Privacy Policy
1. Who We Are
AIA Technology ("AIA Cater," "we," "us," "our") provides AI-powered catering-management software and related services (the "Services").
Privacy questions: privacy@askaia.ai
2. Information We Collect
| Category | Examples | Source |
|---|---|---|
| Account Data | Restaurant name, owner/manager name, business address, email, phone, login credentials | You |
| Customer & Order Data | Guest names, phone numbers, dietary notes, menu items, order totals, delivery addresses, timestamps | You or your guests (phone, text, email, WhatsApp, web chat) |
| Payment Tokens | Non-identifiable card tokens, payment IDs, refund IDs | Stripe, Square |
| Usage & Device Data | IP address, browser type, cookies, device IDs, pages viewed, error logs, feature-interaction stats | Collected automatically |
| Support Content | Chats, emails, or recordings with our support team | You |
No raw payment-card data (PAN, CVV) is stored on our servers.
3. How We Use Information
| Purpose | Legal Basis* |
|---|---|
| Provide, secure, and troubleshoot the Services | Contract performance; legitimate interest |
| Facilitate payments, refunds, and chargebacks | Contract performance; legal obligation |
| Display dashboards, analytics, and reports | Contract performance |
| Train and improve AI models (on de-identified or aggregate data only) | Legitimate interest |
| Send account or product updates and marketing emails | Consent (for marketing); legitimate interest (for transactional notices) |
| Comply with law, enforce Terms, prevent fraud | Legal obligation; legitimate interest |
*Under GDPR/UK GDPR. Comparable bases apply under CCPA and other regimes.
4. Sharing & Disclosure
- Payment Processors (Stripe, Square) — to tokenize cards and settle transactions.
- Telecom/Messaging Providers (Twilio, WhatsApp) — to route calls, SMS, and chat messages.
- Analytics & Error-Monitoring Tools — to operate and improve the platform (data pseudonymised where possible).
- Authorized Service Providers — hosting (SOC 2-compliant), email delivery, penetration-test vendors—bound by confidentiality agreements.
- Legal or Safety Reasons — if required by law, subpoena, or to protect rights, property, or safety.
We never sell or rent personal data.
5. Cookies & Tracking
We use first-party cookies and similar technologies to:
- keep you signed in,
- remember preferences,
- measure feature adoption.
6. Data Retention
- Account & Order Data: kept for the life of your account plus 90 days (for bookkeeping and dispute resolution) unless you trigger permanent deletion.
- Payment Tokens: retained per Stripe/Square schedules.
- Analytics Logs: 12 months, then aggregated or deleted.
7. Your Rights
| Right | How to Exercise |
|---|---|
| Access / Portability | Request a copy of data stored about you. |
| Correction | Update inaccurate or incomplete information in the dashboard or via support. |
| Deletion (“Right to be Forgotten”) | Use Settings → Privacy → Delete Workspace or contact us; permanent erasure occurs after a 14-day grace period. |
| Restrict / Object | Object to certain processing (e.g., direct marketing). |
| Withdraw Consent | Opt out of marketing via the unsubscribe link or email privacy@askaia.ai. |
We respond within 30 days (or as required by law).
8. Security Measures
- TLS 1.3 encryption in transit, AES-256 encryption at rest.
- Tenant-level isolation (“pocket universes”)—separate databases and keys per restaurant.
- Three-Step Verification (password + SMS code + Master Key) for critical actions.
- SOC 2-compliant cloud infrastructure, continuous vulnerability scanning, quarterly third-party penetration tests.
- While no system is 100% secure, we follow industry best practices to protect your data.
9. International Transfers
Data may be stored or processed in the United States or other countries where we or our subprocessors operate. We rely on Standard Contractual Clauses or equivalent safeguards for cross-border transfers.
10. Children’s Privacy
Our Services are not directed to children under 16. If we learn we have collected data from a child without parental consent, we will delete it promptly.
11. Changes to This Policy
We may update this Policy from time to time. We will post any revisions here and notify account holders via email or in-app banner. Continued use after the effective date constitutes acceptance.
12. Contact Us
For privacy questions, data requests, or complaints:
Email: privacy@askaia.ai
If you are in the EU/UK and feel we have not addressed your concern, you have the right to lodge a complaint with your local supervisory authority.