Privacy Policy
Last updated: June 2026
1. Who We Are
DeepSolve Tech Limited ("DeepSolve", "we", "us") is an AI consultancy and product company licensed in the Dubai International Financial Centre (DIFC). This Privacy Notice describes how we collect, use, share, and protect personal data in connection with our services and our website at www.deepsolve.io.
Our registered details:
- Legal name: DeepSolve Tech Limited
- DIFC Commercial Licence: CL10387 (issued 30 April 2026)
- Registered address: Unit IH-00-01-02-OF-01, Level 2, Innovation One, Dubai International Financial Centre, Dubai, UAE
- Mailing address: PO Box DeepSolve – 506983, Dubai, UAE
- Privacy contact: info@deepsolve.io
Where you are located in the European Economic Area or the United Kingdom, we also aim to meet the standards of the EU General Data Protection Regulation (GDPR) and UK GDPR in addition to UAE PDPL and DIFC DPL.
2. Scope
This Privacy Notice applies to:
- Visitors to www.deepsolve.io and other DeepSolve-operated public web pages.
- Prospective clients, clients, and partners with whom we communicate or do business.
- Suppliers and service providers who provide services to us.
- Job applicants and other individuals who interact with DeepSolve.
- DeepSolve personnel (employees and contractors), in respect of the personal data DeepSolve processes about its own workforce — including managed-device telemetry from company-issued laptops, M365 sign-in and activity logs, MFA registration, and HR records.
3. The Data We Collect
We may collect the following categories of personal data:
- Identity and contact details: name, professional role, employer, work email address, work phone number, postal address.
- Communications: emails, messages, meeting recordings (with consent), call notes.
- Engagement data: information shared by clients during consulting engagements, which may include personal data of the client's employees or end-users where contractually agreed.
- Website data: technical metadata (IP address, browser type and version, operating system, device type, screen resolution); aggregated traffic data (pages visited, referrer, time spent on page, click interactions, scroll depth); and, only with your consent, anonymised session replays of your interactions with the site (mouse movements, clicks, scrolling). The specific analytics technologies we use are described in Section 10.
- Recruitment data: where you apply for a role with us, your CV, work history, references, and right-to-work documentation.
- Personnel data (for DeepSolve employees and contractors): identity details (Entra ID account, name, role), M365 sign-in and activity logs, managed-device telemetry (Microsoft Intune and Defender for Business), security event logs, MFA registration data, leave and time records, and HR records.
We do not knowingly collect personal data of children under 18.
4. How We Use Personal Data and the Legal Basis
We use personal data only for specified, lawful purposes. Our processing is governed by UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection ("UAE PDPL") and the DIFC Data Protection Law 2020 ("DIFC DPL"). Under Article 10 of the DIFC DPL (and, where applicable, Article 6 of the EU GDPR / UK GDPR), we rely on the following lawful bases:
- Performance of a contract — to deliver consulting and product services to our clients, manage our supplier relationships, respond to your contact-form submissions, and answer your requests.
- Consent — for marketing communications, optional cookies, PostHog analytics, and session replay recordings. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
- Legitimate interests — to operate, maintain, secure, and improve DeepSolve and its services; to detect and prevent fraud and security incidents; to rate-limit by IP address to prevent abuse; for aggregated, anonymised website analytics (Vercel Web Analytics) and performance monitoring (Vercel Speed Insights); and to manage prospective business relationships.
- Legal obligation — to meet our obligations under UAE law (including tax, anti-money-laundering, and corporate-compliance), DIFC regulations, applicable customer contracts, and employment law in respect of personnel data.
For DeepSolve personnel and contractors specifically, the predominant lawful bases for processing are performance of the employment or engagement contract, our legitimate interests in operating and securing the business (including security monitoring, audit trails, and incident detection), and legal obligations under UAE employment, tax, and applicable regulations.
5. How We Share Personal Data
We share personal data only as needed to deliver our services and operate our business:
- Service providers — including Microsoft (Microsoft 365, Azure), GitHub, Microsoft Teams, OpenAI, Anthropic, Vercel (website hosting, cookieless analytics, and performance monitoring — vercel.com/legal/privacy-policy), Neon (database hosting for contact-form submissions, Frankfurt EU region — neon.com/privacy-policy), PostHog (consent-based analytics and session replays, EU region — posthog.com/privacy), the corporate password-manager vendor, and Emirates Post (mailing). Each provider is bound by a data-processing agreement and processes personal data only on our instructions and only for the purposes we have authorised.
- Clients — where personal data is part of a deliverable provided to a client, sharing is limited to the named engagement team.
- Authorities — where required by law, regulation, court order, or competent authority.
- Advisors — our legal, accounting, and audit advisors, under confidentiality obligations.
We do not sell, trade, or rent personal data. We do not use personal data to train Large Language Models (LLMs) without specific, informed consent from the data subject or contractual permission from the controller.
6. Cross-Border Transfers
DeepSolve has personnel based in the UAE and offshore locations (current locations are recorded in DST-ISMS-AST-001). Where UAE-origin personal data is processed by personnel based outside the UAE, the transfer is treated as a cross-border transfer under UAE PDPL and DIFC DPL. We rely on contractual safeguards (the Information Security & Confidentiality Addendum signed by all DeepSolve personnel) and on the law of the destination country to provide adequate protection.
Some of our service providers (Microsoft, GitHub, OpenAI, Anthropic) host data in jurisdictions outside the UAE / DIFC. We rely on each provider's published data-processing terms, including the EU Standard Contractual Clauses where they apply, and on DPA/processing addenda where available.
