1. Identity and contact details
The data controller is ZVELTO LIMITED, trading as Zvelto and Zvelto AI.
Registered address: 66 Paul Street, London, EC2A 4NA, United Kingdom.
ICO registration number: ZC103696
Contact email: privacy@zvelto.ai
Supervisory authority:
- UK users: the Information Commissioner's Office (ICO).
- EU users: as Zvelto does not have a physical office in the EU, you may contact our UK office for all data matters. You also have the right to lodge a complaint with the data protection authority in the EU member state where you reside.
2. Categories of personal data we process
We process different data depending on how you interact with Zvelto: as a restaurant operator with a dashboard account, or as a diner ordering, booking or leaving feedback through a restaurant's website.
- Operator account data: name, business email address, and hashed password for restaurant staff and owners with a dashboard login.
- Organisational data: restaurant or company name and professional role.
- Diner data (web ordering, reservations and feedback): when you place an online order, request a table, or leave feedback through a restaurant's website, we collect the name and phone number you provide, plus the email address and delivery address when you enter one. We also store the details of your order or request itself (items, quantities, requested time, party size, comments) so the restaurant can fulfil it.
- Order and reservation alerts: to reach restaurant staff immediately, the name, phone number and order or reservation details you submit are forwarded to that restaurant's own Telegram notification channel. This is an operational alert used to fulfil your order or request, not a marketing channel, and it is controlled by the restaurant, not shared onward by us for any other purpose.
- Session and activity data (operator accounts): exact login and logout timestamps and total session duration. If an explicit logout is not recorded (for example the browser is closed), the session is closed at the time of the next login as a best-effort record.
- Presence heartbeat (operator accounts): a background request sent approximately every 60 seconds while the dashboard is open, used to update a "last active" timestamp for administrative visibility. This is overwritten continuously and has no historical value.
- Payment data: handled by Stripe for operator subscription billing. We do not store card details on our servers; we receive only confirmation of payment and associated billing metadata.
- Technical data: IP address and browser user agent, including for anti-abuse checks on public order, reservation and feedback forms.
- Cookies and local storage: we use a small number of strictly necessary and functional cookies and browser local-storage entries: a short-lived country cookie set at the edge to choose your default currency, your saved language and currency preferences, and, for restaurant operators, a sign-in token that keeps you logged in. We do not use advertising or cross-site tracking cookies.
- AI feature data: anonymised business data (such as menu items and review text) processed to generate operational insights for restaurant operators.
- Documents uploaded to the AI assistant (operator accounts): restaurant operators can upload their own business documents (for example a menu, a recipe sheet or a supplier invoice) to the AI assistant in their dashboard. We read the text out of the file and keep it as notes that the assistant consults when answering their questions. Whatever an operator uploads is processed, so a document may contain other people's details, such as a supplier contact on an invoice. The file itself is not stored: it is processed in memory and discarded once the text has been read out of it.
- Planner event briefs: external event planners can submit an event date window, session, guest count, tax-inclusive budget, occasion, area and notes. They may also provide dietary or allergy requirements for attendees. This is a staging design and production collection is disabled pending qualified legal review. Dietary and allergy information can be special-category data under Article 9 GDPR. The planner's confirmation is an operational attestation that they have permission to share it, not a lawful basis or an Article 9 condition. Do not enter attendee names, contact details or other identities in a brief or its free-text fields.
3. Legal basis for processing (Article 6 GDPR)
- Contractual necessity (Art 6(1)(b)): processing is necessary to provide the platform, manage an operator's account, and fulfil an order, reservation or feedback submission you make through a restaurant's website, including forwarding it to that restaurant's staff.
- Legitimate interests (Art 6(1)(f)): we track operator account activity for platform security, fraud prevention and service reliability. Our legitimate interests assessment confirms the privacy impact is low and limited to essential system timestamps.
- Legal obligation (Art 6(1)(c)): retaining financial and transaction records for tax compliance.
- Consent (Art 6(1)(a)): for optional marketing communications.
