Privacy Policy

Version date 21 September 2026

This completed draft sets out the proposed policy for Figr. Its implementation assumptions are recorded in the separate internal review note. It takes effect when Figr first publishes it on its website.

1 Who we are

Figr is the trading name of EnlyAI Inc., a Delaware corporation, with a correspondence address at 131 Continental Dr, Suite 305, Newark, DE 19713, United States. Our website is https://figr.so. You can contact us about privacy at privacy@figr.so or write to our correspondence address, marked for the attention of the Privacy Team.

Figr helps businesses look after their customers through AI agents that provide guidance, visual experiences and connected service actions. This policy explains how we handle personal information when we determine why and how it is used, including on our own website, in business enquiries, demonstrations, customer account administration, sales and support communications.

Features vary by deployment. References to visualisation, voice, memory, messaging and connected actions apply only when the relevant feature is available and used. They do not promise that a feature is available in every deployment.

2 When a business uses Figr to serve you

When a business uses Figr to serve its customers, that business generally determines the purposes of processing and acts as the data controller. Figr processes information on its behalf under documented instructions and the applicable customer agreement and data processing agreement. That business’s privacy notice governs its collection and use of your information.

For example, a retailer controls its shopping conversations and a hotel controls its guest service conversations. Contact that business to exercise rights over those records. We assist the business as required by law and our agreement. If a request reaches Figr, we route or assist with it as appropriate.

This policy separately applies where Figr determines its own processing purpose, such as maintaining its billing contacts. A business’s use of Figr does not authorise us to use its customers’ personal information for our own advertising or unrelated model development.

3 Information we collect

Contact and account information. We receive names, business email addresses, telephone numbers, company names, professional roles, account identifiers and authentication information when you contact us or use an account. We also receive correspondence, support requests, commercial enquiries, subscription details, invoices and relevant payment status information.

Conversations and files. A Figr-operated agent or demonstration may receive your messages, requests, preferences, feedback and uploaded files, together with generated responses and action records. Enabled visual features may receive photos of clothing, products, people, rooms or properties. Enabled voice features may process speech and transcripts. Camera features process the material shared through the relevant feature. The feature notice explains whether media is processed on-device or transmitted to servers and whether it is recorded.

Technical and usage information. We receive IP addresses, browser and device information, timestamps, authentication events, error reports and service usage information. Where enabled and lawful, this includes pages visited, interactions, referral sources and approximate location derived from an IP address. Precise location is not required for our standard business website or demonstrations.

Other sources. We may receive business contact details from your employer, colleagues, referrals, event organisers, publicly available professional sources and business contact service providers. Connected systems may supply information that you or the relevant business authorise them to share. Where required, we explain indirect collection within the applicable legal period or at our first communication.

Inferences. An agent may infer preferences, likely intent or a useful next step from an interaction. These inferences may be inaccurate. You can ask Figr, or the business operating the agent, to correct information relevant to your experience.

Please use designated payment workflows rather than entering complete card numbers or payment authentication details in chat. Avoid supplying identity documents, health records, intimate images or other highly sensitive information unless an expressly approved workflow asks for it and explains the safeguards.

4 Purposes and legal bases

Where European or UK data protection law applies, we rely on the bases below. We assess legitimate interests against the impact on individuals and obtain consent where required. A contract with your employer does not automatically provide a contractual basis for processing your personal information.

Delivering requested services. We use contact, account and interaction records to answer questions, arrange demonstrations, deliver requested features and provide support. Our basis is performance of a contract with you or steps you request before entering one. For representatives of business customers, we rely on legitimate interests in managing the business relationship.

Administration and security. We use relevant records to administer accounts, invoice, maintain financial records, investigate errors, authenticate users, prevent abuse, resolve disputes and protect systems. Our bases are contract performance where applicable, legitimate interests in reliable business operations and protection of rights, and relevant legal obligations.

Evaluation and improvement. We use feedback, proportionate usage information and authorised testing records to understand failures and improve Figr-operated services. Our basis is legitimate interests, subject to safeguards and reasonable expectations, or consent where required. Data from customer deployments remains subject to the separate limits below.

Communications and marketing. We respond to enquiries and send relevant business communications where lawful. We rely on consent when required and legitimate interests when permitted by applicable marketing law. You may object to direct marketing at any time. Agreeing to service terms is not consent to marketing.

Optional processing. We obtain consent where required for nonessential tracking, recording or other optional features. Device permission for a camera or microphone does not replace any additional legal requirement for notice or consent. We explain a materially different processing purpose and its legal basis before introducing it.

Information necessary to provide a requested feature may be required to deliver it. If you do not provide that information, the relevant feature may be unavailable. Optional marketing and nonessential tracking are not conditions of basic website access.

