Skip to content
BookFrom.EU
Log in Get started EN RO

Legal · BookFrom.EU

Privacy Policy

This Privacy Policy explains how ARX CLOUD SYSTEMS SRL, at Strada Celofibrei 40, Bragadiru, registration details CUI RO46510890 (“BookFrom”, “we” or the “Operator”), handles personal data through BookFrom.EU. It applies to visitors, Customers, Consultants and account users.

It should be read together with the Terms of Service and Cookie Policy. This notice describes BookFrom's processing; a Consultant must provide any additional privacy information required for the Consultant's own professional or customer records.

Version
2026-09-30.1
Effective from
30.09.2026

Service operator

ARX CLOUD SYSTEMS SRL

Address
Strada Celofibrei 40, Bragadiru
Registration
CUI RO46510890
Legal contact
armand@kirie.ro

On this page

  1. 1. Controller and contact details
  2. 2. When BookFrom and the Consultant have different roles
  3. 3. Personal data we process
  4. 4. Sources of data
  5. 5. Purposes and legal bases
  6. 6. Payments and Mollie
  7. 7. Invoicing and SmartBill
  8. 8. Google user data and Limited Use
  9. 9. Recipients and disclosures
  10. 10. International transfers
  11. 11. Retention
  12. 12. Security
  13. 13. Your rights
  14. 14. Automated decisions
  15. 15. Children
  16. 16. Changes to this Policy

1. Controller and contact details

For Platform accounts, security, payment orchestration, legal records, service administration and the other purposes described below, the controller is ARX CLOUD SYSTEMS SRL.

Address: Strada Celofibrei 40, Bragadiru

Registration: CUI RO46510890

Privacy and rights requests: armand@kirie.ro

General support: armand@kirie.ro

If a data protection officer or EU representative becomes legally required, their details will be added to this Policy before the relevant processing begins.

Back to top ↑

2. When BookFrom and the Consultant have different roles

BookFrom is an independent controller when it decides why and how data is used to create and secure accounts, operate the Platform, orchestrate and reconcile payments, prevent abuse, maintain legal and audit records, handle support and improve reliability.

The Consultant is an independent controller for selecting Customers, delivering the consultation, maintaining professional or tax records, communicating outside the Platform and deciding any further use of Customer data. Contact the Consultant shown on the service and Booking pages for those activities.

For limited operations in which BookFrom stores or transmits Booking and intake data only on the Consultant's instructions, BookFrom may act as the Consultant's processor under the data-processing terms in the Terms of Service. These roles depend on the actual purpose of each processing operation and do not make the parties joint controllers by default.

Mollie generally acts as an independent controller for payment processing, regulatory compliance, identity verification and fraud prevention. Google processes information under Google's own terms when a User chooses Google Login or connects Google Calendar; BookFrom also uses Google Workspace to deliver transactional emails. When a Romanian Consultant enables SmartBill, BookFrom transmits invoice data to SmartBill on that Consultant's instructions; the Consultant remains responsible for the customer relationship, tax treatment and accounting records, while SmartBill's role is governed by the Consultant's SmartBill agreement.

Back to top ↑

3. Personal data we process

Depending on how you use BookFrom, we process:

  • account data, such as email address, password hash, preferred language, email-verification status, roles, login timestamps and a linked Google account identifier;
  • Consultant profile and business data, such as display and legal name, biography, photograph, business type, tax or registration identifiers, billing address, support email, country, languages and public URL;
  • service and availability data, including descriptions, prices, currency, duration, scheduling rules, weekly hours, exceptions and cancellation settings;
  • Customer data, such as name, email, optional phone number, language, timezone, billing fields and answers to the Consultant's intake questions;
  • Booking data, such as selected service, Consultant, date and time, status, cancellation reason, legal-document acceptances, management tokens and calendar or meeting references;
  • transaction data, such as amount, currency, platform commission, payment/refund status and Mollie payment, organisation and profile identifiers; BookFrom does not receive or store full card numbers;
  • invoicing data, such as the Consultant's SmartBill API email, encrypted API token, company tax code, selected invoice series and VAT rate, the status, series, number, identifier and public link of an invoice or credit note, and the equivalent references for the ARX commission invoice to the Consultant;
  • Google integration data described in section 8, including authorised scopes, selected calendar, account email, encrypted credentials, free/busy results and event identifiers;
  • communications and support data, including transactional delivery details and information you include in a request;
  • technical and security data, such as IP address, timestamps, session and CSRF identifiers, request identifiers, user agent, security events and audit logs; and
  • consent, preference and rights-request records needed to demonstrate compliance.