We rely on the following transfer mechanisms under the DIFC DPL: (a) Adequacy (Article 26 DIFC DPL) — for transfers to jurisdictions on the DIFC adequacy list, including the European Economic Area where some of our processors are based (Neon in Frankfurt, PostHog in the EU); (b) DIFC Standard Contractual Clauses (Article 27 DIFC DPL) — for transfers to jurisdictions not on the adequacy list (Microsoft 365, Vercel, GitHub, OpenAI, Anthropic), supplemented by a transfer impact assessment where required. Where you are located in the EEA or the UK, equivalent safeguards (EU SCCs, the UK International Data Transfer Agreement, or recognised adequacy decisions) apply to transfers of your data to these providers.
7. Retention
We retain personal data only as long as necessary for the purpose for which it was collected, plus the period required by law or contract:
- Prospect and marketing contact data — until you ask us to remove it, or 3 years from last contact, whichever is earlier.
- Client engagement data — for the duration of the engagement plus the period required by the engagement contract (typically 7 years for contracts and supporting records).
- Supplier records — for the duration of the relationship plus 5 years.
- Recruitment data — for 12 months for unsuccessful candidates (with consent), and for the duration of employment plus 5 years for successful candidates.
- Website analytics — typically 14 months.
- Contact-form submissions and the IP address stored alongside (for rate limiting) — 12 months from date of submission, after which permanently deleted from the database and cannot be recovered.
- Session replay recordings (PostHog) — 30 days, after which automatically deleted.
- Email notifications of contact-form submissions in our team mailbox — same 12-month retention as the underlying form submission.
Detailed retention is documented in our internal Records Retention Schedule (DST-ISMS-RET-001).
8. Security
We protect personal data using administrative, technical, and physical safeguards proportionate to the sensitivity of the data, including: multi-factor authentication, encryption in transit and at rest, role-based access controls, security awareness training, supplier security review, and an incident response capability. We are pursuing certification to ISO/IEC 27001:2022, the international standard for information security management.
Contact-form submissions are stored in a secure, encrypted PostgreSQL database hosted by Neon in the European Union (Frankfurt). Access is restricted to authorised team members under role-based access controls and secure authentication. Each submission is stored alongside the submitter's IP address, which is used solely for rate limiting and abuse prevention. A notification email containing your submission is sent to our internal team mailbox via Microsoft 365 (Outlook) using encrypted SMTP (TLS); this email is accessible only to authorised team members.
9. Your Rights
Subject to UAE PDPL and DIFC DPL (Articles 32–38 of the DIFC DPL), and where applicable the EU GDPR and UK GDPR, you have rights in relation to your personal data, including:
- Right of access — to know what personal data we hold about you and how we process it.
- Right of rectification — to have inaccurate or incomplete personal data corrected.
- Right to erasure — to have your personal data deleted in certain circumstances.
- Right to restrict or object to processing — including the right to object to direct marketing.
- Right to data portability — to receive your personal data in a structured, machine-readable format.
- Right to withdraw consent — where processing is based on consent.
- Right to lodge a complaint — with the UAE Data Office (under PDPL) or the DIFC Commissioner of Data Protection (commissioner@dp.difc.ae; dp.difc.ae). If you are located in the EEA or the UK, you may also lodge a complaint with the data protection authority in your country of residence.
To exercise any of these rights, please contact us at info@deepsolve.io. We will respond within the timeframes set out in the applicable law (typically 30 days).
10. Cookies and Similar Technologies
Our website uses your browser's localStorage to remember your analytics consent preference (strictly necessary; no consent required). Beyond that, we use a small number of analytics tools — some cookieless under legitimate interests, and one consent-based:
- Cookieless analytics and performance monitoring (Vercel Web Analytics + Vercel Speed Insights): aggregated traffic patterns and site-performance metrics. These tools do not set cookies, do not use localStorage, and do not store personal identifiers; your IP address and User-Agent are processed transiently to derive an anonymised daily-rotating hash and your approximate country. The IP is not stored, and visitors cannot be tracked across days or across sites. Lawful basis: legitimate interests.
- Consent-based detailed analytics and session replays (PostHog): we collect anonymised usage data and record session replays only after you click "Accept" on our consent banner. PostHog uses localStorage (not cookies) for persistence. Session replays capture mouse movements, clicks, and scrolling; all text input into form fields is masked by default to exclude personal data. Replays are retained for 30 days. If you click "Decline" no usage data is collected and no sessions are recorded. Lawful basis: consent.
- You can change your analytics preference at any time by clearing your browser's local storage for this site, which will re-display the consent banner on your next visit.
11. Children
Our services are intended for businesses and professionals. We do not knowingly collect personal data of individuals under 18. If you believe we may have collected such data, please contact us at info@deepsolve.io and we will take steps to delete it.
12. Changes to This Notice
We may update this Privacy Notice from time to time to reflect changes in our processing activities, in technology, or in applicable law. The version date at the top of this Notice indicates when it was last updated. Material changes will be communicated by reasonable means (such as a notice on the website or by direct communication where appropriate).
13. Contact Us
If you have any questions about this Privacy Notice or our handling of personal data, please contact:
- Email: info@deepsolve.io
- Postal: DeepSolve Tech Limited, PO Box DeepSolve – 506983, Dubai, UAE
- Or write to the Founder & ISMS Owner via the contact form on www.deepsolve.io