Privacy Policy
How Second Sight collects, uses, protects, and never misuses your information.
Our Core Privacy Commitments
| Commitment | What It Means |
|---|---|
| Zero Data Retention | Your inputs are never used to train AI models by any third party. |
| UAE Data Law Compliant | Aligned with Federal Decree-Law No. 45 of 2021 (UAE PDPL). |
| No Data Selling | Your data is never sold, rented, or traded to any third party. |
| AFZA Licensed | Operated by an entity licensed for e-commerce by the Ajman Free Zone Authority (AFZA) in the United Arab Emirates. |
SECTION 01 — Overview
Second Sight FZE (“Second Sight,” “we,” “us,” or “our”) is committed to protecting the privacy and confidentiality of all personal and organizational data entrusted to us by users of the Second Sight platform.
This Privacy Policy explains how we collect, use, store, share, and protect personal data and organizational data when you use our Platform, visit our website at secondsight.tech, or interact with us in any capacity.
We operate in compliance with the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (“UAE PDPL”), the regulations of the Ajman Free Zone Authority governing licensed entities, and where applicable, the European Union's General Data Protection Regulation (GDPR).
A Custodian of Your Strategy
Second Sight processes highly sensitive strategic organizational data. We have designed our data practices around the principle that your strategic information is yours. We are only its temporary custodian for the purpose of delivering our services.
SECTION 02 — Data Controller
The data controller responsible for your personal data is:
- Company: Second Sight FZE
- Jurisdiction: Ajman Free Zone, Ajman, United Arab Emirates
- Licensing Authority: Ajman Free Zone Authority (AFZA) — E-Commerce Licence
For enterprise customers with a Data Processing Agreement in place, Second Sight acts as a data processor with respect to personal data contained within organizational User Data.
SECTION 03 — What We Collect
Account and Identity Data
- Full name
- Business email address
- Organization name, industry, and country
- Password (stored in encrypted, non-reversible form)
Platform Usage Data (User Data)
- Focal issues or strategic questions
- Driving forces, key uncertainties, and scenario narratives you create
- Financial baseline data and modeling inputs you provide
- Signpost monitoring entries and environmental scan data
- Workshop session records, collaboration activity, and participant inputs
Technical and Analytics Data
- IP address, browser type, device type, and operating system
- Pages visited, features used, and session duration
- Error logs and performance diagnostics
- Cookies and similar tracking technologies (see Section 11)
| Data Category | Sensitivity | Stored in UAE? |
|---|---|---|
| Account and Identity | Standard | Yes, primary storage |
| Strategic User Data | Highly Sensitive | Yes, UAE/GCC region servers |
| Financial Modeling Data | Highly Sensitive | Yes, encrypted at rest |
| Analytics and Usage | Low | Yes, anonymized |
SECTION 04 — How We Use Your Data
Service Delivery
- Processing your scenario planning inputs and generating Scenario Outputs
- Enabling collaboration features between team members
- Delivering signpost alerts and environmental monitoring notifications
- Generating and formatting board-ready reports and presentations
- Maintaining your organizational strategic memory and scenario history
Platform Improvement
- Analyzing anonymized, aggregated usage patterns to improve features
- Identifying and resolving technical errors and performance issues
Communications
- Sending transactional emails (account confirmation, password reset, billing)
- Delivering product updates and feature announcements
- Responding to support requests and enquiries
- Sending marketing communications where you have given consent (opt-out available at any time)
Strict Usage Limit
We do not use your strategic User Data for any purpose other than delivering the services you have requested. We do not sell this data, share it with advertisers, or use it to benchmark against other organizations without explicit consent.
SECTION 05 — Legal Basis for Processing
| Processing Purpose | Legal Basis |
|---|---|
| Account creation and service delivery | Contract performance |
| Billing and payment processing | Contract performance / Legal obligation |
| Platform security and fraud prevention | Legitimate interests |
| Product analytics and improvement | Legitimate interests (anonymized) |
| Marketing communications | Consent (withdrawable at any time) |
| Legal compliance and regulatory response | Legal obligation |
SECTION 07 — AI Processing and Zero Data Retention
Second Sight uses advanced AI language models to power its scenario generation, analysis, and output features. We understand that the strategic data you input to the Platform is among the most sensitive information your organization possesses.
Zero Data Retention (ZDR) Basis
Second Sight operates exclusively on a Zero Data Retention (ZDR) basis with its AI infrastructure providers. Your inputs are processed in real time to generate outputs and are not stored, logged, or used for AI model training by any third-party infrastructure provider.
What this means in practice:
- Your strategic inputs are not retained by AI model providers after processing.
- Your data is not used to train, fine-tune, or improve any third-party AI model.
- No third-party AI provider has persistent access to your organizational data.
- All AI processing occurs under enterprise API agreements with explicit zero retention commitments.
SECTION 08 — Security
Technical Measures
- AES-256 encryption for all data at rest.
- TLS 1.3 encryption for all data in transit.
- Multi-factor authentication available for all accounts; mandatory for enterprise accounts.
- Role-based access controls limiting data access to authorized personnel only.
- Regular penetration testing by independent security specialists.
- Data hosted on ISO 27001-certified infrastructure within the UAE/GCC region.
Organizational Measures
- Strict data access controls with explicit audit logging.
- Regular staff security training and data protection awareness programs.
- Background checks for all personnel with access to platform infrastructure.
- Documented incident response plan with regulatory notification procedures.
In the event of a data breach that poses a risk to your rights and interests, we will notify affected users and the relevant regulatory authority within 72 hours of becoming aware of the breach, as required by applicable law.
SECTION 09 — Your Rights
Under UAE PDPL and applicable international data protection law, you have the following rights regarding your personal data:
| Right | Description |
|---|---|
| Right of Access | Request a copy of all personal data we hold about you, including a full export of your User Data. |
| Right to Rectification | Request correction of any inaccurate or incomplete personal data. |
| Right to Erasure | Request deletion of your personal data and User Data, subject to legal retention requirements. |
| Right to Portability | Receive your User Data in a structured, machine-readable format. |
| Right to Restrict Processing | Request that we limit the processing of your data in certain circumstances. |
| Right to Object | Object to processing based on legitimate interests, including marketing. |
To exercise any of these rights, submit a request to support@secondsight.tech.
SECTION 11 — International Data Transfers
Second Sight's primary data storage is located within the UAE and GCC region. Where data may be processed outside the UAE, we ensure appropriate safeguards are in place including standard contractual clauses or adequacy decisions under UAE PDPL.
Enterprise customers requiring data residency exclusively within UAE borders may request our Private Deployment option.
SECTION 12 — Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and by posting a prominent notice on the Platform at least 14 days before the changes take effect.
SECTION 13 — Contact and Complaints
For privacy questions, concerns, or complaints, please contact our team at:
If you are not satisfied with our response, you have the right to lodge a complaint with the UAE Data Office or the relevant supervisory authority in your jurisdiction.