Please do not submit sensitive or special-category data in intake answers unless it is genuinely necessary and the Consultant has explained the legal basis and safeguards for doing so. BookFrom does not intentionally request such data as a standard account requirement.

Back to top ↑

4. Sources of data

We obtain data directly from Users, from Consultants who configure their pages, from a Customer completing a Booking, and automatically from the browser and Platform operations. We also receive limited status, identity or document data from providers you choose, including Mollie, SmartBill and Google. A Consultant may receive Customer data from BookFrom in order to fulfil a Booking.

If you provide personal data about another person, you must have authority to do so and give them any information required by law.

Back to top ↑

5. Purposes and legal bases

We process personal data only where a legal basis applies:

  • to create accounts, publish services, hold slots, complete Bookings, send operational messages, manage cancellations and provide requested integrations, because processing is necessary to perform a contract or take requested pre-contract steps;
  • to orchestrate payments, refunds, reconciliation and connected-account operations, because this is necessary to perform the Platform contract and, where applicable, comply with financial and accounting duties;
  • to issue an invoice through a Consultant's optional SmartBill connection and email its document link through BookFrom after verified payment, because the Consultant requests this integration to perform the customer contract and meet applicable accounting or tax duties;
  • to issue and email the ARX commission invoice to the Consultant and retain the related records, because this is necessary to perform the Platform contract and meet ARX's financial, accounting and tax duties;
  • to verify identity details, retain invoices, transaction evidence, legal acceptances and rights-request records, because the law requires it or the records are needed to establish, exercise or defend legal claims;
  • to secure the Platform, prevent fraud and abuse, diagnose failures, maintain audit trails and improve reliability, based on our legitimate interests in a safe and effective service, balanced against User rights;
  • to answer support requests and communicate material service or legal changes, based on contract necessity, legal obligations or legitimate interests as appropriate;
  • to use Google Calendar or another optional integration, because you request the feature and grant provider authorisation; you may disconnect it at any time; and
  • for optional Google Analytics 4 statistics about visits to public pages, only after your consent in the cookie banner. The data, cookie durations and controls are described in the Cookie Policy. We do not enable advertising cookies, Google Signals or advertising personalisation.

Where we rely on consent, you may withdraw it at any time without affecting earlier lawful processing. Where we rely on legitimate interests, you may object as described in section 12.

Back to top ↑

6. Payments and Mollie

At checkout you are redirected to or interact with Mollie's payment environment. BookFrom sends the amount, currency, Booking reference and connected Consultant account needed to create and reconcile the payment. Mollie returns identifiers, method and status information needed to confirm payment, process a refund and investigate discrepancies.

Mollie may collect payment instrument, payer, device, identity and anti-fraud information directly and may retain or disclose it to banks, schemes and authorities under its own legal obligations. That processing is governed by Mollie's privacy notice. BookFrom stores only the provider references and transaction metadata needed for the Platform; it does not store full card credentials.

Back to top ↑

7. Invoicing and SmartBill

For Consultants based in Romania, the SmartBill connection used for the Customer invoice is an optional, Consultant-controlled integration. When it is active and a payment is verified, BookFrom sends SmartBill the invoice issuer and configuration data selected by the Consultant; the Customer's name, billing email, optional phone, billing address, country and, for companies, tax and registration identifiers; and the service description, Booking reference, gross amount, currency, payment date and online-card payment method. SmartBill issues the invoice in the Consultant's account. BookFrom then sends the Customer the document link through its Google Workspace transactional email account. BookFrom does not send intake answers to SmartBill.

If Mollie confirms a full refund and the Customer invoice was issued through this integration, BookFrom sends the series, number and date needed to issue the credit note in the same SmartBill account. After issuance, it separately sends the original billing email address so the document can be emailed. We store the status and references of both documents, including issuance or email errors, to prevent duplicates and provide support.

