Privacy

Privacy Policy

Wittify.AI Technologies FZ-LLC

Last updated: May 14, 2025

This Privacy Policy ("Policy") explains how Wittify.AI Technologies FZ-LLC and our affiliates ("Wittify.ai," "we," "our," or "us") collect, use, disclose, and otherwise process Personal Data when individuals ("you," "your," or "users") access or use our platform, websites, mobile or desktop applications, APIs, and related online services (collectively, the "Services").

"Personal Data" means any information relating to an identified or identifiable natural person.

This Policy applies whenever Wittify.ai acts as a data controller. When we process Personal Data solely on behalf of an enterprise customer, we act as a data processor/service provider and that processing is governed by our customer agreements and Data Processing Addendum (the "DPA").

We do not knowingly offer the Services to anyone under 18 years old. If we learn that we have collected Personal Data from a child, we will delete it promptly.

1. Categories of Personal Data We Collect

1(a) Personal Data you provide to us

CategoryTypical examples
Account & Contact DataName, business e-mail, phone, job title, company name, address, preferred language
Authentication DataHashed passwords, SSO tokens, MFA seeds
Payment & Billing DataCardholder name, card last-4, VAT/tax ID (processed by Stripe and local providers)
Voice DataRaw audio uploads, voice recordings, derived voice models, transcripts
Support & CommunicationsHelp-desk tickets, survey responses, event registrations, newsletter sign-ups
Marketing PreferencesOpt-in status, campaign interaction history
Verification / KYC DataGovernment ID, selfie, proof-of-address (only for identity verification features)

1(b) Personal Data we collect automatically

  • Usage & Device DataIP address, browser type, OS version, device identifiers, click-stream events, interaction timestamps.
  • Cookie & Similar Technologies Datasee Section 9 (Cookies).

1(c) Personal Data we receive from third parties

  • OAuth / SSO providerse.g., name, e-mail, profile picture.
  • Payment processorsconfirmation of completed transactions.
  • Analytics & advertising partnersaggregated usage metrics, campaign performance.
  • Public sources & partnersvoice or language datasets licensed for AI research and model training.

2. Purposes of Processing and Legal Bases

PurposeDescriptionLegal Basis
Provide & secure the ServicesSet up accounts, authenticate users, deliver features, provide support, maintain uptime, detect abuseContract; Legitimate Interest (security)
Process paymentsHandle subscriptions, invoices, refunds, tax complianceContract; Legal Obligation
Personalise user experienceRemember settings, recommend features, suggest contentLegitimate Interest (opt-out available)
Train & improve AI modelsRefine ASR, TTS, LLM performanceConsent for identifiable data; Legitimate Interest for de-identified data
Marketing communicationsProduct updates, event invites, surveysConsent (EEA/UK); Legitimate Interest elsewhere
Fraud prevention & KYCVerify identity, screen against sanctions lists, investigate misuseLegitimate Interest; Legal Obligation
Comply with legal requestsRespond to subpoenas, court orders, regulatory enquiriesLegal Obligation

3. Personal Data and Voice Services

When you upload voice recordings, our proprietary AI analyses acoustic patterns to build a voice model. Depending on your jurisdiction, Voice Data may be considered biometric data; we obtain explicit checkbox consent before processing. We do not use Voice Data to infer sensitive traits (e.g., gender identity, health status) and we delete or de-identify Voice Data per Section 6.

4. Sharing and Disclosure

We may disclose Personal Data to:

  • Affiliates under common ownership, subject to this Policy.
  • Service providers / processors who support the Services (hosting, payments, analytics, email delivery, support tooling, error monitoring).
  • Other users if you deliberately publish or share content.
  • Third-party partners for jointly developed features or co-branded events (disclosed at point of collection).
  • Law-enforcement, regulators, courts, or auditors where legally required.
  • Successors in the event of a merger, acquisition, or reorganisation.
  • With your consent for any additional purpose you authorise.

