Atlas Legal
Privacy Policy
Last updated 9 September 2026
1. Introduction
Atlas Group Technologies Ltd ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and website (collectively, the "Platform").
We are registered in England and Wales under company number 13937385 with our registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.
For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Atlas Group Technologies Ltd is the data controller.
2. Information We Collect
2.1 Personal Information You Provide
- Name and email address when you create an account
- Date of birth (mandatory, required for age verification under UK licensing law and to administer birthday rewards)
- Profile information including photos and preferences
- Payment information when making purchases (processed securely by Stripe)
- Phone number (optional, for two-factor authentication and SMS verification)
- Communications you send to us or other users, including direct messages
- Reviews, ratings, and other content you post
- Voice recordings when using Trinity AI concierge
- Competition entry details, ticket numbers, and skill question answers
- Story/Moments content (photos and videos) you upload
- Feedback data including star ratings, sentiment tags, and free-text comments submitted via Trinity conversations, venue check-ins, and platform feedback forms
2.2 Information Collected Automatically
- Device information (type, operating system, unique identifiers)
- Location data: We collect your device location automatically when you use location-based features like venue discovery, "near me" searches, and Trinity AI recommendations. This data is used solely to provide personalised, proximity-based results. Location is not stored permanently and is only used during your active session. You can disable location access at any time through your browser or device settings - the app will continue to function using your profile city instead.
- Usage data (pages visited, features used, interaction times)
- IP address and browser type
- Cookies and similar tracking technologies
- QR code check-in history and venue visit data
- Blockchain wallet address and transaction history (if using Atlas Card)
2.3 Information from Third Parties
- Social login information (if you sign in via Google)
- Venue information from partner establishments
- Analytics data from service providers
2.4 Special Categories of Data
We may process dietary preferences or allergy information you voluntarily provide for personalised venue recommendations. This data is only used to enhance your experience and is never shared without your explicit consent.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our Platform
- Process transactions and send related information
- Send you technical notices, updates, and support messages
- Respond to your comments, questions, and requests
- Personalise your experience and provide tailored recommendations
- Monitor and analyse trends, usage, and activities
- Detect, investigate, and prevent fraudulent or illegal activities
- Send promotional communications (with your consent)
- Process voice interactions through Trinity AI concierge
- Facilitate blockchain transactions and wallet services
- Send birthday rewards and loyalty notifications
- Administer prize competitions, determine winners, and fulfil prizes
- Display public profile information to other users
- Personalise marketplace product recommendations and track browsing behaviour for venue analytics
- Fulfil any other purpose for which you provide the information
4. Trinity AI Voice Concierge
4.1 Voice Data Collection
When you use Trinity, our AI voice concierge, we collect and process:
- Voice recordings during active conversation sessions
- Transcriptions of your voice input
- Conversation history and context
- Session metadata (duration, language, venue context)
4.2 Personalisation & Memory
Trinity learns and stores your preferences to provide personalised service:
- Dietary requirements and allergies you share
- Cuisine and venue preferences
- Facts you tell Trinity to remember
- Visit patterns inferred from your check-in history
This data is stored securely and used solely to enhance your experience. You may request deletion at any time.
4.3 Third-Party AI Processing (ElevenLabs)
4.3.1 Who is ElevenLabs
ElevenLabs Inc. is our sub-processor for voice and text AI conversations within the Trinity concierge. ElevenLabs acts as a data processor under UK GDPR Article 28, processing your data solely on our instructions and under a binding Data Processing Agreement.
4.3.2 What Data is Sent
- Audio stream from your microphone during voice sessions
- Text messages you type during text-mode sessions
- Session metadata (selected language, timestamps, session duration)
- Conversation context required for generating relevant responses (e.g. venue name, your stated preferences)
4.3.3 How Data is Processed
ElevenLabs performs speech-to-text conversion, AI response generation, and text-to-speech synthesis. All data is transmitted in real-time via encrypted WebRTC and WebSocket connections. Processing occurs on ElevenLabs servers located in the United States; international data transfers are governed by Standard Contractual Clauses (SCCs) as approved by the UK Information Commissioner's Office.
4.3.4 ElevenLabs Data Retention
ElevenLabs may retain conversation data for up to 90 days for service improvement and model quality purposes. Voice biometrics are not extracted or stored. After the retention period, all data is permanently and irreversibly deleted. For full details, see the ElevenLabs Privacy Policy.
4.3.5 Atlas Data Retention
- Conversation transcripts are stored for 90 days and then automatically purged by our daily cleanup process
- Session metadata (duration, venue context, mode used) is retained for analytics and service improvement
- Preference data you share with Trinity (e.g. dietary requirements) is retained until you delete your account or request erasure
4.3.6 Your Rights Regarding ElevenLabs Data
- Right to refuse: You may close the Trinity consent gate without accepting — no data will be sent to ElevenLabs
- Right to erasure: You may request deletion of your conversation data before the 90-day auto-purge by contacting support@atlasfoodanddrink.com
- Right to access: You may request an export of your Trinity conversation transcripts via a Subject Access Request
- Right to withdraw consent: You may revoke your Trinity data processing consent at any time through your profile settings; this will prevent further Trinity sessions until consent is re-granted
4.3.7 Consent Mechanism
A one-time consent gate is displayed before your first Trinity session, clearly disclosing that your conversations are processed by a third-party AI provider. Your acceptance is logged with a timestamp for audit purposes. You may review ElevenLabs' full privacy practices at elevenlabs.io/privacy.
