This policy explains what personal data EverEdge Group FZ-LLC collects, why we collect it, who we share it with, and the rights you have over it. We've tried to write it in plain language while remaining legally complete.
Last updated: 22 July 2026
EverEdge Group FZ-LLC (“EverEdge Group”, “we”, “us”, or “our”) operates the website at https://everedgegroup.com and the tools and services offered through it. We are the data controller (Controller) responsible for the personal data described in this policy — meaning we decide why and how it is processed.
Legal entity: EverEdge Group FZ-LLC (trading as EverEdge Group)
Registered address: Sharjah Media City (Shams), Al Messaned, Al Bataeh, Sharjah, United Arab Emirates, P.O. Box 515000
Data-protection contact: compliance@everedgegroup.com
We have not appointed a statutory Data Protection Officer, but the mailbox above is monitored by the person responsible for privacy matters at EverEdge Group. Please direct any question, request or complaint about your personal data there.
This policy applies to personal data we process about visitors to our website, prospective and actual clients, newsletter subscribers, and people who use our AI estimator, audit/rescue tool, chatbot, or booking and payment flows. It does not cover third-party websites we link to, which have their own privacy policies.
EverEdge Group FZ-LLC is established in the Sharjah Media City (Shams) free zone. Shams is a non-financial free zone and does not operate its own standalone data-protection regime. Accordingly, our processing is governed by the UAE Federal Personal Data Protection Law — Federal Decree-Law No. 45 of 2021 (the “PDPL”) and its implementing regulations, as administered by the UAE Data Office. For the avoidance of doubt, the specialised data-protection frameworks of the DIFC and ADGM financial free zones do not apply to us.
Where we offer our services to, or monitor the behaviour of, individuals located in the European Union, the European Economic Area or the United Kingdom, we also process personal data in accordance with Regulation (EU) 2016/679 (the “GDPR”) and the UK GDPR. Where the GDPR applies, the additional lawful-basis and rights provisions in Sections 4, 10 and 11 of this policy apply to you.
We collect personal data at the following points. We aim to collect only what we need for the purpose described.
When you fill in a contact or lead form, subscribe to our newsletter, use the AI estimator or the AI audit/rescue tool, or interact with our chatbot, you may provide:
This information is stored in our content and customer datastore, Sanity CMS. Submitted leads are automatically enriched with a lead score, a temperature label (Hot, Warm or Cold), and basic firmographic attributes inferred from your email domain. This enrichment is deterministic and performed in-house — we do not buy data about you from external data brokers.
When you use our on-site chatbot, the full text of your conversation is stored in our datastore (in a chatLog record) together with a one-way pseudonymous key derived from your IP address. We do not store the raw IP address in the chat record. The conversation itself is also sent to a third-party AI provider (Google Gemini) to generate replies — see Section 5.
To understand how our site is used, our own first-party analytics beacon records page views, the referring page, UTM campaign parameters, your browser user-agent, and an approximate location (country and city) derived from your IP address. To distinguish repeat visits it sets a first-party cookie called ee_vid (see Section 6). This data is stored in our datastore. We do not use it to build advertising profiles.
The table below sets out what we do with your personal data, together with our lawful basis under the GDPR and the corresponding legal ground under the UAE PDPL (Article 4).
| Purpose | GDPR lawful basis | PDPL legal ground |
|---|---|---|
| Responding to enquiries and providing estimates, audits and quotes you request | Performance of a contract / steps prior to a contract (Art. 6(1)(b)) | Necessary for performance of a contract or to take pre-contractual steps |
| Delivering our services, managing bookings, and issuing and collecting invoices | Performance of a contract (Art. 6(1)(b)) | Necessary for performance of a contract |
| Sending our newsletter and marketing updates | Consent (Art. 6(1)(a)) — withdrawable anytime | Consent of the data subject |
| Lead scoring, enrichment, AI triage and prioritising follow-up | Legitimate interests (Art. 6(1)(f)) — running and growing our business efficiently | Necessary for our legitimate interests, balanced against your rights |
| First-party analytics, security, fraud prevention and rate-limiting | Legitimate interests (Art. 6(1)(f)) — keeping the site secure and understanding usage | Necessary for our legitimate interests / to protect the security of processing |
| Powering the on-site AI chatbot | Legitimate interests (Art. 6(1)(f)) — you choose to start the conversation | Consent / legitimate interests (you initiate the chat) |
| Complying with legal, tax and accounting obligations | Legal obligation (Art. 6(1)(c)) | Necessary to comply with a legal obligation |
Where we rely on legitimate interests, you have the right to object (see Section 10). Where we rely on consent, you can withdraw it at any time without affecting processing carried out before withdrawal.
