Privacy Policy
CNTXT FZCO

1. Introduction

1.1 About This Policy

This Privacy Policy ("Policy") explains how CNTXT FZCO and its affiliates and subsidiaries operating under the 'CNTXT' brand ("CNTXT AI", "we", "our" or "us") collect, store, use, disclose, and otherwise process personal data about you when you interact with our website www.cntxt.tech ("Website"), our AI data services, annotation platform, and other products or services (collectively, the "Services").

1.2 Our Commitment

CNTXT AI is committed to protecting your privacy and ensuring the security of your personal data in accordance with:

  • UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data
  • Dubai Data Law (Law No. 26 of 2015) as amended
  • International Free Zone Authority (IFZA) regulations
  • Where applicable, the General Data Protection Regulation (EU) 2016/679 ("GDPR")

1.3 Data Controller Information

CNTXT FZCO
International Free Zone Authority (IFZA)
Dubai Silicon Oasis, Dubai, United Arab Emirates
Email: privacy@cntxt.tech

2. Acceptance of Terms

By accessing or using our Website and Services, you acknowledge that you have read, understood, and agree to be bound by this Policy. If you do not agree with this Policy, please do not use our Services.

3. Applicable Legislation & Regulatory Framework

This Policy is designed to comply with:

3.1 Primary UAE Legislation

  • UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data
  • Dubai Data Law (Law No. 26 of 2015) as amended
  • UAE Cybercrime Law (Federal Decree-Law No. 34 of 2021)
  • IFZA Regulations applicable to technology companies
  • UAE National Strategy for Artificial Intelligence 2031
  • UAE National Cybersecurity Strategy

3.2 Sector-Specific Requirements

  • Healthcare: UAE Health Data Law where applicable
  • Financial Services: UAE Central Bank regulations for fintech
  • Government: Enhanced requirements for government contracts
  • Telecommunications: TRA (TDRA) requirements where applicable

3.3 International Frameworks

  • GDPR (Regulation (EU) 2016/679) for EU data subjects
  • CCPA for California residents
  • ISO/IEC 27701 Privacy Information Management
  • ISO/IEC 29100 Privacy Framework
  • Other applicable international data protection laws

3.4 Industry Standards and Best Practices

  • NESA Standards (National Electronic Security Authority)
  • Dubai Electronic Security Center Guidelines
  • UAE IA Standards (Information Assurance)
  • Cloud Security Alliance Guidelines
  • AI Ethics Guidelines from UAE AI Office

4. Definitions

Unless otherwise defined in this Policy, terms shall have the following meanings:

"Consent" means any freely given, specific, informed, and unambiguous indication of the data subject's agreement to the processing of their personal data.

"Controller" means the entity that determines the purposes and means of processing personal data.

"Data Subject" means the identified or identifiable natural person to whom the personal data relates.

"Personal Data" means any data related to an identified or identifiable natural person as defined under UAE Federal Decree-Law No. 45 of 2021, including but not limited to name, voice, picture, identification number, online identifier, geographic location, or one or more special elements that express the physical, psychological, economic, cultural, or social identity of that person.

"Processing" means any operation or set of operations performed on personal data, whether or not by automated means, including collecting, recording, organizing, structuring, storing, adapting, altering, retrieving, using, disseminating, disclosing, combining, restricting, erasing, or destroying.

"Processor" means the entity that processes personal data on behalf of the Controller.

"Sensitive Personal Data" means personal data that reveals or relates to:

  • Family details
  • Racial or ethnic origin
  • Political opinions or affiliations
  • Religious or philosophical beliefs
  • Criminal records
  • Biometric or genetic data
  • Health data
  • Data determined as sensitive by the UAE Data Office

5. Scope of This Policy

This Policy applies to personal data collected through:

5.1 Direct Collection

  • Information you provide when registering for an account
  • Data submitted through our Services
  • Information provided when contacting us
  • Details shared at events or conferences

5.2 Automated Collection

  • Technical data collected via cookies and similar technologies
  • Usage information and analytics
  • Device and browser information
  • IP addresses and location data

5.3 Third-Party Sources

  • Authentication providers (e.g., Google OAuth)
  • Business partners and resellers
  • Public databases and directories
  • Social media platforms