4.4 Business Lead Collection
If you enquire about listing a venue through Trinity, we collect:
- Venue name and location
- Contact name and email address
- Phone number (if provided)
- Type of enquiry and notes
This data is used for sales follow-up and stored until the enquiry is resolved or you request deletion.
4.5 Data Retention
Voice recordings are processed in real-time and are not permanently stored by us. Conversation transcripts may be retained for up to 90 days for quality improvement and analytics purposes. Preference data is retained until you delete your account or request erasure.
4.6 AI Transparency Register
A plain-English register of every AI system in Atlas — what it does, which provider processes the data, whether a human reviews the output, and how to object — is published at /legal/ai-transparency.
4B. Trinity Line — AI Telephone Agent (August 2026)
Some venues on Atlas use Trinity Line, our AI telephone agent, to answer their phone. If you call a venue that has it enabled, you will be speaking to an automated assistant. This section explains that processing. It applies whether or not you have an Atlas account.
4B.1 What Is Collected on a Call
- The phone number you are calling from (caller line identity) and the venue number you dialled
- Your speech during the call, streamed in real time to our voice AI processor
- A written summary of the conversation, plus the outcome (booking made, order taken, enquiry answered, voicemail left, transferred)
- Any details you give in order to be served — name, party size, date and time, table or seating preference, allergies or dietary requirements, order contents, collection time
- Call metadata: start time, duration, and a technical call reference used for support and fault diagnosis
- A voicemail recording, if you choose to leave one when the agent cannot help
4B.2 AI and Recording Notice
At the start of every answered call you are told that you are speaking to an AI assistant and that the call is processed and summarised automatically. If you would rather not be handled by an automated system, you may ask to be passed to a member of staff or leave a message, or you can end the call and book through the venue's website, the Atlas app or email instead. Continuing the call after the notice is how you indicate you are content to proceed.
4B.3 Who Is Responsible (Controller and Processor)
- The venue you called is the data controller for the content of your call and for anything it records about you as a guest.
- Atlas acts as the venue's processor, operating the telephony and AI infrastructure on the venue's instructions under our Data Processing Agreement.
- Atlas is a controller in its own right only for a narrow set of purposes: platform security and abuse prevention, fault diagnosis, and metering call volumes for billing and fair use.
4B.4 Lawful Basis
- Necessary for steps taken at your request (Article 6(1)(b)) — handling your reservation, order or enquiry.
- Legitimate interests (Article 6(1)(f)) — answering calls reliably, keeping an accurate record of what was agreed, resolving disputes, preventing nuisance and fraudulent calls, and maintaining service quality.
- Where you volunteer allergy or health-related information so that the venue can serve you safely, we rely on your explicit consent given in the call, and that information is used for no other purpose.
4B.5 Outbound Calls
Some venues may also place outbound calls through Trinity Line — for example to confirm a booking, offer a table from the waitlist, or return a call you asked for. Outbound calls are only placed to numbers already linked to an existing booking, an existing waitlist entry, or a previous inbound call to that venue. Trinity Line is never used for cold or unsolicited marketing calls, and we do not sell or share your number for marketing.
4B.6 Who Processes It
Calls are carried by Twilio (telephony and voicemail storage), the conversation is voiced and transcribed by ElevenLabs, and the assistant's reasoning uses Google Gemini models via the Lovable AI Gateway. All three are contractually bound as processors under UK-approved Standard Contractual Clauses and are barred from training their models on Atlas data. Voice biometrics are not extracted, stored or compared — the system does not attempt to identify you from your voice. Full details are in our Subprocessors register.
4B.7 Retention
- Your phone number, the conversation summary and the technical call reference are automatically redacted 90 days after the call by a scheduled job.
- Anonymous call statistics (duration, outcome, whether the call was answered) are kept after redaction for capacity planning and billing.
- Voicemail recordings are held by our telephony processor for the venue to listen to and are deleted on the same 90-day cycle.
- Where the call produced a booking or an order, that booking or order record follows the normal retention period for bookings (see section 14) because it is a separate transaction record.
4B.8 Accuracy and Limits
The agent can mishear names, numbers and accents. Everything it books is visible to the venue's team, who confirm, amend or decline it — no charge is ever taken during the call. Do not rely on the agent for allergen safety: confirm allergens and cross-contamination risk directly with the venue's staff before you eat. Never use Trinity Line for an emergency; call 999.
4B.9 Your Rights if You Do Not Have an Atlas Account
You do not need an Atlas account to exercise your rights over a call. Email support@atlasfoodanddrink.com with the number you called from, the venue and the approximate date, and we will locate the record and either action your request or, where the venue is the controller, forward it to the venue and support them in answering it. We respond within one month. You may also object to this processing at any time under Article 21.