Separately, ARX uses its own SmartBill account for the BookFrom commission invoice to a Romanian Consultant. For this purpose, we send the legal identity, available tax and registration identifiers, professional address, country and email of the Consultant from the snapshot fixed with the Booking, together with the commission amount and currency, payment date and an opaque Booking/payment reference. We do not put the Customer's name, contact details, billing address or intake answers on the commission invoice. SmartBill is instructed to email the commission invoice to the Consultant.

The Consultant's SmartBill API token is encrypted at rest and is not shown again in BookFrom; the ARX account credentials are kept in the Platform's secret configuration. BookFrom stores the resulting status, series, number, document identifier and view link for operational, support and legally required recordkeeping. Disconnecting SmartBill prevents new automatic Consultant invoices, may prevent an automatic credit note and removes the token from active use, but does not erase documents or records that must be retained. The Consultant determines the correct invoice series, VAT treatment, measuring unit, any SmartBill credit-note email configuration and any e-Factura, correction, cancellation or retention steps required for documents issued in its name.

Back to top ↑

8. Google user data and Limited Use

Google Login and Google Calendar are separate, optional features:

  • Google Login requests the openid, email and profile scopes. BookFrom uses the verified email address, stable Google subject identifier and available profile name to create a BookFrom account when needed, authenticate the User and link the Google identity. The short-lived authorisation code and ID/access tokens used during login are not retained after authentication.
  • Google Calendar requests calendar.events, calendar.events.freebusy, openid and email access. BookFrom uses free/busy information to avoid conflicting slots and creates, reads as operationally necessary, updates or deletes Booking events and Google Meet conference links in the Consultant's selected calendar.
  • For a Calendar connection, BookFrom stores the Google account identifier and email, selected calendar identifier, authorised scopes, token expiry, encrypted access and refresh tokens, connection health and created event identifiers. Tokens are encrypted at rest and used only to operate the requested integration.

BookFrom's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not sold, used for targeted advertising, used to build advertising profiles or transferred for unrelated purposes. Human access is allowed only with the User's affirmative agreement for support, where necessary to investigate security or abuse, where required by law, or for internal operations using aggregated and anonymised data where feasible.

You can disconnect Calendar in the BookFrom integration settings and revoke BookFrom in your Google Account security settings. Disconnecting removes stored Calendar credentials from active use; revocation at Google prevents future API access. You may also request deletion under section 13. Calendar events already shared with attendees may remain in their calendars or in Google systems under their own controls.

Back to top ↑

9. Recipients and disclosures

We disclose personal data only as necessary to:

  • the booked Consultant and authorised account users, so they can administer and deliver the service;
  • hosting, database, email-delivery, monitoring, security and customer-support suppliers acting under appropriate contractual duties;
  • Mollie, banks and payment networks for payment, refund, compliance and fraud controls;
  • SmartBill, to issue and store an invoice and credit note in the account of a Romanian Consultant who enables the integration, to email a credit note, and to issue and email the ARX commission invoice to a Romanian Consultant;
  • Google Workspace for transactional email delivery; Google when a User enables Google Login or Calendar, and calendar attendees when an event is created; Google Ireland Limited for optional Google Analytics 4 after cookie consent;
  • professional advisers, auditors and insurers under confidentiality obligations;
  • competent courts, regulators, law-enforcement or public authorities where disclosure is legally required or necessary to protect rights and safety; and
  • a buyer or successor in a genuine corporate transaction, subject to confidentiality and continued data-protection safeguards.

BookFrom does not sell personal data. We do not share personal data with data brokers or use it for cross-context behavioural advertising.

Back to top ↑

10. International transfers

Providers may process data outside your country or the European Economic Area. Where GDPR transfer restrictions apply, BookFrom relies on an applicable adequacy decision, the European Commission's Standard Contractual Clauses with supplementary measures where needed, or another lawful transfer mechanism. You may request information about the relevant safeguard at armand@kirie.ro. Provider-controlled transfers, including those by Mollie or Google as independent controllers, are described in their privacy documentation.

