Legal / privacy
Privacy policy
Effective 7 September 2026
This policy explains how aifel.ai handles information submitted through the public website. Data used in a client project is governed by its own agreement.
1. Who controls the data
Aifel Labs FZ-LLC, Dubai, United Arab Emirates, is responsible for personal data collected through this website. Privacy questions and rights requests can be submitted through the inquiry form.
2. Inquiry data
If you submit an inquiry, we receive your name, email address, optional company, selected primary reason, message, submission time, and the policy version you accepted. We use this information to review and respond to the inquiry, prevent abuse, keep necessary business records, and establish or manage a requested business relationship.
Validated inquiries are sent securely from the website server to the private service Aifel uses to receive and route inquiries. The destination is not exposed to the browser. We may use hosting, automation, communications, and professional-service providers under appropriate contractual controls. We do not sell personal data.
3. AI-assisted assessment and demonstrations
When you run the homepage process assessment, the process description and answers you enter may be sent through Aifel Labs' server to OpenAI to produce a preliminary assessment. In the fictional Atelier and ORBIT demonstrations, a room brief or journey request may be sent through the same server-side route to interpret your intent. Each interface labels this transfer beside the relevant input.
Do not enter personal, confidential, regulated, or client data in these public AI interfaces. Their outputs are exploratory or synthetic, may be inaccurate, and are not used by this website to make legal or similarly significant decisions about people. Human validation is required before any project decision or implementation.
4. Essential session and abuse controls
The site sets a random, first-party, HTTP-only session cookie for up to 24 hours. The server uses a one-way derived value for rate limits and provider safety controls. Application logs are designed to record operational outcomes and request references without inquiry text, names, email addresses, raw cookie values, or provider response bodies. Infrastructure access logs may separately contain standard request information needed for security and operations.
5. Optional analytics
Analytics is disabled unless Aifel Labs explicitly enables it. When enabled, the site asks for your choice before sending an allowlisted page path, named page-journey or assessment milestone, and timestamp to a first-party endpoint. The analytics event contains no advertising identifier, form data, inquiry text, or workflow content. The choice is stored in your browser's local storage rather than an analytics cookie. Global Privacy Control and Do Not Track signals disable this optional measurement in the browser.
6. Legal bases, retention, and transfers
Depending on the context, processing may be necessary to take steps you request, based on your consent, required for legal obligations, or supported by our legitimate interests in operating a secure website and responding to business inquiries. We retain data only while needed for those purposes, an active business relationship, dispute handling, or applicable legal obligations, then delete or anonymise it where reasonably possible.
Our company and service providers may process data outside your country. Where a law requires a specific transfer safeguard, the applicable arrangement must be used for that transfer.
7. Your choices and rights
Depending on the law that applies, you may request information, access, correction, deletion, restriction, portability, or objection; withdraw consent for future processing; or complain to a competent authority. A request may be limited where another legal obligation or permitted exception applies. We may need to verify your identity before acting on a request.
8. Security, children, and changes
We use technical and organisational controls intended to reduce unauthorised access, disclosure, alteration, and loss. No internet service can promise absolute security. This business website is not directed to children, and we do not knowingly seek children's personal data through it.
We may update this policy when the website or its data flows change. The effective date identifies the published version.