Legal

Faira Privacy Policy

Last updated: 27 August 2026

27 sections

Faira Platforms Ltd (“Faira”, “we”, “us” or “our”) respects your privacy and is committed to protecting your personal data.

This Privacy Policy explains how we collect, use, disclose, store and protect personal data when you:

  • visit or use the Faira website;
  • contact Faira;
  • create or use a Faira account;
  • use Faira’s products or services;
  • communicate with a business that uses Faira;
  • communicate with an AI assistant or voice agent powered by Faira;
  • communicate through WhatsApp, Instagram, Facebook or Messenger through a Faira-powered integration; or
  • otherwise interact with Faira or a service powered by Faira.

This Privacy Policy is intended to explain Faira’s processing activities in a clear and transparent way.

Where a business uses Faira to process information about its own customers, patients, clients, prospects or other individuals, that business may be the controller of that information and Faira may act as its processor. In those circumstances, the business customer’s own privacy notice may also apply.

FAIRA PLATFORMS LTD is a company incorporated in England and Wales.

Company number
17059377
Registered office
2 Guthrum Court, 1 Cavendish Square, London, England, E16 2XN

Companies House records Faira Platforms Ltd as an active private limited company incorporated on 27 February 2026.

Unless otherwise stated in this Privacy Policy, Faira is the organisation responsible for the processing described here.

Faira provides technology that helps businesses capture, manage and convert customer enquiries and communications.

Depending on the service and configuration, Faira may provide:

  • AI-powered customer communications;
  • AI voice receptionists and voice agents;
  • telephone and voice communications;
  • WhatsApp communications;
  • Instagram Direct messaging;
  • Facebook Messenger communications;
  • website chat and enquiry capture;
  • customer enquiry management;
  • lead qualification;
  • appointment and booking workflows;
  • CRM integration;
  • automated follow-up;
  • conversation transcription;
  • conversation analysis;
  • AI-generated responses;
  • workflow automation; and
  • reporting and analytics.

Not every feature is available to every customer.

The role Faira plays depends on the circumstances.

3.1 When you interact directly with Faira

When you:

  • visit our website;
  • contact us;
  • request a demonstration;
  • create an account;
  • subscribe to Faira;
  • use our website or application directly; or
  • communicate with Faira support or sales teams,

Faira will generally act as a data controller.

This means Faira determines why and how your personal data is processed.

3.2 When you interact with a business using Faira

A business may use Faira to communicate with its own customers, patients, clients, members, prospects or other contacts.

For example, a business may use Faira to:

  • answer incoming telephone calls;
  • respond to WhatsApp messages;
  • respond to Instagram messages;
  • respond to Facebook messages;
  • qualify enquiries;
  • arrange appointments; or
  • follow up with prospective customers.

In these circumstances, the business will generally determine why your personal data is processed and Faira will generally act as a data processor on that business’s behalf.

The business remains responsible for determining its lawful basis for processing and providing appropriate privacy information to individuals.

Faira may nevertheless act as a controller for certain limited processing necessary for Faira’s own purposes, including security, fraud prevention, service administration, legal compliance and protection of our systems and rights.

The information Faira processes depends on how you interact with Faira and which features a business has enabled.

4.1 Identity and contact information

This may include:

  • name;
  • email address;
  • telephone number;
  • postal address;
  • company or organisation;
  • job title;
  • account identifiers; and
  • other contact information.

4.2 Account and business information

For Faira customers and authorised users, this may include:

  • business name;
  • company information;
  • account information;
  • subscription information;
  • billing information;
  • user roles;
  • permissions;
  • configuration information;
  • integration settings; and
  • information about use of the Faira platform.

4.3 Communications data

When you communicate through Faira, we may process:

  • messages;
  • voice communications;
  • emails;
  • SMS;
  • WhatsApp messages;
  • Instagram Direct messages;
  • Facebook Messenger messages;
  • call metadata;
  • recordings where recording is enabled;
  • transcripts;
  • attachments;
  • images or other content you provide; and
  • information generated from those communications.

