Privacy Policy

Effective Date 19 August 2026

This Privacy Policy explains how SC Enterprises Group LLC, the company that provides Saisify, collects, uses, discloses, and retains personal data when you visit our websites, create or use a Saisify account, build or publish an app, communicate with us, or otherwise use our services (collectively, the "Services").

It also explains the important difference between data Saisify controls for its own business and Tenant Data that Saisify processes only on behalf of a customer who built a Customer App.

Company and controller
SC Enterprises Group LLC, Shams Business Center, Sharjah Media City Free Zone, Al Messaned, Sharjah, United Arab Emirates.
Licence and tax details
Licensing authority: Sharjah Media City Free Zone (Shams). Trade Licence No.: 2429651.01. UAE Tax Registration Number (TRN): 104375278900003.
Privacy and legal contact
legal@saisify.com
Tenant Data
The customer who built the Customer App is normally the controller. Saisify is its processor or service provider.
Helping improve Saisify
Saisify does not use Tenant Data to train Saisify or other general-purpose AI models, or voluntarily opt it into an optional provider model-improvement or training program. AI providers may process and retain Tenant Data under the terms and data settings applicable to the selected service. Eligible Builder Content and related customer-specific Implementation Materials may be used to help improve Saisify only as described in Section 6, with an opt-out where permitted and affirmative opt-in where required by law.

1. Scope

What this Policy covers

This Policy applies to personal data handled through the Saisify websites, account application, AI-assisted builder, hosted Customer Apps, app data and member services, support, billing, analytics, and related features. It does not govern a third party's own service or a Customer App owner's independent use of information.

Customer App End Users

If you are an End User of a Customer App, the app owner should give you its own privacy notice. Contact that owner first about its purposes, legal bases, or your rights in Tenant Data. We will assist the owner as required by Section 20 of our Terms & Conditions and applicable law.

2. When Saisify is a controller and when it is a processor

Saisify as controller

Saisify determines the purposes and means of processing for website visits, Saisify accounts, subscriptions, direct communications, platform security, fraud prevention, first-party product analytics, legal compliance, and the use of eligible content to help improve Saisify as described in Section 6. For this processing, SC Enterprises Group LLC is the controller or business.

Saisify as processor

A Saisify customer ordinarily determines why and how its Customer App collects End User records such as bookings, form submissions, member details, customer records, and app transactions. For this Tenant Data, the customer is the controller or business and Saisify is the processor or service provider. Section 20 of our Terms & Conditions, titled "Data Processing Terms," governs that processing; it is part of the Terms & Conditions rather than a separate page.

Limited independent processing

We may act as an independent controller for limited security logs, fraud signals, billing records, and legal-compliance records associated with a Customer App where we determine those purposes ourselves.

