Privacy Policy

Version: v2026-04 Effective: April 26, 2026 Last Updated: April 26, 2026

This Privacy Policy explains how EEAB Studio Limited ("we", "us", "our") collects, uses, stores, and shares personal data when you use our AI assistant platform. We comply with the EU General Data Protection Regulation (GDPR) and the UAE Personal Data Protection Law (PDPL).

1.Effective Date and Version

This Privacy Policy is version v2026-04, effective from April 26, 2026. It supersedes all previous versions. We will update the version number and effective date whenever we make material changes.

2.Who We Are

EEAB Studio Limited ("EEAB Studio", "we", "us", "our") operates an AI assistant platform that enables business owners to automate customer interactions across messaging channels including WhatsApp, Telegram, email, and webchat.

EEAB Studio Limited (License No. MC 13993) is a company incorporated in the Masdar City Free Zone, Abu Dhabi, United Arab Emirates, with registered address at Smart Station, Incubator Building, Masdar City, Abu Dhabi, UAE. For all privacy-related inquiries, contact us at ceo@eeabstudio.com.

This Privacy Policy applies to all our products and services, including: (a) the EEAB Studio web platform and onboarding form available at eeabstudio.com; and (b) the iOS mobile application "AI Assistant" (bundle identifier com.eeabstudio.aiassistant), which provides Business Owners with administrative access to their EEAB Studio Limited account on mobile devices.

3.What Data We Collect

Our platform processes two distinct categories of data, with different roles and responsibilities under data protection law.

3.1 From Business Owners ("Customers")

When you sign up as a business owner using our platform, we collect:

3.2 From End-Customers of Business Owners

When end-customers interact with the AI assistant deployed by a Business Owner, the following data may be processed:

Important — roles under GDPR: For end-customer data, the Business Owner is the Data Controller and EEAB Studio Limited acts as a Data Processor (Article 28 GDPR). This relationship is governed by a Data Processing Agreement between EEAB Studio Limited and each Business Owner. End-customers wishing to exercise their data subject rights should contact the Business Owner whose service they used; we will assist the Business Owner in fulfilling such requests.

4.How We Use Data

We use the data described above for the following purposes:

5.iOS Mobile Application

This section provides additional disclosures specific to our iOS mobile application "AI Assistant" (bundle identifier com.eeabstudio.aiassistant), as required by Apple App Store guidelines.

5.1 What the App Sends to Our Servers

When you use the App, the following data is transmitted to our backend over HTTPS:

5.2 Third-Party Services Specific to the App

The App itself integrates with the following third-party services. For all AI processing services (OpenAI, Pinecone), the App does not communicate directly; instead, your data is forwarded by our backend, which acts as an intermediary.

5.3 What the App Does NOT Do

We want to be explicit about what the App does not collect or transmit:

5.4 Data Stored on Your Device

The App stores the following data locally on your device, encrypted using the iOS Keychain:

The App does not cache messages, customer data, business documents, or appointments on your device. All such data is held only in memory while the App is running and is cleared when the App is closed.

5.5 Account Deletion

You can delete your account and all associated data at any time from within the App, by going to Settings → Danger Zone → Delete Account. After confirmation, the deletion request is sent to our backend and your account, along with all conversations, customers, appointments, documents, and other tenant data, is permanently removed from our primary systems. Encrypted backups containing the deleted data are purged within 30 days.

5.6 Push Notifications

Push notifications are optional. We request permission after you sign in. If you decline, the App functions normally except that you will not receive real-time alerts about new customer messages or appointment changes. You can revoke push permission at any time from your device's iOS Settings → Notifications → AI Assistant.

5.7 Children's Use of the App

The App is intended for business use by adults aged 18 and over. It is not directed at children, and we do not knowingly process personal data of minors through the App. See Section 12 for more details on Children's Privacy.

6.Third-Party Services

We rely on the following third-party services to operate our platform. For each service, we describe what data is shared, where it is processed, and link to the provider's privacy policy.

6.1 — OpenAI (USA)

Purpose: AI processing — generating responses and creating embeddings for semantic search.

Data shared: Content of end-customer messages and uploaded business documents.

Note: Per the OpenAI API Data Usage Policy, data submitted via the API is not used to train OpenAI's models.

