Legal
Privacy policy
Last updated: 2026-09-16
This Privacy Policy governs the processing of the personal data provided by users through the website taula.ai (hereinafter, the "Website") and the taula.ai platform, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council, of 27 April 2016 (GDPR), Spanish Organic Law 3/2018, of 5 December, on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD) and other applicable regulations.
1. Data controller
- Identity: Joan Sanfeliu Vilarrasa
- Tax ID (NIF): 79279716G
- Address: Barcelona, Spain
- Email: hola@taula.ai
Hereinafter, "the Controller". Given the nature and volume of the processing carried out, the appointment of a Data Protection Officer is not required. Nevertheless, the Controller will personally handle any query sent to the indicated email address.
2. Personal data processed
The Controller processes only the personal data strictly necessary for the purposes described in this policy. Specifically:
- Contact form and communications: name, email address, type of business (optional) and the content of the message that the user chooses to provide voluntarily when getting in touch.
- Registration and use of the platform: account and identification data (name, email, access credentials managed securely) necessary to create and administer the user account in the management dashboard (app.taula.ai) and to provide the contracted services.
- Billing and payment data: identification, tax and billing data necessary to contract the subscription service. Payment data —card details or, where the customer chooses direct debit, the bank account number (IBAN) and the SEPA mandate— is handled directly by the payment provider Stripe; the Controller stores neither full card details nor the IBAN in its systems.
The Website may use Google Analytics 4 for statistical purposes only, and only if the visitor accepts it in the cookie notice: until then no analytics cookie is installed. No tracking cookies are used for advertising purposes and no profiling is carried out. For more information, see the Cookies Policy.
2 bis. Data processed on behalf of the restaurant (processor role)
This is the most important part of this policy and it is worth reading slowly, because here taula.ai does not act as controller.
When a restaurant uses the platform, personal data about its guests is recorded there: name, phone number, email address, language, party size, date and time of the booking, table assigned, visit history, no-shows, internal notes written by the restaurant's staff and, where applicable, food allergies and intolerances. Also the messages exchanged through the messaging agent, where that feature is enabled.
For this data the controller is the restaurant, which decides what is collected and why. taula.ai acts solely as a processor (Art. 28 GDPR), processing it only on the restaurant's instructions and in order to provide the contracted service. The terms of that arrangement are set out in the Data Processing Annex, which forms part of the contract with every customer.
Allergies and intolerances may constitute health data (Art. 9 GDPR). taula.ai provides the field as a service tool, but it is for the restaurant to have a valid legal basis for collecting it —normally the guest's explicit consent—, to inform the guest and not to record more than is necessary.
Retention periods on behalf of the restaurant. Bookings and customer cards are kept for up to 24 months from the diner's last visit and are automatically deleted every night once that period has passed. If a restaurant stops using the service, all its bookings and customer cards are deleted 30 days later, once the recovery period has elapsed. Messaging-agent conversations are deleted automatically when their technical lifetime ends. The restaurant may request early deletion of a specific card at any time.
If you are a guest and wish to exercise your rights over this data, please contact the restaurant where you booked, as it is the one that decides on it. If you write to us, we will pass your request on to the restaurant and let you know.
2 ter. Artificial intelligence features
The platform uses AI models at three specific points:
- Reading and translating the menu: when the restaurant uploads a PDF or a photograph of its menu, it is processed by a model to extract dishes and prices, and to produce the versions in the languages the restaurant itself chooses.
- Generating the restaurant's website: the website's texts are drafted by a model from the public information on the business's Google listing, its menu and the photographs it supplies; the Controller reviews the result and the restaurant approves it before publication (section 2 quater).
- Messaging agent: where this feature is enabled, incoming messages are processed in order to answer against the business's real agenda.
This processing takes place through Amazon Bedrock, within AWS infrastructure in the European Union. Under the terms of that service, the data sent is not used to train models and is not shared with the model providers for that purpose.