Key Vendors

VendorPurposeLocation
Amazon Web ServicesHosting, databases, storageIreland / Germany / UAE
Google Cloud PlatformHosting, databases, storageSaudi Arabia
GroqAI inference / accelerator nodesSaudi Arabia
Rime LabsLLM / voice APIsUSA
StripePayments & billingUSA / Ireland
Google Analytics 4Usage analyticsUSA
SentryError trackingUSA / EU
PostmarkTransactional e-mailUSA
LivekitWebRTCUSA
Anthropic ClaudeLLM inferenceUSA

We do not sell Personal Data or share it for cross-context behavioural advertising.

5. International Transfers

Primary production workloads run on AWS eu-west-1 (Ireland) with disaster-recovery in eu-central-1 (Frankfurt). Enterprise customers may contract for data-residency in AWS me-central-1 (UAE). For transfers outside the EEA/UK, we rely on 2021 EU Standard Contractual Clauses, the UK International Data Transfer Addendum, and/or the EU-US Data Privacy Framework.

6. Retention of Personal Data

CategoryRetention period
Chat logs & text promptsUntil user deletes or 90 days after account closure
Raw voice recordingsUntil user deletes or 90 days after account closure
Derived voice modelsUntil user deletes or 90 days after account closure
Billing & tax records7 years (statutory)
Inactive accountsAnonymised or deleted after 24 months of no login

User-initiated deletions trigger immediate logical deletion; physical purge from active systems occurs within 30 days and backups within 60 days.

7. Security Measures

  • End-to-end encryption: TLS 1.3 in transit, AES-256 at rest.
  • Role-based access control and mandatory MFA for all employees.
  • Network segmentation, least-privilege IAM, secret-management vault.
  • 24 × 7 intrusion-detection and anomaly monitoring.
  • Annual external penetration testing and vulnerability scanning.
  • ISO 27001 certification and SOC 2 Type I attestation in progress.
  • Voice-model watermarking and abuse-detection heuristics.

8. Your Privacy Rights

Depending on your location, you may have rights to:

  • Access a copy of Personal Data we hold about you
  • Correct inaccurate or incomplete data
  • Delete Personal Data (subject to legal exceptions)
  • Restrict or object to certain processing
  • Data portability
  • Withdraw consent (including model-training or marketing)
  • Opt out of targeted advertising or certain analytics
  • Lodge a complaint with a supervisory authority

Exercise most rights through in-app controls or by e-mailing [email protected].

9. Cookies and Similar Technologies

We use cookies, SDKs, pixels, and local-storage to:

  • Ensure site functionality ("strictly necessary" cookies)
  • Measure traffic and diagnose performance (Google Analytics 4, Sentry, Mixpanel)
  • Provide live chat and account-based messaging
  • Run limited remarketing campaigns

Visitors from the EEA/UK receive a granular consent banner. You can also manage cookies via browser settings.

Our Services may link to or interoperate with third-party sites, plugins, or APIs we do not control. Their privacy practices are governed by their own policies; we encourage you to review those policies before providing information.

11. Children’s Privacy

The Services are not directed to children under 18. Uploading voice recordings of minors or otherwise providing their Personal Data is strictly prohibited. If you believe we have inadvertently processed such data, contact [email protected] and we will delete it.

12. Biometric Information (Voice Data)

Where Voice Data constitutes biometric identifiers under applicable law:

  • We obtain explicit written consent before collection.
  • We use Voice Data solely to provide, secure, and improve voice-based features.
  • We do not disclose Voice Data to third parties other than contracted processors.
  • We store Voice Data for no longer than the period specified in Section 6.
  • We implement reasonable measures to protect Voice Data from unauthorised access.

13. Automated Decision-Making

Wittify.ai does not engage in fully automated decision-making that produces legal or similarly significant effects about individuals.

14. Updates to This Policy

We may revise this Policy from time to time. If we make material changes, we will provide notice (e.g., via e-mail or in-product banner) and update the "Updated" date above. Continued use of the Services after the effective date constitutes acceptance.

15. Contact Us

Wittify.AI Technologies FZ-LLC

IN5 Tech, Dubai Internet City, Dubai, UAE

E-mail: [email protected]

If we are unable to resolve your concerns, you have the right to lodge a complaint with your local data-protection authority.

Thank you for reading our Privacy Policy.