PRIVACY NOTICE

1. About this notice

Mantiq Technologies Limited (“we”, “us” or “our”) is a provider of software and related information technology services. Our registered office is at Level 23, Index Tower, Dubai International Financial Centre (“DIFC”), Dubai, United Arab Emirates (“UAE”)

This Privacy Notice explains how we collect and Process Personal Data when we:

  1. operate our website and communicate with visitors, prospective clients and business contacts;
  2. provide, administer, secure and support our software and IT services;
  3. Process Personal Data for our own business, employment, recruitment, legal and administrative purposes; and
  4. provide or use AI-enabled functionality that may Process Personal Data.

This notice is intended to satisfy the transparency requirements of the DIFC Data Protection Law, DIFC Law No. 5 of 2020, as amended (the “DIFC DP Law”), the Data Protection Regulations and, in particular, Regulation 10 concerning autonomous and semi-autonomous systems.

Additional or more specific notices may apply to particular activities, including employee, recruitment, cookie or client-specific notices. If a specific notice conflicts with this notice, the more specific notice will apply to the relevant Processing.

By using this website, you signify your agreement to the this Privacy Policy. If you do not agree with this policy, please do not use this site. Your continued use of this site following the posting of changes to these terms will mean you accept those changes.

2. Our roles

2.1 Where we act as Controller

We act as a Controller when we determine why and how Personal Data is Processed for our own business. This generally includes Personal Data relating to:

  1. website visitors and persons who contact us;
  2. prospective and existing client representatives and authorised users;
  3. suppliers, advisers and other business contacts;
  4. job applicants, employees, former employees and contractors;
  5. persons attending our meetings, events or premises; and
  6. security, compliance, service administration and corporate records maintained for our own purposes.

2.2 Where we act as Processor

When a client uses our services to Process Personal Data for purposes determined by that client, the client normally acts as Controller and we act as its Processor. This may include information relating to the client’s employees, applicants, contractors, customers or other authorised users.

In that context, we Process Personal Data only on the client’s documented instructions, subject to our legal obligations and the applicable services agreement and data processing terms. The client is responsible for establishing a lawful basis, providing required notices and responding to Data Subject requests. We assist the client as required by the DIFC DP Law and our contract.

If you are an individual whose information is held in a client-controlled environment, you should normally direct privacy requests to that client. We will support the client in responding.

2.3 AI roles

For the purposes of Regulation 10, a client that authorises or benefits from the operation of an AI-enabled feature will normally be the Deployer and will be treated as Controller in respect of that Processing. Where we operate or supervise that feature for the client and on its instructions, we will normally be the Operator and will be treated as Processor. When we use the same feature for our own authorised purposes, we may act as Deployer and Controller.

3. Personal Data we Process

Depending on your relationship with us and the services used, we may Process the following categories of Personal Data:

  1. Identity and contact information: name, title, employer, business contact details, account identifiers and signature.
  2. Account and authentication information: usernames, access rights, authentication records and security credentials in protected form.
  3. Client and service information: contracts, orders, instructions, licence information, service configurations and authorised-user information.
  4. Technical and usage information: IP address, device and browser information, timestamps, audit logs, system events, feature usage and diagnostic information.
  5. Communications and support information: emails, calls, meeting records, support requests, attachments, screenshots and troubleshooting information.
  6. Marketing and preference information: communication preferences, event participation and engagement with our communications, where applicable.
  7. Recruitment and workforce information: CVs, qualifications, work history, references, employment details, attendance, leave, compensation, performance, training, immigration and emergency-contact information.
  8. Financial and transaction information: billing contacts, payment status, bank or payment information and transaction records, where applicable.
  9. Compliance information: records required for legal, regulatory, sanctions, fraud-prevention, dispute or audit purposes.
  10. AI interaction information: prompts, queries, retrieved content, generated outputs, feedback, embeddings or vector records, and related logs, to the extent the relevant feature creates or retains them.

3.1 Special Categories of Personal Data

For our own employment, workplace security, legal or compliance purposes, we Process limited Special Categories of Personal Data where necessary and lawfully permitted. This includes biometric fingerprint information used to authenticate authorised persons and control access to our office, as well as information such as health or disability information, sick-leave records, racial or ethnic origin, religious beliefs or criminal-record information where relevant to our employment or legal obligations.

Fingerprint information is used only for physical access control and related security administration. It is not used by our AI-enabled features, for Profiling, or to evaluate or make decisions about individuals.

