected depend on how ReceptionGO is used.
Not every category applies to every individual.
6.1 Information Provided by Accommodation Providers
When a hotel creates a ReceptionGO account we may collect:
6.2 Account Information
When users create accounts we may collect:
6.3 Guest Information
Accommodation providers determine which guest information is requested during Self Check-in.
Depending on configuration this may include:
6.4 Government Reporting Information
Where required by law, ReceptionGO may process information necessary for mandatory reporting to governmental authorities.
Depending on jurisdiction this may include:
ReceptionGO only processes such information on behalf of the accommodation provider and according to applicable legislation.
6.5 Identity Verification Information
ReceptionGO may provide identity verification features.
Depending on hotel configuration this may include:
Where enabled, ReceptionGO may also support:
Identity verification services may be provided directly by ReceptionGO or by specialised third-party identity verification providers.
6.6 Payment Information
ReceptionGO itself does not store complete payment card numbers.
Payments are processed through PCI DSS compliant payment providers such as Stripe.
ReceptionGO may receive:
ReceptionGO does not receive or store:
Such information is handled directly by the payment provider.
6.7 Booking Information
ReceptionGO may process booking information including:
6.8 Communications
We may process communications including:
6.9 Technical Information
When users access ReceptionGO we automatically collect technical information such as:
This information helps us maintain system security and improve our services.
6.10 Cookies and Similar Technologies
ReceptionGO uses cookies and similar technologies to:
Detailed information is provided in our separate Cookie Policy.
ReceptionGO does not intentionally collect:
Where such information is processed, appropriate safeguards are applied in accordance with GDPR.
We collect personal data from several sources.
These may include:
We do not knowingly obtain personal information from unlawful sources.
We rely on accommodation providers and guests to ensure that the information provided is accurate and up to date.
Where legally permitted, inaccurate or incomplete information may prevent successful guest registration, identity verification, payment processing, or reporting to competent authorities.
Individuals may request correction of inaccurate personal data in accordance with applicable law.
ReceptionGO processes personal data according to the following principles:
These principles guide the design, operation and continuous improvement of all ReceptionGO services. 11.
Legal Bases for Processing (Article 6 GDPR)
ReceptionGO processes personal data only where a valid legal basis exists under Article 6 of the General Data Protection Regulation (GDPR). The applicable legal basis depends on the nature of the processing activity and our role as either a Data Controller or a Data Processor.
11.1 Performance of a Contract (Article 6(1)(b) GDPR)
We process personal data where such processing is necessary to perform a contract with our customers or to take steps at the request of a customer before entering into a contract.
Examples include:
Where ReceptionGO processes guest data solely on behalf of an accommodation provider, such processing is carried out under the instructions of the accommodation provider acting as the Data Controller.
11.2 Compliance with a Legal Obligation (Article 6(1)(c) GDPR)
ReceptionGO may process personal data where processing is necessary to comply with legal obligations imposed by applicable laws.
Depending on the jurisdiction and the services used, these obligations may include:
Where ReceptionGO processes personal data solely on behalf of an accommodation provider to enable compliance with such legal obligations, the accommodation provider remains responsible for determining the legal basis for the processing.
11.3 Legitimate Interests (Article 6(1)(f) GDPR)
ReceptionGO may process personal data where such processing is necessary for our legitimate business interests, provided those interests are not overridden by the rights and freedoms of the data subject.
Our legitimate interests include:
When relying on legitimate interests, we carefully balance our interests against the privacy rights of individuals and implement appropriate safeguards where necessary.
11.4 Consent (Article 6(1)(a) GDPR)
Where required by applicable law, ReceptionGO processes personal data based on the individual's consent.
Examples may include:
Where processing is based on consent, individuals may withdraw their consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
11.5 Vital Interests (Article 6(1)(d) GDPR)
In exceptional circumstances, ReceptionGO may process personal data where necessary to protect the vital interests of an individual or another natural person.
Such situations are expected to be rare and may include emergencies involving risks to life, health, or personal safety.
11.6 Public Interest (Article 6(1)(e) GDPR)
ReceptionGO may process personal data where such processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority, but only where this legal basis is applicable under the laws governing the relevant processing activity.
In most cases involving mandatory guest registration and reporting, the accommodation provider determines the applicable legal basis under national legislation, while ReceptionGO acts solely as a Data Processor.
11.7 Processing Special Categories of Personal Data
ReceptionGO does not intentionally process special categories of personal data as defined in Article 9 GDPR unless:
Where special categories of personal data are processed, ReceptionGO implements additional technical and organisational safeguards appropriate to the sensitivity of the data.
11.8 Processing on Behalf of Accommodation Providers
In the majority of guest-related processing activities, ReceptionGO acts exclusively as a Data Processor.
The accommodation provider determines:
ReceptionGO processes such personal data only in accordance with the documented instructions of the accommodation provider, the applicable Data Processing Agreement (DPA), and relevant data protection legislation.
11.9 Changes to the Legal Basis
Where the purpose of processing changes or additional processing activities are introduced, ReceptionGO will ensure that an appropriate legal basis exists before commencing such processing. Where required by law, affected individuals will be informed of the new purpose and the corresponding legal basis.
ReceptionGO processes personal data only for specified, explicit and legitimate purposes. We collect and use personal data solely to provide our services, comply with legal obligations, protect the security of our platform, and improve the quality of our services.
The purposes for which personal data is processed depend on the type of user, the services used, and our role as either a Data Controller or a Data Processor.
12.1 Providing the ReceptionGO Services
We use personal data to provide and operate the ReceptionGO platform, including:
12.2 Guest Self Check-in
ReceptionGO processes personal data submitted during the Self Check-in process to enable accommodation providers to complete guest registration efficiently and securely.
