Privacy Policy

Last updated: 13 July 2026

1. Introduction

Genifea, Brand owned by Soham Technologies Limited, (“we”, “us”, “our”) operates an AI-powered platform for estate agencies. 

This policy explains what personal data we handle, why, on what legal basis, how long we keep it, and the rights you have. We comply with the UK GDPR and the Data Protection Act 2018 (and, where applicable, the EU GDPR).

2. Our Role: Processor and Independent Controller

We act in two distinct capacities depending on the specific processing:

  • As a *data processor* — we handle the personal data of an agency’s end users (callers, tenants, buyers, sellers) to deliver the service on that agency’s instructions. For this data the estate agency is the controller; we process it only as needed to provide the service and under our agreement with them. The agency’s own privacy notice also applies to you, and you can exercise your rights with the agency or with us (see Your Rights).
  • As an *independent controller* — we determine the purposes and means ourselves for: visitors to our website; our estate-agency customers and their staff (account and billing data); the de-identified, redacted, or anonymised datasets we create from interactions to improve, develop, and (in future) train our products; and security, fraud-prevention, and product analytics. Where we re-use data we originally handled for an agency to create these datasets, we do so as authorised by that agency, and thereafter act as a separate, independent controller (not a joint controller) for that derived data, under our own legal basis (see Legal Basis). For data we control in this capacity, you exercise your rights directly with us (see Your Rights).

3. Whose Data We Process

  • Website visitors — people who visit genifea.com.
  • Customers — estate agencies and their staff who use Genifea.
  • End users — callers, tenants, buyers, sellers, and other users who interact with our AI on an agency’s behalf (by phone, WhatsApp, email, messaging, or any other channel).

4. Categories of Personal Data

  • Identity & contact data — name, phone number, email address.
  • Communication data — call recordings, transcripts, messages (including WhatsApp), and emails.
  • Business & property data — enquiry details, property interest, appointment data.
  • Interaction data — conversation history and behavioural signals about how an enquiry was handled.
  • Technical & usage data — device, log, and usage information.

5. How and why we use personal data

5.1 Delivering the service

We use personal data to operate the AI assistant for the agency — answering enquiries, qualifying leads, booking and managing appointments, taking messages, and routing to staff.

5.2 Quality assurance and service improvement — *what we do today*

Authorised Genifea personnel review a limited selection of interactions — including call recordings and transcripts, particularly those where the AI did not perform as intended — to diagnose problems, fix errors, and improve the product. This review focuses on how the enquiry was handled, not on identifying the people involved. Access is limited to authorised personnel, we minimise the personal data used, and we retain review material only as long as necessary for this purpose.

5.3 Building and training our AI — *what we may do*

We do not currently use interaction data to train machine-learning models. We reserve the right to do so in the future, and if we do, we will use only de-identified or anonymised data:

  • We may create redacted copies of interactions — transcripts with identifying details removed, and call recordings with personal details (such as names, phone numbers, and email addresses) masked (“beeped”) out — and use them to train and improve our AI models.
  • We use such data to learn how enquiries are handled, not to identify individuals.
  • We do not use identifiable voice recordings or other identifiable personal data to train models without a separate lawful basis (such as your explicit consent).

Where we can fully anonymise data so that no individual can be identified, it is no longer personal data and may be retained and used indefinitely (see Retention).

5.3.1 Google user data
The use and transfer of raw or derived user data received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google Calendar data only to provide the scheduling features you see in the product. We do not use Google user data — including Google Calendar data or any data derived from it — to train or improve any AI or machine-learning model.

5.4 Security, fraud prevention, and legal compliance

We use personal data to keep the service secure, detect and prevent abuse, and meet our legal obligations — including handling requests from public authorities under our Government & Law-Enforcement Data Request Policy (see Requests from public authorities).

5.5 Aggregated insights

We may produce aggregated and anonymised statistics and industry insights. These do not identify any individual.

6. Legal Basis

Purpose

Lawful basis

Delivering the service 

Performance of a contract; or, for end-user data, the agency’s instructions as controller

Quality assurance & improvement 

Legitimate interests in providing and improving a safe, effective service — *you may object*

Creating de-identified datasets / future model training 

Legitimate interests in improving our services — *you may object*; or explicit consent where required

Security, fraud, legal compliance

Legitimate interests; legal obligation

Aggregated insights 

Legitimate interests (operates on anonymised data)

7. Automated Decision Making

Our AI makes some decisions autonomously, without a person reviewing each one beforehand — most importantly, qualifying enquiries (assessing, against the estate agency’s criteria, whether and how an enquiry proceeds, for example to a viewing or appointment). These decisions are surfaced to the agency for audit, but they are made automatically.

