legal

Data protection policy

The internal rules Benerra Innovation Ltd follows when it processes personal data, as a controller and as a processor for its clients. Where the privacy policy tells a visitor what happens to their own data, this page sets out the governance behind it, for clients, auditors and anyone who needs the fuller detail.

Benerra Innovation Ltd · version 1.0 · effective 16 September 2026

1. Policy statement and scope

Benerra Innovation Ltd, incorporated under the laws of the United Arab Emirates, with its registered address at Unit IH-00-01-03-OF-05, Level 3, Innovation One, Dubai International Financial Centre, Dubai, United Arab Emirates (the "Company"), provides AI voice call services (the "Services") to legal entities (the "Clients"). The Services consist of AI agents, operated by the Company, that answer inbound calls from and place outbound calls to natural persons (the "Customers") on behalf of Clients.

This policy sets out the internal rules under which the Company processes and manages personal data. It is binding on all personnel and applies to every system used to process personal data. Information addressed to individuals about their own data is provided separately, in the privacy policy & personal data consent and the cookie policy.

The Company acts as a controller for Company Personal Data (defined in Section 3) and as a processor for Customer Personal Data (also defined in Section 3).

2. Compliance and governance

The Company processes personal data in compliance with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR"), the other data protection law applicable to it, the rules on cookies and electronic marketing communications, and the rules on transparency of AI systems. For Customer Personal Data, the Company also follows the data-processing terms agreed with each Client (the "DPA"), whether as a standalone agreement or incorporated into the service agreement. In interpreting this policy, the Company takes into account the guidelines, recommendations and opinions of the European Data Protection Board.

The Company's representative in the European Union under Article 27 GDPR can be reached at hello@benerra.ai. Supervisory authorities and data subjects may address any related matter there.

All personnel must comply with this policy and consult management in case of doubt. A violation may lead to disciplinary measures or termination of the relevant contract.

3. Definitions

Other terms used here — "Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Consent" and "Personal Data Breach" — carry the meaning the GDPR gives them.

4. Key roles and responsibilities

RoleResponsibilities
Company managementSets the Company's strategy and direction, including on personal-data processing; is responsible for compliance with applicable data-protection requirements; approves this policy and allocates the resources needed to apply it.
IT and securityImplements, at the technical level, the requirements set by management, including the measures described in Section 9; maintains and monitors the systems through which personal data is processed.
PersonnelProcesses personal data in line with applicable data-protection requirements and this policy; reports any actual or suspected personal data breach as set out in Section 9.

As the volume and nature of the personal data the Company processes develop, the Company assesses whether Article 37 GDPR requires it to designate a data protection officer. If that designation becomes mandatory, the Company will make it and reflect the role in an updated version of this policy.

5. Data protection principles

The Company processes personal data:

Data protection is considered when the Services, or any change to them, are designed. By default, only the personal data a given purpose needs is processed, and access is limited to personnel who need it to do their job.

6. Personal data processed and lawful bases

Data typeExamplePurposeBasis
Registration and account dataFull name, email, phone number, company name and position, username, password (encrypted).Creating and administering a Client's account, providing the Services, communicating about them.Our legitimate interest in performing the contract with the Client on whose behalf the individual acts.
Contact and demo-request dataFull name, email, phone number, company name, content of the request.Responding to the enquiry, arranging and conducting a demo call.Our legitimate interest in responding to business enquiries.
Demo call dataTranscript, phone number, date, time and duration of the call.Conducting the demo call and following up on it.Our legitimate interest in presenting the Services; consent to the transcript, where the law requires it.
Cookie dataCookie identifiers, site preferences, IP address.Running the site (strictly necessary cookies); showing the right regional pricing (other cookies).Strictly necessary cookies: our legitimate interest. Other cookies: consent.
Server logsIP address, browser and device type, date and time of access, pages requested.Keeping the site and its systems secure, finding and fixing faults.Our legitimate interest in security and proper operation.
Call data processed for ClientsVoice recordings, transcripts, phone numbers, call metadata, contact lists the Client supplies.Providing the Services under the Client's instructions.Determined by the Client as controller; we process it as a processor under the DPA.

The Company does not process special categories of personal data as a controller. Before a contract is concluded, it informs each Client which categories of personal data the requested agent will process and the characteristics relevant to the Client's own GDPR assessment.

Customer Personal Data may include special categories of data, including health data, where that follows from the Services provided to a Client. The Company processes such data only as a processor, on the Client's documented instructions and under the DPA; the Client is responsible for having a lawful condition for that processing, and personnel with access to it are bound by a specific duty of confidentiality.

For Customer Personal Data, the Client determines the legal basis. The Company processes it only on the Client's documented instructions, tells the Client immediately if it believes an instruction breaches data-protection law, and assists with data-protection impact assessments where the processing requires one.