4A. Wallet, Identity & Operational Telemetry
4A.1 Multi-Chain Wallet Data (ADA, BTC L1, Spark L2)
When you connect or create an Atlas Wallet we store your public Cardano (ADA), Bitcoin (BTC) and Spark L2 addresses against your account so that on-chain rewards, payments and NFT mints can be routed correctly. The wallet is non-custodial: private keys, seed phrases and signing material are generated and held inside the UTXOS-provided iframe on your device and are never transmitted to or stored by Atlas.
On-chain transaction metadata (transaction hashes, amounts, counterparty addresses, timestamps) is, by the nature of public blockchains, permanently visible to anyone. Any link between an address and your Atlas account exists only inside our database and is treated as personal data. Cardano queries are routed through our Blockfrost edge-function proxy so that your IP address is not directly exposed to Blockfrost.
4A.2 Crypto Payment Rate Sourcing, Receipts & Reconciliation
When you initiate a crypto payment (ADA or BTC) we fetch a live GBP exchange rate from one or more third-party market data providers — currently CoinGecko and Kraken. Only the public asset identifier and target currency (e.g. cardano → gbp) are sent; no personal identifiers leave Atlas. The most recent successful rate is cached in our ada_gbp_daily table and tagged with its source provider, both to minimise external requests and as a last-resort fallback if every live provider is unavailable.
Confirmed crypto payments produce a downloadable PDF receipt generated entirely in your browser at the moment you click Download. Atlas does not store, email, or share these receipts; each download is a fresh render of the underlying payment record.
A daily reconciliation job scans the last 24 hours of confirmed crypto payments for anomalies (missing transaction hashes, settlement lag, large rate drift, deposit-address rotation faults, single-provider rate lock-in). Findings are written to an internal system_health_alerts log visible only to Atlas administrators. Critical findings may also be forwarded to our incident management provider at launch (currently incident.io) so that on-call operators can investigate; only the alert metadata is shared, never your payment amount, wallet address or transaction hash.
Each Bitcoin payment is quoted to a unique deposit address derived from an Atlas extended public key (xpub), so separate payments cannot be trivially linked together on-chain by a third-party observer. For ADA payments we attach a small CIP-20 transaction message containing only a payment reference and the purchase type — never your name, email, account ID or booking details. Bookings and guarantees are card-only via Stripe; no crypto escrow is used for reservations.
4A.2.1 Crypto Payment Exception Audit Log
Where Atlas applies a payment exception (duplicate, fraud, regulator order — see Terms clause 11.5.1), the original payment record is stamped with the operator who actioned it, the timestamp, a reason code and the remedy applied. A linked entry is also written to our administrator audit log. This data is retained for the lifetime of the underlying payment record (which is itself retained for at least the statutory accounting period of 6 years) and is accessible to you on request via our DSAR process.
4A.2.2 Wallet Tax Export & Historical Pricing
When you generate a wallet tax export (Explorer / VIP feature), our wallet-tax-export edge function reads your transaction history via Blockfrost and looks up historical ADA/BTC GBP prices from the same cached rate sources described above, falling back to CoinGecko for dates not yet captured. The generated CSV is delivered directly to your browser and is not retained server-side after delivery.
4A.3 Booking Card Guarantees
Most table bookings use a Stripe-issued card guarantee rather than a deposit. Stripe stores a tokenised reference to your card; Atlas only stores the token, the authorisation status and (where applicable) the captured no-show amount. We do not retain raw card numbers.
4A.4 Allergen & Dietary Data
Allergen and dietary preferences you save on your profile are special-category-adjacent data and are used solely to filter recommendations and to populate "Safe for Me" badges. Menu allergen tags supplied by venues may be marked as AI-suggested until the venue explicitly confirms them; this status is shown to you at the point of decision so you can make an informed choice.
4A.5 Age Verification via Midnight (Zero-Knowledge Proofs)
Where supported, age verification is performed using zero-knowledge proofs on the Midnight network. Only a cryptographic attestation that you are over 18 is recorded; your date of birth and any underlying identity data are not transmitted on-chain or to Midnight. Your DOB stays inside our protected database and is immutable after first save.
4A.6 Passkeys (WebAuthn)
When you enrol a passkey inside the Atlas iOS or Android app, we store only the WebAuthn public key, credential ID and metadata (device label, last-used timestamp). The corresponding private key never leaves your device's secure enclave and is synchronised — if at all — through your platform keychain (Apple iCloud Keychain or Google Password Manager), not through Atlas.
4A.7 Push Notifications (Pushwoosh)
If you grant push notification permission, Pushwoosh issues a device-specific HWID and push token which we use to deliver targeted notifications (booking reminders, follower activity, venue updates). You can revoke permission at any time in your browser or device settings; revocation immediately stops new notifications, and the corresponding token is purged from our records on next sync.
4A.8 Maps (Mapbox)
Map tiles, geocoding and venue markers are served by Mapbox. Mapbox receives your IP address and approximate viewport bounds in order to serve tiles, and processes a session-level telemetry cookie. Mapbox is loaded only once you have accepted the "Analytics" cookie category.
