Privacy Policy
How Axum AI Systems Limited protects and uses data when you use CARA.
Last updated: 11 September 2026
This Privacy Policy explains how Axum AI Systems Limited (“Axum”, “we”, “us”, “our”), the company behind CARA®, collects, uses, and protects information when you use cara.irish or interact with CARA as part of a business’s phone line.
This policy is written to comply with the General Data Protection Regulation (GDPR) and Irish data protection law.
Who this applies to
This policy covers two groups of people, and we handle their data differently:
- Business clients — the businesses that sign up to use CARA
- Callers — the customers who call your business and speak with CARA
What data we collect
From business clients, at signup and while using the service:
- Business name and trade type
- Contact name, email address, and phone number
- Account login details
- Billing and pricing information relevant to your plan
From calls handled by CARA on your business’s phone line:
- The caller’s phone number
- Call recordings
- Written transcripts of the call
- Details discussed during the call that relate to booking an appointment, such as a preferred date, time, or service requested
- Calendar and booking details, where your business has connected a calendar
We do not collect more than we need to provide the service.
Why we collect it
- To answer calls, book appointments, and sync bookings to your calendar on your business’s behalf
- To keep an accurate record of what was agreed on a call, in case of a dispute or a misunderstanding
- To review call quality and improve how CARA handles future calls
- To maintain your account and communicate with you about it
- To meet our own legal and accounting obligations
How long we keep data
Call recordings and transcripts are retained for a minimum of 90 days. This allows enough time for quality review and for any booking disputes to be resolved. After that period, they are permanently deleted from our systems unless we are legally required to keep them longer.
Account and business information is kept for as long as your account is active, and for a reasonable period afterwards to meet accounting and legal obligations — typically up to 6 years, in line with standard Irish record-keeping requirements.
If your business asks us to delete a call recording or transcript before the 90-day period ends, it is hidden from your dashboard immediately, but retained securely on our backend for the remainder of the 90 days. This is to protect both your business and your callers in case a record is genuinely needed — for example, a dispute over what was agreed — before it is gone for good.
Our role under GDPR: Data Processor and Data Controller
This is an important distinction, and we want to be upfront about it:
For call data — recordings, transcripts, and details about your callers — your business is the Data Controller, and Axum AI Systems Limited acts as a Data Processor on your behalf. This means your business decides why this data is collected, and we process it under your instruction, using the service as designed.
For your own account and billing information — the details you gave us directly to set up and manage your account — Axum AI Systems Limited acts as the Data Controller.
If you are a business client, this means you have your own obligations to your customers under GDPR regarding the call data CARA collects on your behalf. We are glad to support you in meeting them, but the responsibility for your own customers’ data ultimately sits with you as the Controller.
Call Recordings — a closer look
Because call recordings are sensitive, they get their own section:
Purpose
Recordings are made so your business has an accurate record of what was discussed, to support quality review of CARA’s performance, to help resolve any dispute about what was agreed on a call, and to improve how CARA is trained over time.
Disclosure
Every caller hears a clear spoken notice at the start of the call that the call may be recorded. See CARA’s Spoken Greeting elsewhere in this section.
Storage and security
Recordings are stored securely using encrypted cloud infrastructure. Access is strictly limited. Your business can only ever see or hear recordings from calls made to your own business line. No other business using CARA can access your calls, recordings, or transcripts, and this is enforced at the database level, not just by permission settings in the app.
Retention
Minimum of 90 days, as above.
Your rights under GDPR
If you are a caller whose data was collected during a call, or a business client, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Erase your data, subject to our legal retention obligations
- Restrict how we process your data in certain circumstances
- Object to certain kinds of processing
- Receive a copy of your data in a portable format
- Complain to the Irish Data Protection Commission (DPC) if you believe your data has been mishandled
To exercise any of these rights, contact us at hello@cara.irish.
If you are a caller and your query relates to how a specific business uses your data, we may need to direct you to that business directly, since they are the Data Controller for that data.
Governing law
This Privacy Policy is governed by the laws of Ireland, and any disputes relating to it are subject to the exclusive jurisdiction of the Irish courts.