Shaffra AI Privacy Notice

Effective date: 15 September 2026

Contents13 sections

1. About Shaffra and this Privacy Notice

Shaffra Technology Labs Ltd and its applicable affiliates and entities are referred to in this Privacy Notice as “Shaffra,” “we,” “us” or “our.”

Shaffra develops enterprise artificial intelligence software that enables organisations to configure and deploy AI-powered digital workers, agents and business automation solutions. The Shaffra platform includes tools to build and configure AI employees, monitor their work and outputs, and enable individuals to interact with them through text, voice, avatar, telephone, email and supported messaging channels. Depending on the customer’s configuration, the platform may support human resources, recruitment, call-centre and customer-service operations, project management, sales, enterprise knowledge access, business analytics and related workflows.

Shaffra’s solutions may be deployed within infrastructure selected or controlled by the customer, including on-premises, sovereign-cloud or customer-cloud environments. Where Shaffra provides managed hosting, the provider and location are selected for the relevant deployment and may include approved infrastructure in the Kingdom of Saudi Arabia, Oman or Qatar. Current managed deployments include Google Cloud infrastructure in Dammam, Kingdom of Saudi Arabia, and approved local infrastructure in Oman and Qatar. Amazon Web Services is used separately to store static assets in Frankfurt, Germany and deliver them through a content delivery network.

This Privacy Notice explains how Shaffra collects, uses, stores, discloses and otherwise processes Personal Data in the following distinct contexts:

  • when individuals visit or interact with Shaffra’s website;
  • when Shaffra manages enquiries, customer accounts and other business relationships;
  • when Shaffra recruits employees, contractors or other personnel; and

when Shaffra provides hosted customer services.

This Notice also explains the distinction between circumstances in which Shaffra acts as a Data Controller and circumstances in which it acts as a Data Processor on behalf of a customer.

Shaffra is subject to the Data Protection Law, DIFC Law No. 5 of 2020, as amended or supplemented from time to time, referred to in this Notice as the “DIFC Data Protection Law.”

Where Personal Data processing takes place in, or relates to individuals residing in, the Kingdom of Saudi Arabia, Shaffra may also be subject to the Saudi Personal Data Protection Law issued under Royal Decree No. M/19 dated 9/2/1443H, as amended by Royal Decree No. M/148 dated 5/9/1444H, together with its Implementing Regulations and applicable supporting rules, referred to in this Notice as the “Saudi PDPL.”

Other privacy and data protection laws may apply depending on the location of the individual, the relevant customer and the processing activity.

In this Notice, “Personal Data” means information referring to an identified or identifiable natural person. References to “processing” include collecting, recording, organising, storing, accessing, using, disclosing, transferring, modifying, analysing, restricting, deleting and otherwise handling Personal Data.

2. Scope

This Privacy Notice applies to individuals whose Personal Data Shaffra processes in connection with its business activities, including:

  • visitors to our website;
  • individuals who contact us or request information about our products or services;
  • customers and authorised users of our services where Shaffra acts as Data Controller;
  • representatives of our customers, suppliers and business partners;
  • applicants for employment; and

any other individuals whose Personal Data we collect or process in accordance with this Privacy Notice.

Where Shaffra processes Personal Data solely on behalf of a customer, Shaffra acts as a Data Processor and the customer acts as the Data Controller. The customer determines the purposes, data categories, workflows and any decisions made using the platform and is responsible for providing the applicable privacy information to affected individuals. The sections of this Notice addressing customer deployments explain Shaffra’s role and processing in support of those customers.

3. Collection of Information

Information you give us

This is Personal Data you provide directly to us, including when you use our website, contact us by telephone, email or other electronic means, request information about our products or services, subscribe to newsletters or other communications, apply for employment, or otherwise interact with Shaffra.

If you contact us, we will keep an electronic record of our correspondence and any Personal Data you choose to provide so that we can respond to your enquiry, manage our relationship with you, or fulfil another legitimate business purpose.

Depending on how you interact with us, the Personal Data you provide may include your name, employer, job title, business or residential address, email address, telephone number, account credentials, photographs, curriculum vitae, employment history, qualifications, and any other information you choose to provide.