3. Information we collect

Categories of information

Account, profile, and verification
Name, email address, account identifier, password hash or social-login identifier, organization and role, profile details, preferences, account settings, verification status, and information or documents you provide when we reasonably need to verify identity, age, authority to act for an organization, business registration, tax status, payment authorization, or other relevant account information.
Billing and subscriptions
Plan, credits, billing address, tax information, invoices, payment status, transaction and checkout identifiers, renewal and cancellation records, refunds, disputes, and limited payment-method details received from Stripe. Stripe processes full card or bank credentials; Saisify does not receive full payment-card numbers.
Connected payments
Stripe connected-account identifiers and status, product and price configuration, Customer App transaction and subscription records, payout-related status, refunds, disputes, and information needed to route and reconcile payment events.
Builder Content and AI interactions
Prompts, messages, conversation history, instructions, feedback, uploaded files and images, tool inputs and outputs, model choices, user-facing generated content and media, edits, memories or personalization notes, usage, cost, and diagnostic metadata.
Projects and Customer Apps
App names and identifiers, internally generated source and build artifacts, preview and publication history, custom domains, access settings, integration configuration, member-auth settings, invitations, app plans and feature gates, email configuration, hosted data schemas, AI Gateway configuration, and other feature settings.
Tenant Data
Information that an app owner configures a Customer App to collect, store, or process in Saisify's hosted data service, including structured database records and fields, End User contact and member records, authentication identifiers, invitations, memberships, bookings, form submissions, CRM records, content and file uploads, app activity, transaction-related records, and AI Gateway prompts, conversation context, files, and Output. The exact fields depend on the Customer App.
Customer App email events
Sender and recipient addresses, message and app identifiers, delivery status, opens, clicked and original links, bounce or complaint details, suppression status, event time, and metadata reported by the email provider such as user agent, email client, operating system, and approximate geography. Customer App owners may use this information to monitor delivery and engagement.
Learning activity
Courses and lessons available to your account, access source and expiry, lesson status, progress percentage, playback position, first and last access, completion time, and visit count.
Communications
Support requests, emails, survey responses, feedback, complaint details, and other communications with us, including attachments.
Device, log, and security data
IP address, timestamps, browser and device type, operating system, user agent, language, approximate location derived from IP, request and response metadata, authentication events, session identifiers, security events, fraud and abuse indicators, and diagnostic logs.
Fraud and account-integrity data
Normalized email variants; signup and login IP address, user agent, and device type; a browser-derived device identifier; referral or affiliate code; and payment-card fingerprint, issuer country, and payment-method identifier supplied by Stripe. We use these signals to identify suspected duplicate or abusive accounts, protect promotional credits and payments, and respond to disputes. These signals are indicators rather than proof and may be reviewed by a person.
Usage, metering, and product analytics
Pages and app routes viewed, referrer, feature and button interactions, session duration, model and tool usage, Customer App request counts and compute time, storage and hosted-record quota usage, email-send usage, credit consumption, performance, errors, and aggregated usage patterns. We use this information to provide usage views, apply plan limits and credit charges, forecast capacity, and operate and improve the Services. Our first-party product analytics do not intentionally duplicate prompt text.
Error and session-replay telemetry
Frontend errors, stack traces, performance traces, network metadata, account identifier and email, browser interactions, and sampled session replays. Replays may capture text and media visible in the Saisify interface, including prompts or support text. Full payment fields are handled by Stripe and passwords are not intended to be captured, but you should not place secrets or sensitive data in ordinary text fields.
Cookies, referrals, and marketing data
Cookie and similar identifiers, affiliate and Customer App badge referral codes, referring creator, campaign and attribution data, referral qualification and credit grants, ad interactions, conversion events, and hashed contact or account identifiers used for measurement where enabled.
Third-party account and integration data
Basic profile and authentication data from a social-login provider, and information returned by integrations or data sources you choose to connect or ask us to use.
Derived and aggregated data
Approximate location, device category, feature preferences, suspected fraud or abuse risk, and statistics derived from the categories above. Aggregated or anonymized information is not personal data where it can no longer reasonably identify a person.

Sensitive information

The Services are not designed for you to submit sensitive or special-category data unless we have expressly confirmed in writing that a specific feature supports it. Content is user-directed, so we cannot prevent a user or End User from entering sensitive information. If you do, you are responsible for having a lawful basis and using an appropriate Service configuration.

4. Sources of information

We collect personal data:

5. How and why we use information

Purposes and legal bases

The legal bases below apply where a law such as the EU or UK GDPR requires us to identify one. Under UAE law, we process with consent or under another lawful case, including where processing is necessary to perform a contract or fulfil a legal obligation.