Depending on the accommodation provider's configuration, this may include:
ReceptionGO processes this information on behalf of the accommodation provider and in accordance with its documented instructions.
12.3 Identity Verification (KYC)
Where enabled by the accommodation provider, ReceptionGO may process personal data to facilitate identity verification.
This may include:
Identity verification may be performed directly by ReceptionGO or through trusted third-party identity verification providers acting under appropriate contractual and data protection obligations.
12.4 Compliance with Legal Requirements
ReceptionGO may process personal data to assist accommodation providers in complying with applicable legal obligations.
Depending on the jurisdiction, this may include:
ReceptionGO performs such processing only where required by applicable law or instructed by the accommodation provider.
12.5 Payment Processing
ReceptionGO uses personal data to facilitate payment-related services, including:
ReceptionGO does not store complete payment card information. Payment card data is processed directly by PCI DSS compliant payment providers such as Stripe.
12.6 Customer Support
We use personal data to provide customer support, including:
Support communications may be retained to improve future support and to document the resolution of technical issues.
12.7 Platform Security
ReceptionGO processes personal data to maintain the security, availability and integrity of the platform.
This includes:
These measures help protect both accommodation providers and guests against fraud, cyberattacks and unauthorised use.
12.8 Service Improvement
ReceptionGO continually improves its services using operational and technical information.
This may include analysing:
Where possible, aggregated or anonymised information is used for these purposes.
12.9 Communications
ReceptionGO uses personal data to communicate with customers and users regarding:
These communications are considered necessary for the operation of the service and generally do not constitute marketing communications.
12.10 Marketing Communications
Where permitted by applicable law or based on the individual's consent, ReceptionGO may use personal data to send:
Recipients may unsubscribe from marketing communications at any time using the unsubscribe link included in the communication or by contacting us directly.
12.11 Fraud Prevention
ReceptionGO processes personal data to detect, prevent and investigate fraudulent or unlawful activities.
This may include:
12.12 Legal Claims and Protection of Rights
ReceptionGO may process personal data where necessary to:
12.13 Business Operations
We may use personal data to support the ordinary operation of our business, including:
12.14 Product Development
ReceptionGO may analyse technical and operational information to develop new products, improve existing functionality and enhance user experience.
Whenever reasonably possible, development activities are performed using anonymised, aggregated or pseudonymised data rather than directly identifiable personal data.
12.15 Automated Processing
Certain platform functions operate automatically to provide requested services.
Examples include:
ReceptionGO does not make decisions producing legal or similarly significant effects based solely on automated processing unless permitted by applicable law or expressly requested by the accommodation provider in compliance with applicable legislation.
12.16 No Sale of Personal Data
ReceptionGO does not sell personal data to third parties.
We do not rent personal data, trade customer databases, or disclose personal information to third parties for their independent marketing purposes.
Any disclosure of personal data occurs only for the purposes described in this Privacy Policy, in accordance with customer instructions, applicable law, or contractual obligations.
ReceptionGO treats personal data as confidential and does not sell, rent, or disclose personal data to third parties except where necessary to provide our services, comply with legal obligations, protect our legitimate interests, or where instructed by our customers.
The categories of recipients described below depend on the services used and the specific configuration selected by the accommodation provider.
13.1 Sharing with Accommodation Providers
ReceptionGO primarily processes guest personal data on behalf of accommodation providers.
Personal data submitted by guests during the Self Check-in process is made available to the accommodation provider operating the relevant property. This enables the accommodation provider to:
The accommodation provider remains responsible for determining how such personal data is further processed in accordance with applicable law.
13.2 Sharing with Service Providers
ReceptionGO works with carefully selected third-party service providers that support the operation of our platform.
Depending on the services used, personal data may be shared with providers delivering:
These providers process personal data only on our documented instructions or, where applicable, on the instructions of the accommodation provider, and are contractually required to implement appropriate technical and organisational measures to protect personal data.
13.3 Payment Service Providers
Where payment functionality is used, ReceptionGO shares the information necessary to process payments with trusted payment service providers.
For example, payment transactions may be processed through Stripe or another payment provider selected by the accommodation provider.
Depending on the transaction, shared information may include:
ReceptionGO does not disclose or store complete payment card numbers, CVV codes, or PIN codes.
Payment providers process payment information under their own privacy policies and in accordance with applicable payment industry standards, including PCI DSS.
13.4 Identity Verification Providers
Where identity verification (KYC) services are enabled, ReceptionGO may transmit identity verification data to specialised identity verification providers.
Depending on the provider selected by the accommodation provider, this may include:
Identity verification providers process this information solely for the purpose of performing the requested verification services and in accordance with applicable contractual and legal requirements.
13.5 Property Management System (PMS) and Channel Manager Integrations
ReceptionGO may exchange information with third-party systems integrated by the accommodation provider.
Examples include:
The categories of information exchanged depend on the integration configured by the accommodation provider and may include reservation details, guest information, payment status, room assignments, or access credentials.
ReceptionGO exchanges only the data necessary for the requested integration to function.
13.6 Smart Lock Providers
Where supported by the accommodation provider, ReceptionGO may communicate with electronic access control systems to facilitate guest access.
Depending on the integration, limited information may be shared, including:
ReceptionGO does not share more information than is reasonably necessary for access management.
13.7 Government Authorities
ReceptionGO may transmit personal data to competent public authorities where:
The categories of information transmitted depend on the legal requirements applicable in the relevant jurisdiction.
ReceptionGO does not voluntarily disclose guest information to public authorities beyond what is legally required or authorised by the accommodation provider.
13.8 Professional Advisers
ReceptionGO may disclose personal data where reasonably necessary to professional advisers acting under confidentiality obligations, including:
Such disclosures are limited to information reasonably necessary for the relevant professional service.