Where you apply for employment with Shaffra, we may also collect information relating to your professional experience, education, references, interview notes and, where relevant to the role, the results of recruitment assessments, including AI-assisted or psychometric assessments. Shaffra uses these assessments to support its own recruitment process and does not make legally or similarly significant employment decisions about its own applicants solely by automated means.

Our website, products and services collect and process Personal Data only for specific, lawful and transparent purposes in accordance with the DIFC Data Protection Law and other applicable laws. At the relevant point of collection, we indicate whether requested information is mandatory or voluntary and, where applicable, the possible consequences of not providing it.

Our website and services are not directed at children, and we do not knowingly collect Personal Data from children except where this is necessary for a specific lawful purpose and permitted by applicable law.

Information we collect about you and your device

When you visit our website, our website and supporting infrastructure may automatically process limited technical information necessary to deliver and secure the website, including:

  • your IP address, browser type and version, operating system, language settings, referring URL, requested pages, date and time of access, and limited diagnostic or security information generated when your device communicates with the website;
  • information contained in ordinary server, security and content-delivery request logs;

technical logs generated to maintain the security, availability and performance of our website and services.

We use this information to operate, maintain, improve and secure our website and online services.

Shaffra does not currently use cookies or similar tracking technologies on its public website, and Google Analytics is disabled. If Shaffra introduces any non-essential analytics, advertising or similar technology in the future, it will not be activated until any consent required by applicable law has been obtained. You will then be given clear information and an accessible mechanism to:

Accept non-essential technologies

Reject non-essential technologies

Manage or later withdraw your preferences

Other Information we may collect

Depending on your relationship with Shaffra, we may also collect Personal Data:

  • from publicly available business sources, such as company websites or professional networking platforms;
  • from your employer where you represent one of our customers, suppliers or business partners;
  • from recruitment agencies, referees or publicly available professional profiles during recruitment;

from authorised customer administrators where you are an authorised user of a customer deployment.

Where Shaffra provides hosted services to customers, the customer determines the Personal Data processed through its deployment and remains responsible for providing appropriate privacy information to the relevant individuals. Shaffra processes such Personal Data only on the customer's documented instructions where it acts as a Data Processor.

Depending on the customer’s configuration, Personal Data may be submitted to or collected through the Shaffra platform using customer-configured application interfaces and workflows; uploaded text, files or documents; websites, databases and application programming interfaces (APIs); approved customer-system integrations; telephone, email and supported messaging channels; and text, voice or avatar interactions. Customer administrators determine which approved information sources and organisational knowledge are made available to particular AI employees, teams or enterprise knowledge functions.

The categories of Personal Data processed through a customer deployment depend on the relevant use case. They may include names and contact details; account, authentication and technical log data; employee, applicant, customer, lead, project and business records; curriculum vitae, qualifications and interview responses; KPIs and performance information; documents and database records; written or spoken communications; messages, call content, audio recordings and transcripts; CRM, HRMS, support and workflow data; and routing or escalation information. Where necessary for a customer’s approved use case, this may include health information, psychometric information or other Special Categories of Personal Data.

The platform may also generate Personal Data from submitted information, including transcripts, summaries, classifications, extracted information, scores, rankings, competency or psychometric assessments, profiles, recommendations, draft communications, routing or escalation outcomes and other inferences. The customer determines the permitted sources, categories and purposes of this Processing and is responsible for ensuring that individuals receive appropriate information about the specific deployment.

4. Use of Personal Data

Shaffra processes your Personal Data on one or more of the following legal bases, as permitted by the DIFC Data Protection Law:

Consent – where you have given your consent for a specific purpose, such as receiving marketing communications or accepting non-essential cookies.

Performance of a Contract – where processing is necessary to take steps at your request before entering into a contract with you or to perform a contract to which you are a party.

Compliance with Legal Obligations – where processing is necessary to comply with applicable legal or regulatory obligations.