Provide and administer the Services
Create and authenticate accounts; process prompts and files; generate, build, host, and publish Customer Apps; provide data, email, member, domain, AI, and payment features; measure usage; provide support; and process subscriptions and credits. Basis: contract and steps requested before contract.
Secure and protect
Detect, investigate, and prevent fraud, abuse, unauthorized access, malware, cross-tenant access, policy violations, and security incidents; maintain logs; debug; and enforce our Terms. Basis: legitimate interests in protecting users and the Services, contract, and legal obligations.
Operate and improve
Analyze feature adoption and performance, troubleshoot, test, develop features, forecast capacity, and improve reliability and usability. Basis: legitimate interests in operating and improving the Services. AI model training is governed separately below.
Communicate
Send transactional, security, billing, service, and support messages; respond to requests; and provide important policy or product notices. Basis: contract, legal obligation, and legitimate interests.
Market and measure
Send marketing where permitted, attribute visits and conversions, measure campaigns, show or evaluate advertising, and identify business customers using an organization's name and publicly available logo under the limited permission in our Terms. Basis: consent where required, the Terms, and otherwise legitimate interests, subject to applicable rights and the business customer's ability to opt out of future identification.
Help improve Saisify
Develop, train, fine-tune, test, and evaluate AI models and safety systems using eligible Builder Content and related customer-specific Implementation Materials. Basis: legitimate interests where an opt-out model is permitted and we have provided the required notice and choice; consent where applicable law requires affirmative opt-in; the associated content licence; and Saisify's rights in its Implementation Materials. Tenant Data is excluded.
Comply and defend rights
Maintain tax, accounting, audit, consent, and transaction records; respond to lawful requests; resolve disputes; and establish, exercise, or defend legal claims. Basis: legal obligation and legitimate interests.

Legitimate interests and required data

Where we rely on legitimate interests, we consider the purpose, necessity, and impact on your rights. You may object as described in Section 11. Where processing is required to provide the Services, declining to provide the information may mean we cannot provide the relevant feature.

6. AI processing and model training

Providing AI features

When you use an AI feature, we process Builder Content and related context to generate the requested Output, operate tools, meter usage, prevent abuse, and maintain conversation and project continuity. We may send the information needed for the request to the AI provider selected or routed for that feature. We use providers under the account, API, cloud-service, and data-processing terms and data settings applicable to Saisify's use of the relevant service, which may be generally available online terms rather than separately negotiated agreements. Provider roles, retention, and data-use rules may vary by feature and provider.

AI features in Customer Apps

If a Customer App owner enables an AI feature, an authenticated End User may submit prompts, conversation context, and supported files through Saisify's AI Gateway. We process that Tenant Data and send the information needed for the request to the selected AI provider to generate the response. We also associate the request with the Customer App and authenticated End User identifier and process model, token, usage, credit, rate-limit, and diagnostic data to authenticate requests, prevent abuse, enforce owner-configured limits, and charge the Customer App owner's Saisify credit balance. The app owner controls the purpose and should explain the feature in its own privacy notice. Saisify does not use this Tenant Data to train Saisify or other general-purpose AI models, or voluntarily opt it into an optional provider model-improvement or training program. The selected provider may process and retain the data for service delivery, abuse monitoring, safety, security, legal compliance, and other purposes permitted by the terms and settings applicable to Saisify's use of that service.

How your content may help improve Saisify

Saisify will not use Tenant Data to train or improve Saisify or other general-purpose AI models. Where applicable law permits an opt-out model, the “Help improve Saisify” setting may be on by default after we provide clear notice and an effective way to turn it off. Where consent or another affirmative choice is required, we will not select eligible material unless you turn the setting on.

Eligible material may include builder prompts, instructions, configurations, uploaded content, feedback, edits to user-facing Output, and related customer-specific Implementation Materials such as internally generated app source and build artifacts. The fact that internally generated source is eligible for this use does not make it visible to the customer or change the ownership terms governing it. Before activating this use, we require safeguards that include access controls, recording the applicable notice and participation choice or lawful basis, honouring required regional restrictions, and reasonable screening intended to remove personal data and secrets before material enters a training corpus. Do not place personal data, API keys, passwords, or confidential third-party information in content intended for this use.

You may opt out of future selection through an available account control or by emailing legal@saisify.com. We will stop selecting new Builder Content and related customer-specific Implementation Materials from your account after processing the opt-out. Material already incorporated into a trained model may not be capable of being isolated or removed without retraining the model; an opt-out does not affect processing that was lawful beforehand. A verified erasure request is not used as an occasion to create a new training archive.

