Legal

Data Processing Agreement

Last updated: 27 August 2026

37 sections

This Data Processing Agreement (“DPA”) forms part of the agreement between FAIRA PLATFORMS LTD (“Faira”, “Processor”, “we”, “us” or “our”) and the customer identified in the applicable Order Form or subscription agreement (“Customer”, “Controller”, “you” or “your”).

This DPA governs Faira’s processing of Personal Data on behalf of Customer in connection with the Faira services.

It is incorporated into and forms part of the applicable Terms of Service, SaaS Agreement, Order Form or other agreement governing Customer’s use of the Faira services (the “Agreement”).

Where Customer and Faira have entered into a separately negotiated data processing agreement, that agreement will prevail over this DPA to the extent of any inconsistency.

In this DPA:

“Applicable Data Protection Law” means all applicable laws and regulations relating to privacy, data protection and the processing of Personal Data applicable to the Processing under this DPA, including, where applicable:

  • the UK GDPR
  • the Data Protection Act 2018
  • applicable EU data protection legislation
  • applicable national implementing legislation
  • applicable amendments or successor legislation

“Controller” means the natural or legal person that determines the purposes and means of the Processing of Personal Data.

“Data Subject” means an identified or identifiable natural person to whom Personal Data relates.

“Personal Data” means personal data, personal information or equivalent information protected by Applicable Data Protection Law.

“Processing” has the meaning given to it under Applicable Data Protection Law and includes collecting, recording, storing, organising, structuring, adapting, retrieving, consulting, using, disclosing, transmitting, restricting, erasing and destroying Personal Data.

“Processor” means an organisation that processes Personal Data on behalf of a Controller.

“Subprocessor” means a third party appointed by Faira to process Personal Data on behalf of Customer.

“Security Incident” means a breach of security resulting in accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data processed by Faira on behalf of Customer.

Controller

Customer is the Controller of Personal Data processed through the Faira services where Customer determines the purposes and means of that Processing.

Customer is responsible for:

  • determining the purposes and lawful basis for Processing
  • providing appropriate privacy information to Data Subjects
  • ensuring that its instructions to Faira comply with Applicable Data Protection Law
  • ensuring that it has all necessary rights, permissions and consents to provide Personal Data to Faira
  • determining appropriate retention periods
  • responding to Data Subject requests where Customer is the Controller
  • carrying out any required Data Protection Impact Assessments

Processor

Faira acts as Customer’s Processor where Faira processes Personal Data on Customer’s behalf. Faira will:

  • process Personal Data only in accordance with Customer’s documented instructions
  • maintain appropriate security measures
  • maintain confidentiality
  • assist Customer with applicable data protection obligations
  • comply with the requirements applicable to processors under Applicable Data Protection Law

The subject matter of Processing is the provision of the Faira services. Faira may process Personal Data for the duration of the Customer’s use of the relevant services and for any additional period required to complete deletion, return or other end-of-contract obligations.

The duration of individual Processing activities may vary depending on:

  • the Faira service used
  • Customer’s configuration
  • Customer’s instructions
  • applicable retention settings
  • legal obligations
  • the applicable Agreement

Faira may process Personal Data as necessary to provide and support the Faira services. Processing may include:

  • receiving customer enquiries
  • managing customer communications
  • telephone and voice communications
  • call routing
  • call recording where enabled
  • transcription
  • AI-powered conversation processing
  • generating AI responses
  • lead qualification
  • appointment scheduling
  • workflow execution
  • CRM synchronisation
  • WhatsApp communications
  • Instagram messaging
  • Facebook and Messenger communications
  • customer support
  • authentication
  • security monitoring
  • fraud and abuse prevention
  • service administration
  • troubleshooting
  • reporting and analytics
  • deletion or return of Personal Data

Faira will not process Personal Data for purposes outside the scope of the Agreement except:

  1. 1.on Customer’s documented instructions; or
  2. 2.where required by applicable law.

Depending on Customer’s use of the Faira services, Data Subjects may include:

  • customers
  • prospective customers
  • leads
  • website visitors
  • patients or clients
  • members
  • service users
  • callers
  • message senders
  • employees
  • contractors
  • representatives
  • suppliers
  • business contacts
  • other individuals whose information Customer chooses to process through Faira

Customer is responsible for ensuring that its use of Faira is appropriate for the relevant categories of Data Subjects.

