Legal
Privacy policy
Last updated: 24 August 2026
The short version
Faira answers for businesses across voice, calls and VoIP, and chat, meaning a website widget, WhatsApp, Instagram and email. That means we handle recordings of conversations, written threads, and sometimes sensitive things people say or type during them. We take that seriously.
There are two different situations, and this policy covers both.
When you're a Faira customer, the information about you, your account, your billing, your usage, is ours to look after. We decide what happens to it. Part A explains what we do.
When Faira answers for you, the information about the person contacting you is yours to look after. You decide what happens to it. We only act on your instructions. Part B explains how that works.
If you're a member of the public and Faira answered your call, chat, message or email, Part B and your rights are the sections for you, and the business you contacted is the first place to go with a request.
1. Who we are
- Company
- Faira Platforms Ltd
- Company number
- 17059377
- Registered office
- 2 Guthrum Court, 1 Cavendish Square, London, E16 2XN, England
- Privacy contact
- privacy@getfaira.com
- Data protection lead
- Contact legal@getfaira.com for the current name and role.
- EU representative (Article 27 GDPR)
- Contact legal@getfaira.com for the current name and address.
- Nigeria contact
- Contact legal@getfaira.com for the current local contact.
Part A: When we're the controller
This part covers people we deal with directly: visitors to our website, people who enquire about Faira, our customers and their staff, and applicants for jobs.
What we collect and why
| What | Why | Our lawful basis |
|---|---|---|
| Name, business email, phone, company name | To respond to enquiries, create and run your account | Contract; legitimate interests (responding to enquiries) |
| Account and login data | To authenticate you and secure your account | Contract; legal obligation (security) |
| Billing details, plan, invoices, payment status | To take payment and keep accounts | Contract; legal obligation (tax and accounting) |
| Usage data: calls handled, minutes used, features used, errors | To run and improve the service, and to bill you correctly | Contract; legitimate interests (running and improving a service you pay for) |
| Support conversations | To help you, and to improve how we help | Contract; legitimate interests |
| Onboarding answers about your business | To configure your agent | Contract |
| Marketing preferences, email engagement | To send you things you've asked for, and to stop sending things you haven't | Consent; legitimate interests (B2B marketing to existing customers) |
| Website analytics and cookies | To understand how the site is used | Consent, where required. See our cookie policy. |
| Device, IP address, log data | Security, fraud prevention, debugging | Legitimate interests; legal obligation |
We do not buy personal data from data brokers, and we do not sell or rent yours.
Marketing
If you're an existing customer or you've asked us about Faira, we may email you about the product. You can stop that at any time using the link in any email, or by writing to privacy@getfaira.com. We'll still send you service messages: billing, security, outages, because you need those.
How long we keep it
| What | How long |
|---|---|
| Account records | For the life of your account, then 12 months |
| Trial accounts that don't convert | 30 days after the trial ends, then deleted |
| Accounts refunded under the money-back guarantee | 30 days after the refund, then deleted. Sooner if you ask |
| Billing and tax records | 6 years, as UK tax law requires |
| Support conversations | 24 months |
| Enquiries that don't become customers | 12 months |
| Marketing preferences | Until you change them, plus a suppression record kept indefinitely so we don't contact you again |
| Security logs | 12 months |
Part B: When we're the processor
When Faira answers a call, replies to a message, takes a booking or sends an email on behalf of a business, that business is the controllerof the information involved. We are its processor. We act on its documented instructions and nothing else.
This applies across every channel: calls, VoIP, the website widget, WhatsApp, Instagram and email.
If you contacted a business and Faira answered, the business you contacted decides how your information is used and how long it is kept. Contact them first. If you'd rather come to us, write to privacy@getfaira.com and we'll pass your request on and help them respond.
What gets processed
- Who they are: phone number, WhatsApp number, Instagram handle and display name, email address, and their name if they give it
- What they said or wrote: call audio and transcripts, website widget messages, WhatsApp and Instagram messages, and email content including anything attached
- Booking details: service, date, time, staff member, notes
- Whether they're a returning contact, and what happened last time, including on a different channel
- Outcomes: booked, not booked, needs follow-up, payment requested
- Technical data: time, duration, channel, route, call quality, message delivery and read status
Recordings, transcripts and messages
Faira works by listening or reading, then responding. Recording, transcription and message storage are not optional extras, they are how the product functions.