We process Special Categories of Personal Data only where an additional condition under Article 11 of the DIFC DP Law applies. Depending on the context, this may include necessity for employment-related rights and obligations, compliance with a specific legal requirement, the establishment or defence of legal claims, or explicit consent where consent is appropriate and freely given.

When we act as Processor, the categories of data are determined by the relevant client. Our services may store and otherwise Process Special Categories of Personal Data on the client’s documented instructions. However, our standard AI-enabled features are not intended or configured to Process a material amount of Special Categories of Personal Data. A client must not use the AI-enabled features for such Processing unless it has been separately assessed, lawfully authorised and expressly approved in writing by its Data Subjects.

4. How we obtain Personal Data

We may obtain Personal Data:

  1. directly from you, including through our website, business cards, communications, contracts, applications or employment relationship;
  2. from the organisation you represent or work for;
  3. from our clients when they use our services;
  4. from authorised users and systems connected to our services at a client’s direction;
  5. from service providers, advisers, recruitment agencies and business partners;
  6. from publicly available sources and professional directories, where lawful;
  7. automatically through logs, cookies and similar technologies; and
  8. from information generated through the operation, security and support of our services.

5. Purposes and lawful bases

Where we act as Controller, we Process Personal Data only where one or more lawful bases under the DIFC DP Law applies. The principal purposes and bases are set out below.

PurposePrincipal lawful basis
Responding to enquiries; negotiating and administering contracts; providing requested servicesContractual necessity and/or legitimate interests in conducting and managing our business
Creating and administering accounts; authenticating users; providing supportContractual necessity and legitimate interests in delivering and administering secure services
Operating, maintaining, monitoring and improving our servicesLegitimate interests in ensuring service quality, reliability and usability, subject to data minimisation and client instructions
Security, fraud prevention, incident response, audit and legal claimsLegal obligations and legitimate interests in protecting systems, rights and business operations
Recruitment, employment, biometric office access and workforce administrationContractual necessity, steps before contract, legal obligations and legitimate interests; plus an applicable Article 11 condition for Special Category Data
Billing, finance, tax and corporate administrationContractual necessity, legal obligations and legitimate interests
Business-to-business marketingConsent where required, or legitimate interests where permitted, with the right to object or unsubscribe
Compliance with regulators, courts and competent authoritiesApplicable legal obligations and other lawful grounds permitted by the DIFC DP Law

Where consent is the lawful basis, it may be withdrawn at any time without affecting Processing that was lawful before withdrawal. We will not rely on consent where it cannot be freely given, including in an employment context where another lawful basis is more appropriate.

Where we act as Processor, the relevant client determines and is responsible for the lawful basis. We Process the data in accordance with documented instructions and the applicable data processing agreement.

6. How we use AI-enabled features

6.1 Nature and purposes of the AI

Our services may include locally hosted AI functionality that assists authorised users, in accordance with their assigned roles and access permissions, with retrieving, organising, inputting and summarising authorised information. The AI may Process Personal Data contained in information that the relevant user is authorised to access and may generate responses, summaries or draft material for that user’s review.

All AI Processing requires human initiation, input and oversight. The AI is configured to Process Personal Data only for human-defined or human-approved purposes and within documented human-defined constraints. It is not authorised to establish independent purposes for Processing Personal Data or to take action without human review and approval.

6.2 No High-Risk Processing

Based on our documented assessment of the intended use, configuration, data scope and safeguards, we do not design, authorise or make the AI-enabled features available for High-Risk Processing Activities as defined by the DIFC DP Law. In particular, the features are not intended or authorised to:

  1. carry out systematic and extensive evaluation or Profiling of individuals;
  2. score, rank, predict or assess an individual’s performance, reliability, conduct, health, suitability or behaviour;
  3. make or determine decisions producing legal or similarly significant effects;
  4. Process a material amount of Special Categories of Personal Data through the AI; or
  5. use technology or methods that materially increase risk to individuals or make their rights materially more difficult to exercise.

Clients and users must not configure or use the services for a prohibited High-Risk purpose. If a proposed use could constitute High-Risk Processing, it must not commence unless and until the use has been separately assessed, appropriate safeguards and approvals have been implemented, and its use is permitted under applicable law and our written agreement.

6.3 Outputs and human review

The AI does not make autonomous employment or any other decisions. Outputs are assistive only and must be meaningfully reviewed and verified by an authorised person against appropriate source information before being relied upon. The AI may produce incomplete, inaccurate or inappropriate output, and users must apply independent judgment.

