Legal

Security & Compliance

Last updated: 27 August 2026

24 sections

Faira Platforms Ltd (“Faira”, “we”, “us” or “our”) is committed to protecting the security, confidentiality and integrity of the information processed through our platform.

Faira provides infrastructure for businesses to capture, manage and automate customer communications across voice, WhatsApp, Instagram, Facebook/Messenger and other channels.

This page describes Faira's current security and compliance approach.

It should be read together with our Privacy Policy, Terms of Service and, where applicable, our Data Processing Agreement.

Faira's security approach is based on five principles:

Confidentiality

Personal data and customer information are accessible only to authorised systems and individuals with a legitimate business need.

Integrity

We use appropriate controls designed to protect information from unauthorised modification, loss or corruption.

Availability

Our infrastructure is designed to provide resilient and reliable access to the Faira platform.

Data minimisation

We seek to collect, process and retain only information necessary to provide the relevant service.

Least privilege

Access to systems and information is restricted according to role and business need.

Faira's core application infrastructure is hosted using Amazon Web Services (AWS).

Faira uses AWS services for functions including:

  • application hosting
  • databases
  • storage
  • networking
  • monitoring
  • backups
  • security infrastructure

Faira uses geographically appropriate AWS infrastructure where available and appropriate.

Our intended regional architecture is:

Customer / data regionIntended AWS processing
United KingdomUK
European UnionEU
United StatesUS
AfricaUS

Regional processing does not mean that every component of a service, operational log, support system or third-party provider necessarily remains within the same geographic region.

Where personal data is transferred internationally, Faira applies appropriate safeguards in accordance with applicable data protection law.

Faira uses encryption and other appropriate technical measures to protect information in transit and at rest, where appropriate to the service and data involved.

Data transmitted between systems is protected using appropriate transport security mechanisms.

Access to infrastructure and sensitive systems is controlled through authentication and access-management mechanisms.

Faira applies access controls designed to ensure that access to customer information is limited to authorised users and systems.

Controls may include:

  • role-based access
  • authentication
  • least-privilege permissions
  • access reviews
  • credential management
  • service-level permissions
  • logging and monitoring

Faira limits employee and contractor access to customer information to what is reasonably necessary to perform their role.

Faira incorporates security considerations into the design and development of its platform.

Depending on the service, controls may include:

  • authenticated access
  • authorisation controls
  • input validation
  • secure API design
  • secrets management
  • dependency management
  • logging
  • monitoring
  • vulnerability management
  • controlled deployment processes

Faira continuously evaluates and improves its security controls as the platform develops.

Faira connects with third-party platforms and services through APIs and other integration mechanisms.

These may include:

  • Meta
  • WhatsApp
  • Instagram
  • Facebook/Messenger
  • Twilio
  • Africa's Talking
  • Vapi
  • OpenAI
  • CRM platforms
  • booking platforms
  • other supported services

Where supported, Faira uses appropriate authentication and authorisation mechanisms, including API credentials, access tokens and OAuth-based authorisation.

Faira seeks to limit the permissions granted to integrations to those necessary to provide the requested functionality.

Faira may integrate with Meta technologies including:

  • WhatsApp Business Platform
  • Instagram messaging
  • Facebook Pages
  • Facebook Messenger
  • other Meta APIs

Faira is responsible for protecting information processed through its systems in accordance with applicable law and its contractual obligations.

Businesses connecting Meta accounts to Faira are responsible for:

  • maintaining control of their Meta accounts
  • authorising only appropriate users
  • complying with applicable Meta policies
  • configuring their integrations appropriately
  • ensuring that their use of Meta services is lawful

Faira does not sell Meta Platform Data.

Faira uses third-party telecommunications and voice infrastructure to provide voice functionality.

Depending on the market, Faira may use:

Twilio

Twilio may be used for voice and telecommunications services in:

  • the United Kingdom
  • the United States
  • Europe

Where supported, Faira may use regional Twilio infrastructure and processing.

Africa's Talking

Africa's Talking may be used for voice services in:

  • Nigeria
  • Kenya

Vapi

Vapi may be used for voice AI orchestration and associated voice-processing functionality.

Voice infrastructure may process:

  • telephone numbers
  • call metadata
  • audio
  • call recordings where enabled
  • transcripts
  • AI-generated responses
  • other information required to provide the voice service

Faira uses AI technologies to provide features such as:

  • transcription
  • conversation understanding
  • lead qualification
  • summarisation
  • response generation
  • workflow execution
  • AI voice interactions

Faira may use OpenAI and Vapi as part of its AI infrastructure.

Faira applies appropriate controls to the information sent to AI providers and seeks to minimise unnecessary personal data.

AI providers may process information according to their applicable contractual terms and technical architecture.

Faira does not represent that AI-generated output is always accurate or free from error.

Faira is designed to process customer information only to the extent necessary to provide the services and other permitted purposes.

Faira does not sell customer data.

Where Faira uses third-party AI services, Faira seeks to ensure that contractual and technical controls are in place regarding the use of customer information.

Customers should avoid submitting information to Faira that is unnecessary for the service they are using.

Faira uses a regionalised infrastructure model where technically and commercially appropriate.