Legitimate Interests – where processing is necessary for Shaffra's legitimate business interests, provided those interests are not overridden by your rights and freedoms. Where we rely on our legitimate interests, those interests include operating and improving our Services, ensuring information security, preventing fraud, maintaining our business operations, developing and enhancing our AI technologies, responding to enquiries and protecting our legal rights, provided that such interests are not overridden by your rights and freedoms. Where Shaffra acts as Data Controller and processes Special Categories of Personal Data, it does so only where an applicable condition under Article 11 of the DIFC Data Protection Law has been established and documented, including where processing is necessary in the employment or recruitment context, based on explicit consent where appropriate, or necessary for the establishment, exercise or defence of legal claims.

We may use your Personal Data to:

  • operate, maintain and improve our website, products and services;
  • respond to enquiries, arrange demonstrations, prepare proposals and manage our relationship with prospective and existing customers;
  • create and administer customer accounts, authenticate authorised users and provide customer support;
  • provide, operate and maintain our enterprise AI solutions, including any optional managed hosting services requested by our customers;
  • communicate with you regarding our products, services, events, updates or other information that may be relevant to your relationship with Shaffra, where permitted by applicable law;
  • administer Shaffra’s own recruitment processes, assess applications, communicate with applicants and make recruitment decisions. Where AI-assisted or psychometric assessments are used by Shaffra for its own purposes, they support the recruitment process and are not used as the sole basis for legally or similarly significant employment decisions;
  • perform internal business administration, financial management, regulatory compliance, auditing, fraud prevention, dispute resolution and legal record keeping;
  • monitor, maintain and improve the security, availability and performance of our website, products and services;
  • develop, test and improve our products and services using information that has been anonymised or aggregated where appropriate; and

comply with applicable laws, regulations, legal processes and requests from competent authorities.

More specifically, where Shaffra acts as a Data Controller, we may collect and use Personal Data to manage customer and supplier relationships; administer customer accounts and authorised users; respond to enquiries and support requests; recruit and administer employees and contractors; conduct AI-assisted or psychometric recruitment assessments; manage payroll and employment obligations; protect our systems and investigate security incidents; respond to Data Subject requests; maintain regulatory, governance and business records; establish, exercise or defend legal claims; and operate, secure and improve our website and services.

Where the Shaffra platform is used on behalf of a customer, the customer determines the specific purposes for which Personal Data is collected and processed. Depending on the approved configuration, these may include: recruitment, interviewing, headhunting, employee enablement, KPI and performance management; inbound or outbound call-centre and customer-service operations, including health-request routing and escalation; project-management workflows involving employee, customer or project information; sales, CRM, lead and customer-interaction workflows; enterprise knowledge access; business analytics; and other customer-defined workflows. Shaffra processes such Personal Data only for the customer’s documented purposes and does not independently determine a new or unrelated purpose.

Where Shaffra provides managed hosting, the platform’s application workloads, AI processing, customer data, authentication and login services, databases and platform logs are hosted in the location approved for the relevant customer deployment.

Current locations may include: the Kingdom of Saudi Arabia, Oman and Qatar, using Google Cloud or other approved local or sovereign infrastructure. The specific provider and location are recorded for the deployment. Amazon Web Services is used separately for asset delivery: static assets such as images, videos and similar media are stored in Amazon S3 in Frankfurt, Germany and delivered through Amazon CloudFront. CloudFront may process limited technical information, such as IP addresses and request data, through distributed edge locations when delivering content. Limited Personal Data may also be processed through Google Workspace for business communications and collaboration.

5. Processing, Storage and Transfer of Personal Data

We take reasonable steps to ensure that your Personal Data is processed lawfully, fairly and transparently in accordance with the DIFC Data Protection Law, the Kingdom of Saudi Arabia's Personal Data Protection Law (where applicable), this Privacy Notice and any other applicable laws.

We process and store Personal Data only for as long as necessary to fulfil the purposes described in this Privacy Notice, comply with legal and regulatory obligations, resolve disputes and enforce our legal rights. Retention periods vary depending on the type of Personal Data and the purpose for which it was collected.

Where you request correction of inaccurate Personal Data or exercise another applicable data protection right, we will take reasonable steps to update, restrict or erase your Personal Data where required by law. We may retain certain information where continued retention is necessary to comply with legal obligations, establish or defend legal claims, or perform our contractual obligations.

