Legal

Privacy Policy.

Last updated: July 2026

1. Who we are and our roles

This privacy policy is issued by Fenna Ltd, Bond House, 216 Sheriff Street Upper, Coopers Cross, Dublin 1, D01 K1W5, Ierland ("Fenna", "we"). Fenna provides an AI receptionist for restaurants, cafes and salons. For the data we process through our own website, demo requests and your account, we act as the data controller. For the data of your business's callers and guests the roles are reversed: you, our customer, are the controller and we process that data solely on your instructions as a processor, as set out in our data processing agreement. You can reach us with any privacy question at privacy@heyfenna.com.

2. Data from the website and demo

When you visit our website, we only process what is technically necessary to keep the site working properly and securely. If you request a demo or contact us, we process the details you leave with us, such as your name, your business name, your phone number and your email address. We use them solely to run the demo and answer your enquiry.

3. Your account data

When you create an account, we process your name, email address and login credentials, together with the business details you enter during onboarding, such as opening hours, capacity and your receptionist settings. We also process usage data from the service, such as call statistics and reports, and invoicing and payment details where applicable.

4. Data about your callers and guests

When Fenna answers the phone for your business, we process the caller's data: their phone number, the transcript of the conversation, the call recording if that feature is switched on for your business, and the booking or appointment details the caller provides, such as name, party size, date and time. Confirmations sent by SMS or WhatsApp are part of this too. We process this data solely on the business's instructions; the business is the controller for it.

5. Call recording and AI disclosure

Callers are told at the start of the call that they are speaking with an AI assistant. Call recording is a setting that can be switched on or off per business; where it is on, this is also announced at the start of the call. Transcripts and any recordings are available to you as the business in your dashboard, so you can check what was agreed.

6. Purposes and legal bases

For website and demo data, the legal basis is taking steps at your request prior to entering into a contract, alongside our legitimate interest in answering enquiries and keeping the site secure. For account data, the basis is the performance of our agreement with you, and for invoicing a legal obligation. For caller and guest data, you as the controller determine the basis; in practice this is usually the performance of the booking or appointment the caller requests. We do not use this data for our own purposes and we never sell it.

7. Retention

We keep call recordings and transcripts for 90 days by default, booking data for 180 days and demo and lead data (phone number) for 30 days. After that they are automatically deleted or anonymised, unless the law requires us to keep them longer. Account data is kept for as long as you are a customer; after termination we delete or anonymise it, except for data we are legally required to retain, such as invoices.

8. Sub-processors

We engage a small number of carefully chosen sub-processors to deliver the service, each under a data processing agreement with obligations equivalent to our own: a database and account platform (EU-Ireland), providers for speech technology, language models and speech recognition (US), telephony and messaging providers (US/EU), a hosting provider (US/EU), an email provider (US) and a payment provider (EU). A current list is available on request via privacy@heyfenna.com.

9. International transfers

Your core data, the database holding accounts, bookings and transcripts, is stored in the EU (Ireland). Some of our sub-processors are located outside the EEA, mainly in the US, including speech, AI and telephony providers. For those transfers we rely on appropriate safeguards: the Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented by the EU-US Data Privacy Framework where the party concerned is certified under it.

10. Cookies

Our website only uses strictly necessary cookies, for example to keep you signed in. We do not use tracking, advertising or marketing cookies, and we do not place third-party cookies for such purposes. That is also why you will not see a cookie banner on our site: strictly necessary cookies do not require consent.

11. Security

We protect your data with appropriate technical and organisational measures, including encryption of traffic, strict access control and strict separation of each customer's data in the database. The core database runs in the EU. No system is ever completely watertight; should a data breach occur that poses a risk to you, we will inform you without undue delay.

12. Your rights

You have the right to access, rectify, erase and port your data, to restrict processing, to object to processing based on legitimate interest, and to withdraw any consent you previously gave. Send your request to privacy@heyfenna.com; we respond within the statutory one-month period. If you are unhappy with how we handle your data, you can lodge a complaint with the Data Protection Commission (Ireland) or the Autoriteit Persoonsgegevens (Netherlands).

13. Rights of callers and guests

If you are a guest or caller of a business that uses Fenna, that business is the controller for your data. Please direct requests for access, rectification or erasure to the business first; we then help the business carry out your request. If you cannot resolve it with the business or do not know who to contact, email privacy@heyfenna.com and we will forward your request to the right business and assist where we can.

14. Minors, changes and contact

Fenna is a business service and is not directed at children; we do not knowingly collect data from children under 16 for our own purposes. If you believe this has happened anyway, email privacy@heyfenna.com and we will delete the data. We may update this privacy policy, for example when we add features or when regulations change; the current version is always available on our website with the date of the last change, and we will notify our customers of material changes. For any questions or comments, contact Fenna Ltd, Bond House, 216 Sheriff Street Upper, Coopers Cross, Dublin 1, D01 K1W5, Ierland via privacy@heyfenna.com.

Also legal:Terms and ConditionsData Processing Agreement (DPA)Ethical AI Framework