MiseOS

Privacy Policy

Effective date: [to follow] · Controller: [company legal name] (company number [number]), [registered address], trading as MiseOS. ICO registration [to follow]. · Contact: [support email].

Published draft. Complete in substance; undergoing final solicitor review. Company and registration details will be completed on incorporation. Material changes will be notified to account holders.

1. The two hats we wear

MiseOS is kitchen software used by food businesses. That means personal data flows through it in two distinct ways, and your rights route differently depending on which applies:

  1. Your MiseOS account (we are the controller). Information about you as the person or business signing up — covered by sections 2–8 of this policy.
  2. What a kitchen records in its venue (we are the processor). Names on a rota, wage rates, shift times, sign-offs in the food-safety diary, supplier contacts. The kitchen (our customer) is the controller of that data; we process it on their instructions under our Data Processing Agreement. If you are a member of staff at a kitchen that uses MiseOS and want to exercise data rights over rota, pay or diary records, your employer is the right first contact — we will assist them in responding.

2. Data we collect as controller

We do not run advertising trackers. Local storage on your device is used to make the app work offline, not to profile you.

3. Why we use it (lawful bases)

4. The AI features and your content

When you use an AI feature — asking Sous a question, photographing an invoice, importing a recipe, or having text read aloud — the content you submit is sent to the relevant AI provider (Anthropic for text intelligence; Google for voice synthesis) to generate the response, over encrypted connections and via our own server-side proxy so that provider keys are never exposed to your device. Under our agreements with these providers, API content is not used to train their models. We do not use your content to train models either. Responses are returned to your device; our proxy does not build a store of your conversations beyond the metering counts described above and the sync of features you choose to save (for example saved Sous chats within your venue).

5. Who we share data with (subprocessors and services)

We share personal data only with the providers needed to run MiseOS:

ProviderPurposeRegion
SupabaseDatabase, authentication, syncEU (Frankfurt, eu-central-1)
NetlifyHosting and serverless functionsUS/global CDN
StripePaymentsUS/EU
AnthropicAI text features (Sous, imports, invoice reading)US
Google (Gemini API)Voice synthesisUS
[email provider]Transactional email[region]

The live list, with changes, is published at /subprocessors. We do not sell personal data.

6. International transfers

Some providers process data in the United States. Where personal data leaves the UK we rely on appropriate safeguards: the UK–US Data Bridge where the provider is certified, or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses otherwise. Details per provider are available on request.

7. How long we keep it

8. Your rights

You have the rights under UK GDPR to access, rectify, erase, restrict, object, and to data portability, and the right to complain to the Information Commissioner's Office (ico.org.uk). Contact [support email] to exercise them. Remember §1: for data recorded about you by your employer in their venue, your employer is the controller and first contact.

9. Security

Encryption in transit; venue-level isolation enforced in the database (row-level security); authentication via our identity provider; provider-side encryption at rest; server-side secret management so API keys never reach the browser; daily backups; guards against bulk destructive actions. No system is perfectly secure, but security decisions in MiseOS are made venue-first.

10. Children

MiseOS accounts are for people running or working in food businesses and are not directed at children. Venue records may lawfully reference employed staff aged 16–17; their employer is the controller of those records.

11. Changes

We'll post changes here and, for material changes, notify account holders by email or in-app.

← Back to MiseOS