Privacy Policy
This policy explains what personal data EverEdge Group FZ-LLC collects, why we collect it, who we share it with, and the rights you have over it. We've tried to write it in plain language while remaining legally complete.
Last updated: 22 July 2026
Summary at a glance
- Who: EverEdge Group FZ-LLC, a company registered in the Sharjah Media City (Shams) free zone, United Arab Emirates.
- What we collect: contact details you give us (name, email, and optionally phone, company and project details), plus first-party analytics and chatbot transcripts.
- AI: some of what you type into our estimator, audit tool and chatbot is sent to third-party AI providers (OpenAI, Google Gemini, Anthropic) to generate responses. See Section 5.
- Where: some processors are outside the UAE (e.g. the US and EU). We rely on appropriate safeguards for those transfers.
- Your rights: you can access, correct, delete, or object to the use of your data. Email compliance@everedgegroup.com.
- Laws that apply: the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and, for EU/EEA/UK visitors, the GDPR.
1. Who we are
EverEdge Group FZ-LLC (“EverEdge Group”, “we”, “us”, or “our”) operates the website at https://everedgegroup.com and the tools and services offered through it. We are the data controller (Controller) responsible for the personal data described in this policy — meaning we decide why and how it is processed.
Legal entity: EverEdge Group FZ-LLC (trading as EverEdge Group)
Registered address: Sharjah Media City (Shams), Al Messaned, Al Bataeh, Sharjah, United Arab Emirates, P.O. Box 515000
Data-protection contact: compliance@everedgegroup.com
We have not appointed a statutory Data Protection Officer, but the mailbox above is monitored by the person responsible for privacy matters at EverEdge Group. Please direct any question, request or complaint about your personal data there.
2. Scope & the laws that apply
This policy applies to personal data we process about visitors to our website, prospective and actual clients, newsletter subscribers, and people who use our AI estimator, audit/rescue tool, chatbot, or booking and payment flows. It does not cover third-party websites we link to, which have their own privacy policies.
UAE Personal Data Protection Law (PDPL)
EverEdge Group FZ-LLC is established in the Sharjah Media City (Shams) free zone. Shams is a non-financial free zone and does not operate its own standalone data-protection regime. Accordingly, our processing is governed by the UAE Federal Personal Data Protection Law — Federal Decree-Law No. 45 of 2021 (the “PDPL”) and its implementing regulations, as administered by the UAE Data Office. For the avoidance of doubt, the specialised data-protection frameworks of the DIFC and ADGM financial free zones do not apply to us.
EU / EEA / UK GDPR
Where we offer our services to, or monitor the behaviour of, individuals located in the European Union, the European Economic Area or the United Kingdom, we also process personal data in accordance with Regulation (EU) 2016/679 (the “GDPR”) and the UK GDPR. Where the GDPR applies, the additional lawful-basis and rights provisions in Sections 4, 10 and 11 of this policy apply to you.
3. Personal data we collect
We collect personal data at the following points. We aim to collect only what we need for the purpose described.
Data you give us
When you fill in a contact or lead form, subscribe to our newsletter, use the AI estimator or the AI audit/rescue tool, or interact with our chatbot, you may provide:
- Identity & contact data: name and email address (always), and optionally your phone number and company or business name.
- Project data: business description, industry, project or message details, budget, goals, preferred design style, and your preferred contact time.
This information is stored in our content and customer datastore, Sanity CMS. Submitted leads are automatically enriched with a lead score, a temperature label (Hot, Warm or Cold), and basic firmographic attributes inferred from your email domain. This enrichment is deterministic and performed in-house — we do not buy data about you from external data brokers.
Chatbot conversations
When you use our on-site chatbot, the full text of your conversation is stored in our datastore (in a chatLog record) together with a one-way pseudonymous key derived from your IP address. We do not store the raw IP address in the chat record. The conversation itself is also sent to a third-party AI provider (Google Gemini) to generate replies — see Section 5.
Visitor analytics (first-party)
To understand how our site is used, our own first-party analytics beacon records page views, the referring page, UTM campaign parameters, your browser user-agent, and an approximate location (country and city) derived from your IP address. To distinguish repeat visits it sets a first-party cookie called ee_vid (see Section 6). This data is stored in our datastore. We do not use it to build advertising profiles.
