1. Who we are
NioReview is operated by Innova Poslovno Svetovanje, Rudi Medved, s.p., Tax ID 10593594, registration no. 9048219000, with its registered address at Jurčkova cesta 112, Ljubljana 1000, Slovenia. This entity is the data controller for personal data collected for NioReview’s own business purposes.
2. Scope and our data-protection roles
This notice applies when you:
- visit nioreview.com or another page that links to this policy;
- request a demo, contact us or communicate with our team;
- create or administer a NioReview business account; or
- use the NioReview service on behalf of a customer.
A hotel customer generally determines why hotel, employee and guest-related information is processed through the Service. For that Customer Data, the hotel is normally the controller and NioReview acts as its processor under the applicable customer agreement and data processing agreement.
3. Personal data we collect
- Contact and business information: name, work email, role, hotel or company, phone number and information included in a demo request or message.
- Account information: login identifiers, account permissions, organisation details and preferences.
- Service and support information: requests, communications, feedback and records needed to provide support.
- Review and operational data: review text, ratings, review metadata, property information and related insights supplied by a customer or obtained through an authorised integration.
- Technical information: IP address, device and browser information, timestamps, diagnostic logs, security events and basic usage information.
- Billing information: subscription, invoice and transaction records. Payment card details should be handled by the selected payment provider rather than stored directly by NioReview.
4. How and why we use personal data
| Purpose | Typical legal basis |
|---|---|
| Provide accounts, features, support and contracted services | Performance of a contract or steps requested before a contract |
| Respond to enquiries and arrange product demonstrations | Legitimate interests and pre-contractual steps |
| Secure, troubleshoot and improve the Service | Legitimate interests in operating a safe and effective service |
| Manage billing, records and legal obligations | Contract and compliance with legal obligations |
| Send optional product news or marketing | Consent where required, or legitimate interests where permitted |
Where we rely on legitimate interests, we consider the impact on individuals and do not use that basis where their rights and interests override ours. Where consent is used, it can be withdrawn at any time.
5. Sources of personal data
We may receive personal data:
- directly from you or the organisation you represent;
- from a NioReview customer that authorises your account or supplies Customer Data;
- from review platforms and integrations that the customer authorises;
- from publicly available review sources where collection and use are lawful; and
- automatically from systems used to deliver and secure the Service.
6. How personal data is shared
We may share limited personal data with:
- hosting, database, authentication, communications, AI and support providers working for us;
- review platforms or integrations selected by the customer;
- professional advisers, auditors, insurers and payment providers;
- authorities where disclosure is legally required; and
- a buyer or successor in connection with a genuine corporate transaction.
| Provider | Purpose | Data involved |
|---|---|---|
| NEOSERV | Public website hosting and delivery | Technical request information and server logs |
| Supabase | Database and application infrastructure; primary region North EU (Stockholm, Sweden) | Account, customer, review and service data |
| Stripe | Payment processing, billing and fraud prevention | Contact, billing and transaction information |
| OpenAI API | AI-assisted analysis, recommendations and draft replies | Relevant review text, instructions and generated output |
| Google Workspace (Gmail) | Business email and customer communications | Contact details and message contents |
Providers process personal data under their applicable agreements, data-protection terms and safeguards. Stripe may also act as an independent controller for regulated payment, fraud-prevention and compliance activities.
7. International data transfers
The public website is hosted through NEOSERV in Slovenia. NioReview’s primary Supabase database is hosted in the North EU region in Stockholm, Sweden. Stripe, OpenAI, Google and provider subprocessors may process some data outside Slovenia or the European Economic Area, depending on the service configuration. Where required, we rely on an approved transfer mechanism, such as an adequacy decision or standard contractual clauses, and assess supplementary safeguards where appropriate.
8. How long we keep data
We retain personal data only for as long as needed for the relevant purpose, customer instructions, security, dispute handling and legal obligations. Our standard retention schedule is:
| Data | Standard period |
|---|---|
| Demo requests and sales enquiries | Up to 24 months after the last meaningful contact |
| Customer accounts and Customer Data | For the contract term, then deleted or anonymised within 30 days unless the customer agreement or law requires otherwise |
| System backups | Overwritten or deleted within 90 days after deletion from active systems |
| AI inputs and generated outputs | Copies stored by NioReview follow the Customer Data period; OpenAI API abuse-monitoring logs may be retained for up to 30 days under its default controls |
| Support and business correspondence | Up to 24 months after the matter is closed |
| Security and diagnostic logs | Up to 12 months, unless needed for an active security investigation |
| Invoices and accounting records | 10 years after the end of the year to which the record relates |
| Marketing preferences | Until consent is withdrawn or an objection is made; a minimal suppression record may be retained to respect the opt-out |
Data may be kept longer where necessary to comply with law, resolve a dispute, establish or defend legal claims, or follow a documented customer instruction. When an exception ends, the data is deleted or anonymised.
9. Security
We use reasonable technical and organisational measures designed to protect personal data against accidental or unlawful loss, alteration, disclosure or access. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
10. Your data-protection rights
Depending on your location and the circumstances, you may have the right to:
- request access to and a copy of your personal data;
- correct inaccurate or incomplete data;
- request deletion or restriction of processing;
- object to processing based on legitimate interests or direct marketing;
- receive certain data in a portable format;
- withdraw consent without affecting earlier lawful processing; and
- lodge a complaint with your local data protection authority.
To make a request, contact us using the details below. We may need to verify your identity. If NioReview processes data only for a hotel customer, we may direct the request to that customer.
11. Automated processing
NioReview uses automated analysis to identify patterns, themes and operational signals in review data. The Service is designed to support decisions by hotel teams, not to make decisions that produce legal or similarly significant effects on an individual without meaningful human involvement.
Relevant review text and instructions may be sent to the OpenAI API to generate analysis, recommendations or draft replies. These outputs are intended as assistance for business users and should be reviewed before use.
12. Children
The Service is intended for business users and is not directed to children. We do not knowingly ask children to create accounts or provide personal data directly to us.
13. Changes to this policy
We may update this policy as our Service, providers or legal obligations change. We will post the updated version with a new date and give additional notice where required.
14. Contact and complaints
Privacy questions and requests can be sent to info@nioreview.com.
Postal correspondence may be sent to Innova Poslovno Svetovanje, Rudi Medved, s.p., Jurčkova cesta 112, Ljubljana 1000, Slovenia.
You may also lodge a complaint with the Information Commissioner of the Republic of Slovenia, Dunajska cesta 22, SI-1000 Ljubljana, or with another competent supervisory authority.