Who we are
Sayfitech Ltd ("Sayfitech", "we", "us", "our"), trading as SAYFI, is a private company incorporated in the Dubai International Financial Centre under the Companies Law, DIFC Law No. 5 of 2018, on 2025-06-18. Our registered office is at Unit IH-00-01-03-OF-05, Level 3, Innovation Hub, Dubai International Financial Centre, Dubai, United Arab Emirates. We meet visitors at Fountain Views Tower 2, Downtown Dubai, Dubai, United Arab Emirates. We design and build software, automation, data and growth infrastructure for clients internationally under commercial licence CL10697.
For the processing described in this notice, Sayfitech is the Controller: we determine the purposes for which, and the means by which, personal data is processed.
- Controller
- Sayfitech Ltd
- Trading name
- SAYFI
- Jurisdiction of registration
- Dubai International Financial Centre
- Registered number
- 10697
- Commercial licence
- CL10697
- Registered office
- Unit IH-00-01-03-OF-05, Level 3, Innovation Hub, Dubai International Financial Centre, Dubai, United Arab Emirates
- Operating address
- Fountain Views Tower 2, Downtown Dubai, Dubai, United Arab Emirates
- Data protection contact
- privacy@sayfi.ai
- General enquiries
- info@sayfi.ai
Data protection matters are handled by our data protection contact, who is reachable at privacy@sayfi.ai. Correspondence sent to that address is treated as a formal privacy request and logged as such.
What this notice covers
This notice applies to personal data we process:
- when you visit this website;
- when you contact us, or we contact you, about work;
- in the course of an engagement with a client, supplier or partner organisation, including personal data about that organisation's personnel;
- in the operation of our own business, accounting, record-keeping and the defence of legal claims.
It does not apply to:
- personal data we process on behalf of a client in systems we build or operate for them. There, the client is the controller and their own privacy notice governs; our role is described in Processing on behalf of clients.
- third-party websites we link to. Their operators publish their own notices and we are not responsible for them.
The law we apply
We are a DIFC entity with an international client base, so more than one data protection regime is capable of applying to us. We apply, as relevant to each activity:
- DIFC Data Protection Law, DIFC Law No. 5 of 2020, and the Data Protection Regulations issued under it. This is our primary regime. The supervisory authority is the Commissioner of Data Protection of the DIFC.
- Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the UAE PDPL), where a processing activity falls within its scope rather than the DIFC regime.
- Regulation (EU) 2016/679 (the GDPR) and the UK GDPR together with the Data Protection Act 2018, in respect of personal data of individuals in the EEA and the United Kingdom where our processing is caught by their territorial scope.
Where more than one regime applies to the same processing, we apply the standard that affords you the greater protection. References in this notice to a right or an obligation are to be read as references to the equivalent provision under whichever of those laws applies to you.
Personal data we collect, and where it comes from
We collect the minimum needed for the purpose at hand. We do not collect special categories of personal data, health, biometric, genetic, religious, political or similar, and we ask you not to send them to us.
| Category | Examples | Source |
|---|---|---|
| Identity and contact data | Name, job title, employing organisation, business email address, telephone number | You, or a colleague at your organisation |
| Correspondence | The content of emails, messages and calls, meeting notes, and the record of our exchanges | You |
| Engagement data | Requirements, scope documents, approvals, feedback, and credentials issued to us for the duration of a project | You and your organisation |
| Billing data | Billing entity and address, tax registration number, purchase order and payment references | You and your organisation |
| Technical data | IP address, date and time of request, requested URL, referring page, browser and device type, response status | Generated automatically by our hosting infrastructure when you visit this website |
| Audience measurement data | The page viewed, the referring page, country, device type, browser and operating system, and a short-lived hash used to count a visit once | Generated by cookieless analytics on this website; nothing is stored on your device |
| Interaction data | A reconstruction of your visit: the pages viewed, clicks, taps, scrolling and pointer movement, the referring page, an approximate location derived from your IP address, device type, screen size, browser and operating system, and a pseudonymous identifier that lets the same browser be recognised on a later visit | Generated by Microsoft Clarity, a third-party analytics script embedded in this website |
| Preference data | The interface language you selected | Set by this website when you choose a language |
| Business contact data | Name, role, employer and business contact details of people at organisations we believe may need our services | Public company sources and professional networks |
- Category
- Identity and contact data
- Examples
- Name, job title, employing organisation, business email address, telephone number
- Source
- You, or a colleague at your organisation
- Category
- Correspondence
- Examples
- The content of emails, messages and calls, meeting notes, and the record of our exchanges
- Source
- You
- Category
- Engagement data
- Examples
- Requirements, scope documents, approvals, feedback, and credentials issued to us for the duration of a project
- Source
- You and your organisation
- Category
- Billing data
- Examples
- Billing entity and address, tax registration number, purchase order and payment references
- Source
- You and your organisation
- Category
- Technical data
- Examples
- IP address, date and time of request, requested URL, referring page, browser and device type, response status
- Source
- Generated automatically by our hosting infrastructure when you visit this website
- Category
- Audience measurement data
- Examples
- The page viewed, the referring page, country, device type, browser and operating system, and a short-lived hash used to count a visit once
