Trust & data
The first question you should ask any AI vendor
Most operators tell us their biggest worry about AI isn't whether it works — it's where the data goes. Fair. Here is where it goes.
Your venue is physically isolated. Every customer gets their own dedicated memory stores. Not a shared database with a filter — separate infrastructure per customer. Your bookings, your customers, your numbers are never pooled with another venue's, never used to train anything, and never seen by another customer's Alf.
Your data is yours, in writing. Every customer gets a signed data processing agreement (Article 28, UK GDPR), a retention schedule, and a current sub-processor list — before go-live, not on request.
Your DPIA, done with you. UK GDPR puts a duty on the venue deploying systems like Alf to assess the impact first. Most vendors leave you to figure that out. We hand you a pre-filled data protection impact assessment for your venue as part of onboarding — describing exactly what data flows where, ready for your records and your review.
Callers are told. Calls Alf handles are answered by an automated speech system, disclosed, with human backup you control. Every call and every action is logged and available to you.
When you leave, it leaves. Your records are exported back to you. Alf's learned memory of your business is destroyed — never transferred to a new owner, never folded into anyone else's system.
| Document | When you get it |
|---|---|
| Data processing agreement (Art. 28 UK GDPR) | At signature |
| Pre-filled DPIA for your venue | During onboarding |
| Retention schedule | At signature |
| Sub-processor list | At signature, updated on change |
| Call & action logs | Continuously, in your owner view |
Questions we haven't answered here — ask them: contact us. If you'd like your data protection adviser on the call, bring them.