6. Types of Personal Data We Collect

6.1 Identity and Contact Information

  • Full name and title
  • Email address
  • Phone number
  • Emirates ID number (where legally required)
  • Company name and job title
  • Professional credentials

6.2 Account Information

  • Username and password
  • Account preferences
  • Profile information
  • Authentication data
  • API keys and access tokens

6.3 Technical Information

  • IP address
  • Browser type and version
  • Device information
  • Operating system
  • Time zone settings
  • Location data (with consent)

6.4 Usage Information

  • How you use our Services
  • Pages visited and features used
  • Search queries
  • Click-through data
  • Session duration
  • API usage metrics

6.5 Transaction Information

  • Purchase history
  • Billing information
  • Payment details (tokenized)
  • Contract details
  • Invoice records

6.6 Communication Data

  • Email correspondence
  • Support tickets
  • Feedback and surveys
  • Call recordings (with consent)
  • Meeting notes and transcripts

6.7 AI Training and Annotation Data

  • Data submitted for annotation
  • Model training parameters
  • Performance metrics
  • Quality assurance data
  • Dataset metadata
  • Arabic language datasets
  • Multilingual training data

6.8 Marketing Information

  • Communication preferences
  • Newsletter subscriptions
  • Event attendance
  • Marketing campaign responses

6.9 Government and Enterprise Data

When working with UAE government entities or enterprises:

  • Security clearance information (where applicable)
  • Project classification levels
  • Access authorization data
  • Compliance certifications

6.10 Google Workspace API Data

When you connect Google Workspace:

  • Calendar information
  • Email metadata (not content unless explicitly authorized)
  • Drive file metadata
  • Contact information

Important Note: Data accessed through Google Workspace APIs is NOT used for:

  • Developing generalized AI models
  • Training machine learning models
  • Creating or enhancing AI/ML capabilities
  • Any purpose beyond providing our specified Services

6.11 Sovereign Data Categories

In alignment with UAE sovereign AI initiatives:

  • Data classified under UAE data sovereignty requirements
  • National infrastructure project data
  • Government service interaction data
  • Critical sector information (energy, healthcare, finance)

7. How We Use Your Personal Data

We process your personal data for the following purposes:

7.1 Service Delivery

  • Providing access to our AI annotation and data services
  • Managing your account and authentication
  • Processing transactions
  • Delivering customer support
  • Fulfilling contractual obligations
  • Enabling API access and integrations

7.2 AI and Innovation Services

  • Facilitating data annotation and labeling services
  • Quality assurance and validation processes
  • Performance analytics and metrics
  • Model training support (not using your confidential data)
  • Supporting Arabic language AI development
  • Advancing multilingual AI capabilities
  • Contributing to UAE's AI ecosystem

7.3 Service Improvement

  • Enhancing user experience
  • Developing new features and capabilities
  • Conducting analytics and research
  • Personalizing content and recommendations
  • Optimizing platform performance
  • Innovation in AI technologies

7.4 Communication

  • Responding to inquiries
  • Sending service notifications
  • Providing technical support
  • Sharing updates and announcements
  • Delivering training and educational content

7.5 Marketing (with consent where required)

  • Sending promotional materials
  • Informing about new services
  • Event invitations
  • Newsletter distribution
  • Industry insights and thought leadership

7.6 Security and Compliance

  • Preventing fraud and abuse
  • Ensuring platform security
  • Complying with legal obligations
  • Enforcing our terms
  • Protecting rights and property
  • Meeting regulatory requirements

7.7 Government and Enterprise Services

  • Supporting digital transformation initiatives
  • Enabling sovereign AI capabilities
  • Facilitating public-private partnerships
  • Contributing to national AI strategies
  • Supporting critical infrastructure projects

7.8 Legal and Regulatory

  • Complying with UAE laws and regulations
  • Meeting IFZA requirements
  • Responding to legal requests
  • Establishing or defending legal claims
  • Supporting law enforcement (where legally required)

8. Legal Basis for Processing

We process your personal data based on the following legal grounds under UAE Data Protection Law:

8.1 Consent

You have provided explicit, clear, and informed consent for processing, which you may withdraw at any time.