13.9 Corporate Transactions
If ReceptionGO is involved in a merger, acquisition, restructuring, financing transaction, sale of assets, or similar corporate transaction, personal data may be transferred as part of that transaction where permitted by applicable law.
Where required, affected customers will be informed of material changes relating to the processing of their personal data.
Any successor organisation will remain bound by applicable data protection obligations.
13.10 Legal Requirements
ReceptionGO may disclose personal data where we believe in good faith that disclosure is necessary to:
Such disclosures are limited to the extent required by applicable law.
13.11 International Service Providers
Some third-party service providers used by ReceptionGO may process personal data outside the European Economic Area (EEA).
Where this occurs, ReceptionGO implements appropriate safeguards as described in the section International Data Transfers of this Privacy Policy.
13.12 Data Minimisation
Whenever personal data is shared with third parties, ReceptionGO applies the principle of data minimisation.
Only the personal data necessary for the specific purpose of the disclosure is shared.
Where possible, data is pseudonymised, encrypted, aggregated, or otherwise protected before transmission.
13.13 No Sale of Personal Data
ReceptionGO does not sell personal data.
We do not license customer or guest databases to third parties.
We do not disclose personal data to third parties for their own direct marketing purposes.
Any disclosure of personal data is carried out solely for the purposes described in this Privacy Policy, in accordance with contractual obligations, customer instructions, or applicable law.
ReceptionGO uses carefully selected third-party service providers to support the operation, security, and functionality of our platform.
These providers perform specific services on our behalf or, where applicable, on behalf of the accommodation provider. We select providers that maintain appropriate technical, organisational, and security measures and, where required by applicable law, enter into appropriate data protection agreements with them.
The third-party providers used by ReceptionGO may change over time as our services evolve. We will update this Privacy Policy where material changes occur.
14.1 Stripe – Payment Processing
ReceptionGO uses Stripe as its primary payment service provider for processing subscription payments and, where enabled by the accommodation provider, guest payments.
Stripe may process information including:
ReceptionGO does not receive or store complete payment card numbers, CVV codes, or PIN codes.
Payment information entered during checkout is transmitted directly to Stripe using encrypted connections and processed in accordance with Stripe's own Privacy Policy and security standards, including PCI DSS.
Stripe acts as an independent Data Controller for payment processing activities that it performs under applicable financial regulations.
14.2 Beds24 and Other Property Management Systems
ReceptionGO may integrate with Beds24 and other Property Management Systems (PMS), Channel Managers, or reservation platforms used by accommodation providers.
Depending on the integration, ReceptionGO may exchange information including:
The accommodation provider controls which integrations are enabled and what information is exchanged.
Each integrated platform processes personal data in accordance with its own privacy policies and applicable legal obligations.
14.3 TTLock and Smart Lock Providers
Where electronic access control is enabled, ReceptionGO may integrate with TTLock or other compatible smart lock providers.
To provide digital access credentials, ReceptionGO may transmit limited information including:
ReceptionGO shares only the minimum amount of information necessary to generate and manage electronic access credentials.
Access control providers remain independently responsible for processing personal data within their own systems.
14.4 Email Service Providers
ReceptionGO uses trusted email delivery providers to send operational communications.
These communications may include:
Information shared with email providers is limited to what is necessary for successful delivery of communications and may include:
Operational emails are considered essential for providing the ReceptionGO service.
14.5 Cloud Infrastructure Providers
ReceptionGO is operated using professional cloud infrastructure providers that support the availability, reliability, scalability, and security of our platform.
Cloud service providers may process personal data for purposes including:
ReceptionGO takes reasonable steps to ensure that cloud providers implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
Where possible, personal data is hosted within the European Economic Area (EEA). If personal data is processed outside the EEA, appropriate safeguards are implemented as described in the section International Data Transfers of this Privacy Policy.
14.6 Additional Service Providers
ReceptionGO may also use additional service providers to support the operation of the platform, including providers of:
Such providers are granted access only to the personal data necessary to perform their contracted services and are required to process personal data in accordance with applicable data protection laws and contractual obligations.
14.7 Data Protection Obligations of Third-Party Providers
ReceptionGO seeks to work only with third-party providers that demonstrate an appropriate level of security and compliance.
Where required by applicable law, ReceptionGO enters into Data Processing Agreements (DPAs) or other legally required contractual arrangements with service providers processing personal data on our behalf.
These agreements generally require providers to:
14.8 Changes to Service Providers
ReceptionGO may replace, add, or discontinue third-party service providers from time to time in order to improve the functionality, security, reliability, or performance of the platform.
Such changes do not alter the purposes for which personal data is processed and are made in accordance with applicable data protection laws. 15. Government Reporting
ReceptionGO provides functionality that enables accommodation providers to comply with statutory guest registration and reporting obligations imposed by applicable laws and regulations.
In the majority of cases, ReceptionGO performs these activities solely on behalf of the accommodation provider. The accommodation provider remains responsible for determining whether reporting is legally required and for ensuring the accuracy and lawfulness of the information submitted.
15.1 Reporting in the Republic of Slovenia
For accommodation providers operating in the Republic of Slovenia, ReceptionGO may process and transmit guest information where required under applicable Slovenian legislation.
Depending on the legal requirements in force, this may include reporting information to competent public authorities responsible for:
The categories of information reported may include, where required by law:
ReceptionGO transmits only the information required by law or instructed by the accommodation provider.
15.2 Reporting in Other Jurisdictions
ReceptionGO is designed for use by accommodation providers throughout Europe and may support government reporting requirements in additional countries and jurisdictions.
Where such functionality is available, ReceptionGO may facilitate the transmission of guest information to competent public authorities in accordance with the laws applicable to the accommodation provider.
