
Your guests trust you with a lot.We take care of it.
Hosting in the European Union, GDPR, AI disclosed as such, and a team that always stays in control.
Your guests’ datastays yours.
A number, an allergy, a birthday: what your guests entrust you with deserves the same care as their welcome.
- 01Hosted in the European UnionIn Frankfurt, Germany. The few transfers outside the EU, linked to messaging or traffic protection, are covered by the European Commission’s standard contractual clauses.
- 02GDPR compliantCollection limited to what the booking needs, your guests’ rights respected, deletion on request.
- 03Never used to train a modelYour conversations are used to reply to your guests, and nothing else.
- 04EncryptedIn transit and at rest, with strong authentication and access limited to what is strictly necessary.
- 05YoursYour data remains your property.
Our commitments, in black and white.

Your teamstays in control.
TableAgent never decides in the house’s place. An unusual request, a sensitive situation, an off-menu question: it hands over.
- 01You decide what TableAgent handles
- 02It passes to the team as soon as a request falls outside its scope
- 03Every passed-on request arrives with its full context
- 04Your team can take over any conversation
- 05Your house rules apply to every reply
- 06Every booking is visible in your software
Immediate, with the full context.
The Grill · Dubai
“I’m The Grill’s AI assistant.”
The guest knows who they’re talking to. The conversation stays natural, in the house’s tone.
Fictional example.
An AI that introduces itselfas one.
As the EU AI Act requires, TableAgent introduces itself as your house’s AI assistant. It never pretends to be a member of the team.
It’s all in writing,and we’ll send it to you.
Data processing agreement, sub-processor list and standard contractual clauses are sent to your IT lead or DPO on request.
[email protected]Data is separated by client and, within a group, by venue.
Encryption in transit and at rest, strong authentication, least privilege, web application firewall and continuous monitoring.
Logging of access and sensitive operations, daily backups, documented incident procedures.
The term of the contract plus ninety days, then deletion. At the end of the contract, export or deletion within thirty days, with a certificate.
Data processing agreement under Article 28 GDPR. Sub-processors listed in the contract, any change notified thirty days in advance.
A compliance audit is possible every year. Dedicated hosting, or hosting in your own infrastructure, on quotation.