The privacy notice is written for people. This page is written for the person doing due diligence — an operator, a group's finance director, or a procurement team working through a questionnaire.
Your venue is the controller of guest data. Hanna AI Ltd is the processor, acting only on your documented instructions under an Article 28 data processing agreement forming part of your contract.
For your own data as our customer — contact details, contract, billing, staff logins — we are the controller.
This is why a guest who contacts us directly to exercise their rights is referred to you rather than handled by us. It is your data and the decision is yours. We help you carry it out inside the product, promptly, but we do not act on your behalf without instruction.
| Category | Examples | Role |
|---|---|---|
| Guest identity and contact | Name, email, telephone, party size, booking history | Processor |
| Dietary and access needsSpecial category data | Allergies, intolerances, mobility and access requirements | Processor |
| Transaction records | Items ordered, amounts, tender type, service charge | Processor |
| Guest correspondence | Enquiries and replies, including those Hanna drafts on your behalf | Processor |
| Staff records | Name, role, access level, clock-in and clock-out times | Processor |
| Your account | Contact details, contract, billing, support correspondence | Controller |
| Diagnostics | Error reports and technical logs, scrubbed of personal detail before transmission | Controller |
No card data. Card payments are handled by the payment provider on their own terminals. Full card numbers are never transmitted to, processed by, or stored in the Hanna platform.
Two sub-processors operate outside the UK and EEA: Anthropic in the United States, and Google globally. Those transfers rely on the safeguards in each provider's own terms — UK international data transfer addenda or standard contractual clauses. Everything else, including backups, stays in the European Union.
The complete list. We give notice before adding to it.
| Provider | Purpose | Personal data | Region |
|---|---|---|---|
| Railway | Application and database hosting | All platform data | EU · Amsterdam |
| Cloudflare | Delivery, DNS and protection | IP addresses in transit | Global edge |
| Anthropic | Language model for guest conversation and narration | Enquiry text, booking context | United States |
| Resend | Transactional and marketing email | Guest name and email address | EU · Ireland |
| Dojo / Paymentsense | Card payment capture and settlement | Transaction references only | UK |
| Sign-in | Email address, account identifier | Global | |
| GlitchTipSelf-hosted | Error monitoring | Scrubbed diagnostics | Our infrastructure |
On the language model. Guest enquiry text is sent to the model provider so that Hanna can understand and answer it. Under the terms we operate on, prompts are not used to train their models. Every figure Hanna states is computed by our own reporting engine against your database and passed to the model only to be phrased — the model has no direct database access, which is both a privacy property and the reason it cannot invent a number.
Every record carries its venue identifier, and every query is scoped to it at the data layer rather than relying on application code to filter correctly. Any operation that takes an entity reference from a request additionally verifies that the entity belongs to the requesting venue before acting on it.
The distinction matters in practice: a filtering bug in application code leaks data between tenants, whereas scoping at the data layer means the query cannot return another venue's rows in the first place. It is an architectural property rather than a policy, which is why we are willing to state it plainly.
| Data | Retained |
|---|---|
| Guest and trading records | For the life of the contract, then deleted within 30 days of its end |
| Financial records | Six years, as UK tax law requires |
| Diagnostic logs | 90 days |
| Backups | Rolling, in the same EU region, and purged with the records they contain |
| Demo enquiries not proceeding | 12 months |
Export is available at any time, from inside the product, without asking us and at no charge — guests, bookings, sales, recipes, invoices and staff hours, in a machine-readable format. The right survives termination and applies on the day you tell us you are leaving. We would rather make leaving easy than make it a retention conversation.
On becoming aware of a personal data breach affecting your data, we notify you without undue delay and in any event within 24 hours, with what we know, what we are doing, and what we do not yet know.
As processor we support your notification obligations to the ICO and to data subjects; as controller of your own account data, we notify where required. We would rather tell you early and incompletely than late and tidily.
Formal assurance material — current certification status, insurance cover and levels, disaster recovery targets, and accessibility conformance — is issued privately on request rather than published here, because it is usually needed alongside context and a procurement team would rather have it in one document than assembled from a web page.
Ask and we will send it. It covers the items a due-diligence questionnaire normally asks for, including Cyber Essentials status, PCI DSS scope and where the responsibility sits, professional indemnity and cyber insurance, documented disaster recovery with recovery targets, and WCAG 2.2 AA conformance.
Where something is not yet in place we say so, give the date it will be, and set out what compensates for it in the meantime. That is more useful to you than a page that only lists what we happen to have.
Article 28 terms, forming part of the contract. Available before signature.
As published above, with notice given before any addition.
The detail behind section 6, in the form procurement teams ask for.
Certifications, insurance, disaster recovery and accessibility, issued on request.
Hanna AI Ltd · Company No. 17119925 · London
[email protected]