---
title: Privacy policy
description: How Holly AI collects, uses and protects personal data on this website and when Holly answers guests for restaurants.
canonical_url: https://www.askholly.ai/privacy/
last_updated: 2026-10-08
---

# Privacy policy

How Holly AI collects, uses and protects personal data, on this website and when Holly answers guests for restaurants.

Last updated 8 October 2026

## 1. Introduction

Holly AI is committed to protecting the privacy of our website visitors, customers and the people who use our services. This policy applies where we act as a data controller, which means we decide why and how personal data is processed.

In this policy, “we”, “us” and “our” refer to Holly AI, a subsidiary of EB Tech Limited, registered in Ireland under company number 676370, with its registered office at Ardeen House, 10/11 Marine Terrace, Dun Laoghaire, County Dublin, Ireland. “GDPR” means the General Data Protection Regulation and, for the UK, the UK GDPR and the Data Protection Act 2018.

Our Data Protection Officer is John King, who you can contact at [support@boxly.ai](mailto:support@boxly.ai).

## 2. When we act for restaurants

When Holly answers a guest on behalf of a restaurant, the restaurant is the controller of that guest’s data and we process it only on the restaurant’s instructions, under our [Data processing terms](https://www.askholly.ai/data-processing/). If you contacted a restaurant that uses Holly, that restaurant’s own privacy notice explains how it uses your data, and you can exercise your rights through the restaurant or by contacting us.

## 3. What we collect

We collect personal data that you give us, for the purpose stated at the time. This includes:

- **Demo bookings.** When you book a demo, Calendly collects your name, email address and any answers you give, and shares them with us so we can hold the call.
- **Customer accounts.** Names, work email addresses, phone numbers, usernames and passwords of the people at restaurants who use the Application.
- **Account administration.** Information our team collects to manage customer accounts, such as company billing addresses, bank details for direct debits and confidential company information.
- **Communications.** Emails and messages you send us, and our replies.
- **Technical data.** Our hosting provider processes standard request information, such as IP addresses and browser type, to deliver and secure this website.

Our systems do not collect or store credit or debit card details. Card payments are processed by third-party payment providers under their own security terms.

We do not use analytics, advertising or tracking cookies on this website. See our [Cookie policy](https://www.askholly.ai/cookies/).

## 4. How we use it

We use personal data only for the purpose it was given for. For example, details you give to book a demo are used to arrange and hold that demo. We do not sell personal data or use it outside the purpose it was collected for.

| Purpose | Lawful basis |
| --- | --- |
| Arranging and holding demos, and responding to enquiries | Legitimate interests in responding to businesses that contact us |
| Providing the Holly service and supporting customers | Performance of our contract with the customer |
| Billing and keeping financial records | Contract, and legal obligation |
| Keeping this website and the service secure | Legitimate interests in protecting our systems and users |

If you agree to receive marketing emails from us, every email includes a way to unsubscribe, which takes effect straight away.

## 5. Who we share it with

We share personal data only with service providers who process it for us under strict confidentiality terms, and only where needed to run our infrastructure, provide and improve our services, or maintain our systems. These include:

- our hosting provider, Vercel, for this website;
- Calendly, for demo bookings;
- Amazon Web Services (AWS), which hosts the Holly service in the EU;
- OpenAI, whose AI models generate Holly’s responses, hosted in the EU;
- Meta, where a restaurant uses Holly on WhatsApp; and
- OpenTable, where a restaurant connects Holly to OpenTable.

Requests from third parties or legal authorities for information about an individual are only met where we are legally required to, for example by a court order.

## 6. Where data is stored

Personal data is stored within the EU. Central administration of our systems takes place in Ireland and the UK, but data can be accessed from other places, for example when our administrators are travelling or when a provider’s support team in the USA helps maintain the service. Where data is accessed or processed outside the UK or European Economic Area, we rely on an adequacy decision or on standard contractual clauses approved for that purpose.

## 7. Security

All traffic in and out of our systems is encrypted. Every service runs over HTTPS, including web traffic, email and access to our back-end servers, and our systems do not respond to unsecured traffic. Direct access to our infrastructure is strictly limited, and data is stored in line with our data security and information governance protocols, further details of which are available on request.

## 8. Personal data breaches

Our systems include software that actively detects data breaches. If a personal data breach occurs, we will notify the relevant supervisory authority as the GDPR requires. Where a breach is likely to result in a high risk to people’s rights and freedoms, we will also tell the people affected directly.

If we believe further attacks are possible or ongoing, we may shut down systems, services and websites as far as needed to contain the threat, and we may work with third-party security experts, who may need access to our infrastructure.

## 9. How long we keep it

We keep personal data until it is no longer needed for the purpose it was collected for, or until the individual or customer asks us to remove it, unless the law requires us to keep it for longer, for example financial records. Guest data processed for restaurants is kept and deleted in line with the restaurant’s instructions and our [Data processing terms](https://www.askholly.ai/data-processing/).

## 10. Your rights

We will respond to every request to exercise your rights under the GDPR. These are:

- the right to be informed;
- the right of access;
- the right to rectification;
- the right to erasure;
- the right to restrict processing;
- the right to data portability;
- the right to object; and
- rights relating to automated decision-making, including profiling.

Contact our Data Protection Officer at [support@boxly.ai](mailto:support@boxly.ai). We will respond within one month, free of charge, although we may charge a reasonable fee where a request is manifestly unfounded or excessive, particularly if it is repetitive.

## 11. Complaints

You can complain to the Data Protection Commission in Ireland ([dataprotection.ie](https://www.dataprotection.ie)) or, in the UK, the Information Commissioner’s Office ([ico.org.uk](https://ico.org.uk)). We would appreciate the chance to resolve your concern first.

## 12. Changes to this policy

We will update this page when our practices change and show the date of the latest version at the top.
