Privacy Policy
Effective Date: January 1, 2025
Our Commitment to Privacy
At AALA AI, privacy isn't a feature—it's the foundation. We build AI systems that process your data without us ever seeing it. This privacy policy explains how we handle information, what we collect (and more importantly, what we don't), and your rights regarding data privacy.
Information We Don't Collect
When you deploy AALA AI systems, especially in on-premises configurations, we do not collect:
- Your business data processed by our AI systems
- Conversations between your team and AI
- Query content or results
- Your proprietary information or trade secrets
- Customer data you process through our systems
Information We Do Collect
To provide and improve our services, we collect limited information:
1. Contact Information
- Name, email address, phone number
- Company name and business address
- Job title and department
2. Service Usage Data
- Performance metrics (anonymized)
- Error logs (sanitized of sensitive content)
- Usage patterns (aggregated)
- Feature utilization statistics
3. Support Information
- Support tickets and correspondence
- Technical configuration details
- Feedback and suggestions
How We Use Information
The limited information we collect is used to:
- Provide and maintain our services
- Respond to support requests
- Improve system performance and reliability
- Develop new features based on usage patterns
- Ensure security and prevent fraud
- Comply with legal obligations
Data Storage and Security
We implement industry-leading security measures:
- AES-256 encryption for data at rest
- TLS 1.3 for data in transit
- Regular security audits and penetration testing
- Access controls and authentication protocols
- Secure data centers with physical security measures
Deployment-Specific Privacy
On-Premises Deployment
When you deploy AALA AI on your infrastructure:
- We have zero access to your data
- All processing happens within your security perimeter
- Telemetry is optional and can be completely disabled
- Your data never touches our servers
Cloud Deployment
For cloud deployments:
- Data encrypted with your keys
- Isolated compute environments
- Automatic data purging per your policies
- Geographic restrictions honored
Data Retention
We retain different types of data for specific periods:
- Support tickets: 90 days after resolution
- Error logs: 30 days
- Performance metrics: 365 days (anonymized)
- Your business data: Never stored by us
Your Rights
You have the right to:
- Access: Request copies of your personal information
- Rectification: Correct inaccurate information
- Erasure: Request deletion of your information
- Portability: Receive your data in a structured format
- Objection: Object to certain processing activities
- Restriction: Request limited processing of your data
International Data Transfers
We operate globally and may transfer information internationally. We ensure appropriate safeguards are in place:
- Standard contractual clauses approved by relevant authorities
- Adequacy decisions where applicable
- Your explicit consent when required
Compliance
We comply with data protection regulations in all jurisdictions where we operate:
- UAE: Federal Decree-Law No. 45 (ADPL)
- Europe: General Data Protection Regulation (GDPR)
- Malaysia: Personal Data Protection Act (PDPA)
- Pakistan: Local data protection regulations
- Singapore: Personal Data Protection Act
- Saudi Arabia: NDMO compliance
Children's Privacy
Our services are not directed to individuals under 18. We do not knowingly collect personal information from children.
Third-Party Services
We may use third-party services for:
- Payment processing (PCI DSS compliant)
- Email delivery (for transactional emails)
- Analytics (anonymized and aggregated)
These services have their own privacy policies and we recommend reviewing them.
Cookies and Tracking
Our website uses minimal cookies for:
- Session management
- Security purposes
- User preferences
We do not use tracking cookies or third-party advertising cookies.
Changes to This Policy
We may update this privacy policy periodically. Changes will be communicated 30 days in advance through:
- Email notification to registered users
- Prominent notice on our website
- In-product notifications where applicable
Contact Us
For privacy-related inquiries or to exercise your rights:
Privacy Officer
AALA AI
Email: [email protected]
Phone: +971 4 123 4567
For urgent privacy concerns, please mark your email as "URGENT - Privacy Matter" for expedited response.