Legal
Privacy policy
How Booking Desks collects, uses and protects personal data, written to be read, not just to comply. It applies to our website, the booking application and our relationship with customers.
Last updated September 13, 2026
1. The short version
- We collect what is needed to book desks and parking and to run a business with our customers. Nothing more.
- Your employer decides what happens with booking data in its workspace. We process it on their behalf.
- We do not sell personal data, show advertising, or use tracking or analytics cookies.
- Data is hosted in the European Union.
- You can reach us about privacy at any time at privacy@booking-desks.com.
2. Who is responsible for your data
Viallo s. r. o., Šustekova 3697/49, 851 04 Bratislava – Petržalka, Slovak Republic, IČO 57 859 043 ("we") is the controller for personal data we process for our own purposes: visitors to our website, contacts at customer organisations (such as billing and administrator contacts), prospects who write to us, and job applicants.
For booking data inside a workspace, your organisation is the controller and we act as its processor under our Data processing agreement. If you use Booking Desks through your employer and want to exercise your rights over booking data, contact your employer first; we will help them respond.
We have not appointed a data protection officer because the law does not require one for our processing. Privacy questions go to privacy@booking-desks.com.
3. What we collect
| Category | Examples | Where it comes from |
|---|---|---|
| Account data | Name, work email address, organisation, role (user or administrator), profile picture if your identity provider supplies one | Your administrator, you when you register, or Google or Microsoft when you sign in with them |
| Booking data | Desks and parking spaces booked, dates and times, check-ins, carpool driver and passengers, who booked on whose behalf, favourite desks, team members you follow | Created as you and your colleagues use the service |
| Preferences | Email and push notification settings, completed onboarding steps | Your choices in the app |
| Device data | Push notification subscription (a browser-generated address and keys) if you turn on push notifications | Your browser, only after you allow notifications |
| Technical data | IP address, browser type, time of request, error logs | Automatically, when you use the site or app |
| Customer contact and billing data | Names, email addresses and phone numbers of contacts, company details, invoices and payments | Your organisation when it orders, and our accounting |
| Correspondence | Messages you send us and our replies | You |
We do not ask for special categories of personal data (such as health data). Please do not put them into names, labels or closed-date descriptions.
4. Why we use it and on what legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing the booking service to a customer's workspace: accounts, bookings, check-in, parking, carpooling, notifications | Performed on behalf of the customer as processor (Art. 28); for the customer, usually Art. 6(1)(b) or (f) |
| Signing you in, including with Google or Microsoft, and keeping accounts secure | Contract (Art. 6(1)(b)) and legitimate interest in security (Art. 6(1)(f)) |
| Managing our contract with customers, invoicing and collecting payment | Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) |
| Keeping invoices and accounting records | Legal obligation under the Slovak Accounting Act (Act No. 431/2002 Coll.) and VAT Act (Art. 6(1)(c)) |
| Answering enquiries and support requests | Legitimate interest in responding (Art. 6(1)(f)), or steps before a contract (Art. 6(1)(b)) |
| Operating, securing and improving the service: logs, error monitoring, preventing abuse | Legitimate interest (Art. 6(1)(f)) |
| Service emails such as booking confirmations, check-in reminders and notices about changes | Contract (Art. 6(1)(b)); optional notifications follow your settings |
| Assessing job applications | Steps before a contract (Art. 6(1)(b)); consent (Art. 6(1)(a)) if we keep your application for future roles |
We do not make decisions about you based solely on automated processing that have legal or similarly significant effects. Automatic release of an unchecked-in desk follows a rule your organisation sets, and can always be reversed by booking again.
5. Who we share it with
Inside a workspace, colleagues can see what the workspace is designed to show: who sits where on a floor plan, team members' desks, and the people in a carpool. Administrators can see and manage the workspace's users and bookings.
We use a small number of service providers (sub-processors) who process data only on our instructions and under contracts that meet GDPR requirements:
| Provider | Purpose | Location |
|---|---|---|
| INTERNET CZ, a.s. (Forpsi), Czech Republic | Servers and database hosting | European Union |
| Websupport, s. r. o., Slovakia | Sending service emails | Location |
| Google (Google Ireland Ltd.) | Sign in with Google, only if your organisation enables it | EU, with transfers under the EU–US Data Privacy Framework |
| Microsoft (Microsoft Ireland Operations Ltd.) | Sign in with Microsoft, only if your organisation enables it | EU, with transfers under the EU–US Data Privacy Framework |
| Your browser's push service (for example Google, Mozilla or Apple) | Delivering push notifications, only if you turn them on | Depends on your browser |
We also share data where the law requires it, for example with tax authorities, courts or supervisory authorities, and with our accountants and legal advisers under confidentiality. We never sell personal data.
6. International transfers
Our servers are in the European Union. Where a provider may process data outside the European Economic Area, as with Google or Microsoft sign-in, the transfer is covered by an adequacy decision (such as the EU–US Data Privacy Framework) or by the European Commission's standard contractual clauses.
7. How long we keep it
- Workspace data (accounts, bookings, settings): for as long as the customer's contract runs, then deleted within 30 days of the contract ending. An administrator can delete individual users earlier.
- Past bookings are kept as part of the workspace so organisations can see how their office is used, unless the customer asks us to delete them sooner.
- Technical logs: up to 90 days, unless needed longer to investigate a specific security incident.
- Invoices and accounting records: 10 years, as the Slovak Accounting Act requires.
- Enquiries and correspondence: up to 3 years after the last contact.
- Job applications: until the role is filled and 6 months after, or up to 2 years with your consent.
8. How we protect it
Every connection is encrypted with TLS. Each organisation's data is separated at the database level and every request is checked against the organisation it belongs to. Passwords are stored only as salted hashes. Servers are patched automatically, protected by a firewall and accessible only with cryptographic keys. More detail is on our Security page.
If a personal data breach occurs that is likely to put your rights at risk, we will inform the affected customers without undue delay, and the supervisory authority where required.
9. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- rectification of inaccurate data;
- erasure of data we no longer need or process unlawfully;
- restriction of processing in certain situations;
- data portability, receiving data you gave us in a machine-readable format;
- object to processing based on legitimate interest;
- withdraw consent at any time where processing is based on consent, without affecting earlier processing.
Write to privacy@booking-desks.com. We answer within one month and may ask you to confirm your identity. For booking data in your employer's workspace, we pass your request to your employer as controller and help them answer it.
You also have the right to lodge a complaint with a supervisory authority. In Slovakia this is the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky), Hraničná 12, 820 07 Bratislava 27, dataprotection.gov.sk. You may also contact the authority in the EU country where you live or work.
10. Cookies
We use only the cookies and browser storage needed for the service to work, such as keeping you signed in. We use no advertising or analytics cookies. See our Cookie policy for the full list.
11. Changes to this policy
We update this policy when our processing changes. The date at the top shows the latest version. We notify customer administrators by email of significant changes.