Fourel — Privacy Policy
Effective date: 1 July 2026 Last updated: 1 August 2026
1. Who is responsible for your data
Fourel is operated by A Company That Sells Everything LLC, a free zone company established in Sharjah Media City (Shams), formation number 2322712, registered at Shams Business Center Open Space, Sharjah, United Arab Emirates ("Fourel", "we", "us", "our").
Privacy contact: privacy@fourel.dev General enquiries: contact@fourel.dev
EU/UK representative (Article 27 GDPR): Dmytro Los Carrer del Pla de la Saïdia 3, 2, 46009 Valencia, Spain gdpr@fourel.dev
Two roles. We act as a controller for data about our Clients — account, billing, and support data. We act as a processor on the Client's instructions for the WhatsApp message content that Fourel reads, where the Client is the controller. Section 3 applies to both.
2. Summary — what you should know before reading further
- Fourel reads the entire contents of every WhatsApp chat a Client has designated for Fourel to listen to.
- Fourel also reads new incoming conversations where the first message is automatically classified as showing buyer behaviour, and those conversations then become listened chats.
- Fourel support staff can access the contents of a Client's listened chats when the Client asks for support.
- WhatsApp's end-to-end encryption does not prevent this. Fourel is an application the Client has authorised to operate their account, and message content is decrypted and processed on our systems and by our AI providers.
- Message content is sent for AI processing to providers located in the United States.
- We do not use message content to train general-purpose AI models.
3. What Fourel reads and processes
3.1 Listened chats
Where a Client designates a chat for Fourel to listen to, we read and process all messages in that chat, inbound and outbound, for as long as the designation is in place. This includes:
- message text, in full;
- attachments and media, including images, documents, audio, and video, and any text extracted from them;
- captions, contact cards, and shared locations;
- sender and recipient phone numbers and WhatsApp display names and profile photographs;
- timestamps, delivery and read status, and thread structure;
- reactions, replies, forwards, and edits.
We read the whole chat, not selected excerpts, and this includes messages sent by the Client's counterparties as well as by the Client.
3.2 Automatic capture of new conversations
We additionally read and process new incoming conversations that a Client has not individually designated, where the first inbound message is semantically classified by our systems as demonstrating buyer behaviour — for example an enquiry about availability, pricing, a viewing, a booking, or a purchase. Where a conversation is classified this way, it becomes a listened chat and everything in Section 3.1 applies to it from that point.
This classification is automated. It can be wrong. A conversation that is not commercial may be classified as commercial and captured.
3.3 Access by our support team
Where a Client requests support assistance, our support personnel may access the contents of that Client's listened chats, including message content, to diagnose and resolve the reported issue. This access is:
- limited to personnel who require it for the specific request;
- limited in scope and duration to that request;
- logged, with the identity of the accessing person, the time, and the chats accessed;
- subject to written confidentiality obligations;
- terminated when the Client withdraws the request or the request is closed.
We do not access listened chats for support purposes absent a request, except where necessary to investigate a security incident, to prevent imminent harm, or where legally compelled.
3.4 Other data we collect
Account data: name, business name, email, phone number, connected WhatsApp numbers, role, authentication data. Billing data: billing name and address, tax identifiers, subscription and transaction records. Card details are handled by our payment provider; we do not store full card numbers. Usage and technical data: IP address, device and browser identifiers, log data, feature usage, error reports, timestamps. Support data: the contents of your correspondence with us. Configuration data: the rules, prompts, playbooks, and designations a Client sets.
4. Why we process it, and on what legal basis
| Purpose | Data | GDPR legal basis |
|---|---|---|
| Providing the AI assistant | Message content (3.1, 3.2), configuration | Processor acting on the Client's documented instructions (Art. 28); Client's own basis under Art. 6(1)(b) or 6(1)(f) |
| Account creation and administration | Account data | Contract (Art. 6(1)(b)) |
| Billing and tax | Billing data | Contract; legal obligation (Art. 6(1)(c)) |
| Support, on request | Message content (3.3), support data | Contract; legitimate interests (Art. 6(1)(f)) |
| Security, abuse prevention, incident investigation | Usage, technical, message metadata | Legitimate interests (Art. 6(1)(f)) |
| Service improvement | Aggregated or de-identified data only | Legitimate interests (Art. 6(1)(f)) |
| Legal compliance and defence of claims | As necessary | Legal obligation; legitimate interests |
| Marketing to Clients | Account data | Consent, or legitimate interests where permitted |
Clients' counterparties. The people a Client exchanges messages with have no direct relationship with us. The Client is the controller of their data and is responsible for informing them that their conversations are read and processed by an automated AI assistant and may be accessed by a human support team, and for establishing a legal basis for that processing. We process their data only on the Client's instructions. Requests from these individuals will normally be referred to the relevant Client, though we will assist the Client in responding.
5. Automated decision-making
The buyer-behaviour classification described in Section 3.2 is an automated process that determines whether a conversation is captured and processed. It does not, in itself, produce legal or similarly significant effects on individuals. Where a Client configures Fourel to take actions with such effects — for example automated qualification, pricing, or rejection — the Client is responsible for compliance with Article 22 GDPR and for providing any required human review.
6. Who we share data with
We do not sell personal data and do not share it for cross-context behavioural advertising.