5 AI providers training and simulations

To provide responses and visual or voice experiences, Figr may send relevant inputs, context and instructions to contracted AI providers. Providers process information for authorised service purposes under appropriate agreements. Information about the providers used for a particular deployment, their functions and relevant safeguards is available from privacy@figr.so and through the applicable customer documentation.

We do not use identifiable customer conversations, uploaded media or other customer personal information to train general-purpose models or improve another customer’s agent. Providers processing that information on our behalf must be contractually restricted from using it to train their own general-purpose models. Any separately proposed training use requires an appropriate agreement, transparent notice and a valid legal basis, including consent where required. This policy alone does not authorise that use.

Where a business instructs us to evaluate its agent, relevant examples or interaction patterns may be used to create simulations, compare responses, test permitted actions and investigate failures. That processing remains on the business’s behalf and within its agreed instructions. We use synthetic examples or minimise identifying information where practical. Human review is limited to authorised personnel with a relevant support, quality or security purpose.

Removing a name does not necessarily make a conversation anonymous. Pseudonymised information and test scenarios that reveal a real person remain protected as personal information. We use genuinely anonymised statistics and general technical learning only where their creation and use are lawful and consistent with our customer commitments. We do not attempt to reidentify anonymised information.

6 Visual features voice and relationship memory

Visual features process the media you choose to supply to generate the requested experience. Voice features may process speech and transcripts. Before recording or transmitting optional media, the relevant feature explains the processing and obtains any required permissions. Revoking device permission stops future access; it does not automatically delete information already supplied.

Our standard visual and voice features are not used to identify people through biometric templates or infer sensitive traits such as health, ethnicity or religion. A proposed feature involving those activities requires a separate assessment, lawful basis, notice and appropriate safeguards before use. Photos, measurements and voices may still be personal information when they are not used for biometric identification.

Where enabled, an agent may retain relevant preferences, conversation history and pending tasks to continue an interaction. A business operating a customer deployment determines its memory instructions and retention. For Figr-operated demonstrations, memory follows the conversation retention period below. You can request correction or deletion through privacy@figr.so.

Linking interactions across a website, email, WhatsApp or another channel requires an appropriate account, verified contact or other reliable connection. We do not treat an unverified contact detail as authority to reveal someone else’s conversation. Using two unrelated businesses does not authorise a shared profile across those businesses.

Requested service updates and promotional messages are treated separately. We, or the business operating the agent, obtain the required channel permissions, respect objections and provide a way to stop optional follow-ups. Declining marketing does not prevent essential updates about a service you requested. External messaging platforms also process information under their own privacy notices.

7 Recipients and international processing

We disclose relevant information to contracted providers of hosting, AI processing, communications, security, support, analytics and payment services, subject to appropriate restrictions. A current list of subprocessors used for a customer deployment is available through the customer agreement or by contacting privacy@figr.so. We do not grant providers unrestricted rights over customer content.

In customer deployments, the relevant business and its authorised staff may receive conversations, action records and handoff summaries. Connected commerce, booking, CRM and support systems receive information needed for authorised actions. Any independent processing by those businesses is governed by their own notices.

We may also disclose necessary information to professional advisers, authorities or legally authorised recipients to meet legal obligations, manage disputes or protect rights. A merger, financing, reorganisation or sale may require limited review or transfer of information, subject to applicable law, confidentiality and appropriate safeguards.

We do not sell personal information or share it for cross-context behavioural advertising. We do not use customer deployment content to create advertising audiences. If our practices materially change, we update the relevant notices and implement legally required choices before the change applies.

Information may be processed in the United States and other countries where authorised providers operate. For restricted international transfers, we use applicable adequacy decisions or appropriate contractual transfer mechanisms, including relevant EU standard contractual clauses and UK transfer arrangements where required, with necessary assessments and supplementary measures. You may request information about the safeguards applicable to your information, and a copy where available, at privacy@figr.so. Figr makes no claim in this policy to hold Data Privacy Framework or other unverified certification.

8 Cookies and tracking choices

Essential technologies support functions such as security, session management and requested preferences. Where we use nonessential analytics or personalisation technologies, we explain their provider, purpose and duration in the consent interface before seeking permission where required. Nonessential technologies stay disabled until the required consent is given.

You can reject optional technologies, use the preference controls presented with them, or withdraw consent through privacy@figr.so. Browser settings may also allow you to block or delete stored technologies. Rejecting nonessential tracking does not prevent access to the basic website. We honour legally required opt-out preference signals, including Global Privacy Control where applicable.

We do not use a policy update, continued browsing or acceptance of general terms as consent to optional tracking. Third-party sites reached through external links have their own practices, which you should review before using them.

9 Retention

For information Figr controls, the following standard periods apply unless a shorter period is appropriate or specific legal requirements justify keeping relevant records longer. We delete information or irreversibly anonymise it when the applicable purpose and period end.

