Yes Chef AI · Legal
Privacy Policy
How Yes Chef AI Ltd uses personal data for its own purposes, and how Customer records are treated.
1. Who we are
The controller for this policy is Yes Chef AI Ltd, company number 17117657, registered in England and Wales. Contact: hello@yeschefai.co.uk.
We have not appointed a data protection officer and we have not appointed a UK or EU representative. If that changes, we will update this notice.
2. When this policy applies
This policy covers the public website at yeschefai.co.uk, account administration, billing administration, customer communications, security, and our own use of the Yes Chef AI application. It does not replace a Customer's own privacy notice for staff, workers or other people whose information the Customer enters into the Service.
3. Our roles
We are the controller when we decide why and how personal data is used for our own purposes, including:
- creating and administering user accounts;
- enquiries sent to us;
- billing and subscription administration;
- securing accounts and the Service;
- service messages about the Customer's account;
- operating this public website.
The Customer is the controller, and we are the processor, for Customer Content that the Customer stores for its own operational purposes. That includes recipes, ingredients, allergen records, due-diligence and temperature records, audits, corrective actions, evidence, staff and worker details, and optional daily fitness-to-work declarations if the Customer enables that feature. Those activities are described in the DPA, not as our own independent purposes.
4. Personal data we use as controller
- Identity and contact data: name, work email, role and organisation.
- Account data: login identifiers, plan selected, terms-acceptance time and version.
- Venue or site names the Customer associates with the account.
- Enquiry and support correspondence sent to us.
- Billing and subscription data: plan, Stripe customer and subscription identifiers, payment status. We do not store payment-card numbers; Stripe handles card data.
- Technical and security data: login, session, device, browser, IP address, role/site context, audit and error records.
If you send us an email that contains other personal data, we will use it to deal with that correspondence.
5. Purpose and lawful-basis table
UK GDPR requires a lawful basis for each controller purpose. Contract in the table below means Article 6(1)(b) where the processing is necessary for a contract with the individual user, or to take steps at that person's request before a contract. Legitimate interests means Article 6(1)(f). Legal obligation means Article 6(1)(c).
| Purpose | Personal data | Lawful basis | Legitimate interest (if used) | Retention criterion |
|---|---|---|---|---|
| Create and administer accounts | Name, email, role, organisation, login identifiers | Contract with the individual user; legitimate interests for business-account administration | Providing a requested business software account to the Customer's authorised users | For the life of the account, then as needed to close it and keep a limited security/accounting record |
| Provide paid access and billing administration | Plan, subscription identifiers, payment status, billing email | Contract; legal obligation for accounting records | — | For the subscription and then for as long as UK accounting and tax rules require us to keep related records |
| Answer enquiries | Contact details and message content | Legitimate interests; contract if the person is already a user | Responding to a business enquiry we have been asked to handle | For as long as needed to complete the enquiry and any related follow-up |
| Security, abuse prevention and debugging | Login, session, IP, device/browser, role/site context, error logs | Legitimate interests | Keeping accounts and the Service safe, investigating incidents, and preventing fraud or misuse | For as long as needed for security investigation and then a limited period for defending legal claims |
| Service messages about the account | Name, email, subscription status | Contract; legitimate interests | Telling users about access, payment status and security matters affecting their account | While the account is active |
| Record Terms and Privacy acceptance | Acceptance time and document version | Legitimate interests; legal obligation where we must show the contract was formed | Showing that the Customer agreed to the current contract documents | For the life of the account and a period afterwards as needed to evidence the contract |
| Operate the public website | Technical request data processed by our host to deliver the pages | Legitimate interests | Publishing the website and keeping it available | Only as needed to deliver the page; this public site does not set its own analytics cookies |
We do not rely on consent as the lawful basis for the controller purposes above. If we later send electronic marketing that requires consent under PECR, we will obtain it and record it. You can object to direct marketing at any time.
6. Where data comes from
- Directly from the user, including at signup, onboarding and in account settings.
- From a Customer administrator who invites or configures users.
- From Google, if the user chooses Google sign-in through our authentication provider.
- From Stripe, for payment status and subscription identifiers.
- From our hosting, authentication and logging systems, for technical and security data.
7. Special-category data
The Service can store daily fitness-to-work declarations (including symptom information such as diarrhoea, vomiting, fever, jaundice, skin lesions or discharge) if a Customer enables that optional feature. That information is health data. For that processing, the Customer is the controller. We process it only as processor under the DPA, on the Customer's instructions, with access limited to delivering the feature.
