Version 1.3
Privacy Statement
Effective from September 20, 2026
Who is responsible?
HS Management & Beheer B.V., Torenlaan 5B, 1402 AT Bussum | Chamber of Commerce 32171536 | VAT NL822369680B01 | info@reoffice.es | 06 34339304, is the controller for the processing operations described in this statement. Questions and privacy requests may be sent to info@reoffice.es, with reference to 'Privacy REOVA'.
For personal data processed by a business Tenant within its own REOVA workspace, that Tenant is typically the controller and the Supplier is the processor. Data subjects should direct substantive requests concerning such workspace data first to the relevant Tenant; the Supplier shall support the Tenant in accordance with the Data Processing Agreement.
Which data and why?
| Purpose | Data | Legal Basis |
|---|---|---|
| Account, trial and agreement | Name, business contact details, organisation, role, account and acceptance evidence | Performance of contract; legitimate interest in evidence and management |
| Billing and payment | Invoice data, VAT and registration numbers, payment status, provider and transaction IDs | Performance of contract; legal obligation |
| Security and abuse prevention | Login, device, IP, audit, error and security data | Legitimate interest in security and fraud prevention; legal obligation where applicable |
| Service and support | Contact details, correspondence, support content and technical context | Performance of contract; legitimate interest in support |
| Product improvement | Limited usage and performance data, feedback and aggregated statistics | Legitimate interest in reliable improvement; consent where required |
| Legal compliance | Contract, audit, incident and communication evidence | Legal obligation; legitimate interest in legal proceedings |
| Marketing | Business contact and preference data | Consent where required; legitimate interest for appropriate B2B communication with right of objection |
Sources and mandatory data
Data originates from the data subject, their employer or Tenant, linked providers, payment and authentication services and from the use of REOVA. Mandatory fields are identifiable as such. Without necessary account, business or payment data, a trial or subscription may not be able to be provided.
Recipients and sub-processors
Data may be shared with hosting, database, storage, email, workflow, real-time, payment, card, communication, authentication and AI service providers, professional advisors, competent authorities and an acquiring group or successor entity. Only necessary data is provided and processors are contractually bound.
The current categories and service providers are listed in the Sub-processor List. Linked services such as Google, Microsoft, WhatsApp/Meta and payment providers may additionally be independent controllers for parts of their own service provision; their own privacy terms may then apply.
International transfers
Where data is processed outside the EEA, the Supplier uses a valid transfer mechanism, such as an adequacy decision or the European Commission's standard contractual clauses, with supplementary measures where necessary. Further information or a copy of applicable safeguards may be requested via the privacy contact, with omission of confidential security information.
Retention periods
| Category | Principle |
|---|---|
| Account and agreement | During the relationship and thereafter as long as necessary for administration, evidence and legal proceedings. |
| Financial administration | In accordance with applicable statutory tax retention periods. |
| Trial or terminated workspace | Minimum 60 days recovery retention after end of operational access; thereafter controlled deletion review, subject to legal hold or legal obligation. |
| Security and audit logs | Risk-driven and no longer than necessary for security, investigation and evidence. |
| Support | As long as necessary for handling, quality assurance and establishment of rights. |
| Marketing | Until withdrawal, objection or expiry of the relationship/necessity, with limited suppression data to respect preferences. |
Security
The Supplier uses appropriate technical and organisational security measures, including access restriction, tenant isolation, encrypted transport, provider security, audit logging, secured credentials, development controls and incident procedures. No digital service can guarantee absolute security.
Automated decision-making and AI
REOVA may deploy AI for drafting, classification, translation, analysis and suggestions. The Supplier does not use these functions to make, as an independent controller, solely automated decisions that have legal or similarly significant consequences for a data subject. The Tenant is responsible for human review of its own use.
Rights of data subjects
- access to, rectification of and, where applicable, deletion of personal data;
- restriction of processing and objection to processing on the grounds of legitimate interest;
- data portability where the statutory conditions are met;
- withdrawal of consent, without prejudice to the lawfulness of prior processing;
- a complaint to the Personal Data Authority or the competent supervisory authority in the country of habitual residence or work.
A request may be sent to the privacy contact. The Supplier may request additional information to verify identity and authority. Requests concerning Tenant data shall be forwarded to or handled together with the relevant Tenant where appropriate.
Changes and succession
This statement may change due to product, supplier, organisational or legislative changes. Material changes will be communicated appropriately. Upon transition of REOVA to the future Spanish S.L., the identity, contact details, transfer date and consequences will be communicated in advance; the new entity shall assume the relevant privacy responsibilities for future processing.