Skip to the document
KINSEI LAB
WhoThesisMethodEverbird.aiContact
00 / ORIGIN--:--:--
Legal · Privacy

Privacy Policy

How Kinsei Lab collects, uses, shares, transfers and protects personal data across our websites and every product we operate. Written against the UAE Personal Data Protection Law, and against the EU, UK and United States rules that reach us because of who our customers are.

Effective
7 August 2026
Version
1.0
Jurisdiction
Sharjah, United Arab Emirates
Contents
  1. 01Identity and structure
  2. 02Collection
  3. 03Use and basis
  4. 04Group and product operations
  5. 05Sharing
  6. 06Cross-border
  7. 07Rights
  8. 08Site, security, closing
01 / IDENTITY

Identity and structure

Who is answerable for your data, which documents govern what, and where a request lands.

Section 1. 01About This Policy

This policy explains what Kinsei Lab does with personal data. It covers our own websites, the accounts and billing relationships we hold with customers, and the corporate relationships we hold with partners, suppliers and applicants.

It is written to be read rather than survived. Where a section carries a legal consequence — who answers a request, how long we keep something, where data physically sits — it says so plainly instead of gesturing at it.

Terms used here follow the UAE Personal Data Protection Law: a Data Subject is the person the data is about, a Controller decides why and how data is processed, and a Processor handles data on a Controller's instructions.

Section 2. 02Who We Are

Kinsei Lab is an independent product studio. We build and operate our own software products rather than delivering client projects, and each product is run by the same company under a shared operational and security model.

Products currently operated under this policy: Everbird.ai. New products are added to section 5 when they launch, and this policy applies to them from the day they do.

Section 3. 03Our Legal Entity and Registration Details

Kinsei Lab is the trading name of Kinsei Lab LLC, a company registered in Sharjah, United Arab Emirates with Sharjah Media City under commercial licence number 2645921.01.

Legal entity
Kinsei Lab LLC
Trading name
Kinsei Lab
Licensing authority
Sharjah Media City
Licence number
2645921.01
Tax registration
105482318000001
Registered address
Kinsei Lab, Sharjah Media City, Sharjah, United Arab Emirates

Any reference in this policy to “we”, “us” or “our” means that entity, unless a section names a different one.

Section 4. 04How This Policy Relates to Our Product Privacy Policies

This is the umbrella policy. Kinsei Lab LLC is the Controller of account data, billing data and corporate-relationship data across every product we operate — the identity you sign up with, the payment records, the support history, the contract. That does not change when you move between our products, and it does not change when a product publishes its own notice.

Each product also publishes a product-level privacy notice. That notice governs the data processed inside the product itself: the content you create, the files and records you upload, the messages the product sends on your behalf, and anything the product's own integrations pull in. It describes the mechanics of that product, and it can be more specific than this document because it is describing one system rather than all of them.

The division is deliberate and it decides who answers a request. A request about your account, your billing history, your marketing preferences or our corporate records is answered here, by us, under this policy. A request about the contents of a specific product workspace is answered under that product's notice — but it still reaches the same privacy contact in section 7, and we route it internally rather than sending you elsewhere.

Where the two documents genuinely conflict on a point about account, billing or corporate data, this policy governs. Where they conflict on a point about how a product internally handles the content inside it, the product notice governs. If you find a conflict we have not anticipated, tell us — that is a defect in the documents, not something you should have to resolve.

Section 5. 05Scope — Which Websites, Products and Services Are Covered

This policy applies to:

  • ▚Our marketing websites and any page served from a domain we operate.
  • ▚The account, sign-up, authentication and billing layer shared by our products: Everbird.ai.
  • ▚Support and other direct correspondence with us.
  • ▚Business relationships with partners, suppliers, contractors and prospective hires.

It does not apply to third-party sites we link to, to a customer's own end users where that customer is the Controller and we are only processing on their instructions, or to anything you send us through a channel we do not operate.

Section 6. 06Our Role: Controller, Processor, or Both

We are both, on different data, and the distinction changes who you go to.

Where we act as Controller — we decide why and how the data is processed, and we answer to you directly:

Account and identity data
The name, email address, credentials and profile you register with, across every product.
Billing and transaction data
Subscriptions, invoices, payment records, refunds and chargebacks.
Website and marketing data
Visits to our sites, enquiries, mailing-list subscriptions and analytics.
Corporate relationship data
Partners, suppliers, contractors and job applicants.
Support data
The correspondence you have with us and the records we keep of it.

Where we act as Processor — a customer decides why and how, and we act on their documented instructions:

Customer workspace content
The records, documents, contacts and messages a business customer puts into one of our products, including personal data about that customer's own clients and staff.

If you are an individual whose data was put into one of our products by a business that uses us, that business is the Controller. Your rights request goes to them first, and we support them in answering it. If you contact us directly we will tell you who the Controller is and, where we are permitted to, pass the request on rather than leaving it with you.