No decisions are taken based solely on automated processing that produce legal effects on individuals or similarly significantly affect them (Art. 22 GDPR), and no profiling is carried out. The platform does apply automatic rules that each restaurant configures: if a table is free according to the capacity and opening hours the restaurant has defined, the booking is confirmed immediately; if the restaurant has enabled manual confirmation, it remains pending until the restaurant validates it; and if it has enabled reconfirmation, a booking the guest does not reconfirm within the margin set by the restaurant is released automatically, which the guest is always warned about beforehand. These are availability calculations on parameters set by a person, not an assessment of the guest. In any case, the guest can book by phone and speak directly with the restaurant.
2 quater. Restaurant websites on taula.ai subdomains
Each customer restaurant may have a website published on a taula.ai subdomain bearing its business name (for example, yourname.taula.ai) or, on the Pro plan, on its own domain. The content of that site —texts, photographs, menu, opening hours and contact details— is decided and approved by the restaurant, which is responsible for it towards visitors (the site's template, code and design belong to taula.ai, on a rental basis, under section 9 of the Terms) and must identify itself there with its own legal notice and privacy policy, using the details it gives taula.ai at sign-up. taula.ai hosts and maintains it as a processor on the restaurant's behalf, under the terms of the Data Processing Annex.
Visitors to these sites provide no personal data unless they make a booking, in which case section 2 bis applies. To serve the page and protect it from abuse, the server temporarily processes the visitor's IP address, under the same conditions and legitimate interest as on the Website (section 4).
3. Purposes of processing
Personal data will be processed for the following purposes:
- To respond to queries, requests for information or other requests submitted by the user.
- To create and manage the user account and enable access to and use of the taula.ai platform.
- To provide the micro-services and tools contracted by subscription and to support the user.
- To publish and maintain the restaurant's website on its taula.ai subdomain or, on the Pro plan, on its own domain.
- To manage billing, subscription payments and compliance with applicable accounting, tax and administrative obligations.
- To send, where applicable, communications related to the requested or contracted services (operational notices, changes to the service, etc.).
Today the Controller does not send commercial communications. If in the future it sends them to its customers about its own services similar to those contracted, it will do so under article 21.2 of the Spanish LSSI and its legitimate interest (art. 6.1.f GDPR), and the customer will be able to object at sign-up, from their profile in the dashboard and through the unsubscribe link that every message will carry, simply and free of charge.
4. Legal basis for processing
The legal bases that legitimise the processing of the data are the following:
- Consent of the data subject (art. 6.1.a GDPR), given when submitting the contact form or initiating communication with the Controller.
- Performance of a contract to which the data subject is party, or the application of pre-contractual measures at their request (art. 6.1.b GDPR), in particular for the creation of the account and the provision of the subscription service.
- Compliance with legal obligations applicable to the Controller, in particular in tax, commercial and accounting matters (art. 6.1.c GDPR).
- Legitimate interest of the Controller in maintaining the customer relationship, responding to communications received, ensuring the security of the platform —including the temporary processing of the IP address of anyone making a booking or viewing a menu, for a maximum of one hour, to prevent bulk requests and abuse— and retaining the related documentation (art. 6.1.f GDPR).
5. Retention period
The data will be retained for as long as strictly necessary to fulfil the purposes for which it was collected and, in any case, for the periods legally required to address any liabilities arising from the processing.
Communications received that do not result in a contractual relationship will be retained for a maximum of the period necessary to handle the query and, once concluded, for the applicable legal period. Data linked to the account and to the provision of services will be retained for the duration of the contractual relationship and, subsequently, for the limitation periods of the resulting legal actions, as well as those required by tax, commercial and accounting regulations (generally, up to six years).
6. Recipients and disclosures
Personal data will not be disclosed to third parties, except by legal obligation or where strictly necessary for the provision of the requested service.