Our current intended model is:

  • UK. UK customer data is intended to be hosted on UK AWS infrastructure.
  • EU. EU customer data is intended to be hosted on EU AWS infrastructure.
  • US. US customer data is intended to be hosted on US AWS infrastructure.
  • Africa. African customer data is intended to be hosted on US AWS infrastructure.

Certain third-party services may operate independently of this AWS architecture.

As a result, some information may be processed outside the customer's primary geographic region.

This may occur for:

  • telecommunications
  • AI processing
  • Meta platform services
  • security
  • monitoring
  • support
  • authentication
  • service administration
  • other necessary functions

Where required, Faira implements appropriate international data-transfer safeguards.

Faira uses carefully selected third-party providers to deliver parts of its services.

Principal providers may include:

ProviderFunction
Amazon Web ServicesCloud infrastructure, hosting, databases and storage
OpenAIArtificial intelligence processing
VapiVoice AI orchestration
TwilioTelecommunications and voice infrastructure
Africa's TalkingTelecommunications and voice infrastructure in Nigeria and Kenya
Meta / WhatsAppWhatsApp communications
Meta / InstagramInstagram messaging
Meta / Facebook / MessengerFacebook and Messenger communications

Further information about our subprocessors and processing locations is available through the Subprocessor Schedule where applicable.

Faira limits access to customer information based on role and business need.

Where appropriate, personnel with access to confidential or personal information are subject to:

  • confidentiality obligations
  • access controls
  • security procedures
  • security awareness requirements
  • appropriate onboarding and offboarding processes

Access is removed or adjusted when personnel no longer require it.

Faira monitors its infrastructure and services for security and operational events.

Depending on the system, this may include:

  • authentication events
  • access logs
  • application events
  • infrastructure events
  • system errors
  • suspicious activity
  • service availability

Security information may be retained for an appropriate period to support:

  • incident investigation
  • security monitoring
  • fraud prevention
  • troubleshooting
  • legal or regulatory requirements

Faira seeks to identify and address security vulnerabilities affecting its systems.

Depending on the nature and severity of a vulnerability, Faira may:

  • investigate the issue
  • assess its potential impact
  • apply security patches
  • update affected components
  • implement mitigating controls
  • monitor the issue through remediation

Security issues are prioritised according to their potential impact and risk.

Faira maintains processes for identifying, investigating and responding to suspected security incidents.

Where Faira determines that a security incident has resulted in a personal data breach requiring notification under applicable law, Faira will make notifications within the applicable statutory timeframe.

Where Faira acts as a processor, Faira will notify the relevant business customer in accordance with the applicable Data Processing Agreement.

Customers are responsible for maintaining accurate security and privacy contacts so that incident notifications can be delivered promptly.

Faira uses cloud infrastructure and operational controls designed to support service resilience.

Depending on the service, these may include:

  • backups
  • redundancy
  • monitoring
  • recovery procedures
  • infrastructure automation
  • incident-response processes

Recovery objectives may vary depending on the service and infrastructure involved.

Faira does not guarantee uninterrupted availability.

Faira maintains processes for deleting personal data in accordance with applicable retention requirements.

Customers may request deletion of applicable personal data through Faira's privacy process.

Where Faira acts as a processor, deletion is handled in accordance with the customer's instructions and applicable contractual requirements.

Further information is available on our Data Deletion & Privacy Requests page.

Security is a shared responsibility.

Customers are responsible for:

  • maintaining secure account credentials
  • controlling user access
  • using appropriate authentication
  • configuring integrations securely
  • protecting devices used to access Faira
  • ensuring authorised use of customer data
  • maintaining appropriate internal security policies
  • promptly reporting suspected security incidents

Customers should not share account credentials between users.

Faira is committed to complying with applicable data protection and other legal requirements relevant to the services it provides.

Depending on the applicable service and jurisdiction, this may include requirements under:

  • UK GDPR
  • the Data Protection Act 2018
  • applicable EU data protection law
  • applicable telecommunications laws
  • electronic marketing laws
  • Meta platform requirements
  • other applicable regulatory requirements

Faira's compliance obligations depend on the role Faira plays in a particular processing activity.

Faira's approach to personal data is described in our Privacy Policy.

Where Faira processes personal data for a business customer, the relevant processing relationship is governed by the applicable Data Processing Agreement.

The DPA may include additional requirements relating to:

  • processing instructions
  • confidentiality
  • security
  • subprocessors
  • international transfers
  • data subject requests
  • security incidents
  • deletion and return of data
  • audits

Faira is committed to developing its security and compliance programme in line with recognised industry practices.

Unless expressly stated in writing, Faira does not represent that it currently holds a particular third-party security certification or independent assurance report.

We will update this page as certifications or independent assurance programmes are completed.

Security and privacy enquiries can be directed to compliance@getfaira.com.

For security-related matters, please include the subject line Security Enquiry.

For suspected security incidents involving Faira, please provide sufficient information for us to investigate the issue, while avoiding the transmission of unnecessary personal or confidential information.

Faira may update this Security & Compliance page as our security programme, infrastructure, services or regulatory obligations evolve.

The date at the top of this page indicates when it was last updated.