4A.9 Live Broadcasts (LiveKit)
When you go live or join a live room, audio and video streams are routed through LiveKit's WebRTC infrastructure. Streams are not recorded by default; if a venue chooses to record a stream this is clearly indicated in-room and the recording is governed by Atlas retention rules.
4A.10 Audit Logs & Client Error Reporting
Sensitive actions (admin operations, security events, role changes, GDPR requests) are recorded in immutable audit log tables for accountability and incident investigation. Unhandled client-side errors are captured (URL, stack trace, anonymised user id) to help us diagnose bugs. Audit and error data is retained for up to 24 months and then purged.
4A.11 Lovable AI Gateway (Server-Side AI)
Server-side AI features (venue description drafting, allergen suggestion, sentiment analysis, creator matchmaking, milestone NFT generation) route prompts through the Lovable AI Gateway to Google Gemini and OpenAI models. Prompts may include venue or content metadata but are not used to train upstream models. The full sub-processor list is available in our Subprocessors register.
4A.12 Offline Mode (Device-Local Cache & Queue)
The Atlas mobile and web app uses an on-device cache (IndexedDB via Dexie) so you can browse recent venues, view tickets, draft reviews and queue check-ins while offline. The cache stores a copy of data already shown to you in the app — it does not contain other users' private data. Queued actions are replayed automatically once you reconnect; any conflicts are surfaced to you via an in-app conflict inbox for review. The cache is purged when you sign out or uninstall the app, and relies on the operating system's at-rest encryption (Keychain / Keystore). You can clear the cache at any time from Profile → Settings → Privacy & Security → Clear offline data.
4A.13 Quest Completions Anchored to Cardano
When you complete an in-app quest, a tamper-evident record of that completion is sealed to the Cardano public blockchain via our hourly Merkle-root batch. What we anchor is a one-way salted hash of your user ID together with the quest identifier, quest version, venue ID, completion timestamp and AXP awarded — no email, name, wallet address or other personal data is written to the chain. If a completion is later revoked or amended (for example, fraud or a bug), the original seal is never rewritten; instead a compensating event is anchored so the on-chain history remains a truthful audit trail. You can view any completion's proof at /verify/<tx_hash>. Because the hash is anonymised at source, exercising your Right to Erasure removes the link between you and any on-chain hash without needing to alter the blockchain itself.
5. Prize Competition Data
5.1 Data Collected
When you enter a prize competition on the Platform, we collect and process:
- Entry details (competition entered, number of tickets purchased)
- Ticket numbers assigned to you
- Payment information (processed by Stripe; we do not store card details)
- Your answer to the skill-based question
- Date and time of entry
5.2 Purpose
This data is used to administer prize draws, determine winners, process payments, prevent fraud, and comply with UK legal requirements for prize competitions.
5.3 Winner Publication
As required by UK competition law, the winner's first name and city may be published on the Platform and in promotional materials. By entering a competition, you consent to this publication in the event you win.
5.4 Retention
Competition entry records (including ticket numbers, payment references, and winner details) are retained for 7 years after the draw date. This extended retention period is required for tax compliance and legal obligations relating to prize fulfilment under UK law.
6. Public Profile & Stories Data
6.1 Public Profile Data
The following information from your profile is publicly visible to other Atlas users:
- Display name and profile picture
- Posts, reviews, and ratings you have submitted
- Badges and achievements earned
- XP level and leaderboard position
- NFT Passport stamps
- Social connections (friends list)
Your email address, date of birth, phone number, and payment information are never publicly displayed. Reviews and posts are publicly visible once submitted and cannot be made private retroactively (but can be deleted).
6.2 Atlas Moments (Stories) Data
When you use Atlas Moments (Stories):
- Photos and videos you upload are stored temporarily and automatically deleted after 24 hours
- Viewer analytics (who viewed your Story, view count) are collected and available to you as the creator
- Venue tags associated with your Stories are visible to the tagged venue
- We may retain anonymised engagement metrics after Stories expire
7. SMS, Two-Factor Authentication & Phone Data
7.1 Phone Number Collection
If you enable two-factor authentication (2FA) or opt in to SMS notifications, we collect and store your phone number. Your phone number is used solely for:
- Sending one-time passcodes (OTPs) for account verification
- Security alerts related to your account
- SMS notifications you have explicitly opted into
7.2 SMS Consent
SMS consent is explicitly captured via a mandatory checkbox during 2FA setup. The date and time of your consent is recorded. You may withdraw SMS consent at any time through your profile settings, which will disable 2FA via SMS.
7.3 OTP Data Lifecycle
In accordance with UK GDPR data minimisation principles, OTP codes are handled as follows:
- Successfully verified OTP codes are deleted immediately upon verification
- Expired, unverified OTP codes are automatically purged within 1 hour
- Verification attempts are logged in our security audit trail (retained for 12 months)
7.4 Third-Party Processing
SMS messages are delivered by Twilio, our SMS service provider. Twilio processes your phone number and message content for delivery purposes only. Their privacy policy is available at twilio.com/legal/privacy.