The availability, scope, and content of reporting features may differ between jurisdictions depending on local legal requirements.
ReceptionGO does not determine whether reporting is legally required in a particular jurisdiction. Accommodation providers are responsible for understanding and complying with the legal obligations applicable to their business.
15.3 Role of ReceptionGO
When processing personal data for government reporting purposes, ReceptionGO generally acts as a Data Processor on behalf of the accommodation provider.
The accommodation provider remains responsible for:
ReceptionGO processes and transmits personal data only in accordance with the documented instructions of the accommodation provider and the applicable Data Processing Agreement (DPA), except where processing is required by applicable law.
15.4 Legal Basis for Government Reporting
Government reporting is generally carried out on the basis of legal obligations applicable to the accommodation provider under national legislation.
ReceptionGO processes the relevant personal data only to the extent necessary to enable the accommodation provider to comply with those obligations.
15.5 Accuracy of Submitted Information
ReceptionGO relies on the accommodation provider and, where applicable, the guest to provide accurate and complete information.
ReceptionGO is not responsible for inaccuracies resulting from:
Accommodation providers are responsible for reviewing submitted information where required by applicable law.
15.6 Security of Government Reporting
ReceptionGO implements appropriate technical and organisational measures designed to protect personal data transmitted for government reporting purposes.
Where technically supported by the receiving authority, data transmissions may be protected using secure communication protocols, encryption, authentication mechanisms, digital certificates, or other appropriate security measures.
15.7 Record Retention
ReceptionGO may retain records relating to government reporting activities where necessary to:
Retention periods depend on the accommodation provider's configuration, applicable legislation, contractual obligations, and our data retention policies.
15.8 Changes to Reporting Requirements
Government reporting requirements may change over time due to amendments in applicable legislation or regulatory guidance.
ReceptionGO may update its reporting functionality to reflect such changes. Accommodation providers remain responsible for ensuring that their use of the platform complies with the laws applicable to their jurisdiction.
ReceptionGO is operated from the European Union and is committed to ensuring that any transfer of personal data is carried out in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
Where possible, personal data is processed and stored within the European Economic Area (EEA). However, certain services used by ReceptionGO or selected by accommodation providers may involve the transfer of personal data to countries outside the EEA.
16.1 When International Transfers May Occur
International transfers of personal data may occur where necessary to:
Such transfers are limited to what is reasonably necessary for the relevant processing activity.
16.2 Appropriate Safeguards
Where personal data is transferred to a country that has not been recognised by the European Commission as providing an adequate level of data protection, ReceptionGO implements appropriate safeguards as required by Chapter V of the GDPR.
Depending on the circumstances, these safeguards may include:
These safeguards are intended to ensure that personal data continues to receive a level of protection that is substantially equivalent to that required within the European Union.
16.3 Transfers to Third-Party Service Providers
Some third-party service providers used by ReceptionGO may process personal data outside the EEA.
Examples may include providers of:
Before engaging such providers, ReceptionGO seeks to ensure that appropriate contractual, technical, and organisational safeguards are in place to protect personal data.
16.4 Transfers Initiated by Accommodation Providers
Accommodation providers may choose to enable integrations with third-party systems that independently process personal data outside the EEA.
Where such integrations are activated by the accommodation provider, ReceptionGO transfers only the information necessary to support the requested functionality.
The accommodation provider remains responsible for assessing whether the selected third-party services comply with applicable data protection requirements.
16.5 Access from Outside the European Economic Area
ReceptionGO users may access the platform while travelling or working outside the EEA.
Such access may result in the transmission of personal data across international networks. ReceptionGO protects these communications using appropriate security measures, including encrypted connections and authentication mechanisms.
16.6 Security of International Transfers
ReceptionGO applies appropriate technical and organisational measures designed to protect personal data during international transfers.
Depending on the nature of the transfer, these measures may include:
16.7 Derogations for Specific Situations
Where no adequacy decision or appropriate safeguard is available, ReceptionGO may rely on one of the derogations provided under Article 49 GDPR where legally permitted.
Such situations are expected to be exceptional and may include:
ReceptionGO does not rely on these derogations for routine or repetitive transfers where alternative lawful transfer mechanisms are available.
16.8 Future Changes
ReceptionGO continually monitors developments in international data protection law and may update its transfer mechanisms where necessary to reflect changes in legislation, regulatory guidance, judicial decisions, or the services used by the platform.
Any material changes affecting international data transfers will be reflected in this Privacy Policy or otherwise communicated where required by applicable law.
ReceptionGO uses automated technologies to provide efficient, secure, and reliable services. These technologies assist in processing information, validating data, performing technical checks, and automating routine operational tasks.
ReceptionGO is designed to support accommodation providers in managing guest registration and related services. Automated processing is used to facilitate these services and not to make independent decisions about individuals beyond the scope necessary to operate the platform.
17.1 Automated Processing Activities
Depending on the services enabled by the accommodation provider, ReceptionGO may automatically perform tasks including:
These automated processes are designed to improve efficiency, reduce manual errors, and enhance the user experience.
17.2 Identity Verification
Where identity verification (KYC) services are enabled, automated technologies may be used to assist with:
ReceptionGO may perform these checks directly or through specialised third-party identity verification providers.
The results of these automated checks are intended to assist the accommodation provider and do not automatically determine whether a guest is accepted or refused accommodation.
17.3 Fraud Prevention and Security
ReceptionGO may use automated monitoring systems to help detect:
Where appropriate, automated systems may temporarily restrict access or require additional verification to protect the security of the platform and its users.
17.4 No Automated Decisions Producing Legal or Similarly Significant Effects
ReceptionGO does not intentionally make decisions based solely on automated processing that produce legal effects or similarly significant effects on individuals within the meaning of Article 22 of the GDPR.
