Shamz
shamz

Shamz.ai Privacy Policy (B2B)

Last updated: May 4, 2026

Company: Shamz For Artificial Intelligence LLC (doing business as "Shamz.ai")

Address: Shams Media City, Sharjah, UAE

Privacy contact: PRIVACY@SHAMZ.AI

1. Scope

This Privacy Policy explains how Shamz.ai collects, uses, shares, and protects personal data when you:

  • Visit our websites and pages that link to this Policy;
  • Create and manage a business account for Shamz.ai;
  • Use our B2B AI front desk platform (each AI-powered conversational agent is an "AI Front Desk"), including related dashboards, APIs, integrations, analytics, and support (the "Business Services").

This Policy does not cover third-party websites or services you integrate with Shamz.ai.

2. Roles: When We Act as Controller vs. Processor

Because Shamz.ai is a B2B platform, there are two common roles:

A) Shamz.ai as a Controller

We act as a controller for personal data we collect and use for our own business purposes, such as:

  • Account owner and authorized user details;
  • Billing and payment administration data;
  • Sales/marketing contacts and communications;
  • Website analytics and security logs.

B) Shamz.ai as a Processor (Customer Data)

When your company uses Shamz.ai to run an AI Front Desk for your end users (e.g., your customers, website visitors, employees), Shamz.ai typically processes those conversations and related data on your instructions. In that case:

  • Your company is the controller of that end-user data; and
  • Shamz.ai is the processor.

If you need it, we can provide a Data Processing Addendum (DPA) upon request or as part of your contract pack.

3. Personal Data We Collect

A) Business Account and Contact Data

  • Name, work email, phone number, company name, job title
  • Login credentials (password stored hashed), MFA information
  • User roles/permissions (admin, agent, analyst, etc.)

B) Billing and Transaction Data

  • Billing contact details, billing address
  • Invoices, subscription plan details, payment status
  • Payment method tokens and limited card details (e.g., last four digits) if provided by payment providers

(We generally do not store full card numbers.)

C) Service Data (Configuration + Usage)

  • Bot configuration (intents, flows, knowledge base pointers, routing rules)
  • Integration settings (e.g., CRM/helpdesk connections)
  • Analytics and performance metrics (volumes, response times, resolution rates)
  • Audit logs (admin actions, settings changes)

D) Conversation and Support Data

Depending on customer configuration, we may process:

  • Chat transcripts and messages
  • Attachments uploaded into chats (files/images) if enabled
  • Support tickets, emails, call notes, and troubleshooting logs

E) Website and Device Data (Automatic)

  • IP address, approximate location derived from IP
  • Browser type, device identifiers, operating system
  • Pages visited, session duration, referrer URLs
  • Cookies and similar tracking technologies (see "Cookies & Analytics" below)

Cookies & Analytics

We use Google Analytics 4 to understand how visitors use our website, measure the effectiveness of our marketing campaigns, and improve our services. Google Analytics collects information such as:

  • Pages you visit and time spent on each page
  • How you arrived at our site (referrer)
  • Your general location (country/city level)
  • Device and browser information
  • Interactions with buttons, forms, and other elements

Google Analytics data is retained for 14 months. You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on or by adjusting your browser's cookie settings. For more information, see Google's Privacy Policy.

4. How We Use Personal Data

We process personal data on the legal bases set out by UAE Federal Decree-Law 45/2021 (Personal Data Protection Law, "PDPL") Article 4, namely: performance of a contract with you, our legitimate interests where they do not override your rights, your consent where required, and compliance with legal obligations. The legal basis for each category of use is identified inline below.