Shaffra’s enterprise AI solutions may be deployed within a customer’s own on-premises, sovereign-cloud or customer-cloud environment. Where Shaffra provides managed hosting, the platform’s application workloads and customer data are hosted in the approved location for the relevant deployment, which may include the Kingdom of Saudi Arabia, Oman or Qatar. Static assets may be stored in Amazon S3 in Frankfurt, Germany and delivered through Amazon CloudFront.

For Personal Data processed by Shaffra as a Data Controller, we determine the purposes and means of processing in accordance with this Privacy Notice.

Where Shaffra provides services on behalf of a customer, including optional managed hosting, Shaffra generally acts as a Data Processor and processes Personal Data only on the documented instructions of the relevant customer. In those circumstances, the customer remains responsible for determining the purposes of processing and for providing any required privacy information to the individuals concerned.

Personal Data processed through customer deployments is not used to train Shaffra’s proprietary AI models, improve models for other customers, or for Shaffra’s own independent commercial purposes. If a customer requests a distinct training or fine-tuning activity involving Personal Data, the conditions described in section 5.2 apply. Where Shaffra uses AI-assisted or psychometric assessments in its own recruitment, meaningful human review forms part of the process and legally or similarly significant employment decisions are not based solely on automated processing.

Where Personal Data is transferred outside the jurisdiction in which it was collected, Shaffra implements appropriate safeguards in accordance with applicable data protection laws. Depending on the nature of the processing, these safeguards may include contractual commitments, the DIFC Standard Contractual Clauses or another recognised transfer mechanism, together with appropriate technical and organisational measures designed to protect Personal Data.

5.1 Cross-border data transfers from the Kingdom of Saudi Arabia

Current hosting and cross-border processing locations

Shaffra’s hosting and processing arrangements are configured for each customer deployment. Not every provider or location listed below applies to every customer. The relevant arrangement is determined by the customer’s requirements, the selected hosting model and the services enabled for that deployment.

Shaffra’s current hosting and cross-border processing arrangements may include:

Kingdom of Saudi Arabia: application workloads, AI processing, customer data, authentication services, databases and platform logs may be hosted using Google Cloud Platform in Dammam. Certain Saudi deployments may instead use approved Alibaba Cloud infrastructure located in the Kingdom. Customer environments for Bahrain-based customers, and certain proof-of-concept environments for Oman-based customers, may also be hosted on Google Cloud Platform in Dammam. In these circumstances, the processing location is the Kingdom of Saudi Arabia rather than the customer’s country of establishment.

Oman: production environments for relevant Oman deployments may be hosted using Oman Data Park infrastructure in Oman.

Qatar: relevant customer environments may be hosted using Ooredoo Cloud infrastructure in Qatar.

Germany: static assets, including applicable images, videos and similar media, may be stored using Amazon S3 in Frankfurt and delivered through Amazon CloudFront. CloudFront may process limited technical information, such as IP addresses and request data, through distributed edge locations when delivering content.

United States and other approved provider locations: limited Personal Data may be processed by approved artificial-intelligence, model-inference, communications, collaboration or integration providers where the relevant service is enabled for a particular deployment. The applicable provider and processing location are assessed and recorded before production use.

Limited Personal Data may also be processed through Google Workspace for Shaffra’s business communications and collaboration activities.

Before Personal Data is transferred internationally, Shaffra identifies the applicable provider, processing location, purpose and categories of Personal Data involved. Where required, Shaffra implements an appropriate transfer mechanism, which may include the DIFC Standard Contractual Clauses or another mechanism recognised under applicable law, together with appropriate contractual, technical and organisational safeguards. Transfers are limited to the Personal Data necessary for the relevant purpose.

Where Shaffra processes or stores Personal Data originating in, or relating to, individuals within the Kingdom of Saudi Arabia, any transfer or disclosure of such Personal Data outside the Kingdom will take place only where permitted under the Kingdom's Personal Data Protection Law (PDPL) and its Implementing Regulations.

