Privacy Policy
Last updated: July 8, 2026
Jump to section
- 1. Introduction
- 2. Data Controller and Processor Roles
- 3. Data We Collect
- 4. Legal Bases for Processing
- 5. How We Use Information
- 6. AI Processing
- 7. Categories of Sub-Processors
- 8. Data Sharing and Disclosure
- 9. Data Storage and Security
- 10. Data Retention
- 11. Cross-Border Data Transfers
- 12. Your Rights
- 13. Cookies and Tracking
- 14. Children's Data
- 15. Data Breach Notification
- 16. Compliance Framework
- 17. Changes to This Policy
- 18. Contact
1. Introduction
Aradus AI Limited ("Aradus", "we", "us", "our") is incorporated in the Dubai International Financial Centre ("DIFC") and is committed to protecting the privacy of individuals whose personal data we process. As a DIFC entity, our processing of personal data is primarily governed by the DIFC Data Protection Law No. 5 of 2020 ("DIFC DP Law"). This Privacy Policy explains how we collect, use, store, and protect personal data in connection with the operation of the Aradus platform and our business activities, in compliance with the DIFC DP Law and, where applicable, the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("UAE PDPL"), the EU General Data Protection Regulation ("GDPR"), the Saudi Arabia Personal Data Protection Law ("Saudi PDPL"), and other applicable data protection legislation.
2. Data Controller and Processor Roles
Aradus acts in two distinct roles depending on the category of data:
- Data Controller for personal data we collect to operate user accounts and deliver the Service — including names, email addresses, authentication credentials, and usage data of platform users.
- Data Processor for the business content our customers upload and process through the platform — including documents, invoices, shipment records, orders, and counterparty contact information. In that role, the customer is the controller, and our processing is governed by the Aradus Data Processing Agreement (available on request for enterprise customers).
For any questions or requests relating to this policy or your personal data, contact us at privacy@aradus.ai.
3. Data We Collect
3.1 Platform Account Data
Required to operate user accounts and provide platform services:
- Name, email address, profile image, and (where you provide it) phone number
- Authentication credentials — hashed password, or OAuth tokens for Google or Microsoft sign-in if you use those providers
- Organisation membership, role, and dashboard preferences
- Session data — IP address, user-agent string, login timestamps
3.2 Customer Content
Business content you upload or generate through the platform — for example, invoices, bills of lading, packing lists, purchase orders, shipment records, supplier and customer contact details, and emails routed through the platform. Aradus processes this content on your behalf as a data processor.
3.3 Usage and Analytics Data
Where you have given consent via our cookie banner, we collect product analytics (page views, feature interactions, session metadata) and anonymous session recordings with form inputs masked, across both our marketing site and the authenticated platform. See section 13 for details.
3.4 Operational Records
Audit logs of significant actions taken in the platform, error logs, and notification delivery logs. These are used for security, debugging, and service-quality purposes.
3.5 Special Categories of Personal Data
We do not intentionally collect or process special categories of personal data (as defined under the DIFC DP Law), such as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic or biometric data, health, or data concerning a person's sex life or sexual orientation. The Aradus platform is a business-to-business tool for supply chain operations and is not designed to process such data.
4. Legal Bases for Processing
We process personal data only where a valid legal basis exists under the applicable law, including the lawful-processing conditions of the DIFC DP Law:
- Performance of a contract: processing required to provide platform access and deliver the Service under our agreement with you or your organisation.
- Legitimate interest: security monitoring, fraud and abuse prevention, platform improvement, and product analytics, balanced against the rights and interests of data subjects. We rely on legitimate interests as a lawful basis under Article 13 of the DIFC DP Law.
- Legal obligation: retaining transactional and tax records as required by applicable financial regulations.
- Consent: for optional analytics, session recording, and direct marketing. Consent may be withdrawn at any time without affecting prior processing.
5. How We Use Information
We use collected information to:
- Operate and maintain the platform and your account
- Classify, extract, and organise the documents you upload
- Track shipments and deliver status notifications
- Reconcile invoices and surface operational insights
- Respond to your support requests
- Improve and develop platform features
- Detect and prevent security incidents and abuse
- Comply with legal and regulatory obligations
6. AI Processing
The Aradus platform uses AI to read, classify, and extract structured data from the documents and emails you process through it, and to power conversational features such as chat. To do this, the relevant content is sent to Google's Gemini API for processing.
- Aradus does not use customer content to train AI models.
- Google's data-handling commitments for the Gemini API are governed by the Gemini API Additional Terms of Service(opens in new tab). We do not warrant Google's behaviour on Google's behalf — please review their terms.
- Where AI output materially affects an automated decision, a human reviewer remains in the loop within the platform's workflow.
7. Categories of Sub-Processors
We engage sub-processors to deliver the Service. Each is contractually bound to obligations no less protective than those in our Data Processing Agreement. Personal data is shared with sub-processors falling within the categories below:
| Category | Purpose |
|---|---|
| Cloud hosting and infrastructure | Application hosting, managed databases, and object storage for customer files |
| AI processing | Document classification, data extraction, and conversational features |
| Email infrastructure | Transactional email delivery and inbound email intake on the platform's notifications domain |
| Shipment-tracking APIs | Tracking of shipments by Bill of Lading and container references |
| Product analytics and session replay | Consent-gated analytics on platform usage, with form inputs masked in session recordings |
| Marketing-site analytics | Consent-gated analytics on visits to our public marketing site |
A current list of named sub-processors is provided to enterprise customers in our Data Processing Agreement on request to privacy@aradus.ai. Material changes to the categories above will be reflected on this page; named-processor changes are notified to enterprise customers per their DPA.
