HannaAI

What we do with personal data, and what we don't.

Written to be read. If any part of this is unclear, that is our failing rather than yours — tell us and we will rewrite it.

Version 1.0 · 27 July 2026
Section 1

Who we are

Hanna AI Ltd, registered in England and Wales, company number 17119925, registered office in London. We build and operate the Hanna platform for hospitality venues.

For questions about this notice or about any data we hold, write to [email protected]. A named person reads that inbox; it is not a ticketing system.

Section 2

The important distinction

For your guests' data, your venue is the controller and we are the processor. You decide what is collected and why. We act on your instructions and on nobody else's.

For your own data as a customer of ours — your name, your venue, your billing — we are the controller. That is a much smaller set, and it is covered in section 3.

This is not a technicality and it is worth being clear about, because it is the legal expression of the thing we say everywhere else on this site: your guests are yours. A platform that made itself the controller of your guest list would be free to use that list for its own purposes. We are not, and we have written it this way deliberately.

The arrangement is set out properly in the data processing agreement that forms part of your contract with us. This notice describes it; the agreement governs it.

Section 3

Data we hold as controller

This is data about you and your staff as our customer, not about your guests.

WhatWhyLawful basis
Name, work email, venue, venue typeFrom the demo form or from talking to usTo prepare for and hold a demo, and to reply to youLegitimate interests
Contract and billing detailsCompany, address, payment referenceTo provide the service and get paid for itContract
Staff logins and rolesName, role, PIN, hours workedTo run the product for you, and so hours reach your payrollContract
Support correspondenceEmails, notes from callsTo help you, and to remember what we agreedLegitimate interests
Diagnostic and error dataTechnical logs, scrubbed of personal detailTo find and fix faultsLegitimate interests

We do not run advertising, we do not buy contact lists, and we do not add you to a marketing sequence because you booked a demo. If you ask us to stop contacting you, we stop.

Section 4

Data we hold as processor

This is your guests' data. We hold it on your behalf, under your instructions, because you asked us to run software that needs it.

  • Booking details — name, contact details, party size, date and time, and anything the guest tells you when booking
  • Dietary and access requirements — allergies, intolerances and access needs. Some of this is health data and is treated accordingly
  • Visit history — what was ordered, what was spent, when they came, which table
  • Correspondence — messages between the guest and your venue, including those Hanna answers on your behalf
  • Marketing consent — whether given, and when

Allergy and access information is special category data. It is collected because a guest volunteered it so that you could serve them safely, it is used only for that, and it is not used to build audiences or to target marketing.

Section 5

What we never do

  • We never sell personal data. Not guest data, not yours. There is no circumstance in which this changes without your explicit agreement
  • We never market other venues to your guests. We have no marketplace and no diner network, so there is nothing to market and no incentive to try
  • We never mix one venue's guests with another's. Records are separated at the database layer rather than filtered in application code
  • We do not use your data to train general-purpose AI models. Your data is used to answer your questions and run your venue, and for nothing else
  • We do not require you to ask us for an export. You can take everything, whenever you like, from inside the product
Section 6

Who else touches it

We use a small number of sub-processors to run the platform. Each is bound by contract, each is listed here, and we will tell you before we add one.

WhoWhat forWhere
RailwayApplication and database hostingRunning the platform and storing your recordsEU · Amsterdam
CloudflareContent delivery and site hostingServing the applications and protecting themGlobal edge
AnthropicLanguage modelUnderstanding guest enquiries and writing answersUnited States
ResendTransactional and marketing emailSending confirmations, reminders and your notes to guestsEU · Ireland
Dojo / PaymentsenseCard paymentsTaking payment at the table and reconciling itUK
GoogleSign-inLetting staff and guests sign in with a Google accountGlobal

On the language model. Guest enquiries are sent to Anthropic's API so that Hanna can understand and answer them. Prompts are not used to train their models under the terms we operate on. Any figure Hanna quotes is computed by our own reporting engine and passed to the model to put into a sentence — the model does not query your database directly.

Section 7

Where it is kept

Your records, and their backups, are held in the European Union, in Amsterdam. Email is sent from Ireland. Two sub-processors operate outside the UK and EEA — Anthropic in the United States, and Google globally — and those transfers rely on the safeguards in each provider's own terms: UK international data transfer addenda or standard contractual clauses.

Section 8

How long we keep it

WhatKept for
Guest and trading recordsAs long as you are a customer, then deleted within 30 days of your contract ending
Financial recordsSix years, as UK tax law requires
Demo enquiries that go nowhere12 months, then deleted
Diagnostic logs90 days
Section 9

Your rights

Where we are the controller — your own data — you can ask us to show you what we hold, correct it, delete it, restrict what we do with it, hand it over in a portable format, or object to processing we do on the basis of legitimate interests.

Write to [email protected]. We will respond within one month, and usually much sooner.

If we get it wrong you can complain to the Information Commissioner's Office at ico.org.uk. We would rather you told us first so we can fix it, but it is your right either way and we will not treat it as a hostile act.

Section 10

Guests' rights, and what we do when one gets in touch

If one of your guests asks us directly to see, correct or delete their data, we do not act on it ourselves — because it is not our data to act on. We pass the request to you promptly, and we help you carry it out inside the product.

That is what being a processor means in practice, and it is the correct answer even though it is the slower one.

Section 11

Security

  • Encrypted in transit and at rest
  • Venue records separated at the database layer, not merely filtered in application code
  • Access on a least-privilege basis, with staff roles and PINs set by you
  • Card payments handled by the payment provider on their own terminals — we never see or store full card numbers
  • Error and diagnostic reporting scrubbed of personal detail before it leaves the platform
  • If a breach affects your data, we tell you without undue delay and support you in meeting your own obligations
Section 12

Changes, and how to reach us

If we change this notice we will date the new version and tell every venue by email. We will not make a material change quietly and hope nobody reads it.

Hanna AI Ltd · Company No. 17119925 · London
[email protected]