The same processing can move between the two roles. Security logs generated while running a customer's workspace, for example, are processed under our own responsibility as Controller because we — not the customer — decide that the platform needs them.

Section 7. 07Contact Details for Privacy Matters

Privacy questions, rights requests and complaints all go through one route — the contact form below — and it is read by a person rather than a queue that discards what it cannot classify.

If you would rather write on paper:

Entity
Kinsei Lab LLC
Post
Kinsei Lab, Sharjah Media City, Sharjah, United Arab Emirates

Please say which product or account the request concerns if you can. It is not required, and we will not refuse a request for leaving it out, but it shortens the identity check in section 42.

Section 8. 08Data Protection Officer or Privacy Contact

We have not appointed a formal Data Protection Officer.

The UAE Personal Data Protection Law requires one only where processing meets specific thresholds — high-risk processing arising from new technologies and the volume of data, large-scale processing of sensitive personal data, or systematic and comprehensive evaluation of it. The EU and UK GDPR set out equivalent thresholds. Our processing does not meet them: we do not collect sensitive personal data (section 16), and we do not profile you or make automated decisions with legal effect (section 26).

Saying so plainly is the point of this section. Privacy matters are handled directly by Kinsei Lab, and every request reaches a person through the contact route in section 7 — there is no unattended inbox and no requirement to address a request to a named officer for it to be valid.

If our processing changes such that an appointment becomes mandatory, we will appoint a Data Protection Officer, name them here, and record the change in the version history in section 53.

02 / DATA

Collection

What we actually collect, from whom, and how it reaches us.

Section 9. 09Information We Collect From Website Visitors

You can read our sites without telling us who you are. We do not require an account to browse, and we do not gate content behind a form.

What we collect from a visit:

  • ▚Technical data your browser sends: IP address, user agent, language, referring page and the pages you view.
  • ▚Anything you type into a contact form: name, email address, the subject you pick and the message itself.
  • ▚An email address, if you subscribe to updates.

Form submissions are stored so we can reply and so we have a record of what was asked. They are not used to build a profile of you, and we do not enrich them against third-party data brokers.

Section 10. 10Information We Collect From Customers of Our Products

When you hold an account with one of our products we collect:

  • ▚Identity and account data: name, email address, password credentials or federated sign-in identifiers, and any profile details you choose to add.
  • ▚Organisation data: company name, role, team members you invite, and the permissions you assign them.
  • ▚Configuration data: the settings, templates and integrations you set up.
  • ▚Usage data: which features you use and when, at the level needed to run the service, bill it correctly and see what is broken.
  • ▚Content data: the records, documents and messages you put into the product.

Content data is the category where we are usually the Processor rather than the Controller — see section 6. We do not read it to learn about you, and we do not mine it for marketing.

Section 11. 11Billing, Payment and Transaction Information

We collect what is needed to charge you correctly and to keep books that survive an audit: billing name, billing address, the country you are taxed in, any tax registration number you give us, the plan you are on, invoice history, payment status, refunds and chargebacks.

We do not collect or store full payment card numbers. Card details are entered directly into our payment provider's hosted fields and never reach our systems. What we receive back is a token, the card's brand, its last four digits and its expiry — enough to show you which card is on file and to take the next payment, and not enough to make a payment anywhere else.

Billing data sits with the parent entity rather than at product level, because the payment account is held there. Section 23 explains what that means for who you are contracting with.

Section 12. 12Information We Collect From Business Contacts and Partners

If you work for a supplier, partner, reseller or prospective customer, we hold your business contact details, your role, the correspondence between us, and the commercial records of the relationship — contracts, statements of work, purchase orders and invoices.

Where a relationship requires it we also collect the compliance data needed to enter into it: company registration details, beneficial-ownership information, tax and VAT registration, and bank details for payment.

Section 13. 13Information We Collect From Job Applicants

If you apply to work with us we collect your CV, the contact details and work history in it, anything you write in a covering note, your responses in interviews, and any work you send as part of an assessment.

We collect references only with your knowledge and only at the point where an offer is realistic. We do not contact a current employer without asking you first.

Retention for unsuccessful applications is in section 20. If you would rather we did not keep your details on file at all, say so and we will delete them at the end of the process instead.

Section 14. 14Information Collected Automatically

Some data is generated by the act of using the service rather than given to us deliberately:

  • ▚Server logs: IP address, timestamp, request path, response status and user agent.
  • ▚Security and audit events: sign-ins, failed sign-in attempts, permission changes and administrative actions.
  • ▚Diagnostic data: error traces and performance timings when something fails.
  • ▚Cookie and local-storage identifiers, described in section 45.

This data is the operational floor of running a service that is available, secure and debuggable. It is retained on short cycles — see section 20 — and it is not combined with content data to profile you.

