Privacy Policy
How we handle personal data, and the rights you have under the GDPR.
Version 1.1 · 12 August 2026This policy explains how Abbott & Raihi B.V., trading as House of EDA ("we", "us"), collects and uses personal data. It applies to our website houseofeda.ai, to our sales and support activities, and to the accounts of salons who subscribe to our AI assistant service.
- Controller
- Abbott & Raihi B.V.
- Trading as
- House of EDA
- Address
- Nicolaas Witsenkade 31G, 1017 ZT Amsterdam, Netherlands
- Chamber of Commerce
- KVK 34279745
- VAT number
- NL818307572B01
- Privacy contact
- info@houseofeda.ai
1. Two different roles
It matters which role we are in, because it decides who is responsible for what.
- We are the controller for data about our own website visitors, prospects and subscribing salons — the people we sell to and support. That is what this policy covers.
- We are a processor for the personal data of a salon's own clients — the people who message that salon and whose enquiries our assistant handles. The salon decides why and how that data is used; we act on its instructions. Those terms are in our Data Processing Addendum, and the salon's own privacy notice governs how it treats its clients.
2. What we collect and why
2.1 When you visit the website
We do not use analytics, advertising or tracking cookies. There is no cookie banner because we set no cookies.
We store three items in your browser's local storage, purely so the site works the way you left it: your chosen language (eda_lang), your chosen currency (eda_cur) and a random demo-chat session identifier (eda_demo_sess). These stay on your device, are not personal identifiers, and you can clear them at any time through your browser settings.
Our hosting provider processes your IP address and standard request data in server logs, as any web server must, to deliver the site and protect it from abuse.
2.2 When you use the "Try Elif" demo chat
The demo assistant on our website is a fictional salon used for demonstration. What you type is sent to our server, processed by our AI provider to generate a reply, and stored so we can review and improve the assistant. Please do not type real personal details, or anything confidential, into the demo.
- Data: the messages you send, the replies generated, a random session ID, and a timestamp.
- Legal basis: our legitimate interest in demonstrating, monitoring and improving the product (Art. 6(1)(f) GDPR).
- Retention: 12 months, then deleted.
2.3 When you enquire or become a customer
| Data | Why | Legal basis |
|---|---|---|
| Name, business name, email, phone, country | To answer enquiries, prepare quotes and set up your account | Steps prior to a contract, and performance of the contract — Art. 6(1)(b) |
| Account and configuration data (salon details, services, prices, opening hours, assistant settings) | To build, run and support your assistant | Performance of the contract — Art. 6(1)(b) |
| Billing data (company details, VAT number, invoices, payment status) | To take payment and meet our tax obligations | Contract, and legal obligation — Art. 6(1)(b) and (c) |
| Support correspondence | To resolve issues and keep a record of what was agreed | Contract, and our legitimate interest in a support record — Art. 6(1)(b) and (f) |
| Marketing emails to business contacts | To tell you about the service and relevant updates | Consent, or legitimate interest in business-to-business marketing — Art. 6(1)(a) or (f). You can opt out at any time. |
We never see your card details. Payments are handled by Stripe on a page hosted by Stripe. Card numbers do not reach our servers.
3. Who we share data with
We use the following providers. Each processes personal data only to deliver its part of the service, under a contract with us.
| Provider | Purpose | Location |
|---|---|---|
| Anthropic | The AI model that generates assistant replies | United States |
| OpenAI | Voice-note transcription (higher tiers) | United States |
| Twilio | WhatsApp message delivery | United States / Ireland |
| Meta Platforms | WhatsApp Business and Instagram messaging | Ireland / United States |
| Railway | Application hosting and data storage | United States |
| Netlify | Website hosting and content delivery | United States |
| Stripe | Subscription payments and invoicing (EU customers) | Ireland / United States |
| Web fonts served on our pages (receives your IP address) | United States |
We also disclose data where we are legally required to — for example to tax authorities, or to our accountants and professional advisers under a duty of confidence. We do not sell personal data, and we do not share it for anyone else's advertising.