ReceptionGO provides technology that assists accommodation providers in carrying out their operational processes. Decisions relating to matters such as:
are made by the accommodation provider or in accordance with the accommodation provider's configuration and instructions.
17.5 Automated Decisions by Accommodation Providers
Accommodation providers may configure certain automated workflows within ReceptionGO, such as:
Such workflows are configured and controlled by the accommodation provider, which remains responsible for ensuring that their use complies with applicable laws and regulations.
17.6 Human Review
Where ReceptionGO supports automated verification or validation processes, accommodation providers may review the relevant information and make their own decisions where appropriate.
ReceptionGO does not prevent accommodation providers from exercising human oversight over guest registration and related processes.
17.7 Rights of Individuals
Where Article 22 GDPR applies, individuals may have the right:
Requests relating to guest data should generally be directed to the relevant accommodation provider, which acts as the Data Controller for most guest-related processing activities.
Where ReceptionGO acts as a Data Controller, such requests may be submitted directly to ReceptionGO using the contact details provided in this Privacy Policy.
ReceptionGO retains personal data only for as long as necessary to fulfil the purposes for which it was collected, to comply with applicable legal obligations, to resolve disputes, to enforce contractual agreements, and to protect the legitimate interests of ReceptionGO and its customers.
Retention periods vary depending on the type of personal data, the services used, applicable legal requirements, and our role as either a Data Controller or a Data Processor.
18.1 General Retention Principles
ReceptionGO applies the following principles when determining retention periods:
18.2 Guest Personal Data
Where ReceptionGO processes guest personal data on behalf of an accommodation provider, such data is retained in accordance with the instructions of the accommodation provider and the applicable Data Processing Agreement (DPA).
The accommodation provider determines:
ReceptionGO does not independently determine retention periods for guest data unless required by applicable law.
18.3 Customer Account Information
Information relating to customer accounts may be retained for the duration of the contractual relationship and for a reasonable period thereafter in order to:
18.4 Billing and Financial Records
Invoices, payment records, accounting information, and other financial records may be retained for the period required under applicable accounting, tax, and commercial legislation.
Retention periods for financial records are determined by the legal requirements applicable to Active line d.o.o. and may not be shortened upon request where retention is legally required.
18.5 Identity Verification Data
Where identity verification services are used, identity verification data is retained only for as long as necessary to provide the requested services, comply with applicable legal obligations, or as instructed by the accommodation provider.
ReceptionGO encourages accommodation providers to retain copies of identity documents only where required by applicable law.
Where technically possible, ReceptionGO supports configurations that minimise long-term storage of identity document images.
18.6 Government Reporting Records
Records relating to statutory guest registration and government reporting may be retained where required:
The applicable retention period depends on the legal requirements of the relevant jurisdiction.
18.7 System Logs and Security Records
Technical logs, audit logs, authentication records, and security monitoring information are retained only for as long as reasonably necessary to:
Older log data may be securely deleted or anonymised as part of routine system maintenance.
18.8 Customer Support Records
Customer support communications, including emails, tickets, and correspondence, may be retained for a reasonable period to:
18.9 Marketing Information
Where personal data is processed for marketing purposes based on consent, ReceptionGO retains such information until:
Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
18.10 Backup Copies
Personal data may continue to exist in encrypted backup systems for a limited period after deletion from active systems.
Backup data is retained solely for disaster recovery, business continuity, and system restoration purposes.
Backup copies are protected by appropriate technical and organisational security measures and are deleted or overwritten in accordance with ReceptionGO's backup lifecycle procedures.
18.11 Deletion and Anonymisation
When personal data is no longer required, ReceptionGO will, where appropriate:
The deletion method used depends on the nature of the data, the storage medium, and applicable legal requirements.
18.12 Requests for Deletion
Where ReceptionGO acts as a Data Controller, individuals may request deletion of their personal data in accordance with applicable data protection laws.
Where ReceptionGO acts as a Data Processor, requests relating to guest personal data should generally be submitted to the relevant accommodation provider, which is responsible for determining whether deletion is permitted under applicable law.
ReceptionGO will assist accommodation providers in responding to such requests where required under the applicable Data Processing Agreement.
18.13 Legal Holds
ReceptionGO may retain personal data beyond the standard retention period where necessary to:
Such data will be retained only for as long as necessary for the relevant legal purpose.
18.14 Periodic Review
ReceptionGO periodically reviews its data retention practices to ensure that personal data is not retained longer than necessary.
Retention schedules may be updated to reflect changes in applicable legislation, regulatory guidance, operational requirements, or improvements to our services.
ReceptionGO is committed to protecting personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, unauthorised access, and other forms of unlawful processing.
We implement appropriate technical and organisational measures designed to ensure a level of security appropriate to the nature of the personal data we process, taking into account the risks associated with the processing activities, available technology, implementation costs, and the likelihood and severity of potential risks to individuals.
While no information system can guarantee absolute security, ReceptionGO continuously reviews and improves its security practices to reduce identified risks.
19.1 Technical Security Measures
ReceptionGO implements appropriate technical safeguards, which may include:
The security measures applied may evolve over time as technology and security risks develop.
19.2 Organisational Security Measures
ReceptionGO maintains organisational measures designed to protect personal data, including:
Access to personal data is restricted to individuals who require such access to perform their authorised responsibilities.
19.3 Access Control
ReceptionGO limits access to personal data through appropriate authentication and authorisation mechanisms.
Access permissions are granted according to business responsibilities and are periodically reviewed.
Administrative access to production systems is restricted to authorised personnel.
Accommodation providers are responsible for managing user accounts, passwords, permissions, and access rights within their own organisations.
19.4 Secure Communications
Communications between users and the ReceptionGO platform are protected using encrypted connections designed to safeguard information transmitted over public networks.