Depending on the services configured by Customer, Faira may process:

Identity data

  • name
  • username
  • customer ID
  • account identifier
  • profile information

Contact data

  • email address
  • telephone number
  • postal address
  • social media identifiers

Business data

  • company
  • job title
  • business contact information
  • customer relationship information

Communications data

  • messages
  • emails
  • WhatsApp messages
  • Instagram messages
  • Facebook and Messenger messages
  • website enquiries
  • attachments
  • call metadata

Voice data

  • telephone numbers
  • call audio
  • call recordings where enabled
  • speech
  • transcripts
  • call summaries
  • conversation metadata

Appointment and service data

  • appointment details
  • booking information
  • service preferences
  • availability
  • workflow information

Technical data

  • IP address
  • device information
  • browser information
  • identifiers
  • authentication information
  • system logs
  • usage information

Other information

Customer may choose to submit other Personal Data through the Faira services.

Customer should not provide Personal Data that is unnecessary for the relevant service.

Faira does not require Customer to process special category Personal Data through the services unless the relevant functionality has been agreed or made available for that purpose.

Where Customer chooses to process special category Personal Data, Customer is responsible for ensuring that:

  • an appropriate legal basis exists
  • an applicable additional condition for Processing is satisfied
  • appropriate transparency is provided
  • the Processing is necessary and proportionate
  • any required Data Protection Impact Assessment is completed

Where Customer uses Faira in healthcare, financial services, insurance, employment or another regulated environment, Customer remains responsible for assessing the legal requirements applicable to its Processing.

Faira will process Personal Data only on Customer’s documented instructions.

Customer’s instructions are contained in:

  • this DPA
  • the Agreement
  • the applicable Order Form
  • Customer’s configuration of the Faira platform
  • Customer’s use of supported integrations
  • Customer’s documented requests
  • other written instructions provided by Customer

Customer may provide additional documented instructions during the term of the Agreement.

Faira will notify Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law.

Faira will ensure that persons authorised to process Customer Personal Data:

  • are subject to appropriate confidentiality obligations
  • process Personal Data only as necessary to perform their role

Faira will limit access to Personal Data according to business need and appropriate access controls.

Faira will implement appropriate technical and organisational measures designed to protect Personal Data against:

  • accidental or unlawful destruction
  • accidental loss
  • alteration
  • unauthorised disclosure
  • unauthorised access
  • other unlawful forms of Processing

Depending on the service, Faira’s security measures may include:

  • encryption in transit
  • encryption at rest where appropriate
  • access controls
  • authentication
  • role-based permissions
  • least-privilege access
  • secure API authentication
  • logging and monitoring
  • infrastructure security
  • vulnerability management
  • backup and recovery controls
  • security incident response
  • personnel confidentiality obligations
  • secure deletion procedures

Faira may update its technical and organisational measures over time provided that such changes do not materially reduce the overall security of the services.

Further information is available in Faira’s Security & Compliance documentation.

Taking into account the nature of Processing, Faira will reasonably assist Customer in responding to requests from Data Subjects exercising their rights under Applicable Data Protection Law.

Such rights may include:

  • access
  • rectification
  • erasure
  • restriction
  • objection
  • portability
  • rights relating to automated decision-making

Where Faira receives a Data Subject request relating to Personal Data processed on behalf of Customer, Faira will not respond to the request except:

  • on Customer’s documented instructions; or
  • where required by Applicable Data Protection Law.

Faira may refer the Data Subject to Customer where Customer is the Controller.

Faira will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data.

The notification will include, where reasonably available:

  • the nature of the incident
  • the categories of Personal Data affected
  • the categories and approximate number of Data Subjects affected
  • the likely consequences
  • measures taken or proposed to address the incident
  • a contact point for further information

Faira will reasonably cooperate with Customer in relation to:

  • investigation
  • containment
  • remediation
  • regulatory notifications
  • communications to affected Data Subjects
  • other legally required actions

Faira’s notification of a Security Incident does not constitute an admission of fault or liability.

Taking into account the nature of the Processing and information available to Faira, Faira will reasonably assist Customer with information necessary for Customer to conduct:

  • Data Protection Impact Assessments
  • risk assessments
  • consultations with regulators
  • other compliance assessments required under Applicable Data Protection Law

Customer remains responsible for determining whether a DPIA is required.

Faira will maintain information reasonably necessary to demonstrate compliance with its obligations under this DPA and Applicable Data Protection Law.

Upon reasonable request, Faira will provide Customer with information necessary to demonstrate compliance with the obligations applicable to processors.

