Legal
Terms of service
Last updated: 2026-09-16
These Terms govern the contracting and use of taula.ai (the "Service") by companies and professionals (the "Customer"). By creating an account, the Customer accepts them in full. The Service is aimed exclusively at professionals and businesses; it is not intended for consumers.
This is version 2026-09-16 of the Terms. It applies to accounts created from that date; for earlier accounts it applies thirty (30) days after notice is given, as set out in section 10, and they accept it in the dashboard. When the account is created —or, where the Provider created the account, on first access to the dashboard— the Provider records which version the Customer accepted and when, and will provide it on request. Previous versions (the latest dated 17 August 2026) are kept and can be requested at hola@taula.ai.
1. Provider and purpose
The Service is provided by Joan Sanfeliu Vilarrasa, tax ID 79279716G, based in Barcelona (Spain), email hola@taula.ai (the "Provider").
The Service is a cloud platform for managing bookings and serving the customers of hospitality businesses, available at app.taula.ai, comprising the booking engine and its public page, the QR digital menu, a website for the business published on a taula.ai subdomain —or, on the Pro plan, on the Customer's own domain— and the AI features described in the Privacy Policy. The WhatsApp messaging agent presented on the website as a future service is not part of any plan until the Provider announces its availability.
2. Sign-up, trial, plans and price
Contracting takes place by signing up at app.taula.ai. The Provider may offer a free trial period, whose length is shown in the account itself; during it no payment method is required and the Customer may stop using the Service at any time at no cost.
After the trial, the Service is provided by subscription on one of these plans:
- Basic: €9.99 + VAT (€12.09) a month, or €99 + VAT (€119.79) a year. Includes the website on a taula.ai subdomain, the QR menu, the full dashboard and up to sixty (60) online bookings a month (section 2 bis).
- Pro: €24.99 + VAT (€30.24) a month, or €249 + VAT (€301.29) a year. Everything in Basic, unlimited online bookings, your own domain (the domain itself is billed separately, at cost) and deposits for large parties.
- Custom: from €69 + VAT (€83.49) a month, at a price agreed in writing for each account. Includes everything in Pro and a website of your own, designed and built to order; the scope, price and terms of that commission are set out in a separate quote.
All prices exclude VAT; VAT is added on the invoice at the applicable rate (currently 21 %). The fee is billed in advance and the subscription renews automatically for periods of the same length, monthly or yearly. There are no setup fees, no per-booking or per-guest commissions and no minimum term. The plan and billing period contracted are shown in the Customer's account.
The Provider may change the price on at least thirty (30) days' notice sent to the account's email address. The new price applies from the first renewal after the notice period; if the Customer does not accept it, they may cancel the subscription before it takes effect, with no penalty. Prices agreed in writing for the Custom plan change only by mutual agreement.
2 bis. Online booking limit on the Basic plan
The Basic plan includes up to sixty (60) online bookings per calendar month. Only bookings made by guests themselves through the restaurant's website, the public booking page or the link published on the Google listing count. Bookings the Customer or its staff add by hand from the dashboard never count, nor do cancelled, rejected or no-show bookings.
The limit never blocks the guest: the booking page keeps accepting bookings even after the month has passed sixty. If the limit is exceeded in a given month, the Provider informs the Customer and, from the following month, the account moves to the Pro plan at that plan's price, always with prior notice by email. The Customer may move back to Basic if the current month is within the limit; the change applies at the end of the period already invoiced.
Until the automatic plan change is in operation, the limit is not applied: the Provider charges nothing for bookings beyond sixty and does not change the Customer's plan without their agreement. When it is switched on, the Provider will give the notice set out in section 10.
3. Payment and non-payment
Payment is made through Stripe, by card or by SEPA Direct Debit. When choosing direct debit, the Customer signs a SEPA Direct Debit mandate in favour of the Provider, managed by Stripe, and authorises each fee to be charged to the bank account given; the Customer is notified of each charge with the notice the SEPA scheme requires. The Customer undertakes to keep a valid payment method on file and to provide accurate, up-to-date billing details.
In the event of non-payment —including a returned direct debit—, the Provider will notify the Customer and may suspend the Service seven (7) calendar days after the first failed charge. Suspension means the public booking page stops accepting requests and the business website stops being published; the Customer's data is retained as set out in section 8.
4. Term and cancellation
The subscription runs indefinitely and renews automatically for periods equal to the one contracted: month by month or year by year. The Customer may cancel at any time from the dashboard or by written notice; cancellation takes effect at the end of the period already invoiced, with no refund of the unused portion, unless applicable law provides otherwise.
On yearly billing, the year's fee is earned in full in advance and no part of it is refunded if the Customer cancels before the year ends: the Service continues until the end of the period paid for. Plan or billing-period changes are requested from the dashboard or in writing; upgrades apply when the Customer confirms them and downgrades at the end of the period already invoiced.
The Provider may terminate on thirty (30) days' notice should it decide to discontinue the Service; and immediately in the event of material breach by the Customer, in particular use of the Service for unlawful purposes or repeated non-payment.