7. Voice call and AI processing

The Company processes Call Data as a processor on behalf of Clients, except for demo-call data, where it acts as a controller.

At the start of every call, the person is told clearly that they are speaking with an AI system. The Services let each Client also tell callers, at the same time, the Client's identity, that the call is recorded and transcribed, and where to find the full processing information.

Outbound calls are placed only on a Client's documented instructions, to numbers from lists the Client supplies. The Client confirms it has a lawful basis for the calls — including prior consent to automated calls where required — and complies with the rules on call recording, opt-out registers and, where special categories of data are involved, professional-secrecy requirements. Objections a called person raises are recorded and passed to the Client.

The Company does not create voiceprints or otherwise process voice data to identify or verify a person. The Services do not infer callers' emotions or intentions. The Company does not use Customer Personal Data, including Call Data, to train, fine-tune or otherwise develop AI models, and does not use it for its own purposes. The Services are not designed to make decisions based solely on automated processing that produce legal or similarly significant effects on a person.

8. Data retention

Longer retention applies only where the law requires it or it is necessary to establish, exercise or defend a legal claim. Customer Personal Data is retained under the Client's instructions and the DPA; on termination of the Services it is deleted or returned at the Client's choice, unless the law requires storage, and any backup copy is removed in the ordinary backup cycle.

9. Security and personal data breaches

The Company applies technical and organisational measures appropriate to the risk, including pseudonymisation and encryption of personal data, measures for the ongoing confidentiality, integrity, availability and resilience of processing systems, the ability to restore access after a physical or technical incident, and a process for regularly testing and assessing those measures. Personal data is hosted on servers within the European Union. Personnel access personal data only through authorised systems, do not store it on local devices, and are bound by confidentiality.

Personnel report any actual or suspected personal data breach to management as soon as they become aware of it, and every breach is documented whether or not it is notified. Where the Company is the controller, it notifies the competent supervisory authorities without undue delay and, where feasible, within 72 hours, unless the breach is unlikely to cause a risk to individuals; because the Company has no establishment in the EU, notification goes to the supervisory authority of each Member State whose residents are affected. Where a breach is likely to cause a high risk, the Company also informs the affected individuals without undue delay. Where the Company is the processor, it notifies the affected Client without undue delay and gives it the information it needs to meet its own obligations.

10. Disclosure and sharing of personal data

The Company discloses personal data only to personnel who need it for their duties, to processors engaged under Section 11, or to a public authority where the law requires it — verifying the legal basis of the request, disclosing only the minimum required, and informing the Client concerned unless the law forbids that.

A sub-processor for Customer Personal Data is engaged only with the Client's prior authorisation, general or specific, given in writing (including electronically). Where general authorisation applies, the Company tells the Client in advance of any intended new or replacement sub-processor, and the Client may object. A sub-processor is bound by the same data-protection obligations as the Company under the DPA, and the Company remains fully liable to the Client for the sub-processor's performance of them.

11. International transfers

Personal data is stored on servers within the European Union and is accessed by authorised personnel of the Company; this policy applies to it regardless of where it is accessed from.

Where a Client subject to the GDPR makes Customer Personal Data available to the Company, that transfer is governed by the European Commission's standard contractual clauses, incorporated into the DPA. The Company assesses the relevant law and practice of the United Arab Emirates and applies the supplementary measures that assessment identifies.

Any other transfer outside the European Economic Area, including to a processor, takes place only to a country recognised as adequate, under an appropriate safeguard such as standard contractual clauses following a documented transfer assessment, or exceptionally on a specific ground the law permits for an occasional transfer. An onward transfer of Customer Personal Data additionally requires the Client's authorisation. Data subjects can ask about the safeguards applied at hello@benerra.ai.

12. Data subject rights and requests

Data subjects have the right to access, rectify and erase their personal data, to restrict or object to its processing, to data portability, not to be subject to a solely automated decision with a legal or similarly significant effect, to withdraw consent, and to lodge a complaint with a supervisory authority.

A request about Company Personal Data is handled without undue delay and within one month of receipt; that period may be extended by two further months for a complex or numerous request, with the requester told within the first month. The Company may ask for further information only where it has reasonable doubt about the requester's identity, and may decline or charge a reasonable fee for a manifestly unfounded or excessive request. A request about Customer Personal Data is forwarded to the relevant Client without undue delay and answered only with the Client's authorisation. Requests may be addressed to hello@benerra.ai, which also reaches the Company's EU representative.

13. Records, training and review

The Company keeps records of its processing activities as both controller and processor, and makes them available to its EU representative and, on request, to a supervisory authority. Personnel are briefed on this policy when they join the Company. The policy is reviewed on any material change to the Services, the processing they involve, or the applicable law.