7. How we disclose information

Service providers

We disclose personal data only as reasonably necessary for the purposes described in this Policy, on your instruction, or as permitted by law. A provider receives only the categories relevant to the service it supplies. Current provider relationships may include:

Where a provider processes Tenant Data on our behalf, its legal name and role are listed on our Subprocessor Schedule. The categories below also include providers that process Saisify's own account, billing, website, or operational data and therefore are not necessarily Tenant Data subprocessors.

Cloud and network providers
Hosting, compute, databases, object storage, queues, transactional email infrastructure, code sandbox services, DNS, content delivery, web security, edge computing, published-app routing, backups, and related operations.
Stripe
Saisify subscription and credit payments, invoicing, fraud controls, and Customer App payments. Stripe may act as our processor for specified services and as an independent controller for matters such as payment execution, fraud prevention, identity verification, regulatory compliance, and service operations. Customer App payments are direct charges on the app owner's connected Stripe account: the owner is the merchant, has its own Stripe relationship, and instructs Saisify to transmit the technical payment request and related transaction data. Stripe is therefore a customer-selected payment provider for that flow, not a Saisify Tenant Data subprocessor merely because the Services facilitate the connection.
AI providers
AI inference; generation and editing of written content, code, images, and other digital materials; embeddings; research; and related model operations, depending on the model or feature selected or configured.
Google, Meta/Facebook, Microsoft, and Apple
Social sign-in when the provider is configured and you choose it. We may receive the provider account identifier, email, verification status, name, and other profile data you authorize the provider to disclose. For this sign-in relationship, the provider and Saisify generally each determine their own purposes and responsibilities under their respective terms; providing data at your request does not by itself make the identity provider our processor or a Tenant Data subprocessor.
Google Fonts
Saisify's website and application, and Customer Apps that use selected hosted typefaces, may load font resources from Google's hosted font service. When a page does so, the visitor's browser connects directly to Google and sends the IP address, browser or device information, requested font resources, referring page information where transmitted, and other technical request data. Google may process that information under its own terms. A Customer App owner must account for its own use in its End User privacy or cookie disclosures and obtain any consent required by applicable law.
Google Analytics and Google Tag Manager
Site and campaign measurement, tag management, conversion attribution, and related diagnostics where enabled. Google may process analytics data on our behalf where its processor terms apply and may act separately for other configured destinations or uses. Tag Manager loads and controls configured tags; those destination tags may collect and send additional data under their own terms.
Google Ads
Advertising attribution, conversion measurement, bidding, and audience or remarketing features where enabled. Event data may include page or event details, URLs, timestamps, a Google click identifier, transaction value and identifier, device or browser data, and hashed contact or account identifiers used for enhanced conversion matching. Depending on the processing and applicable law, Google may act as our processor or as an independent controller under its advertising and customer data terms. These technologies rely on your Advertising choice and on Google Consent Mode signals, and are not used where you have declined or where an enabled Global Privacy Control signal applies.
Microsoft Clarity
Website and product analytics, heatmaps, interaction diagnostics, and sampled session recordings where enabled. Clarity may process cookie or similar identifiers, IP address and approximate location, browser and device data, visited URLs, clicks, scrolling, pointer movement, navigation, page layout and DOM information, performance events, and masked or otherwise captured interface content depending on our configuration.
Meta Pixel and Conversions API
Advertising attribution, audience measurement, and conversion reporting where enabled. Event data may include page or event details, URLs, timestamps, transaction value, IP and device or browser data, and hashed account, contact, or approximate-location identifiers used for matching. Depending on the processing and applicable law, Meta may act as our processor, a joint controller with us, or an independent controller under its Business Tools Terms.
Error monitoring and diagnostics providers
Frontend error monitoring, performance tracing, logs, and sampled session replay.
Google Workspace
Business email and customer-support communications. Google may process names, email addresses, organization and account details, message content, attachments, support history, and technical or diagnostic information that a sender chooses to include. Avoid sending passwords, payment-card information, or unnecessary sensitive or End User data in support messages.
Customer App email providers
Transactional email and email services configured by Customer App owners, including delivery, open, click, bounce, complaint, and suppression events.
Location and security-data providers
Approximate country, region, and city lookup from IP address for analytics and security.
Accounting and tax providers
Bookkeeping, invoicing, tax reporting, reconciliation, financial records, and related legal-compliance support.
Research, media, and requested data sources
Public-data retrieval, media search, and content tools only when the relevant feature is enabled or requested.