5. Customer obligations
- Use the Service lawfully and in accordance with these Terms, and not for unlawful purposes.
- Safeguard its credentials and be answerable for activity carried out from its account.
- Ensure it has a valid legal basis and provides adequate information for processing the personal data of its own customers entered or managed on the platform, in particular allergies and intolerances, which may constitute health data.
- Ensure it holds the rights to the content it supplies (text, photographs, logos, menu).
- Review and approve the website before it is published, and keep its information up to date (hours, prices, allergens, contact details), as set out in section 9.
- Not attempt to access other customers' data or do anything that compromises the security or availability of the Service.
6. Service availability
The Provider will use reasonable means to keep the Service continuously available but does not guarantee any particular level of availability nor the absence of errors or interruptions. The Service may be interrupted for maintenance, by incidents affecting its infrastructure providers, or by force majeure.
The Service is provided "as is", without express or implied warranties of merchantability, fitness for a particular purpose or commercial outcome. The Customer is responsible for maintaining reasonable fallback procedures for its business.
7. Liability
The Provider shall be liable only for direct damage actually caused by wilful misconduct or gross negligence in providing the Service. Indirect damages, loss of profit, loss of custom, lost bookings or revenue and reputational harm are expressly excluded.
In any event, and save for wilful misconduct, the Provider's total aggregate liability to the Customer on any ground is limited to the amount actually invoiced to the Customer in the three (3) months preceding the event giving rise to the claim.
The Customer shall hold the Provider harmless against third-party claims arising from its use of the Service, from the content it supplies, or from breach of its data protection obligations towards its own customers.
8. Customer data and return
The data the Customer enters into the platform —bookings, guest records, menu and configuration— belongs to the Customer. During the term it may export it or request a copy at any time.
On termination, the Provider will retain that data for thirty (30) calendar days to allow recovery and, after that period, will delete it, except for data it must keep by law (in particular, invoicing records).
9. Intellectual property and the Customer's website
The Service, its software, its design and its trade marks belong to the Provider. The subscription grants the Customer a non-exclusive, non-transferable right of use limited to the term of the contract.
The website is a rental. The website the Provider builds, publishes and maintains for the Customer within the Basic and Pro plans is provided on a rental basis(a licence to use), and not as a sale, a commissioned work or the delivery of a product. The Provider is its sole owner, and holds all intellectual property rights in the template, the source code, the design (structure, style and layout), the texts generated by the Provider —with or without the help of artificial intelligence— and the taula.ai subdomain on which it is published. None of these elements is ever transferred to the Customer, neither during the subscription nor when it ends.
Licence to use. While the subscription is active, the Customer holds a non-exclusive, non-transferable, non-sublicensable and revocable licence to use the website, tied to the subscription, for its business without any restriction on use and paying nothing for hosting, certificate or content changes, all of which the Provider bears in full. The licence ends automatically when the subscription ends, for any reason. The Provider may revoke it and unpublish the website, notifying the Customer at the account email address, if the site is used for purposes contrary to the law or to these Terms, or if content that infringes third-party rights is published on it and the Customer does not remove it when asked.
Subdomain. The Customer's website is published on a taula.ai subdomain bearing the business name (for example, yourname.taula.ai). The subdomain belongs to the Provider and is licensed for use for as long as the subscription lasts: the Customer acquires no rights over the taula.ai domain or the subdomain, and may not assign or transfer it. Where two businesses ask for the same name, the Provider assigns it in order of sign-up, and may require a different one where it matches a third party's trade mark or is misleading.
The Customer's content. The content the Customer supplies —its own texts, photographs, menu, logo and brand— is and remains the Customer's. The Customer only grants the Provider a free, non-exclusive licence, limited to the term of the subscription, to reproduce that content, adapt it to the site's format and display it on the website and on the booking page. The business information (hours, prices, dishes, contact details) belongs to the Customer; the texts the Provider writes from that information belong to the Provider.
AI-assisted generation. The Provider builds the site from the public information on the business's Google listing, the menu and the photographs the Customer supplies, using artificial intelligence models to draft the texts and arrange the menu. The Provider reviews the result before showing it and the Customer reviews and approves it before it is published; afterwards the Customer can correct any content from the dashboard. Generated texts may contain inaccuracies: the Customer is the one who knows their business and who answers for what is published.
Responsibility for content. The Customer warrants that it holds the rights to the photographs, texts, logo and menu published, and that the information (hours, prices, allergens, contact details) is accurate. Photographs taken from Google, social networks or other websites may not be published without the rights holder's permission; the Provider may remove them on receiving a complaint. To publish the site, the Customer provides the business owner's details (name or company name, tax ID and address) that the law requires for the site's legal notice and privacy policy; until they are provided, the site may be kept unpublished or unindexed.