For managed deployments using infrastructure in the Kingdom of Saudi Arabia, application workloads and customer data may be hosted on Google Cloud Platform in Dammam or another approved local environment. Static assets may be transferred to and stored in Amazon S3 in Frankfurt, Germany and delivered through Amazon CloudFront, which may use distributed edge locations. Depending on the services used, limited Personal Data may also be processed through Google Workspace for business communications and collaboration. Any other transfer from the Kingdom, including to a deployment-specific AI, speech, communications or integration provider, is assessed and recorded for the relevant deployment before production use.

Where an international transfer of Personal Data is required, Shaffra will ensure that appropriate safeguards are in place, including contractual transfer mechanisms recognised under applicable law and appropriate technical and organisational measures to protect Personal Data.

Any transfer will be limited to the Personal Data necessary for the relevant purpose and carried out only where permitted under applicable law.

5.2 Autonomous Processing

The Shaffra platform incorporates artificial intelligence technologies to deliver automation, analytics, communications and decision-support capabilities. It allows customers to configure AI employees and workflows; provide approved organisational knowledge; monitor conversations, outputs and reports; and make the functionality available through text, voice, avatar, telephone, email, messaging and connected business systems. Where the platform processes customer Personal Data, Shaffra acts as a Data Processor on the customer’s documented instructions.

AI processing may include:

  • analysing information submitted to the Service;
  • classifying or categorising data;
  • extracting information from documents and structured or unstructured content;
  • generating summaries, recommendations or proposed outputs;
  • supporting workflow automation and business process optimisation;
  • identifying patterns, trends or anomalies;
  • conducting assessments or generating insights based on the information provided; and

performing psychometric, behavioural or competency assessments where such functionality has been implemented by the relevant customer.

The degree of automation is determined by the customer’s configuration and instructions. Some customer deployments use AI only to assess, recommend, rank, route, draft or automate parts of a process while a person makes the final decision. Other customer deployments may be configured to carry out actions or decisions solely by automated means, including candidate shortlisting, rejection, interview approval or similar workflow outcomes. Shaffra does not determine those customer purposes or decisions.

Where a customer enables solely automated processing that produces legal effects or similarly significantly affects an individual, the customer, as Data Controller, is responsible for establishing a lawful basis and, where Special Categories of Personal Data are involved, an applicable Article 11 condition; giving the required notice, including meaningful information about the relevant logic, significance and possible outcomes; carrying out any required impact assessment; and implementing applicable safeguards and Data Subject rights. These include the right to object and require manual review, and may include the ability to express a point of view and contest the decision, as required by applicable law. Shaffra supports the customer in meeting those obligations in accordance with the parties’ contract and the customer’s documented instructions.

Personal Data processed on behalf of customers is not used to train or improve Shaffra’s proprietary models, models made available to other customers, or a provider’s general-purpose models. If a customer requests a distinct training or fine-tuning activity involving Personal Data, it will be undertaken only on the customer’s documented instructions, for a specifically defined purpose, and after the relevant Controller has established an applicable lawful basis, provided all required transparency, completed any necessary data protection impact assessment and implemented appropriate contractual and technical safeguards.

For customer deployments, the customer determines the purposes of processing, the categories of Personal Data, retention periods, permitted knowledge sources and integrations, the level of automation, and any decisions made using the platform. Shaffra processes the Personal Data only on the customer’s documented instructions and may provide authorised configuration, support, security monitoring, troubleshooting and service-quality review under access controls and confidentiality obligations.

Where Shaffra determines the purposes and means of AI processing for its own activities, it acts as Data Controller. This includes Shaffra’s use of the HR functionality for its own recruitment and workforce purposes. Shaffra may use AI-assisted or psychometric assessments for those purposes, but does not make legally or similarly significant decisions about its own applicants or personnel solely by automated means.

Shaffra AI maintains an AI governance framework designed to support responsible and trustworthy AI. This includes documented governance arrangements, risk management processes, human oversight appropriate to the level of risk, technical and organisational security measures, testing and validation activities where appropriate, and ongoing monitoring of AI systems throughout their lifecycle. Shaffra also maintains an Autonomous Systems Register covering its relevant Systems and use cases, including necessity and proportionality, access and correction, automation, recipients, lawful bases, contractual arrangements, processing locations and transfer safeguards. Relevant information from the register may be made available on request, subject to applicable confidentiality and legal restrictions.