Bookings & payments
- Bookings: when you schedule a call, your booking details are handled through Cal.com.
- Payments: when you pay a deposit or invoice, Stripe processes your name, email and the amount. Card and banking details are entered directly with Stripe and are never stored on our systems.
Data we generate or infer
- Lead score, temperature and firmographic inferences (described above).
- AI-generated summaries and triage scores produced from the lead data you submit (see Section 5).
- Technical and security data — for example rate-limiting keys derived from your IP address, and error/diagnostic context captured when something goes wrong.
4. How & why we use your data — and our legal grounds
The table below sets out what we do with your personal data, together with our lawful basis under the GDPR and the corresponding legal ground under the UAE PDPL (Article 4).
| Purpose | GDPR lawful basis | PDPL legal ground |
|---|---|---|
| Responding to enquiries and providing estimates, audits and quotes you request | Performance of a contract / steps prior to a contract (Art. 6(1)(b)) | Necessary for performance of a contract or to take pre-contractual steps |
| Delivering our services, managing bookings, and issuing and collecting invoices | Performance of a contract (Art. 6(1)(b)) | Necessary for performance of a contract |
| Sending our newsletter and marketing updates | Consent (Art. 6(1)(a)) — withdrawable anytime | Consent of the data subject |
| Lead scoring, enrichment, AI triage and prioritising follow-up | Legitimate interests (Art. 6(1)(f)) — running and growing our business efficiently | Necessary for our legitimate interests, balanced against your rights |
| First-party analytics, security, fraud prevention and rate-limiting | Legitimate interests (Art. 6(1)(f)) — keeping the site secure and understanding usage | Necessary for our legitimate interests / to protect the security of processing |
| Powering the on-site AI chatbot | Legitimate interests (Art. 6(1)(f)) — you choose to start the conversation | Consent / legitimate interests (you initiate the chat) |
| Complying with legal, tax and accounting obligations | Legal obligation (Art. 6(1)(c)) | Necessary to comply with a legal obligation |
Where we rely on legitimate interests, you have the right to object (see Section 10). Where we rely on consent, you can withdraw it at any time without affecting processing carried out before withdrawal.
5. AI processing disclosure
Several of our tools use third-party artificial-intelligence providers to generate content or analyse the information you submit. Because this involves your data leaving our systems, we set it out plainly here. In each case the text you provide is transmitted to the provider, processed to generate a response, and returned to us; the providers act as our processors and are not permitted to use your inputs to train their public models for our account.
- AI Estimator (OpenAI): your business name, business description, goals and industry are sent to OpenAI to generate a tailored mockup and content. Your email address is not sent to OpenAI.
- AI Audit / Rescue tool (Google Gemini): the business and project descriptions you enter are sent to Google Gemini to produce your report. The full report is unlocked after you provide your name and email.
- Chatbot (Google Gemini): the entire conversation you have with our chatbot is sent to Google Gemini to generate replies. As noted above, the transcript and a one-way pseudonymous key derived from your IP address are also stored in our datastore; the raw IP is not stored.
- Lead triage / summarisation (Anthropic): lead data you have submitted is summarised and scored using Anthropic's models to help us prioritise and prepare for follow-up.
We do not use these tools to make solely automated decisions that produce legal or similarly significant effects about you. AI outputs (such as scores and summaries) assist our team; a human remains responsible for decisions about your enquiry. Please avoid entering sensitive personal data (such as health, religious or biometric information) into these tools, as they are not designed to process it.
8. International data transfers
Because several of the providers listed above are based in the United States, the European Union or elsewhere, your personal data may be transferred to, and processed in, countries outside the United Arab Emirates. Data-protection laws in those countries may differ from those in the UAE, the EEA or the UK.
Under the UAE PDPL, we transfer personal data outside the UAE only where an adequate level of protection exists (for example to a jurisdiction recognised by the UAE Data Office), or, in the absence of adequacy, on the basis of appropriate contractual safeguards, your consent, or another lawful transfer condition permitted by Articles 22–23 of the PDPL.
