Legal

Privacy policy

Last updated: 24 August 2026

The short version

Faira answers for businesses across voice, calls and VoIP, and chat, meaning a website widget, WhatsApp, Instagram and email. That means we handle recordings of conversations, written threads, and sometimes sensitive things people say or type during them. We take that seriously.

There are two different situations, and this policy covers both.

When you're a Faira customer, the information about you, your account, your billing, your usage, is ours to look after. We decide what happens to it. Part A explains what we do.

When Faira answers for you, the information about the person contacting you is yours to look after. You decide what happens to it. We only act on your instructions. Part B explains how that works.

If you're a member of the public and Faira answered your call, chat, message or email, Part B and your rights are the sections for you, and the business you contacted is the first place to go with a request.

1. Who we are

Company
Faira Platforms Ltd
Company number
17059377
Registered office
2 Guthrum Court, 1 Cavendish Square, London, E16 2XN, England
Privacy contact
privacy@getfaira.com
Data protection lead
Contact legal@getfaira.com for the current name and role.
EU representative (Article 27 GDPR)
Contact legal@getfaira.com for the current name and address.
Nigeria contact
Contact legal@getfaira.com for the current local contact.

Part A: When we're the controller

This part covers people we deal with directly: visitors to our website, people who enquire about Faira, our customers and their staff, and applicants for jobs.

What we collect and why

WhatWhyOur lawful basis
Name, business email, phone, company nameTo respond to enquiries, create and run your accountContract; legitimate interests (responding to enquiries)
Account and login dataTo authenticate you and secure your accountContract; legal obligation (security)
Billing details, plan, invoices, payment statusTo take payment and keep accountsContract; legal obligation (tax and accounting)
Usage data: calls handled, minutes used, features used, errorsTo run and improve the service, and to bill you correctlyContract; legitimate interests (running and improving a service you pay for)
Support conversationsTo help you, and to improve how we helpContract; legitimate interests
Onboarding answers about your businessTo configure your agentContract
Marketing preferences, email engagementTo send you things you've asked for, and to stop sending things you haven'tConsent; legitimate interests (B2B marketing to existing customers)
Website analytics and cookiesTo understand how the site is usedConsent, where required. See our cookie policy.
Device, IP address, log dataSecurity, fraud prevention, debuggingLegitimate interests; legal obligation

We do not buy personal data from data brokers, and we do not sell or rent yours.

Marketing

If you're an existing customer or you've asked us about Faira, we may email you about the product. You can stop that at any time using the link in any email, or by writing to privacy@getfaira.com. We'll still send you service messages: billing, security, outages, because you need those.

How long we keep it

WhatHow long
Account recordsFor the life of your account, then 12 months
Trial accounts that don't convert30 days after the trial ends, then deleted
Accounts refunded under the money-back guarantee30 days after the refund, then deleted. Sooner if you ask
Billing and tax records6 years, as UK tax law requires
Support conversations24 months
Enquiries that don't become customers12 months
Marketing preferencesUntil you change them, plus a suppression record kept indefinitely so we don't contact you again
Security logs12 months

Part B: When we're the processor

When Faira answers a call, replies to a message, takes a booking or sends an email on behalf of a business, that business is the controllerof the information involved. We are its processor. We act on its documented instructions and nothing else.

This applies across every channel: calls, VoIP, the website widget, WhatsApp, Instagram and email.

If you contacted a business and Faira answered, the business you contacted decides how your information is used and how long it is kept. Contact them first. If you'd rather come to us, write to privacy@getfaira.com and we'll pass your request on and help them respond.

What gets processed

  • Who they are: phone number, WhatsApp number, Instagram handle and display name, email address, and their name if they give it
  • What they said or wrote: call audio and transcripts, website widget messages, WhatsApp and Instagram messages, and email content including anything attached
  • Booking details: service, date, time, staff member, notes
  • Whether they're a returning contact, and what happened last time, including on a different channel
  • Outcomes: booked, not booked, needs follow-up, payment requested
  • Technical data: time, duration, channel, route, call quality, message delivery and read status

Recordings, transcripts and messages

Faira works by listening or reading, then responding. Recording, transcription and message storage are not optional extras, they are how the product functions.

