Skip to main content
Back home
Legal

Privacy Policy

This policy explains what personal data EverEdge Group FZ-LLC collects, why we collect it, who we share it with, and the rights you have over it. We've tried to write it in plain language while remaining legally complete.

Last updated: 22 July 2026

Summary at a glance

  • Who: EverEdge Group FZ-LLC, a company registered in the Sharjah Media City (Shams) free zone, United Arab Emirates.
  • What we collect: contact details you give us (name, email, and optionally phone, company and project details), plus first-party analytics and chatbot transcripts.
  • AI: some of what you type into our estimator, audit tool and chatbot is sent to third-party AI providers (OpenAI, Google Gemini, Anthropic) to generate responses. See Section 5.
  • Where: some processors are outside the UAE (e.g. the US and EU). We rely on appropriate safeguards for those transfers.
  • Your rights: you can access, correct, delete, or object to the use of your data. Email compliance@everedgegroup.com.
  • Laws that apply: the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and, for EU/EEA/UK visitors, the GDPR.

1. Who we are

EverEdge Group FZ-LLC (“EverEdge Group”, “we”, “us”, or “our”) operates the website at https://everedgegroup.com and the tools and services offered through it. We are the data controller (Controller) responsible for the personal data described in this policy — meaning we decide why and how it is processed.

Legal entity: EverEdge Group FZ-LLC (trading as EverEdge Group)

Registered address: Sharjah Media City (Shams), Al Messaned, Al Bataeh, Sharjah, United Arab Emirates, P.O. Box 515000

Data-protection contact: compliance@everedgegroup.com

We have not appointed a statutory Data Protection Officer, but the mailbox above is monitored by the person responsible for privacy matters at EverEdge Group. Please direct any question, request or complaint about your personal data there.

2. Scope & the laws that apply

This policy applies to personal data we process about visitors to our website, prospective and actual clients, newsletter subscribers, and people who use our AI estimator, audit/rescue tool, chatbot, or booking and payment flows. It does not cover third-party websites we link to, which have their own privacy policies.

UAE Personal Data Protection Law (PDPL)

EverEdge Group FZ-LLC is established in the Sharjah Media City (Shams) free zone. Shams is a non-financial free zone and does not operate its own standalone data-protection regime. Accordingly, our processing is governed by the UAE Federal Personal Data Protection Law — Federal Decree-Law No. 45 of 2021 (the “PDPL”) and its implementing regulations, as administered by the UAE Data Office. For the avoidance of doubt, the specialised data-protection frameworks of the DIFC and ADGM financial free zones do not apply to us.

EU / EEA / UK GDPR

Where we offer our services to, or monitor the behaviour of, individuals located in the European Union, the European Economic Area or the United Kingdom, we also process personal data in accordance with Regulation (EU) 2016/679 (the “GDPR”) and the UK GDPR. Where the GDPR applies, the additional lawful-basis and rights provisions in Sections 4, 10 and 11 of this policy apply to you.

3. Personal data we collect

We collect personal data at the following points. We aim to collect only what we need for the purpose described.

Data you give us

When you fill in a contact or lead form, subscribe to our newsletter, use the AI estimator or the AI audit/rescue tool, or interact with our chatbot, you may provide:

  • Identity & contact data: name and email address (always), and optionally your phone number and company or business name.
  • Project data: business description, industry, project or message details, budget, goals, preferred design style, and your preferred contact time.

This information is stored in our content and customer datastore, Sanity CMS. Submitted leads are automatically enriched with a lead score, a temperature label (Hot, Warm or Cold), and basic firmographic attributes inferred from your email domain. This enrichment is deterministic and performed in-house — we do not buy data about you from external data brokers.

Chatbot conversations

When you use our on-site chatbot, the full text of your conversation is stored in our datastore (in a chatLog record) together with a one-way pseudonymous key derived from your IP address. We do not store the raw IP address in the chat record. The conversation itself is also sent to a third-party AI provider (Google Gemini) to generate replies — see Section 5.

Visitor analytics (first-party)

To understand how our site is used, our own first-party analytics beacon records page views, the referring page, UTM campaign parameters, your browser user-agent, and an approximate location (country and city) derived from your IP address. To distinguish repeat visits it sets a first-party cookie called ee_vid (see Section 6). This data is stored in our datastore. We do not use it to build advertising profiles.

Bookings & payments

  • Bookings: when you schedule a call, your booking details are handled through Cal.com.
  • Payments: when you pay a deposit or invoice, Stripe processes your name, email and the amount. Card and banking details are entered directly with Stripe and are never stored on our systems.

Data we generate or infer

  • Lead score, temperature and firmographic inferences (described above).
  • AI-generated summaries and triage scores produced from the lead data you submit (see Section 5).
  • Technical and security data — for example rate-limiting keys derived from your IP address, and error/diagnostic context captured when something goes wrong.

4. How & why we use your data — and our legal grounds

The table below sets out what we do with your personal data, together with our lawful basis under the GDPR and the corresponding legal ground under the UAE PDPL (Article 4).