Other disclosures

We may also disclose information:

Sale, sharing, and targeted advertising

We do not sell personal data for money. Our use of advertising and analytics technologies may be considered a "sale," "sharing," or targeted advertising under some U.S. state laws even when no money changes hands. Section 13 explains relevant choices.

8. Cookies, analytics, advertising, and session replay

Technologies we use

We use cookies, local storage, pixels, tags, server-side events, and similar technologies. Depending on the surface and environment, these include:

Your choices

We use a visitor's general location to provide privacy settings appropriate to the region. Optional Analytics and Advertising technologies are off by default in some regions and enabled by default in others. You can review or change these settings at any time through Cookie preferences. If we cannot determine which settings apply, they remain off.

You can review or change these settings at any time through “Cookie preferences” in the website footer or the application's Settings area. A saved selection applies to that browser and, where technically available, across our Saisify website and application subdomains, and remains effective until it is changed or expires. Turning a category off stops future optional collection and clears supported first-party analytics or advertising cookies from the browser where feasible.

We also honor a browser's enabled Global Privacy Control signal as an opt-out from Advertising technologies. You can block or delete cookies through your browser as well. Blocking essential technologies may prevent login, payments, preferences, or other features from working. You may opt out of marketing email using the unsubscribe link. For another advertising-related objection or request, contact legal@saisify.com.

9. International transfers

Where processing occurs

Saisify is established in the United Arab Emirates and uses providers and infrastructure in the United States and other countries. Cloud and network providers may process data globally. As a result, personal data may be transferred to a country whose privacy laws differ from those where you live.

Transfer safeguards

Where law requires a transfer mechanism, the mechanism may be an applicable adequacy decision, provider data-processing and transfer terms that legally apply to the relevant account and use, completed European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum, or another legally recognized instrument, together with supplementary measures where appropriate. Our Terms do not represent that every possible customer transfer is covered automatically. Before submitting Tenant Data whose transfer requires a customer-specific mechanism, contact legal@saisify.com so the required mechanism can be confirmed or completed. Where UAE data-protection law requires a transfer basis for particular processing, we will confirm or put an appropriate permitted basis in place before carrying out that restricted transfer.

10. Retention and deletion

Standard retention approach

We retain personal data only for as long as reasonably necessary for the purposes described here, including to provide the Services, honour your choices, comply with law, resolve disputes, prevent fraud, and enforce agreements. The schedule below describes our standard approach; a longer or shorter period may apply where law, a dispute, security, backup cycles, or a documented customer instruction requires it.

