Privacy Policy
Last updated: 12 July 2026
1. Introduction
This Privacy Policy explains how personal data is collected, used, stored, and shared when you use websites, web applications, mobile applications, tablet kiosk apps, booking widgets, APIs, and related services operated under the Yiasemis Collection brand (together, the “Services”). The Services are a modular hospitality platform whose products include Table Circuit, Clock Hawk, PayVigil, Marketing Hub, Spa Booking, and additional modules described in our Apps section.
Depending on how you interact with us, different companies may act as controller (they decide why and how data is used) or processor (they handle data on another party's instructions). Where a restaurant, hotel, spa, or other venue or employer (“Venue”) uses our software to run their business, that Venue is typically the controller of guest and staff data processed in their account, and we process such data on documented instructions as a processor. Where we determine the purposes of processing for our own operations (for example account administration, security monitoring of our platform, or product analytics tied to our legitimate interests), we act as a controller. If you are unsure who is responsible in your case, contact us using the details at the end of this policy and we will help route your request.
This policy is written to align with common requirements under the EU and UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and comparable laws. It does not waive protections that mandatory local laws grant you.
2. Products this policy covers
This single policy covers every module on the platform. Availability of each module depends on a Venue's subscription and your role. In summary:
- Table Circuit — table booking, floor plans, functions, pre-orders, events/ticketing, deposits, and guest messaging (web plus iOS and Android apps).
- Clock Hawk — rotas, clock-in/out, timesheets, absence, training, and HR records (web), with a locked-down Clock Hawk Kiosk tablet app for on-site PIN clock-in and photo verification.
- PayVigil — suppliers, invoices, payments, subscriptions, financial alerts, and optional email-inbox sync (web).
- Marketing Hub — marketing subscriber lists and consent management (web).
- Spa Booking — treatment bookings, therapists, rooms, and a public booking widget (web).
- Membership, PMS, EPOS, Insights, and Room Maintenance — planned or in-development modules; sections below apply once they begin processing personal data.
3. Categories of data we collect
We may process the following categories of personal data, depending on your role:
- Account and profile: name, email address, phone number, job title or role, organisation, username, password hash, security preferences, profile photo if you upload one, language and time zone, and marketing preferences where applicable.
- Authentication and security: sign-in logs, device or session identifiers, IP address, multi-factor authentication factors (for example TOTP seeds managed by our auth provider), trusted-device records, IP allow-lists, and fraud-prevention signals.
- Reservation and guest data: reservation details (date, time, party size, table or area, special requests), guest contact details, dietary and allergen information, notes entered by staff, waitlist entries, and event or ticket registrations.
- Workforce and HR data: employment details, rotas and shifts, clock punches and breaks, timesheets, absence and leave records, training results, and HR profile information (see the Clock Hawk entry in Section 4 and Section 5 for sensitive categories).
- Financial and supplier data: invoices, payment records, supplier and agreement details, subscription and direct-debit schedules, and organisation or supplier bank details used for payment-file export.
- Payments: when payments or card storage are enabled, our payment partners (such as Stripe) process card numbers and verification data. We typically receive limited tokens, last four digits, brand, expiry, and transaction status — not full card numbers.
- Communications: guest and staff messages sent through the platform, messages you send to support, feedback forms, records of consents or legal notices you accept, and — where you enable inbox sync in PayVigil — the content of connected email accounts.
- Images: optional profile and therapist photos, and staff photo verification images captured at kiosk clock-in/out (see Section 5).
- Location: approximate location derived from IP, and — where a Venue enables it — precise GPS coordinates captured on a web clock punch (see Section 6).
- Technical and usage data: browser type, operating system, app version, crash diagnostics, and product usage events used to maintain, secure, and improve the Services.
- Widget and public booking flows: data you submit when booking as a guest, including contact fields required by the Venue.
4. Data by product module
The following describes, per module, the personal data typically processed. Full, per-app breakdowns are also available in our Apps section.
