Automated Processing and AI
Last updated 2026-08-01 · v2026-08-01.1
Αυτή η σελίδα δεν έχει μεταφραστεί ακόμη στα Ελληνικά, γι’ αυτό εμφανίζεται στα Αγγλικά.
Draft — not yet reviewed by a lawyer
The descriptions of how this service works are accurate. The legal conclusions have not been checked by anyone qualified to check them, and this must not be relied on as it stands.
1. You are talking to a machine, and we say so
The ordering assistant is an artificial intelligence system. It is not a person, it is not a member of restaurant staff, and it does not become one at any point in a conversation. We tell you this at the start of every conversation rather than relying on it being obvious.
Article 50 of the EU AI Act requires exactly this disclosure for a system that interacts directly with a person, and it applies from 2 August 2026. We make the disclosure in both our markets rather than only where it is compelled.
2. What the assistant does, and what it cannot do
It proposes. It reads the menu, reads what you asked for, and suggests a basket of dishes. You confirm it or you do not, and nothing is ordered until you do.
It cannot price anything. The model is given no field in which to return a price, a total, a discount or a fee — the shape of its answer has nowhere to put one — and every figure you see is calculated afterwards by the same pricing code that runs at checkout. There is no model on the payment path at all.
It cannot place an order, apply a refund, or change anything about your account. Its output is reduced to menu item identifiers and quantities before anything else happens.
It does not give medical, dietary or allergen advice, and it will not tell you a dish is safe for you. It can repeat what a restaurant has stated about a dish and tell you what the restaurant has not answered. It cannot go beyond that, because we hold no recipe and no ingredient list to go beyond it with.
3. What it learns about you, and how
Nothing you say to the assistant is stored as a fact about you unless you tap to confirm it. The assistant may notice something and offer to remember it; the offer is a question with a button, and only the button writes anything. The code that writes has no connection to the model at all, so there is no sequence of model outputs that can produce a stored fact.
It never records an allergy it was not told. It cannot infer one, and this is enforced by the shape of the software rather than by a rule somebody might change: the structure that holds a behavioural observation has no field for severity, so an inferred allergy has nowhere to live.
Everything the assistant knows about you is visible to you in your account, each item labelled with how it was learned, and each item individually deletable.
4. Profiling, and why it does not decide anything about you
Greece and the EU only
Building a picture of what you like from what you order is profiling within the meaning of Article 4(4) of the GDPR. We do it, and we say so.
Article 22 of the GDPR gives you the right not to be subject to a decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you. Our view is that suggesting dishes does not reach that threshold: a ranked list of suggestions determines nothing, you can ignore it, the whole menu remains available to you, and nothing is added to your basket without you doing it.
That answer would change if the profile started doing more. If it set your price, refused you service, suppressed restaurants or dishes from what you can see, or decided whether you could pay after delivery, then it would be making a decision about you and Article 22 would engage. We do not do any of those things, and none of them exists in the software.
You can ask us for an explanation of how a suggestion was arrived at, and we will answer in terms of what was actually taken into account.
Needs a qualified lawyer: The Art. 22 conclusion is the conservative and, in our view, correct one on WP29 WP251rev.01 pp.21-22 (the threshold is calibrated to credit refusal and automated recruitment) and CJEU SCHUFA C-634/21 (the automated output must play a determining role). Two things counsel should confirm: (1) SCHUFA pushes Art. 22 UP the chain to whoever generates a determinative score, so if this platform ever computes a fraud score, a pay-later creditworthiness score or a merchant-suspension score on which anybody relies, the platform becomes the Art. 22 controller for it even if a human formally decides; (2) C-203/22 Dun & Bradstreet (27 Feb 2025) hardens the explanation duty into a counterfactual-grade obligation that trade secrecy cannot switch off, so the promise in the last paragraph must be answerable in production before it is made.