On calls, audio is recorded and transcribed. The business you called is responsible for telling you that, and for having a lawful basis to record. Faira provides call announcements to help them do it.

In the website widget, on WhatsApp, on Instagram and in email, the content of the conversation is stored, because Faira needs the thread to answer sensibly and the business needs the record. Written channels tend to keep more, for longer, and in a form that is easier to read at a glance than an audio file.

Retention is set by the business, within the options we offer. Our default is 90 days for audio and 24 months for transcripts and messages, but a business can shorten or extend that.

If a business lets a trial lapse, or takes a refund under our money-back guarantee, there is no longer anyone instructing us on that data. We give them 30 days to export it, then delete it.

What we receive from Meta

When someone messages a business's WhatsApp or Instagram, Meta passes us their phone number or handle, their display name, their profile picture where the platform provides it, and the content of the message.

That is the extent of it. We do not receive their contacts, their friends, their posts, their browsing, or anything else from their Meta profile, and we do not ask for it.

What we access in a connected mailbox

Where a business connects email, Faira accesses that mailbox within the permission the business grants, and reads messages in order to answer them.

We use mailbox contents only to run the service for that business. We do not use them for advertising, for building profiles, or for training AI models, and we hold that access to the limited-use requirements the mail provider imposes. The business can revoke our access at any time from their mail provider.

Sensitive information

Some Faira customers are clinics, dental practices and medical practices. People contacting those businesses often mention health information without being asked to: a condition, a treatment, a medication. They do it on the phone, and they do it just as readily in a WhatsApp message or an email, where it stays written down.

Health information gets extra protection under data protection law. Wherever it appears, in a call, a chat, a message or an email, it is processed under the same instructions as everything else, and it is subject to the additional safeguards in our data processing agreement: restricted internal access, encryption at rest and in transit, and no use for any purpose beyond delivering the service.

We instruct our customers not to configure Faira to solicit health information it does not need, on any channel. Whether they follow that instruction is their responsibility as controller.

We do not use Faira to infer emotion, health status, or any other characteristic about a person beyond what is needed to handle the conversation. People are told they are dealing with an AI.

AI and model training

We do not train general-purpose AI models on your calls, your recordings or your transcripts. Your content is not used to build a model that other Faira customers benefit from, and it is not sold or licensed to anyone who does that.

Faira Instinctâ„¢ learns within your account. It observes what happened on your calls, whether people booked, what they asked about, where conversations broke down, and uses that to improve how your agent behaves. That learning stays with your agent. It is not pooled across customers.

We use third-party AI providers for speech recognition, speech synthesis and language processing. We contract with them on terms that prohibit using your content to train their models and that require prompt deletion. Our current providers are listed below.

We use aggregated statistics to improve Faira generally: how long calls take, how often transfers happen, which intents fail. These are counts and rates. They contain no personal data and cannot be traced back to a caller or a customer.

Faira makes no automated decision that produces a legal or similarly significant effect on a caller. It books, answers and routes. It does not decide eligibility, price, credit or access to a service on its own. If a Faira customer configures it to do something closer to that line, they are responsible for meeting the additional requirements that apply.

Who we share information with

We share personal data with service providers who help us run Faira. Each one is contractually bound, processes only on our instructions, and is subject to appropriate security requirements.