Account and profile
For the life of the account. A standard deletion request ordinarily has a 30-day recovery period, after which identity data is deleted or anonymized except for required records.
Verification materials
Only for as long as reasonably necessary to complete the verification and meet applicable fraud-prevention, tax, payment, sanctions, dispute, or legal-record obligations. We may retain the verification result and a limited audit record longer without retaining the full supporting document where feasible.
Builder Content and Customer App implementation
While the account or project remains active and during the 30-day account-deletion recovery period, then purged from active systems subject to backup cycles and legal exceptions. Cancelling or downgrading without deleting the account may freeze apps and retain their internal implementation and artifacts so they can be restored.
Tenant Data
While the Customer App and account remain active or recoverable. A record deleted through the hosted data service is removed from active use but may persist for a limited period in backups or recovery systems before being overwritten or purged; this does not guarantee that an individual record can be restored. A downgrade or cancellation may freeze an app without deleting its Tenant Data. Tenant Data is purged from active systems after the applicable app or account hard-deletion process, ordinarily following the 30-day account recovery period, subject to limited backup cycles and legal exceptions.
Customer App email and suppression records
Message-delivery and engagement events are ordinarily retained with the Customer App owner's account as an operational, billing, deliverability, and abuse-prevention ledger. Bounce, complaint, and suppression records may be retained for as long as reasonably necessary to prevent repeated unwanted delivery, protect sending reputation, resolve disputes, or comply with provider and legal requirements.
Saisify transactional email
Copies and delivery records for transactional messages sent by Saisify may be retained in our email-provider archive for up to one year for deliverability, security, support, and audit purposes, and longer where a legal hold or dispute requires it.
User files and trash
Active files are retained with the account. Files placed in trash are ordinarily recoverable for 30 days and then permanently deleted. Account deactivation may place files into the same recovery process.
Product analytics
Page-view and interaction events are ordinarily retained for 365 days. After that, those events are deleted and raw IP addresses in the corresponding analytics sessions are removed. Aggregated or de-identified statistics and coarse device or geography data may be retained longer.
Content used to help improve Saisify
Selected content is retained for as long as needed to develop and evaluate the relevant systems or until future use is withdrawn, subject to de-identification, legal requirements, and technical limits. Individual contributions already incorporated into a trained model may not be removable without retraining.
Billing, tax, and transactions
For the period required by tax, accounting, payment, anti-fraud, and financial-record laws, commonly 5–7 years depending on the record and jurisdiction.
Fraud and account-integrity records
Signup, login, browser-device, and card-fingerprint records used for anti-fraud purposes are ordinarily retained for 18 months and then deleted, unless a dispute, legal hold, security investigation, or law requires longer.
Other security, consent, and audit records
For as long as reasonably necessary to protect the Services, prove consent or compliance, investigate abuse, respond to payment disputes, preserve immutable teardown records, or establish and defend legal claims.
Support and legal communications
For as long as needed to resolve the matter and, where relevant, for the applicable legal-claims period.

Backups and de-identified information

Deletion from live systems may not immediately remove encrypted backup copies. We isolate backups from ordinary use and overwrite or expire them under backup schedules. We may retain anonymized or de-identified information that can no longer reasonably identify you. We maintain such information in de-identified form and do not attempt to re-identify it except where law permits testing whether our de-identification measures are effective.

11. Your privacy rights

Rights that may be available

Depending on where you live and subject to legal exceptions, you may have the right to:

How to submit a request

Submit a request to legal@saisify.com. Describe the right and account involved. We may ask for information reasonably necessary to verify identity and authority, and we will respond within the time required by applicable law. We will not discriminate against you for exercising a privacy right.

Tenant Data requests and exceptions

If your request concerns Tenant Data in a Customer App, identify the app and contact its owner. Because the owner controls that data, we normally forward or refer the request to it and act on its verified instruction. We may deny or limit a request where law permits, including to protect another person's rights, security, confidential information, legal claims, or records we must retain. Where applicable, you may appeal a refusal by replying to our response.

12. Additional EEA, Swiss, and UK information

Controller and legal bases

If the EU GDPR, UK GDPR, or equivalent Swiss law applies, SC Enterprises Group LLC is the controller for the controller activities described in Section 2. Our legal bases are set out in Section 5. Where we rely on legitimate interests, those interests include providing a safe, reliable, and commercially sustainable service; understanding and improving product use; preventing fraud and abuse; supporting customers; and protecting legal rights.

Objections and complaints

You may object to legitimate-interest processing based on your particular situation. We stop direct marketing upon objection. You may lodge a complaint with the data-protection authority where you live or work or where you believe an infringement occurred. International-transfer safeguards are described in Section 9.

Automated decision-making

Saisify does not use solely automated processing to make decisions about a builder user that produce legal or similarly significant effects. Automated security or fraud systems may temporarily flag or restrict activity; you may contact support to request review. Customer App owners are responsible for any automated decision-making they configure in their apps.

13. California and other U.S. state notices

This section applies only where the California Consumer Privacy Act (CCPA) or a similar U.S. state privacy law applies to Saisify's processing. Terms such as "sell," "share," and "sensitive personal information" have the meanings given by the applicable law.

