Privacy Policy
Last updated 2026-09-26
This policy explains how Lenouar Artificial Intelligence Developing Services LLC handles personal data in connection with ValiCrew. It is written to the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL).
Two different roles, and why it matters
ValiCrew involves personal data in two distinct ways, and our obligations differ in each.
Data we handle for ourselves — we are the controller. Your account details, the name and email of the people who administer your workspace, billing records, support correspondence, and website visit data. We decide why and how this is used.
Workforce data you put into ValiCrew — you are the controller, we are the processor. Your employees' names, identity documents, salaries and schedules are yours. You decide what to collect and why; we hold and process it on your instructions and nothing more. Those instructions are set out in the Data Processing Agreement.
The rest of this policy is mostly about the first role. If you are an employee of a ValiCrew customer and want to know what is held about you, read the Worker Privacy Notice and speak to your employer — they control that data, not us.
What we collect as controller
When you create a workspace: company name, subdomain, administrator name and email address, plus any optional mobile number you choose to provide, and the password you set (stored hashed, never in readable form). A supplied mobile number is normalized and encrypted. We use it for account and service contact; it is not a workforce record and is not permission to send promotions.
If you choose marketing contact at signup: we record your separate consent to receive product and offer information by phone, SMS or WhatsApp, including when, where and under which notice version you consented. The checkbox is optional and never selected for you. You can withdraw that consent at any time by contacting [email protected]; withdrawal does not affect your workspace or ordinary account/service messages.
If you sign in with Microsoft or Google: your name, email address and the account identifier from that provider. We do not receive your password.
When you subscribe: billing name, address, tax registration number and invoice history. Card details go directly to Stripe — they never reach our systems.
When you contact us: whatever you put in the message. If you request a live product demo, we collect your name, company, work email, optional phone number and preferred time so we can arrange and deliver that meeting. These fields are encrypted at rest. Supplying a phone number on this form does not give marketing consent. If you arrived through a signed outreach link, we may connect the request to that existing campaign record so we can understand which invitation led to the request; this identifiable record remains in Outreach and never enters anonymous website analytics.
When you explore a sample workspace: we do not ask for a name, email, phone number or company. After a bot check, ValiCrew opens a private, temporary workspace under an ordinary authenticated session, using fictional data. We record only coarse allocation outcomes such as requested, workspace allocated, temporarily unavailable or system failure. We do not instrument clicks or product usage inside the authenticated sample workspace. The workspace and its changes are automatically erased when its time limit ends. Do not enter real personal, confidential or business information there.
When you use the in-app widget: suggestions you post to the shared ideas board (shown to other customers without your name or company), support tickets, and any screen recording you choose to make. A recording captures what was on your screen, which in this application will usually include real personal data about your workers — so we treat recordings as your workspace data under the DPA, and delete them once the issue is resolved. Feedback, Suggestions & Recordings explains this properly, and is worth reading before you record anything.
When you visit valicrew.com: standard security server logs (IP address, browser and pages requested) and the Cloudflare Turnstile check that keeps automated signups out. On the landing pages, Field Notes, how-to guides, free tools, signup journey, live-demo request and sample-workspace entry pages we also run our own first-party website measurement. It uses a random browser-tab identifier held in session storage to count sessions, page views, trusted engagement, active visible time, selected calls to action (including download-button clicks) and coarse signup stages and outcomes. Free-tool inputs and calculated results are never included in this measurement. Those outcomes distinguish page opened, details reached, submitted, validation failure, bot-check failure, system failure and completion. Demo measurement similarly distinguishes a form opening, submission, recorded request, allocation, temporary pool unavailability and system failure. These events never include a submitted value, field name, account, workspace, raw error or individual-session report. We keep only a referring hostname and validated campaign labels, never a referring path, query string, form value or a persistent visitor identity. The identifier expires when that tab closes and cannot recognise a return visit. This measurement runs in ValiCrew's UAE infrastructure and uses no third-party analytics or advertising tracker. See the Cookie Notice.
When you follow a signed outreach link: the outreach record is separate from anonymous website measurement. We associate the click with the campaign recipient and temporarily retain its IP address and browser user-agent to identify automated corporate link scanners and investigate abuse. Those two diagnostic fields are removed after 30 days; the campaign event and derived scanner flag remain as marketing history.