ProviderWhat they doWhere
AWSCloud hosting, application infrastructure, databases and storageUK / EEA / US, depending on the AWS region configured
VapiVoice AI orchestration, call routing and media handlingUS / other jurisdictions, depending on service configuration
TwilioTelecoms infrastructure, phone numbers and call deliveryUK / EEA / US, depending on the service and routing configuration
OpenAISpeech recognition, text-to-speech and AI language processingUK / EEA / US, depending on the service and processing configuration
Meta PlatformsDelivery of WhatsApp and Instagram messagesIreland / US
Cal.comCalendar integration and appointment schedulingUS / EEA, depending on service configuration
n8nWorkflow automation and orchestrationUK / EEA / US, depending on hosting configuration
Email infrastructure providerSending and receiving email on your connected domainUK / EEA / US, depending on the email provider and configuration
Widget CDNServing the Faira website chat widget and related assetsGlobal / distributed network
StripeSubscription billing and payment links where enabledUK / EEA / US, depending on the service and processing configuration
Support and analytics providersCustomer support, product analytics and understanding product useUK / EEA / US, depending on the provider and configuration

A current list of sub-processors is available on request from privacy@getfaira.com. Customers can ask to be notified of changes.

We also share information:

  • with professional advisers: lawyers, accountants, auditors, where needed
  • with authorities, where the law requires it and after checking that the request is valid
  • with a buyer, if our business is sold, subject to the same protections
  • with anyone else, only if you ask us to

Sending information between countries

Faira operates in the UK, France and Nigeria, and some of our providers operate elsewhere. That means personal data sometimes moves between countries.

Where we move personal data out of the UK or the EEA to a country without an adequacy decision, we use:

  • the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses
  • the EU Standard Contractual Clauses
  • a transfer risk assessment, and additional technical measures such as encryption where the assessment calls for them

For Nigeria, transfers are made on the bases permitted by the Nigeria Data Protection Act 2023.

Customers can ask us for details of the safeguards that apply to their account at privacy@getfaira.com.

Keeping information secure

We use encryption in transit and at rest, role-based access controls, least-privilege internal access, logging and monitoring, and regular review of who can see what.

Access to call recordings, transcripts and message threads is restricted to staff who need it to support the service, and that access is logged.

No system is perfectly secure. If a breach affects your personal data and is likely to result in a high risk to you, we will tell you, and we will notify the relevant regulator within the time the law allows.

Add certifications here once achieved, for example ISO 27001, SOC 2 or Cyber Essentials. Do not claim any certification you do not hold.

Your rights

Depending on where you are, you have rights over your personal data. In the UK and the EU these include the right to:

  • know what we hold and get a copy of it
  • correct it if it's wrong
  • delete it, in some circumstances
  • restrict or object to how we use it, including for marketing
  • take it with you in a portable format
  • withdraw consent at any time, where we relied on consent
  • not be subject to a decision made solely by automated means with legal or similarly significant effect

In Nigeria, the Nigeria Data Protection Act 2023 gives you comparable rights.

To exercise a right, email privacy@getfaira.com. We'll respond within one month, and we'll tell you if we need longer. We may need to verify who you are first. We don't charge, unless a request is clearly excessive.

If Faira answered your call, chat, message or email to a business, that business decides how your data is used. Ask them first, they can act on your request directly. If you contact us instead, we'll pass it on promptly and support them in answering it.

Complaints

Please tell us first at privacy@getfaira.com, we'd rather fix it.

You can also complain to a regulator:

  • UK: Information Commissioner's Office, ico.org.uk, 0303 123 1113
  • France: Commission Nationale de l'Informatique et des Libertes, cnil.fr
  • Nigeria: Nigeria Data Protection Commission, ndpc.gov.ng
  • Elsewhere in the EU: your national supervisory authority

Children

Faira is not intended for children, and we don't knowingly collect data about anyone under 16 through our website or our sales process.

People contacting a Faira customer may sometimes be minors: a parent's phone, a teenager booking an appointment, a message from an Instagram account. WhatsApp and Instagram set their own minimum ages, and we rely on the platform to enforce them. Where a minor does get through, the business is the controller and is responsible for handling it appropriately. Tell us at privacy@getfaira.com if you believe a child's data has been handled incorrectly and we'll help the business put it right.

Changes to this policy

We'll update this page when what we do changes. If a change is significant, we'll tell customers by email or in-app before it takes effect. The date at the top always shows the current version.

Faira Platforms Ltd is registered in England and Wales, company number 17059377, at 2 Guthrum Court, 1 Cavendish Square, London, E16 2XN.