Where supported, secure protocols are also used for communication with integrated third-party systems and service providers.
19.5 Infrastructure Security
ReceptionGO uses professional hosting and cloud infrastructure designed to support the confidentiality, integrity, and availability of personal data.
Infrastructure security may include:
19.6 Identity Verification Security
Where identity verification services are used, ReceptionGO applies additional safeguards appropriate to the sensitivity of identity-related information.
Depending on the services enabled, these safeguards may include:
19.7 Monitoring and Incident Detection
ReceptionGO continuously monitors its systems to help identify:
Monitoring activities are intended to protect both ReceptionGO and its customers while respecting applicable data protection laws.
19.8 Security Testing
ReceptionGO periodically evaluates the effectiveness of its security measures through activities that may include:
Security improvements are implemented as part of our ongoing development and operational processes.
19.9 Personal Data Breaches
ReceptionGO maintains procedures for identifying, investigating, managing, and responding to suspected personal data breaches.
Where ReceptionGO acts as a Data Controller, we will notify the competent supervisory authority and affected individuals where required by applicable law.
Where ReceptionGO acts as a Data Processor, we will notify the relevant accommodation provider without undue delay after becoming aware of a personal data breach affecting data processed on its behalf, as required by the applicable Data Processing Agreement and Article 33 of the GDPR.
19.10 Customer Responsibilities
Accommodation providers also play an important role in protecting personal data.
Customers are responsible for:
ReceptionGO cannot be responsible for unauthorised access resulting from compromised customer credentials or failures within the customer's own information security practices.
19.11 Continuous Improvement
Information security is an ongoing process.
ReceptionGO regularly reviews and updates its technical and organisational measures to address evolving security threats, technological developments, changes in applicable legal requirements, and improvements in industry best practices.
Our objective is to maintain a security framework that supports the confidentiality, integrity, availability, and resilience of the ReceptionGO platform and the personal data entrusted to us.
If you are located in the European Economic Area (EEA), the United Kingdom, Switzerland, or another jurisdiction with similar data protection legislation, you may have certain rights regarding your personal data under applicable law.
The availability of these rights depends on the nature of the processing activity and whether ReceptionGO acts as a Data Controller or a Data Processor.
Where ReceptionGO processes personal data solely on behalf of an accommodation provider, requests relating to guest personal data should generally be directed to the relevant accommodation provider, which acts as the Data Controller.
ReceptionGO will provide reasonable assistance to accommodation providers in responding to data subject requests where required by applicable law or our Data Processing Agreement (DPA).
20.1 Right of Access
You may have the right to obtain confirmation as to whether ReceptionGO processes your personal data and, where applicable, to request access to that personal data.
Subject to applicable law, you may also request information regarding:
Where legally permitted, you may also request a copy of your personal data.
20.2 Right to Rectification
You may request the correction of inaccurate personal data or the completion of incomplete personal data.
Where ReceptionGO acts as a Data Processor, corrections relating to guest information are generally carried out under the instructions of the relevant accommodation provider.
20.3 Right to Erasure ("Right to be Forgotten")
You may request the deletion of your personal data where one of the conditions set out in Article 17 GDPR applies.
This right is not absolute and may be limited where processing is necessary to:
Where ReceptionGO acts as a Data Processor, requests for deletion should generally be submitted to the relevant accommodation provider.
20.4 Right to Restriction of Processing
You may request that processing of your personal data be restricted where permitted under Article 18 GDPR.
For example, restriction may be requested where:
During a period of restriction, personal data may continue to be stored but will generally not be processed except where permitted by applicable law.
20.5 Right to Data Portability
Where processing is based on consent or the performance of a contract and is carried out by automated means, you may request to receive certain personal data in a structured, commonly used, and machine-readable format.
Where technically feasible and legally permitted, you may also request that such data be transmitted directly to another data controller.
20.6 Right to Object
Where ReceptionGO processes personal data based on legitimate interests, you may object to such processing on grounds relating to your particular situation.
If a valid objection is received, ReceptionGO will cease the relevant processing unless compelling legitimate grounds exist or the processing is necessary for the establishment, exercise, or defence of legal claims.
You also have the right to object at any time to the processing of your personal data for direct marketing purposes.
20.7 Right to Withdraw Consent
Where processing is based on your consent, you may withdraw your consent at any time.
Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
Withdrawal of consent may affect the availability of certain optional features or services where consent is required for their operation.
20.8 Rights Relating to Automated Decision-Making
Where Article 22 GDPR applies, you may have the right:
ReceptionGO generally uses automated processing to support operational activities and does not intentionally make decisions producing legal or similarly significant effects solely through automated processing.
20.9 Right to Lodge a Complaint
If you believe that your personal data has been processed in violation of applicable data protection laws, you have the right to lodge a complaint with the competent supervisory authority.
If ReceptionGO acts as the Data Controller, you are encouraged to contact us first so that we may have the opportunity to investigate and resolve your concerns.
Nothing in this Privacy Policy limits your statutory right to contact the competent supervisory authority directly.
20.10 Verification of Identity
To protect personal data from unauthorised disclosure, ReceptionGO may request reasonable information necessary to verify the identity of the person submitting a data protection request.
Where legally permitted, requests may be refused or additional information requested if ReceptionGO cannot reasonably verify the identity or authority of the requester.
20.11 Response Time
ReceptionGO will respond to requests relating to personal data within the time limits required by applicable data protection legislation.
Where ReceptionGO acts as a Data Processor, requests received directly from guests may be forwarded to the relevant accommodation provider unless applicable law requires otherwise.
Where permitted by law, the response period may be extended where requests are particularly complex or numerous. In such cases, the requester will be informed of the reason for the extension.
