This page contains the legal documents that govern the Ferrison platform and a summary of how we protect the data we handle on your behalf. The summary comes first; the full documents are further down the page.
These summaries are provided for convenience. If anything here differs from the full policies below, the full policies apply.
We do not sell call records, message content, customer details or transcripts, and we do not use them to train AI models. You can export your data as CSV at any time.
We honour the data subject rights set out in UK and EU GDPR, and the privacy rights of California and other US states. Breaches are notified within 72 hours where the law requires it, and a Data Processing Agreement is available on request.
Calls, texts and transcripts are encrypted in transit and at rest. Each access to customer data is logged with the person, time and reason, and you can review the log from your dashboard.
Each conversation handled by your AI agent produces a transcript and summary in your dashboard, and each billable action is recorded in your activity log.
Select the document you need. If you have a question the documents do not answer, email info@ferrison.com.
These Website Terms and Conditions ("Website T&Cs") govern your use of the ferrison.com website and any Ferrison-branded web pages (collectively, the "Website"). The Website is operated by Ferrison Ltd (trading as "Ferrison"), a company registered in England and Wales (company number: 17227541) ("Ferrison", "we", "us", or "our").
By accessing or using the Website, you confirm that you have read, understood, and agree to be bound by these Website T&Cs. If you do not agree, please do not use the Website.
These Website T&Cs apply to all visitors and users of the Website, wherever located, including visitors in the United Kingdom, the European Economic Area, and the United States. They are separate from the Ferrison Terms of Service, which govern access to and use of the Ferrison software platform by registered subscribers.
Without limiting the above, you must not use the Website to:
If you have any questions about these Website T&Cs or our Website, please contact:
Email: info@ferrison.com
Company: Ferrison Ltd
This Privacy Policy explains how Ferrison Ltd (trading as "Ferrison"), a company registered in England and Wales (company number: 17227541) ("Ferrison", "we", "us", or "our") collects, uses, shares, and protects personal data in connection with the Ferrison platform and website.
We are committed to protecting your privacy and processing your personal data in accordance with the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018, the EU General Data Protection Regulation ("EU GDPR") where applicable, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA") and other US state privacy laws where applicable, and other applicable data protection laws.
Ferrison is a B2B SaaS platform that enables small businesses to deploy a single AI-powered assistant across their telephone lines and messaging channels (including SMS text messaging), with built-in appointment booking. When you interact with Ferrison, whether as a business customer, a website visitor, or a caller or texter who has reached a business using our platform, this Policy explains how we handle your personal data.
This Policy applies to:
If you are an End User, please note that the business whose AI Agent handled your call or message (the Customer) is the data controller for your personal data in relation to that interaction, and you should also refer to that business's own privacy notice. Ferrison processes End User data as a data processor (a "service provider" under US law) on the Customer's behalf.
Where we refer to Data Protection Law in this Policy, this means the UK GDPR, the Data Protection Act 2018, the EU GDPR (where applicable), the CCPA/CPRA and other US state privacy laws (where applicable), and any other applicable privacy or data protection laws, in each case as amended or updated from time to time, and any successor legislation.
Your privacy is important to us. We will process your data in accordance with Data Protection Law. This means the personal information we hold about you must be:
For personal data relating to Platform Users and Website Visitors, Ferrison acts as an independent data controller (a "business" under the CCPA/CPRA).
For personal data relating to Callers and texters (End Users) processed via the AI Agent infrastructure, Ferrison acts as a data processor (a "service provider" under US law) on behalf of the Customer (who is the data controller / "business"). The Customer determines why and how End User data is processed; Ferrison merely processes it on their documented instructions and does not sell or share it, retain it, or use it for any purpose other than providing the Service.
If you have queries about how a specific Customer processes your data as an End User, please contact that Customer directly.
When you register for or use the Ferrison platform, we collect:
When an individual calls or sends a text message to a telephone number managed through the Ferrison platform, messages a Customer on Facebook Messenger or Instagram, or chats, books, orders or enquires on a Ferrison-hosted booking page or a Customer's website chat widget, we (on behalf of the relevant Customer) may process:
We use Platform User personal data for the following purposes:
Ferrison processes End User data as a data processor / service provider on the instructions of Customers. The Customer determines the lawful basis for processing End User data. Ferrison uses End User data solely to:
Ferrison does not sell or share End User data, does not use it for its own marketing, and does not use it to train AI models for any party.
If you choose to connect a Google account to sync your bookings with Google Calendar, Ferrison asks Google for permission to see the list of calendars in that account and to view and edit events on them. We use that access only to provide the calendar sync you have switched on:
We do not use Google user data for advertising, we do not sell it, we do not use it to train or improve AI models, and we do not allow people to read it except where you ask us to for support, where it is needed for security, or where the law requires it. Ferrison's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We use Website Visitor data to operate and improve our website, analyse traffic, and ensure security (lawful basis: legitimate interests).
This section provides the "notice at collection" required under the CCPA/CPRA. It describes the categories of personal information Ferrison collects from Platform Users and Website Visitors as a business, the purposes for which it is used, and the retention applied. We do not sell or share (for cross-context behavioural advertising) any of these categories, and we do not collect this information for those purposes.
| CCPA category | Examples we collect | Purpose | Retained |
|---|---|---|---|
| Identifiers | Name, email, phone number, account ID, IP address | Account creation, login, support, security | Account life + 7 years |
| Customer records / commercial information | Business details, credit balance, transaction history | Billing, fraud prevention, accounting | Account life + 7 years |
| Internet / network activity | Usage logs, feature interactions, session data, activity log | Service delivery, analytics, security | Up to 26 months |
| Audio / electronic information | Live call audio (transient), call transcripts, message content (processed as a service provider for Customers) | Providing the AI assistant service to the Customer | Per Customer's instructions; audio not stored |
| Professional / employment information | Job title, employer (the Customer) | Account administration | Account life + 7 years |
We do not knowingly collect "sensitive personal information" as defined by the CCPA/CPRA for the purpose of inferring characteristics about an individual. We do not use or disclose sensitive personal information for any purpose other than those permitted under the CCPA/CPRA.
