This is proposed public text for a future U.S. Dohos service. It is not a current Privacy Notice and does not describe or authorize current processing. It cannot be activated until the Dohos legal entity, contact channels, Restaurants, Providers, data flows, retention, rights operations, jurisdictions, and release-specific behavior are verified and inserted through the controlled approval process.
01Purpose of this notice
This Privacy Notice explains how Dohos collects, uses, discloses, retains, and protects Personal Data when people:
- visit a Dohos-operated website
- create or use a Restaurant Account
- contact Dohos for sales, support, security, privacy, or other business purposes
- interact with a Restaurant through a Dohos-powered voice, web, SMS, or other approved ordering channel
- otherwise use a service that links to this notice
The activated version will identify the legal entity operating Dohos, its address, effective date, contact details, and any state-specific supplement. Those identity and contact facts are not yet approved, so this draft cannot be published as effective.
02Scope
This notice applies only to Dohos-operated services and processing expressly described here. It does not apply to:
- a Restaurant's own website, app, location, loyalty program, marketing, employment, delivery, or independent data use
- a payment Provider's independent services
- another third party's service or privacy practice
- a capability that Dohos has not activated and disclosed
A Restaurant may provide an additional privacy notice for its own practices. If you are interacting with a Restaurant, that Restaurant is responsible for its independent decisions about your information.
03Who is responsible for Personal Data
Responsibility depends on why information is processed.
Restaurant-instructed service data. For Personal Data processed only to receive, route, confirm, fulfill, support, secure, and evidence an order for a specific Restaurant:
- the Restaurant generally decides why it offers the channel and how it uses the information for its customer relationship
- Dohos processes the information for that Restaurant under the service agreement and documented instructions
Requests about a Restaurant's independent use may need to be directed to that Restaurant. Dohos will help route and fulfill requests where its agreement and applicable law require.
Dohos's own business purposes. Dohos is independently responsible for narrowly defined purposes such as:
- creating and administering Dohos Accounts
- authenticating users and managing access
- billing Restaurants for Dohos services
- maintaining security, preventing fraud and abuse, and investigating incidents
- operating, troubleshooting, and improving service reliability using minimized data
- responding to support, legal, privacy, and security requests
- managing Providers and business records
- complying with law and enforcing agreements
Dohos does not treat a broad phrase such as "improve our services" as permission for unrelated use of Restaurant or Diner content.
04Personal Data we collect
The categories depend on how you interact with the service.
Restaurant and Account information. We may collect:
- name, business email, business phone number, job title, and Restaurant affiliation
- Restaurant legal/trade name, locations, hours, contact details, menus, fulfillment settings, and authorized-user roles
- Account, authentication, session, access, and security information
- subscription, invoice, billing contact, tax, and limited payment-status information
- support, implementation, configuration, and training records
- contract, consent, notice, and administrative records
Diner and order information. We may collect information needed for the selected Restaurant transaction, such as:
- name, phone number, email, delivery address, or pickup details
- Restaurant, location, items, quantities, modifiers, price components, fulfillment choice, timing, status, and approved special instructions
- non-sensitive payment token, transaction reference, and status supplied by the approved payment Provider
- AI/voice disclosure, confirmation, correction, refusal, and human-routing events
- support, complaint, refund, dispute, and incident information
Voice and AI interaction information. For an approved voice interaction, Dohos may process audio and machine-generated text transiently to understand and respond during the session. The initial target service:
- identifies itself as an AI system
- uses only the minimum live processing needed for the Restaurant interaction
- stores structured Order Evidence together with a text transcript of the completed call for the restaurant's operational use, rather than retaining raw call audio by default
- does not create a Voiceprint or use voice to identify a person
- does not use Customer Content to train or fine-tune a general model
- provides a human or non-AI route described in the interaction
The activated notice must match the actual Provider and runtime configuration. If Dohos later proposes recording, biometrics, training, or another materially different use, it will require separate legal/product review and a new notice or consent where required.
Website, device, and service information. We may collect minimized technical information such as:
- IP address, device/browser type, operating system, language, and approximate network-derived location
- pages, routes, referring page, timestamps, clicks, and service interactions
- cookie or local-storage identifiers used for authentication, security, preferences, and approved analytics
- diagnostic, availability, performance, error, and security events
- communications and support metadata
The activated Cookie Notice will identify the release-specific technologies, purposes, durations, and choices. Advertising and session replay are disabled in the initial target.
Information from other people and sources. We may receive Personal Data from:
- you
- the Restaurant and its authorized users
- someone placing an order for another person
- payment, telephony, messaging, AI, hosting, authentication, security, and integration Providers
- support, professional, legal, insurance, and fraud-prevention sources
- public or government sources when needed for business identity, security, or legal compliance
If you give us information about another person, provide only what is necessary and make sure you have authority to do so.
05How we use Personal Data
We use Personal Data for the following target purposes.
Provide the Restaurant service.
