Privacy Policy
Our commitment to protecting your data, intellectual property, and rights across the GCC and globally.
Last updated: June 17, 2026
1. Introduction
This Privacy Policy explains how [COMPANY LEGAL NAME] (”Aia”, “we”, “us”) collects, uses, shares, and protects personal data when you use the Aia platform, AI agents, plugins, APIs, and website (the “Platform”). We serve users across the GCC and globally, and this Policy is designed to be compatible with applicable data protection laws across the Gulf Cooperation Council — including the UAE, Saudi Arabia, Bahrain, Qatar, Oman, and Kuwait — as well as the EU and UK GDPR and the California Consumer Privacy Act (CCPA/CPRA) for our international users. By using the Platform, you acknowledge this Policy.
2. Who We Are
The data controller is [OPERATOR LEGAL NAME], an individual or sole proprietor operating under the name “Aia”, of [ADDRESS]. The Platform is currently operated by this individual or proprietor; we intend to transfer controllership to a newly incorporated entity once established, and will update this Policy and notify you when that occurs. For privacy questions, contact us at [PRIVACY EMAIL]. Our data protection contact is [DPO / PRIVACY CONTACT NAME OR EMAIL].
3. Information We Collect
You provide:
• Account data — name, email, password, organization, billing details.
• User Content — prompts, instructions, code, files, and data you submit to build and run projects.
• Communications — support requests, feedback, survey responses.
Collected automatically:
• Usage data — features used, actions taken, AI agent and plugin activity, projects created, logs.
• Device and technical data — IP address, browser, device identifiers, operating system.
• Cookies and similar technologies — see Section 12.
From third parties:
• Payment data — processed by our payment provider; we receive limited confirmation and billing metadata, not full card numbers.
• Authentication / single sign-on — if you log in via a third-party provider.
• Connected plugins and integrations — data exchanged when you authorize a plugin.
• End-user data in your applications. Where you use the Platform to build or host applications that collect personal data from your own users or customers, you are the controller of that data and we process it on your behalf as your processor, under our Data Processing Addendum. This Policy describes our own processing as a controller and does not govern how you handle your end-users’ data.
4. How We Use Personal Data
- provide, operate, and maintain the Platform and its AI agents and plugins;
- generate, process, and deliver Output in response to your inputs;
- authenticate users, process payments, and manage accounts;
- secure the Platform, prevent abuse and fraud, and enforce our Terms;
- provide support and communicate with you about service, security, and (where permitted) marketing;
- analyze usage to maintain and improve the Platform; and
- comply with legal obligations.
5. AI Processing and Model Training
When you use the Platform, your inputs are sent to AI models — our own and/or third-party providers — to generate Output. This processing is necessary to deliver the service you request.
We do not use your User Content or prompts to train or fine-tune our own or third-party foundation models. Your User Content is used only to provide and operate the service for you, and is not used to train or improve models for other users. We retain AI interaction logs as described in Section 9 for security, debugging, abuse prevention, and service operation.
We pass inputs to the third-party AI providers listed in Section 7 only as needed to generate your Output, subject to their terms.
6. Legal Bases for Processing
Where the GCC data protection laws, GDPR, or UK GDPR apply, we process personal data on these bases: performance of a contract (to provide the Platform); legitimate interests (security, fraud prevention, and product improvement, where not overridden by your rights); consent (for certain cookies and marketing); and legal obligation (tax, accounting, and lawful requests). Where we rely on consent, you may withdraw it at any time without affecting prior processing.
7. How We Share Personal Data
We share personal data with:
• Service providers / sub-processors — cloud hosting, AI model providers, payment processors, analytics, customer support, and email tools, acting on our instructions under contract. A current list of sub-processors is available at [SUB-PROCESSOR LIST URL].
• Plugins and integrations you authorize — data is shared with a plugin only when you enable it.
• Legal and safety — to comply with law, respond to lawful requests, enforce our Terms, or protect rights, safety, and security.
• Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.
We do not sell your personal data, and we do not share it for cross-context behavioral advertising.
8. International Data Transfers
We and our providers may process personal data in countries other than yours, including outside the GCC, EEA, and UK. Where we transfer personal data internationally, we use appropriate safeguards required under the applicable law — such as Standard Contractual Clauses, adequacy or equivalent decisions, or the transfer mechanisms recognized under the relevant GCC data protection laws.
9. Data Retention
We retain personal data only as long as necessary for the purposes in this Policy. As a general rule, we retain account data for the life of your account and for up to [12] months after closure; AI interaction and security logs for up to [90] days; and billing records for the period required by applicable tax and accounting law. Backups may persist for up to [30] days after deletion. When personal data is no longer needed, we delete or anonymize it.
10. Security
We implement technical and organizational measures designed to protect personal data, including encryption in transit and at rest, access controls, and monitoring. No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal data, we will notify you and the relevant authorities where required by law.
11. Your Rights
Depending on your location, you may have the right to access, correct, delete, port, restrict, or object to the processing of your personal data, and to withdraw consent. These rights are available to users across the GCC under the applicable national data protection laws, to EU and UK users under GDPR, and to California residents under CCPA/CPRA (including the right to opt out of any “sale” or “sharing,” which we do not engage in, without discrimination). To exercise your rights, contact [PRIVACY EMAIL]. We will respond within the timeframe required by applicable law and may need to verify your identity. You may also lodge a complaint with the data protection authority in your jurisdiction, including the relevant GCC regulator.
12. Cookies and Tracking
We use cookies and similar technologies to keep you signed in, remember preferences, secure the Platform, and analyze usage. You can control cookies through your browser and, where applicable, through our cookie banner. Where required by law, we obtain consent before setting non-essential cookies.
13. Children
The Platform is not directed to children under 18, and we do not knowingly collect their personal data. If you believe a child has provided us personal data, contact us and we will delete it.
14. Changes to This Policy
We may update this Policy. We will post the new version with an updated date and, for material changes, provide additional notice. Continued use after the effective date constitutes acknowledgment.
15. Contact
Privacy questions or requests: [PRIVACY EMAIL] [COMPANY LEGAL NAME], [REGISTERED ADDRESS]