NioReview

Legal

Privacy Policy

This notice explains how NioReview handles personal data when people visit our website, contact us or use our services.

Last updated: 30 August 2026

1. Who we are

NioReview is operated by Innova Poslovno Svetovanje, Rudi Medved, s.p., Tax ID 10593594, registration no. 9048219000, with its registered address at Jurčkova cesta 112, Ljubljana 1000, Slovenia. This entity is the data controller for personal data collected for NioReview’s own business purposes.

2. Scope and our data-protection roles

This notice applies when you:

  • visit nioreview.com or another page that links to this policy;
  • request a demo, contact us or communicate with our team;
  • create or administer a NioReview business account; or
  • use the NioReview service on behalf of a customer.

A hotel customer generally determines why hotel, employee and guest-related information is processed through the Service. For that Customer Data, the hotel is normally the controller and NioReview acts as its processor under the applicable customer agreement and data processing agreement.

3. Personal data we collect

  • Contact and business information: name, work email, role, hotel or company, phone number and information included in a demo request or message.
  • Account information: login identifiers, account permissions, organisation details and preferences.
  • Service and support information: requests, communications, feedback and records needed to provide support.
  • Review and operational data: review text, ratings, review metadata, property information and related insights supplied by a customer or obtained through an authorised integration.
  • Technical information: IP address, device and browser information, timestamps, diagnostic logs, security events and basic usage information.
  • Billing information: subscription, invoice and transaction records. Payment card details should be handled by the selected payment provider rather than stored directly by NioReview.

4. How and why we use personal data

PurposeTypical legal basis
Provide accounts, features, support and contracted servicesPerformance of a contract or steps requested before a contract
Respond to enquiries and arrange product demonstrationsLegitimate interests and pre-contractual steps
Secure, troubleshoot and improve the ServiceLegitimate interests in operating a safe and effective service
Manage billing, records and legal obligationsContract and compliance with legal obligations
Send optional product news or marketingConsent where required, or legitimate interests where permitted

Where we rely on legitimate interests, we consider the impact on individuals and do not use that basis where their rights and interests override ours. Where consent is used, it can be withdrawn at any time.

5. Sources of personal data

We may receive personal data:

  • directly from you or the organisation you represent;
  • from a NioReview customer that authorises your account or supplies Customer Data;
  • from review platforms and integrations that the customer authorises;
  • from publicly available review sources where collection and use are lawful; and
  • automatically from systems used to deliver and secure the Service.

6. How personal data is shared

We may share limited personal data with:

  • hosting, database, authentication, communications, AI and support providers working for us;
  • review platforms or integrations selected by the customer;
  • professional advisers, auditors, insurers and payment providers;
  • authorities where disclosure is legally required; and
  • a buyer or successor in connection with a genuine corporate transaction.
ProviderPurposeData involved
NEOSERVPublic website hosting and deliveryTechnical request information and server logs
SupabaseDatabase and application infrastructure; primary region North EU (Stockholm, Sweden)Account, customer, review and service data
StripePayment processing, billing and fraud preventionContact, billing and transaction information
OpenAI APIAI-assisted analysis, recommendations and draft repliesRelevant review text, instructions and generated output
Google Workspace (Gmail)Business email and customer communicationsContact details and message contents

Providers process personal data under their applicable agreements, data-protection terms and safeguards. Stripe may also act as an independent controller for regulated payment, fraud-prevention and compliance activities.

7. International data transfers

The public website is hosted through NEOSERV in Slovenia. NioReview’s primary Supabase database is hosted in the North EU region in Stockholm, Sweden. Stripe, OpenAI, Google and provider subprocessors may process some data outside Slovenia or the European Economic Area, depending on the service configuration. Where required, we rely on an approved transfer mechanism, such as an adequacy decision or standard contractual clauses, and assess supplementary safeguards where appropriate.

8. How long we keep data

We retain personal data only for as long as needed for the relevant purpose, customer instructions, security, dispute handling and legal obligations. Our standard retention schedule is:

DataStandard period
Demo requests and sales enquiriesUp to 24 months after the last meaningful contact
Customer accounts and Customer DataFor the contract term, then deleted or anonymised within 30 days unless the customer agreement or law requires otherwise
System backupsOverwritten or deleted within 90 days after deletion from active systems
AI inputs and generated outputsCopies stored by NioReview follow the Customer Data period; OpenAI API abuse-monitoring logs may be retained for up to 30 days under its default controls
Support and business correspondenceUp to 24 months after the matter is closed
Security and diagnostic logsUp to 12 months, unless needed for an active security investigation
Invoices and accounting records10 years after the end of the year to which the record relates
Marketing preferencesUntil consent is withdrawn or an objection is made; a minimal suppression record may be retained to respect the opt-out

Data may be kept longer where necessary to comply with law, resolve a dispute, establish or defend legal claims, or follow a documented customer instruction. When an exception ends, the data is deleted or anonymised.

9. Security

We use reasonable technical and organisational measures designed to protect personal data against accidental or unlawful loss, alteration, disclosure or access. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

10. Your data-protection rights

Depending on your location and the circumstances, you may have the right to:

  • request access to and a copy of your personal data;
  • correct inaccurate or incomplete data;
  • request deletion or restriction of processing;
  • object to processing based on legitimate interests or direct marketing;
  • receive certain data in a portable format;
  • withdraw consent without affecting earlier lawful processing; and
  • lodge a complaint with your local data protection authority.

To make a request, contact us using the details below. We may need to verify your identity. If NioReview processes data only for a hotel customer, we may direct the request to that customer.

11. Automated processing

NioReview uses automated analysis to identify patterns, themes and operational signals in review data. The Service is designed to support decisions by hotel teams, not to make decisions that produce legal or similarly significant effects on an individual without meaningful human involvement.

Relevant review text and instructions may be sent to the OpenAI API to generate analysis, recommendations or draft replies. These outputs are intended as assistance for business users and should be reviewed before use.

12. Children

The Service is intended for business users and is not directed to children. We do not knowingly ask children to create accounts or provide personal data directly to us.

13. Changes to this policy

We may update this policy as our Service, providers or legal obligations change. We will post the updated version with a new date and give additional notice where required.

14. Contact and complaints

Privacy questions and requests can be sent to info@nioreview.com.

Postal correspondence may be sent to Innova Poslovno Svetovanje, Rudi Medved, s.p., Jurčkova cesta 112, Ljubljana 1000, Slovenia.

You may also lodge a complaint with the Information Commissioner of the Republic of Slovenia, Dunajska cesta 22, SI-1000 Ljubljana, or with another competent supervisory authority.