We seek to ensure that AI processing remains proportionate, transparent, secure and consistent with applicable data protection and AI governance requirements, including Regulation 10 of the DIFC Data Protection Regulations where applicable.

6. Sharing of Personal Data

We may share your Personal Data as described in this Privacy Notice or as otherwise notified to you at the time of collection, but only where necessary for the relevant purpose and in accordance with applicable law.

Through our website and services

Where necessary to provide our website, products or services, we may share your Personal Data:

  • with service providers who support the operation, security, hosting and maintenance of our website, products and services;
  • with third parties where this is necessary to provide a service you have requested or where you have asked us to integrate with another system or service; or

with third parties where you have instructed or authorised us to do so.

Where Shaffra provides services on behalf of a customer as a Data Processor, Personal Data processed through the customer's deployment is processed only in accordance with that customer's documented instructions.

Other types of data sharing

We will only share your Personal Data where it is necessary for the purposes for which it was collected, where required by law, or where another lawful basis applies.

Any sharing of Personal Data will:

  • be limited to the minimum Personal Data reasonably necessary for the relevant purpose;
  • be carried out in accordance with applicable data protection laws; and

be subject to appropriate contractual, technical and organisational safeguards designed to protect your Personal Data.

We do not sell your Personal Data or disclose it to third parties for their own independent marketing purposes.

Where Shaffra engages third-party service providers, those providers are contractually required to process Personal Data only for the agreed purposes and to implement appropriate security and confidentiality measures.

Depending on the relevant Processing activity and the customer’s selected deployment, configuration and integrations, Personal Data may be made available to the following categories of recipients:

  • The relevant customer and its authorised users, where Personal Data is processed through a customer deployment, so that the customer can operate its approved workflow, review System outputs, provide services and make decisions for which it remains responsible;
  • Cloud hosting, storage, content-delivery, backup, security and infrastructure providers. For Shaffra-managed hosting, application workloads and customer data are hosted in the provider and location approved for the relevant deployment, which may include Google Cloud Platform in Dammam, Kingdom of Saudi Arabia, or approved local or sovereign infrastructure in Oman or Qatar. Amazon S3 in Frankfurt stores applicable static assets and Amazon CloudFront delivers them through distributed edge locations;
  • Approved artificial-intelligence, model-inference, speech-to-text, text-to-speech, video or similar technology providers where selected for the relevant deployment. The provider and processing location vary by deployment and may include services supplied by OpenAI, Google Vertex AI, ElevenLabs, Hamsa or SambaNova, as well as open-source models or Shaffra-developed text-to-speech capabilities hosted by Shaffra or within the customer’s environment;
  • Communications, messaging and integration providers, and customer-selected systems such as CRM, HRMS, support, project-management, calendar, telephony or database services, where needed to transmit communications, connect approved systems or deliver the configured workflow;
  • Suppliers, contractors and professional advisers, including legal advisers, auditors and insurers, where necessary to provide services to Shaffra, support our operations, comply with legal obligations or establish, exercise or defend legal claims;
  • Shaffra affiliates or group companies, where necessary for legitimate internal administration, service delivery, security or compliance;
  • Regulatory authorities, law-enforcement agencies, courts and other competent public authorities where disclosure is legally required. Shaffra has no standing arrangement to disclose platform Personal Data to a government or requesting authority; any request is assessed case by case in accordance with applicable law, contractual obligations and Shaffra’s privacy requirements; and

Prospective purchasers, investors and their professional advisers in connection with an actual or proposed merger, financing, restructuring, acquisition or sale, subject to appropriate confidentiality and data protection safeguards.

The particular providers, recipients and processing locations involved in a customer deployment depend on the services, hosting model, region, integrations and AI capabilities selected by the customer. This may include on-premises, sovereign-cloud or customer-cloud hosting. Shaffra requires relevant providers to process Personal Data only for authorised purposes and subject to appropriate contractual, confidentiality, security and international-transfer safeguards. The customer, as Controller, remains responsible for identifying any additional recipients involved in its use of the platform and providing appropriate information to affected individuals.