4.4 Voice and telephone data

Where Faira provides voice functionality, we may process:

  • telephone numbers;
  • caller and recipient information;
  • call date and time;
  • call duration;
  • call routing information;
  • call status;
  • call audio;
  • call recordings, where enabled;
  • speech-to-text transcripts;
  • AI-generated summaries;
  • conversation metadata; and
  • information relating to actions taken during or following a call.

Faira may use Twilio for voice and telecommunications services in the UK, United States and Europe.

Faira may use Africa’s Talking for voice services in Nigeria and Kenya.

Faira may use Vapi for voice AI orchestration and associated voice-processing functionality.

4.5 Information from third-party platforms

Where a business connects Faira to a third-party platform, Faira may receive information made available through that integration.

This may include information from:

  • Meta platforms;
  • WhatsApp;
  • Instagram;
  • Facebook and Messenger;
  • CRM systems;
  • booking and calendar systems;
  • telephony providers;
  • communication platforms;
  • website forms;
  • analytics platforms; and
  • other services authorised by the business.

The information available depends on the permissions granted and the functionality enabled.

Faira may integrate with Meta technologies to enable businesses to manage customer communications through supported Meta services.

Depending on the integration, these services may include:

  • WhatsApp Business Platform;
  • Instagram messaging / Instagram Direct;
  • Facebook Pages and Messenger; and
  • other Meta APIs or technologies made available to Faira.

Where permitted by the relevant Meta platform and the permissions granted by the business, Faira may process:

  • Meta account or page identifiers;
  • Instagram account information;
  • WhatsApp Business information;
  • Facebook Page information;
  • message content;
  • message metadata;
  • profile information made available through the applicable API;
  • conversation history; and
  • other information required to provide the requested integration.

Faira uses Meta Platform Data to provide the functionality requested by the business customer and for purposes permitted by applicable law and the applicable Meta platform terms.

Faira does not sell Meta Platform Data.

Faira does not use Meta Platform Data for purposes unrelated to the functionality for which it was obtained.

Where applicable, individuals can request deletion of personal data associated with their use of Meta-connected services through Faira’s Data Deletion & Privacy Requests process.

Faira provides technology that may allow businesses to use AI-powered voice agents and other automated telephone functionality.

Depending on the configuration selected by the business, Faira may:

  • receive incoming calls;
  • make outbound calls;
  • route calls;
  • process caller information;
  • transcribe speech;
  • analyse conversations;
  • generate AI responses;
  • record calls;
  • generate summaries;
  • identify information within a conversation; and
  • trigger configured business workflows.

Call recording

A business may configure Faira to record calls.

Where recording is enabled, the relevant business is generally responsible for determining whether recording is lawful and for providing any disclosures or obtaining any consent required by applicable law.

Call recordings may be:

  • transmitted through telecommunications infrastructure;
  • processed by voice AI infrastructure;
  • converted into transcripts;
  • analysed by AI systems;
  • made available to authorised users of the relevant business; and
  • deleted in accordance with the applicable retention configuration and contractual requirements.

Faira may provide technical functionality to support call recording disclosures and consent mechanisms. The availability or use of such functionality does not itself guarantee compliance with the laws applicable to a particular call, business or jurisdiction.

Faira uses artificial intelligence to provide parts of its platform.

Depending on the service, AI may be used to:

  • understand customer enquiries;
  • transcribe voice conversations;
  • classify conversations;
  • identify customer intent;
  • qualify enquiries;
  • summarise conversations;
  • generate responses;
  • assist with appointment booking;
  • recommend workflow actions;
  • execute configured workflow actions; and
  • assist human operators.

Faira may process conversation content, audio, transcripts, prompts, contextual information and other relevant data through AI systems in order to provide these services.

7.1 OpenAI

Faira uses OpenAI for certain artificial intelligence processing.

Depending on the functionality, information sent to OpenAI may include:

  • conversation content;
  • voice transcripts;
  • prompts;
  • contextual information;
  • customer-provided information; and
  • other information necessary to generate the requested AI output.

