---
title: Data processing terms
description: How Holly AI processes guest personal data on behalf of restaurants that use Holly, in line with the GDPR and UK GDPR.
canonical_url: https://www.askholly.ai/data-processing/
last_updated: 2026-10-08
---

# Data processing terms

How Holly AI processes personal data on behalf of restaurants that use Holly. These terms form part of our [Terms of business](https://www.askholly.ai/terms/).

Last updated 8 October 2026

## 1. Roles

The customer is the controller and Holly AI is the processor of personal data processed through Holly on the customer’s behalf. These terms apply in addition to clause 9 of our [Terms of business](https://www.askholly.ai/terms/) and meet the requirements of Article 28 of the GDPR and UK GDPR.

## 2. Scope of processing

- **Subject matter and duration:** Providing the Services for the term of the Contract and any agreed export period afterwards.
- **Nature and purpose:** Receiving, answering, sorting and routing guest enquiries across the customer’s Channels; making and amending bookings in connected booking systems; storing conversations and enquiry records; and reporting.
- **Data subjects:** Guests and prospective guests who contact the customer, and the customer’s Users.
- **Personal data:** Names, email addresses, phone numbers, message content, booking details (dates, times, party size, occasion), dietary and allergy information that guests choose to share, and User account details.
- **Special category data:** Guests may volunteer health information, such as allergies or accessibility needs, to arrange their visit. It is processed only to answer and record that request.

## 3. Instructions

We process personal data only on the customer’s documented instructions, which are given by the Contract and the customer’s configuration and use of the Services, unless the law requires otherwise. We will tell the customer if we believe an instruction breaks data protection law.

## 4. Confidentiality

Everyone we authorise to process personal data is bound by a duty of confidentiality.

## 5. Security

We implement appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, role-based access controls, logging, secure development practices and regular back-ups, in line with our data security and information governance protocols, further details of which are available on request. All traffic in and out of our systems is encrypted over HTTPS.

## 6. Sub-processors

The customer authorises us to use the sub-processors below. We will give at least 30 days’ notice of any new sub-processor, during which the customer may object on reasonable data protection grounds. We impose data protection terms on each sub-processor that are no less protective than these.

| Sub-processor | Purpose | Location |
| --- | --- | --- |
| Amazon Web Services (AWS) | Hosting the Application and data | EU |
| OpenAI | AI models that generate Holly’s responses | EU |
| Meta Platforms Ireland | WhatsApp Business messaging, where used | EU |
| OpenTable | Bookings, where connected | Under the customer’s own OpenTable account |

## 7. International transfers

Personal data is stored within the EU. Central administration takes place in Ireland and the UK. We will not transfer it outside the UK or European Economic Area unless an adequacy decision applies or appropriate safeguards, such as standard contractual clauses, are in place.

## 8. Assistance

Taking into account the nature of the processing, we will help the customer respond to requests from data subjects exercising their rights, and with security, breach notification, data protection impact assessments and prior consultation with supervisory authorities.

## 9. Personal data breaches

We will notify the customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting the customer’s data, with the information the customer needs to meet its own obligations.

## 10. Return and deletion

When the Contract ends, we will make the customer’s data available for export as set out in our [Terms of business](https://www.askholly.ai/terms/), and then delete it, unless the law requires us to keep it. Deletion from back-ups follows our back-up cycle.

## 11. Audits

We will make available the information reasonably needed to demonstrate compliance with these terms, and allow for and contribute to audits by the customer or an auditor it appoints, on reasonable notice and no more than once a year unless required by a supervisory authority.

## 12. Contact

For data processing questions, or to request a signed copy of these terms, contact our Data Protection Officer, John King, at [support@boxly.ai](mailto:support@boxly.ai).
