Staffa.work Logo Staffa.work
Home / Global Privacy Policy
🛡️ Multi-Jurisdictional Privacy Framework

Global Privacy Policy

Effective Date: 20 September 2026 • Published by Wnode Ltd trading as Staffa

1. Introduction & International Scope

Staffa is committed to safeguarding personal information across all jurisdictions in which we operate. This Global Privacy Policy details how Wnode Ltd trading as Staffa ("Staffa", "we", "us", or "our") processes, stores, and protects personal data in compliance with:

  • United Kingdom: UK General Data Protection Regulation (UK GDPR), Data Protection Act 2018 (DPA 2018), and PECR 2003.
  • European Union: EU General Data Protection Regulation (EU GDPR 2016/679) and the ePrivacy Directive (2002/58/EC).
  • United States: Telephone Consumer Protection Act (TCPA, 47 U.S.C. § 227), CAN-SPAM Act (15 U.S.C. § 7701), and California CCPA/CPRA.
  • Canada: Personal Information Protection and Electronic Documents Act (PIPEDA) and Canada's Anti-Spam Legislation (CASL).
  • Australia: Privacy Act 1988 (Cth) including the Australian Privacy Principles (APPs) and the Spam Act 2003 (Cth).

2. Data Controller vs. Data Processor

Staffa as Data Controller: We act as Data Controller for website visitor information on staffa.work, prospective client communications, client account management, and direct billing relationships.

Staffa as Data Processor / Service Provider: When providing automated AI voice reception, call triage, SMS dispatch, and scheduling to our clients, Staffa acts strictly as a Data Processor. Our client is the Data Controller determining the lawful basis and triage rules for incoming calls.

Registered Entity: Wnode Ltd t/a Staffa (incorporated in England and Wales, company address: 61a Bridge Street, Kington, Herefordshire, HR5 3DJ, UK). Data Controller & Support: support@staffa.work.

3. Lawful Bases for Processing (UK & EU GDPR Art. 6)

Data Category Operational Purpose Lawful Basis (Art. 6)
Client Account Data Provisioning DID numbers, brain compilation, customer support Art. 6(1)(b) Contract Performance
Billing & Usage Wallet Processing £147/$187 setup, £15/mo base, and £25 wallet auto-reloads Art. 6(1)(b) Contract & Art. 6(1)(c) Legal Duty
Caller Triage Data Transcribing fault, address, and dispatching urgent SMS to staff Art. 6(1)(b) Contract (as Processor)
B2B Discovery Corporate outreach adhering to UK PECR corporate exemptions Art. 6(1)(f) Legitimate Interests

4. Multi-Jurisdictional Telephony & Marketing Protections

United States (TCPA & CAN-SPAM)

Prior express written consent enforced for automated voice/SMS. Immediate automated opt-out via "STOP" keyword. Outbound dispatches strictly constrained to 8:00 AM – 9:00 PM recipient local time. CAN-SPAM compliant headers and physical address.

Canada (CASL Compliance)

Commercial Electronic Messages (CEMs) require express or verified implied consent. Mandatory sender identification and 60-day accessible unsubscribe facility processed within 10 business days.

Australia (Spam Act & APPs)

Outreach conducted strictly with consent. Functional unsubscribe facility honored within 5 business days. Full adherence to the Australian Privacy Principles (APPs) for information governance.

United Kingdom (PECR & GDPR)

Cold B2B electronic outreach strictly limited to corporate subscribers (Ltd / LLP). Sole traders and personal email domains are systematically excluded. Frictionless opt-out provided on every contact.

5. Third-Party Payment Processor Disclosures (Stripe)

Payment transactions, recurring subscriptions, and usage wallet auto-reloads are processed directly through Stripe Payments Europe, Ltd. and its international affiliates:

  • Payment card data is encrypted directly via TLS 1.3 to Stripe's secure infrastructure. Staffa servers never receive or store complete Primary Account Numbers (PAN) or CVV codes.
  • Stripe acts as an independent data controller for fraud detection (Stripe Radar), anti-money laundering (AML), and regulatory financial reporting.
  • For full details, visit stripe.com/privacy.

6. Sub-Processors & International Transfers

To deliver low-latency conversational AI intake, we partner with vetted sub-processors:

  • Telnyx LLC: Telecommunications carrier layer for local DID phone numbers and SIP routing.
  • ElevenLabs, Inc.: Conversational voice synthesis and natural language processing.
  • Cal.com, Inc.: Interactive walkthrough booking and live diary synchronization.

International transfers outside the UK/EEA are protected via Standard Contractual Clauses (SCCs), the UK IDTA, or adequacy regulations under Chapter V of GDPR.

7. 100% Zero-Notice Cancellation & Wallet Refunds

Zero Notice Period: Cancel your subscription anytime with zero prior notice and zero penalty or exit fees.

Service Continuity: Your intake number, AI receptionist, and SMS dispatch stay 100% active until the end of your current paid 30-day billing cycle.

Prepaid Wallet Refund: Upon account closure, any unconsumed prepaid usage wallet balance above £5.00 / $5.00 is refunded via Stripe upon written request to support@staffa.work within 30 days of service expiration.

8. Your Data Subject & Consumer Privacy Rights

Depending on your jurisdiction, you have the right to request access, rectification, erasure ("right to be forgotten"), restriction, and data portability, as well as the right to object to direct marketing or opt-out of personal information sharing (CCPA/CPRA).

To exercise your rights, email our team at support@staffa.work. We respond to all verified requests within one calendar month.

9. Contact & Supervisory Authority Information

Wnode Ltd t/a Staffa 61a Bridge Street, Kington, Herefordshire, HR5 3DJ
Data Controller & Support: support@staffa.work
UK Supervisory Authority: Information Commissioner's Office (ICO) • Helpline: 0303 123 1113 • ico.org.uk