5. We do not manipulate you, and here is what we mean by that
A suggestion that fits something we know you like is a suggestion. A suggestion designed to exploit something we know is wrong is not, and we do not make the second kind.
Concretely, and as commitments rather than aspirations: we do not use knowledge of a vulnerability — a person's age, a disability, or a difficult financial situation — to push them to order more or to order at all. We do not use a declared allergy or a health condition to target anything at anybody. We do not manufacture urgency or scarcity that is not real. We do not make it harder to leave than it was to arrive, and we do not use a dark pattern to obtain a consent.
Article 5 of the EU AI Act prohibits AI systems that use manipulative or deceptive techniques to materially distort behaviour in a way likely to cause significant harm, and separately prohibits exploiting vulnerabilities arising from age, disability, or a specific social or economic situation. Those prohibitions have applied since 2 February 2025. Ordinary commercial persuasion is not caught by them and we do not pretend otherwise — what is caught is the second kind of suggestion, and the line above is where we hold ourselves.
Suggesting a side dish with a main course is upselling. Suggesting a larger order to somebody a model believes is in financial difficulty is not something we will build.
Needs a qualified lawyer: These are enforceable promises once published, and that is intended. Counsel should confirm the business is willing to be held to them, and product should confirm that no current or planned surface breaches them — in particular any late-night or lapsed-customer re-engagement campaign that segments on inferred spending capacity. Note also DSA Art. 26(3), which bans advertising based on profiling using Art. 9 special-category data OUTRIGHT, with no consent gateway: targeting off inferred halal, kosher, gluten-free or diabetic ordering patterns is prohibited regardless of any permission obtained.
6. Is the assistant a "high-risk" AI system?
Greece and the EU only
No. The EU AI Act designates specific uses as high risk, and helping somebody choose lunch is not one of them. Nothing here does biometrics, credit scoring, employment decisions, education, law enforcement or access to essential services.
Profiling does not by itself make a system high risk. It removes an exemption that only applies to systems already listed as high risk, which this is not.
Two adjacent systems would be a different question if we build them, and we would treat them as such: anything that allocates work to couriers or evaluates their performance, and anything that scores a customer for deferred payment. The first is listed under employment and workers' management; the second under access to essential private services.
Needs a qualified lawyer: Confirm the Annex III walk-through, and note the timing correction: the high-risk regime for Annex III systems was deferred from 2 August 2026 to 2 DECEMBER 2027 by Regulation (EU) 2026/1744. The courier allocation exposure is real and is not hypothetical for long — see docs/COURIER-PAY.md. Because it would be an Annex III point 4(b) system that profiles couriers, it could never use the Art. 6(3) "no significant risk" escape.
7. Text the assistant writes
Greece and the EU only
Where the assistant produces text for you to read, it is the assistant's text and it is labelled as such in the interface.
Needs a qualified lawyer: AI Act Art. 50(2) requires providers of systems generating synthetic text to mark outputs in a machine-readable format and detectably as artificially generated, so far as technically feasible. Confirm (a) whether Angie Eats is a "provider" or a "deployer" here — it deploys a third-party model but places its own AI system on the market, which likely makes it a provider of that system; (b) whether any machine-readable marking is implemented, because none was found in the codebase; (c) the Art. 111(4) grace, which gives systems on the market before 2 August 2026 until 2 December 2026 to comply with Art. 50(2).
8. Human involvement, and how to reach one
A person confirms every order. If you want a person from our side, ask for one and a complaint about an order is answered by a human being, not a model.
9. If this notice and the software disagree
The software wins, and the notice is wrong and will be corrected. We maintain an internal record mapping every claim in this notice to the part of the system that supports it, and to the change that would make the claim false, so that a change to the software is visible as a change to what we may say.
4 clauses on this page carry a note above because they need a qualified lawyer. They are published rather than hidden: a reader is better served by an open question than by a confident answer that is wrong.
sha256 f610f477cb51206ce7cd1eaa1405bd91222ea2f10d232eeaf70f094ee69eb334