Faira will configure AI processing in accordance with the applicable Faira service architecture, contractual requirements and available regional processing capabilities.

7.2 AI-generated information

AI-generated information can contain errors, omissions or inaccuracies.

Businesses using Faira are responsible for configuring appropriate workflows, reviewing AI outputs where appropriate and determining when human intervention is required.

Faira does not represent that AI-generated information is always accurate, complete or appropriate for a particular purpose.

Faira supports automated processing and workflow execution.

For example, Faira may automatically:

  • classify an enquiry;
  • identify an apparent customer intent;
  • determine which configured workflow applies;
  • ask qualification questions;
  • route a conversation;
  • schedule an appointment; or
  • send a configured follow-up message.

These activities are generally performed to provide the service configured by the business customer.

Where a business uses Faira to make decisions about individuals that have legal or similarly significant effects, the business is responsible for ensuring that the processing complies with applicable data protection law, including requirements relating to solely automated decision-making and profiling.

Faira does not intentionally design its standard customer-enquiry functionality to make solely automated decisions producing legal or similarly significant effects on individuals.

Individuals may choose to provide sensitive or special category information during a conversation.

Depending on the circumstances, this could include information concerning:

  • health;
  • disability;
  • racial or ethnic origin;
  • religious or philosophical beliefs;
  • political opinions;
  • sexual orientation;
  • biometric information; or
  • other specially protected information.

Faira does not require individuals to provide such information unless it is necessary for a particular service configured by a business.

Where a business uses Faira in circumstances involving special category data, the business is responsible for determining whether it has an appropriate lawful basis and additional legal condition for processing.

Businesses should configure Faira to minimise the collection of sensitive information and should not request such information unless there is a legitimate and lawful reason to do so.

Faira may receive personal data from sources other than the individual concerned.

These may include:

  • Faira business customers;
  • Meta platforms;
  • WhatsApp;
  • Instagram;
  • Facebook;
  • CRM systems;
  • booking systems;
  • calendar systems;
  • telecommunications providers;
  • communication platforms;
  • service providers;
  • publicly available sources; and
  • other integrations authorised by a business customer.

Where required by applicable law, Faira will provide appropriate privacy information when personal data is obtained from another source.

We process personal data for the following purposes.

PurposeExamplesTypical lawful basis
Provide FairaAccounts, communications, workflows and integrationsContract
Provide voice servicesCalls, routing, recordings and transcripts where enabledContract / legitimate interests / consent where required
Provide messaging servicesWhatsApp, Instagram and Messenger communicationsContract
Provide AI functionalityTranscription, analysis and AI-generated responsesContract
SecurityAuthentication, monitoring, abuse prevention and fraud detectionLegitimate interests / legal obligation
Service administrationSupport, troubleshooting and account managementContract / legitimate interests
Product improvementReliability, performance and service developmentLegitimate interests / contractual restrictions
Legal complianceRegulatory, legal and accounting requirementsLegal obligation
MarketingBusiness communications and marketing where permittedConsent / legitimate interests, as applicable

The applicable lawful basis depends on the specific processing activity and circumstances.

Where UK GDPR or equivalent data protection law applies, Faira relies on one or more of the following lawful bases.

Contract

Where processing is necessary to:

  • provide a service;
  • manage an account;
  • fulfil a subscription;
  • provide requested functionality; or
  • take steps at an individual’s request before entering into a contract.

Legitimate interests

Faira may rely on legitimate interests for purposes including:

  • operating our business;
  • securing our systems;
  • preventing fraud and abuse;
  • improving our services;
  • administering accounts;
  • communicating with business contacts;
  • protecting our legal rights; and
  • maintaining the reliability and security of the platform.

Where we rely on legitimate interests, we consider the impact on individuals and balance our interests against their rights and freedoms.

Legal obligation

Where processing is necessary to comply with a legal or regulatory obligation.

Consent

Where applicable law requires consent, we will obtain it before carrying out the relevant processing.