Why we use it, and on what basis
| Purpose | Basis |
|---|---|
| Providing the service you signed up for | Performance of a contract |
| Taking payment and issuing invoices | Performance of a contract, and legal obligation |
| Security, abuse prevention and audit logging | Legitimate interest, and legal obligation |
| Service notices about your account | Performance of a contract |
| Answering your support requests | Performance of a contract |
| Arranging and delivering a live product demo you requested | Steps you asked us to take before a contract |
| Operating an abuse-protected, temporary sample workspace | Legitimate interest |
| Understanding which public pages, signup steps and demo options are useful | Legitimate interest |
| Optional product and offer contact by phone, SMS or WhatsApp | Your consent |
We do not sell personal data. We do not use your workspace data to train AI models, and we do not use it to build any product other than the service you are paying for.
Where data is stored
The ValiCrew application, its database and its backups run on Oracle Cloud Infrastructure in Abu Dhabi, United Arab Emirates. Your workspace data stays in the UAE.
A limited number of supporting services operate outside the UAE — payment processing, platform email, minimized private-channel operational alerts and bot protection. Telegram alerts contain workspace-level lifecycle facts only: they exclude names, contact details, customer identifiers, meeting links and private notes, while free text is masked and truncated before it leaves ValiCrew. These services are listed with their purpose and location in the Sub-processors page. Transfers to them are limited to what the service requires, are protected by contractual safeguards with each provider, and are made on the bases permitted by PDPL Articles 22 and 23.
Connected storage: Microsoft 365 and Google Drive
You can connect your own SharePoint or Google Drive so that uploaded documents are stored in your tenancy rather than ours. When you do:
- files go directly to your storage; the platform holds only metadata and a file reference
- for Google, we request the
drive.filescope only. This is the narrowest Drive permission available: the application can see and manage only the files it creates, and has no visibility of anything else in your Drive - for Microsoft, access is limited to the site and library you choose
- the credential we retain (a Google refresh token) is encrypted at rest and destroyed when you disconnect
Limited use. ValiCrew's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, we do not sell it, and we do not allow humans to read it except with your explicit permission, for security purposes, to comply with applicable law, or where the data has been aggregated and anonymised.
More detail is in Customer Data & Storage.
How long we keep it
Account and billing records, including the billing owner's contact details, are kept while your workspace is active and for as long as UAE accounting and tax law requires afterwards. Marketing consent and withdrawal evidence is kept as needed to prove and honour your choice. Workforce data inside your workspace is governed by your own retention setting and by the Data Retention & Deletion policy.
Anonymous public journey events are retained for 30 days. Daily totals by page, acquisition source, locale and coarse device class are retained for 13 months; they contain no tab identifier or individual journey. Raw outreach click IP addresses and user-agent strings are retained for 30 days. Inactive live-demo request and contact details are retained for no more than 183 days after their last activity or elapsed lifecycle, then purged while non-identifying lifecycle and audit facts remain. Provider event identifiers and meeting links are purged 30 days after the scheduled time. Disposable sample workspaces expire after 30 minutes of inactivity or after 90 minutes at the latest; their schemas and authenticated sessions are then removed. A minimized, non-identifying allocation ledger is retained for 30 days to operate the pool and investigate abuse.
How we protect it
Encryption in transit and at rest, per-tenant data isolation, role-based access, audit logging, encrypted daily backups with tested restores, and malware scanning of every uploaded file. The Security Policy sets this out properly.
Your rights
Under PDPL you can ask us to give you a copy of your personal data, correct it, delete it, restrict or object to how it is used, or provide it in a portable format. You can also withdraw consent where consent was the basis.
Write to [email protected]. We will respond within the period the law allows and will ask you to verify your identity first.
If your request concerns data held inside a customer's workspace — because you work for a company that uses ValiCrew — we will pass it to that company, since they control it. We cannot release or delete their records on our own initiative.
Data breaches
If a breach affects personal data we hold, we will notify the UAE Data Office and affected controllers without undue delay, in line with PDPL Article 9, and give you what you need to meet your own notification duties.
Children
ValiCrew is a business tool and is not directed at children. We do not knowingly collect data about anyone under 18 other than as workforce records lawfully created by an employer.
Changes
We will update this policy as the service changes. The date at the top always reflects the current version, and material changes are notified to workspace administrators by email.
Contact
Lenouar Artificial Intelligence Developing Services LLC Al Muroor, Abu Dhabi, United Arab Emirates Commercial registration CN-6272765
Privacy: [email protected] Security: [email protected]
Lenouar Artificial Intelligence Developing Services LLC · Al Muroor, Abu Dhabi, United Arab Emirates · Commercial registration CN-6272765