4. Transfers outside the EEA
Several of the providers above are based in the United States, so some personal data is transferred outside the European Economic Area. Where that happens we rely on the European Commission's Standard Contractual Clauses, together with the EU–US Data Privacy Framework where the provider is certified under it, and on additional technical measures such as encryption in transit. You can ask us for a copy of the safeguards that apply to a particular transfer.
5. How long we keep it
| Data | Kept for |
|---|---|
| Invoices and accounting records | 7 years — required by Dutch tax law |
| Customer account and configuration data | Duration of the contract, then 12 months |
| Enquiries that do not become customers | 24 months from last contact |
| Demo-chat transcripts | 12 months |
| Support correspondence | 3 years from the end of the contract |
| Server logs | Up to 12 months |
Salon client data that we process on a salon's behalf is governed by the Data Processing Addendum and is deleted or returned when that contract ends.
6. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you, and receive a copy;
- Rectify data that is inaccurate or incomplete;
- Erase data, where we have no overriding reason to keep it;
- Restrict or object to processing, including direct marketing — if you object to marketing we will stop, without exception;
- Portability — receive data you gave us in a structured, machine-readable format;
- Withdraw consent at any time, where we relied on consent. This does not affect processing already carried out.
Write to info@houseofeda.ai. We will respond within one month. There is no charge unless a request is manifestly unfounded or excessive.
If you are unhappy with how we have handled your data you may complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or to the authority where you live or work. We would appreciate the chance to put things right first.
7. AI, model training and human review
Our assistant is built on AI models supplied by third parties. Because this is the question people most often ask, we answer it plainly:
- We do not use your data — or your clients' data — to train AI models. Not ours, and not anyone else's.
- Our AI providers are contractually prohibited from training on it. Anthropic's commercial terms, which govern our use of their models, state that Anthropic "may not train models on Customer Content from Services". Data sent through their API is used to generate a reply and nothing else.
- People do sometimes read conversations. A salon's own team can read and take over any conversation — that is a feature of the product. Our staff may also review conversations where it is necessary to provide support, investigate a fault, or check the assistant is answering safely and accurately. Access is limited to those who need it and everyone is bound by confidentiality.
Where a plan includes voice-note understanding, the recording is transcribed by our transcription provider solely to produce the text the assistant reads.
8. Where your data is held
We are honest about this because some providers advertise EU-only hosting and we cannot claim it. Delivering an AI assistant means using AI, messaging and hosting providers that operate from the United States — they are named in section 3. Your data therefore leaves the EEA.
What protects it: the contractual safeguards in section 4, the training prohibition above, encryption in transit, and the fact that we send these providers only what is needed to produce a reply. If EU-only processing is a firm requirement for your business, tell us before you subscribe so we can be clear about whether we can meet it.
9. Automated decision-making
Our assistant generates message replies automatically. It does not make decisions that produce legal effects for you or similarly significantly affect you, within the meaning of Article 22 GDPR. A human can always take over a conversation, and every salon retains a person who can be reached.
10. Security
We take appropriate technical and organisational measures to protect personal data, including encryption in transit (TLS), access control on administrative systems, hosting with reputable providers, and limiting access to those who need it. Card data is handled entirely by our payment provider and never reaches our systems. No system is completely secure, but we take this seriously and will notify you and the supervisory authority of a personal-data breach where the law requires it.
11. Children
Our service is sold to businesses and is not directed at children. We do not knowingly collect data from anyone under 16 through this website.
12. Changes
We may update this policy as the service develops. The version number and date at the top will change. Where a change materially affects your rights we will tell subscribing customers directly.
13. Contact
Questions about this policy, or about how we handle your data:
Abbott & Raihi B.V. — Nicolaas Witsenkade 31G, 1017 ZT Amsterdam, Netherlands
info@houseofeda.ai
This policy is written in English. If we publish a translation and the two versions differ, the English version prevails.