Introduction
This Privacy Policy (the “Policy”) is issued by CERTYTECH AI LIMITED (“CERTY”, “We”, “Us” or “Our”), a company incorporated in the Dubai International Financial Centre (“DIFC”), and governs the collection, use, processing, and disclosure of personal data in connection with the use of CERTY’s web-based platform, software solutions, and related services (the “Platform”).
CERTYTECH AI LIMITED is a registered company under the laws of the Dubai International Financial Centre (DIFC) with its commercial license number CL9918, having its registered address at Level 1 of the Innovation Hub, DIFC, Dubai, United Arab Emirates.
CERTY is committed to ensuring that all personal data is processed in accordance with applicable data protection laws, including DIFC Law No. 5 of 2020 (the DIFC Data Protection Law), the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL), and, where applicable, the General Data Protection Regulation (EU) 2016/679 (GDPR) (collectively, the “Applicable Data Protection Laws”).
For the purposes of this Policy, “You” refers to any natural person acting on behalf of a corporate entity, including employees, representatives, agents, or counterparties of CERTY’s clients and partners, whose personal data may be processed in connection with the use of the Platform.
CERTY acts as a data controller in respect of personal data processed in connection with the Platform and associated services.
1. Collection and use of personal data
CERTY collects and processes personal data strictly to the extent necessary to provide its services and operate its Platform within a business-to-business context. Such data may include identifying information, professional contact details, corporate affiliation, and other information required to enable access to the Platform, manage client relationships, and facilitate the provision of services.
In addition, CERTY may collect technical and usage-related data, including but not limited to internet protocol (IP) addresses, browser types, system configuration, access logs, and interaction data generated through the use of the Platform. CERTY may also process data relating to transactions, counterparties, and financial or operational activities, to the extent such data contains or relates to identifiable individuals.
CERTY processes personal data for the purposes of providing its services, including but not limited to the delivery of credit intelligence, risk analytics, and financial insights; facilitating interactions between users, financial institutions, and counterparties; maintaining and improving the functionality, security, and performance of the Platform; responding to user inquiries and support requests; and ensuring compliance with legal and regulatory obligations.
Processing of personal data is carried out on the basis of one or more lawful grounds, including where such processing is necessary for the performance of a contract, compliance with legal obligations, the legitimate interests pursued by CERTY, or, where required, the consent of the data subject.
2. Disclosure of personal data
CERTY may disclose personal data to third parties where such disclosure is necessary for the purposes described in this Policy or otherwise permitted by Applicable Data Protection Laws.
Such third parties may include service providers engaged by CERTY for the purposes of hosting, maintaining, and securing the Platform; financial institutions and commercial partners involved in the provision of services or execution of transactions; and professional advisors, including legal, financial, and compliance consultants.
CERTY may also disclose personal data to regulatory authorities, law enforcement bodies, or other competent authorities where required by applicable law, regulation, or legal process, or where such disclosure is necessary to protect CERTY’s legal rights or the rights of third parties.
In the event of a corporate transaction, including a merger, acquisition, or sale of assets, personal data may be transferred to relevant third parties, subject to appropriate confidentiality safeguards.
3. International Transfers
Given the global nature of CERTY’s operations and partnerships, personal data may be transferred to and processed in jurisdictions outside of the DIFC and the United Arab Emirates.
Where such transfers occur, CERTY ensures that appropriate safeguards are implemented in accordance with the DIFC Data Protection Law and the UAE PDPL, including the use of contractual protections, standard data protection clauses, or reliance on adequacy determinations where applicable.
4. Data Retention
CERTY retains personal data only for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying legal, regulatory, accounting, or reporting requirements.
Personal data may be retained for longer periods where required to comply with applicable laws, including retention obligations under commercial, tax, or financial regulations, or where necessary for the establishment, exercise, or defense of legal claims.
Where personal data is no longer required, CERTY will take reasonable steps to ensure that such data is securely deleted or anonymized.
5. Profiling and Automated Processing
CERTY may use advanced analytical tools, including artificial intelligence and machine learning models, to process data for the purposes of generating insights, including credit risk assessments, behavioural analysis, and predictive analytics.
Such processing may involve profiling techniques based on aggregated datasets and operational indicators. However, such profiling is used solely to support business decision-making processes and does not produce legal or similarly significant effects on individuals without appropriate human oversight.
CERTY implements appropriate safeguards to ensure that such processing is fair, transparent, and compliant with Applicable Data Protection Laws.
7. Data Subject Rights
Subject to Applicable Data Protection Laws, You have the right to request access to your personal data, request rectification or erasure of such data, restrict or object to its processing, and request data portability.
Where processing is based on consent, You have the right to withdraw such consent at any time, without affecting the lawfulness of processing carried out prior to such withdrawal.
Requests to exercise these rights may be submitted to CERTY using the contact details provided below. CERTY reserves the right to verify the identity of the requester prior to responding to any such request.
8. Updates to this Policy
CERTY reserves the right to amend or update this Policy at any time to reflect changes in its practices, legal requirements, or operational needs.
Any material changes will be communicated through appropriate channels, including the Platform or via electronic communication.
9. Contact
For any questions, requests, or concerns regarding this Policy or the processing of personal data, You may contact CERTY at michel@gocerty.com, or vlad@gocerty.com, or nour@gocerty.com.