Faira may satisfy information requests through:

  • security documentation
  • policies
  • audit reports
  • certifications, where available
  • questionnaires
  • summaries of technical and organisational measures
  • relevant testing information
  • other appropriate documentation

Customer provides Faira with general authorisation to appoint subprocessors in accordance with this DPA.

Faira’s principal subprocessors may include:

SubprocessorFunctionIntended processing geography
Amazon Web Services (AWS)Hosting, databases, storage and infrastructureUK to UK; EU to EU; US to US; Africa to US
OpenAIAI processingRegional processing where available and configured
Vapi Inc.Voice AI orchestrationRegional processing where available and configured
TwilioTelecommunications and voiceUK, US and Europe
Africa’s TalkingTelecommunications and voiceNigeria and Kenya
Meta / WhatsAppWhatsApp communicationsMeta infrastructure
Meta / InstagramInstagram messagingMeta infrastructure
Meta / Facebook / MessengerFacebook and Messenger communicationsMeta infrastructure

Faira may appoint new subprocessors where necessary to provide or improve the services.

Faira will provide notice of material changes to its subprocessors in accordance with the Agreement or applicable subprocessor notification process.

Customer may object to the appointment of a new subprocessor on reasonable data protection grounds.

Where Customer objects, the parties will work in good faith to address the objection.

If the parties cannot reasonably resolve the objection, Faira may, where commercially and technically feasible, offer an alternative configuration or the parties may discuss termination of the affected service.

Faira will enter into a written agreement with each subprocessor requiring the subprocessor to provide an appropriate level of protection for Customer Personal Data.

The subprocessor will be required to comply with obligations relating to:

  • confidentiality
  • security
  • data protection
  • international transfers
  • deletion or return of Personal Data

Faira remains responsible for the performance of its subprocessors to the extent required by Applicable Data Protection Law and the Agreement.

Faira may transfer or permit access to Customer Personal Data outside the United Kingdom where necessary to provide the services.

Faira’s intended infrastructure architecture includes:

  • UK AWS infrastructure for UK data
  • EU AWS infrastructure for EU data
  • US AWS infrastructure for US data
  • US AWS infrastructure for African data

Certain third-party services may process Personal Data outside these regions. These may include:

  • AI services
  • telecommunications services
  • Meta services
  • monitoring and security services
  • other subprocessors

Where a transfer constitutes a restricted transfer under Applicable Data Protection Law, Faira will implement an appropriate lawful transfer mechanism. Depending on the circumstances, this may include:

  • an adequacy regulation or decision
  • the UK International Data Transfer Agreement
  • the UK Addendum to the EU Standard Contractual Clauses
  • appropriate contractual safeguards
  • another lawful transfer mechanism

Where required, Faira will conduct or support an appropriate transfer risk assessment or data protection test, and the parties will cooperate reasonably to address additional safeguards.

If Faira receives a legally binding request from a public authority for access to Customer Personal Data, Faira will, where legally permitted:

  • notify Customer
  • provide information about the request
  • limit disclosure to what is legally required
  • challenge or seek clarification of an unlawful or excessive request where reasonably appropriate

Faira may be prevented from notifying Customer where prohibited by law.

Customer is responsible for determining what Personal Data is submitted to Faira.

Customer should configure the Faira services to collect and process only Personal Data reasonably necessary for the relevant business purpose.

Faira may provide functionality that assists with data minimisation, retention and deletion, but Customer remains responsible for determining appropriate Processing.

Where Customer uses Faira’s AI functionality, Faira may process Customer Personal Data through AI infrastructure, including third-party providers such as OpenAI and Vapi.

AI Processing may include:

  • speech-to-text transcription
  • natural language understanding
  • classification
  • summarisation
  • response generation
  • conversation analysis
  • lead qualification
  • workflow decisions
  • other AI-enabled functionality

Faira will process Customer Personal Data through AI services only as necessary to provide the relevant functionality and in accordance with this DPA and the Agreement.

Faira will not knowingly instruct an AI provider to use Customer Personal Data for purposes incompatible with this DPA.

Where Customer uses Faira’s voice services, Personal Data may be processed through:

  • Twilio
  • Africa’s Talking
  • Vapi
  • OpenAI
  • other infrastructure required to provide the service

This may include:

  • telephone numbers
  • call metadata
  • audio
  • recordings
  • transcripts
  • AI prompts
  • AI responses
  • conversation summaries
  • workflow information

Customer is responsible for ensuring that call recording, transcription and automated calling are lawful in the jurisdictions in which the services are used.