Section 15. 15Information From Third-Party Sources

A limited amount of data reaches us from somewhere other than you:

  • ▚Federated sign-in providers, where you choose to sign in with an existing identity — we receive the identifier, name and email address that provider releases, and nothing further.
  • ▚Our payment provider, which tells us whether a payment succeeded, failed, was refunded or was disputed.
  • ▚Integrations you connect yourself, which return only the data the scopes you approved allow.
  • ▚Publicly available business information, where we are checking that a company we are about to contract with is real.
  • ▚Colleagues, where someone at your organisation invites you into a workspace and supplies your email address to do it.

We do not buy personal data from list brokers, and we do not enrich our records against commercial data-appending services.

Section 16. 16Sensitive Personal Data

We do not seek sensitive personal data — data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning a person's sex life or sexual orientation — and none of our products require it to work.

We ask you not to put sensitive data into free-text fields, support tickets or product content where it is not needed. Where a business customer chooses to process sensitive data inside a product, they do so as Controller and are responsible for having a lawful basis for it; our processing of it stays limited to what is needed to run the service for them.

If sensitive data reaches us unsolicited, we delete it unless we are legally required to keep it.

03 / PURPOSE

Use and basis

Why we process each category, what makes it lawful, and how long it stays.

Section 17. 17How We Use Personal Data

We use personal data to:

  • ▚Create and run your account, and authenticate you.
  • ▚Provide, maintain and improve the products you use.
  • ▚Charge you, issue invoices and receipts, and handle refunds and disputes.
  • ▚Answer support requests and keep a record of what was asked and answered.
  • ▚Send service messages: outages, security notices, billing failures, material changes to terms.
  • ▚Keep the platform secure — detect abuse, investigate incidents, and enforce our terms.
  • ▚Meet legal, tax, accounting and regulatory obligations.
  • ▚Understand how the products are used in aggregate, so we build the right things.
  • ▚Send marketing where you have asked for it or where we are permitted to, always with a working opt-out.
  • ▚Evaluate applications for roles and manage business relationships.

We do not use personal data to make decisions about you that produce legal or similarly significant effects without a human involved — see section 26.

Section 18. 18Lawful Basis for Processing

Under the UAE PDPL, processing is lawful where the data subject consents or where one of the specified exceptions applies. Under the GDPR and the UK GDPR, where those apply to us, one of the Article 6 bases must apply. We rely on the following, mapped to purpose:

Lawful basis by processing purpose
PurposeBasisNotes
Running your account and delivering the productPerformance of a contractWe cannot provide the service without it.
Billing, invoicing and collectionsPerformance of a contractStatutory record-keeping thereafter is a legal obligation.
Tax, accounting and statutory recordsLegal obligationFixed by UAE commercial and tax law — see section 24.
Security, abuse prevention and audit loggingLegitimate interestsBalanced against your interests; the data is minimal and short-lived.
Product analytics in aggregateLegitimate interestsAggregated, and not used to make decisions about individuals.
Non-essential cookies and web analyticsConsentWithdrawable at any time — see section 47.
Marketing to individualsConsentOpt-in, with an unsubscribe link on every message.
Marketing to existing business customersLegitimate interestsRelated products only, always with an opt-out.
RecruitmentSteps prior to entering a contractRetention beyond the process itself relies on consent.
Responding to legal processLegal obligationSee section 31.

Where we rely on legitimate interests we have considered whether the processing is necessary, whether a less intrusive route exists, and whether it would override your rights and expectations. You can ask us for the reasoning behind any specific balancing test.

Section 19. 19Consent and How to Withdraw It

Where we rely on consent, it is a positive action you take — ticking a box, clicking accept, subscribing. Silence, a pre-ticked box or continued use of a page is not consent, and we do not treat it as such.

You can withdraw consent at any time:

  • ▚Marketing: the unsubscribe link in any message, or your account's notification settings.
  • ▚Cookies and analytics: the cookie controls described in section 47.
  • ▚Anything else: the contact route in section 7.

Withdrawing consent is as easy as giving it, is free, and does not affect the lawfulness of what we processed before you withdrew. It also does not switch off processing that rests on a different basis — we will still bill you, still keep the statutory records, and still send the service messages you cannot opt out of while you hold an account.

Section 20. 20Retention Periods and Deletion

Retention is where most privacy policies stop being specific, and it is the area most commonly left undefined in UAE PDPL implementation — organisations document what they collect and never document when it goes. Ours is set out below as concrete periods.

Two things are kept deliberately separate. Statutory bookkeeping retention for a UAE entity is fixed by law and cannot be shortened by a deletion request. Product and account data is ours to define, and is set to the shortest period that still lets us run the service, resolve disputes and defend claims. Collapsing the two into one blanket line would either over-retain the product data or misstate the statutory obligation.

