What we do with your information.
We sell record-keeping and data discipline to restaurants. It would be a poor advertisement if we were careless with yours, so this says exactly what we hold, why, who else sees it, and how to make us stop.
Version 10 · updated 2 October 2026 · AI4Hospitality Ltd · SC898661
The short version
- 🍪Nothing is set until you say yes. We use Google Analytics to see which pages people read, and, on the one page you reach after sending an enquiry, a Google Ads tag that tells us an advert led to it. Neither loads unless you accept the cookie banner. Say no and nothing is set at all.
- 🧾If you send invoices for a free check, we delete them once we have replied.
- 📇If we emailed you first, we say in that email where we got your details, and one reply stops it permanently.
- 🔑The tools live in a workspace that belongs to you. We never hold your login; we have our own named seat inside it, which you control and can remove in two clicks.
- 🚫We do not ask for payroll, bank details, staff home addresses and phone numbers, right-to-work documents, medical or disciplinary records, or your customers' personal data, and we will not accept them if offered.
- 📭No mailing list. No newsletter. Nothing is sold or shared for anyone else's marketing, ever.
01Who we are
AI4Hospitality Ltd is the data controller. Registered in Scotland, company number SC898661. Registered office: Dun Auladh Farm, Dervaig, Isle of Mull, PA75 6QR.
Registered with the Information Commissioner’s Office, registration reference ZC219458.
The business is run by one person, and if you write, you are writing to him: hello@ai4hospitality.co.uk. Nobody else has access to anything on this page. Data questions can go to privacy@ai4hospitality.co.uk.
02What we collect, and why
If you contact us, or fill in the form
Your name, the restaurant, an email address or phone number, the job you said you would hand over first, and how you heard about us.
We use it to reply to you and to keep track of the conversation. That is all. The lawful basis is taking steps at your request before entering a contract, and our legitimate interest in running a business that answers its post.
If you send invoices for the free check
Supplier invoices, and whatever is printed on them. We ask for supplier invoices only; please do not send anything with a member of staff or a customer on it.
We delete what you send once we have replied, along with any working notes made from it. If you would like the reply deleted too, say so and it goes as well.
If we emailed you and you had not heard of us
We only approach limited companies and limited liability partnerships, never sole traders or individuals. We take the company's own published details: the register at Companies House, and the business contact details the business itself publishes.
Every first email says where the details came from, because that is what the law requires and because it is a fair question. The lawful basis is our legitimate interest in offering a business service to another business.
One reply saying no is enough, and it is permanent. We keep the address on a suppression list purely so that we never contact it again, which is itself a use of your data, and the only honest way to keep a promise not to write.
If you become a client
Business records: supplier invoices and prices, stock, recipes, menus, trading figures, reviews, and staff first names, roles and hours worked, the last of these only because a rota cannot be checked without them.
One deliberate exception, added August 2026. If you give a member of your staff a seat in your workspace (usually whoever cooks, because allergen questions can only be answered by them), that seat needs a name and an email address, and both are visible to us. We ask that it is a work address rather than a personal one, and we take nothing else about that person beyond what is already listed above. Their own conversations are not ours to read and we do not ask for them. They can be reached only through an export of the whole account by an administrator, which section 03 explains.
What we do not take, and will not accept:
- Payroll, salaries or bank details, in any direction, for any reason
- Staff home addresses and personal phone numbers. Personal email addresses too, except where a member of staff has been given a workspace seat using one (see above), and we would rather it was a work address
- Right-to-work documents, passports or immigration paperwork
- Anything medical, and anything about a disciplinary or a grievance
- Your customers' personal data
If a piece of work looks like it needs something from that list, we stop and say so rather than working around it.
This website
Two Google tags, and neither runs until you say yes. One measures which pages people read. The other, on a single page, tells us when an advert produced an enquiry. Both sit behind the same banner: if you decline, neither script is ever fetched and no cookie is set. We do not load them and then switch them off; we do not load them at all.
Google Analytics 4, on every page. It records which pages are read and how people arrived, so we know what is worth writing.
A Google Ads conversion tag, on the thank-you page only: the page you reach after sending an enquiry. Nowhere else on this site loads it. It tells Google Ads that an advert we paid for led to an enquiry: one count, no name attached, nothing about who you are or what you wrote. Without it we would be buying adverts with no idea which of them work. Arriving from one of our adverts also puts an identifier in the web address, and that is how the count is matched back to the click.
Ad personalisation is switched off and stays off. We do not build advertising audiences, we do not run remarketing, and nobody is followed around the internet for having read this page. There are no other pixels and no other tracking tags of any kind: no Meta, no LinkedIn, no heatmaps, no session recording.
What changed, and when. Version 4 of this notice said there were no advertising tags on this site. That was true when it was written on 20 August 2026 and it stopped being true on 22 August, when the conversion tag went on the thank-you page. We would rather say so plainly than quietly reword it.
Version 6, 24 August 2026. The ICO registration reference was added to section 01 once the certificate was issued. Version 5 said only that the business was registered, which was true but less useful to anyone wanting to check.
The enquiry form checks you are not a robot. The form is provided by Copper and sits inside this page in a frame of its own. From 25 August 2026 it uses Google reCAPTCHA, which sets cookies and sends Google information about your browser and how you moved around the form, so that automated submissions can be told apart from real ones. That check belongs to the form rather than to the rest of this site, and unlike the analytics it runs whether or not you pressed Allow; its job is to keep junk out of a very small inbox. What Google does with it is covered by Google’s own privacy notice and the reCAPTCHA terms.
