Privacy

Privacy Policy

This policy explains the personal information Leora may process, why it is used, the organisations involved, and the choices and rights available to people in the UK.

Last updated: 25 August 2026

This is a launch-stage privacy policy for Leora. It describes the current technical architecture and does not claim regulatory certification. The formal operator identity, contracts, retention schedule and international-transfer assessment require legal review before general launch.

Who we are

Leora is a hospitality software platform. No canonical registered company name, company number or registered office is currently published in the product repository, so those details are not invented here. Privacy questions can be sent to admin@leorahq.com.

When Leora is controller or processor

Leora is likely to act as a controller for account administration, public website enquiries, platform security, Leora support and internal administration. For much of the information about a participating business's customers, Leora is designed to process information on that business's instructions. The precise controller and processor roles depend on the circumstances and final contracts and are marked for legal review.

Information we may process

Business users

Customers of participating businesses

Business knowledge

AI and provider information

Operations and security

Why information is used and likely lawful bases

InformationPurposeLikely basisRetention
Account and business-user dataAuthenticate accounts and provide the contracted serviceContract; legitimate interests for securityRETENTION_POLICY_REQUIRED
Customer conversations, bookings and relationship recordsRespond to enquiries and operate services for the participating businessDetermined by the business controller; commonly contract or legitimate interestsRETENTION_POLICY_REQUIRED
Security and audit recordsProtect the platform, investigate incidents and meet legal dutiesLegitimate interests; legal obligation where applicableRETENTION_POLICY_REQUIRED
Optional analytics or marketingMeasure or promote Leora where enabledConsent where UK PECR/UK GDPR requires itNo optional tracker is currently installed

The correct lawful basis can depend on context and the participating business's instructions. Final determinations are LEGAL_REVIEW_REQUIRED.

AI transparency

AI assists with customer responses, business insights and drafts. Depending on the feature and the material provided, personal information may be processed by an AI provider. Recorded business information controls important factual responses, uncertainty is surfaced, and supported sensitive or provider actions retain human review. AI output does not replace the responsible business's judgement.

Providers and recipients

Information is sent only in the context of the feature being used; it is not sent to every provider. A formal subprocessor register, processor agreements and international-transfer assessment remain LEGAL_REVIEW_REQUIRED.

Retention and deletion

Leora does not publish arbitrary retention periods that are not enforced. Formal schedules, enforcement jobs, backup-deletion handling and conversation/Customer Passport deletion procedures remain RETENTION_POLICY_REQUIRED. Some current customer controls archive a relationship while preserving historical operational records; this is not represented as complete erasure.

Your rights

Depending on the circumstances, UK data-protection law may provide rights of access, correction, erasure, restriction, objection and portability. Consent can be withdrawn where processing relies on consent. Rights may be limited by lawful exemptions and should usually be directed to the business responsible for the relevant customer relationship. You may also complain to the UK Information Commissioner's Office at ico.org.uk.

Cookies and similar storage

Optional categories are off until chosen. The consent choice itself is stored first-party so Leora can respect it. Authentication and essential security storage are not removed when optional consent is withdrawn. See the Cookie Policy or use Cookie settings in the footer.

Security and incidents

Leora uses tenant-aware access controls, server-side authority resolution, protected provider credentials and audit mechanisms in supported workflows. No system is described as absolutely secure. The formal breach-response process and external notification procedure remain launch requirements.

Changes and contact

Material changes will use a new consent-policy version where renewed choice is appropriate. Contact admin@leorahq.com with questions or requests.