Table Circuit (reservations)
Guest contact and identity (name, email, phone), dietary and allergen information, reservation history and notes, no-show records, marketing consent where opted in, payment tokens and metadata via Stripe, guest and staff message content, and — in the mobile app — push-notification tokens and session data. Where a Venue uses the mobile app's staff onboarding flow, it may also collect Clock Hawk employee data (see below).
Clock Hawk (workforce & HR)
Staff identity and employment details (name, role, team, contract type, pay rate); HR and right-to-work records (date of birth, address, tax/NI, passport, visa status, ID documents); payroll bank details (bank name, sort code, account number); emergency contact details; rota, shift, and time-record data (punch timestamps, breaks, corrections); geolocation on web punches where enabled; facial images captured at kiosk clock-in/out for attendance audit; sickness reasons, absence notes, and supporting documents; training quiz scores, completion dates, and signed contract evidence; and kiosk device registration tokens. See Sections 5 and 6 for sensitive categories and location data.
PayVigil (finance)
Supplier business contacts (names, emails, websites, contact persons); financial records (invoice amounts, VAT, payment history, agreement spend); organisation and supplier bank details for payment-file export; email bodies and attachments from inboxes you connect; and security data such as two-factor factors, trusted-device metadata, and whitelisted IP addresses.
Marketing Hub
Marketing contact details (email, name); consent metadata (subscribe/unsubscribe timestamps and source); and optional linkage to a reservation guest profile. Marketing Hub currently manages subscriber lists and consent only; it does not yet send campaigns or perform open/click tracking.
Spa Booking
Guest contact details (name, email, phone; optional gift-recipient name); booking notes; treatment selections, durations, and prices; therapist profile photos; and payment amounts and status via Stripe together with therapist commission records. Spa Booking is not designed to hold clinical or medical records.
5. Sensitive & special-category data
Some Services can process data that may be treated as sensitive or “special category” under GDPR and similar laws. Where this occurs, the Venue or employer is generally the controller and is responsible for any consent or additional condition required by law. We process such data only on their instructions and apply heightened safeguards.
- Facial images (photo verification): the Clock Hawk Kiosk can capture a staff photo at clock-in/out to verify attendance. Images are stored in a private, access-controlled bucket and are viewable only by authorised managers. Depending on how they are used, facial images may be treated as biometric data in some jurisdictions; where that is the case, the employer/Venue is responsible for obtaining any required staff consent, and photo verification can be disabled per venue.
- Right-to-work and identity documents: Clock Hawk HR profiles may hold passport country and expiry, visa status, and uploaded ID documents required for employment compliance.
- Health-adjacent data: Clock Hawk absence and sickness records may include reasons or uploaded supporting documents, and reservation or spa notes may include allergen or dietary information. Please avoid entering clinical or medical detail in free-text notes where it is not required.
- Financial account details: payroll bank details and supplier or organisation bank details are treated as sensitive and access-restricted.
6. Location data
We derive approximate location from IP address for security and analytics. In addition, Clock Hawk supports optional precise GPS capture on a web clock punch when a Venue enables geofenced locations and the relevant staff setting; the browser will ask for permission before any coordinates are recorded. Coordinates, where captured, are stored with the punch to confirm the punch occurred at an approved site. Clock-ins made on the Clock Hawk Kiosk tablet do not transmit GPS coordinates.
7. Where data comes from
We obtain personal data from:
- Information you provide directly;
- Venues, employers, and authorised users who administer accounts on your behalf;
- Automated technologies when you use our apps and sites;
- Email accounts you choose to connect (PayVigil inbox sync);
- Service providers who assist with hosting, email delivery, analytics, or payments;
- Publicly available sources only where permitted and relevant (for example company registrations for billing verification).