For the development of its activity, the Controller relies on the following service providers, which act as data processors, subject to the corresponding contractual obligations and to data protection regulations:
- Amazon Web Services (AWS): cloud infrastructure, database, identity management and email delivery. Processing takes place on servers located in the European Union: booking and account data, and outgoing email, are processed and stored in the eu-west-3 region (Paris); inbound email to the domain is processed in the eu-west-1 region (Ireland); restaurant websites (section 2 quater) are hosted in the eu-west-3 region (Paris) and distributed with Amazon CloudFront, AWS's content delivery network, which serves their public content from points of presence close to the visitor (in Europe, for European visitors); and processing with artificial intelligence models (Amazon Bedrock, section 2 ter) may run in any AWS region within the European Union, depending on available capacity. Booking and account data do not leave the European Union. The public content of restaurant websites may be served from CloudFront points of presence outside the Union, and the IP address of the visitor is processed by AWS as a processor under its Standard Contractual Clauses (REVISAR ADVOCAT); the other case is Google Analytics, described in the Cookies Policy. Where a sub-processor involves an international transfer, it relies on an adequacy decision or on Standard Contractual Clauses.
- Stripe Payments Europe, Ltd. (Ireland): payment processing and subscription billing, by card or by SEPA Direct Debit. Card data, the bank account number (IBAN) and the SEPA mandate are processed directly by Stripe; taula.ai does not store them in its systems. In addition to the subscription payment, where the restaurant enables booking deposits, Stripe processes the guest's payment data on behalf of the restaurant, which is the seller. taula.ai neither accesses the card details nor receives that money.
- Meta Platforms Ireland Ltd.: only where the restaurant enables the messaging agent or WhatsApp booking reminders, to send and receive WhatsApp messages with the guest.
- Google Ireland Ltd.: only where the restaurant enables booking from Google, to publish its availability and receive bookings made through Google. Also Google Analytics 4 for statistical purposes on the website, and only if the visitor accepts analytics cookies; Google may process this data outside the European Union under the EU-US Data Privacy Framework and, where applicable, the European Commission's standard contractual clauses. The details are in the Cookies Policy.
The Controller will ensure that these providers are located in the European Economic Area or, failing that, that they provide adequate safeguards for international transfers in accordance with articles 44 et seq. of the GDPR.
7. Rights of the data subject
The user may exercise the following rights at any time:
- Access to their personal data.
- Rectification of inaccurate or incomplete data.
- Erasure of the data when, among other reasons, it is no longer necessary.
- Objection to processing for reasons related to their particular situation.
- Restriction of processing in the cases provided for by law.
- Portability of the data to another controller, where processing is based on consent or on a contract.
- Withdrawal of consent given, without affecting the lawfulness of the prior processing.
- Not to be subject to automated individual decisions, including profiling, with legal effects.
To exercise these rights, the user may contact the Controller in writing by email at hola@taula.ai, clearly indicating the right they wish to exercise and attaching, where necessary, a copy of their identity document or other means of proving their identity.
If you have not received a reply within one month, or the reply does not satisfy you, you may lodge a complaint with the Spanish Data Protection Agency (C/ Jorge Juan, 6, 28001 Madrid, www.aepd.es).
8. Security measures
The Controller has adopted the technical and organisational measures necessary to guarantee the security of personal data and to prevent its alteration, loss, unauthorised processing or access, taking into account the state of the art, the nature of the data and the risks to which it is exposed.
Notwithstanding the above, the user acknowledges that security measures on the internet are not impregnable and that sending information over the network entails certain risks assumed by the user.
9. Accuracy of the data
The user guarantees that the personal data provided is truthful, accurate, complete and up to date, and undertakes to notify any changes. The user will be solely responsible for any direct or indirect damage that may be caused to the Controller or to third parties as a result of providing inaccurate, incomplete or outdated data.
10. Modifications
The Controller reserves the right to modify this Privacy Policy in order to adapt it to legislative or case-law developments or to changes in its activity. Modifications shall take effect from their publication on the Website.