Retention periods by data category
CategoryWhat it coversHow longWhy
Statutory accounting and tax recordsInvoices, receipts, payment records, credit notes, and the ledgers and books they support5 years from the end of the relevant tax period; accounting books for 5 years from the end of the financial yearUAE Federal Tax Procedures Law and the Commercial Transactions Law — a legal obligation, not a choice
Corporate and contractual recordsSigned contracts, statements of work, purchase orders, supplier and partner agreementsDuration of the contract, then 6 yearsLegitimate interests — the limitation window for a contractual claim
Account and identity dataName, email, credentials, organisation and roleFor as long as the account is open, then 90 days after closurePerformance of a contract; the 90 days allows reactivation and dispute resolution
Product content dataRecords, documents, messages and files inside a workspaceFor as long as the account is open, then 30 days, then deletedProcessed on the customer's instructions; the window exists so an accidental closure is recoverable
BackupsEncrypted point-in-time copies of production dataRolling 35 days, then overwrittenLegitimate interests — disaster recovery. Deletion requests are applied to live systems immediately and take effect in backups as the cycle turns
Support correspondenceTickets, emails and the notes attached to them3 years from the last message in the threadLegitimate interests — continuity of support and evidence in a dispute
Security and audit logsSign-ins, permission changes, administrative actions12 monthsLegitimate interests — incident investigation
Server and diagnostic logsIP address, request path, error traces, performance timings30 daysLegitimate interests — operating and debugging the service
Marketing dataSubscription status, send and engagement historyUntil you unsubscribe, then a suppression record kept indefinitelyConsent. The suppression record exists so we do not re-add you, and holds only your email address
Website enquiry formsName, email, subject, message24 months from submissionLegitimate interests — following up and keeping a record of what was asked
Recruitment — unsuccessful applicantsCV, correspondence, interview notes, assessments6 months after the decision, or 12 months with your consentSteps prior to a contract; the longer period is consent-based and separately asked for
Cookie and consent recordsThe consent choice made and when12 monthsLegal obligation — demonstrating that consent was obtained

A deletion request cannot override a statutory retention period. Where you ask us to erase data we are legally required to keep, we restrict it instead — it is removed from active use, kept only for the statutory purpose, and deleted when the period expires. We will tell you which category this applied to and when it ends.

At the end of a period, data is deleted or irreversibly anonymised. Anonymised data — aggregate usage counts with no identifiers — may be kept indefinitely, because it is no longer personal data and cannot be turned back into it.

Section 21. 21Marketing Communications and Opt-Out

Marketing email goes only to people who asked for it, or to existing business customers about products related to what they already use. Every message carries a one-click unsubscribe that works without signing in and without a reason.

Service messages are different and cannot be opted out of while you hold an account: outages, security notices, billing failures, changes to terms. They are sent because you have a contract with us, not because you were marketed to, and they contain no promotion.

We do not sell or rent our mailing list, and we do not share it with anyone other than the provider that delivers the mail for us.

04 / GROUP

Group and product operations

How data moves between our products, who you pay, and what our automation does.

Section 22. 22Group Structure and Sharing Between Our Products

Kinsei Lab LLC operates every product under this policy. There is no separate operating company per product, which means the identity you register with is a single account across the studio rather than a fresh relationship each time.

What that means concretely — data that is shared across our products:

  • ▚Your account identity: name, email address and credentials. Signing into a second product uses the same identity, not a copy of it.
  • ▚Your billing relationship: one payer, one payment method on file, one invoice history, regardless of how many products you subscribe to.
  • ▚Support history: so you do not restate your situation to a second team.
  • ▚Security and abuse signals: an account suspended for abuse in one product is suspended across the studio.

What is not shared:

  • ▚Product content data. Records, documents and messages inside one product's workspace are not exposed to another product, and are not used to populate, train or enrich it.
  • ▚Product-specific configuration and integration credentials.
  • ▚Any data a customer has instructed us to process for a single product only.

We may tell you about another of our products — in-app, or by email if you are an existing customer and have not opted out. This is disclosed here rather than added later on purpose: retrofitting a cross-product marketing disclosure after the fact would require going back and obtaining fresh consent, which is worse for everyone. If you do not want it, the opt-out in section 21 covers it and takes effect across every product.

If we ever restructure — spinning a product into its own entity, or bringing another company in — section 32 governs what happens to your data, and we will tell you before it takes effect rather than after.

Section 23. 23Payments, Invoicing and Merchant of Record

The payment account is held by Kinsei Lab LLC, not by any individual product. That entity is the merchant of record: it is who you are contracting with for the purchase, whose name appears on your card statement, who issues the invoice, and who is answerable for a refund or a chargeback.

This matters for two practical reasons. First, if you dispute a charge, the dispute runs against the parent entity and is resolved there — you do not have to work out which product to raise it with. Second, the billing records that result from that dispute are held at the parent, under this policy, rather than in a product's own systems under its notice.

