Privacy Policy
This Privacy Policy explains how ABUSE TECH - FZCO, a free zone company registered with the International Free Zone Authority (IFZA), Dubai Digital Park, Dubai, United Arab Emirates (“we”, “us”) collects, uses, and protects personal data when you use Nxor at https://nxor.ai (the “Service”). ABUSE TECH - FZCO is established in the IFZA free zone and is subject to the federal PDPL (it is not established in the DIFC or ADGM financial free zones). We act as the data controller for the personal data described here. For personal data we process on behalf of business customers (Inputs and Outputs containing third-party personal data), our Data Processing Addendum applies.
We comply with the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and its implementing regulations (the “PDPL”), as supervised by the UAE Data Office, and, where the Service is offered to users in the European Economic Area or the United Kingdom, with the General Data Protection Regulation (“GDPR”) and UK GDPR.
1. Data We Collect
- Account data — name, email address, password (hashed), and account settings.
- Subscription and billing data — your plan, billing history, and limited payment confirmation data. Payment card details are collected and processed by Paddle, our Merchant of Record; we do not store your full card number.
- Input and Output — the prompts, files, and data you submit, and the content the Service generates in response. See Section 4 for how we handle AI processing.
- Usage data — features used, Token consumption, logs, timestamps, and interaction data.
- Device and technical data — IP address, browser type, device identifiers, and similar information collected via cookies and similar technologies (see our Cookie Policy).
- Communications — messages you send to support and related correspondence.
2. How We Use Your Data
We use personal data to: provide, operate, and secure the Service; create and manage your Account; process Subscriptions and confirm payments via Paddle; meter and enforce Token usage and fair-use limits; route Inputs to AI Providers and return Output; provide customer support; detect, prevent, and investigate fraud, abuse, and security incidents; comply with legal obligations; and improve and develop the Service.
3. Legal Bases (GDPR)
Where GDPR applies, we rely on: performance of a contract (to provide the Service you subscribe to); legitimate interests (security, fraud prevention, service improvement, analytics, balanced against your rights); consent (for non-essential cookies and any optional communications); and legal obligation (tax, accounting, compliance). Under the PDPL we process personal data on comparable bases, including your consent and the necessity to perform the contract.
4. How We Handle Inputs, Outputs, and AI Processing
To generate Output, your Input is transmitted to the relevant third-party AI Provider and processed by their model. Each AI Provider processes data under its own terms and privacy practices.
We do not use the content of your Inputs or Outputs to train our own models, and we contract with AI Providers on terms intended to limit their use of your content to delivering the Service. We may process Inputs and Outputs to operate, secure, debug, and enforce policies (for example, automated safety filtering). Please do not submit sensitive personal data, confidential information, or content you are not authorised to share.
6. International Transfers
We and our service providers may process data outside the UAE, including in the EEA and other countries. Where we transfer personal data internationally, we use safeguards required by the PDPL and, for GDPR-covered transfers, mechanisms such as Standard Contractual Clauses or transfers to adequate jurisdictions.
7. Data Retention
We retain personal data for as long as your Account is active and as needed to provide the Service, then for the period required to comply with legal, tax, accounting, and dispute-resolution obligations. Inputs and Outputs may be retained for a limited period to operate and secure the Service and are deleted or anonymised thereafter, subject to law.
8. Security
We implement technical and organisational measures appropriate to the risk, including encryption in transit, access controls, and monitoring. Where a personal data breach occurs, we will notify the UAE Data Office and, where required, affected individuals without undue delay and, where feasible, within 72 hours in line with UAE Data Office guidance. No system is completely secure, and we cannot guarantee absolute security.
9. Your Rights
Subject to the PDPL and, where applicable, GDPR, you may have the right to: access your personal data; correct inaccurate data; request erasure; restrict or object to processing; withdraw consent; request data portability; and lodge a complaint with the competent supervisory authority (the UAE Data Office under the PDPL, or your local data protection authority under GDPR). To exercise these rights, contact [email protected]. We will respond within the timeframes required by applicable law.
10. Children
The Service is not directed to, and we do not knowingly collect personal data from, anyone under 18. If you believe a minor has provided us personal data, contact [email protected] and we will delete it.
12. Changes to This Policy
We may update this Policy from time to time. We will post the updated version with a new “Last updated” date and, for material changes, provide additional notice.
13. Contact
ABUSE TECH - FZCO — IFZA, Dubai Digital Park, Dubai, United Arab Emirates. Privacy enquiries: [email protected] · Support: [email protected]