A) Provide and Operate the Business Services (Legal basis: Contract)

  • Create accounts, authenticate users, manage permissions
  • Deliver AI Front Desk functionality, dashboards, APIs, and integrations
  • Provide customer support and technical assistance

B) Security, Abuse Prevention, and Reliability (Legal basis: Legitimate interest)

  • Monitor for suspicious activity, prevent abuse and fraud
  • Maintain logs for security auditing and incident investigation
  • Debug, monitor uptime, and improve stability

C) Billing and Contract Administration (Legal basis: Contract and legal obligation)

  • Process subscriptions, payments, renewals, invoices
  • Communicate service notices and administrative messages

D) Product Improvement (Legal basis: Legitimate interest)

  • Understand usage patterns and improve features
  • Develop new capabilities and performance enhancements

E) Marketing (B2B) (Legal basis: Consent / legitimate interest)

Send product updates and promotional communications to business contacts where permitted. You can opt out of marketing emails using the unsubscribe link or by contacting us.

5. AI Services, Subprocessors, and Model Training

Shamz.ai may provide AI-assisted features (e.g., suggested replies, summarization, intent classification).

  • Customer Data (processor role): We process Customer Data to provide the service. We do not use Customer Data to train general-purpose models for other customers unless your contract (or explicit opt-in) allows it.
  • De-identified/aggregated data: We may use de-identified or aggregated data to improve reliability, security, and product performance where permitted by law and contract.
  • Third-party AI providers: Some AI functions may be delivered using third-party infrastructure. We share only what is necessary to provide the feature and apply contractual safeguards.

5.1 AI Service Provider (Microsoft Azure OpenAI)

Shamz.ai uses Microsoft Azure OpenAI Service as its AI/LLM provider. Features such as chatbot responses, suggested replies, summarization, and intent classification are generated by large language models hosted on Microsoft Azure.

What we send to Azure OpenAI: user messages, conversation context (recent chat history within a session), and prompt metadata necessary to generate a response. We do not send credentials, passwords, or Google OAuth tokens to the model.

Microsoft's data processing terms: Azure OpenAI processes data under Microsoft's enterprise data processing terms. Microsoft does not use customer data submitted to Azure OpenAI to train, retrain, or improve OpenAI foundation models or any Microsoft or third-party products. For details, see the Azure OpenAI data, privacy, and security documentation.

Google user data: Data obtained via Google APIs (including information received through Google OAuth sign-in) is handled in accordance with the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not used to train, fine-tune, or otherwise improve AI/ML models, and is not sold or transferred to third parties except as required to provide or improve user-facing features, comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users.

6. How We Share Personal Data

We may share personal data with:

A) Service Providers (Sub-processors)

Vendors who help us deliver the Business Services, such as:

  • Cloud hosting and infrastructure
  • AI/LLM inference (Microsoft Azure OpenAI Service)
  • Customer support systems
  • Analytics and monitoring providers (including Google Analytics 4 for website usage analytics and conversion tracking)
  • Payment processors
  • Security and fraud prevention tools

We require service providers to protect personal data and use it only for the services they provide to us.

B) Your Organization (Admins)

Your organization's administrators may access your team's account data, settings, and (depending on configuration) conversation history.

C) Legal and Compliance

We may disclose information if we believe it is necessary to:

  • Comply with applicable law or legal process
  • Protect the rights, safety, and security of Shamz.ai, our customers, and others
  • Enforce our contracts and policies

D) Business Transfers

If we undergo a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of the transaction, subject to appropriate protections.

7. International Transfers

Although Shamz.ai is established in the United Arab Emirates, the production environment that hosts the Business Services is operated on Microsoft Azure in the East US 2 region (United States). Personal data submitted to the Business Services therefore leaves the UAE and is processed in the United States. Some sub-processors may also process data in other regions where they operate.

We rely on the following safeguards for these cross-border transfers under UAE Federal Decree-Law 45/2021 (PDPL) Article 22:

  • Standard Contractual Clauses incorporated through Microsoft's Online Services Data Protection Addendum, which Shamz.ai has executed for its Azure environment.
  • Encryption in transit and at rest for all data stored on Azure-managed infrastructure.
  • Sub-processor flow-down obligations requiring our other sub-processors (e.g., payment processors, communication providers) to apply equivalent protections.

You may request a copy of the cross-border transfer mechanism applicable to your account by contacting privacy@shamz.ai.