8. Direct Messages
8.1 Data Collection
When you use the direct messaging (DM) feature, we collect and store:
- Message content (text and images)
- Sender and recipient identifiers
- Timestamps of messages sent and read
- Conversation metadata (mute status, group membership)
- Message reports you submit, including the reason and any description you provide
8.2 Retention
Direct messages are retained until you delete your account (plus the 30-day grace period). Individual messages cannot currently be deleted by users. DM content is included in Subject Access Request exports. Message reports are retained for 3 years in accordance with our legal obligations.
8.3 Privacy and Monitoring
Direct messages are private between participants. We do not conduct bulk surveillance or automated scanning of message content. However, we may access specific message content in the following limited circumstances:
- User-initiated reports: When a participant in a conversation reports a specific message using the "Report Message" feature, the flagged message content and surrounding context will be reviewed by our trust and safety team
- Legal requirements: Where required by law, court order, or regulatory authority (e.g. under the Online Safety Act 2023)
- Terms enforcement: To investigate credible allegations of harassment, abuse, spam, or other violations of our Terms of Service, following an internal escalation process
8.4 Report Message Feature
You can report individual messages by hovering over a message and selecting the flag icon. When you report a message, the following data is shared with our admin team for review:
- The content of the reported message
- Your identity as the reporter
- The identity of the message sender
- The reason you selected (harassment, spam, inappropriate, or other)
- Any additional description you provided
Reports are reviewed by authorised administrators only. The reported user is not notified of who filed the report. All report reviews are logged in our admin audit trail for accountability. The legal basis for this processing is legitimate interests (UK GDPR Art. 6(1)(f)) — specifically, maintaining a safe platform environment and protecting users from harmful content.
9. Legal Basis for Processing
Under UK GDPR, we process your personal data based on:
- Contract: Processing necessary to perform our contract with you (providing the Platform, administering competition entries)
- Legitimate Interests: Processing necessary for our legitimate business interests (improving services, fraud prevention, AI quality improvement)
- Legitimate Interests (Location): We process location data based on our legitimate interest in providing accurate, proximity-based venue recommendations. This processing is proportionate and essential to our core service of helping users discover nearby dining options.
- Consent: Where you have given explicit consent (marketing communications, voice recording, birthday rewards, SMS/2FA, venue email subscriptions)
- Legal Obligation: Processing necessary to comply with our legal obligations (competition records retention, tax compliance)
10. How We Share Your Information
We may share your information with:
- Venues: When you check in, make reservations, or interact with venue profiles (including visit history for loyalty programs)
- AI Service Providers: ElevenLabs for voice processing, other AI providers for recommendations
- Email Delivery: Our managed delivery service for account, app and opted-in venue emails
- SMS Provider: Twilio for sending OTP codes and SMS notifications
- Blockchain Networks: Transaction data is recorded on public blockchain networks (immutable)
- Service Providers: Third parties who perform services on our behalf (hosting, analytics, payment processing)
- Business Partners: With your consent, for joint marketing initiatives
- Legal Requirements: When required by law, regulation, or legal process
- Business Transfers: In connection with a merger, acquisition, or sale of assets
- Competition Winners: Winner first name and city as required by UK competition law
We do not sell your personal information to third parties.
For a full, up-to-date list of the third-party processors we engage (including purpose, data categories, processing region and DPA links), see our Subprocessors page. We provide at least 14 days' notice before adding new subprocessors.
11. Venue Customer Data (For Venue Partners)
11.1 Customer Data Uploads
Venues may upload customer data (CSV files) to the Platform for the purpose of sending invitations and managing loyalty programs. In this context:
- The venue is the data controller for their customer data
- Atlas Group Technologies Ltd acts as a data processor on the venue's behalf
- Data is stored securely and separately for each venue
- Data is only used for the purposes specified by the venue
11.2 UK GDPR Compliance
Venue-uploaded customer data is processed in accordance with our Data Processing Agreement. Venues are responsible for ensuring they have appropriate legal bases and consents to share customer data with us. We implement appropriate technical and organisational measures to protect this data.
11.3 Venue Email Campaigns & Tracking
Venues with eligible subscription tiers may send branded marketing emails to their subscribers through the Platform. For these emails, we record:
- Sending status: Whether an email was accepted for sending or rejected
- Email outcomes: Bounces, spam complaints and unsubscribes
This data helps venue owners manage their subscriber list and understand sending failures. Open and click tracking is not provided.
Email campaigns use Atlas's managed delivery service. You may unsubscribe at any time using the unsubscribe link included in every campaign email.
11.4 Venue Email Branding
Venues may configure custom email branding including a display name, reply-to email address, logo, and brand colours. Reply-to addresses direct your replies to the venue's own inbox. Venue branding configuration data is stored as part of the venue's profile.
11.5 Venue Compliance Vault
Recent change (19 April 2026): We have introduced a Compliance Vault for venue partners — a private, encrypted area where venues can store their own regulatory and operating documents (licences, insurance schedules, training and safety certificates, etc.). This section explains what it means for you as a customer.