8.2 Contract Performance

Processing is necessary to:

  • Perform our contract with you
  • Take steps before entering a contract
  • Deliver requested Services

8.3 Legal Obligations

Processing is required to comply with:

  • UAE Federal laws
  • Dubai regulations
  • IFZA requirements
  • Other applicable laws

8.4 Legitimate Interests

Processing is necessary for legitimate interests, including:

  • Business operations and administration
  • Marketing and business development
  • Network and information security
  • Fraud prevention
  • Product development and improvement

8.5 Vital Interests

Processing is necessary to protect vital interests, including life-threatening situations.

8.6 Public Interest

Processing serves the public interest as recognized under UAE law.

8.7 GDPR Basis (for EU Data Subjects)

Where applicable, we also rely on Article 6 of the GDPR for processing EU personal data.

9. Disclosure of Personal Data

9.1 Service Providers

We may share data with carefully selected third-party service providers:

  • Cloud infrastructure providers (UAE-based where required)
  • Payment processors licensed in UAE
  • Email and communication services
  • Analytics providers
  • Customer support platforms
  • Security service providers

All service providers are:

  • Contractually bound to protect your data
  • Prohibited from using data for their own purposes
  • Required to delete data after service completion
  • Subject to regular audits

9.2 Strategic Partners

  • Technology integration partners
  • UAE government entities (for joint initiatives)
  • Research institutions (anonymized data only)
  • Industry collaborators
  • Academic partners for AI research

9.3 Legal and Regulatory Disclosures

We may disclose data when required by:

  • UAE Federal Courts
  • Dubai Courts and authorities
  • IFZA regulatory bodies
  • UAE Data Office
  • Law enforcement agencies (with proper warrants)
  • National security authorities (as legally required)

9.4 Business Transfers

In case of:

  • Merger or acquisition
  • Asset sale
  • Corporate restructuring
  • Joint ventures

Your data may be transferred with appropriate protections.

9.5 With Your Explicit Consent

  • Specific third-party services you request
  • Partner integrations you authorize
  • Research participation you agree to
  • Marketing partnerships (opt-in only)

9.6 Important Restrictions

We commit to:

  • NEVER selling personal data to third parties
  • NEVER renting or trading personal data
  • NEVER sharing data for unauthorized AI training
  • NEVER using client data to train models for other clients
  • Requiring strict data protection agreements with all recipients
  • Ensuring data minimization principles
  • Implementing purpose limitation controls

9.7 Transparency Commitment

We maintain a registry of all data sharing activities and can provide you with:

  • List of categories of recipients
  • Purposes of each disclosure
  • Safeguards implemented
  • Your rights regarding each disclosure

10. International Data Transfers

10.1 Transfer Locations

Your data may be transferred to and processed in:

  • Countries where we have operations
  • Countries where our service providers are located
  • Countries with data centres we utilize

10.2 Transfer Safeguards

We ensure appropriate protection through:

For UAE Data:

  • Compliance with UAE Data Office requirements
  • Transfers to countries with adequate protection
  • Appropriate technical and organizational measures
  • Data transfer agreements with UAE-required clauses

For EU Data (where applicable):

  • Standard Contractual Clauses
  • Adequacy decisions
  • Other GDPR-compliant mechanisms

10.3 Data Localization

Where required by UAE law, we maintain data within the United Arab Emirates.

11. Data Security

11.1 Technical Measures

  • Encryption at rest (AES-256) and in transit (TLS 1.2+)
  • Multi-factor authentication
  • Access controls and authorization
  • Network segmentation
  • Intrusion detection systems
  • Regular security updates

11.2 Organizational Measures

  • Security policies aligned with UAE standards
  • Employee training and awareness
  • Confidentiality agreements
  • Background checks (where permitted)
  • Access on need-to-know basis
  • Regular audits and assessments

11.3 Physical Security

  • Secure data centers
  • Access controls
  • Environmental monitoring
  • Secure disposal procedures

11.4 Incident Response

In case of a data breach:

  • Immediate investigation and containment
  • Notification to UAE Data Office within 72 hours
  • Notification to affected individuals where required
  • Documentation and remediation
  • Implementation of preventive measures

12. Data Retention

12.1 Retention Periods

We retain personal data for:

