Last updated: 7 October 2026
1. Who we are
This website and the Quendoo platform (the hotel management dashboard, booking engine, channel manager and related services) are operated by Quendoo AD, a joint-stock company registered in Bulgaria, company number (EIK) 207759475, VAT BG207759475, registered office: 2 Tsanko Tserkovski St, floor 2, Lozenets, Sofia 1164, Bulgaria (“Quendoo”, “we”, “us”).
For any question about this policy or your personal data, contact us at [email protected] or +359 2 437 16 79.
2. Scope of this policy
This policy explains how we handle personal data:
- of visitors to quendoo.com, quendoo.bg and our other websites;
- of our customers (hotels, their owners and staff) who use the Quendoo platform;
- that we receive from Google when a customer connects a Google account to Quendoo (section 6).
When a hotel uses Quendoo to take bookings, the data of its guests is processed on behalf of that hotel. For guest data the hotel is the controller and Quendoo acts as its processor under our agreement with the hotel; guests should address their requests to the hotel.
3. What data we collect
- Contact data you give us through our forms, by email or phone: name, business and hotel name, email address, phone number and the content of your message.
- Account data of platform users: name, email, phone, login credentials (passwords are stored only in hashed form), security settings, and records of sign-ins.
- Business data you enter into the platform: properties, rooms, prices, availability, bookings and settings.
- Technical and usage data: IP address, browser and device type, pages visited, date and time, and similar log data needed to run and secure the service.
- Billing data needed to invoice our services.
4. Why we use it and on what legal basis
- To provide the platform and the services you requested — performance of a contract (Art. 6(1)(b) GDPR).
- To answer your enquiries and prepare offers — steps at your request before a contract (Art. 6(1)(b)).
- To keep the service secure, detect abuse and fix errors — our legitimate interest (Art. 6(1)(f)).
- To meet accounting, tax and other legal obligations — legal obligation (Art. 6(1)(c)).
- To send news about our products — your consent or, for existing customers, our legitimate interest; you can opt out at any time.
- To measure the effectiveness of our own advertising with Google tags — our legitimate interest and your consent to cookies (see section 9).
5. Who we share data with
We do not sell personal data. We share it only with:
- service providers that process data on our behalf under a data processing agreement — hosting and infrastructure, email delivery, payment processing and customer support tools;
- channels and partners a hotel itself chooses to connect (for example online travel agencies or payment providers), to the extent needed for that connection;
- authorities, where the law requires it.
Where a provider is located outside the European Economic Area, we rely on an adequacy decision or the European Commission’s Standard Contractual Clauses.
6. Google user data
Quendoo lets a hotel connect its Google accounts so that it can work with them from the Quendoo dashboard. We access Google data only after the account holder signs in with Google and grants permission on Google’s consent screen, and only for the features described here.
6.1 What we access
- Basic profile (email address, name, Google account ID) — to identify which Google account is connected and show it in the dashboard.
- Google Ads (scope
https://www.googleapis.com/auth/adwords) — the hotel’s Google Ads account structure, campaigns, budgets and performance statistics. On the hotel’s instruction we create and change campaigns, and we upload conversions (bookings made through the hotel’s Quendoo booking engine, with their value) so the hotel can measure the return on its advertising.
- Google Business Profile (scope
https://www.googleapis.com/auth/business.manage) — the hotel’s business locations and guest reviews. On the hotel’s instruction we publish replies to reviews.
6.2 How we use it
- Google user data is used only to provide and improve the features the hotel uses in Quendoo and that are visible to it: showing its advertising results and reviews, managing its campaigns and replying to its reviews.
- We do not sell Google user data, use it for advertising to anyone, use it to build user profiles, or transfer it to third parties, except to the hotel itself, where necessary to provide the feature, to comply with the law, or as part of a merger or acquisition with the same protections.
- We do not use Google user data to develop, improve or train generalised artificial-intelligence or machine-learning models.
- Our staff do not read Google user data except with the hotel’s consent (for example in a support request), when needed for security reasons or to comply with the law.
6.3 Storage, retention and deletion
- The access tokens Google issues are stored encrypted on our servers and are never shown in the browser or shared.
- We keep Google user data only as long as the account stays connected. When a hotel disconnects the Google account in Quendoo, or revokes access, we stop accessing it and delete the tokens and the Google data we hold within 30 days, except where the law requires us to keep a record.
- You can revoke Quendoo’s access at any time in the Quendoo dashboard or at myaccount.google.com/permissions.
6.4 Limited Use
Quendoo’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. How long we keep data
- Account and business data: for as long as the customer uses Quendoo and up to 12 months afterwards, unless the customer asks for earlier deletion.
- Invoices and accounting records: for the period required by Bulgarian law (currently 10 years).
- Enquiries that did not lead to a contract: up to 2 years.
- Technical logs: for a limited period, normally no longer than 12 months.
- Google user data: as described in section 6.3.
8. Security
We protect data with encryption in transit (HTTPS), encryption of secrets and access tokens at rest, access controls, two-factor authentication for accounts, and monitoring of our systems.
9. Cookies
Our websites use cookies that are necessary for them to work, and Google tags (Google Ads) that measure how visitors reach us through our advertising and whether they then contact us. These tags may set cookies and send data such as your IP address and the pages you visited to Google, which processes it under its own privacy policy. You can delete or block cookies in your browser settings, and limit ad personalisation at adssettings.google.com.
10. Your rights
Under the GDPR you have the right to access your data, to have it corrected or deleted, to restrict or object to its processing, to data portability, and to withdraw a consent at any time. To exercise them, write to [email protected]. We will answer within one month.
You also have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (2 Prof. Tsvetan Lazarov Blvd, Sofia 1592, www.cpdp.bg) or with the supervisory authority of your country.
11. Changes
We may update this policy. The date at the top shows the latest version; for material changes we will inform our customers in advance.