Categories handled in the preceding 12 months

Depending on how you used the Services, we may have collected the following statutory categories: identifiers; customer-record information; commercial information; internet or other electronic-network activity; approximate geolocation; audio, electronic, visual, or similar information; professional or employment-related information you submitted; inferences; and sensitive personal information such as account credentials, payment-related information handled through Stripe, or content you chose to submit. Sections 3–5 describe the sources and purposes, and Section 10 describes retention.

We may have disclosed each relevant category to cloud, security, payment, AI, communications, analytics, professional-adviser, integration, and transaction parties for the business purposes described in Section 7. We do not sell personal information for money. Through Google, Meta, and similar advertising or analytics tools, we may have "shared" identifiers, commercial or conversion information, internet activity, approximate location, and related inferences for cross-context behavioral advertising or measurement.

Your choices and requests

Subject to applicable law, you may request access, categories and specific pieces, correction, deletion, portability, an opt-out of sale or sharing and targeted advertising, limitation of certain sensitive-personal-information uses, and freedom from discriminatory treatment. We use sensitive personal information only to provide and secure the Services, process payments, prevent fraud, comply with law, or as otherwise permitted, unless we give you a separate notice.

To opt out of sale, sharing, or targeted advertising in this browser, open “Cookie preferences” and turn off Advertising. You may also email legal@saisify.com with the subject "Do Not Sell or Share." For access, correction, deletion, or portability, email the same address and identify the request. An authorized agent may submit a request with proof of authority; we may also verify the request directly with you. We do not knowingly sell or share personal information of anyone under 16.

14. Children

Builder accounts

Saisify builder accounts are intended for adults and are not directed to anyone under 18. We do not knowingly permit a child to open a builder account. If you believe a child has provided account personal data, contact us and we will investigate and delete it where required.

Customer Apps directed to children

Customers may not use Saisify to operate a Customer App directed to children under 13 or knowingly collect their personal data without our prior written approval and compliance with applicable children's privacy and safety laws. A Customer App owner remains responsible for age controls, parental notices and consent, data minimization, advertising restrictions, and responding to parents.

15. Security

Our measures

We use reasonable technical and organizational measures designed to protect personal data, including access controls, authentication, logical tenant separation, protected cloud storage, encryption in transit, logging and monitoring, dependency and vulnerability management, backups where appropriate, and measures supporting incident detection, investigation, and response. Measures vary based on the data, feature, and risk. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

Your responsibilities

You are responsible for protecting credentials, controlling collaborators, using designated secret and payment fields, configuring and testing Customer App access and user-facing behaviour, and notifying us promptly of suspected compromise at legal@saisify.com.

16. Personal-data breaches

If we confirm a personal-data breach, we will investigate, mitigate, document, and notify affected controllers, people, or authorities when and within the time required by applicable law. If you are a Customer App owner, you remain responsible for notifications concerning Tenant Data as controller; Section 20 of our Terms & Conditions describes how we assist you.

17. Changes to this Policy

We may update this Policy as the Services, providers, laws, and practices change. We will post the revised version, update the effective date, and keep prior versions or other reasonable evidence of the notice that applied where required for compliance or dispute purposes.

If a change materially affects how we use personal data already being processed, we will provide a prominent notice through the Service or by email before the changed processing begins. Where practicable, we will give at least 30 days' advance notice, but a shorter period may be necessary for law, security, fraud prevention, or to protect people or the Services. A new optional feature may have a just-in-time notice presented before you enable or use it.

Updating this Policy does not by itself create consent for a new purpose. If applicable law requires consent for a materially different use, we will request the required choice before beginning that use. Where another legal basis applies, we will provide the notice and honor the rights required by applicable law.

18. Contact and complaints

Email

For legal questions, complaints, security reports, or privacy-rights requests, contact legal@saisify.com. For general support, contact support@saisify.com.

Postal address

You may also write to: SC Enterprises Group LLC, Shams Business Center, Sharjah Media City Free Zone, Al Messaned, Sharjah, United Arab Emirates.