- identify the Restaurant and selected location
- understand, assemble, price, read back, confirm, submit, and provide status for an order
- route instructions and communications
- support pickup, delivery, correction, cancellation, refund, and dispute handling
- preserve minimal Order Evidence
- provide a human or non-AI alternative
Operate Accounts and business relationships.
- create and administer Accounts
- verify authority and manage roles
- implement and configure the service
- provide support and service communications
- bill and collect Dohos fees
- maintain contracts, approvals, and business records
Security, integrity, and reliability.
- authenticate users and protect Accounts
- detect, prevent, investigate, and respond to fraud, abuse, security threats, incidents, outages, and prohibited use
- enforce tenant and access boundaries
- debug and monitor service performance using minimized data
- maintain backups, continuity, and recovery under approved schedules
Legal and compliance.
- respond to valid legal process
- exercise or defend legal rights
- comply with applicable law, tax, accounting, recordkeeping, and Provider requirements
- handle privacy, accessibility, security, and other requests
- enforce agreements and policies
Carefully governed product integrity. Dohos may use synthetic test data, approved aggregate metrics, and minimized service events to test and improve reliability. Dohos does not use Restaurant/Diner Customer Content to train a general AI model in the initial target.
06Sensitive information
Order interactions can reveal sensitive facts even when Dohos does not ask for them. For example, a special instruction may reveal an allergy, health-related condition, religion, or disability.
Dohos will:
- collect only the minimum instruction needed for the Restaurant transaction
- use it only for approved service, safety, support, security, or legal purposes
- restrict access and disclosure
- not use it for advertising, general-model training, emotion/vulnerability inference, or unrelated profiling
- apply the approved retention and deletion rules
Dohos is not a healthcare provider and the initial service is not approved for clinical, diagnosis, treatment, medication, insurance, patient-record, or HIPAA business-associate workflows. Being outside HIPAA would not eliminate other privacy and breach duties.
07Payment information
The target payment architecture uses an approved hosted payment experience and a Restaurant connected account. The Restaurant is the seller of Restaurant Products and the target payment-account merchant.
Dohos does not want you to speak or type full card numbers, card security codes, PINs, passwords, or bank credentials into the AI, order notes, support, logs, or analytics. The approved payment Provider processes Payment Credentials under its own terms and privacy notice.
Dohos may receive limited tokenized or non-sensitive payment information such as a transaction identifier, payment status, amount, refund, or dispute state when needed to provide and evidence the service.
08How we disclose Personal Data
Dohos may disclose Personal Data only for approved purposes to:
The Restaurant. The Restaurant receives the information needed to review, accept, prepare, fulfill, support, refund, or dispute its order and comply with its legal duties.
Approved Providers. Providers may process data for approved functions such as:
- payment processing
- telephony and transaction-specific messaging
- AI processing
- database, authentication, storage, and hosting
- email/support
- security, reliability, and minimized observability
- approved Restaurant integrations
The activated Subprocessor List will identify the actual approved Providers and material processing facts. This draft does not name a production Provider chain because actual account and runtime evidence is incomplete.
Professional advisers and insurers. Dohos may disclose information to lawyers, auditors, accountants, insurers, brokers, security specialists, and other advisers under appropriate duties when needed for their services.
Legal, safety, and rights purposes. Dohos may disclose information when reasonably necessary to:
- comply with valid law or legal process
- protect rights, safety, security, and service integrity
- investigate fraud, abuse, incidents, or unlawful conduct
- establish, exercise, or defend legal claims
- complete a corporate transaction subject to appropriate review, notice, and protections
Dohos does not promise notice of every legal request where notice is prohibited or impractical.
09Sale, sharing, advertising, and profiling
The initial target service does not:
- sell Personal Data
- share Personal Data for cross-context behavioral advertising
- use Personal Data for Targeted Advertising
- build cross-Restaurant advertising profiles
- broker Personal Data
- use AI to make decisions producing legal or similarly significant effects
Dohos will honor recognized opt-out preference signals, such as Global Privacy Control or another applicable Universal Opt-Out Mechanism, when relevant to a covered practice and jurisdiction. The release-specific Cookie Notice will explain any available controls. Whether customer data ever trains a model is answered directly at AI training and your data.
If a future practice conflicts with this section, it cannot be enabled silently. It will require review, notice, choice/consent where required, Provider/contract changes, and a new activation decision.
10Deidentified and aggregate information
Dohos may create and use information that has been deidentified or aggregated under an approved process. Dohos will maintain technical and contractual controls designed to prevent reidentification and will not call data deidentified merely because direct identifiers were removed.
Dohos will not publish Restaurant-specific confidential metrics or small-group statistics that could reasonably identify a person or reveal protected Restaurant information without authorization.
11Retention and deletion
Dohos keeps each category only for the period reasonably necessary for its approved purpose, including transaction fulfillment, support, security, disputes, chargebacks, accounting/tax, legal claims, contract, and legal requirements.