Government data sharing

Shaffra has no standing arrangement to disclose platform Personal Data to a government, requesting authority or public authority. Personal Data will be disclosed only where legally required or otherwise permitted by applicable law, and each request will be assessed case by case in accordance with applicable law, contractual obligations and Shaffra’s privacy requirements.

Before making such disclosures, we will take reasonable steps to satisfy ourselves that the request is lawful and that the disclosure is limited to what is required in the circumstances.

Where permitted by law, we may also disclose Personal Data in connection with the establishment, exercise or defence of legal claims, including the recovery of outstanding debts or the enforcement of contractual rights.

7. Your Rights and Choices

You have the following rights regarding your Personal Data, subject to the conditions and limitations set out in applicable law:

Right of Access

You have the right to request confirmation of whether we process your Personal Data and, where we do, to receive a copy of that Personal Data together with information about how it is processed.

Right to Rectification

You have the right to request that we correct inaccurate or incomplete Personal Data that we hold about you.

Right to Erasure

You may request that we erase your Personal Data where it is no longer necessary for the purpose for which it was collected, where you withdraw your consent (where consent is the lawful basis), or where applicable law otherwise requires us to erase it.

Right to Restrict Processing

You have the right to request that we restrict the processing of your Personal Data in circumstances permitted by applicable law, including while we consider a request to correct or object to processing.

Right to Object and Automated Decision Review

You have the right to object to the processing of your Personal Data where we rely on our legitimate interests as the lawful basis, including processing for direct marketing purposes. You also have the right to object to a decision based solely on automated processing, including profiling, that produces legal consequences or other seriously impactful consequences for you, and to require the decision to be reviewed manually, subject to the conditions and exceptions in applicable law.

Right to Data Portability

Where applicable, you may request a copy of the Personal Data you have provided to us in a structured, commonly used and machine-readable format, or request that it be transmitted to another controller where technically feasible.

Right to Withdraw Consent

Where we rely on your consent, you may withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing carried out before consent was withdrawn.

Right to Complain

If you believe that your Personal Data has been processed in breach of applicable data protection laws, you have the right to lodge a complaint with the DIFC Commissioner of Data Protection or another competent supervisory authority, where applicable.

To exercise any of these rights, please contact us at dpo@shaffra.com or through the contact form available on our website. We may ask you to verify your identity before responding to your request.

We will respond to access and correction requests without charge and within one month of receiving the request and any information reasonably required to verify your identity. If a request is particularly complex, or we receive numerous requests, we may extend this period by up to a further two months. We will notify you within the initial one-month period and explain the reason for the extension.

Where Shaffra processes Personal Data solely on behalf of a customer as a Data Processor, you should normally direct your request to that customer. Shaffra may refer the request to the customer and will assist it in responding in accordance with our contractual obligations. This includes assistance, where applicable, with requests relating to solely automated decisions, such as requests for human intervention, to express a point of view or to contest a decision.

As provided by Article 39 of the DIFC Data Protection Law, we will not discriminate against you for exercising your data protection rights except where permitted by applicable law.

Depending on the processing activity, we rely on one or more of the following lawful bases: performance of a contract, compliance with legal obligations, our legitimate interests, your consent where required, or the establishment, exercise or defence of legal claims.

Marketing and Preferences

Where permitted by applicable law, we may send you information about our products, services, events or other updates that we believe may be of interest to you.

You may opt out of receiving marketing communications at any time by following the unsubscribe instructions included in the communication or by contacting us using the details provided in this Privacy Notice.

Please note that even if you opt out of marketing communications, we may continue to send you administrative, transactional or service-related communications where necessary.

Shaffra does not currently use cookies or similar tracking technologies. If non-essential technologies are introduced in the future, you will be able to manage and withdraw your preferences as described in the Cookies section of this Privacy Notice.

8. Security

Shaffra is committed to protecting your Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

We have implemented appropriate technical and organisational measures designed to protect Personal Data, taking into account the nature of the information we process and the risks associated with that processing.

