← Back to Dashboard
⚠️ DRAFT — Requires legal review before publishing.

Privacy Policy

Last updated: March 2026

1. Data Controller

Name: [FILL IN: Legal name]

Address: [FILL IN: Full legal address, Austria]

Email: hello@b-software.eu

2. Data We Collect

We collect and process the following personal data on behalf of our business tenants:

  • Account Information: Name, professional email address, phone number.
  • Tenant Branding: Logo images, business name.
  • Customer Data: Name, phone number, booking history, WhatsApp conversation content (as provided by you).
  • Technical Data: IP address, session cookies (for authentication only), browser type.

3. Purpose and Legal Basis

We process data for the following purposes:

  • Contract Performance (Art. 6(1)(b) GDPR): To provide the booking management service to our tenants.
  • Legitimate Interest (Art. 6(1)(f) GDPR): To ensure system security and prevent fraud.
  • Consent (Art. 6(1)(a) GDPR): Where you have explicitly opted into marketing or other optional services.

4. Your Rights

As a data subject under GDPR, you have the following rights:

  • Right of Access (Art. 15): Request a copy of your data.
  • Right to Rectification (Art. 16): Correct inaccurate data.
  • Right to Erasure (Art. 17): Request deletion of your data.
  • Right to Portability (Art. 20): Request your data in a machine-readable format.

5. Subprocessors

We use trusted third-party services to operate the platform. A full list of subprocessors is available upon request and includes: Render (Hosting), Stripe (Payments), Meta (WhatsApp Business API).

6. Data Retention

[FILL IN: Define specific retention periods for your business model].

7. Contact

For privacy inquiries, contact hello@b-software.eu. You also have the right to lodge a complaint with the Austrian Data Protection Authority (DSB).

8. AI Processing (EU AI Act & GDPR)

AI Assistant: BookFlow uses artificial intelligence (AI) to process incoming customer messages and generate automated responses for booking management. This is a DEPLOYER use case under EU AI Act Regulation (EU) 2024/1689.

8.1 AI Providers

We use third-party AI providers to power our assistant features:

  • Google (Gemini): Default AI model for intent detection and reply suggestions.
  • OpenAI (GPT): Alternative AI model.
  • Groq: Alternative AI model for fast processing.

When AI processes a customer message, the message content is transmitted to these providers for analysis. No data is used to train their models.

8.2 AI Disclosure

Customers whose messages are processed by AI will receive responses that are automatically identified as AI-generated. Each AI-sent message includes a disclosure: "_🤖 Sent by BookFlow AI_"

8.3 Customer Rights Regarding AI

Under GDPR Article 22, you have the right to request human review of any automated decision that significantly affects you. To request a human review of an AI-assisted booking decision, contact your service provider directly or email hello@b-software.eu.

8.4 Opt-Out of AI Processing

Customers can opt out of AI processing by sending "STOP" in response to any AI-generated message, or by contacting the business tenant directly. When a customer opts out, AI processing is disabled for that contact.