Business enquiries and prospect contact records are retained for up to 24 months after the last meaningful interaction. Figr-operated demonstration conversations, transcripts and associated memory are retained for up to 90 days after the interaction. Uploaded images, submitted audio or video and generated visual media are retained for up to 30 days unless you expressly ask us to retain them for an ongoing service. Processing may be transient where the feature does not require storage.

Security and operational logs are retained for up to 12 months. Account administration and support records are retained during the relationship and for up to 24 months after closure. Financial and transaction records needed for tax, accounting and legal purposes are retained for seven years after the relevant financial year, or another period required by applicable law. Minimal suppression records are retained as needed to respect an objection to marketing.

Residual backups are overwritten or deleted within 30 days of deletion from active systems, unless a justified legal hold applies. Deleted information in backups is not used for ordinary processing; if a backup is restored, relevant deletion instructions are reapplied. Legal holds are limited to the records and period needed for the legal purpose.

Customer deployment records, including simulation datasets and memory, follow the retention schedule and deletion instructions in the applicable customer agreement and DPA rather than the demonstration defaults above. Those instructions must cover authorised providers as well as Figr’s own systems.

10 Security

We apply technical and organisational safeguards proportionate to the information and risks, restrict access to authorised personnel and use contractual protections with relevant providers. No system removes every security risk. We investigate incidents and provide notices required by law and our customer agreements. Business customers can request information about applicable security measures through their Figr contact or legal@figr.so.

11 Your rights

Depending on your location and applicable law, you may request access, correction, deletion or a portable copy of your information; restrict processing; object to processing based on legitimate interests; and withdraw consent without affecting the lawfulness of earlier processing. You may object to direct marketing at any time.

Contact privacy@figr.so or write to EnlyAI Inc., Privacy Team, 131 Continental Dr, Suite 305, Newark, DE 19713, United States. We use proportionate identity checks and may verify an authorised representative’s authority. We respond within the applicable legal period and explain any lawful extension or reason for refusing a request. We will not unlawfully discriminate against you for exercising your rights.

If applicable law gives you an appeal right, send your appeal to privacy@figr.so with “Privacy appeal” in the subject. We arrange a review and explain the outcome and any further complaint options. You may complain directly to a competent regulator, including the Spanish AEPD, another EEA supervisory authority, the UK ICO, the Swiss FDPIC or an applicable US state authority. You do not have to contact us first to make a statutory complaint.

For information controlled by a business using Figr, contact that business. Figr assists it rather than independently changing records contrary to lawful customer instructions.

12 Additional US state disclosures

This section applies when our processing is subject to a US state privacy law. The categories described in section 3 include identifiers, customer and account records, commercial information, internet or network activity, approximate location, audio and visual information, professional information and inferences. Sources, purposes, recipient categories and retention criteria are described in sections 3 through 9. Account credentials and voluntarily supplied content may include information treated as sensitive by applicable law.

We use sensitive information only for requested services, authentication, security, legal compliance and other purposes permitted without an additional limitation right, unless we obtain any required consent and provide the necessary choices. We do not sell or share personal information for cross-context behavioural advertising, including information about people known to be under 16. Our standard service does not use personal information for targeted advertising or solely automated decisions that produce legal or similarly significant effects.

Eligible residents may exercise applicable rights to know, access, correct, delete and obtain copies, and rights to opt out of sale, sharing, targeted advertising or qualifying profiling where relevant. Contact privacy@figr.so. We recognise authorised agents and legally required preference signals as applicable. Where a law gives a right to appeal a refusal, use the appeal route in section 11.

13 Automated decisions and children

Agents generate responses and recommendations automatically and may initiate configured actions. Figr-operated website experiences and demonstrations do not make solely automated decisions with legal or similarly significant effects, such as credit, employment or housing eligibility decisions. Customer businesses must assess their own deployments, provide required notices and ensure legally required safeguards and human review.

Our business website, platform accounts and demonstrations are intended for adults aged 18 or over. We do not knowingly solicit children’s personal information through those experiences. Contact privacy@figr.so if you believe a child has provided information contrary to this policy. Customer deployments may reach different audiences; a business must assess age requirements and agree suitable safeguards with Figr before deploying a children-directed experience.

14 Changes and contact

We update this policy as our practices or legal obligations change and give any notice required for material changes. A policy change does not itself provide consent to a new processing purpose. We obtain fresh consent where legally required.

The controller for Figr-operated activities covered by this policy is EnlyAI Inc., trading as Figr. Website https://figr.so. Privacy enquiries privacy@figr.so. Legal enquiries legal@figr.so. Correspondence address 131 Continental Dr, Suite 305, Newark, DE 19713, United States. These contact routes also handle enquiries about applicable local representation and data protection responsibilities.this placeholder with legally reviewed privacy policy content before publishing.

Make exceptional

your standard.

Discover a more personal way to serve your customers.

Make exceptional

your standard.

Discover a more personal way to serve your customers.