AI Food Tour · Mother of Iris

Privacy Policy

Last updated: 10 August 2026

This Privacy Policy explains how AI Food Tour, operating under "Mother of Iris" ("AI Food Tour", "we", "us" or "our"), collects, uses, stores and protects personal data when you use aifoodtour.com, our AI-powered travel and food-tour planning services, account features, and Travel Document Vault.

We are committed to protecting your privacy and processing personal data in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation — GDPR) and other applicable Italian and European data-protection laws.

1. Who We Are

AI Food Tour operates under the umbrella project "Mother of Iris", an AI-powered travel and food-tour platform providing personalized itineraries, food and wine experiences, route planning, guided-tour information, travel assistance and related travel services.

Website: aifoodtour.com
Privacy contact:
Corporate contact:

The legal identity, registered address and other legally required details of the entity acting as Data Controller will be displayed here before the service is commercially launched. Where required by law, contact details for our Data Protection Officer ("DPO") or EU representative will also be provided.

2. Personal Data We May Collect

Depending on the features you use, we may process the following categories of personal data.

2.1 Account and Profile Information

When you register or maintain an account, we may process information such as:

Authentication may be provided through third-party infrastructure such as Supabase. We do not intend to store your password in readable form.

2.2 Travel Preferences

When using our itinerary and AI planning tools, you may provide:

This information is used to create and personalise your travel experience.

2.3 Route and Location Information

Depending on the functionality you enable, we may process:

Precise location information will only be accessed where necessary for the relevant functionality and subject to applicable device permissions. You may disable location permissions through your device or browser where supported.

3. Travel Document Vault

AI Food Tour may provide an optional Travel Document Vault allowing registered users to keep digital copies of travel-related documents in one location. Depending on what you choose to upload, these documents may include:

Please note

Uploading documents is voluntary. You should upload only information that you genuinely need for your travel. The Travel Document Vault should not be treated as the sole repository for essential documents. Users should retain their original documents and, where appropriate, independent secure backups.

4. Important — Information You Must Not Store

The Travel Document Vault is not a banking, payment-card, password or financial credential storage service.

Users must not intentionally upload or store:

If such information is accidentally uploaded, users should delete it immediately and, where appropriate, contact us. AI Food Tour may implement technical controls intended to detect, reject, mask or remove prohibited information.

5. Purposes and Legal Bases for Processing

We process personal data only where we have an appropriate legal basis.

Performance of a Contract

We may process information where necessary to:

Legitimate Interests

Where permitted by law, we may process limited information for legitimate interests including:

Where we rely on legitimate interests, we consider those interests against the rights and freedoms of affected users.

Consent

Where required, we rely on consent for activities such as:

Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal. Where another legal basis is required by law for a particular category of information or processing activity, we will identify and apply that basis before undertaking such processing.

6. Data Minimisation

Users should provide only information reasonably necessary to use the requested feature. AI Food Tour seeks to design its systems so that personal information collected and retained is limited to what is necessary for the relevant purpose.

Do not upload unnecessary pages or information merely because they form part of a larger document. For example, if a booking confirmation is sufficient, avoid uploading additional identity or payment information that is not required.

7. How We Use Personal Data

We may use personal data to:

We will not sell your personal data.

8. AI Processing

Certain AI Food Tour functionality may use third-party artificial intelligence services, including the OpenAI API. Information necessary to fulfil an AI request may be transmitted to the relevant AI service provider.

Documents stored in your Travel Document Vault should not automatically be transmitted to an AI provider merely because they have been uploaded. Where we introduce a feature that analyses a stored document using AI, we will assess the applicable privacy requirements and provide appropriate information and controls before such processing where required.

Users should not enter passport numbers, payment-card information, passwords or other unnecessary confidential credentials into ordinary AI chat prompts.

9. Service Providers and Data Recipients

We may use carefully selected service providers to operate AI Food Tour. Depending upon the final technical configuration, these may include:

We require appropriate contractual and data-protection arrangements with processors where required by applicable law.

10. Security of Travel Documents

Travel and identity documents can contain highly valuable personal information. AI Food Tour will implement technical and organisational measures appropriate to the risks presented by the processing. Depending upon the final technical architecture, these measures may include:

Security safeguards will be reviewed as appropriate considering technological developments and the risks presented by the processing.

11. No System Can Guarantee Absolute Security

Although we take reasonable and appropriate measures to protect personal data, no Internet transmission, cloud-storage platform, mobile device, computer system or electronic database can be guaranteed to be completely secure.