We engage third-party sub-processors to help us deliver the Service. These include providers of telephony and messaging (SMS) infrastructure, social messaging (Facebook Messenger and Instagram), AI model processing, user authentication, calendar sync (where you connect it), payment processing, transactional email, cloud hosting and infrastructure, website platform services, and customer communication tools. Each sub-processor is bound by a data processing agreement requiring them to protect your data to a standard consistent with applicable law.
A current list of our sub-processors, including their location and the safeguard used for any international data transfer, is available at ferrison.com/sub-processors. We will update that list and notify you of any material changes before a new sub-processor starts processing your data.
If Ferrison is involved in a merger, acquisition, financing, or sale of assets, your personal data may be transferred to a successor entity as part of that transaction, subject to equivalent privacy protections.
We may disclose personal data where required to do so by law, court order, or at the request of a competent regulatory authority, or where necessary to protect the rights, property, or safety of Ferrison, its customers, or others.
We do not sell personal data, and we do not share personal data for cross-context behavioural advertising, within the meaning of the CCPA/CPRA or any other US state privacy law. We have not done so in the preceding twelve (12) months. We do not permit third-party advertising networks to access personal data processed through the Ferrison platform.
The sub-processors listed above are based in the United States. When we transfer personal data from the United Kingdom or European Economic Area to these processors, we ensure that appropriate safeguards are in place, including:
Ferrison hosts and processes data using infrastructure located in the United States. We do not represent that personal data is stored within the United Kingdom, the European Economic Area, or any particular jurisdiction. You may request a copy of the transfer safeguards we have in place by contacting us at info@ferrison.com.
We retain personal data for as long as necessary to fulfil the purposes set out in this Policy, and in any event for the following minimum periods:
When personal data is no longer needed, we will securely delete or anonymise it.
If you are located in the United Kingdom or European Economic Area, you have the following rights under UK GDPR / EU GDPR:
To exercise any of these rights, please contact us at info@ferrison.com. We will respond within one month of receipt of your request. We may ask you to verify your identity before processing your request.
UK residents have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
EU residents have the right to lodge a complaint with the supervisory authority in their EU member state of residence.
If you are a California resident, you have the following rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act:
How to submit a request. You may submit a request by emailing info@ferrison.com with the subject line "CALIFORNIA PRIVACY REQUEST", or by using the contact details in the Contact Us section. We will acknowledge your request within ten (10) business days and respond within forty-five (45) days (extendable by a further 45 days where reasonably necessary, with notice). We will verify your identity before fulfilling a request to know, delete, or correct.
Authorised agents. You may use an authorised agent to submit a request on your behalf. We may require the agent to provide proof of authorisation and may require you to verify your own identity directly with us.
"Shine the Light". California Civil Code § 1798.83 permits California residents to request information about disclosure of personal information to third parties for their direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.
If you are a resident of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another US state with a comprehensive privacy law in force, you may have rights to access, correct, delete, and obtain a portable copy of your personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. We do not sell personal data, engage in targeted advertising, or carry out profiling that produces legal or similarly significant effects. To exercise your rights, contact us at info@ferrison.com. If we decline a request, you may appeal by replying to our decision; if your appeal is denied, you may contact your state Attorney General.
If you are located in a jurisdiction with specific data protection rights not covered above (including Canada, Australia, Brazil, or other jurisdictions with applicable privacy laws), you may contact us at info@ferrison.com to exercise any rights afforded to you under applicable local law.
We implement appropriate technical and organisational security measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
No method of transmission over the internet is 100% secure. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and affected individuals in accordance with applicable law.
Our website and platform may use cookies and similar tracking technologies to enhance your experience, analyse usage, and for security purposes.
You can manage your cookie preferences through your browser settings or any cookie consent tool we provide. Please note that disabling certain cookies may affect the functionality of the platform.
The Ferrison platform is a business-to-business service intended solely for use by adults acting on behalf of commercial entities. We do not knowingly collect personal data from individuals under the age of 18 (or under 13 in the United States, in accordance with the Children's Online Privacy Protection Act). If you believe we may have collected data from a minor, please contact us at info@ferrison.com.
Our website or platform may contain links to third-party websites or services. This Privacy Policy does not apply to those third parties' websites or services. We encourage you to review the privacy policies of any third-party sites you visit.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify Platform Users of material changes by email or in-app notification at least 14 days before the changes take effect. The "Last updated" date at the top of this Policy indicates when it was most recently revised.
If you have any questions, concerns, or requests relating to this Privacy Policy or our processing of your personal data, please contact:
Email: info@ferrison.com
Company: Ferrison Ltd
Company number: 17227541
We will do our best to respond to all legitimate enquiries within 30 days.
These Terms of Service ("Agreement") govern your access to and use of the Ferrison platform and services. Please read them carefully before using the Service. By registering for or using the Service, you confirm that you have read, understood, and agree to be bound by this Agreement on behalf of the business entity you represent.
In this Agreement, the following terms have the meanings set out below:
For questions about the platform, these terms or your personal data, contact us at:
For data protection or privacy requests (access, deletion, correction, or objection, including US state privacy requests), please use the same address and mention "Data request" in the subject line so we can prioritise it. California residents should use the subject line "CALIFORNIA PRIVACY REQUEST".
Ferrison Ltd · Registered in England and Wales · Company No. 17227541