Privacy Policy
Last updated: February 2026
Data & Privacy
Luigi calls restaurant guests on behalf of our clients. Here's how we handle that — in plain English, before the legal detail below.
- Calls are disclosed as AI. Every guest Luigi speaks with is informed they're interacting with an AI assistant acting on behalf of the restaurant. No exceptions.
- We process data, we don't own it. The restaurant is the data controller. Dreem Studio acts as data processor. We sign a Data Processing Agreement with every client before going live — available on request.
- What we store, and for how long. Call recordings are retained for 90 days, then deleted. Reservation data for 12 months. Guest phone numbers are never used outside the scope of the reservation they were collected for.
- Opt-out is real. Any guest can decline the call or request removal. The restaurant is notified immediately.
- Frameworks we comply with. GDPR (France, EU), UK GDPR, and UAE PDPL for our Dubai clients.
Questions? Reach a human: forward@try-luigi.com
Full privacy policy below.
1. Data Controller
2. Data We Collect
• Account data: email address, password (hashed), restaurant name, phone number.
• Reservation data: customer names, phone numbers, reservation dates, guest counts, call recordings and summaries — provided by the restaurant through their reservation system.
• Usage data: pages visited, features used, browser type, IP address (anonymized after 30 days).
• Contact form data: email address, restaurant name submitted through our demo request form.
3. How We Use Your Data
• Provide and improve the Luigi AI service (confirmation calls, dashboard, reports).
• Communicate with you about your account and our service.
• Respond to demo requests and support inquiries.
• Analyze usage patterns to improve our product (aggregated, anonymized data only).
We do not sell, rent, or share personal data with third parties for marketing purposes.
4. Legal Basis (GDPR)
• Contract performance: processing necessary to provide the Luigi AI service to restaurant owners.
• Legitimate interest: improving our service, preventing fraud, ensuring security.
• Consent: for marketing communications (you can opt out at any time).
For reservation data (restaurant guests), the restaurant is the data controller and Luigi AI acts as a data processor under a Data Processing Agreement.
5. Data Retention
• Reservation data: retained for 12 months, then automatically deleted.
• Call recordings: retained for 90 days, then automatically deleted.
• Usage data: anonymized after 30 days, aggregated data retained for analytics.
6. Data Security
7. Your Rights
• Access your personal data.
• Rectify inaccurate data.
• Delete your data ("right to be forgotten").
• Port your data to another service.
• Object to or restrict processing.
• Withdraw consent at any time.
To exercise these rights, email us at forward@try-luigi.com. We will respond within 30 days.
8. Cookies
9. Third-Party Services
• Supabase (database & authentication) — EU data region available.
• Vercel (hosting & analytics) — SOC 2 compliant.
• Formspree (contact form processing).
Each service has its own privacy policy and processes data under our instructions.