Users are therefore responsible for taking reasonable measures to protect their own accounts and devices. Users should:

12. Limitation of Responsibility

AI Food Tour is responsible for complying with its obligations under applicable data-protection and other mandatory laws. However, to the maximum extent permitted by applicable law, AI Food Tour cannot accept responsibility for loss or damage resulting solely from circumstances outside our reasonable control, including:

Nothing in this Privacy Policy excludes, restricts or limits any responsibility or liability that cannot lawfully be excluded or limited under the GDPR, applicable Italian law, consumer-protection legislation or other mandatory law.

13. Personal Data Breaches

We maintain procedures for identifying, assessing and responding to suspected personal-data breaches. Where a breach involving personal data occurs, we will assess its nature, scope and potential consequences. Where required by applicable law, we will notify the competent supervisory authority and/or affected individuals within the legally applicable requirements and timeframes.

14. Data Retention

We will not retain personal data indefinitely merely because it has been provided to us.

Account information will generally be retained while the account remains active and thereafter only for an appropriate period where necessary for legal, security or legitimate business requirements.

Saved routes will generally remain available until they are deleted by the user, the account is deleted, or applicable retention rules require their removal.

Travel documents will be retained only for as long as necessary to provide the storage functionality requested by the user, subject to applicable legal requirements and the specific retention settings made available through the service. We intend to provide users with controls allowing them to delete individual stored travel documents.

When an account is deleted, associated personal data will be deleted or anonymised in accordance with our applicable retention schedule, except where continued retention is required or permitted by law. Backup copies may remain temporarily until they are overwritten or securely removed in accordance with our backup-retention procedures.

15. International Data Transfers

We aim, where reasonably practicable and appropriate to our technical configuration, to use European hosting and data-storage infrastructure for European users. Some service providers or their subprocessors may process information outside the European Economic Area.

Where personal data is transferred internationally, we will use a legally recognised transfer mechanism where required, which may include:

The precise safeguards applicable to a particular provider depend upon our current contractual and technical configuration.

16. Cookies and Analytics

AI Food Tour may use:

Essential Cookies

Necessary for functions such as authentication, account security, session management and basic operation of the website. These do not require consent where legally exempt.

Optional Cookies

Analytics, advertising or other non-essential technologies will only be activated where permitted by applicable law and, where required, after the user provides consent. Users may change or withdraw cookie consent through our cookie-management interface.

Please see our separate Cookie Policy for additional information.

17. Your GDPR Rights

Subject to the conditions and limitations provided by applicable law, individuals may have the right to:

Requests may be sent to:

We may need to verify your identity before fulfilling a request where appropriate to protect your information.

18. Right to Complain

Individuals have the right to lodge a complaint with the competent data-protection supervisory authority. For users in Italy, the relevant authority is:

Garante per la protezione dei dati personali

Users may also have the right to contact another competent supervisory authority depending upon their habitual residence, place of work or the location of an alleged infringement.

19. Children

AI Food Tour is not intended to encourage children to independently upload passports, identity documents, payment information or other sensitive travel documentation. Where services may be used in connection with children or family travel, additional safeguards and appropriate parental or guardian controls may be implemented where required by applicable law.

20. Third-Party Services

AI Food Tour may contain links to hotels, restaurants, tour operators, transportation providers, mapping services and other independent websites or applications. Those organisations may operate as independent data controllers and have their own privacy policies. AI Food Tour is not responsible for the independent privacy practices of third-party services.

Users should review the relevant provider's privacy information before submitting personal information directly to that provider.

21. Changes to This Privacy Policy

We may update this Privacy Policy to reflect:

The current version and its effective date will be published on this page. Where required by law, users will be appropriately informed of material changes.

22. Contact Us

Questions concerning privacy, personal data, document security or the exercise of GDPR rights may be sent to:

AI Food Tour
Website: aifoodtour.com
Email:

Additional legal identity, registered-office and Data Controller information will be inserted before commercial launch.

Important Travel Document Warning

The Travel Document Vault is an optional convenience feature.

DO NOT STORE credit card images, CVV/CVC codes, banking passwords, PIN numbers, cryptocurrency keys, account passwords or other financial authentication credentials.

Upload only documents reasonably necessary for your travel. Always retain your original travel documents and an appropriate independent backup.

AI Food Tour cannot guarantee absolute cybersecurity. Nothing in this statement limits any rights or remedies that users have under mandatory applicable law.