PurposeGDPR lawful basisPDPL legal ground
Responding to enquiries and providing estimates, audits and quotes you requestPerformance of a contract / steps prior to a contract (Art. 6(1)(b))Necessary for performance of a contract or to take pre-contractual steps
Delivering our services, managing bookings, and issuing and collecting invoicesPerformance of a contract (Art. 6(1)(b))Necessary for performance of a contract
Sending our newsletter and marketing updatesConsent (Art. 6(1)(a)) — withdrawable anytimeConsent of the data subject
Lead scoring, enrichment, AI triage and prioritising follow-upLegitimate interests (Art. 6(1)(f)) — running and growing our business efficientlyNecessary for our legitimate interests, balanced against your rights
First-party analytics, security, fraud prevention and rate-limitingLegitimate interests (Art. 6(1)(f)) — keeping the site secure and understanding usageNecessary for our legitimate interests / to protect the security of processing
Powering the on-site AI chatbotLegitimate interests (Art. 6(1)(f)) — you choose to start the conversationConsent / legitimate interests (you initiate the chat)
Complying with legal, tax and accounting obligationsLegal obligation (Art. 6(1)(c))Necessary to comply with a legal obligation

Where we rely on legitimate interests, you have the right to object (see Section 10). Where we rely on consent, you can withdraw it at any time without affecting processing carried out before withdrawal.

5. AI processing disclosure

Several of our tools use third-party artificial-intelligence providers to generate content or analyse the information you submit. Because this involves your data leaving our systems, we set it out plainly here. In each case the text you provide is transmitted to the provider, processed to generate a response, and returned to us; the providers act as our processors and are not permitted to use your inputs to train their public models for our account.

  • AI Estimator (OpenAI): your business name, business description, goals and industry are sent to OpenAI to generate a tailored mockup and content. Your email address is not sent to OpenAI.
  • AI Audit / Rescue tool (Google Gemini): the business and project descriptions you enter are sent to Google Gemini to produce your report. The full report is unlocked after you provide your name and email.
  • Chatbot (Google Gemini): the entire conversation you have with our chatbot is sent to Google Gemini to generate replies. As noted above, the transcript and a one-way pseudonymous key derived from your IP address are also stored in our datastore; the raw IP is not stored.
  • Lead triage / summarisation (Anthropic): lead data you have submitted is summarised and scored using Anthropic's models to help us prioritise and prepare for follow-up.

We do not use these tools to make solely automated decisions that produce legal or similarly significant effects about you. AI outputs (such as scores and summaries) assist our team; a human remains responsible for decisions about your enquiry. Please avoid entering sensitive personal data (such as health, religious or biometric information) into these tools, as they are not designed to process it.

6. Cookies & tracking

A cookie is a small file stored on your device. We keep our cookie use deliberately lean. The cookies and similar technologies we use are:

Cookie / technologyType & purposeDuration
ee_vidStrictly-necessary, first-party analytics identifier. Lets us count unique visits for our own analytics. It is httpOnly, contains no marketing content, and is not shared with advertisers.1 year
NextAuth session cookiesStrictly necessary. Set only for signed-in users of the admin or client portal to keep you logged in.Session
Google Analytics 4Analytics. Only set when this integration is enabled. Helps us measure traffic and content performance.Up to 2 years
PostHogProduct analytics. Only set when this integration is enabled. Helps us understand feature usage.Up to 1 year
SentryStrictly necessary security and error monitoring. May capture error and request context (which can include technical identifiers) when something breaks, so we can protect and repair the service. It is not used for advertising or audience analytics.Transient

How to control cookies and tracking

You can block or delete cookies through your browser settings; note that blocking strictly-necessary cookies may stop parts of the site (such as the portal login) from working. We want to be transparent about one point: the ee_vid analytics cookie is currently set without a prior consent banner. We treat it as strictly necessary to our own first-party analytics, it carries no advertising payload, and it is not shared with third-party advertisers. If you are in the EEA or the UK and wish to object to this first-party analytics processing, please email compliance@everedgegroup.com and we will action your request. Google Analytics and PostHog are only active when those integrations are enabled and you accept optional analytics.

7. Sharing & subprocessors

We do not sell your personal data. We share it only with the service providers (processors and subprocessors) that help us run our website and business, and only as needed for the purposes above. Several of these providers are located outside the UAE (see Section 8). Our current providers are:

ProviderPurposeOutside UAE?
SanityContent & customer datastore (where your data is stored)Yes
VercelWebsite hosting and IP-based geolocationYes
OpenAIAI estimator content generationYes
Google (Gemini)Chatbot and AI audit/rescue toolYes
AnthropicAI lead triage and summarisationYes
ResendTransactional email deliveryYes
CallMeBotInternal WhatsApp lead alerts to our teamYes
StripePayment and invoice processingYes
Cal.comCall and meeting bookingsYes
UnsplashWebsite imagery (no personal data)Yes
Google AnalyticsWebsite analytics (when enabled)Yes
PostHogProduct analytics (when enabled)Yes
SentryError and performance monitoringYes
Upstash RedisRate-limiting (stores IP-derived keys)Yes
Make.comWorkflow automationYes

We may also disclose personal data where required by law, to establish, exercise or defend legal claims, or in connection with a merger, acquisition or reorganisation of our business (in which case we will require the recipient to honour this policy). When you initiate a WhatsApp chat with us, that conversation is carried over Meta/WhatsApp and is subject to their terms.