We do not use those declarations for our own marketing, profiling or independent purposes. We do not currently send fitness-to-work declarations to AI providers as part of a dedicated health-check workflow. If a user pastes health information into an AI prompt, that content may be processed by the AI provider to return the requested output. The Customer must not do that unless it has a lawful basis and an Article 9 condition for its own processing.
8. Recipients
We use specialist providers to operate the Service. They are not all subprocessors of Customer Content. Current providers, by function, are:
| Provider | Function | Role in this notice |
|---|---|---|
| Vercel | Application and website hosting | Processes technical data to deliver the Service; also hosts Customer Content in transit |
| Supabase | Authentication, database and file storage | Stores account data and Customer Content |
| Stripe | Payment and subscription processing | Handles card data and billing; we receive subscription and payment-status information |
| Brevo | Transactional email delivery | Sends account and service emails |
| Anthropic | AI processing for selected features | Receives prompts, images or source material the Customer submits to those features |
| Groq | AI processing for selected chat/agent features | Receives prompts and conversation context the Customer submits to those features |
| Microsoft Azure (Document Intelligence) | Document extraction for invoice/receipt features where used | Receives documents the Customer submits to that feature |
| Upstash | Rate limiting for PIN and similar controls | Processes technical identifiers needed to apply those controls |
| Optional sign-in | Authenticates the user if they choose Google sign-in |
We may also disclose information if the law requires it, to protect rights or security, or to a buyer in a business transfer, subject to appropriate safeguards. A current list of processors used for Customer Content is in the DPA.
9. International transfers
Some providers may process personal data outside the United Kingdom. Public information associated with those providers indicates that hosting and AI processing may involve the United States or other locations, and that database hosting may be configured by region.
Where UK law treats a transfer as a restricted transfer, we will only make it if it is covered by UK adequacy regulations (sometimes called data bridges), or by appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, together with a transfer risk assessment where required, or if an exception in UK GDPR Article 49 applies. We do not state in this notice that a particular signed transfer contract is already in place with every provider. You can contact us for the current position on a specific transfer.
10. Retention
We do not currently publish fixed day-counts for every record type. Controller data is kept only for as long as needed for the purpose in the table above, including contract, accounting, security and legal-claim needs.
If a user deletes their personal account, we anonymise that user's name and email in the account record. Organisation operational records may be retained for the Customer, because they are the Customer's records. If a Customer asks us to close an organisation, we record that request and handle Customer Content in line with the DPA. We do not promise immediate erasure from every backup copy.
Customer Content retention as processor follows the Customer's instructions and the DPA.
11. Your rights
Depending on the circumstances, UK data-protection law may give you rights of access, rectification, erasure, restriction, portability and objection, and rights in relation to automated decision-making. Not every right applies to every processing activity. The right to erasure is not absolute. Portability generally applies where we rely on consent or contract and the processing is automated.
You have an absolute right to object to use of your personal data for direct marketing.
If the data is Customer Content, we will usually direct the request to the Customer (the controller) or help the Customer respond. To exercise rights about our controller processing, email hello@yeschefai.co.uk.
12. Automated decision-making
The Service uses AI-assisted generation, extraction and calculation. Those features produce outputs for the Customer to review. We do not use solely automated decision-making that produces legal or similarly significant effects about an individual as described in UK GDPR Article 22. Fitness-to-work gates in the product are applied according to the Customer's configuration and human review or override by the Customer's managers.
13. Direct marketing
We send transactional and service emails needed to operate accounts. We do not currently run a separate advertising or newsletter programme on the public website. If we send electronic marketing, we will do so in line with PECR and UK GDPR, and every marketing email will include a way to opt out.
14. Cookies
The public website does not currently set cookies or use localStorage or sessionStorage for analytics or advertising. See the Cookie Policy. The logged-in application uses strictly necessary cookies and similar technologies for authentication, session security and user-requested settings.
15. Security
We use technical and organisational measures designed to protect personal data, including authentication, access controls, tenant separation, HTTPS in production, and supplier controls appropriate to the nature of the Service. No internet service can guarantee that personal data will never be accessed without authorisation.
16. Children
The Service is a business product. It is not directed at children.
17. Changes
We may update this policy as the Service or the law changes. The current version is shown at the top of this page.
18. Complaints
Contact us first at hello@yeschefai.co.uk. You also have the right to complain to the Information Commissioner's Office. Current complaint guidance is on the ICO complaints page.
Company details
Yes Chef AI Ltd
Registered in England and Wales
Company no. 17117657
Registered office: 71–75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
hello@yeschefai.co.uk