Where processing relies on consent, you may withdraw your consent at any time.

Withdrawal of consent does not affect processing that occurred before consent was withdrawn.

Faira uses third-party providers to provide, secure and operate its services.

Our principal service providers may include the following:

ProviderPurposeData that may be processedIntended processing / service geography
Amazon Web Services (AWS)Hosting, databases, storage and infrastructureApplication data, account data, customer data, logs and related technical dataUK data: UK; EU data: EU; US data: US; Africa data: US
OpenAIArtificial intelligencePrompts, conversation content, transcripts and information required for AI processingRegional processing where available and configured
Vapi Inc.Voice AI orchestrationCall audio, transcripts, call metadata and AI/voice workflow dataRegional processing where available and configured; Vapi infrastructure may involve US/EU processing depending on configuration
TwilioTelecommunications and voice infrastructurePhone numbers, call metadata, communications data and audio where applicableUK, US and European voice services; processing depends on the applicable Twilio service and configured region
Africa’s TalkingTelecommunications and voice servicesPhone numbers, call metadata, communications data and audio where applicableNigeria and Kenya service deployments; processing locations depend on the applicable service
Meta / WhatsAppWhatsApp Business communicationsMessages, identifiers, metadata and account informationMeta/WhatsApp infrastructure and applicable international transfers
Meta / InstagramInstagram messagingMessages, identifiers, metadata and account informationMeta infrastructure and applicable international transfers
Meta / Facebook / MessengerFacebook messagingMessages, identifiers, metadata and account informationMeta infrastructure and applicable international transfers

The above table describes the principal categories of providers used or intended to be used by Faira. The detailed list of subprocessors and relevant processing information may be maintained separately in Faira’s Subprocessor Schedule.

We may add or replace subprocessors where necessary to operate and develop the service, subject to applicable contractual and legal requirements.

Faira is designed to use geographically appropriate infrastructure where available and appropriate.

Our intended core infrastructure model is:

  • UK customer data: UK AWS infrastructure;
  • EU customer data: EU AWS infrastructure;
  • US customer data: US AWS infrastructure;
  • Africa customer data: US AWS infrastructure.

Voice services may use different infrastructure depending on the country and service.

For example:

  • UK and European voice services may use Twilio infrastructure and regional processing where supported;
  • US voice services may use Twilio US infrastructure;
  • Nigerian and Kenyan voice services may use Africa’s Talking;
  • voice AI orchestration may be provided through regionally configured Vapi infrastructure.

Regional processing does not necessarily mean that every item of data, operational metadata, security log or support information remains within the same geographic region. Some providers may process particular categories of information in other locations as part of providing, securing or supporting their services.

For example, Twilio’s current documentation states that regional processing can store and process customer content in a selected region for supported services, while other account and service-use information may continue to be processed in the United States.

Vapi’s current documentation similarly explains that call logs can include transcripts, recordings and metadata and that orchestration infrastructure operates across its US/EU infrastructure depending on configuration.

Where personal data is transferred outside the United Kingdom, Faira will use an appropriate lawful transfer mechanism and safeguards required by applicable data protection law.

These may include:

  • an adequacy decision;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to the EU Standard Contractual Clauses;
  • appropriate contractual protections; or
  • another legally permitted transfer mechanism.

Faira retains personal data only for as long as reasonably necessary for the purposes for which it is processed, unless a longer period is required or permitted by law.

Retention depends on factors including:

  • the type of data;
  • the purpose of processing;
  • the nature of the relationship;
  • contractual requirements;
  • legal and regulatory requirements;
  • security requirements;
  • dispute resolution requirements; and
  • whether the data is required to establish or defend legal claims.

Different retention periods may apply to:

  • account information;
  • customer records;
  • messages;
  • call recordings;
  • transcripts;
  • AI interaction data;
  • system logs;
  • security records;
  • billing records; and
  • backups.

For personal data processed by Faira on behalf of a business customer, retention will generally follow the customer’s documented instructions and the applicable agreement.

