LEGAL DOCUMENTATION

Privacy Policy

How Second Sight collects, uses, protects, and never misuses your information.

Our Core Privacy Commitments

CommitmentWhat It Means
Zero Data RetentionYour inputs are never used to train AI models by any third party.
UAE Data Law CompliantAligned with Federal Decree-Law No. 45 of 2021 (UAE PDPL).
No Data SellingYour data is never sold, rented, or traded to any third party.
AFZA LicensedOperated by an entity licensed for e-commerce by the Ajman Free Zone Authority (AFZA) in the United Arab Emirates.

SECTION 01 — Overview

Second Sight FZE (“Second Sight,” “we,” “us,” or “our”) is committed to protecting the privacy and confidentiality of all personal and organizational data entrusted to us by users of the Second Sight platform.

This Privacy Policy explains how we collect, use, store, share, and protect personal data and organizational data when you use our Platform, visit our website at secondsight.tech, or interact with us in any capacity.

We operate in compliance with the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (“UAE PDPL”), the regulations of the Ajman Free Zone Authority governing licensed entities, and where applicable, the European Union's General Data Protection Regulation (GDPR).

A Custodian of Your Strategy

Second Sight processes highly sensitive strategic organizational data. We have designed our data practices around the principle that your strategic information is yours. We are only its temporary custodian for the purpose of delivering our services.

SECTION 02 — Data Controller

The data controller responsible for your personal data is:

  • Company: Second Sight FZE
  • Jurisdiction: Ajman Free Zone, Ajman, United Arab Emirates
  • Licensing Authority: Ajman Free Zone Authority (AFZA) — E-Commerce Licence

For enterprise customers with a Data Processing Agreement in place, Second Sight acts as a data processor with respect to personal data contained within organizational User Data.

SECTION 03 — What We Collect

Account and Identity Data

  • Full name
  • Business email address
  • Organization name, industry, and country
  • Password (stored in encrypted, non-reversible form)

Platform Usage Data (User Data)

  • Focal issues or strategic questions
  • Driving forces, key uncertainties, and scenario narratives you create
  • Financial baseline data and modeling inputs you provide
  • Signpost monitoring entries and environmental scan data
  • Workshop session records, collaboration activity, and participant inputs

Technical and Analytics Data

  • IP address, browser type, device type, and operating system
  • Pages visited, features used, and session duration
  • Error logs and performance diagnostics
  • Cookies and similar tracking technologies (see Section 11)
Data CategorySensitivityStored in UAE?
Account and IdentityStandardYes, primary storage
Strategic User DataHighly SensitiveYes, UAE/GCC region servers
Financial Modeling DataHighly SensitiveYes, encrypted at rest
Analytics and UsageLowYes, anonymized

SECTION 04 — How We Use Your Data

Service Delivery

  • Processing your scenario planning inputs and generating Scenario Outputs
  • Enabling collaboration features between team members
  • Delivering signpost alerts and environmental monitoring notifications
  • Generating and formatting board-ready reports and presentations
  • Maintaining your organizational strategic memory and scenario history

Platform Improvement

  • Analyzing anonymized, aggregated usage patterns to improve features
  • Identifying and resolving technical errors and performance issues

Communications

  • Sending transactional emails (account confirmation, password reset, billing)
  • Delivering product updates and feature announcements
  • Responding to support requests and enquiries
  • Sending marketing communications where you have given consent (opt-out available at any time)

Strict Usage Limit

We do not use your strategic User Data for any purpose other than delivering the services you have requested. We do not sell this data, share it with advertisers, or use it to benchmark against other organizations without explicit consent.

SECTION 06 — Data Sharing

Second Sight does not sell, rent, or trade your personal data or User Data to any third party under any circumstances.

Service Providers

We engage a small number of carefully vetted third-party service providers who process data on our behalf under strict contractual data processing agreements. Each provider is bound by confidentiality obligations and is prohibited from using your data for any purpose other than providing the contracted service.