8. Data Retention

We retain personal data only for as long as it is needed for the purposes described in this Policy, to comply with our legal obligations under UAE law (including the Federal Decree-Law on Tax Procedures, which requires accounting records to be kept for a minimum period), and to resolve disputes or enforce agreements. The default retention periods we apply are:

  • Billing and financial records (invoices, payments, tax records): 5 years after the end of the calendar year in which the record was created, in line with UAE tax record-keeping requirements.
  • Account and contact data (workspace owner, admin users, billing contact): 3 years after termination of the contract, then deleted or anonymised.
  • End-user conversation transcripts (chat sessions, messages, attachments): 90 days from session end, except where the transcript is preserved as part of a billing record, a security investigation, or an anticipated legal claim.
  • Service-desk tickets and lead records: 12 months from last activity, then anonymised so the operational metrics survive without the personal identifiers.
  • Marketing analytics (Google Analytics 4 web data): 14 months, matching our GA4 retention configuration.
  • System backups: 30 days on a rolling basis, after which they are overwritten.

On termination of the contract, Customer Data is handled in accordance with the order form, Master Subscription Agreement, and/or DPA — including export and deletion within the timeframes set out there. Where a longer retention period is required by law, we keep only the data necessary for that legal obligation and isolate it from active processing.

9. Security

We use reasonable administrative, technical, and organizational measures designed to protect personal data, such as:

  • Access controls and least-privilege permissions
  • Encryption in transit (and at rest where appropriate)
  • Logging and monitoring for security events

No system can be guaranteed 100% secure. You are responsible for maintaining strong passwords and controlling access to your admin accounts.

10. Your Rights and Choices

A) Business Contacts and Authorized Users

If your personal data is processed by Shamz.ai as data controller, you have the following rights under UAE Federal Decree-Law 45/2021 (PDPL):

  • Right of access — to obtain confirmation of whether we process your personal data and a copy of that data.
  • Right to correction — to ask us to rectify inaccurate or incomplete personal data.
  • Right to erasure — to ask us to delete your personal data, subject to legal retention obligations.
  • Right to data portability — to receive your personal data in a structured, commonly-used format.
  • Right to object — to processing based on our legitimate interests, including direct marketing.
  • Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting prior lawful processing.
  • Right to restrict processing — in specific circumstances permitted by PDPL.

How to exercise these rights: email privacy@shamz.ai with your request and enough information to verify your identity. We will respond within 30 days as required by PDPL Article 13. If we cannot meet a request (for example, where retention is legally required), we will explain the reason.

B) End Users of Your AI Front Desk

If you are an end user interacting with an AI Front Desk operated by one of our business customers, please contact that business directly regarding privacy rights. Shamz.ai processes that data on the customer's instructions (processor role) and we will support the customer in responding to your request.

11. Cookies

We use cookies and similar technologies to operate our websites and improve performance. You can manage cookies through your browser settings. Where available, we provide cookie preference controls.

12. Children's Data

The Business Services are intended for use by businesses and their authorised personnel. Shamz.ai does not knowingly collect personal data of individuals under the age of 18, and the Business Services are not directed at children. End users interacting with an AI Front Desk operated by one of our customers should rely on that customer's own age requirements.

If you believe a minor's personal data has been collected through the Business Services, please contact privacy@shamz.ai and we will take reasonable steps to delete it.

13. Privacy Officer and Complaints

Shamz.ai has appointed a Privacy Officer who is responsible for overseeing privacy compliance and handling enquiries from data subjects. You can reach the Privacy Officer at privacy@shamz.ai.

If, after contacting us, you believe that your personal data has not been handled in accordance with UAE Federal Decree-Law 45/2021 (PDPL) or this Policy, you have the right to lodge a complaint with the UAE Data Office, the supervisory authority for personal data protection in the United Arab Emirates.

14. Changes

We may update this Privacy Policy from time to time. We will update the "Last updated" date and may provide additional notice where required.

15. Contact

For privacy requests or questions:

Email: privacy@shamz.ai

Address: Shams Media City, Sharjah, UAE