8. Purposes and legal bases (EEA, UK, and similar jurisdictions)
Where GDPR-style rules apply, we rely on one or more of the following legal bases:
- Contract (Art. 6(1)(b)): providing the Services you or your Venue requested, including reservations, rotas and timekeeping, invoicing, messaging, authentication, and support.
- Legitimate interests (Art. 6(1)(f)): securing the platform, detecting abuse, improving features, analysing aggregated usage, and managing business operations, balanced against your rights.
- Legal obligation (Art. 6(1)(c)): tax, accounting, employment, right-to-work, or regulatory compliance where applicable.
- Consent (Art. 6(1)(a)): optional cookies, marketing communications, GPS location capture, and (where applicable) photo verification, requested separately. You may withdraw consent at any time without affecting prior lawful processing.
- Employment and special-category conditions (Art. 9): where sensitive data is processed, the Venue/employer relies on an appropriate Article 9 condition (for example employment law obligations) as controller.
- Vital interests or public task only in rare cases required by law.
11. International transfers
Our infrastructure or subprocessors may be located outside your country, including in the United States or the European Economic Area. Where GDPR applies, we implement appropriate safeguards such as Standard Contractual Clauses approved by the European Commission, supplemented by technical and organisational measures. You may request a copy of relevant transfer mechanisms by contacting us.
12. Retention
We retain personal data only as long as necessary for the purposes described, including to satisfy legal, accounting, or reporting requirements. Retention periods vary by data category: security logs may be kept for months; contract, employment, payroll, and billing records for years as required by law; guest reservation data and staff time records may be retained according to Venue configuration and statutory hospitality, employment, or tax rules. Photo-verification images are retained per Venue configuration for attendance-audit purposes and then deleted. When data is no longer needed, we delete or anonymise it where feasible.
13. Security
We implement technical and organisational measures appropriate to the risk, including encryption in transit, access controls, role-based permissions, private storage buckets for sensitive files and images, logging, multi-factor authentication options, and secure development practices. No method of transmission or storage is completely secure; if you believe your interaction with us has been compromised, notify us promptly.
14. Your rights
Depending on your location, you may have rights to access, rectify, erase, restrict, or object to certain processing, and to data portability. You may also lodge a complaint with a supervisory authority. Where we act as processor for a Venue or employer, we may need to forward your request to that party for action on their instructions.
To exercise rights against us as controller, email privacy@yiasemis.com. We will verify your identity before fulfilling requests and respond within the timelines required by applicable law (often within one month, extendable where permitted). To close an account or delete data, see our Account & data deletion page.
15. California residents (CCPA/CPRA)
California residents may have the right to know, delete, and correct personal information, and to opt out of certain “sharing” or “selling” as defined by California law. We do not sell personal information for money. Where targeted advertising uses personal information in scope of “sharing,” we will honour opt-out signals such as the Global Privacy Control where required once our cookie tooling is configured for your deployment.
You may designate an authorised agent; we may require proof of authorisation. We will not discriminate against you for exercising privacy rights.
16. Other regions
If you reside in Brazil (LGPD), Canada, Switzerland, Japan, South Korea, Australia, or other jurisdictions with privacy laws, you may have comparable rights. Contact us and we will respond in line with applicable requirements.
17. Children
The Services are not directed to children under 16 (or the higher age required locally). Venues should not collect children's data through the Services except where legally permitted and with appropriate consent. If you believe we have collected a child's data inappropriately, contact us for deletion.
18. Automated decision-making
We do not use personal data for solely automated decisions that produce legal or similarly significant effects unless we expressly notify you, explain logic, and provide meaningful human review rights where required. Clock Hawk features such as rota conflict checks and clock exceptions surface information to human reviewers and do not make final decisions about you automatically.
19. Changes
We may update this Privacy Policy to reflect product, legal, or regulatory changes. We will revise the “Last updated” date and, where changes are material, provide additional notice (for example by email or in-product banner).
20. Contact
Questions about this Privacy Policy or our privacy practices: privacy@yiasemis.com.