AI Infrastructure

The Platform uses AI language model infrastructure to generate scenario outputs. Please see Section 7 for our specific commitments regarding AI data processing.

Legal Requirements

We may disclose data where required to do so by applicable law, court order, or governmental authority. Where legally permitted, we will notify you of such a requirement before disclosure.

SECTION 07 — AI Processing and Zero Data Retention

Second Sight uses advanced AI language models to power its scenario generation, analysis, and output features. We understand that the strategic data you input to the Platform is among the most sensitive information your organization possesses.

Zero Data Retention (ZDR) Basis

Second Sight operates exclusively on a Zero Data Retention (ZDR) basis with its AI infrastructure providers. Your inputs are processed in real time to generate outputs and are not stored, logged, or used for AI model training by any third-party infrastructure provider.

What this means in practice:

  • Your strategic inputs are not retained by AI model providers after processing.
  • Your data is not used to train, fine-tune, or improve any third-party AI model.
  • No third-party AI provider has persistent access to your organizational data.
  • All AI processing occurs under enterprise API agreements with explicit zero retention commitments.

SECTION 08 — Security

Technical Measures

  • AES-256 encryption for all data at rest.
  • TLS 1.3 encryption for all data in transit.
  • Multi-factor authentication available for all accounts; mandatory for enterprise accounts.
  • Role-based access controls limiting data access to authorized personnel only.
  • Regular penetration testing by independent security specialists.
  • Data hosted on ISO 27001-certified infrastructure within the UAE/GCC region.

Organizational Measures

  • Strict data access controls with explicit audit logging.
  • Regular staff security training and data protection awareness programs.
  • Background checks for all personnel with access to platform infrastructure.
  • Documented incident response plan with regulatory notification procedures.

In the event of a data breach that poses a risk to your rights and interests, we will notify affected users and the relevant regulatory authority within 72 hours of becoming aware of the breach, as required by applicable law.

SECTION 09 — Your Rights

Under UAE PDPL and applicable international data protection law, you have the following rights regarding your personal data:

RightDescription
Right of AccessRequest a copy of all personal data we hold about you, including a full export of your User Data.
Right to RectificationRequest correction of any inaccurate or incomplete personal data.
Right to ErasureRequest deletion of your personal data and User Data, subject to legal retention requirements.
Right to PortabilityReceive your User Data in a structured, machine-readable format.
Right to Restrict ProcessingRequest that we limit the processing of your data in certain circumstances.
Right to ObjectObject to processing based on legitimate interests, including marketing.

To exercise any of these rights, submit a request to support@secondsight.tech.

SECTION 10 — Cookies and Tracking

Essential Cookies

Required for the Platform to operate and cannot be disabled. They enable session management, security features, and authentication.

Analytics Cookies

We use privacy-respecting analytics tools to understand how users navigate the Platform. All analytics data is anonymized and aggregated.

Marketing Cookies

We do not use third-party advertising or retargeting cookies on the Platform. On our public website, limited marketing cookies may be present. These can be declined via our cookie consent banner.

SECTION 11 — International Data Transfers

Second Sight's primary data storage is located within the UAE and GCC region. Where data may be processed outside the UAE, we ensure appropriate safeguards are in place including standard contractual clauses or adequacy decisions under UAE PDPL.

Enterprise customers requiring data residency exclusively within UAE borders may request our Private Deployment option.

SECTION 12 — Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and by posting a prominent notice on the Platform at least 14 days before the changes take effect.

SECTION 13 — Contact and Complaints

For privacy questions, concerns, or complaints, please contact our team at:

Second Sight FZE

Ajman Free Zone, Ajman, United Arab Emirates

Email: support@secondsight.tech

If you are not satisfied with our response, you have the right to lodge a complaint with the UAE Data Office or the relevant supervisory authority in your jurisdiction.