- Source
- Generated by cookieless analytics on this website; nothing is stored on your device
- Category
- Interaction data
- Examples
- A reconstruction of your visit: the pages viewed, clicks, taps, scrolling and pointer movement, the referring page, an approximate location derived from your IP address, device type, screen size, browser and operating system, and a pseudonymous identifier that lets the same browser be recognised on a later visit
- Source
- Generated by Microsoft Clarity, a third-party analytics script embedded in this website
- Category
- Preference data
- Examples
- The interface language you selected
- Source
- Set by this website when you choose a language
- Category
- Business contact data
- Examples
- Name, role, employer and business contact details of people at organisations we believe may need our services
- Source
- Public company sources and professional networks
Why we process it, and on what lawful basis
Every purpose below is tied to a lawful basis. Where we rely on legitimate interests, those interests are set out in Our legitimate interests.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Responding to an enquiry and preparing a proposal | Identity and contact data, correspondence | Steps taken at your request prior to entering a contract; our legitimate interests in responding to enquiries about our services |
| Delivering an engagement and managing the relationship | Identity and contact data, correspondence, engagement data | Performance of a contract where you contract with us personally; otherwise our legitimate interests in performing the contract with your organisation |
| Invoicing, collecting payment and maintaining accounts | Billing data, identity and contact data | Performance of a contract; compliance with a legal obligation under applicable tax and accounting law |
| Operating, securing and improving this website | Technical data | Our legitimate interests in keeping the website available, performant and protected against abuse |
| Understanding, in aggregate, which pages are read | Audience measurement data | Our legitimate interests in knowing which parts of the site are useful; the measurement is cookieless, stores nothing on your device and does not identify you |
| Seeing how a page is used, and where a reader gets stuck | Interaction data | Our legitimate interests in fixing a page once we can see how it is read; the cookies this involves are not strictly necessary, and the Cookie Policy sets out where they are set and how to refuse them |
| Serving the website in the language you chose | Preference data | Necessary to deliver a function you asked for; the cookie is strictly necessary for that function |
| Sending material you have asked to receive | Identity and contact data | Your consent, which you may withdraw at any time |
| Contacting organisations about services relevant to them | Business contact data | Our legitimate interests in developing business relationships in a business-to-business context |
| Establishing, exercising or defending legal claims, and responding to regulators | Any of the above, as relevant | Our legitimate interests in protecting our position; compliance with a legal obligation |
- Purpose
- Responding to an enquiry and preparing a proposal
- Data used
- Identity and contact data, correspondence
- Lawful basis
- Steps taken at your request prior to entering a contract; our legitimate interests in responding to enquiries about our services
- Purpose
- Delivering an engagement and managing the relationship
- Data used
- Identity and contact data, correspondence, engagement data
- Lawful basis
- Performance of a contract where you contract with us personally; otherwise our legitimate interests in performing the contract with your organisation
- Purpose
- Invoicing, collecting payment and maintaining accounts
- Data used
- Billing data, identity and contact data
- Lawful basis
- Performance of a contract; compliance with a legal obligation under applicable tax and accounting law
- Purpose
- Operating, securing and improving this website
- Data used
- Technical data
- Lawful basis
- Our legitimate interests in keeping the website available, performant and protected against abuse
- Purpose
- Understanding, in aggregate, which pages are read
- Data used
- Audience measurement data
- Lawful basis
- Our legitimate interests in knowing which parts of the site are useful; the measurement is cookieless, stores nothing on your device and does not identify you
- Purpose
- Seeing how a page is used, and where a reader gets stuck
- Data used
- Interaction data
- Lawful basis
- Our legitimate interests in fixing a page once we can see how it is read; the cookies this involves are not strictly necessary, and the Cookie Policy sets out where they are set and how to refuse them
- Purpose
- Serving the website in the language you chose
- Data used
- Preference data
- Lawful basis
- Necessary to deliver a function you asked for; the cookie is strictly necessary for that function
- Purpose
- Sending material you have asked to receive
- Data used
- Identity and contact data
- Lawful basis
- Your consent, which you may withdraw at any time
- Purpose
- Contacting organisations about services relevant to them
- Data used
- Business contact data
- Lawful basis
- Our legitimate interests in developing business relationships in a business-to-business context
- Purpose
- Establishing, exercising or defending legal claims, and responding to regulators
- Data used
- Any of the above, as relevant
- Lawful basis
- Our legitimate interests in protecting our position; compliance with a legal obligation
Our legitimate interests
Where we rely on legitimate interests we have carried out a balancing assessment: we identified the interest, tested whether the processing is necessary to achieve it, and weighed it against your interests, rights and freedoms. The interests we rely on are:
- responding to people who approach us, and approaching organisations about work we can do for them;
- performing and administering contracts entered into with organisations, which necessarily involves processing data about their personnel;
- keeping accurate business records;
- keeping this website and our systems secure and available, and understanding which parts of the site are read and how they are used;
- protecting our legal position, including establishing, exercising and defending claims.