These measures include, where appropriate:

  • encryption of Personal Data in transit and, where appropriate, at rest;
  • role-based access controls and authentication mechanisms designed to limit access to authorised personnel;
  • monitoring, testing and periodic review of our security measures;
  • security awareness training for personnel with access to Personal Data;
  • procedures for detecting, investigating and responding to security incidents; and

appropriate contractual and security requirements for third-party service providers who process Personal Data on our behalf.

Where Shaffra provides optional managed hosting services, customer environments are protected using security measures appropriate to the nature of the hosted services and the applicable contractual arrangements.

Although we take reasonable steps to protect your Personal Data, no method of transmitting or storing information electronically can be guaranteed to be completely secure.

If a Personal Data Breach occurs, Shaffra will respond in accordance with applicable law and, where required, notify the relevant supervisory authority and affected individuals.

If you have any questions regarding how we protect your Personal Data, please contact us using the contact details provided in this Privacy Notice.

9. Cookies

A cookie is a small text file that is stored on your browser or device when you visit a website. Cookies help websites operate efficiently, remember your preferences and improve your browsing experience.

At the effective date of this Privacy Notice, Shaffra does not use cookies or similar tracking technologies on its public website. Google Analytics is disabled.

If this changes, we will update this Privacy Notice before enabling any non-essential technology.

Future use of non-essential technologies

Before any non-essential analytics, advertising or similar technology is activated, Shaffra will provide clear information about its provider, purpose and duration and will obtain consent where required by applicable law.

Where consent is required, the mechanism will allow you to accept, reject or manage non-essential technologies and to withdraw or change your choice as easily as it was given.

Our website may contain links to websites, applications or services operated by third parties ("External Sites"). These links are provided for your convenience only and do not imply that Shaffra endorses or is responsible for the content, products, services or privacy practices of those External Sites.

If you choose to access an External Site, you do so at your own risk. We encourage you to review the privacy notice and terms of use of any third-party website before providing your Personal Data.

Shaffra is not responsible for the privacy practices, security or content of External Sites and accepts no liability for any loss or damage arising from your use of them.

11. Buildings Security and Contents

Where you visit Shaffra's offices, we may collect limited Personal Data for building security and visitor management purposes. This may include your name, organisation, date and time of entry and departure, and other information required by building management or applicable security procedures.

Such information is processed for security, health and safety, business continuity and access control purposes, and is retained only for as long as necessary to fulfil those purposes or comply with applicable legal or regulatory obligations.

Shaffra is not responsible for personal belongings, documents or other items left on its premises.

12. Changes to this Privacy Notice

We may update this Privacy Notice from time to time to reflect changes to our business, services, processing activities, legal obligations or applicable data protection laws.

Where we make material changes, we will take appropriate steps to inform you, such as by publishing the updated Privacy Notice on our website or, where appropriate, notifying you by email or through another suitable communication channel.

The "Effective" date at the beginning of this Privacy Notice indicates when it was last updated. We encourage you to review this Privacy Notice periodically to remain informed about how we collect, use and protect your Personal Data.

This Privacy Notice is available through our website and may also be incorporated by reference into our agreements, contracts, end-user licence agreements and other documents where appropriate.

13. Contact Us

If you have any questions about this Privacy Notice, how Shaffra processes your Personal Data, or if you wish to exercise any of your data protection rights, please contact Shaffra Technology Labs Ltd at DIFC Innovation Hub, Dubai International Financial Centre, Dubai, United Arab Emirates, or contact our Data Protection Officer:

Email: dpo@shaffra.com

Shaffra has appointed a Data Protection Officer in accordance with Article 16 of the DIFC Data Protection Law. The Data Protection Officer can also be contacted through the contact form available on our website.

If you are not satisfied with our response, or believe that your Personal Data has been processed in breach of applicable data protection laws, you have the right to lodge a complaint with the DIFC Commissioner of Data Protection.

Dubai International Financial Centre Authority

Level 14, The Gate Building

Dubai International Financial Centre

Dubai, United Arab Emirates

Telephone: +971 4 362 2222

Email: commissioner@dp.difc.ae

Further information is available from the DIFC Commissioner of Data Protection.