Fourel — Privacy Policy

Effective date: 1 July 2026 Last updated: 1 August 2026


1. Who is responsible for your data

Fourel is operated by A Company That Sells Everything LLC, a free zone company established in Sharjah Media City (Shams), formation number 2322712, registered at Shams Business Center Open Space, Sharjah, United Arab Emirates ("Fourel", "we", "us", "our").

Privacy contact: privacy@fourel.dev General enquiries: contact@fourel.dev

EU/UK representative (Article 27 GDPR): Dmytro Los Carrer del Pla de la Saïdia 3, 2, 46009 Valencia, Spain gdpr@fourel.dev

Two roles. We act as a controller for data about our Clients — account, billing, and support data. We act as a processor on the Client's instructions for the WhatsApp message content that Fourel reads, where the Client is the controller. Section 3 applies to both.


2. Summary — what you should know before reading further


3. What Fourel reads and processes

3.1 Listened chats

Where a Client designates a chat for Fourel to listen to, we read and process all messages in that chat, inbound and outbound, for as long as the designation is in place. This includes:

We read the whole chat, not selected excerpts, and this includes messages sent by the Client's counterparties as well as by the Client.

3.2 Automatic capture of new conversations

We additionally read and process new incoming conversations that a Client has not individually designated, where the first inbound message is semantically classified by our systems as demonstrating buyer behaviour — for example an enquiry about availability, pricing, a viewing, a booking, or a purchase. Where a conversation is classified this way, it becomes a listened chat and everything in Section 3.1 applies to it from that point.

This classification is automated. It can be wrong. A conversation that is not commercial may be classified as commercial and captured.

3.3 Access by our support team

Where a Client requests support assistance, our support personnel may access the contents of that Client's listened chats, including message content, to diagnose and resolve the reported issue. This access is:

We do not access listened chats for support purposes absent a request, except where necessary to investigate a security incident, to prevent imminent harm, or where legally compelled.

3.4 Other data we collect

Account data: name, business name, email, phone number, connected WhatsApp numbers, role, authentication data. Billing data: billing name and address, tax identifiers, subscription and transaction records. Card details are handled by our payment provider; we do not store full card numbers. Usage and technical data: IP address, device and browser identifiers, log data, feature usage, error reports, timestamps. Support data: the contents of your correspondence with us. Configuration data: the rules, prompts, playbooks, and designations a Client sets.


4. Why we process it, and on what legal basis

PurposeDataGDPR legal basis
Providing the AI assistantMessage content (3.1, 3.2), configurationProcessor acting on the Client's documented instructions (Art. 28); Client's own basis under Art. 6(1)(b) or 6(1)(f)
Account creation and administrationAccount dataContract (Art. 6(1)(b))
Billing and taxBilling dataContract; legal obligation (Art. 6(1)(c))
Support, on requestMessage content (3.3), support dataContract; legitimate interests (Art. 6(1)(f))
Security, abuse prevention, incident investigationUsage, technical, message metadataLegitimate interests (Art. 6(1)(f))
Service improvementAggregated or de-identified data onlyLegitimate interests (Art. 6(1)(f))
Legal compliance and defence of claimsAs necessaryLegal obligation; legitimate interests
Marketing to ClientsAccount dataConsent, or legitimate interests where permitted

Clients' counterparties. The people a Client exchanges messages with have no direct relationship with us. The Client is the controller of their data and is responsible for informing them that their conversations are read and processed by an automated AI assistant and may be accessed by a human support team, and for establishing a legal basis for that processing. We process their data only on the Client's instructions. Requests from these individuals will normally be referred to the relevant Client, though we will assist the Client in responding.


5. Automated decision-making

The buyer-behaviour classification described in Section 3.2 is an automated process that determines whether a conversation is captured and processed. It does not, in itself, produce legal or similarly significant effects on individuals. Where a Client configures Fourel to take actions with such effects — for example automated qualification, pricing, or rejection — the Client is responsible for compliance with Article 22 GDPR and for providing any required human review.


6. Who we share data with

We do not sell personal data and do not share it for cross-context behavioural advertising.

AI processing providers. Message content is transmitted to third-party AI providers to generate outputs: OpenAI, L.L.C., Anthropic, PBC, Groq, Inc., and Eleven Labs, Inc. Each acts as our sub-processor, is contractually prohibited from using the content to train its models, and is subject to retention limits.

Payments. Stripe, Inc. and its affiliates process subscription payments as an independent controller under Stripe's own privacy policy.