Card details go directly to our payment provider and never reach our servers. We receive a token, the card brand, its last four digits and its expiry. The provider is an independent Controller for its own fraud-prevention and regulatory-compliance processing, and its own privacy policy governs that — we cannot vary it and do not attempt to describe it here.

Where local tax rules require it, the invoice will show the tax registration and the tax charged. Tax data we collect for that purpose is used for it and for nothing else.

Section 24. 24Tax, Accounting and Statutory Record-Keeping

As a UAE-registered entity we are required to maintain accounting records, invoices and supporting documents for periods fixed by law. Those periods are in the retention table in section 20 and are stated separately from product retention because they are not ours to shorten.

Records held for this purpose are removed from operational use and kept for the statutory purpose alone. They are not used for marketing, analytics or product decisions, and access to them is limited to the people who need it for accounting, audit or a regulator's request.

Section 25. 25Customer Support and Communications

When you contact support we hold the correspondence, the account it relates to and any diagnostic detail you send us. Support staff can see account and billing data. Access to the content inside your workspace is restricted, logged, and used only where it is necessary to resolve the specific issue you raised.

We may quote a support exchange internally to fix the underlying problem. We do not publish it, and we do not use it in marketing without asking you first.

Section 26. 26Automated Processing and AI in Our Products

Some of our products use automated processing, including AI models, to do work inside your own workspace — drafting a message, summarising a thread, spotting that something has stalled and suggesting a follow-up. This is disclosed rather than buried because it is a core mechanic of what we build, not an incidental feature.

The limits we hold ourselves to:

  • ▚Your content is not used to train general-purpose models, ours or anyone else's.
  • ▚Where a third-party model provider processes your content to return a result, it does so as our Processor, under contract, without rights to retain or train on it.
  • ▚Automated output that acts outward — an email sent on your behalf, for example — is under your control: you decide whether it sends, and you can turn the automation off.
  • ▚We do not use automated processing to make decisions about you that produce legal or similarly significant effects without human involvement.

Where we operate automated checks on our own account — fraud and abuse detection, for example — a positive signal is reviewed by a person before an account is suspended, and you can contest the outcome by contacting the privacy contact in section 7.

05 / SHARING

Sharing

Who else sees your data, on what terms, and what we will never do.

Section 27. 27Who We Share Personal Data With

Categories of recipient
RecipientWhat they receiveWhy
Cloud infrastructure and hosting providersAll hosted data, encrypted at restRunning the service
Payment providerBilling identity, transaction data, card tokenTaking payment, handling refunds and disputes
Email delivery providerEmail address, message contentSending service and marketing mail
Analytics providerPseudonymised usage eventsUnderstanding how the products are used
AI model providerThe specific content submitted for a taskReturning the result you asked for
Support toolingCorrespondence and account identifiersHandling your requests
Professional advisersWhatever a specific matter requiresLegal, accounting and audit work
AuthoritiesWhatever is lawfully requiredLegal process — see section 31

This is the shape of our supplier set. A current, named list of sub-processors is available on request from the privacy contact in section 7, and material additions are notified before they take effect.

We do not share personal data with anyone outside these categories, and we do not disclose it to advertisers or data brokers in any form.

Section 28. 28Service Providers and Processors

Every provider that handles personal data on our behalf does so under a written contract that binds them to process only on our instructions, to keep it confidential, to apply appropriate security measures, to engage sub-processors only with our permission, to help us answer rights requests, and to delete or return the data when the engagement ends.

We assess a provider's security and privacy posture before engaging them and reassess it while the engagement runs. Where a provider processes data outside the UAE, sections 35 and 36 govern the transfer.

Section 29. 29Payment Providers

Our payment provider processes card and transaction data. For the parts of that processing it performs on our instructions it acts as our Processor. For its own fraud prevention, anti-money-laundering and regulatory compliance it acts as an independent Controller under its own privacy policy, which we cannot vary.

We receive from it only what we need to run billing: whether a payment succeeded, the token and last four digits of the card, and the details of any refund or dispute.

Section 30. 30Professional Advisers and Auditors

Lawyers, accountants, auditors, tax advisers and insurers see personal data where a specific matter requires it — a filing, an audit, a claim, a transaction. They are bound by professional confidentiality obligations as well as by contract, and they receive only the data the matter needs.

Section 31. 31Legal, Regulatory and Law Enforcement Disclosures

We disclose personal data to a court, regulator or law enforcement body where we are legally required to, or where it is necessary to establish, exercise or defend a legal claim.

How we handle a request:

  • ▚We check that it is valid, that it comes from an authority with jurisdiction over us, and that it is served through the correct legal channel.
  • ▚We disclose the minimum the request actually compels, and we push back on requests that are broader than their legal basis.
  • ▚Where a business customer's data is involved and we are permitted to, we refer the requester to that customer rather than disclosing on their behalf.
  • ▚We notify you before disclosing, unless we are legally prohibited from doing so or notification would defeat the purpose of a lawful investigation.

