HannaAI

The detail, for whoever has to sign it off.

The privacy notice is written for people. This page is written for the person doing due diligence — an operator, a group's finance director, or a procurement team working through a questionnaire.

Section 1

Roles

Your venue is the controller of guest data. Hanna AI Ltd is the processor, acting only on your documented instructions under an Article 28 data processing agreement forming part of your contract.

For your own data as our customer — contact details, contract, billing, staff logins — we are the controller.

This is why a guest who contacts us directly to exercise their rights is referred to you rather than handled by us. It is your data and the decision is yours. We help you carry it out inside the product, promptly, but we do not act on your behalf without instruction.

Section 2

What we process, and on what basis

CategoryExamplesRole
Guest identity and contactName, email, telephone, party size, booking historyProcessor
Dietary and access needsSpecial category dataAllergies, intolerances, mobility and access requirementsProcessor
Transaction recordsItems ordered, amounts, tender type, service chargeProcessor
Guest correspondenceEnquiries and replies, including those Hanna drafts on your behalfProcessor
Staff recordsName, role, access level, clock-in and clock-out timesProcessor
Your accountContact details, contract, billing, support correspondenceController
DiagnosticsError reports and technical logs, scrubbed of personal detail before transmissionController

No card data. Card payments are handled by the payment provider on their own terminals. Full card numbers are never transmitted to, processed by, or stored in the Hanna platform.

Section 3

Where it lives

  • Application and database: European Union — Amsterdam
  • Backups: same region — European Union, Amsterdam, with point-in-time recovery
  • Static assets and delivery: global edge network, carrying no personal data

Two sub-processors operate outside the UK and EEA: Anthropic in the United States, and Google globally. Those transfers rely on the safeguards in each provider's own terms — UK international data transfer addenda or standard contractual clauses. Everything else, including backups, stays in the European Union.

Section 4

Sub-processors

The complete list. We give notice before adding to it.

ProviderPurposePersonal dataRegion
RailwayApplication and database hostingAll platform dataEU · Amsterdam
CloudflareDelivery, DNS and protectionIP addresses in transitGlobal edge
AnthropicLanguage model for guest conversation and narrationEnquiry text, booking contextUnited States
ResendTransactional and marketing emailGuest name and email addressEU · Ireland
Dojo / PaymentsenseCard payment capture and settlementTransaction references onlyUK
GoogleSign-inEmail address, account identifierGlobal
GlitchTipSelf-hostedError monitoringScrubbed diagnosticsOur infrastructure

On the language model. Guest enquiry text is sent to the model provider so that Hanna can understand and answer it. Under the terms we operate on, prompts are not used to train their models. Every figure Hanna states is computed by our own reporting engine against your database and passed to the model only to be phrased — the model has no direct database access, which is both a privacy property and the reason it cannot invent a number.

Section 5

How venues are kept apart

Every record carries its venue identifier, and every query is scoped to it at the data layer rather than relying on application code to filter correctly. Any operation that takes an entity reference from a request additionally verifies that the entity belongs to the requesting venue before acting on it.

The distinction matters in practice: a filtering bug in application code leaks data between tenants, whereas scoping at the data layer means the query cannot return another venue's rows in the first place. It is an architectural property rather than a policy, which is why we are willing to state it plainly.

Section 6

Technical and organisational measures

  • Encryption in transit (TLS) and at rest
  • Least-privilege access, with staff roles and permissions set by you within your venue
  • No shared administrative credentials; access to production is individually attributed
  • Irreversible and schema-level database operations restricted to named individuals through a controlled path, never through an application route
  • Money-path changes tested against a transaction and rolled back before release
  • Automated test gates on every change, with deployment blocked on failure
  • Error reporting scrubbed of personal data before it leaves the platform
  • Backups taken automatically, with point-in-time recovery available
Section 7

Retention and deletion

DataRetained
Guest and trading recordsFor the life of the contract, then deleted within 30 days of its end
Financial recordsSix years, as UK tax law requires
Diagnostic logs90 days
BackupsRolling, in the same EU region, and purged with the records they contain
Demo enquiries not proceeding12 months

Export is available at any time, from inside the product, without asking us and at no charge — guests, bookings, sales, recipes, invoices and staff hours, in a machine-readable format. The right survives termination and applies on the day you tell us you are leaving. We would rather make leaving easy than make it a retention conversation.

Section 8

If something goes wrong

On becoming aware of a personal data breach affecting your data, we notify you without undue delay and in any event within 24 hours, with what we know, what we are doing, and what we do not yet know.

As processor we support your notification obligations to the ICO and to data subjects; as controller of your own account data, we notify where required. We would rather tell you early and incompletely than late and tidily.

Section 9

Certifications, insurance and assurance

Formal assurance material — current certification status, insurance cover and levels, disaster recovery targets, and accessibility conformance — is issued privately on request rather than published here, because it is usually needed alongside context and a procurement team would rather have it in one document than assembled from a web page.

Ask and we will send it. It covers the items a due-diligence questionnaire normally asks for, including Cyber Essentials status, PCI DSS scope and where the responsibility sits, professional indemnity and cyber insurance, documented disaster recovery with recovery targets, and WCAG 2.2 AA conformance.

Where something is not yet in place we say so, give the date it will be, and set out what compensates for it in the meantime. That is more useful to you than a page that only lists what we happen to have.

Section 10

Documents available on request

Data processing agreement

Article 28 terms, forming part of the contract. Available before signature.

Sub-processor list

As published above, with notice given before any addition.

Technical and organisational measures

The detail behind section 6, in the form procurement teams ask for.

Capability pack

Certifications, insurance, disaster recovery and accessibility, issued on request.

Hanna AI Ltd · Company No. 17119925 · London
[email protected]