1. Who We Are
SetMyClaw is a brand of ORIETUR CONSULTANCY - FZCO, a free zone company licensed by the Dubai Integrated Economic Zones Authority (IFZA) under Trade Licence No. 91283, at IFZA Properties, DSO-IFZA, Dubai Silicon Oasis, Dubai, United Arab Emirates. Our manager is Nicolò Ricci.
This policy covers our website and our own business relationships: visitors to the site, people who send us enquiries, and the staff of our clients and suppliers whom we deal with. For this data we are the controller, which means we decide why and how it is processed.
It does not cover the business data we process inside a system we run for a client. Section 4 explains that and points to our Data Processing Addendum.
For privacy questions or requests, write to info@setmyclaw.com.
2. Data We Collect
- Contact data: your name, email address, phone or WhatsApp number, and the content of the messages, calls and meetings we have with you.
- Business data: your company name, your role, what you need, the systems and tools you use, and the notes, proposals and contracts that come out of our discussions.
- Billing data: invoicing details, payment records, and the transaction references our payment provider gives us. We do not see or store your full card details.
- Technical and analytics data: basic information about visits to our website, such as pages viewed, approximate country, referring site, and device or browser type.
Two tools run on the website. PostHog gives us product analytics without cookies: it keeps a session identifier in your browser only until you close the tab and does not follow you across sites. The Meta Pixel, together with Meta's Conversions API on our server, measures whether our advertising on Facebook and Instagram leads to enquiries. The Pixel sets a Meta cookie and sends Meta the pages you view and the actions you take on the site, such as booking a call. See section 10 for how to opt out.
We do not ask for special category data such as health or biometric data, and you should not send it to us in an enquiry.
3. How We Use It and Our Legal Bases
We process personal data under UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and its Executive Regulations. Where the EU or UK GDPR applies to you or to a data subject, we also meet the obligations it places on us. The bases we rely on are these.
- To answer enquiries and prepare proposals. Basis: your consent when you contact us, or the steps needed before entering a contract.
- To deliver our services and manage the engagement. Basis: performance of a contract, or our legitimate interest in managing a contract held with your employer.
- To invoice and keep accounting records. Basis: legal obligation, and performance of a contract.
- To provide support, fix problems and keep systems secure. Basis: performance of a contract, and our legitimate interest in running secure services.
- To send service updates and occasional follow-ups. Basis: your consent, or our legitimate interest in keeping existing clients informed. You can opt out at any time.
- To understand website use and improve the site. Basis: our legitimate interest in cookieless product analytics.
- To measure our advertising. Basis: your consent where the law requires it for advertising cookies, and otherwise our legitimate interest in knowing which campaigns work. You can opt out at any time, see section 10.
- To meet legal and regulatory duties and to defend legal claims. Basis: legal obligation, and our legitimate interest.
We do not sell personal data and we do not use it for automated decisions that produce legal effects for you.
4. Client Data Processed in Our Systems
When we host and run a system for a client, that system handles the client's business data. This can include emails, messages, documents, contacts, call audio and transcripts, and any personal data those contain about the client's own customers and staff.
For that data the client is the controller and we are the processor. We act on the client's documented instructions. The client is responsible for having a lawful basis for the data it puts into the system and for giving the required notices to its own data subjects. The terms are set out in our Data Processing Addendum.
Where a system runs in the client's own accounts, or on providers the client chose, those providers are the client's, and the client's agreements with them apply. Where we host a system, the data goes to the providers we use for it, described by category in the Data Processing Addendum and named in the client's Engagement Terms. We do not use client data to train models for our own purposes or for other clients.
Where a system is built in the client's own accounts, the client's own agreements with those providers apply and we hold no copy of the data once the handover is complete, except any access the client has asked us to keep for maintenance.
If you are a customer or employee of one of our clients and you want to exercise rights over data held in their system, please contact that client. We will pass on any request that reaches us.
5. Sharing and Subprocessors
We do not sell personal data. We share it only in these cases:
- Service providers: the hosting, database, AI, speech, messaging, email and payment providers we use to run our business and our clients' systems, under data processing agreements. They are described in section 4 of our Data Processing Addendum, which describes the categories of provider we work with.
- Professional advisers: our accountants, auditors and lawyers, under duties of confidence.