6.4 AI data controls

Subject to the applicable configuration and client instructions, our controls include:

  1. role-based access and alignment with the authorised user’s underlying permissions;
  2. segregation of client environments and restrictions against cross-client access;
  3. documented permitted and prohibited use cases;
  4. human review of outputs and escalation of potentially unfair, inaccurate or unlawful output;
  5. logging, monitoring and controlled approval of material changes;
  6. security testing addressing unauthorised retrieval, prompt manipulation and data leakage;
  7. mechanisms to access, correct, restrict or delete relevant information where required; and
  8. the ability to suspend or disable AI functionality where necessary.

Client Personal Data is not used to train or fine-tune a general model, develop functionality for another client or otherwise benefit another client.

The AI model is hosted locally on our servers in the DIFC. Personal Data processed by the AI, including prompts, outputs, telemetry and diagnostic data, remains within this environment and is not transferred outside the DIFC.

6.5 Notice at first interaction

When a user first accesses an AI-enabled feature, a pop-up informs the user that AI technology may Process Personal Data and provides direct access to this Privacy Notice. This Privacy Notice constitutes the notification provided under Regulation 10 .The Privacy Notice remains accessible to users after the initial interaction.

7. Automated decision-making and Profiling

We do not use solely automated Processing, including Profiling, to make decisions that produce legal or similarly significant effects concerning Data Subjects. If this position changes, we will complete the required assessment, implement suitable safeguards, update this notice and provide meaningful information about the logic, significance and possible consequences before commencing that Processing.

8. Recipients and Sub-processors

We may disclose or make Personal Data available, only where necessary and lawful, to:

  1. the relevant client and its authorised users;
  2. our authorised employees, officers and contractors who are subject to confidentiality obligations;
  3. approved hosting, infrastructure, communications, security, support and professional-service providers;
  4. our group and affiliates entities where necessary for legitimate internal administrative purposes and subject to safeguards;
  5. professional advisers, auditors and insurers;
  6. regulators, courts, law-enforcement bodies and other competent authorities where lawfully required; and
  7. a purchaser, investor or successor in connection with an actual or proposed corporate transaction, subject to appropriate safeguards.

When we appoint a Sub-processor for client data, we do so in accordance with the applicable client agreement, including required authorisation, notice of changes and contractual flow-down of data protection obligations. Our current Sub-processors are listed is Google Cloud, which provides cloud-hosting services. Google Cloud Processes Personal Data solely for the purpose of providing the relevant hosting and infrastructure services and is subject to contractual data protection, confidentiality and security obligations.

We remain responsible for the performance of our Sub-processor’s data protection obligations in accordance with the applicable client agreement and the DIFC DP Law. We will notify affected clients via an updated Privacy Notice upon appointment of any additional or replacement Sub-processor.

We do not sell Personal Data.

9. International transfers

Personal Data is stored and Processed only in the DIFC and in jurisdictions recognised by the DIFC Commissioner of Data Protection as providing an adequate level of protection for Personal Data. We do not transfer Personal Data to jurisdictions that have not been recognised as providing an adequate level of protection. Where we act as a Processor, transfers are carried out in accordance with the relevant client’s documented instructions and the applicable data processing agreement.

10. Retention and deletion

We retain Personal Data only for as long as necessary for the relevant purposes, including to provide services, comply with law, resolve disputes, establish or defend legal claims and enforce agreements. Retention periods take account of the nature, volume and sensitivity of the data, the risks of continued retention and applicable legal or contractual requirements.

When we act as Processor, we return or delete client Personal Data at the client’s choice at the end of the services, unless applicable law requires retention. Where immediate deletion from a backup is not technically possible, the data will be protected, isolated from ordinary use and deleted in accordance with the applicable backup cycle.

11. Security and confidentiality

We maintain technical and organisational measures appropriate to the risks, nature and context of the Processing. These measures include, as applicable:

  1. authentication and role-based access control;
  2. periodic access reviews;
  3. network boundary protection and security monitoring;
  4. audit logging and monitoring of privileged or unusual activity;
  5. client segregation;
  6. secure development, code review, vulnerability management and testing;
  7. backup, restoration, continuity and incident-response controls;
  8. confidentiality obligations and privacy/security training; and
  9. vendor risk assessment and contractual safeguards.

No system is completely secure. We review our measures to address changes in technology, risk, law and our Processing activities.

