This is a launch-stage privacy policy for Leora. It describes the current technical architecture and does not claim regulatory certification. The formal operator identity, contracts, retention schedule and international-transfer assessment require legal review before general launch.
Who we are
Leora is a hospitality software platform. No canonical registered company name, company number or registered office is currently published in the product repository, so those details are not invented here. Privacy questions can be sent to admin@leorahq.com.
When Leora is controller or processor
Leora is likely to act as a controller for account administration, public website enquiries, platform security, Leora support and internal administration. For much of the information about a participating business's customers, Leora is designed to process information on that business's instructions. The precise controller and processor roles depend on the circumstances and final contracts and are marked for legal review.
Information we may process
Business users
- Name, email, authentication and account information.
- Business profile information, configuration and support communications.
- Help & Fixes reports and operational activity associated with the workspace.
Customers of participating businesses
- Phone or other contact identifiers where a supported channel requires them.
- WhatsApp conversations, enquiries, bookings and conversation summaries.
- Customer Passport records maintained separately for each business relationship.
- Preferences that are explicitly and legitimately stored, together with consent state where applicable.
- Needs Attention handoffs and associated operational history.
Business knowledge
- Menus, prices, opening hours, policies, FAQs and website material.
- Uploaded documents and business-approved knowledge.
AI and provider information
- Coach interactions and customer-response processing where AI assistance is used.
- Model/provider request telemetry, usage records and generated drafts.
- Google Business Profile account, location and review identifiers when a business chooses to connect Google; review text and owner replies may then be processed.
Operations and security
- Audit events, request identifiers, delivery states, provider telemetry and security logs.
Why information is used and likely lawful bases
| Information | Purpose | Likely basis | Retention |
|---|---|---|---|
| Account and business-user data | Authenticate accounts and provide the contracted service | Contract; legitimate interests for security | RETENTION_POLICY_REQUIRED |
| Customer conversations, bookings and relationship records | Respond to enquiries and operate services for the participating business | Determined by the business controller; commonly contract or legitimate interests | RETENTION_POLICY_REQUIRED |
| Security and audit records | Protect the platform, investigate incidents and meet legal duties | Legitimate interests; legal obligation where applicable | RETENTION_POLICY_REQUIRED |
| Optional analytics or marketing | Measure or promote Leora where enabled | Consent where UK PECR/UK GDPR requires it | No optional tracker is currently installed |
The correct lawful basis can depend on context and the participating business's instructions. Final determinations are LEGAL_REVIEW_REQUIRED.
AI transparency
AI assists with customer responses, business insights and drafts. Depending on the feature and the material provided, personal information may be processed by an AI provider. Recorded business information controls important factual responses, uncertainty is surfaced, and supported sensitive or provider actions retain human review. AI output does not replace the responsible business's judgement.
Providers and recipients
- Supabase supplies authentication, database and storage services.
- Vercel hosts and delivers the application.
- OpenAI processes content for enabled AI features.
- Meta/WhatsApp processes supported messaging traffic.
- Google processes connected Business Profile accounts, locations and reviews.
- Resend supports transactional email where configured.
Information is sent only in the context of the feature being used; it is not sent to every provider. A formal subprocessor register, processor agreements and international-transfer assessment remain LEGAL_REVIEW_REQUIRED.
Retention and deletion
Leora does not publish arbitrary retention periods that are not enforced. Formal schedules, enforcement jobs, backup-deletion handling and conversation/Customer Passport deletion procedures remain RETENTION_POLICY_REQUIRED. Some current customer controls archive a relationship while preserving historical operational records; this is not represented as complete erasure.
Your rights
Depending on the circumstances, UK data-protection law may provide rights of access, correction, erasure, restriction, objection and portability. Consent can be withdrawn where processing relies on consent. Rights may be limited by lawful exemptions and should usually be directed to the business responsible for the relevant customer relationship. You may also complain to the UK Information Commissioner's Office at ico.org.uk.
Cookies and similar storage
Optional categories are off until chosen. The consent choice itself is stored first-party so Leora can respect it. Authentication and essential security storage are not removed when optional consent is withdrawn. See the Cookie Policy or use Cookie settings in the footer.
Security and incidents
Leora uses tenant-aware access controls, server-side authority resolution, protected provider credentials and audit mechanisms in supported workflows. No system is described as absolutely secure. The formal breach-response process and external notification procedure remain launch requirements.
Changes and contact
Material changes will use a new consent-policy version where renewed choice is appropriate. Contact admin@leorahq.com with questions or requests.