Section 32. 32Corporate Transactions and Business Transfers

If we are acquired, merge, restructure, or sell part of the business, personal data may transfer to the acquiring or successor entity as part of the assets. Data shared during due diligence is limited, minimised, and covered by confidentiality obligations.

Any successor is bound by this policy in respect of the data it receives until it lawfully gives you notice of a different one. We will tell you before a transfer takes effect, not after, and where the change would materially affect how your data is handled you will be able to close your account and have it deleted first.

Section 33. 33We Do Not Sell Personal Data

We do not sell personal data. We do not rent, trade or otherwise disclose it to a third party for that party's own commercial purposes.

We also do not “share” personal data for cross-context behavioural advertising, in the specific sense that term carries under United States state privacy laws. We do not run advertising networks or advertising pixels on our sites, and there is no advertising identifier to sell.

This is a statement of practice, not of intent. If it ever changes, it changes here first, with notice, and with a working opt-out before any such disclosure begins.

06 / TRANSFERS

Cross-border

Where your data physically is, how it leaves the UAE, and what protects it when it does.

Section 34. 34Where Your Data Is Processed

We are established in Sharjah, United Arab Emirates. Our infrastructure and several of our providers are not, so personal data is processed outside the UAE as a matter of ordinary operation rather than as an exception.

Where processing takes place
ProcessingLocation
Our own operations and staff accessUnited Arab Emirates
Application hosting, databases and backupsProvider regions outside the UAE, primarily in the European Union and the United States
Payment processingPayment provider's regions, primarily the United States and the European Union
Email deliveryProvider regions, primarily the United States and the European Union
AI model inferenceProvider regions, primarily the United States

Specific regions per provider are available on request from the privacy contact in section 7.

Section 35. 35International Transfers Out of the UAE

Personal data we hold is transferred out of the UAE. This is a live disclosure, not a theoretical one: our hosting and our payment processing both sit outside the country, which means essentially every record described in this policy crosses a border at some point in its life.

The UAE PDPL permits a cross-border transfer where the destination provides an adequate level of protection — because it is recognised as adequate, or because it is bound by a bilateral or multilateral agreement the UAE is party to. Where no such adequacy exists, a transfer is still permitted where appropriate contractual safeguards are in place, where you have given explicit consent, where the transfer is necessary to perform a contract with you or one made in your interest, where it is necessary for a legal claim, or where it is necessary to protect a vital interest.

Our transfers rest on two of those routes. Transfers necessary to deliver the service you have contracted for — hosting your workspace, taking your payment, sending your mail — are made on the contractual-necessity basis, because the service cannot be provided without them. Every other transfer is made under the contractual safeguards described in section 36.

We do not treat consent as the primary route for infrastructure transfers. Consent that you cannot realistically refuse without losing the service is not meaningful consent, and building the architecture on it would be a worse protection than the contractual one.

Section 36. 36Transfer Safeguards and Adequacy

The safeguards applied to every transfer:

  • ▚A written data processing agreement with each recipient, binding it to process only on our instructions and to maintain security measures at least equivalent to ours.
  • ▚Standard contractual clauses, or the recipient's equivalent transfer mechanism, where the destination is not covered by an adequacy recognition.
  • ▚A transfer assessment before engagement, covering the destination's legal regime, the recipient's exposure to government access requests, and the practical and technical measures that mitigate it.
  • ▚Encryption in transit and at rest, so that data intercepted in the course of a transfer is unreadable.
  • ▚Contractual commitments requiring the recipient to notify us of any legally binding request for disclosure, to the extent it is permitted to.

Where a destination is later recognised as adequate by the UAE Data Office, we rely on that recognition and the contractual safeguards remain in place alongside it. Where an adequacy recognition or transfer mechanism we rely on is invalidated, we reassess the transfer and either move the processing or suspend it — we do not continue on a mechanism that no longer stands.

You can ask us for a description of the safeguards applying to a specific transfer, and we will provide it.

Section 37. 37Compliance With Non-UAE Privacy Laws

The UAE PDPL reaches beyond the UAE's borders: it applies to a controller or processor outside the country that processes the personal data of people inside it. The same logic runs the other way at us, and we treat it as applying rather than arguing about it.

A Sharjah-registered entity selling to customers in the European Union, the United Kingdom and the United States inherits obligations under each of those regimes regardless of where it is registered, because those laws attach to who we target and whose data we process rather than to where our licence was issued.

So, in addition to the PDPL, we operate to:

  • ▚The EU General Data Protection Regulation, where we offer services to or monitor the behaviour of people in the EEA.
  • ▚The UK GDPR and the Data Protection Act 2018, where we offer services to or monitor the behaviour of people in the UK.
  • ▚United States state privacy laws, including the California Consumer Privacy Act as amended, where we meet their applicability thresholds.