12. Personal Data breaches

We maintain procedures to identify, contain, investigate, document and remediate Personal Data Breaches. Where we act as Processor, we notify the relevant client without undue delay after becoming aware of a breach. Where we act as Controller, we notify the DIFC Commissioner of Data Protection as soon as practicable where required and notify affected individuals where the breach is likely to result in a high risk to their security or rights.

13. Your rights

Subject to the DIFC DP Law and any applicable limitations, you may have the right to:

  1. withdraw consent where consent is the lawful basis;
  2. request access to Personal Data and information about its Processing;
  3. request rectification of inaccurate Personal Data;
  4. request erasure where the data is no longer required or another legal ground applies;
  5. object to Processing based on legitimate interests or to direct marketing;
  6. request restriction of Processing;
  7. receive relevant Personal Data in a structured, commonly used and machine-readable format where the portability right applies;
  8. object to solely automated significant decision-making and request manual review; and
  9. lodge a complaint with the DIFC Commissioner of Data Protection.

You may also question or challenge an AI-generated output relating to you. Where appropriate, we or the relevant client will review the underlying information and the use made of that output.

We may need to verify your identity before acting on a request. Rights are not absolute, and we may decline or limit a request where permitted by law, in which case we will explain the position where legally permitted. You will not be discriminated against for exercising your rights.

14. How to exercise your rights

You may contact us through either of the following methods, neither of which requires payment or the creation of an account:

  1. Email: notification@mantiq.com
  2. Online form or postal address: Level 23, Index Tower, DIFC, Dubai, UAE

If we Process your information solely on behalf of a client, we may refer the request to that client or ask you to contact it directly. We will assist the client as required.

15. Contact details

Organisation: Mantiq Technologies Limited

Registered address: Level 23, Index Tower, DIFC, Dubai, UAE

Email: notification@mantiq.com

16. Complaints

We encourage you to contact us first so that we can address your concern. You may also lodge a complaint with:

DIFC Commissioner of Data Protection
Dubai International Financial Centre
Gate Building, Level 14
Dubai, United Arab Emirates
Email: commissioner@dp.difc.ae
Website: www.difc.com

17. Changes to this notice

We may update this notice to reflect changes in our services, AI functionality, Processing activities, safeguards or applicable law. Material changes will be brought to the attention of affected persons by an appropriate method. The effective date shown at the beginning identifies the current version.

18. Acknowledgement and lawful Processing

By accessing or using our services, you acknowledge that you have read and understood this Privacy Notice and that your Personal Data will be Processed as described in it. This acknowledgement does not constitute consent where consent is required by applicable law. We Process Personal Data on the lawful bases identified in this Privacy Notice, including where Processing is necessary to provide the services, comply with legal obligations or pursue legitimate interests. Where we are required to obtain consent for a specific Processing activity, we will request it separately through a clear affirmative action and provide an appropriate method for withdrawing that consent.

19. Definitions

Controller: a person that determines the purposes and means of Processing Personal Data.

Data Subject: the identified or identifiable natural person to whom Personal Data relates.

Deployer: a person under whose authority or for whose benefit a Regulation 10 System is operated or who receives its benefit or output.

High-Risk Processing Activities: Processing meeting one or more of the criteria in Schedule 1 of the DIFC DP Law, including certain materially risky new technologies, considerable amounts of high-risk Personal Data, significant automated evaluation or material amounts of Special Categories of Personal Data.

Operator: a Provider that operates or supervises a Regulation 10 System for the benefit and on the direction of a Deployer.

Personal Data: information referring to an identified or identifiable natural person.

Process / Processing: any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, restriction, erasure or destruction.

Processor: a person that Processes Personal Data on behalf of a Controller.

Profiling: automated Processing used to evaluate personal aspects relating to an individual.

Special Categories of Personal Data: Personal Data revealing or concerning the sensitive characteristics listed in the DIFC DP Law, including health, race or ethnicity, religion, criminal record, genetics and certain biometrics.

System: a machine-based system operating autonomously or semi-autonomously that Processes Personal Data and generates output, as described in Regulation 10.

Where You Can Find Us

Based at our headquarters in Dubai, Properti.es also currently has offices located across Europe, the Middle East and North Africa.

Switzerland Map
Rue des Alpes 7
1201 Genève
Switzerland
UAE Map
Level 23 - East Entrance
Index Tower, DIFC
PO Box 482015
Dubai, UAE
Morocco Map
Quartier Anfa Club, Ryad Anfa
Bloc A1, Étage 7 N°74
Casablanca, Morocco