Issued by: AI Digidot Limited
Registered at the Dubai International Financial Centre
License No. CL10599
Trading as: Aisfy
1. Introduction
This Privacy Policy explains how AI Digidot Limited (“we”, “our”, or “Aisfy”) collects, uses, stores, and protects personal data when users access the Aisfy platform. This policy aligns with:
Aisfy is committed to protecting the rights of data subjects and maintaining full transparency with respect to data processing activities. We adhere to the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality, and accountability.
2. Scope
This policy applies to all personal data collected and processed through the Aisfy platform, including through:
3. Types of Data Collected
Aisfy may process the following types of personal and operational data:
Note: Aisfy does not intentionally collect sensitive personal data (e.g. health, biometrics, national IDs), and users are advised not to upload such data unless explicitly agreed in writing.
Aisfy acts as a processor for user-uploaded content on behalf of enterprise clients, and will never use such content for training or analysis without explicit authorization.
Aisfy applies data minimization principles and collects only data necessary for the performance of services or as required by applicable law.
4. Legal Basis for Processing
Personal data is processed on one or more of the following legal bases:
Users may withdraw consent for integrations or optional features at any time. Users may withdraw consent at any time by accessing their account settings or contacting the DPO. Withdrawal does not affect the lawfulness of processing prior to the withdrawal.
5. Data Residency & International Transfers
Aisfy stores and processes data in secure data centers located in the UAE and the United States. For international data transfers outside the DIFC or UAE, the following safeguards are in place:
Aisfy clients are notified if data processing is required in new jurisdictions. Wherever possible, UAE residency is prioritized for regulated entities. For transfers to non-adequate jurisdictions (e.g. USA), Aisfy relies on Standard Contractual Clauses under Article 27(2)(c) of DIFC Data Protection Law No. 5 of 2020.
6. Security Measures
Aisfy implements enterprise-grade security protocols:
- Endpoint Device Controls: Access is restricted via device fingerprinting and activity-based session control.
- Third-Party Risk Reviews: All processors are vetted for ISO 27001 or equivalent compliance.
7. Data Subject Rights
Under DIFC, PDPL, and applicable international laws, users have the right to:
- Access their personal data
- Correct inaccurate or outdated data
- Request data erasure (right to be forgotten)
- Restrict or object to certain types of processing
- Data portability (where technically feasible)
Requests must be sent to: đź“§ compliance@aisfy.ai
Aisfy may require verification of identity before acting on a request.
We respond to all verified requests within 15 business days, unless lawfully extended. Data subjects also have the right to lodge a complaint with the DIFC Commissioner of Data Protection if they believe their rights have been violated.
8. Sub-Processors & Third-Party APIs
Aisfy uses carefully selected sub-processors with strict contractual safeguards. These include:
| Provider | Purpose | Retention | Region |
| Amazon Web Services | Hosting infrastructure | Configurable | UAE / US |
| OpenAI API | Language model processing | Stateless | US |
| Meta (Facebook/Instagram Graph API) | Content publishing | OAuth-based only | Global |
| Google Cloud APIs | Image generation & rendering | Transient prompts | UAE / US |
Aisfy does not resell or share user data with any third party unless required by law or explicitly authorized by the client. All publishing or external integrations require user consent.
9. Retention & Deletion Policy
Where required by law or pending legal/regulatory matters, data may be retained beyond the standard retention window in a secure, access-restricted archive.
10. Breach Notification & Incident Response
Aisfy maintains a structured breach response policy:
All breach notifications follow the 72-hour reporting window required under DIFC Law, unless a longer period is justified by forensic investigation protocols.
11. AI Workflow, Agent-Based Processing & System Notice (Final Compliant Version)
Aisfy incorporates AI-powered modules and custom agents to assist users in automating marketing, compliance, and operational workflows. These agents are activated based on user input and role-based access permissions, and operate within defined platform boundaries.
Use Cases
AI agents may support:
All actions taken by AI agents are initiated or reviewed by the user and are bound by account-level permissions.
AI System Notice
“This feature is powered by AI. Outputs are generated based on your inputs and system context. Please review and approve all content before publishing or acting. No fully automated decisions with legal or significant effects are made without human review.”
This notice appears in the platform UI wherever AI-driven features are used.
Human Oversight & Explainability
Transparency & Audit Logging
Data Categories Processed
Opt-Out & Customization
Model Governance & Third Parties
12. Children’s Privacy
Aisfy is not designed for individuals under the age of 18. If it becomes known that personal data has been submitted by a minor, the data will be deleted immediately.
13. Contact
Data Protection Officer: Kanwal Shahzad
AI Digidot Limited (DIFC License No. CL10599)
📍 DIFC AI Campus, Dubai, UAE
đź“§ compliance@aisfy.ai
14. Changes to This Policy
This policy may be updated from time to time to reflect platform changes or regulatory developments.
All updates will be posted on our website and, where applicable, notified to clients via email or in-app notification.