Messaging platform. Meta Platforms, Inc. and its affiliates operate the WhatsApp service through which messages travel. Meta's handling of data on its own platform is governed by Meta's terms and privacy policy, not by this policy.

Hosting and infrastructure. Hetzner Online GmbH provides server hosting and storage for the Service. Error monitoring and other operational providers necessary to run the Service are listed, together with all sub-processors named above and their locations, at fourel.dev/subprocessors. We give Clients notice before adding a new sub-processor and an opportunity to object.

Others. Professional advisers, insurers, and auditors under confidentiality; competent authorities where required by valid legal process or to establish or defend legal claims; and an acquirer or successor in a merger, acquisition, or sale of assets, subject to this policy.


7. International transfers

We are established in the United Arab Emirates. The UAE is not the subject of an adequacy decision under Article 45 GDPR. Our personnel access our systems from the United Arab Emirates, which constitutes a transfer. The hosting providers and other sub-processors that store and process data on our behalf are listed at fourel.dev/subprocessors, together with their locations.

Where message content is processed. Our AI providers are all incorporated in the United States and, on our current configuration, process message content on infrastructure located in the United States:

Transfer mechanism. Where we receive personal data from the EEA, the UK, or Switzerland, transfers to us and onward to the recipients above are made under the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with supplementary technical and organisational measures including encryption in transit and at rest, access controls, and contractual restrictions on retention and training. A copy of the relevant transfer mechanism, and of our transfer impact assessment, is available on request at privacy@fourel.dev.


8. How long we keep it

DataRetention
Message content — active storage90 days rolling
Message content — archiveRetained in archive and retrievable by the Client for the duration of the subscription; deleted on account deletion per below
Derived summaries, classifications, and CRM records12 months following account deletion, unless a full erasure request is made
Support access logs24 months
Security and audit logs12 months
Account and configuration dataTerm of subscription, then 12 months
Billing and tax records5 years from the end of the relevant tax period, as required by UAE tax law

On account deletion. All communication data — active and archived message content — is deleted from our live systems within 8 hours of the unsubscribe or account-deletion request. Derived CRM records are retained for 12 months so that the Client can resume service, unless the Client submits an explicit request to erase everything, in which case they are deleted within 30 days. Encrypted backups are purged on their ordinary rotation cycle within 30 days; during that window backup copies are inaccessible for ordinary use and are not restored except for disaster recovery.

Records required for legal compliance or for the establishment or defence of legal claims are retained for the periods stated above regardless of a deletion request.


9. Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit and at rest, role-based access control, least-privilege access for support personnel, logging of all support access to message content, network segregation, vulnerability management, and staff confidentiality undertakings and training.

No system is perfectly secure. Where a personal data breach occurs, we will notify affected Clients without undue delay and, where we act as processor, will assist Clients in meeting their own notification obligations.


10. Your rights

Depending on where you are, you may have the right to access, rectify, erase, restrict, port, or object to processing of your personal data, to withdraw consent, and to lodge a complaint with a supervisory authority — in the EEA, the authority in your country of residence; in the UK, the Information Commissioner's Office; in the UAE, the UAE Data Office.

If you are a Fourel Client, contact us at privacy@fourel.dev. We respond within one month, extendable by two further months where the request is complex.

If you exchanged messages with a Fourel Client and want to exercise rights over that conversation, contact that Client directly — they control that data. If you contact us at privacy@fourel.dev, we will forward your request to them and support their response. We may not be able to identify which Client holds your data without further information from you.


11. Children

Fourel is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 18 in the course of Client account registration. Where a Client's counterparty is a minor, the Client is responsible for the lawfulness of that processing. If you believe a child's data has been processed inappropriately, contact privacy@fourel.dev.


12. Changes to this policy

We may update this policy. We will give not less than 30 days' notice of material changes — particularly any change to what Fourel reads, who can access it, or where it is sent — by email and in-product. The "last updated" date at the top reflects the most recent revision. Prior versions are archived at fourel.dev/privacy-archive.


13. Contact

A Company That Sells Everything LLC Shams Business Center Open Space, Sharjah Media City, Sharjah, United Arab Emirates Formation number 2322712

General: contact@fourel.dev Privacy and data protection: privacy@fourel.dev

EU/UK representative under Article 27 GDPR Dmytro Los Carrer del Pla de la Saïdia 3, 2, 46009 Valencia, Spain gdpr@fourel.dev