- Compliance Vault documents belong to the venue and are not visible to customers or other users of the Atlas platform.
- Documents are stored in a private, encrypted bucket hosted in the UK/European region. Access is technically restricted to the relevant venue's administrators.
- Downloads are issued via short-lived (5-minute) audited signed URLs; direct anonymous access to the storage layer is not possible.
- Every upload, download, and deletion is logged with the acting user, timestamp, and IP address for accountability (UK GDPR Art. 5(2)).
- The venue is the Data Controller for anything uploaded; Atlas acts only as the Data Processor on the venue's instructions.
- Venues are contractually prohibited from uploading customers' personal data, NHS records, DBS certificates, passport/right-to-work scans, payroll data, or special category data.
- If, exceptionally, a customer's name appears in a vault document (for example, a venue-held complaint log — which we discourage), the venue is responsible for handling Data Subject Access and Erasure requests as the Controller. Atlas will assist the venue on request.
- Retention follows UK statutory minimums by default (for example, Employer's Liability Insurance: 40 years; food safety records: 12 months) unless the venue sets a longer or shorter period within lawful limits. Atlas flags documents past their retention date for venue review but does not auto-delete.
For Subject Access or Erasure requests relating to documents you believe a venue may hold about you, please contact the venue directly in the first instance, or email support@atlasfoodanddrink.com and we will route your request appropriately.
11.6 Venue CRM & Guest Intelligence (August 2026)
Venues on paid tiers can use Atlas CRM to recognise returning guests. This section explains what that means for you as a diner.
- What a venue can see: your bookings and check-ins at that venue only, visit count, average and total spend bands where the venue has captured them, allergy and preference notes you or the venue recorded, and no-show or late-cancellation history.
- Automatic tags: our AI proposes descriptive tags (for example "regular", "wine lover", "weekday luncher"). Tags are editable by staff, are advisory, and are never used to refuse service or to charge you a different price.
- Strictly venue-scoped: a venue cannot see your activity at any other venue, your Atlas wallet, your AXP balance detail, or your account-level history. Guest profiles are never sold, pooled across venues, or shared with third parties.
- Contact details: venues see only what is needed to serve your booking. Where a booking is fulfilled without direct contact, contact details remain shielded in line with our zero-exposure policy.
- Controller: the venue is the data controller for its CRM records; Atlas is its processor. Objections and erasure requests can be sent to the venue or to us for routing.
- Retention: guest CRM records are retained while the guest relationship is active and are purged in line with the venue's configured retention period and our automated GDPR retention sweep.
11.7 Atlas Paylink (Remote Card Guarantees)
Where a venue takes a booking or order by phone or message, it may send you an Atlas Paylink to place a card guarantee. The page is hosted by Stripe; card details are entered directly with Stripe and are never seen, heard or stored by Atlas, the venue or Trinity Line. We hold only the link status, the amount, the associated booking or order reference, and Stripe's payment identifier. See Terms clause 12.8.
11.8 Till (EPOS) Connections & Matched Spend (September 2026)
A venue may connect its own till / point-of-sale system to Atlas so that its takings and guest records line up. Supported providers are Square, Lightspeed Restaurant, Clover, SumUp, Zettle by PayPal and Tabology (BarTab). This section explains what that means for you as a diner.
- What we receive: closed bill records from the venue's till — bill total, tips, service charge, discounts, payment method type, item lines, table or order reference, the serving staff identifier and the time the bill closed. Card numbers are never transmitted to Atlas; the till provider handles the payment itself.
- How a bill is linked to you: only where there is a firm signal — a seated booking of yours at that table and time, or an Atlas QR check-in at that venue inside a short window. Where no signal exists the bill stays unattributed and is counted only in the venue's totals.
- "Matched spend" means measured, not estimated: the spend figures a venue sees against a guest come from bills we could actually match. Atlas does not estimate, model or infer what you spent, and unmatched bills are shown to the venue as unmatched rather than guessed.
- Venue-scoped: a venue sees till-derived spend for its own site only. Nothing is pooled across venues, sold, or used for advertising.
- Corrections and refunds: where the till later voids, corrects or refunds a bill, the matched record and any spend figure derived from it are updated to follow the till.
- Controller: the venue is the controller of its own till records; Atlas is its processor for the matching and reporting described here. The till provider is the venue's own supplier.
- Staff data: staff identifiers arriving from the till are used for the venue's internal sales reporting only and are never shown to diners.
11.9 Return Invitations ("Invite back")
A venue may invite a past guest back through Atlas. An invitation is only sent where you hold the relevant marketing consent for that channel, and every skipped send is logged so we can show the venue why. Whether an invitation led to a later visit is measured from your own check-in, matched bill or seated booking inside a defined window — never from tracking pixels or third-party ad networks. You can withdraw consent at any time in your profile settings, and the unsubscribe link in every message works immediately.
