Skip to content

Status of this document

This document forms part of the agreement between you and FALCON NEST TECHNOLOGIES LTD ("Falcon Nest", "we", "us"), a company registered in England and Wales under company number 17384940, with its registered office at 37 Croydon Road, Beckenham, BR3 4AB, United Kingdom.

These are our standard processing terms. They form part of the agreement automatically when you use the service to process personal data, so there is nothing to sign for the standard case. If your procurement process needs a countersigned copy, or your own paper with negotiated terms, email billy@falconneststore.com.

Where this document and the Terms and Conditions disagree about the processing of personal data, this document wins.

1. Roles

You are the controller of personal data contained in the content you send us to process. We are your processor for that data.

We are a separate, independent controller for your own account, billing, security and support records. Our handling of those is described in the Privacy Policy, not here.

Both parties comply with the UK GDPR, the Data Protection Act 2018 and, where it applies to your processing, the EU GDPR.

2. Subject matter and duration

Subject matter — providing the Falcon Nest voice AI and FDE assistant services you have subscribed to.

Duration — for as long as your subscription is active, plus the deletion window in section 9.

Nature and purpose — hosting, storage, transcription, indexing, retrieval, generation of responses, transmission, backup, and support and diagnostics at your request. We process only on your documented instructions, which are given by your configuration of the service and your use of it.

Types of personal data — whatever your content happens to contain. Typically: names, contact details, voice recordings and voiceprint-derived audio features, call transcripts, correspondence, identifiers inside documents, and personal data appearing incidentally in source code, commit history or tickets.

Categories of data subject — your customers, callers, end users, employees and contractors.

Special category data and children's data are not expected. If your use case involves either, tell us before you begin so we can confirm the controls are adequate and record the additional measures.

3. Our obligations

We will:

  • Process personal data only on your instructions, and tell you if we believe an instruction breaches data protection law
  • Not process it for our own purposes, and never use it to train shared models
  • Ensure everyone with access is bound by confidentiality that survives the end of their engagement
  • Limit access to staff who need it for a specific task, and log privileged access
  • Implement and maintain the measures in section 4
  • Assist you with data subject requests, impact assessments and regulator enquiries
  • Notify you of a personal data breach without undue delay
  • Delete or return the data at the end of the engagement

If we are compelled by law to disclose personal data, we will tell you first unless the law forbids it, and we will disclose the minimum required.

4. Security measures

The controls in place are described on our Security page, which forms part of these terms. In summary:

  • TLS 1.2 or higher in transit, AES-256 at rest, and separately held backup encryption keys
  • Role-based access control enforced server-side, with mandatory two-factor authentication for all staff accounts
  • Per-tenant partitioning of customer content, with per-engagement retrieval boundaries on FDE Team
  • Append-only audit logging of privileged actions with actor, timestamp and before and after state
  • Encrypted daily backups with a tested restore procedure
  • Card data never touching our systems; checkout is a hosted page operated by a regulated payment institution

We may change a specific measure, but not in a way that materially reduces the overall level of protection.

5. Sub-processors

You give general authorisation for us to use sub-processors. Each one is placed under written terms no less protective than these, and we remain responsible to you for what they do.

The current list is published on our Sub-processors page. We give at least 30 days' notice before adding a sub-processor that will process customer content. If you have a reasonable, substantiated objection within that notice period, tell us: we will look for an alternative, and if there is not one you may terminate the affected part of the service and receive a pro-rata refund of the unused prepaid term.

6. International transfers

Your content is stored in the region you select at setup — the UK, EU or US.

Where a transfer outside that region is necessary, it is made under the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, with a transfer risk assessment on file that we will share with you on request.

Enterprise customers can remove transfers from the picture entirely by self-hosting, in which case we process nothing and this document falls away except for support data you choose to send us.

7. Assisting you

Data subject requests — if a data subject contacts us directly about your data, we will not respond substantively; we will refer them to you and tell you promptly. Where a request requires access to your content, we help you find, export, correct or delete it. Self-service tools cover most cases at no charge.

Impact assessments and prior consultation — we provide the information you reasonably need, including our security documentation and sub-processor details.

Audit — you may audit our compliance once in any twelve month period, and after a breach affecting your data. In the first instance we satisfy this with our security documentation, questionnaire responses and penetration test summary. Where that is genuinely insufficient, we will accommodate a proportionate audit on reasonable notice, during business hours, without disrupting other customers, and under NDA.

8. Breach notification

We notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting your content.

The notification will include what we know at the time: the nature of the breach, the categories and approximate volume of data and data subjects affected, the likely consequences, the measures taken or proposed, and a contact point. Where we cannot provide all of it at once, we send what we have and follow up rather than waiting until the picture is complete.

We do not notify your regulator or your data subjects on your behalf, because that is the controller's decision, but we give you what you need to make it inside your own statutory deadline.

9. Deletion and return

You can export your content at any time during the subscription, in open formats, at no charge.

On termination or expiry, your content remains available for 30 days so an accidental lapse is recoverable. After that it is deleted from live systems within 7 days, and from encrypted backups as those backups age out, within 35 days of deletion from live systems.

You can ask for immediate deletion instead, and we will confirm in writing when it is done. Where law requires us to retain something — invoices and tax records, for example — we retain only that, only for as long as required, and it stays subject to these terms.

10. Liability and governing law

Each party's liability under this document is subject to the limitations in the Terms and Conditions. Nothing here limits liability that cannot lawfully be limited, including a data subject's rights or a regulator's powers.

This document is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.

Questions: billy@falconneststore.com.