ReceptionGO is committed to facilitating the exercise of data protection rights in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
The procedure for exercising your rights depends on whether ReceptionGO acts as a Data Controller or a Data Processor in relation to the personal data concerned.
21.1 Requests Relating to Customer Account Data
If your request concerns personal data that ReceptionGO processes as a Data Controller, such as:
you may submit your request directly to ReceptionGO using the contact details provided in this Privacy Policy.
21.2 Requests Relating to Guest Personal Data
In most cases, ReceptionGO processes guest personal data solely on behalf of the relevant accommodation provider.
If your request concerns personal data collected during:
you should normally contact the relevant accommodation provider directly.
The accommodation provider acts as the Data Controller and is responsible for deciding how such requests should be handled under applicable law.
Where appropriate, ReceptionGO will assist the accommodation provider in responding to your request in accordance with our contractual obligations and applicable data protection legislation.
21.3 How to Submit a Request
Requests relating to personal data may be submitted using the contact information provided in this Privacy Policy.
To help us process your request efficiently, please provide:
Providing complete information helps us respond more efficiently and reduces unnecessary delays.
21.4 Verification of Identity
Before responding to a request, ReceptionGO may take reasonable steps to verify the identity of the requester.
This helps protect personal data against unauthorised disclosure.
Depending on the nature of the request, verification may include:
If ReceptionGO is unable to verify the identity or authority of the requester, we may request additional information before processing the request or decline the request where permitted by applicable law.
21.5 Timeframe for Responding
ReceptionGO will respond to requests within the time limits required by applicable data protection legislation.
Where ReceptionGO acts as a Data Controller, we aim to respond without undue delay and, where applicable, within one month of receiving the request.
Where permitted by law, this period may be extended if a request is particularly complex or if multiple requests are received from the same individual.
If an extension is required, the requester will be informed of the reasons for the delay.
21.6 Fees
ReceptionGO will generally process requests free of charge.
However, where permitted by applicable law, we may charge a reasonable administrative fee or refuse to act on a request if it is:
Any such decision will be made in accordance with the GDPR and other applicable legislation.
21.7 Limitations
Certain requests may be limited where ReceptionGO is required or permitted by law to retain or continue processing personal data.
Examples include situations where processing is necessary to:
Where legally permitted, ReceptionGO will explain the reasons why a request cannot be fully satisfied.
21.8 Assistance to Accommodation Providers
Where ReceptionGO acts as a Data Processor, we will provide reasonable assistance to accommodation providers in responding to requests from data subjects, as required by Article 28 of the GDPR and the applicable Data Processing Agreement (DPA).
Such assistance may include:
21.9 Contacting ReceptionGO
If you have any questions regarding your privacy rights or wish to exercise your rights where ReceptionGO acts as the Data Controller, you may contact us using the contact details provided in the Contact Information section of this Privacy Policy.
We encourage individuals to contact us before escalating concerns to a supervisory authority, and we will make reasonable efforts to resolve privacy-related issues promptly, transparently, and in accordance with applicable law.
ReceptionGO is not directed to children and is not intended for use by individuals under the age of 18 as an independent service.
ReceptionGO provides software exclusively to accommodation providers. Any collection of personal data relating to children occurs solely in connection with accommodation services provided by the relevant accommodation provider and only where such processing is necessary and permitted by applicable law.
22.1 Processing of Children's Personal Data
Accommodation providers may collect personal data relating to minors when required for purposes such as:
ReceptionGO processes such information solely on behalf of the accommodation provider and in accordance with its documented instructions.
22.2 Responsibility of Accommodation Providers
The accommodation provider is responsible for determining:
ReceptionGO does not independently determine whether parental consent is required in a particular jurisdiction.
22.3 No Intentional Collection from Children
ReceptionGO does not knowingly collect personal data directly from children for its own purposes, including:
Children are not permitted to create ReceptionGO customer accounts.
22.4 Identity Verification of Minors
Where applicable law requires the registration or identification of minor guests, ReceptionGO may process identity information relating to minors solely for the purposes specified by the accommodation provider and in accordance with applicable legal requirements.
Any identity verification involving minors is performed only where necessary and supported by the accommodation provider's instructions.
22.5 Data Protection Measures
ReceptionGO applies the same technical and organisational security measures to personal data relating to children as it does to all other personal data.
Where appropriate, additional safeguards may be applied based on the nature and sensitivity of the information being processed.
22.6 Requests Relating to Children's Personal Data
Requests concerning the personal data of children should generally be submitted to the relevant accommodation provider, which acts as the Data Controller for guest-related processing.
Where ReceptionGO acts as a Data Processor, we will assist the accommodation provider in responding to such requests in accordance with the applicable Data Processing Agreement (DPA) and relevant data protection legislation.
22.7 Deletion of Information
If ReceptionGO becomes aware that personal data relating to a child has been collected or processed for purposes not authorised by applicable law or contrary to this Privacy Policy,
we will take appropriate steps to investigate the matter and, where required, delete or restrict the processing of such information in accordance with applicable legal obligations.
ReceptionGO uses cookies and similar technologies to ensure the proper operation of our website and platform, improve user experience, enhance security, and analyse the performance of our services.
This section provides a general overview of our use of cookies. More detailed information, including the categories of cookies used, their purposes, retention periods, and available user choices, is provided in our separate Cookie Policy.
23.1 What Are Cookies?
Cookies are small text files placed on a user's device when visiting a website or using an online service.
Cookies allow websites and applications to recognise devices, remember user preferences, maintain secure sessions, and improve overall functionality.
ReceptionGO may also use similar technologies, including local storage, session storage, pixels, software development kits (SDKs), and comparable technologies where appropriate.