AI processing providers. Message content is transmitted to third-party AI providers to generate outputs: OpenAI, L.L.C., Anthropic, PBC, Groq, Inc., and Eleven Labs, Inc. Each acts as our sub-processor, is contractually prohibited from using the content to train its models, and is subject to retention limits.
Payments. Stripe, Inc. and its affiliates process subscription payments as an independent controller under Stripe's own privacy policy.
Messaging platform. Meta Platforms, Inc. and its affiliates operate the WhatsApp service through which messages travel. Meta's handling of data on its own platform is governed by Meta's terms and privacy policy, not by this policy.
Hosting and infrastructure. Hetzner Online GmbH provides server hosting and storage for the Service. Error monitoring and other operational providers necessary to run the Service are listed, together with all sub-processors named above and their locations, at fourel.dev/subprocessors. We give Clients notice before adding a new sub-processor and an opportunity to object.
Others. Professional advisers, insurers, and auditors under confidentiality; competent authorities where required by valid legal process or to establish or defend legal claims; and an acquirer or successor in a merger, acquisition, or sale of assets, subject to this policy.
7. International transfers
We are established in the United Arab Emirates. The UAE is not the subject of an adequacy decision under Article 45 GDPR. Our personnel access our systems from the United Arab Emirates, which constitutes a transfer. The hosting providers and other sub-processors that store and process data on our behalf are listed at fourel.dev/subprocessors, together with their locations.
Where message content is processed. Our AI providers are all incorporated in the United States and, on our current configuration, process message content on infrastructure located in the United States:
- OpenAI, L.L.C. — United States by default. European data residency exists but is configured per project at creation and requires approval; we have not enabled it.
- Anthropic, PBC — primarily United States infrastructure.
- Groq, Inc. — customer data is held in Google Cloud Platform storage located in the United States. Groq also operates European inference capacity in Helsinki, Finland; we do not use it.
- Eleven Labs, Inc. — United States. Where data residency is selected, processing may nevertheless occur outside the selected location, including by ElevenLabs' affiliates, sub-processors, support staff, and content-moderation team.
Transfer mechanism. Where we receive personal data from the EEA, the UK, or Switzerland, transfers to us and onward to the recipients above are made under the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with supplementary technical and organisational measures including encryption in transit and at rest, access controls, and contractual restrictions on retention and training. A copy of the relevant transfer mechanism, and of our transfer impact assessment, is available on request at privacy@fourel.dev.
8. How long we keep it
| Data | Retention |
|---|---|
| Message content — active storage | 90 days rolling |
| Message content — archive | Retained in archive and retrievable by the Client for the duration of the subscription; deleted on account deletion per below |
| Derived summaries, classifications, and CRM records | 12 months following account deletion, unless a full erasure request is made |
| Support access logs | 24 months |
| Security and audit logs | 12 months |
| Account and configuration data | Term of subscription, then 12 months |
| Billing and tax records | 5 years from the end of the relevant tax period, as required by UAE tax law |
On account deletion. All communication data — active and archived message content — is deleted from our live systems within 8 hours of the unsubscribe or account-deletion request. Derived CRM records are retained for 12 months so that the Client can resume service, unless the Client submits an explicit request to erase everything, in which case they are deleted within 30 days. Encrypted backups are purged on their ordinary rotation cycle within 30 days; during that window backup copies are inaccessible for ordinary use and are not restored except for disaster recovery.
Records required for legal compliance or for the establishment or defence of legal claims are retained for the periods stated above regardless of a deletion request.
9. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit and at rest, role-based access control, least-privilege access for support personnel, logging of all support access to message content, network segregation, vulnerability management, and staff confidentiality undertakings and training.
No system is perfectly secure. Where a personal data breach occurs, we will notify affected Clients without undue delay and, where we act as processor, will assist Clients in meeting their own notification obligations.
10. Your rights
Depending on where you are, you may have the right to access, rectify, erase, restrict, port, or object to processing of your personal data, to withdraw consent, and to lodge a complaint with a supervisory authority — in the EEA, the authority in your country of residence; in the UK, the Information Commissioner's Office; in the UAE, the UAE Data Office.
If you are a Fourel Client, contact us at privacy@fourel.dev. We respond within one month, extendable by two further months where the request is complex.
If you exchanged messages with a Fourel Client and want to exercise rights over that conversation, contact that Client directly — they control that data. If you contact us at privacy@fourel.dev, we will forward your request to them and support their response. We may not be able to identify which Client holds your data without further information from you.
11. Children
Fourel is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 18 in the course of Client account registration. Where a Client's counterparty is a minor, the Client is responsible for the lawfulness of that processing. If you believe a child's data has been processed inappropriately, contact privacy@fourel.dev.
12. Changes to this policy
We may update this policy. We will give not less than 30 days' notice of material changes — particularly any change to what Fourel reads, who can access it, or where it is sent — by email and in-product. The "last updated" date at the top reflects the most recent revision. Prior versions are archived at fourel.dev/privacy-archive.
13. Contact
A Company That Sells Everything LLC Shams Business Center Open Space, Sharjah Media City, Sharjah, United Arab Emirates Formation number 2322712
General: contact@fourel.dev Privacy and data protection: privacy@fourel.dev
EU/UK representative under Article 27 GDPR Dmytro Los Carrer del Pla de la Saïdia 3, 2, 46009 Valencia, Spain gdpr@fourel.dev
