GDPR Policy

Last updated: 2026-07-31

This GDPR Policy explains how iFarrier Ltd ("we", "us", or "our") processes personal data in compliance with the General Data Protection Regulation (GDPR) and related legislation. It supplements our Privacy Policy.

Data Controller

iFarrier Ltd
Email: privacy@ifarrier.com

Applicable Regulations

  • GDPR (EU Regulation 2016/679) — General Data Protection Regulation
  • UK GDPR (UK Data Protection Act 2018)
  • CCPA (California Consumer Privacy Act) — where applicable

Legal Basis for Processing

We process your personal data under the following legal bases as defined by Article 6 of the GDPR:

  • Legitimate Interest (Article 6(1)(f)): Providing efficient, AI-powered customer support to improve customer service and business operations. We collect only the minimum data necessary and apply strong security controls.
  • Contract Performance (Article 6(1)(b)): For existing customers, processing is necessary to perform the contract for service provision.
  • Consent (Article 6(1)(a)): Obtained through our chatbot interface for non-customers and for optional communications.

Your Rights

Under GDPR, you have the following rights regarding your personal data. To exercise any of these rights, please contact us at privacy@ifarrier.com. We will respond within 30 days.

  • Right to Access (Article 15): You may request a copy of the personal data we hold about you.
  • Right to Erasure (Article 17): You may request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations.
  • Right to Rectification (Article 16): You may request correction of inaccurate personal data we hold about you.
  • Right to Data Portability (Article 20): You may request a machine-readable export of your personal data.
  • Right to Object (Article 21): You may object to processing based on legitimate interest. We will cease processing unless overriding legitimate grounds exist.
  • Right to Restrict Processing (Article 18): You may request that we limit processing of your data while a dispute is resolved.

Data Retention

We retain personal data only as long as necessary:

  • AI conversation records: 7 years (legal/tax compliance)
  • Escalation records: 10 years (audit trail)
  • Email ingestion audit logs: 7 years (SOX/GDPR compliance)
  • API usage records: 1 year (financial tracking)
  • Anonymous consent events (cookie consent choices captured before you register or log in): 90 days, after which unreconciled records are automatically deleted. If you register or log in within that window, your choice is carried over to your account and kept for as long as your account exists, as with all other account data.
  • After the applicable retention period, data is anonymised or securely deleted via automated cleanup processes.

Third-Party Processors

We share personal data with the following sub-processors, each subject to a Data Processing Agreement (DPA) and Standard Contractual Clauses (SCCs) for international transfers:

  • OpenAI — AI text processing. Email content is sent via API for generating responses. OpenAI does not use API data for model training. Data retained by OpenAI for 30 days. Location: USA.
  • Mailgun — Email delivery and inbound webhook processing. Logs retained for 30 days. Location: USA.
  • DigitalOcean — Infrastructure hosting (Kubernetes cluster). All data encrypted at rest. Location: EU/USA.
  • Google — Analytics, Ads and Calendar integration. With your consent, Google Analytics (GA4) receives pageview and usage data, and Google Ads receives click-tracking data (gclid) for conversion attribution. If you connect Google Calendar, appointment data syncs directly with your Google account. Location: USA/EU.
  • Meta — Advertising conversion tracking. With your consent, a cryptographically hashed email address is shared with Meta (Facebook/Instagram) to match conversions to ad campaigns. Meta never receives your email address in plain text. Location: USA/EU.

Data Breach Procedures

In the event of a personal data breach, we will:

  • Notify the relevant supervisory authority within 72 hours where the breach is likely to result in a risk to the rights and freedoms of data subjects (GDPR Article 33).
  • Notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms (GDPR Article 34).
  • Maintain an internal breach register documenting all incidents, remediation measures, and lessons learned.

To report a suspected data breach, please contact: security@ifarrier.com

Supervisory Authority

If you are located in the UK, our lead supervisory authority is the Information Commissioner's Office (ICO). You have the right to lodge a complaint with the ICO if you believe we have not handled your data lawfully:

If you are located in the EU, please contact the supervisory authority in your member state.

Contact Us

For any questions about this GDPR Policy or to exercise your data subject rights, please contact us at privacy@ifarrier.com. We aim to respond within 5 business days and will fulfil all valid requests within 30 days.