Where Customer connects Meta services to Faira, Faira may process Personal Data obtained through:

  • WhatsApp
  • Instagram
  • Facebook Pages
  • Messenger
  • applicable Meta APIs

Faira will process Meta Platform Data only to provide the functionality authorised by Customer and in accordance with Applicable Data Protection Law and the applicable Meta platform requirements.

Faira will not sell Meta Platform Data.

Customer is responsible for:

  • maintaining appropriate Meta permissions
  • complying with applicable Meta policies
  • providing appropriate privacy information
  • determining the lawful basis for its Processing
  • responding to Data Subject requests where Customer is the Controller

At the end of the Processing relationship, Customer may instruct Faira to:

  • return Personal Data
  • provide an export of Personal Data
  • securely delete Personal Data

Unless otherwise agreed, Faira will delete Customer Personal Data within a reasonable period following termination, subject to:

  • applicable retention requirements
  • backup cycles
  • legal obligations
  • legitimate requirements to establish, exercise or defend legal claims

Where Personal Data remains in backups, Faira will ensure that it is put beyond active use and deleted in accordance with its normal backup deletion cycle.

The ICO specifically recognises that backup data may require a practical deletion cycle provided it is appropriately safeguarded and put beyond use.

Faira will make available to Customer information reasonably necessary to demonstrate compliance with this DPA.

Where required by Applicable Data Protection Law, Faira will permit audits or inspections by Customer or an auditor appointed by Customer. Audits will:

  • be subject to reasonable prior notice
  • take place during normal business hours
  • be conducted in a manner that does not materially disrupt Faira’s operations
  • respect Faira’s confidentiality obligations to other customers
  • not require access to another customer’s data
  • not compromise Faira’s security
  • be subject to reasonable confidentiality obligations

Customer will bear its own audit costs.

If an audit identifies material non-compliance attributable to Faira, Faira will reasonably cooperate in addressing the issue.

The ICO’s Article 28 guidance expressly requires processor contracts to provide for information demonstrating compliance and appropriate audits or inspections.

Where available, Faira may satisfy reasonable audit requests by providing:

  • security documentation
  • independent assurance reports
  • certifications
  • penetration-testing summaries
  • security questionnaires
  • policies
  • technical documentation
  • other relevant evidence

Customer will consider such materials before requesting an on-site or technical audit.

Faira will provide an appropriate privacy contact for matters relating to this DPA.

Unless otherwise notified, privacy and data protection enquiries should be sent to compliance@getfaira.com.

If Faira appoints a formal Data Protection Officer or changes its privacy contact, Faira will update the relevant information.

Customer acknowledges that Faira’s ability to comply with this DPA depends on Customer:

  • providing lawful instructions
  • providing accurate information
  • configuring the services appropriately
  • complying with Applicable Data Protection Law
  • maintaining appropriate privacy notices
  • obtaining required consents
  • complying with telecommunications requirements
  • maintaining appropriate retention policies
  • using Faira only for lawful purposes

Customer will not instruct Faira to process Personal Data in a manner that would knowingly cause Faira to breach Applicable Data Protection Law.

The liability of each party under this DPA is subject to the liability provisions contained in the Agreement.

Nothing in this DPA limits or excludes liability to the extent such limitation or exclusion is prohibited by Applicable Data Protection Law.

This DPA remains in force for as long as Faira processes Personal Data on behalf of Customer.

Termination of the Agreement will automatically terminate this DPA once Faira has completed its obligations relating to return, deletion or other lawful retention of Personal Data.

If there is a conflict between this DPA and the Agreement concerning data protection matters, this DPA will prevail to the extent of the conflict.

If there is a conflict between this DPA and a separately executed data protection agreement specifically negotiated between the parties, the separately executed agreement will prevail.

This DPA is governed by the laws of England and Wales, unless otherwise required by Applicable Data Protection Law.

The courts of England and Wales will have jurisdiction over disputes arising under this DPA, subject to any mandatory rights available under Applicable Data Protection Law.

Notices relating to data protection matters should be sent to compliance@getfaira.com.

Customer should provide an appropriate privacy or data protection contact when entering into the Agreement.

Company
FAIRA PLATFORMS LTD
Company number
17059377

A. Subject matter

Provision of Faira’s customer communication, AI, voice, messaging, workflow, booking, CRM and related services.

B. Duration

The duration of the Agreement and any period reasonably required for deletion, return or legally required retention.