On calls, audio is recorded and transcribed. The business you called is responsible for telling you that, and for having a lawful basis to record. Faira provides call announcements to help them do it.
In the website widget, on WhatsApp, on Instagram and in email, the content of the conversation is stored, because Faira needs the thread to answer sensibly and the business needs the record. Written channels tend to keep more, for longer, and in a form that is easier to read at a glance than an audio file.
Retention is set by the business, within the options we offer. Our default is 90 days for audio and 24 months for transcripts and messages, but a business can shorten or extend that.
If a business lets a trial lapse, or takes a refund under our money-back guarantee, there is no longer anyone instructing us on that data. We give them 30 days to export it, then delete it.
What we receive from Meta
When someone messages a business's WhatsApp or Instagram, Meta passes us their phone number or handle, their display name, their profile picture where the platform provides it, and the content of the message.
That is the extent of it. We do not receive their contacts, their friends, their posts, their browsing, or anything else from their Meta profile, and we do not ask for it.
What we access in a connected mailbox
Where a business connects email, Faira accesses that mailbox within the permission the business grants, and reads messages in order to answer them.
We use mailbox contents only to run the service for that business. We do not use them for advertising, for building profiles, or for training AI models, and we hold that access to the limited-use requirements the mail provider imposes. The business can revoke our access at any time from their mail provider.
Sensitive information
Some Faira customers are clinics, dental practices and medical practices. People contacting those businesses often mention health information without being asked to: a condition, a treatment, a medication. They do it on the phone, and they do it just as readily in a WhatsApp message or an email, where it stays written down.
Health information gets extra protection under data protection law. Wherever it appears, in a call, a chat, a message or an email, it is processed under the same instructions as everything else, and it is subject to the additional safeguards in our data processing agreement: restricted internal access, encryption at rest and in transit, and no use for any purpose beyond delivering the service.
We instruct our customers not to configure Faira to solicit health information it does not need, on any channel. Whether they follow that instruction is their responsibility as controller.
We do not use Faira to infer emotion, health status, or any other characteristic about a person beyond what is needed to handle the conversation. People are told they are dealing with an AI.
AI and model training
We do not train general-purpose AI models on your calls, your recordings or your transcripts. Your content is not used to build a model that other Faira customers benefit from, and it is not sold or licensed to anyone who does that.
Faira Instinctâ„¢ learns within your account. It observes what happened on your calls, whether people booked, what they asked about, where conversations broke down, and uses that to improve how your agent behaves. That learning stays with your agent. It is not pooled across customers.
We use third-party AI providers for speech recognition, speech synthesis and language processing. We contract with them on terms that prohibit using your content to train their models and that require prompt deletion. Our current providers are listed below.
We use aggregated statistics to improve Faira generally: how long calls take, how often transfers happen, which intents fail. These are counts and rates. They contain no personal data and cannot be traced back to a caller or a customer.
Faira makes no automated decision that produces a legal or similarly significant effect on a caller. It books, answers and routes. It does not decide eligibility, price, credit or access to a service on its own. If a Faira customer configures it to do something closer to that line, they are responsible for meeting the additional requirements that apply.
Who we share information with
We share personal data with service providers who help us run Faira. Each one is contractually bound, processes only on our instructions, and is subject to appropriate security requirements.