  • Active accounts: Duration of account plus 30 days
  • Transaction records: 7 years (legal requirement)
  • Marketing data: 3 years or until consent withdrawn
  • Communication records: 3 years
  • Security logs: 12 months
  • AI training data: As per service agreement
  • Google Workspace API data: Only during active session

12.2 Retention Criteria

We determine retention based on:

  • Legal and regulatory requirements
  • Contractual obligations
  • Business needs
  • Limitation periods for claims
  • Consent duration

12.3 Data Deletion

Upon expiration of retention periods:

  • Secure deletion or anonymization
  • Instruction to third parties to delete
  • Purging of backups per schedule
  • Documentation of deletion

13. Your Rights

Under UAE Data Protection Law, you have the following rights:

13.1 Access Rights

  • Request confirmation of processing
  • Access your personal data
  • Receive information about processing purposes
  • Understand data categories collected
  • Know recipients of your data
  • Information about retention periods

13.2 Rectification

  • Correct inaccurate data
  • Complete incomplete data
  • Update outdated information

13.3 Erasure ("Right to be Forgotten")

  • Request deletion in certain circumstances
  • Removal from marketing databases
  • Deletion of unnecessary data

13.4 Restriction

  • Limit processing in specific situations
  • Suspend processing pending verification
  • Restrict use for certain purposes

13.5 Data Portability

  • Receive data in structured format (JSON/CSV)
  • Transfer to another controller
  • Direct transfer where technically feasible

13.6 Objection

  • Object to processing based on legitimate interests
  • Object to direct marketing (immediate effect)
  • Object to automated decision-making
  • Object to profiling activities

13.7 Consent Management

  • Withdraw consent at any time
  • Manage communication preferences
  • Control cookie settings
  • Opt-out of analytics

13.8 No Automated Decision-Making

  • Right to human review of automated decisions
  • Explanation of logic involved
  • Challenge automated decisions
  • Request human intervention

13.9 Additional Rights for EU Residents

EU data subjects have additional rights under GDPR:

  • Lodge complaints with supervisory authorities
  • Seek judicial remedy
  • Compensation for damages

13.10 Transparency Rights

  • Clear information about data processing
  • Notification of data breaches
  • Information about third-party sharing
  • Access to privacy impact assessments (where applicable)

13.11 Exercising Your Rights

To exercise your rights:

Email: privacy@cntxt.tech

Response Timeline:

  • Acknowledgment: Within 3 business days
  • Initial response: Within 15 days
  • Complex requests: Up to 30 days (with notification)
  • Extensions: Maximum 60 additional days for complex cases

Verification Process:

  • Identity verification required
  • Emirates ID or passport copy may be requested
  • Additional verification for sensitive requests
  • No fees for standard requests

13.12 Complaints and Escalation

If you're unsatisfied with our response:

  • Internal review by Data Protection Officer
  • Escalation to senior management
  • File complaint with UAE Data Office
  • For EU residents: Lodge complaint with local supervisory authority

14. Cookies and Tracking Technologies

14.1 Types of Cookies

  • Necessary: Required for site functionality
  • Performance: Collect usage information
  • Functional: Remember preferences
  • Marketing: Deliver relevant content

14.2 Cookie Management

You can manage cookies through:

  • Browser settings
  • Cookie consent banner
  • Privacy settings in your account

14.3 Third-Party Cookies

Some third-party services may set cookies. Please review their privacy policies. For detailed information, see our Cookie Policy.

15. AI Model Development and Data Usage

15.1 Our AI Development Principles

Aligned with UAE AI companies' best practices:

  • Transparency: Clear disclosure of AI data usage
  • Separation: Client data never used for other clients' models
  • Innovation: Contributing to Arabic and multilingual AI advancement
  • Sovereignty: Supporting UAE's AI independence goals
  • Ethics: Adhering to UAE AI Ethics Guidelines

15.2 Data Usage in AI Development

For Our Platform Improvement:

  • Aggregated usage patterns (anonymized)
  • Performance metrics (non-identifiable)
  • Error logs and system optimization data
  • General quality improvement insights

For Client-Specific Services:

  • Training data remains isolated to client environment
  • Models trained exclusively for specific client use
  • No cross-contamination between client datasets
  • Clear data ownership maintained

For Research and Innovation:

  • Only with explicit consent
  • Fully anonymized or synthetic data
  • Contributing to open-source Arabic AI development
  • Academic partnerships with data protection agreements