In each case the processing is limited to business contact information used in a business context, it is what a professional would reasonably expect, and it does not involve sensitive data, profiling or automated decision-making. You may object at any time, see Your rights. If you object to business development contact, we will stop and record the objection so we do not contact you again.
What this website actually collects
This website is a publication, not a product. It has no user accounts and no advertising, and it does not build a profile of you.
- Cookieless page counting. We count page views so we know which pages are read. That measurement sets no cookie, writes nothing to your device, and carries no identifier that could recognise you here or anywhere else.
- Heatmaps and session replay. We run Microsoft Clarity, which records how a page is used: clicks, taps, scrolling, pointer movement and the order you moved through the site in. A replay is a reconstruction of the page and those interactions, not a recording of your screen, and Clarity's masking is left on so the text you type into form fields is not captured. It exists so we can find the paragraph nobody reads and the button nobody finds.
- One third-party script. Clarity is served by Microsoft from
clarity.ms, so loading a page here does cause your browser to contact Microsoft. Everything else, fonts, images, our own scripts and the page-view counter, is served from our own domain. - Three cookies.
NEXT_LOCALEremembers the interface language you selected. Clarity sets two more so your page views read as one visit, except for visitors in the EEA, the United Kingdom and Switzerland, where it sets none because we send it no consent signal. Every one of them, and the cookies Microsoft sets on its own domains, is named in the Cookie Policy. - No advertising or social tracking by us. There are no advertising pixels, no conversion tags, no social media plugins, and nothing here is used to sell you something elsewhere. Microsoft does set its own cookies when Clarity loads, and one of them is an identifier it uses across its own sites, including for advertising there. We cannot read it, and the Cookie Policy names it.
- Server logs. Our hosting provider records standard request logs so the site can be delivered and protected against abuse.
Clarity is the only place where this site depends on another company to work, and we would rather say so in the first paragraph than bury it in a vendor list. If we add anything else that stores information on your device or sends it to a third party, we will update this notice and the Cookie Policy before the change goes live.
Processing on behalf of clients
Much of our work involves building and operating systems that process personal data for which our client, not Sayfitech, is the controller. In that role we are a Processor. We:
- act only on the client's documented instructions;
- enter into a written data processing agreement before the processing begins;
- impose equivalent obligations on any sub-processor and remain responsible for their performance;
- bind our personnel to confidentiality;
- assist the client in responding to data subject requests, in securing the processing, and in meeting their breach notification and impact assessment obligations;
- return or delete the personal data at the end of the engagement, save where we are required to retain a copy by law.
If you are an individual whose data is held in a system we operate for a client, please direct your request to that client. If you send it to us, we will pass it on promptly and tell you that we have done so.
Who we share personal data with
We do not sell personal data, and we do not disclose it to third parties for their own marketing. We share it only with the following categories of recipient, and only so far as necessary:
- Cloud hosting and content delivery providers, who host this website and our working systems, and who count page views for us in aggregate.
- Microsoft, which operates the Clarity service that produces the heatmaps and session replays described in What this website actually collects.
- Business email, storage and productivity providers, which hold our correspondence and project documents.
- Accounting, audit and tax advisers, and our banking and payment providers, for invoicing and statutory reporting.
- Professional and legal advisers, where we need advice or must establish or defend a claim.