C. Nature of Processing

  • collection
  • recording
  • organisation
  • storage
  • retrieval
  • consultation
  • transmission
  • analysis
  • transcription
  • AI processing
  • communication
  • workflow execution
  • integration
  • deletion
  • other Processing necessary to provide the Faira services

D. Purposes

  • provide Faira services
  • facilitate customer communications
  • provide AI-powered functionality
  • provide voice and messaging services
  • execute workflows
  • integrate with third-party systems
  • provide customer support
  • secure the platform
  • prevent fraud and abuse
  • maintain service reliability
  • comply with applicable law

E. Categories of Data Subjects

  • customers
  • prospective customers
  • leads
  • callers
  • message senders
  • website visitors
  • patients or clients where applicable
  • members
  • employees
  • contractors
  • business contacts
  • other individuals whose Personal Data is submitted by Customer

F. Categories of Personal Data

  • name
  • email
  • telephone number
  • address
  • business information
  • social media identifiers
  • account identifiers
  • messages
  • voice recordings
  • audio
  • transcripts
  • call metadata
  • appointment information
  • CRM information
  • technical information
  • device and browser information
  • IP address
  • other Personal Data submitted by Customer

G. Special categories

Potentially, depending on Customer’s use:

  • health information
  • racial or ethnic origin
  • religious or philosophical beliefs
  • political opinions
  • biometric information
  • information concerning sex life or sexual orientation
  • other special category Personal Data under Applicable Data Protection Law

Customer is responsible for ensuring that any Processing of special category Personal Data is lawful.

Faira’s technical and organisational measures include, as applicable:

1. Access control

  • role-based access controls
  • least-privilege principles
  • authentication controls
  • user access management
  • access restriction based on business need

2. Data protection

  • encryption in transit
  • encryption at rest where appropriate
  • secure transmission protocols
  • controlled data access

3. Infrastructure security

  • AWS cloud infrastructure
  • network security controls
  • infrastructure monitoring
  • system logging
  • backup and recovery mechanisms

4. Application security

  • secure API authentication
  • authorisation controls
  • input validation
  • dependency management
  • secrets management
  • controlled deployments

5. Monitoring

  • security logging
  • access monitoring
  • infrastructure monitoring
  • incident detection
  • operational monitoring

6. Incident management

  • security incident identification
  • investigation
  • containment
  • remediation
  • customer notification where required

7. Personnel

  • confidentiality obligations
  • role-based access
  • appropriate onboarding and offboarding
  • security awareness measures

8. Data retention and deletion

  • retention controls
  • customer-configurable deletion where supported
  • secure deletion procedures
  • backup lifecycle management

9. Business continuity

  • cloud infrastructure resilience
  • backups
  • recovery procedures
  • monitoring
  • incident response

SubprocessorServiceProcessing
Amazon Web ServicesCloud infrastructureHosting, storage, databases and infrastructure
OpenAIAIAI model processing
Vapi Inc.Voice AIVoice orchestration and AI processing
TwilioTelecommunicationsUK, US and European voice infrastructure
Africa’s TalkingTelecommunicationsNigeria and Kenya voice infrastructure
Meta / WhatsAppMessagingWhatsApp communications
Meta / InstagramMessagingInstagram communications
Meta / Facebook / MessengerMessagingFacebook and Messenger communications

Faira may update this Schedule in accordance with the subprocessor provisions of this DPA.

Faira’s intended infrastructure architecture is:

Data / customer regionPrimary AWS infrastructure
United KingdomUnited Kingdom
European UnionEuropean Union
United StatesUnited States
AfricaUnited States

Additional processing may occur through third-party providers.

Where required, Faira will use an appropriate lawful transfer mechanism, which may include:

  • adequacy
  • UK IDTA
  • UK Addendum
  • EU Standard Contractual Clauses together with the UK Addendum where applicable
  • another legally permitted safeguard

The parties will cooperate in relation to transfer assessments and supplementary measures where required.

By signing or accepting the Agreement incorporating this DPA, Customer:

  1. 1.appoints Faira as its Processor for the Processing described in this DPA;
  2. 2.authorises Faira to process Personal Data in accordance with the Agreement and Customer’s documented instructions;
  3. 3.provides general authorisation for Faira to appoint the subprocessors identified in Schedule 3;
  4. 4.acknowledges the international transfer arrangements described in Schedule 4; and
  5. 5.acknowledges that Customer remains responsible for the lawfulness of its instructions and use of the Faira services.

To request a countersigned copy of this DPA, contact compliance@getfaira.com.