Data Processing Agreement
Last updated: 27 September 2026
About this agreement
This Data Processing Agreement (“DPA”) is between the restaurant business that uses Sonno (“you”, the controller) and Sonno AI, Inc., a Delaware corporation, registered address 2810 North Church Street, STE 89914, Wilmington, DE 19802, United States (“Sonno”, “we”, the processor). It forms part of our Terms, and you agree to it when you agree to them. This is version 2026-09-27.
It covers the personal data we process on your behalf when we provide Sonno (“Customer Personal Data”), and is intended to meet Article 28 of the UK GDPR and the Data Protection Act 2018 (together, “Data Protection Law”). Words such as controller, processor, personal data, processing and personal data breach have the meanings given in Data Protection Law. If this DPA conflicts with the Terms on data protection, this DPA wins.
We are a controller, not your processor, for the data we hold about you and your staff as our customer (account, billing and support data). Our Privacy Policy covers that.
The processing
Subject matter and purpose. Answering and handling phone calls to your restaurant with an AI voice host; taking, changing and cancelling bookings; taking messages and waitlist entries; transferring calls to your staff; sending texts to guests about their bookings; and showing all of this to your staff in the Sonno dashboard.
Nature. Receiving call audio and converting it to text in real time; generating spoken replies with AI models; storing call transcripts, call summaries and booking records; looking up a caller's previous bookings and your notes about them so the host can recognise returning guests; sending and receiving text messages; syncing bookings with any booking system you connect; and storing, displaying and deleting this data. We do not record conversations with the AI host. If the host can't answer a call, the caller can leave a voicemail of up to two minutes: we record it, transcribe it, store the text as a message for you and then delete the recording, normally within minutes; if transcription fails, we keep the recording until a later try succeeds.
Duration. For as long as you use Sonno, and afterwards until the data is deleted as set out below.
Data subjects. People who call your restaurant; guests and the people they book for; people on your waitlist; and your staff, where they appear in calls, notes or transfers.
Types of personal data. Names; phone numbers; email addresses where given; booking details (date, time, party size, table, status, special requests); what callers say during calls, as transcripts and summaries; messages left for you, including voicemail recordings until they are transcribed; text messages sent and received, and text opt-outs; and your guest notes and guest-book details (such as preferences, occasions and visit history).
Special category data. Callers and your staff may record allergies, dietary requirements or accessibility needs, which can be health data, and callers may say other sensitive things during a call. The Service is not designed to ask for special category data beyond what a booking needs.
Your instructions
We process Customer Personal Data only on your documented instructions. Those instructions are the Terms, this DPA, how you configure Sonno, and what you and your staff do in the dashboard. We will tell you if we think an instruction breaks Data Protection Law. We may also process Customer Personal Data where UK law requires us to; if so, we will tell you first unless the law forbids it.
Your duties as controller
You are responsible for your use of Sonno complying with Data Protection Law. In particular, you:
- give your callers and guests your own privacy notice that tells them their calls to your restaurant may be answered by an AI system, that calls are converted to text and summarised (and that the audio is not kept, apart from a voicemail, which is recorded until it is transcribed), that booking texts are sent, and that providers including some in the United States process their data on your behalf. Sonno's greeting does not say this by default; if you want callers told at the start of each call, ask us and we will add it to your greeting;
- have a lawful basis for the processing, including a condition for any health data such as allergies;
- make sure you are allowed to send the texts you switch on, in particular review requests;
- keep the information you give Sonno accurate, and only ask it to collect what you need; and
- respond to requests from your callers and guests to exercise their data protection rights.
A suggested starting point for your privacy notice is at the end of this page.
Our duties as processor
- We make sure everyone at Sonno who can access Customer Personal Data is bound by confidentiality.
- Our staff access your data only to provide the Service to you: to support you, investigate and fix problems (including by reviewing call transcripts), and keep the Service secure.
- We do not use Customer Personal Data to train AI models, and we do not sell it or use it for our own marketing.
- We take the security measures described below, as required by Article 32 of the UK GDPR.
- We use sub-processors only as described below.
- We help you, taking into account what we can reasonably do, to respond to requests from people exercising their rights, to keep data secure, to deal with personal data breaches, and with data protection impact assessments and any consultation with the Information Commissioner's Office. If a caller or guest contacts us directly about their data, we will pass the request to you without undue delay.