- Specialist subcontractors, engaged under written confidentiality and data protection terms where a project requires a capability we do not hold in-house.
- Courts, regulators and public authorities, where disclosure is required by law or by an order binding on us.
- A buyer or successor, in the event of a reorganisation, merger or sale of the business or its assets, subject to equivalent protections.
Each provider acts under a written contract that restricts them to processing on our instructions. A current list of the processors we use is available on request from privacy@sayfi.ai.
International transfers
We are established in the DIFC, our clients are international, and some of our providers are located outside the DIFC and outside the United Arab Emirates. Personal data may therefore be transferred across borders. Every such transfer is made on one of the following bases:
- the destination jurisdiction has been assessed as providing an adequate level of protection under Article 26 of the DIFC Data Protection Law;
- otherwise, appropriate safeguards under Article 27 of that Law, contractual clauses, including the standard clauses published by the Commissioner, or binding corporate rules;
- for personal data protected by the GDPR, the standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/914; for personal data protected by the UK GDPR, the UK International Data Transfer Agreement or Addendum. In each case we carry out a transfer risk assessment and apply supplementary measures where the assessment calls for them;
- in narrow cases, a statutory derogation, your explicit consent, necessity for a contract concluded in your interest, or the establishment, exercise or defence of legal claims.
You may request a copy of the safeguards we rely on for a particular transfer by writing to privacy@sayfi.ai. We may redact commercially confidential terms.
How long we keep it
We keep personal data only for as long as we need it for the purpose it was collected for, then delete it or irreversibly anonymise it. Our standard periods are:
| Record | Retention period | Why |
|---|---|---|
| Enquiries that do not result in an engagement | 24 months from the last contact | So we hold the context of a conversation that may resume, and can evidence how a contact reached us |
| Client contracts and engagement records | 6 years after the engagement ends | Limitation periods and the defence of legal claims |
| Accounting, invoicing and tax records | The period required by applicable UAE tax and accounting legislation | Compliance with a legal obligation |
| Records of consent and of its withdrawal | 24 months after consent is withdrawn | To demonstrate that we honoured the withdrawal |
| Objections and erasure requests | For as long as needed to keep honouring them | A suppression record is the only way to guarantee we do not contact you again |
| Website server logs | A short period set by our hosting provider | Security, abuse prevention and service availability |
| Audience measurement data | Held in aggregate by our analytics provider for the window its service retains; the hash used to count a visit is short-lived and is never stored against you | It exists to count a visit, not to recognise a visitor |
| Interaction data held by Clarity | 30 days for session replays, 9 months for heatmaps and aggregate click data. The periods are Microsoft's and we cannot shorten them | It answers a question about the current version of a page, and stops being useful once the page changes |
| Language preference cookie | Until you close your browser | It exists only for the duration of your visit |
- Record
- Enquiries that do not result in an engagement
- Retention period
- 24 months from the last contact
- Why
- So we hold the context of a conversation that may resume, and can evidence how a contact reached us
- Record
- Client contracts and engagement records
- Retention period
- 6 years after the engagement ends
- Why
- Limitation periods and the defence of legal claims
- Record
- Accounting, invoicing and tax records
- Retention period
- The period required by applicable UAE tax and accounting legislation
- Why
- Compliance with a legal obligation
- Record
- Records of consent and of its withdrawal
- Retention period
- 24 months after consent is withdrawn
- Why
- To demonstrate that we honoured the withdrawal
- Record
- Objections and erasure requests
- Retention period
- For as long as needed to keep honouring them
- Why
- A suppression record is the only way to guarantee we do not contact you again
- Record
- Website server logs
- Retention period
- A short period set by our hosting provider
- Why
- Security, abuse prevention and service availability
- Record
- Audience measurement data
- Retention period
- Held in aggregate by our analytics provider for the window its service retains; the hash used to count a visit is short-lived and is never stored against you
- Why
- It exists to count a visit, not to recognise a visitor
- Record
- Interaction data held by Clarity
- Retention period
- 30 days for session replays, 9 months for heatmaps and aggregate click data. The periods are Microsoft's and we cannot shorten them
- Why
- It answers a question about the current version of a page, and stops being useful once the page changes
- Record
- Language preference cookie
- Retention period
- Until you close your browser
- Why
- It exists only for the duration of your visit
Where no fixed period is stated, we set retention by reference to the nature and sensitivity of the data, the purpose it serves, the risk of harm from unauthorised use, whether the purpose can be achieved by other means, and the limitation periods and statutory retention rules that apply.
