Skip to content
nlesen

Version 1.3

Privacy Statement

Effective from September 20, 2026

Who is responsible?

HS Management & Beheer B.V., Torenlaan 5B, 1402 AT Bussum | Chamber of Commerce 32171536 | VAT NL822369680B01 | info@reoffice.es | 06 34339304, is the controller for the processing operations described in this statement. Questions and privacy requests may be sent to info@reoffice.es, with reference to 'Privacy REOVA'.

For personal data processed by a business Tenant within its own REOVA workspace, that Tenant is typically the controller and the Supplier is the processor. Data subjects should direct substantive requests concerning such workspace data first to the relevant Tenant; the Supplier shall support the Tenant in accordance with the Data Processing Agreement.

Which data and why?

PurposeDataLegal Basis
Account, trial and agreementName, business contact details, organisation, role, account and acceptance evidencePerformance of contract; legitimate interest in evidence and management
Billing and paymentInvoice data, VAT and registration numbers, payment status, provider and transaction IDsPerformance of contract; legal obligation
Security and abuse preventionLogin, device, IP, audit, error and security dataLegitimate interest in security and fraud prevention; legal obligation where applicable
Service and supportContact details, correspondence, support content and technical contextPerformance of contract; legitimate interest in support
Product improvementLimited usage and performance data, feedback and aggregated statisticsLegitimate interest in reliable improvement; consent where required
Legal complianceContract, audit, incident and communication evidenceLegal obligation; legitimate interest in legal proceedings
MarketingBusiness contact and preference dataConsent where required; legitimate interest for appropriate B2B communication with right of objection

Sources and mandatory data

Data originates from the data subject, their employer or Tenant, linked providers, payment and authentication services and from the use of REOVA. Mandatory fields are identifiable as such. Without necessary account, business or payment data, a trial or subscription may not be able to be provided.

Recipients and sub-processors

Data may be shared with hosting, database, storage, email, workflow, real-time, payment, card, communication, authentication and AI service providers, professional advisors, competent authorities and an acquiring group or successor entity. Only necessary data is provided and processors are contractually bound.

The current categories and service providers are listed in the Sub-processor List. Linked services such as Google, Microsoft, WhatsApp/Meta and payment providers may additionally be independent controllers for parts of their own service provision; their own privacy terms may then apply.

International transfers

Where data is processed outside the EEA, the Supplier uses a valid transfer mechanism, such as an adequacy decision or the European Commission's standard contractual clauses, with supplementary measures where necessary. Further information or a copy of applicable safeguards may be requested via the privacy contact, with omission of confidential security information.

Retention periods

CategoryPrinciple
Account and agreementDuring the relationship and thereafter as long as necessary for administration, evidence and legal proceedings.
Financial administrationIn accordance with applicable statutory tax retention periods.
Trial or terminated workspaceMinimum 60 days recovery retention after end of operational access; thereafter controlled deletion review, subject to legal hold or legal obligation.
Security and audit logsRisk-driven and no longer than necessary for security, investigation and evidence.
SupportAs long as necessary for handling, quality assurance and establishment of rights.
MarketingUntil withdrawal, objection or expiry of the relationship/necessity, with limited suppression data to respect preferences.

Security

The Supplier uses appropriate technical and organisational security measures, including access restriction, tenant isolation, encrypted transport, provider security, audit logging, secured credentials, development controls and incident procedures. No digital service can guarantee absolute security.

Automated decision-making and AI

REOVA may deploy AI for drafting, classification, translation, analysis and suggestions. The Supplier does not use these functions to make, as an independent controller, solely automated decisions that have legal or similarly significant consequences for a data subject. The Tenant is responsible for human review of its own use.

Rights of data subjects

  • access to, rectification of and, where applicable, deletion of personal data;
  • restriction of processing and objection to processing on the grounds of legitimate interest;
  • data portability where the statutory conditions are met;
  • withdrawal of consent, without prejudice to the lawfulness of prior processing;
  • a complaint to the Personal Data Authority or the competent supervisory authority in the country of habitual residence or work.

A request may be sent to the privacy contact. The Supplier may request additional information to verify identity and authority. Requests concerning Tenant data shall be forwarded to or handled together with the relevant Tenant where appropriate.

Changes and succession

This statement may change due to product, supplier, organisational or legislative changes. Material changes will be communicated appropriately. Upon transition of REOVA to the future Spanish S.L., the identity, contact details, transfer date and consequences will be communicated in advance; the new entity shall assume the relevant privacy responsibilities for future processing.