- We make available the information you reasonably need to show that we meet this DPA, and allow audits as described below.
Security
The measures we take today include:
- encryption in transit for the dashboard, our APIs and our connections to providers;
- storage in a managed database in the European Union that is encrypted at rest by our provider;
- no recording of conversations with the AI host: calls are converted to text as they happen, and a voicemail recording is deleted once it is transcribed;
- log-in for every dashboard user, with each restaurant able to see only its own data, and owner-only controls over who has access;
- access by Sonno staff limited to the people who need it to run and support the Service;
- signed links for guests managing their own bookings, and authenticated connections between our systems; and
- deletion of our operational logs after 14 days.
We may change these measures, but not in a way that lowers the overall level of protection.
Sub-processors
You give us general authorisation to use sub-processors. We have a written contract with each one that protects Customer Personal Data to the standard required by Data Protection Law, and we remain responsible to you for their work. Our current sub-processors are:
- OpenAI (United States): the AI voice, real-time transcription and the language models that handle calls, transcribe voicemails, write call summaries and classify calls.
- Twilio (United States): phone numbers, carrying calls, holding voicemail recordings until they are transcribed, and sending and receiving text messages.
- Supabase (database hosted in Ireland, EU): our database, where all Customer Personal Data is stored.
- Railway (servers in the Netherlands, EU): hosting for the Sonno application and the service that connects calls to the AI.
- Cloudflare (global network): website traffic, network security and scheduled jobs.
- Resend (United States): emails to your staff, such as daily summaries and notifications, which can include guests' names and booking details.
If you connect another booking system, such as TheFork, we send booking details to it and receive them from it on your instruction. It is your provider rather than ours.
We also use Stripe (payments) and Google (public information about restaurants, and maps). They process data about your business and our billing, not your callers or guests.
We will email you at least 30 days before we add or replace a sub-processor. If you object on reasonable data protection grounds, tell us within that period; we will try to address the objection, and if we can't, you may cancel your subscription with effect from the change.
International transfers
Customer Personal Data is stored in the European Union, which the UK recognises as providing adequate protection. Some sub-processors, and Sonno AI, Inc., a Delaware corporation itself, are based in the United States, so Customer Personal Data is also transferred to and accessed from there.
Where a transfer is not covered by UK adequacy regulations (including the UK Extension to the EU-US Data Privacy Framework, where the recipient is certified), it is made under the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, which are incorporated into this DPA by reference.
Personal data breaches
We will tell you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, with the information you need to meet your own obligations (including any report to the ICO), as far as we have it. We will update you as we learn more and take reasonable steps to contain the breach and reduce its effects.
Retention and deletion
While you use Sonno, we keep Customer Personal Data for as long as you keep it in your account: we do not delete bookings, call transcripts, summaries, messages or guest records automatically. You can ask us at any time to delete particular records, or everything we hold about a particular guest, and we will do so.
When your subscription ends, you can ask for a copy of your data within 30 days, which we will provide in a common format. We then delete Customer Personal Data within 30 days of the end of your subscription unless the law requires us to keep it. Copies in our providers' backups are overwritten on their normal schedule, within 7 days.
Audits
On request, we will answer reasonable questions and provide documents about how we protect Customer Personal Data. If that is not enough to show we meet this DPA, you (or an independent auditor bound by confidentiality) may audit our compliance, once a year unless a regulator requires more, on at least 30 days' notice, during business hours and at your cost. Audits must not give access to other customers' data.
Liability and duration
Each party's liability under this DPA is subject to the limits in the Terms. This DPA lasts for as long as we process Customer Personal Data for you.
A privacy notice starting point
You are responsible for your own privacy notice. As a starting point, you could add something like this to it and adapt it to your restaurant (it is not legal advice):
“Calls to our restaurant may be answered by Sonno, an AI phone host that works on our behalf. It helps you book, change or cancel a table and answers common questions. Your call is converted to text and summarised so our team can see what was arranged; the audio is not kept. If you leave a voicemail, it is recorded, turned into text for our team and then deleted. We use your name, phone number and booking details to manage your booking and to text you about it; reply STOP to stop texts. Sonno and its providers, some of which are in the United States, process this information for us under a data processing agreement. We keep it for as long as we need it for these purposes. To ask about or exercise your rights, contact us at [your contact details].”
Contact
Questions about this DPA, or data protection requests: [email protected].