LegalΕλληνικά

Privacy Notice

Last updated: 7 September 2026

Service en Place helps operators capture operating records and act on what matters next. To do that, we process some account, workspace, and operational information.

These pages are early-access drafts written by the engineering team and are not solicitor-approved.

Who we are

The legal entity or person responsible for Service en Place, including company registration and address details: To be confirmed before launch. Legal review required before launch.

For privacy questions or data requests, contact support@serviceenplace.com.

What data we collect

We collect the following kinds of information:

- Account, organisation, and workspace information

- Operating records you enter into the product

- Uploaded documents you submit for processing

- AI-assisted extraction drafts created from your documents

- Guest feedback you choose to record

- Labour, timesheet, and draft payroll support information

- Integration records you choose to connect

- Billing and subscription information

- Optional product feedback and permitted first-party acquisition attribution

- Browser privacy receipts and optional browser preference, analytics, and attribution signals

- Security and audit logs

Uploaded documents

Documents you upload (such as menus or invoices) may be processed to extract operating records. Uploaded-document records and local original bytes follow a retention lifecycle; copies held in external object storage are handled separately.

The current target for original-file retention is 90 days. When eligibility and hold checks permit, authorised retention or data-request actions can clear local database-held original bytes and linked legacy copies. A direct authorised upload-deletion action can mark an original held in external object storage as scheduled for deletion; the current retention batch neither marks nor deletes external objects. This is a lifecycle target, not an instant or guaranteed destructive action today.

AI-assisted processing

Service en Place uses AI-assisted extraction and classification to help turn documents you submit into operating records. AI assists operator judgement; it does not replace it.

Operators confirm AI-assisted outputs before relying on them. Raw AI payload fields have a configured 30-day retention target and can be cleared by an authorised, scoped retention or data-request action when eligible. The application defaults the retention executor to dry-run unless destructive execution is explicitly enabled, so this target is not a guarantee of automatic deletion at exactly 30 days. AI-assisted outputs can contain mistakes.

Guest feedback

Where you record guest feedback, you control what you enter. Please avoid unnecessary names, contact details, booking references, or private-message content.

Guest feedback is recorded only from what you enter, not collected for you from other platforms.

Labour, timesheet, and draft payroll support

Labour, timesheet, and payroll support features help you prepare draft figures. Draft payroll support is draft-only.

Draft payroll support only. Verify hours, rates, deductions, and statutory obligations before using anything outside Service en Place. This is not payroll, tax, legal, or HR advice, and it is not HMRC-ready payroll software.

Integrations

Where a supported integration is enabled for your account, you may connect an account you are authorised to manage. Connected provider records are imported only where that integration is available and authorised.

Connect only supported accounts you are authorised to manage.

Billing and subscriptions

Paid plans are billed through Stripe. Payment card details are handled by Stripe, not stored directly by Service en Place.

Cookies, storage, and analytics

Service en Place uses essential cookies and browser storage for sign-in, security, core function, and a necessary browser privacy receipt. Optional preferences, analytics, and attribution are separate choices, denied until you explicitly accept, and can be withdrawn from the persistent Privacy settings control in the footer. Signed-in choices are saved to your account; signed-out choices are browser-specific. Global Privacy Control denies analytics and attribution. The current inventory has no marketing-cookie entries; that absence is not, by itself, proof that no tracking exists.

Optional first-party analytics is disabled by default. It requires both the service's analytics feature to be enabled and your separate analytics choice. Signed-in choices are saved to your account and checked when collecting optional events; signed-out choices apply only to that browser and site address. An account without a saved choice starts off, even if the browser previously accepted. Global Privacy Control blocks analytics and attribution. When permitted, the service records a limited set of product-journey events without marketing cookies, fingerprinting, raw referrer URLs, IP marketing records, or arbitrary event details. Signed-in events may be linked to organisation, workspace and user identifiers; they are not necessarily anonymous.

Optional product feedback

After a business creates its first Read, its founding owner may optionally choose one governed answer about what made them try Service en Place. The answer can be skipped and does not require free text. This explicit product feedback is separate from passive attribution and does not require an attribution opt-in. Passive first-visit and signup attribution requires its own browser choice and the service feature to be enabled; Global Privacy Control blocks it.

Security and audit logs

Service en Place applies a range of security and access controls, but no service can guarantee absolute security.

Selected sensitive operations and data-request lifecycle actions generate audit events. This is not a claim that every activity is logged or that audit/security records are automatically deleted after 90 days. Service en Place does not claim formal external certifications or penetration testing unless and until separately confirmed.

Why we use data

We use this information to provide the service, authenticate users, manage organisations and workspaces, process subscriptions, support operating features, understand how businesses find and try the service where permitted, improve the product from optional feedback, and keep the platform secure.

Who processes data

This is an incomplete engineering inventory of provider references found in the current application code. It is not a complete or legally verified list of current subprocessors; provider roles, regions, and contractual status require confirmation for a final public legal notice.

- Clerk: Account authentication and sign-in session management.

- Stripe: Subscription billing and payment processing.

- OpenAI: AI-assisted extraction and classification of documents you submit.

Retention

Different categories of information have provisional engineering retention targets and lifecycle rules. Some records are kept longer where required for security, billing, employment, audit, or legal reasons; actual enforcement varies by category and requires review.

Retention rules are engineering policy primitives and targets. The current destructive executor covers eligible local uploaded-original bytes and raw AI payload fields, runs dry-run by default, and does not claim automated deletion of audit/security records or external object-storage originals. Analytics and attribution can currently be identified for review only: this process does not delete, clear or anonymise them. It does not cover anonymous analytics records. Existing upload and AI-byte cleanup remains unchanged. Some fields may persist until separately reviewed or fully removed.

Your data requests

You can use authenticated in-app Data Controls to request access, deletion review, or export. Contact us to request correction or another data request. Support email is a manual help route, not an automatic intake or suppression system. We may need to verify your identity or authority first.

Deletion may be limited by security, billing, employment, audit, legal, or operational retention needs. Broad deletion requests remain manual-fulfilment workflows; narrow local-upload and AI-raw actions can execute only when authorised eligibility checks pass. Requests are not completed the moment they are received.

Exports are bounded technical inventories generated from selected tenant-scoped categories and direct application links. They may omit raw files or sensitive fields, may not represent every source requiring review, and must be manually checked for coverage, third-party information, exemptions, and secure delivery.

Contact and legal review

Questions about this notice can be sent to support@serviceenplace.com.

International transfer mechanisms, lawful bases, and supervisory-authority details: Legal review required before launch.