- Authorities: where the law, a court order or a regulator requires it.
- A buyer or successor: if the business is sold or reorganised, under equivalent protections.
The list of subprocessors changes as our services change. We tell clients about material changes and give them 14 days to object.
6. International Transfers
We are based in the United Arab Emirates and our providers operate in several countries, including the United States and the European Union. Your data, and client data in systems we host, may be processed outside the UAE and outside your own country.
When that happens we rely on contractual safeguards. We sign the data processing agreements the providers offer, we use the EU Standard Contractual Clauses where the GDPR applies, and we choose providers that maintain appropriate security. A client can ask us which providers and which locations apply to its engagement.
7. Retention
- Enquiries and business contacts: for as long as we have, or may reasonably have, a business relationship with you or your company. We review contact data periodically, and we delete it on request unless we need it for one of the reasons below.
- Contract, invoice and accounting records: for at least 5 years after the end of the engagement, as UAE law requires, and for as long after that as we need them to manage the relationship, defend a claim or meet a legal duty.
- Client business data processed under the Data Processing Addendum: deleted or returned within 30 days after the engagement ends, unless the law requires us to keep it longer or the client instructs otherwise.
- Website analytics and advertising measurement: PostHog data is kept for 12 months. Data sent to Meta is held by Meta under its own retention terms.
We do not keep data we have no use for. Where we keep something only for a legal reason, we keep what is needed and we stop using it for anything else. You can ask us at any time what we hold about you and to delete it, and we will, except where a law or a contract requires us to keep it.
8. Security
We protect data with measures appropriate to the system and the risk. Typically these include:
- Data is encrypted in transit. Managed databases and storage we use encrypt data at rest, and we enable disk encryption on servers where the platform supports it.
- Access is limited to the people who need it for their work, on a least privilege basis, and is removed when it is no longer needed.
- Accounts use strong, unique credentials and multi-factor authentication where the provider supports it.
- Key-based access to the servers we manage, with password login disabled where the setup allows it.
- Secrets and API keys are kept out of source code, in environment configuration with restricted access.
- We keep access and system logs, and we review them when investigating an incident.
- We apply security updates to the systems we run and we separate client environments.
No system can be completely secure. If a breach affects your personal data we will act on it and notify you and the relevant authority where the law requires it.
9. Your Rights
Under the UAE PDPL, and under the GDPR where it applies to you, you can ask us to:
- Give you access to the personal data we hold about you and tell you how we process it.
- Correct data that is wrong or incomplete.
- Erase your data where there is no longer a reason for us to keep it.
- Restrict how we process your data while a question about it is resolved.
- Give you a copy of the data you provided in a portable, machine-readable format, or send it to another controller where that is technically possible.
- Stop processing your data where you object to it, including for direct marketing.
- Withdraw consent you gave earlier. That does not affect processing that already took place.
To exercise a right, write to info@setmyclaw.com. We may need to check your identity first. We respond within 30 days. There is no charge unless a request is clearly excessive or repeated.
If you are unhappy with how we handled your data, please tell us first so we can put it right. You can also complain to the UAE Data Office, or, where the GDPR applies, to the supervisory authority in your country.
10. Cookies
- Strictly necessary: what the site needs to work. No consent needed.
- Analytics, PostHog: no cookies. A session identifier is stored in your browser's session storage and is cleared when you close the tab.
- Advertising measurement, Meta Pixel: sets the Meta cookie _fbp and reports page views and actions to Meta so we can measure our Facebook and Instagram advertising. Meta may combine this with data it holds about you under its own privacy policy.
To opt out of the Meta Pixel, block third-party cookies in your browser, use a content blocker, or adjust your ad settings in your Facebook account. Blocking cookies does not stop the site from working.
11. Children
Our website and services are for businesses and are not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us personal data, write to us and we will delete it.
12. Changes to This Policy
We may update this policy. The current version is always on this page with a revision date. If a change is material we will tell clients by email where we hold their address. Please check this page from time to time.
13. Contact
ORIETUR CONSULTANCY - FZCO, IFZA Properties, DSO-IFZA, Dubai Silicon Oasis, Dubai, United Arab Emirates.
Email, including for privacy requests: info@setmyclaw.com
See also our Data Processing Addendum, including the categories of provider we work with, and our Terms of Service.