The initial target uses these principles:
- call audio is not stored by default, and only exists where a Restaurant has separately enabled and disclosed call recording
- a text transcript of each completed call is retained for the restaurant's operational use, access limited to authorized staff by role, and deleted on a counsel/CPA-approved schedule
- transient Provider buffers are limited to the shortest technically necessary period supported by verified configuration
- structured Order Evidence is retained for a counsel/CPA-approved period
- Account, billing, security, support, consent, and legal records use category-specific periods
- backups age out through a documented process, subject to legal holds and technical limits
Deletion must address active databases, storage, logs, indexes, caches, support systems, approved Providers, and backups under the applicable process. Dohos may retain the minimum information needed for a legal exception, fraud/security, tax/accounting, dispute, legal hold, or suppression of a request you asked us to honor.
The final activated retention schedule and Provider behavior must be tested before any specific public period is promised.
12Security
Dohos intends to use administrative, technical, and organizational safeguards proportionate to the nature and sensitivity of the information, including access control, authentication, encryption where appropriate, secure development, logging/monitoring, vulnerability management, Provider diligence, backups, and incident response.
No system is completely secure. This notice does not promise perfect security, uninterrupted availability, a certification, or protection from every incident.
If you believe you found a security issue, use the security reporting channel.
13Your choices
Depending on the service and applicable law, you may be able to:
- correct order information before submission
- decline AI processing and use an available human/non-AI route
- stop transaction-specific messages using the stated instructions
- manage approved cookies/preferences
- update Account details and security settings
- cancel a Restaurant subscription under the agreement
- submit a privacy request
Some information is necessary to provide a selected transaction or secure an Account. If you do not provide it, the relevant function may not be available. Dohos will not condition service on unnecessary Personal Data where prohibited.
14Privacy rights
Depending on where you live and how Dohos processes your information, you may have rights to:
- know or access Personal Data
- correct inaccurate Personal Data
- delete Personal Data
- obtain a portable copy
- opt out of sale, sharing, Targeted Advertising, or certain profiling
- limit or withdraw consent for certain Sensitive Data processing
- appeal a denied request
- use an authorized agent
Dohos intends to offer a voluntary baseline for access, correction, and deletion even when a particular comprehensive state privacy law does not apply, subject to verification, security, Restaurant routing, legal exceptions, and feasibility.
Submitting a request does not require you to create an Account if you did not have one. See the full privacy rights request process.
15How requests are handled
The activated Privacy Rights Request Notice will provide the web, email, phone, and/or other approved methods.
Dohos may need to:
- verify your identity or authority at a level proportionate to the request
- ask for information needed to locate records
- route a Restaurant-controlled request to the Restaurant
- decline or limit a request where an exception applies
- preserve minimum information for security, fraud, tax, dispute, legal hold, or opt-out suppression
Dohos will not ask for full Payment Credentials, Account passwords, or unnecessary sensitive documents to process a request.
If a request is denied and appeal rights apply, the response will explain the appeal method and any regulator contact required by law.
16Authorized agents
An authorized agent may submit a request where permitted. Dohos may ask for evidence of authority and may separately verify the individual's identity or confirmation unless applicable law provides another process.
Dohos will not disclose Personal Data to someone merely because that person knows an email address, phone number, Restaurant, or order detail.
17Children and teens
The initial service is not directed to children and is not designed to create child profiles or companion relationships. Dohos does not knowingly use children's Personal Data for advertising, general-model training, biometrics, or high-impact decisions.
Family/household Restaurant orders can include information about another person. Provide only what is necessary.
If Dohos learns that child data was provided outside an approved path, it will follow a documented review, containment, deletion/preservation, and response process. Future youth-oriented features require a separate legal/product approval.
18Accessibility
Dohos intends to provide accessible privacy information and request methods. If you need this notice or a privacy process in another accessible format, use the activated accessibility assistance channel described at the Accessibility Statement.
Dohos will not require unnecessary medical details to provide an accessible format or assistance.
19United States service and international processing
The initial target is a U.S. service. A Provider's personnel or subprocessors may nevertheless access or process data from other locations. The activated Provider and transfer record will identify material locations and safeguards where required.
No EU, UK, Canadian, or other international privacy compliance claim is made by this draft. Dohos must not launch internationally without separate review.
20State-specific information
Privacy-law coverage, rights, sensitive-data consent, opt-out signals, appeals, and notices differ by state and depend on thresholds, roles, exemptions, data, and conduct.
21Changes to this notice
The activated notice will show an effective date and preserve prior versions at the version archive. Dohos may update the notice when practices, Providers, law, or services change.
Dohos will provide additional notice or obtain consent before a materially different use where required. Posting a new notice will not retroactively authorize an incompatible use.
22Contact Dohos
The final notice will list:
- the responsible Dohos legal entity
- mailing address
- privacy email or request portal
- toll-free or other phone method where required
- accessibility assistance method
- regulator/appeal information where required