12. Blockchain and Wallet Data
12.1 Public Blockchain Data
If you use Atlas Card (our digital wallet feature), please note that blockchain transactions are recorded on the Cardano public blockchain. This means:
- Transaction history is publicly visible and permanently recorded
- Wallet addresses are pseudonymous but may be linked to your identity
- We cannot delete blockchain transaction records
12.2 Wallet Data We Store
We store the association between your account and your wallet address, transaction metadata, and NFT ownership records. This data is used to display your assets and transaction history within the app.
13. International Data Transfers
Your information may be transferred to, and processed in, countries other than the United Kingdom. These countries may have different data protection laws. When we transfer your data internationally, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner's Office (ICO).
13.1 Sub-processors & Transfer Safeguards
The following third-party processors may process your data outside the UK:
- ElevenLabs Inc. (USA) — Voice AI processing for Trinity concierge. Transfer basis: UK-approved SCCs under a binding Data Processing Agreement. Data retained up to 90 days.
- Stripe Inc. (USA) — Payment processing and subscription management. Transfer basis: UK-approved SCCs. PCI-DSS Level 1 certified. We never store card details.
- Blockfrost / IOHK (various) — Cardano blockchain API for wallet balance and transaction queries. Transfer basis: public blockchain data; wallet addresses are pseudonymous. Proxied through our backend to avoid direct client exposure.
- Google Cloud (various) — AI model inference for taste recommendations and content moderation. Transfer basis: UK-approved SCCs under Google's Data Processing Terms.
- CoinGecko (Singapore) — Live and historical ADA/BTC GBP exchange rate market data. Only public asset identifiers are queried; no personal data is sent. Transfer basis: limited to public market data requests.
- Kraken / Payward Inc. (USA) — Secondary live ADA/BTC GBP exchange rate provider used when CoinGecko is unavailable. Public market endpoints only; no personal data is sent. Transfer basis: limited to public market data requests.
- mempool.space (EU) — Bitcoin (BTC) transaction verification API used to confirm payments to our treasury. Only public transaction hashes are queried; no personal data is sent.
- incident.io (UK/EU) — On-call incident management for critical platform anomalies (including crypto payment recon alerts) at launch. Only alert metadata is forwarded — never payment amounts, wallet addresses or transaction hashes.
- Apple Push Notification Service (Apple Inc., USA) — Native push delivery for the iOS app. Receives push token + notification payload only. Transfer basis: UK-approved SCCs incorporated into Apple's Developer Terms.
- Firebase Cloud Messaging (Google LLC, USA) — Native push delivery for the Android app. Receives push token + notification payload only. Transfer basis: UK-approved SCCs under Google's Data Processing Terms.
- Apple App Store Connect (Apple Inc., USA) — App distribution, crash reports and aggregate install metrics for the iOS app. Receives anonymised diagnostics; no PII.
- Google Play Console (Google LLC, USA) — App distribution, ANR/crash reports and aggregate install metrics for the Android app. Receives anonymised diagnostics; no PII.
You may request a copy of the relevant transfer safeguards by contacting support@atlasfoodanddrink.com.
13A. Automated Decision-Making & Profiling (Article 22)
We use automated processing in the following areas. None of these produce legally binding or similarly significant effects, but we believe in transparency:
- AI Taste Recommendations: Trinity and The Vault use your check-in history, reviews, dietary preferences, and stated tastes to generate personalised venue suggestions. This is powered by Google Gemini models. No booking or financial decision is made automatically — recommendations are suggestions only.
- Content Quality Grading: User-generated content (photos, videos) receives an automated quality score used to determine AXP rewards and visibility. Content is never removed solely by automated decision — all moderation actions are human-reviewed.
- Churn Risk Scoring: We calculate engagement scores to identify users who may benefit from re-engagement offers. This does not restrict your access to any features.
- Fraud Detection: Competition entries, crypto payments, and voucher redemptions are monitored for unusual patterns. Flagged transactions are reviewed by a human before any action is taken.
- Venue Guest Intelligence & Auto-Tagging: Where a venue uses Atlas CRM, our models summarise that venue's own booking and visit records into guest tags (for example "regular", "wine lover", "birthday guest"), visit counts and spend bands. Tags are suggestions for staff, are editable and removable by the venue, and are never used to refuse service or to set a different price for you. The venue is the controller; Atlas is its processor.
- AI Pre-Shift Briefings: A written summary generated for venue staff before service, covering expected covers, allergy flags, VIP arrivals and demand conditions. Advisory only and read by a manager before use.
- Trinity Line Call Handling: The AI telephone agent interprets what a caller says and drafts a reservation, order or enquiry. Every output is confirmed, amended or declined by the venue's team, and the agent cannot charge you (see section 4B).
- Demand & Dynamic Happy Hour Scoring: Aggregate booking, footfall, weather and time signals estimate how busy a venue is likely to be, driving offer timing. No individual profiling decision restricts your access or pricing.
A full register of every AI system in Atlas — purpose, provider, data used, human review and opt-out route — is published in our AI Transparency Statement.
Your Rights
You have the right to: (a) request meaningful information about the logic involved in any automated processing, (b) request human review of any automated decision that affects you, and (c) contest any automated decision. Contact support@atlasfoodanddrink.com to exercise these rights.