Back to top ↑

11. Retention

We keep data only as long as needed for the stated purpose, legal obligations and proportionate dispute protection. The principal criteria and operational periods are:

  • the cookie preference and optional Analytics cookies last up to 180 days; Google Analytics event-level data is retained for 2 months, while aggregated reports may remain longer;
  • browser sessions expire after up to 2 hours; Calendar and Google Login OAuth state is valid for up to 10 minutes;
  • password-reset tokens expire after 1 hour and email-verification tokens after 24 hours; used or superseded tokens are no longer valid;
  • active account, profile, service and integration data is retained while the account is open; Calendar and SmartBill credentials remain until disconnection, revocation or completed account deletion;
  • slot holds remain as short-lived transaction records after their configured hold period so concurrency and Booking integrity can be demonstrated;
  • Booking, payment, refund, legal-acceptance, invoice-related and audit records are retained for the period required by tax, accounting, consumer, anti-fraud and limitation laws, commonly up to 10 years where Romanian accounting retention applies, and are access-restricted when no longer needed operationally;
  • support and security records are retained according to severity and the time needed to resolve the issue, enforce rights and meet legal duties; and
  • encrypted backups are removed through scheduled rotation. Data due for deletion may remain inaccessible in a backup until that backup is overwritten, unless restoration is required for disaster recovery.

A verified Customer erasure request is completed after active Bookings, payments and refunds are resolved. Identity and non-required intake data is anonymised; billing or legal evidence is retained only where an approved legal basis requires it. Completed Consultant account deletion removes credentials, public profile data and active integration tokens while restricted financial and legal records may remain for required periods.

Back to top ↑

12. Security

BookFrom uses measures designed for the risk, including password hashing, encryption of third-party credentials at rest, HTTPS in production, access controls, tenant scoping, CSRF protection, expiring signed or random tokens, rate limits, audit records, backups and controlled administrative workflows. Payment-card data is handled by the payment provider rather than stored by BookFrom.

No internet service is completely secure. Users must protect account credentials, avoid sending secrets through intake forms and report suspected compromise to armand@kirie.ro. If a personal-data breach creates a legally reportable risk, BookFrom will notify the competent authority and affected people as required.

Back to top ↑

13. Your rights

Subject to the GDPR and applicable law, you may have the right to:

  • obtain confirmation and access to your personal data;
  • correct inaccurate or incomplete data;
  • request erasure;
  • restrict processing;
  • receive data you provided in a structured, commonly used and machine-readable format and transmit it to another controller;
  • object to processing based on legitimate interests, including any direct marketing;
  • withdraw consent at any time where consent is the basis; and
  • complain to the supervisory authority in your habitual residence, place of work or place of the alleged infringement.

To exercise a right, email armand@kirie.ro and describe the account, Booking or Consultant concerned. We may ask for proportionate identity verification and clarification. We normally respond within one month, with any legally permitted extension explained. Rights are not absolute; if a request is limited or refused, we will explain the applicable reason and complaint options.

For processing independently controlled by a Consultant or Mollie, or performed by SmartBill under the Consultant's account, you may contact the relevant party directly. BookFrom will reasonably assist in routing a request where appropriate.

Back to top ↑

14. Automated decisions

BookFrom does not make decisions producing legal or similarly significant effects solely by automated processing. Automated security controls may rate-limit activity, flag a transaction for review or prevent an invalid Booking, but material disputes can be reviewed by a person. Mollie may apply its own automated fraud and compliance controls as described in Mollie's notices.

Back to top ↑

15. Children

BookFrom is intended for adults and is not directed to children under 18. We do not knowingly create accounts for children. If you believe a child has provided data without lawful authorisation, contact armand@kirie.ro so it can be investigated and deleted where required.

Back to top ↑

16. Changes to this Policy

We may update this Policy when processing, providers or law changes. The page shows a version and effective date. Material changes will be highlighted or communicated to registered Users where appropriate. A change does not retroactively create a new legal basis for prior processing.

Questions, complaints and rights requests can be sent to armand@kirie.ro. You also have the right to contact the data-protection supervisory authority competent for your location; a list of EU/EEA authorities is available through the European Data Protection Board.

Back to top ↑

Questions and rights requests

Need a clear answer?

Contact the legal and privacy address for these documents, data requests or a complaint. Use technical support for account and booking issues.

armand@kirie.ro Technical support: armand@kirie.ro
Related legal documents Terms of Service Privacy Policy Cookie Policy
BookFrom.EU · Built in the EU for independent experts.
Terms of Service Privacy Policy Cookie Policy

Your cookie preferences

We use essential cookies to keep BookFrom working. With your permission, Google Analytics helps us understand visits to public pages. You can change your choice at any time. Read the cookie policy

Essential cookies — Always active for login, security and remembering your cookie choice.