Sections 39 and 40 set out the additional rights those regimes give you. Where two regimes apply to the same processing we apply the higher standard rather than the more convenient one.

07 / RIGHTS

Rights

What you can require of us, how to ask, and what happens if we fail.

Section 38. 38Your Rights Under the UAE PDPL

As a data subject under the UAE Personal Data Protection Law you have the right to:

Access and information
Obtain confirmation of whether we process your data, a copy of it, and information about the purposes, recipients, retention and safeguards involved.
Data portability
Receive the data you provided in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
Rectification
Have inaccurate data corrected and incomplete data completed.
Erasure
Have your data deleted, subject to the statutory retention limits in section 20.
Restriction of processing
Require us to limit processing while a dispute about accuracy or lawfulness is resolved.
Object to processing
Object to processing carried out for direct marketing, for statistical purposes, or on the basis of legitimate interests.
Object to automated decisions
Not be subject to a decision based solely on automated processing that produces a legal or similarly significant effect, and to require human review.
Withdraw consent
Withdraw consent at any time where processing rests on it, without affecting what was lawful before.
Complain
File a complaint with us and, if unsatisfied, escalate to the UAE Data Office — see section 44.

Exercising a right is free. We will not charge you, and we will not degrade your service because you used one.

Section 39. 39Additional Rights for Individuals in the EEA and UK

Where the GDPR or UK GDPR applies to our processing, you hold the rights in section 38 under those regimes as well, together with:

  • ▚The right to be told the lawful basis for a specific processing operation, and the legitimate-interests reasoning where that is the basis.
  • ▚The right to object to processing based on legitimate interests on grounds relating to your particular situation, and an absolute right to object to direct marketing.
  • ▚The right to lodge a complaint with your local supervisory authority, in addition to complaining to us.
  • ▚The right to be informed of a personal data breach likely to result in a high risk to your rights and freedoms.

We have no establishment in the EEA or the UK. Where an Article 27 representative is required for our processing, we will appoint one and name them here.

Section 40. 40Additional Rights for Individuals in the United States

Where a United States state privacy law applies to our processing of your data, you have the right to know what we collect and why, to access and obtain a copy of it, to correct it, to delete it, and not to be discriminated against for exercising any of those rights.

You also have the right to opt out of the sale of personal information and of sharing it for cross-context behavioural advertising. As stated in section 33 we do neither, so there is nothing to opt out of — but if that ever changes we will provide the mechanism before any such disclosure begins.

We do not use or disclose sensitive personal information for purposes beyond those permitted without a limitation right, because we do not collect it in the first place (section 16).

You may use an authorised agent to make a request on your behalf. We will ask for proof of authorisation and, where the law permits, for you to confirm the agent's authority directly.

Section 41. 41How to Exercise Your Rights

Send your request through the contact form:

Or on paper, to Kinsei Lab LLC:

Post
Kinsei Lab, Sharjah Media City, Sharjah, United Arab Emirates

It helps if you say:

  • ▚Which right you are exercising, in whatever words you like — you do not need to cite an article.
  • ▚Which account or product it concerns, if more than one could apply.
  • ▚The email address on the account, so we can match the request to it.

There is no template you have to follow and no legal wording you have to get right. If a request is unclear we will ask, and the clock in section 43 pauses only for as long as it takes you to answer.

If the data is inside a workspace belonging to a business customer, we are the Processor and they are the Controller (section 6). We will tell you who they are and, where permitted, forward the request rather than closing it.

Section 42. 42Identity Verification for Requests

We verify identity before acting on a request, because disclosing or deleting someone's data on an impostor's say-so is itself a breach.

Normally this means replying from the email address on the account, or confirming a detail only the account holder would know. We ask for identity documents only where the request is high-risk and no other route works, and we delete any document sent for this purpose as soon as verification is complete.

If we genuinely cannot verify who you are, we will say so and explain what would satisfy us, rather than ignoring the request.

Section 43. 43Response Timelines

How long we take
StageTimeline
Acknowledgement of a requestWithin 5 business days
Substantive responseWithin 30 days of a verified request
Extension where a request is complexA further 30 days, with reasons given before the first period expires
Notification of a decision to refuseWithin the same period, with the reason and how to challenge it

We may refuse a request that is manifestly unfounded or excessive, particularly if it repeats one we have already answered. If we do, we will say why, and tell you how to complain to the supervisory authority.

Section 44. 44Complaints and Escalation to the UAE Data Office

Complain to us first, through the contact route in section 7. It is the fastest way to resolve it, and most complaints are about something we can simply fix.

If you are not satisfied with our response, or we fail to respond within the period in section 43, you can file a complaint with the UAE Data Office, the supervisory authority established under UAE federal law to oversee the Personal Data Protection Law.