- Planner briefs: the lawful basis for the planner organisation's event-brief processing, and the Article 9 condition for any dietary or allergy information, require confirmation by Zvelto's qualified solicitor before production use. The intake permission confirmation is an operational attestation only. Venue sharing is a future, conditional design and is disabled with the intake gate.
4. Data recipients and international transfers
4.1 Sub-processors
We share data with trusted third-party sub-processors to provide our core infrastructure. This currently includes:
- Database and application hosting: Neon (database), Railway (backend hosting), Vercel (website hosting).
- Payments: Stripe.
- AI analysis: OpenAI.
- AI assistant and document reading: OpenAI. When a restaurant operator uploads a business document to the AI assistant, the contents of that document are sent to OpenAI to be read and turned into notes, and those notes are sent again each time the assistant answers a question. This covers a wider range of information than the review text and business figures above, because it is whatever the operator chooses to upload. Diner orders, reservations and payment details are not sent.
- Communications: Resend.
- Order and reservation alerts: Telegram, via a bot configured by each restaurant for its own staff channel.
- Delivery address lookup: Google (Maps Platform). When you place a delivery order, the delivery address you enter is sent to Google to convert it into a location and measure the driving distance from the restaurant, so the restaurant can tell you whether it delivers to you and what the fee is. Your name, phone number and order contents are not sent.
- Planner event briefs: in the staging design, planner identity, email, organisation and event-brief fields are processed by the planner account and application stack. When the invitation provisioning gate is enabled, the configured Resend integration sends an email containing an opaque invitation token; a planner JWT is stored in the browser's dedicated local storage key. Venue sharing is future and conditional, and production collection is disabled pending legal review.
4.2 Changes to sub-processors
We may update our list of sub-processors from time to time to improve our service. We will ensure that any new providers offer equivalent or superior data protection standards and comply with relevant UK and EU GDPR requirements.
4.3 International transfers and team access
As Zvelto is a distributed team, your personal data may be accessed and processed by our staff and independent consultants operating in the European Economic Area (EEA), specifically Greece. Under the UK GDPR, these transfers are permitted because Greece is covered by the UK Government's adequacy regulations, ensuring a level of protection equivalent to that of the UK.
For transfers to our US-based processors (for example OpenAI, Stripe and Google), we rely on Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA) to ensure an equivalent level of protection.
5. Retention periods
- Operator account data: retained for the duration of the contract plus 6 years, to comply with UK statutory limitation periods for legal claims.
- Order, reservation and feedback records: retained for up to 2 years to support customer service, dispute resolution and the restaurant's own bookkeeping, after which they are deleted or anonymised.
- Session logs: automatically deleted 12 months after creation.
- Presence heartbeat: this value is overwritten continuously and holds no historical value.
- Financial records: retained for 7 years for HMRC and tax compliance.
- AI assistant notes and conversations: the file an operator uploads is never stored, only the notes taken from it. Those notes stay until the operator deletes them, which removes them outright with no copy kept anywhere, and the conversation history stays until the operator clears it. Both are deleted with the account.
- Planner event briefs: migration 0056's design clocks are two years from <code>submitted_at</code> for non-converted briefs, and three years from the event's latest date for dietary and allergy rows, which are hard-deleted leaving only the boolean marker. The migration defines no seven-year planner-account clock. No automated retention sweeper is operational, so these are not deletion promises; append-only transition actor email and reason fields require a future migration for complete identity or free-text erasure. Valid erasure requests are handled sooner.
6. Your rights and automated processing
You have the right to access, rectify, or erase your data, and to object to activity tracking (session/heartbeat), by emailing <mail>privacy@zvelto.ai</mail>.
Automated decision-making: an operator's presence status (online/away) is a simple threshold calculation and does not constitute profiling. Our AI insights currently require human approval before any menu or pricing change is applied; there is no automated decision made about you without a human in the loop.
Complaints: you have the right to lodge a complaint with the ICO (UK) or your local EU supervisory authority.