Under the GDPR / UK GDPR, where we transfer data from the EEA or the UK to a country without an adequacy decision, we rely on appropriate safeguards — principally the European Commission's Standard Contractual Clauses (SCCs), together with the UK International Data Transfer Addendum where relevant, and any supplementary measures needed. You can ask us for more information about the safeguards applied to a specific transfer by emailing compliance@everedgegroup.com.
9. Data retention
We keep personal data only for as long as we need it for the purposes set out in this policy, and then delete or anonymise it. In practice:
- Leads and enquiries are retained for the duration of our relationship and for a reasonable period afterwards (up to 24 months from last contact) so we can follow up, unless you ask us to delete them sooner.
- Client and payment records are retained for as long as required to provide the service and to meet our legal, tax and accounting obligations (generally up to 5 years after the end of the engagement).
- Chatbot transcripts and pseudonymous IP keys are retained for 90 days after the last message for support, security and quality purposes, then automatically deleted. Legacy raw chat IP values are removed by the same retention process.
- Analytics data is retained in line with the cookie durations in Section 6 and then aggregated or deleted.
- Newsletter subscriptions are kept until you unsubscribe or withdraw consent.
Where a specific statutory retention period applies, that period governs. If you would like your data removed earlier, see Section 11.
10. Your rights
Depending on where you are located, you have rights over your personal data under the UAE PDPL and/or the GDPR. We honour these rights regardless of where you live.
Rights under the UAE PDPL
- Right to obtain information about, and access, your personal data;
- Right to request correction or rectification of inaccurate data;
- Right to request erasure / deletion of your data;
- Right to restrict or stop processing in certain circumstances;
- Right to request the transfer of your data (data portability);
- Right to object to processing, including for direct marketing;
- Right to withdraw consent where processing is based on consent; and rights in relation to automated processing.
Rights under the GDPR (EU / EEA / UK)
- Access — a copy of the personal data we hold about you (Art. 15);
- Rectification — correction of inaccurate or incomplete data (Art. 16);
- Erasure — deletion of your data (“right to be forgotten”, Art. 17);
- Restriction — limiting how we use your data (Art. 18);
- Portability — receiving your data in a structured, machine-readable format (Art. 20);
- Objection — objecting to processing based on legitimate interests, and to direct marketing at any time (Art. 21);
- Withdraw consent — at any time, where we rely on your consent (Art. 7(3)).
Exercising these rights is free of charge in most cases, and we will respond within the timeframes required by the applicable law (one month under the GDPR, which may be extended for complex requests). We may need to verify your identity before acting on a request.
11. How to exercise your rights, and how to complain
To exercise any of the rights in Section 10, to withdraw consent, or to ask a question about this policy, contact us at:
EverEdge Group FZ-LLC — Data Protection
Email: compliance@everedgegroup.com
Post: Sharjah Media City (Shams), Al Messaned, Al Bataeh, Sharjah, United Arab Emirates, P.O. Box 515000
Your right to complain
We would always prefer the chance to resolve a concern directly, so please contact us first. However, you also have the right to lodge a complaint with a supervisory authority:
- In the UAE: the UAE Data Office, which administers the Federal Personal Data Protection Law (Federal Decree-Law No. 45 of 2021).
- In the EU / EEA: the data protection authority of your country of residence, place of work, or the place of the alleged infringement.
- In the UK: the Information Commissioner's Office (ICO).
12. Security, children's data, changes & effective date
Security
We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss or misuse — including transport encryption (HTTPS), access controls on our datastore and admin tools, rate-limiting, and error monitoring. Payment card data is handled entirely by Stripe and never touches our servers. No system can be guaranteed completely secure, but we work to protect your data and will notify you and the relevant authority of a personal-data breach where the law requires.
Children's data
Our website and services are directed at businesses and professionals and are not intended for children. We do not knowingly collect personal data from anyone under 18 years of age. If you believe a minor has provided us with personal data, please contact us and we will delete it.
Changes to this policy
We may update this policy from time to time to reflect changes in our practices, tools or legal obligations. When we do, we will revise the “Last updated” date at the top of this page, and for material changes we will take reasonable steps to notify you. Please review this page periodically.
Effective date
This Privacy Policy is effective as of 22 July 2026.
Questions about your privacy? Email compliance@everedgegroup.com.