Data Protection Statement

Last Updated: August 6, 2026

This statement explains how SecraAI approaches personal-data responsibilities under UK GDPR and EU GDPR. Compliance depends on how each customer configures and uses the service, the information collected on calls, and the lawful basis selected by the customer.

1. Our Role

Under the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (EU GDPR), SecraAI acts in two capacities:

  • As a Data Controller: For the personal data of our direct customers (e.g., your account details, billing information, email address). We determine the purposes and means of processing this data to provide our services and manage our business relationship.
  • As a Data Processor: For the personal data that our customers process through our platform (e.g., call recordings, transcripts, caller information, and custom knowledge base contents). We process this data only on documented instructions from you, the Data Controller.

2. Lawful Basis for Processing

Where we act as a Data Controller, we process your personal data on the following lawful bases:

  • Contractual Necessity: To fulfill our obligations under our Terms of Service (e.g., providing access to the platform, billing).
  • Legitimate Interests: For our legitimate business interests, such as improving our services, security, fraud prevention, and marketing (where consent is not required by law).
  • Legal Obligation: To comply with applicable legal and regulatory requirements (e.g., tax and accounting laws).
  • Consent: Where we have obtained your specific consent, which you can withdraw at any time.

3. Data Subject Rights

Under the GDPR, individuals have specific rights regarding their personal data. We facilitate these rights both for our customers and to help our customers address requests from their own end-users (callers):

  • Right to Access: You can request a copy of the personal data we hold about you.
  • Right to Rectification: You can correct any inaccurate or incomplete personal data.
  • Right to Erasure ('Right to be Forgotten'): You can request the deletion of your personal data when it is no longer necessary for the purposes for which it was collected, subject to legal retention requirements.
  • Right to Restriction of Processing: You can request that we restrict the processing of your personal data in certain circumstances.
  • Right to Data Portability: You can request your personal data in a structured, commonly used, and machine-readable format.
  • Right to Object: You can object to our processing of your personal data based on legitimate interests or for direct marketing.

To exercise any of these rights, or if you are a customer needing assistance fulfilling a request from your caller regarding call transcripts or recordings, please contact us.

4. International Data Transfers

SecraAI utilizes infrastructure provided by Microsoft Azure, MongoDB Atlas, Stripe, Twilio, and OpenAI. As such, personal data may be transferred to and processed in countries outside the UK and European Economic Area (EEA), primarily the United States.

The safeguards applying to a transfer depend on the destination, provider, and contractual arrangement in force. These may include adequacy regulations or contractual transfer mechanisms. Contact us for information relevant to your intended use and supplier assessment.

5. Processor Terms and Customer Responsibilities

Customers remain responsible for establishing a lawful basis, giving appropriate caller notices, setting suitable retention periods, and applying additional safeguards for sensitive or regulated conversations. Contact us to discuss current processor terms and subprocessor information before deploying the service.

6. Contact Us

If you have questions about this Data Protection Statement or wish to exercise data-subject rights, contact our privacy team at privacy@secraai.co.uk.