8. Data Sharing and Disclosure
We do not sell, rent, or trade personal data. Personal data is shared only with the sub-processors listed above and where required by law, regulatory order, or to protect the rights, property, or safety of Aradus, our customers, or the public.
In the event of a corporate transaction (merger, acquisition, or sale of assets), personal data may be transferred subject to confidentiality obligations and continued application of this Privacy Policy or an equivalent successor policy.
9. Data Storage and Security
We implement technical and organisational measures appropriate to the risk, including:
- Encryption in transit and at rest using our cloud providers' standard mechanisms
- Role-based access controls and authenticated sessions
- Audit logging of significant platform actions
- Least-privilege service credentials and managed secrets via our hosting provider's secret store
- Multi-tenant isolation at the database and application layers
No security control is absolute. If you believe your account has been compromised, contact us immediately at privacy@aradus.ai.
10. Data Retention
- Platform account data: retained for the life of the account. To delete your account, email privacy@aradus.ai — soft-deletion is applied within 30 days; hard-deletion is performed on written request or as required by law.
- Customer content: retained for the life of the customer's subscription, plus a short window for restoration in the event of accidental deletion. Deletion practices for enterprise customers are governed by the Data Processing Agreement.
- Operational error logs: retained for 90 days, then automatically deleted.
- Billing and tax records: retained as required by applicable financial regulations.
11. Cross-Border Data Transfers
Aradus is incorporated in the DIFC and serves customers in the UAE, the GCC, the United Kingdom, and the European Union. The sub-processors in section 7 may process data outside the data subject's country of residence, including outside the DIFC, the UAE, and the EEA.
Under Article 26 of the DIFC DP Law, transfers to jurisdictions recognised as providing an adequate level of protection (including the European Union/EEA, the United Kingdom, and Ireland) are permitted on that basis.
For transfers to jurisdictions that have not been recognised as adequate, including the United States, we rely on appropriate safeguards under Article 27 of the DIFC DP Law, specifically Standard Contractual Clauses or equivalent vendor data processing agreements pursuant to Article 27(2), together with the data-handling commitments published by each sub-processor. Where the same transfers also fall under the GDPR, UAE PDPL, or Saudi PDPL, we rely on the corresponding safeguards under those frameworks.
Our principal sub-processors, and the categories described in section 7, include Amazon Web Services and Google (the Gemini API and Google Workspace) for cloud hosting and AI processing; Resend for transactional email delivery and inbound email intake; Notion and Slack for internal operations; and PostHog, Google Analytics, and Microsoft Clarity for consent-gated analytics. Several of these process data in the United States under the Article 27 safeguards described above.
Custom data-residency arrangements are available on request as part of enterprise onboarding.
12. Your Rights
Subject to applicable law, data subjects have the following rights under Part 6 of the DIFC DP Law and equivalent provisions of the UAE PDPL, GDPR, and Saudi PDPL:
- Right to be informed about how personal data is collected, used, and shared
- Right of access to personal data we hold about you
- Right to rectification of inaccurate or incomplete data
- Right to erasure where there is no overriding legal basis for continued processing
- Right to restrict or object to processing in defined circumstances
- Right to data portability in a structured, commonly used, machine-readable format
- Right to withdraw consent at any time, where processing is based on consent
- Right not to be subject to a decision based solely on automated processing that significantly affects you
Requests should be directed to privacy@aradus.ai. We aim to respond within 30 calendar days. Where Aradus acts as a data processor on behalf of a customer, requests are routed to the relevant customer (the data controller) for decision.
14. Children's Data
The Aradus platform is a business-to-business service intended for use by professional users acting on behalf of an organisation. It is not directed at, and we do not knowingly collect personal data from, individuals under 18 years of age. If we become aware that we have inadvertently collected such data, we will delete it promptly.
15. Data Breach Notification
In the event of a personal data breach, we will notify the DIFC Commissioner of Data Protection, affected parties, and other relevant supervisory authorities in accordance with the timelines and procedures required by Articles 41 and 42 of the DIFC DP Law and, where applicable, the UAE PDPL, GDPR, and Saudi PDPL, typically without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
16. Compliance Framework
As a DIFC entity, Aradus is primarily governed by the DIFC DP Law, and this policy is designed to comply with:
- DIFC Data Protection Law No. 5 of 2020 ("DIFC DP Law") and its regulations, as our primary data-protection regime
- UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("UAE PDPL")
- EU General Data Protection Regulation ("GDPR"), where applicable to the processing of EU/EEA data subjects' personal data
- Saudi Arabia Personal Data Protection Law ("Saudi PDPL") and its implementing regulations
We have notified the DIFC Commissioner of Data Protection that we process personal data, maintain a Record of Processing Activities, and operate a data-protection compliance programme as required by the DIFC DP Law. We have assessed our processing and determined that we do not carry out High Risk Processing under the DIFC DP Law; accordingly, we are not required to appoint a Data Protection Officer and have not done so, though we keep this assessment under regular review. We monitor regulatory developments and update this policy as needed.
17. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email or through the platform, and the "Last updated" date above will be revised. Your continued use of the Service after a change constitutes acceptance of the updated policy.
18. Contact
For any questions, concerns, or requests regarding this policy or the processing of your personal data, you can reach us by either of the two methods below:
We aim to respond to all enquiries within 30 calendar days.