15.3 Prohibited AI Uses

We will NEVER:

  • Use your data to train models for competitors
  • Sell AI insights derived from your data
  • Create derivative works without permission
  • Use personal data for unauthorized AI training
  • Develop surveillance or monitoring capabilities
  • Create models for harmful or discriminatory purposes

15.4 Arabic Language AI Commitment

As part of UAE's Arabic AI leadership:

  • Protecting Arabic language datasets
  • Ensuring cultural sensitivity in AI development
  • Contributing to sovereign Arabic language models
  • Supporting dialect preservation and understanding

15.5 Model Security and Privacy

  • Encrypted model storage
  • Access-controlled model deployment
  • Audit trails for all model access
  • Privacy-preserving techniques in training
  • Regular model security assessments
  • Protection against model extraction attacks

16. Children's Privacy

Our Services are not directed to individuals under 18 years of age. We do not knowingly:

  • Collect data from minors
  • Market to children
  • Allow minors to create accounts

If we discover data from a minor:

  • Immediate deletion upon discovery
  • Notification to relevant parties
  • Review of collection procedures
  • Implementation of additional safeguards

Parents/guardians may contact us at privacy@cntxt.tech regarding any concerns.

17. Training and Awareness

All CNTXT AI employees receive:

  • Mandatory data protection training during onboarding
  • Regular privacy awareness updates (quarterly)
  • Role-specific training for data handlers
  • AI ethics and responsible data use training
  • Updates on UAE regulatory changes
  • Security awareness and incident response training

We also provide:

  • Privacy training for our partners
  • Best practices guidance for clients
  • Regular privacy webinars and workshops
  • Contribution to UAE privacy awareness initiatives

18. Complaints

If you're unsatisfied with our response:

  • Request escalation to senior management
  • Contact our Data Protection Officer directly
  • Lodge a complaint with UAE Data Office
  • For EU residents: Contact your local supervisory authority

19. Governing Law and Dispute Resolution

19.1 Governing Law

This Policy is governed by:

  • Laws of the United Arab Emirates (Federal)
  • Dubai laws (Emirate level)
  • IFZA regulations and rules

19.2 Dispute Resolution

Any disputes shall be resolved through:

  • Good faith negotiations (30 days)
  • Arbitration under Dubai International Arbitration Centre (DIAC) rules
  • Seat of arbitration: Dubai, UAE
  • Language: English

20. Sovereign AI and Data Localization

20.1 UAE Data Sovereignty Commitment

In alignment with UAE's sovereign AI strategy and following practices of G42, Core42, and other UAE leaders:

  • All UAE government and critical infrastructure data remains within UAE borders
  • Processing occurs in UAE-based data centers
  • No foreign access without explicit government authorization
  • Compliance with UAE data localization requirements
  • Support for national data independence initiatives

20.2 National AI Initiatives

CNTXT AI actively supports UAE's AI ambitions by:

  • Contributing to Arabic language model development
  • Supporting UAE National Strategy for Artificial Intelligence 2031
  • Participating in Dubai AI Roadmap initiatives
  • Collaborating with UAE AI Office on best practices
  • Enabling the UAE's vision to become the first AI-powered government by 2031
  • Supporting the UAE's goal to be a global AI leader

20.3 Strategic Technology Partnerships

We collaborate with UAE technology ecosystem while maintaining data privacy:

  • Partnerships aligned with national objectives
  • Technology transfer initiatives
  • Knowledge sharing with local entities
  • Support for UAE startup ecosystem
  • Collaboration with academic institutions

21. Language

This Policy is provided in English and may be translated into Arabic for accessibility. Where required by UAE law or IFZA regulations, Arabic translations will be provided. In case of any discrepancy between versions, the English version shall prevail unless otherwise required by UAE courts or regulatory authorities.

22. Updates

This Policy may be updated from time to time to reflect changes in accordance with applicable laws.

23. Acknowledgment

By using our Services, you acknowledge that you have read and understood this Privacy Policy and consent to the processing of your personal data as described herein, in accordance with UAE Data Protection Law and our commitment to responsible AI development.

We are proud to contribute to the UAE's vision of becoming a global leader in AI while maintaining the highest standards of data privacy and protection.