Where a decision about you is based solely on automated processing and produces legal or similarly significant effects, you have specific protections under UK GDPR Article 22. For such decisions:

  • The automated qualification is carried out on behalf of the estate agency, which sets the criteria and is the controller of that decision; we act as the agency’s processor.
  • The decision is made to take steps at your request to enter into, or carry out, a transaction with the agency (e.g., arranging a viewing), and/or on the basis of your explicit consent, as the agency relies upon.
  • You have the right to obtain human review of the decision, to express your point of view, and to contest it. To do so, contact the agency, and a person able to change the outcome will review it.
  • Meaningful information about the logic: enquiries are assessed against the agency’s stated qualification criteria; the main consequence is whether and how your enquiry proceeds (for example, whether a viewing is offered).

We do not use special-category data to make these decisions.

8. Requests From Public Authorities

When a government, law-enforcement, regulatory, or judicial body requests personal data, we follow our Government & Law-Enforcement Data Request Policy: we verify the legality of each request, challenge requests we believe are unlawful or overbroad, disclose only the minimum necessary, and document each request and our response. Where legally permitted, we will notify affected individuals.

9. Sharing and Processors

We do not sell identifiable personal data. We share personal data with:

  • Service providers (processors) that help us run the platform, including: cloud hosting and infrastructure ; database hosting ; AI processing of conversation content to generate responses ; and telephony/messaging. All are bound by data-processing agreements.
  • Professional advisers (e.g., legal, accounting), under confidentiality.
  • Public authorities, where required by law and handled per Requests from public authorities.

In a merger, acquisition, restructuring, or sale of assets, personal data may transfer to the successor entity, subject to this policy.

10. Retention

Operational data processed for an agency — kept as needed to provide the service and per the agency’s instructions and our agreement.

  • Quality-assurance / improvement material and PII-redacted (beeped) data — these remain personal data; we keep them only as long as necessary for the purpose and honour erasure requests (see Your Rights).
  • Fully anonymised data — no longer personal data; may be retained indefinitely.
  • We keep records required for legal, tax, or security purposes for the periods the law requires.

11. International Transfers

Some processing may take place outside the UK/EEA. Where it does, we rely on appropriate safeguards such as the UK International Data Transfer Addendum / EU Standard Contractual Clauses.

12. Your Rights

Subject to law, you have the right to: access your data; correct it; erase it; restrict or object to processing; data portability; and to withdraw consent where we rely on it.

How to exercise your rights:

  • Contact contact@genifea.com. We will verify your identity before acting.
  • For data we process on behalf of an estate agency (operational data), the agency is the controller; you can raise your request with the agency or with us, and we will coordinate accordingly.
  • For data we control — in particular the de-identified / PII-redacted material we hold to improve and train our products — you (the individual the data is about) can request erasure directly with us. We act on requests from the data subject; we do not action third-party requests to erase another person’s data from this material.
  • Fully anonymised data cannot be linked back to you and therefore cannot be retrieved or erased on an individual basis.

You also have the right to complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk, or your local supervisory authority.

13. Security

Data security: Your data is encrypted in transit and at rest. Access is protected by database-level access controls, and access to customer data is restricted to authorised personnel on a need-to-know basis.

Data Breaches: If a personal-data breach is likely to result in a risk to your rights, we will notify the ICO within 72 hours where required, and affected individuals where the risk is high.

Children: Our service is not directed at children, and we do not knowingly process children’s personal data. If you believe a child’s data has been provided, contact us and we will delete it.

14. Changes

We may update this policy. We will post the updated version here with a new effective date and, where changes are material, take reasonable steps to notify you.

15. Governing Law

This policy is governed by the laws of England and Wales.

16. Contact

Questions or requests: contact@genifea.com.

Who we are

Suggested text: Our website address is: https://www.genifea.com.

Comments

Suggested text: When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.

An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.

Media

Suggested text: If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.

Cookies

Suggested text: If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.

If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.

When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.

If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.

Embedded content from other websites

Suggested text: Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.

These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.

Who we share your data with

Suggested text: If you request a password reset, your IP address will be included in the reset email.

How long we retain your data

Suggested text: If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue. For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.

What rights you have over your data

Suggested text: If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.

Where your data is sent

Suggested text: Visitor comments may be checked through an automated spam detection service.