23.2 Why We Use Cookies
ReceptionGO uses cookies and similar technologies for purposes including:
ReceptionGO does not use cookies for purposes inconsistent with applicable data protection laws.
23.3 Categories of Cookies
Depending on the services used, ReceptionGO may use the following categories of cookies:
Strictly Necessary Cookies
These cookies are essential for the operation of the website and the ReceptionGO platform.
They enable functions such as:
These cookies cannot generally be disabled because the platform would not function correctly without them.
Functional Cookies
Functional cookies remember user preferences and improve the usability of the platform.
Examples include:
Analytics Cookies
Where enabled, analytics cookies help us understand how visitors interact with our website and services.
Analytics information may include:
Where required by applicable law, analytics cookies are used only after obtaining the user's consent.
Performance Cookies
Performance cookies help us monitor and improve the reliability, speed, and availability of our services.
These cookies assist in identifying technical issues and improving overall platform performance.
Marketing Cookies
ReceptionGO may use marketing or advertising cookies only where permitted by applicable law and only after obtaining the user's consent where required.
Marketing cookies may be used to:
At the time of publication of this Privacy Policy, ReceptionGO does not rely on marketing cookies for the operation of its core platform.
23.4 Third-Party Cookies
Some third-party services integrated into ReceptionGO or used on our website may place their own cookies.
Examples may include providers of:
ReceptionGO does not control cookies placed directly by third-party providers. Their use of cookies is governed by their own privacy and cookie policies.
23.5 Cookie Consent
Where required by applicable law, ReceptionGO requests the user's consent before placing non-essential cookies on their device.
Users may:
Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
23.6 Managing Cookies
Most web browsers allow users to manage cookies through their browser settings.
Users may choose to:
Please note that disabling certain cookies may affect the availability or functionality of some features of the ReceptionGO website or platform.
23.7 Changes to Our Use of Cookies
ReceptionGO may introduce new cookies, discontinue existing cookies, or modify the purposes for which cookies are used as our services evolve.
Any material changes will be reflected in our Cookie Policy and, where required by applicable law, users will be asked to review and update their cookie preferences.
23.8 Cookie Policy
For detailed information regarding:
please refer to our separate Cookie Policy, which forms an integral part of this Privacy Policy.
ReceptionGO may update this Privacy Policy from time to time to reflect changes in our services, applicable laws, regulatory requirements, technological developments, security practices, or business operations.
We encourage users to review this Privacy Policy periodically to remain informed about how we collect, use, and protect personal data.
24.1 Reasons for Updates
This Privacy Policy may be updated for reasons including, but not limited to:
24.2 Effective Date
The current version of this Privacy Policy is identified by the "Effective Date" and "Last Updated" dates displayed at the beginning of this document.
Unless otherwise stated, amendments become effective on the date specified in the updated Privacy Policy.
24.3 Notification of Material Changes
Where required by applicable law, or where changes materially affect the way personal data is processed, ReceptionGO will take appropriate steps to inform affected users.
Depending on the nature of the changes, notification may be provided through one or more of the following methods:
24.4 Continued Use of the Services
Where permitted by applicable law, continued use of the ReceptionGO services after the effective date of an updated Privacy Policy constitutes acknowledgement of the revised Privacy Policy.
Where changes require consent under applicable law, ReceptionGO will request such consent before processing personal data on the basis of the updated provisions.
24.5 Previous Versions
ReceptionGO may retain previous versions of this Privacy Policy for legal, regulatory, compliance, or historical purposes.
Archived versions may be made available upon request where required by applicable law or where ReceptionGO considers it appropriate.
24.6 Questions About Changes
If you have any questions regarding this Privacy Policy or any changes made to it, you may contact ReceptionGO using the contact details provided in the Contact Information section of this Privacy Policy.
We will make reasonable efforts to respond to privacy-related enquiries in a timely and transparent manner.
If you have any questions regarding this Privacy Policy, the processing of your personal data, or your rights under applicable data protection laws, you may contact ReceptionGO using the details below.
Active line d.o.o.
Company Name: Active line d.o.o. Registered Address: Podlimbarskega ulica 43, 1000 Ljubljana, Slovenia VAT ID: SI30336465
Website: https://receptiongo.com
General Email: [email protected]
Privacy Email: [email protected]
Privacy Requests
You may contact us regarding:
To help us process your request efficiently, please include sufficient information to identify your account, booking, or enquiry, together with your contact details and a description of your request.
ReceptionGO may request additional information where reasonably necessary to verify the identity or authority of the requester before disclosing personal data or taking action on a request.
Data Controller and Data Processor
As explained in this Privacy Policy, ReceptionGO may act either as a Data Controller or a Data Processor, depending on the nature of the processing activity.
Where ReceptionGO acts as the Data Controller, requests relating to your personal data may be submitted directly to us using the contact details provided above.
Where ReceptionGO acts as the Data Processor on behalf of an accommodation provider, requests concerning guest personal data should generally be submitted to the relevant accommodation provider, which acts as the Data Controller. ReceptionGO will provide reasonable assistance to the accommodation provider in responding to such requests where required by applicable law and the applicable Data Processing Agreement (DPA).
Supervisory Authority
If you believe that your personal data has been processed in violation of applicable data protection laws, you have the right to lodge a complaint with the competent supervisory authority in your country of residence, place of work, or the place of the alleged infringement.
If Active line d.o.o. acts as the Data Controller, the competent supervisory authority in Slovenia is:
Information Commissioner of the Republic of Slovenia (Informacijski pooblaščenec Republike Slovenije)
ReceptionGO encourages individuals to contact us first so that we have the opportunity to investigate and resolve any privacy-related concerns promptly, transparently, and in accordance with applicable law.
ReceptionGO respects the rights of individuals under applicable data protection laws and cooperates with competent supervisory authorities