| Provider | What they do | Where |
|---|---|---|
| AWS | Cloud hosting, application infrastructure, databases and storage | UK / EEA / US, depending on the AWS region configured |
| Vapi | Voice AI orchestration, call routing and media handling | US / other jurisdictions, depending on service configuration |
| Twilio | Telecoms infrastructure, phone numbers and call delivery | UK / EEA / US, depending on the service and routing configuration |
| OpenAI | Speech recognition, text-to-speech and AI language processing | UK / EEA / US, depending on the service and processing configuration |
| Meta Platforms | Delivery of WhatsApp and Instagram messages | Ireland / US |
| Cal.com | Calendar integration and appointment scheduling | US / EEA, depending on service configuration |
| n8n | Workflow automation and orchestration | UK / EEA / US, depending on hosting configuration |
| Email infrastructure provider | Sending and receiving email on your connected domain | UK / EEA / US, depending on the email provider and configuration |
| Widget CDN | Serving the Faira website chat widget and related assets | Global / distributed network |
| Stripe | Subscription billing and payment links where enabled | UK / EEA / US, depending on the service and processing configuration |
| Support and analytics providers | Customer support, product analytics and understanding product use | UK / EEA / US, depending on the provider and configuration |
A current list of sub-processors is available on request from privacy@getfaira.com. Customers can ask to be notified of changes.
We also share information:
- with professional advisers: lawyers, accountants, auditors, where needed
- with authorities, where the law requires it and after checking that the request is valid
- with a buyer, if our business is sold, subject to the same protections
- with anyone else, only if you ask us to
Sending information between countries
Faira operates in the UK, France and Nigeria, and some of our providers operate elsewhere. That means personal data sometimes moves between countries.
Where we move personal data out of the UK or the EEA to a country without an adequacy decision, we use:
- the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses
- the EU Standard Contractual Clauses
- a transfer risk assessment, and additional technical measures such as encryption where the assessment calls for them
For Nigeria, transfers are made on the bases permitted by the Nigeria Data Protection Act 2023.
Customers can ask us for details of the safeguards that apply to their account at privacy@getfaira.com.
Keeping information secure
We use encryption in transit and at rest, role-based access controls, least-privilege internal access, logging and monitoring, and regular review of who can see what.
Access to call recordings, transcripts and message threads is restricted to staff who need it to support the service, and that access is logged.
No system is perfectly secure. If a breach affects your personal data and is likely to result in a high risk to you, we will tell you, and we will notify the relevant regulator within the time the law allows.
Your rights
Depending on where you are, you have rights over your personal data. In the UK and the EU these include the right to:
- know what we hold and get a copy of it
- correct it if it's wrong
- delete it, in some circumstances
- restrict or object to how we use it, including for marketing
- take it with you in a portable format
- withdraw consent at any time, where we relied on consent
- not be subject to a decision made solely by automated means with legal or similarly significant effect
In Nigeria, the Nigeria Data Protection Act 2023 gives you comparable rights.
To exercise a right, email privacy@getfaira.com. We'll respond within one month, and we'll tell you if we need longer. We may need to verify who you are first. We don't charge, unless a request is clearly excessive.
If Faira answered your call, chat, message or email to a business, that business decides how your data is used. Ask them first, they can act on your request directly. If you contact us instead, we'll pass it on promptly and support them in answering it.
Complaints
Please tell us first at privacy@getfaira.com, we'd rather fix it.
You can also complain to a regulator:
- UK: Information Commissioner's Office, ico.org.uk, 0303 123 1113
- France: Commission Nationale de l'Informatique et des Libertes, cnil.fr
- Nigeria: Nigeria Data Protection Commission, ndpc.gov.ng
- Elsewhere in the EU: your national supervisory authority
Children
Faira is not intended for children, and we don't knowingly collect data about anyone under 16 through our website or our sales process.
People contacting a Faira customer may sometimes be minors: a parent's phone, a teenager booking an appointment, a message from an Instagram account. WhatsApp and Instagram set their own minimum ages, and we rely on the platform to enforce them. Where a minor does get through, the business is the controller and is responsible for handling it appropriately. Tell us at privacy@getfaira.com if you believe a child's data has been handled incorrectly and we'll help the business put it right.
Changes to this policy
We'll update this page when what we do changes. If a change is significant, we'll tell customers by email or in-app before it takes effect. The date at the top always shows the current version.
Faira Platforms Ltd is registered in England and Wales, company number 17059377, at 2 Guthrum Court, 1 Cavendish Square, London, E16 2XN.