End of the subscription. When the subscription ends, for any reason (cancellation, non-payment or termination), the Provider unpublishes the website. The Customer has no right to any compensation, to a transfer of the site, to delivery of the source code, the template, the design, the generated texts, the site files or any other material, or to go on using the subdomain: nothing is transferred. The Provider will supply a copy of the content the Customer supplied if requested within the period in section 8.
Editing policy. The Customer freely changes the site's content from the dashboard, at no cost: hours and holidays, phone number, menu and prices, photographs and notices. The design (template, structure and style) is fixed and is not customised within the Basic and Pro plans. If the Customer wants a different design, the Provider can regenerate the site at a fixed price quoted in writing, or the Customer can move to the Custom plan.
Custom plan. The Custom plan website is produced under a separate written quote and is governed by its terms, including as to ownership of what is delivered; this section applies to it only where the quote is silent.
Your own domain. On the Pro plan, the Customer may publish the site on its own domain name. The domain is registered in the Customer's name and its registration and renewal cost is billed separately, at cost; the Provider manages its technical configuration. A domain registered in the Customer's name belongs to the Customer: when the subscription ends the Customer keeps it and may point it wherever they wish. Where the Provider registered the domain name on the Customer's behalf, the Customer may request its transfer into their own name at any time, including when the subscription ends, bearing only the applicable transfer and renewal costs. If no such request is made within thirty (30) days of the end of the contract, the Provider may let the domain lapse or cancel it.
10. Changes
The Provider may amend these Terms on at least thirty (30) days' notice. If the Customer does not accept them, it may cancel the subscription before they take effect. Continued use of the Service after that date constitutes acceptance.
11. Governing law and jurisdiction
These Terms are governed by Spanish law. For any dispute, the parties submit to the Courts of Barcelona, expressly waiving any other jurisdiction that might apply.
Annex I. Processing of personal data (Art. 28 GDPR)
This Annex forms an inseparable part of the Terms and governs the processing of personal data carried out by the Provider on behalf of the Customer.
Roles. The Customer is the controller of the personal data of its own end customers (guests). The Provider acts as processor.
Subject matter, duration and nature. The processing consists of hosting and managing bookings, guest records and associated communications, through collection, recording, storage, consultation, modification, disclosure to the Customer itself and erasure. Its duration matches the term of the contract, plus the retention period in section 8.
Types of data and categories of data subjects. Identification and contact data (name, phone, email, language), booking data (date, time, party size, table, visit history and no-shows), internal staff notes and, where the Customer chooses to collect them, food allergies and intolerances, which may constitute health data (Art. 9 GDPR). The data subjects are the Customer's end customers.
Provider's obligations as processor. The Provider undertakes to:
- Process the data only on documented instructions from the Customer, including those arising from normal use of the platform, and not use it for its own purposes.
- Ensure persons authorised to process the data commit to confidentiality.
- Apply the technical and organisational measures of Art. 32 GDPR: encryption in transit and at rest, per-account access control and logical separation of each customer's data, authentication managed by a specialist provider, and activity logging.
- Assist the Customer in responding to data subject rights and in complying with Arts. 32 to 36 GDPR, insofar as the information is available to it.
- Notify the Customer without undue delay, and in any case within 48 hours of becoming aware, of any personal data breach affecting it, with the information available.
- At the Customer's choice, delete or return the data on termination, as set out in section 8, save where retention is legally required.
- Make available to the Customer the information necessary to demonstrate compliance with these obligations and allow reasonable audits, on request with sufficient notice.
Retention periods. While the contract is in force, bookings and customer cards are kept on the Customer's behalf for a maximum of twenty-four (24) months from the last visit, and are automatically deleted once that period has passed. On termination, the Provider keeps them for thirty (30) days so that the Customer can recover them and then deletes them, except for what it must keep by law.
Sub-processors. The Customer gives general authorisation for the sub-processors listed in the Privacy Policy (in particular Amazon Web Services, Stripe —card and SEPA Direct Debit— and, where the corresponding features are enabled, Meta and Google). The Provider will give at least thirty (30) days' notice of any addition or replacement, during which the Customer may object on reasoned grounds and, in that case, terminate without penalty. The Provider will impose on sub-processors obligations equivalent to those undertaken here. The Provider will not engage any other processor without this general authorisation and the notice indicated, and will remain answerable to the Customer for their performance.
Location and transfers. Processing takes place on servers located in the European Union: booking and account data, and outgoing email, are processed and stored in the eu-west-3 region (Paris); inbound email to the domain and static hosting of the web pages are processed in the eu-west-1 region (Ireland); and processing with artificial intelligence models (Amazon Bedrock) may run in any AWS region within the European Union, depending on available capacity. No data leaves the European Union, except for the Google Analytics case described in the Cookies Policy. Where a sub-processor involves an international transfer, it relies on an adequacy decision or on Standard Contractual Clauses.
Artificial intelligence. The model processing described in the Privacy Policy takes place within the European Union and, under the provider's terms, the data is not used to train models.
Customer instructions. If the Provider considers that an instruction from the Customer infringes data protection law, it will inform the Customer immediately.