GDPR Information
Last updated: 27 June 2026
This page summarises how Guestwork approaches UK GDPR and data protection. It is not legal advice for your venue, but it explains the practical split between Guestwork Limited and restaurant customers.
1. Website visitors and demo enquiries
When you visit the Guestwork website or submit a demo request, Guestwork Limited is generally the controller of the personal data you provide to us. Details are set out in our Privacy Policy.
2. Venue customers and guest data
When a restaurant or venue uses Guestwork to manage bookings, tables, staff, and guest records, the venue is generally the controller of its own guest and staff data. Guestwork Limited acts as processor for that venue.
3. What venues should consider
- Have a lawful basis for storing guest booking and preference information.
- Tell guests how their information is used, normally through the venue's own privacy notice.
- Limit sensitive notes to what is necessary for service, safety, or hospitality.
- Control staff access and remove access when staff leave.
- Respond to guest rights requests where required by law.
4. How Guestwork supports compliance
- Clear separation between venue data and Guestwork's own website enquiry data.
- A Data Processing Agreement for venue customer processing.
- Security practices designed to protect booking, staff, and guest information.
- Support for operational records such as booking changes and audit trails.
- Reasonable assistance with data subject requests and security questions.
5. Data subject requests
If your request relates to a booking or guest record held by a restaurant, you should normally contact that restaurant first. If your request relates to a demo enquiry or direct communication with Guestwork, contact us at hello@guestwork.co.uk.
6. Related documents
7. Contact
GDPR and privacy questions can be sent to hello@guestwork.co.uk.
Book a demo