13B. Right to Restrict Processing (Article 18)
You have the right to request restriction of processing of your personal data in the following circumstances:
- You contest the accuracy of your data — processing is restricted while we verify accuracy
- Processing is unlawful but you oppose deletion and request restriction instead
- We no longer need the data but you need it for legal claims
- You have objected to processing under Article 21 — processing is restricted pending verification of legitimate grounds
When processing is restricted, your data will be stored but not actively processed (e.g., excluded from recommendations, analytics, and marketing). Your account will remain accessible but with limited functionality. We will inform you before any restriction is lifted.
To request restriction, contact support@atlasfoodanddrink.com. We will respond within one month.
14. Data Retention
We retain your personal information for as long as your account is active or as needed to provide you services. Specific retention periods:
- Account data: Until account deletion + 30-day grace period (during which you may reactivate your account)
- Direct messages: Until account deletion + 30 days
- SMS/OTP data: Verified OTP codes are deleted immediately upon successful verification; expired codes are purged within 1 hour
- Voice transcripts: Up to 90 days
- Trinity preferences: Until account deletion or erasure request
- Business lead data: Until enquiry resolved or erasure request
- Transaction records: 7 years (legal requirement)
- Competition entry records: 7 years (tax/legal requirement for prize fulfilment)
- Blockchain data: Permanent (immutable blockchain)
- Venue visit history: 3 years or until account deletion
- Till (EPOS) bill records matched to you (bill total, tips, service charge, item lines, table reference, closing time): 3 years for the venue's accounting and reporting, or until account deletion, whichever comes first; unmatched bills carry no personal data
- Return invitation records (invitation sent, channel, consent state, whether a later visit was measured): 12 months, then anonymised for campaign reporting
- Gamification data (XP, badges): Until account deletion
- Punch card stamp ledger (venue, stamp count, issuing visit or bill reference, redemption timestamp): Until account deletion, or 3 years after the card was completed or last stamped, whichever comes first
- Offer and deal claim records (claim code, offer, venue, claim and redemption timestamps): 12 months after the claim expires or is redeemed, then anonymised for offer performance reporting
- Game data (RPS): Until account deletion
- Stories media: 24 hours (auto-deleted)
- Analytics data: 2 years in anonymised form
- User feedback (Trinity, venue visits, platform reports): 12 months
When you delete your account, we will delete or anonymise your personal data within 30 days, unless retention is required by law.
15. Your Rights
Under UK data protection law, you have the right to:
- Access: Request a copy of the personal data we hold about you
- Rectification: Request correction of inaccurate or incomplete data
- Erasure: Request deletion of your personal data ("right to be forgotten")
- Restriction: Request restriction of processing of your data
- Portability: Request transfer of your data to another service
- Objection: Object to processing based on legitimate interests
- Withdraw Consent: Withdraw consent at any time where we rely on consent
- Voice Data: Request deletion of voice transcripts and conversation history
- Data Export: Request a full export of your personal data via your profile settings or by contacting us. Our self-service data export covers 40+ data categories including profile data, visits, reviews, messages, transactions, gamification stats, and more
Note: We cannot delete blockchain transaction records as they are immutably stored on public networks. Competition entry records may be retained for 7 years regardless of account deletion due to legal obligations.
To exercise these rights, please contact us at support@atlasfoodanddrink.com. We will respond within one month.
16. Push Notifications & Marketing
We may send you push notifications for:
- Transaction confirmations and security alerts
- Birthday rewards and loyalty program updates
- Flash deals and special offers from venues you've visited
- Friend activity and social features
- Platform updates and new features
- Competition draw results and winner announcements
You can manage your notification preferences in your profile settings. You may opt out of marketing communications at any time while still receiving essential service notifications.
iOS App Tracking Transparency. Atlas does not track you across apps or websites owned by other companies. We do not collect IDFA, do not use third-party advertising SDKs, and do not share data with data brokers. The App Tracking Transparency prompt is therefore not shown. Our Apple Privacy Nutrition Label declares "Data Not Used to Track You".
17. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include encryption, secure servers, access controls, and regular security audits. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
We have conducted Data Protection Impact Assessments (DPIAs) for high-risk processing activities including AI voice processing, location-based services, and direct messaging, in accordance with Article 35 of UK GDPR.
Your date of birth is collected during registration for age verification (18+ requirement under UK licensing law). It is stored securely in your profile and permanently locked after initial entry to prevent tampering. This data is protected by row-level security and is never publicly displayed.
18. Children's Privacy
Our Platform is not intended for children under 18 years of age. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
19. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. You are advised to review this Privacy Policy periodically for any changes.
20. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
Atlas Group Technologies Ltd
Data Protection Contact: support@atlasfoodanddrink.com
We are in the process of formally appointing a Data Protection Officer under Article 37 of UK GDPR. In the meantime, all data protection enquiries can be directed to the above address.
General Privacy Enquiries: support@atlasfoodanddrink.com
Address: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe your data protection rights have been violated. Visit ico.org.uk for more information.