8. International data transfers

Because several of the providers listed above are based in the United States, the European Union or elsewhere, your personal data may be transferred to, and processed in, countries outside the United Arab Emirates. Data-protection laws in those countries may differ from those in the UAE, the EEA or the UK.

Under the UAE PDPL, we transfer personal data outside the UAE only where an adequate level of protection exists (for example to a jurisdiction recognised by the UAE Data Office), or, in the absence of adequacy, on the basis of appropriate contractual safeguards, your consent, or another lawful transfer condition permitted by Articles 22–23 of the PDPL.

Under the GDPR / UK GDPR, where we transfer data from the EEA or the UK to a country without an adequacy decision, we rely on appropriate safeguards — principally the European Commission's Standard Contractual Clauses (SCCs), together with the UK International Data Transfer Addendum where relevant, and any supplementary measures needed. You can ask us for more information about the safeguards applied to a specific transfer by emailing compliance@everedgegroup.com.

9. Data retention

We keep personal data only for as long as we need it for the purposes set out in this policy, and then delete or anonymise it. In practice:

  • Leads and enquiries are retained for the duration of our relationship and for a reasonable period afterwards (up to 24 months from last contact) so we can follow up, unless you ask us to delete them sooner.
  • Client and payment records are retained for as long as required to provide the service and to meet our legal, tax and accounting obligations (generally up to 5 years after the end of the engagement).
  • Chatbot transcripts and pseudonymous IP keys are retained for 90 days after the last message for support, security and quality purposes, then automatically deleted. Legacy raw chat IP values are removed by the same retention process.
  • Analytics data is retained in line with the cookie durations in Section 6 and then aggregated or deleted.
  • Newsletter subscriptions are kept until you unsubscribe or withdraw consent.

Where a specific statutory retention period applies, that period governs. If you would like your data removed earlier, see Section 11.

10. Your rights

Depending on where you are located, you have rights over your personal data under the UAE PDPL and/or the GDPR. We honour these rights regardless of where you live.

Rights under the UAE PDPL

  • Right to obtain information about, and access, your personal data;
  • Right to request correction or rectification of inaccurate data;
  • Right to request erasure / deletion of your data;
  • Right to restrict or stop processing in certain circumstances;
  • Right to request the transfer of your data (data portability);
  • Right to object to processing, including for direct marketing;
  • Right to withdraw consent where processing is based on consent; and rights in relation to automated processing.

Rights under the GDPR (EU / EEA / UK)

  • Access — a copy of the personal data we hold about you (Art. 15);
  • Rectification — correction of inaccurate or incomplete data (Art. 16);
  • Erasure — deletion of your data (“right to be forgotten”, Art. 17);
  • Restriction — limiting how we use your data (Art. 18);
  • Portability — receiving your data in a structured, machine-readable format (Art. 20);
  • Objection — objecting to processing based on legitimate interests, and to direct marketing at any time (Art. 21);
  • Withdraw consent — at any time, where we rely on your consent (Art. 7(3)).

Exercising these rights is free of charge in most cases, and we will respond within the timeframes required by the applicable law (one month under the GDPR, which may be extended for complex requests). We may need to verify your identity before acting on a request.

11. How to exercise your rights, and how to complain

To exercise any of the rights in Section 10, to withdraw consent, or to ask a question about this policy, contact us at:

EverEdge Group FZ-LLC — Data Protection

Email: compliance@everedgegroup.com

Post: Sharjah Media City (Shams), Al Messaned, Al Bataeh, Sharjah, United Arab Emirates, P.O. Box 515000

Your right to complain

We would always prefer the chance to resolve a concern directly, so please contact us first. However, you also have the right to lodge a complaint with a supervisory authority:

  • In the UAE: the UAE Data Office, which administers the Federal Personal Data Protection Law (Federal Decree-Law No. 45 of 2021).
  • In the EU / EEA: the data protection authority of your country of residence, place of work, or the place of the alleged infringement.
  • In the UK: the Information Commissioner's Office (ICO).

12. Security, children's data, changes & effective date

Security

We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss or misuse — including transport encryption (HTTPS), access controls on our datastore and admin tools, rate-limiting, and error monitoring. Payment card data is handled entirely by Stripe and never touches our servers. No system can be guaranteed completely secure, but we work to protect your data and will notify you and the relevant authority of a personal-data breach where the law requires.

Children's data

Our website and services are directed at businesses and professionals and are not intended for children. We do not knowingly collect personal data from anyone under 18 years of age. If you believe a minor has provided us with personal data, please contact us and we will delete it.

Changes to this policy

We may update this policy from time to time to reflect changes in our practices, tools or legal obligations. When we do, we will revise the “Last updated” date at the top of this page, and for material changes we will take reasonable steps to notify you. Please review this page periodically.

Effective date

This Privacy Policy is effective as of 22 July 2026.

Questions about your privacy? Email compliance@everedgegroup.com.