Several of our tools use third-party artificial-intelligence providers to generate content or analyse the information you submit. Because this involves your data leaving our systems, we set it out plainly here. In each case the text you provide is transmitted to the provider, processed to generate a response, and returned to us; the providers act as our processors and are not permitted to use your inputs to train their public models for our account.
We do not use these tools to make solely automated decisions that produce legal or similarly significant effects about you. AI outputs (such as scores and summaries) assist our team; a human remains responsible for decisions about your enquiry. Please avoid entering sensitive personal data (such as health, religious or biometric information) into these tools, as they are not designed to process it.
Because several of the providers listed above are based in the United States, the European Union or elsewhere, your personal data may be transferred to, and processed in, countries outside the United Arab Emirates. Data-protection laws in those countries may differ from those in the UAE, the EEA or the UK.
Under the UAE PDPL, we transfer personal data outside the UAE only where an adequate level of protection exists (for example to a jurisdiction recognised by the UAE Data Office), or, in the absence of adequacy, on the basis of appropriate contractual safeguards, your consent, or another lawful transfer condition permitted by Articles 22–23 of the PDPL.
Under the GDPR / UK GDPR, where we transfer data from the EEA or the UK to a country without an adequacy decision, we rely on appropriate safeguards — principally the European Commission's Standard Contractual Clauses (SCCs), together with the UK International Data Transfer Addendum where relevant, and any supplementary measures needed. You can ask us for more information about the safeguards applied to a specific transfer by emailing compliance@everedgegroup.com.
We keep personal data only for as long as we need it for the purposes set out in this policy, and then delete or anonymise it. In practice:
Where a specific statutory retention period applies, that period governs. If you would like your data removed earlier, see Section 11.
Depending on where you are located, you have rights over your personal data under the UAE PDPL and/or the GDPR. We honour these rights regardless of where you live.
Exercising these rights is free of charge in most cases, and we will respond within the timeframes required by the applicable law (one month under the GDPR, which may be extended for complex requests). We may need to verify your identity before acting on a request.
To exercise any of the rights in Section 10, to withdraw consent, or to ask a question about this policy, contact us at:
EverEdge Group FZ-LLC — Data Protection
Email: compliance@everedgegroup.com
Post: Sharjah Media City (Shams), Al Messaned, Al Bataeh, Sharjah, United Arab Emirates, P.O. Box 515000
We would always prefer the chance to resolve a concern directly, so please contact us first. However, you also have the right to lodge a complaint with a supervisory authority:
We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss or misuse — including transport encryption (HTTPS), access controls on our datastore and admin tools, rate-limiting, and error monitoring. Payment card data is handled entirely by Stripe and never touches our servers. No system can be guaranteed completely secure, but we work to protect your data and will notify you and the relevant authority of a personal-data breach where the law requires.
Our website and services are directed at businesses and professionals and are not intended for children. We do not knowingly collect personal data from anyone under 18 years of age. If you believe a minor has provided us with personal data, please contact us and we will delete it.
We may update this policy from time to time to reflect changes in our practices, tools or legal obligations. When we do, we will revise the “Last updated” date at the top of this page, and for material changes we will take reasonable steps to notify you. Please review this page periodically.
This Privacy Policy is effective as of 22 July 2026.
Questions about your privacy? Email compliance@everedgegroup.com.