Version 7, 25 August 2026. reCAPTCHA was switched on for the enquiry form, and this notice was updated the same day. Version 6 described a form that had no such check.
Version 8, 26 August 2026. Sections 01 and 07 said that one person handled everything and that one person had access. A second administrator account was created on the CRM before that, so both sentences had stopped being true. They now say what is actually the case. Nothing about what is collected, why, or how long it is kept has changed.
Version 9, 14 September 2026. Section 03 said that our seat could not see your own conversations. That is true of the screens we use, but an administrator of your account can export the whole of it, conversations included, and our seat is an administrator. Section 03 now says so, and also says that connecting a document store grants access to that whole account rather than one folder. Section 05 now says how long conversations inside your account are kept. Section 02 now points to the same exception. Section 04 named the company that holds the domain as the host of this website as well. It now names both companies separately.
Version 10, 2 October 2026. Sections 01 and 07 said that a second administrator account existed on the CRM. That account was removed on 1 October, so both sentences had stopped being true. They now say that one person has access. The contact address is now hello@ai4hospitality.co.uk. Nothing about what is collected, why, or how long it is kept has changed.
Your choice is remembered in your own browser so you are not asked again. To change it, clear this site's data in your browser settings and the banner returns.
Both tags are provided by Google, who process the data on our behalf, including outside the UK.
Separately from analytics, our host keeps ordinary server logs, including IP addresses, for security and troubleshooting. Those are necessary to run the site and are not tied to the banner.
03The tools run in your workspace, and we have a seat in it
This is the part most people expect to be the other way round, so it is worth being clear, including about the bit that is less flattering to us.
The tools are built inside a workspace that belongs to you, created in your name and paid for on your card. You are its administrator.
We never hold your login and we never sign in as you. What we do have is one named seat of our own inside your workspace, so that we can install the tools, keep them working and answer your questions with the facts in front of us. That access is real and we would rather say so plainly than describe ourselves as having none.
What that seat can see: the shared project (the reference files that record how your business runs) and the tools themselves. What it does not see day to day: your own conversations, or those of anyone else you give a seat to. They do not appear anywhere in the screens we use, and we do not ask for them.
One exception, and we would rather say it than have you find it. An administrator of your account can export the whole of it, and that export file contains everyone's conversations, including ours. You are an administrator; so is our seat while it exists. It is not that conversations are sealed; it is that reaching them takes a deliberate act that leaves you as the owner of the account. Remove our seat and that ability goes with it.
You can remove us at any time, in two clicks, without notice and without giving a reason, and every tool keeps working. You also hold your own copy of every tool file from the setup day onwards, kept up to date, so nothing depends on our continued involvement.
Your workspace is on a plan that carries a written guarantee that its contents are not used to train models. We show you where that sits on the setup day, and note the date we looked.
Where your files are read from. If you connect a document store (Google Drive, for example) so that the tools can read your own paperwork, the connection is granted at the level of that whole account. There is no setting that limits it to one folder; we tried, and the narrower permission returns nothing. In practice we work from one folder that we build with you on the setup day and we ask for nothing outside it, but the permission you grant is wider than the folder and you should know that before you grant it rather than afterwards. You can withdraw it at any time from your own account settings.
04Who else sees it
We use ordinary business software. Each of these is a processor acting on our instructions, under a contract, and none of them is permitted to use your information for their own purposes.
| Service | What it handles |
|---|---|
| Google Workspace | Email, calendar and documents |
| Copper | The record of our conversation: who we spoke to and when |
| Stripe | Card payments and subscriptions. We never see or hold your card details |
| Xero | Invoices and accounting records |
| GoDaddy | The domain and its DNS |
| Netlify | Hosting this website |
Some of these operate outside the UK. Where information leaves the UK it is covered by the UK's approved transfer safeguards, or by an adequacy decision.
We will also disclose information where the law requires it. Beyond that, nothing is sold, rented, shared or handed to anybody for their own marketing.
05How long we keep it
| What | How long |
|---|---|
| Invoices sent for a free check | Deleted once we have replied |
| An enquiry that goes nowhere | 24 months, then deleted |
| A prospect who has not replied | Reviewed every 12 months and cleared out |
| A suppression-list entry | Kept indefinitely; that is the whole point of it |
| Client records and correspondence | Six years after the engagement ends, for tax and in case a question comes back |
| Conversations inside your account | Held in your account, under your control, for as long as you keep it. Not part of our records. The one route that reaches them is an administrator export of your own account, as section 03 describes |
| Accounting records | As long as HMRC and company law require |
06Your rights
You can ask us to show you what we hold, correct it, delete it, restrict what we do with it, or object to it altogether. You can ask for a copy in a portable format. Where we rely on legitimate interests (which is most of the above), you can object, and we will stop unless there is a compelling reason not to.
Email hello@ai4hospitality.co.uk. It is free, you do not need to give a reason, and we answer within one month.
If we get it wrong you can complain to the Information Commissioner's Office at ico.org.uk or 0303 123 1113. We would rather you told us first, but it is your call and you do not need our permission.
07How it is kept safe
- Two-factor authentication on every account that holds anything
- Access is limited to one person: the person you have been dealing with
- Bank details are never discussed by email: not with you, not with a supplier, not in a reply to something that appears to come from a bank
- Nothing is stored on removable media or a personal phone
08Changes
If this notice changes materially we will date the new version and, where it affects a live client, say so directly rather than quietly updating the page.