Complaining to us is not a precondition of complaining to the Data Office, and you can go to them directly. If you are in the EEA or the UK you can also complain to your local supervisory authority; if you are in a United States state with its own privacy law, to that state's Attorney General or privacy agency.

08 / SECURITY

Site, security, closing

Cookies, how we protect what we hold, what happens when something goes wrong, and how this document changes.

Section 45. 45Cookies and Tracking Technologies

Cookie categories
CategoryPurposeConsent
Strictly necessaryAuthentication, session integrity, security and load balancingNot required — the site cannot work without them
PreferenceRemembering choices such as a dismissed bannerNot required where set at your request
AnalyticsUnderstanding how pages are used in aggregateRequired, and withdrawable

We set no advertising cookies, run no advertising pixels, and participate in no cross-site tracking network.

Local storage and similar technologies are treated as cookies for the purposes of this section — what matters is that something is stored on your device, not the API used to store it.

Section 46. 46Analytics on Our Websites

We use analytics to see which pages are read and where people give up, so we can fix the second. It is configured to minimise what it collects: IP addresses are truncated or not stored, no cross-site identifier is set, and no data is used for advertising.

Analytics runs on consent. Declining it costs you nothing — the site behaves identically — and we would rather have a smaller, honest picture than a complete one obtained by not asking.

Section 47. 47Managing Your Cookie Preferences

You can control cookies in three places:

  • ▚The cookie controls on our site, which let you accept or decline non-essential categories and change your mind later.
  • ▚Your browser settings, which can block or delete cookies for any site.
  • ▚Your device or browser's global privacy control signal, which we honour as an opt-out where the applicable law recognises it.

Blocking strictly necessary cookies will break sign-in — there is no way for us to keep you authenticated without them.

Section 48. 48Security Measures

The measures we apply:

  • ▚Encryption in transit using current TLS, and encryption at rest for stored data and backups.
  • ▚Access control on least privilege, with multi-factor authentication required for administrative access.
  • ▚Audit logging of administrative actions and permission changes.
  • ▚Separation of production from development, with no production personal data in development environments.
  • ▚Dependency and vulnerability monitoring, with patching prioritised by severity.
  • ▚Encrypted, tested backups on the cycle in section 20.
  • ▚Contractual and technical review of every provider that handles personal data.

No system is perfectly secure, and a policy that claimed otherwise would be lying. What we commit to is that these measures are real, that they are reviewed, and that a failure of them is disclosed under section 49 rather than absorbed quietly.

Section 49. 49Personal Data Breach Notification

We maintain an incident process covering detection, containment, assessment, notification and remediation. Every incident is recorded whether or not it turns out to be notifiable.

Where a personal data breach occurs:

  • ▚We notify the UAE Data Office without undue delay where the breach would prejudice the privacy, confidentiality or security of the data.
  • ▚Where the GDPR or UK GDPR applies, we notify the relevant supervisory authority within 72 hours of becoming aware, unless the breach is unlikely to result in a risk.
  • ▚We notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights.
  • ▚Where we are a Processor, we notify the Controller without undue delay so they can meet their own obligations.

A notification will describe what happened, what data was involved, what we assess the likely consequences to be, what we have done about it, and what you may want to do. It will not be written to minimise.

Section 50. 50Children's Data

Our products are business tools. They are not directed at children, and we do not knowingly collect personal data from anyone under 18.

If we learn that we hold data from a child without appropriate consent from a holder of parental responsibility, we delete it. If you believe a child has given us data, contact the privacy contact in section 7 and we will act on it.

Section 51. 51Third-Party Websites and Links

Our sites and products link out to third-party websites, and some products connect to third-party services at your instruction. Those services are operated by other organisations under their own privacy policies, and this policy does not govern them.

Connecting an integration authorises a flow of data between that service and ours within the scopes you approve. You can revoke it at any time, from our side or theirs. We are responsible for what we do with the data we receive; we are not responsible for what that service does with the data it holds.

Section 52. 52Changes to This Policy

We update this policy when our processing changes, when we add a product, when a provider handling personal data changes, or when the law does.

Material changes — a new purpose, a new category of recipient, a new transfer, a longer retention period — are notified by email to account holders and posted on this page before they take effect. Non-material changes such as clarified wording are made with the version and date updated, and recorded in section 53.

Where a change requires your consent, we will ask for it. We will not treat continued use of the service as consent to something we did not tell you about.

Section 53. 53Effective Date and Version History

Version history
VersionDateChange
1.07 August 2026First published.

This policy is effective from 7 August 2026. It is published in English; where it is translated, the English text governs in the event of a discrepancy.

Questions about any of this

Privacy questions, rights requests and complaints all go through the form below, and a person reads them. If you would rather write on paper, the registered address is in section 41.

© 2026 Kinsei Lab —independent, and staying that way.
TermsMethodEverbird.aiTop ↑