Specific retention periods may be set through the Faira product or applicable customer agreement.

Where we are unable to provide a fixed retention period, we use the criteria above to determine how long the information should be retained.

Individuals may request deletion of personal data held by Faira, subject to applicable law and any lawful grounds for retaining information.

Faira may also delete information automatically in accordance with configured retention periods.

Where Faira processes information on behalf of a business customer, deletion requests may need to be handled by or through that business.

For information about how to request deletion, including deletion of information associated with Meta integrations, see our Data Deletion & Privacy Requests page.

Faira uses appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, destruction, alteration or disclosure.

These measures may include:

  • access controls;
  • authentication;
  • role-based permissions;
  • encryption where appropriate;
  • infrastructure security;
  • logging and monitoring;
  • secure development practices;
  • backup and recovery controls;
  • incident management; and
  • access limitation based on business need.

No internet-based service can guarantee absolute security.

Further information about our security practices will be provided on our Security & Compliance page.

Depending on the circumstances and applicable law, you may have the right to:

  • access your personal data;
  • correct inaccurate or incomplete personal data;
  • request deletion;
  • restrict processing;
  • object to processing;
  • request data portability;
  • withdraw consent where processing is based on consent; and
  • object to or obtain safeguards concerning certain forms of automated decision-making and profiling.

These rights are not absolute and may not apply in every circumstance.

For example, Faira may be entitled or required to retain certain information to comply with legal obligations or establish, exercise or defend legal claims.

Where Faira processes your personal data based on legitimate interests, you have the right to object to that processing.

You can exercise this right by contacting compliance@getfaira.com.

We will assess your objection in accordance with applicable law.

Where applicable, you may also object to direct marketing at any time.

To exercise your privacy rights, contact compliance@getfaira.com.

Please provide sufficient information for us to understand your request and, where necessary, verify your identity.

If your personal data is being processed by Faira solely on behalf of a business customer, we may refer your request to that business or assist the business in responding to it.

We will respond within the timeframe required by applicable law.

If you have concerns about Faira’s use of your personal data, please contact us first at compliance@getfaira.com.

You also have the right to lodge a complaint with the relevant data protection supervisory authority.

For individuals in the United Kingdom, this is the Information Commissioner’s Office (ICO).

Further information is available from the ICO’s website.

Where permitted by applicable law, Faira may send marketing communications to business contacts.

You can unsubscribe from marketing communications at any time by:

We may continue to send essential service, transactional or administrative communications where necessary to provide the service.

Faira uses cookies and similar technologies on its website and services.

These may be used for:

  • essential website functionality;
  • security;
  • remembering preferences;
  • analytics;
  • performance measurement; and
  • marketing where applicable.

Further information is provided in our Cookie Policy.

Faira’s services are intended for businesses and are not directed at children.

Faira does not knowingly seek to collect personal data directly from children except where such processing forms part of a service provided by a business customer and is lawful and appropriately managed.

Businesses using Faira are responsible for ensuring that their use of Faira is appropriate for their customer base and complies with applicable requirements concerning children.

If you believe that Faira has received personal data from a child in circumstances where it should not have been collected, please contact compliance@getfaira.com.

Faira may link to or integrate with third-party services.

Third-party services may have their own privacy policies and terms.

Faira is not responsible for the privacy practices of third-party services that it does not control.

When a business enables a third-party integration, the third party may process information in accordance with its own terms and privacy documentation.

We may update this Privacy Policy from time to time to reflect:

  • changes to our services;
  • changes to our processing activities;
  • new technologies;
  • changes to third-party providers;
  • changes to applicable law; or
  • changes to regulatory requirements.

Where appropriate, we will take reasonable steps to notify users of material changes.

The date at the top of this Privacy Policy indicates when it was most recently updated.

For questions about this Privacy Policy, personal data or your privacy rights, contact:

Company
FAIRA PLATFORMS LTD
Company number
17059377
Registered office
2 Guthrum Court, 1 Cavendish Square, London, England, E16 2XN