How we protect it
We maintain technical and organisational measures appropriate to the risk, which we review as our systems change. In general terms they include:
- access granted on a need-to-know basis, with multi-factor authentication on the systems that hold personal data;
- encryption in transit, and encryption at rest where the platform supports it;
- least-privilege, time-limited credentials on client systems, revoked at the end of an engagement;
- separation of production data from development and test environments;
- written confidentiality and security obligations on personnel and subcontractors;
- logging and monitoring, and a documented process for assessing and responding to security incidents.
If a personal data breach occurs, we assess it without undue delay and notify the Commissioner of Data Protection and, where the breach is likely to result in a high risk to you, notify you directly, in each case within the timeframes the applicable law requires.
No transmission over the internet is completely secure. Ordinary email in particular is not a secure channel: please do not send us confidential or sensitive information by unencrypted email, and ask us for a secure channel if you need one.
Automated decision-making and profiling
We do not make decisions about you that produce legal effects concerning you, or similarly significantly affect you, based solely on automated processing. We do not profile you for advertising, scoring or evaluation purposes.
We do build artificial intelligence and automation systems for clients. Where such a system processes personal data, the client determines its purpose and we act as processor, and we support the client in meeting the additional requirements the DIFC regime places on autonomous and semi-autonomous processing.
Children
Our services are offered to organisations, not to individuals under 18, and this website is not directed at children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, write to privacy@sayfi.ai and we will delete it.
Your rights
Subject to the conditions and exemptions in the applicable law, you have the following rights over your personal data:
- Access. To be told whether we process personal data about you and, if we do, to receive a copy of it together with information about the processing.
- Rectification. To have inaccurate personal data corrected and incomplete data completed.
- Erasure. To have personal data deleted where it is no longer necessary for the purpose it was collected for, where you withdraw the consent it relied on, where you successfully object, or where it has been processed unlawfully.
- Restriction. To have processing limited to storage while a dispute about accuracy, lawfulness or an objection is resolved.
- Portability. To receive the personal data you gave us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible, when the processing is based on consent or contract and carried out by automated means.
- Objection. To object at any time to processing based on our legitimate interests, on grounds relating to your particular situation. Where you object to direct marketing, the right is absolute and we will stop immediately.
- Withdrawal of consent. To withdraw consent at any time, where consent is the basis we rely on. Withdrawal does not affect the lawfulness of processing carried out before it.
- Automated decisions. Not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, and to obtain human intervention where such a decision is made.
- Complaint. To lodge a complaint with a supervisory authority, see Complaints.
These rights are not absolute. Where an exemption applies, or where a right does not extend to the processing in question, we will tell you which one and why.
How to exercise your rights
Write to privacy@sayfi.ai. Tell us which right you are exercising and, where it helps, what the request relates to. You do not need to use a particular form of words.
- Verification. We will ask for information sufficient to satisfy us of your identity before we act, so that we do not disclose personal data to the wrong person. If you are acting for someone else, we will ask for evidence of your authority.
- Cost. There is no charge. We may charge a reasonable fee, or decline to act, only where a request is manifestly unfounded or excessive, in particular because it is repetitive, and we will explain our reasoning if that ever arises.
- Timing. We respond within one month of receipt. Where a request is complex, or where you have made a number of requests, we may extend that period by up to two further months; if we do, we will tell you within the first month and explain why.
- Outcome. We will confirm what action we have taken. If we decline a request, we will tell you why and how you can challenge that decision.
Complaints
If you are unhappy with how we have handled your personal data or your request, tell us first at privacy@sayfi.ai. We would rather resolve it directly, and a complaint to us does not affect your right to go to a regulator.
You may complain to:
- the Commissioner of Data Protection of the DIFC, the supervisory authority for our jurisdiction, through the contact channels published by the DIFC's Office of the Commissioner of Data Protection;
- if you are in the EEA, the supervisory authority of the country where you live or work, or where you believe the infringement took place;
- if you are in the United Kingdom, the Information Commissioner's Office;
- if the UAE federal regime applies to the processing, the UAE Data Office.
Changes to this notice
The version in force is always the one published at this address, with its date shown at the top of the page. We keep previous versions and will provide one on request.
Where we make a change that materially affects how we use your personal data, and we hold contact details for you in an ongoing relationship, we will take reasonable steps to tell you directly rather than relying on you to check this page.
Language
This notice is published in English. Any translation is provided for convenience only; in the event of a conflict or inconsistency, the English text prevails.