Privacy policy: https://openai.com/policies/privacy-policy

6.2 — Pinecone (USA)

Purpose: Vector storage for semantic search across the business knowledge base.

Data shared: 3072-dimensional embeddings of messages and documents, plus metadata containing the first 1000 characters of each text chunk.

Privacy policy: https://www.pinecone.io/privacy/

6.3 — AWS S3 (India, ap-south-1 / Mumbai region)

Purpose: Secure, durable storage of files uploaded by Business Owners.

Data shared: Original business documents (PDF, DOCX, XLSX, TXT, CSV) and product images.

Privacy policy: https://aws.amazon.com/privacy/

6.4 — Paddle (United Kingdom)

Purpose: Payment processing and Merchant of Record services under PCI-DSS compliance. Paddle acts as the reseller / Merchant of Record for purchases.

Data shared: Transactional and billing data when payments are processed. EEAB Studio Limited does not store full credit card details.

Privacy policy: https://www.paddle.com/legal/privacy

6.5 — Telegram Bot API (Telegram FZ-LLC, UAE)

Purpose: Delivery of messages via Telegram bots configured by Business Owners.

Data shared: Outgoing messages from the AI assistant, incoming messages from end-customers.

Privacy policy: https://telegram.org/privacy

6.6 — 360Dialog (Germany)

Purpose: Delivery of messages via the WhatsApp Business API.

Data shared: WhatsApp Business API credentials and messages exchanged via the Business Owner's WhatsApp Business account.

Privacy policy: https://www.360dialog.com/privacy-policy/

6.7 — Nylas (USA)

Purpose: Integration with email providers (Gmail, Outlook, and similar) so the AI assistant can read and reply to customer emails.

Data shared: OAuth grants for the Business Owner's email accounts; email metadata and content when retrieved.

Privacy policy: https://www.nylas.com/legal/privacy/

6.8 — Google (USA)

Purpose: Address autocomplete (Google Places API), timezone derivation from coordinates (Google TimeZone API), and bot protection on the onboarding form (Google reCAPTCHA v3).

Data shared: Address fragments during typing; location coordinates; reCAPTCHA telemetry signals.

Privacy policy: https://policies.google.com/privacy

6.9 — SMTP (Self-hosted via Nodemailer)

Purpose: Delivery of system-generated transactional emails (e.g., onboarding confirmation, password reset) directly from EEAB Studio Limited's own infrastructure.

Data shared: Business Owner email address and the system message content.

Note: This service is operated by EEAB Studio Limited; no third-party email service receives Business Owner data through this channel.

7.Data Storage and Security

We implement industry-standard technical and organizational measures to protect your data:

8.International Data Transfers

Your data may be transferred to and processed in countries other than your own. The countries involved in our processing are:

For transfers of personal data outside the European Economic Area (EEA), we rely on appropriate safeguards including, where applicable, the European Commission's Standard Contractual Clauses (SCCs) and the providers' own GDPR-compliant frameworks.

9.Your Rights Under GDPR

If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation:

To exercise any of these rights, contact us at ceo@eeabstudio.com. We will respond within 30 days.

Note for end-customers of Business Owners: For data processed under our role as Data Processor, please direct your request to the Business Owner who collected your data. We will assist the Business Owner in fulfilling your request.

10.Your Rights Under UAE PDPL

If you are located in the United Arab Emirates, you have the following rights under Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("UAE PDPL"):

To exercise any of these rights, contact us at ceo@eeabstudio.com.

11.Data Retention

We retain personal data only as long as necessary for the purposes described in this Policy:

12.Children's Privacy

Our Service is intended for business users only and is not directed to individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact us at ceo@eeabstudio.com and we will delete such data promptly.

13.Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will:

Continued use of the Service after the effective date of an updated Policy constitutes acceptance of the changes. A history of previous versions is available upon request at ceo@eeabstudio.com.

14.Contact Us

For privacy-related questions, requests, or complaints, please contact:

EEAB Studio Limited

Email: ceo@eeabstudio.com

Postal Address: Smart Station, Incubator Building, Masdar City, Abu Dhabi, UAE

License: MC 13993, Masdar City Free Zone