1. Scope and controller
Akii Technologies, Ltd is the controller of personal data described in this Notice. It is a private company registered in the Dubai International Financial Centre under commercial licence number CL12662, with its registered office at IH-00-01-03-OF-05, Level 3, Innovation One, Dubai International Financial Centre, Dubai, United Arab Emirates. Engagement Bot is a product brand operated by Akii Technologies, Ltd, not a separate legal entity.
This Notice covers website visitors, early-access leads, account users, workspace members, billing contacts, support contacts, affiliate-referred visitors, and other people who interact with the website, account, dashboard, monitoring, drafting, notification, billing, support, security, or product-improvement functions. It also covers identifiable people whose public social-media content is returned by an approved collection route.
A customer may act as a controller when it chooses monitored terms, sources, business purposes, exports, and how to use a suggested comment. Engagement Bot may act as a processor for customer-directed processing where applicable law and the circumstances establish that relationship. A signed data-processing agreement controls that processor relationship. Engagement Bot remains a controller for its own account, security, billing, legal, service-improvement, and independently determined operational purposes.
2. Personal data we collect
- Identity and account data, such as verified email, internal account identifier, Google provider identifier stored as a one-way hash when Google sign-in is used, account status, role, workspace membership, session and access status, and legal acceptance evidence.
- Early-access and attribution data, such as email, consent or request time, landing path, permitted campaign parameters, referrer, affiliate or creator attribution, source location, and delivery or suppression status.
- Workspace and configuration data, such as organization or brand name, website, offer summary, audience, goals, selected platforms, monitored terms, exclusions, communities, language, timezone, cadence, notification settings, and member permissions.
- Business-grounding and brand-voice data, such as customer-supplied facts, products, services, prices, policies, FAQs, examples, proof, use cases, links, source documents, writing preferences, comments, edits, and import evidence.
- Public-source data, such as public post or comment text, title, source and canonical URLs, platform identifier, public author name or handle, public author and community URLs, community name, publication time, language, thread context, engagement metrics, deletion or restriction state, content fingerprints, and the terms or reasons that matched it.
- Opportunity and drafting data, such as scores, classifications, summaries, risk reasons, confidence, model and rule provenance, generated and edited comments, copy or posting markers, dismissals, bookmarks, snoozes, feedback, outcomes, and export activity.
- Usage and value data, such as monitoring runs, records processed, comments unlocked, plan allowances, feature activity, workflow events, time-saved estimates and accumulated totals, and aggregated product-performance measures.
- Billing and entitlement data, such as plan, price mapping, billing period, subscription and access state, Stripe customer and transaction references, invoices, amounts, currency, discounts, tax, payment status, refunds, disputes, cancellation, upgrade or downgrade requests, and retained-configuration choices. We do not store a full payment-card number.
- Communications and support data, such as requested notifications, authentication and service-email delivery, unsubscribe and suppression evidence, support requests, attachments, feedback, complaints, privacy requests, and administrator notes.
- Technical and security data, such as request time, limited browser and device information, network and user-agent data or one-way hashes derived from them, session and access tokens stored as one-way hashes, rate-limit events, signed integration events, error and performance telemetry, security events, and audit logs.
- Website and product analytics, such as a privacy-filtered page location, approved interaction event, permitted campaign parameters, filtered referrer, browser and device characteristics, language, approximate location, analytics identifier, and analytics preference.
3. Sources of personal data
We collect information directly from you and authorized workspace users, from your browser or device, from Akii-owned products and Marquorum where you use shared identity or affiliate attribution, and from providers used for authentication, email, billing, analytics, observability, hosting, and support.
We receive public social-media content and related public metadata through approved routes operated by providers such as Bright Data, Apify, and an official platform API where enabled. The customer’s monitored terms and platform choices determine the requested search. We may also revisit a public source to verify freshness, deletion, or context where the route supports it.
We receive AI response content and request metadata from approved AI routing and model inference providers. We may receive subscription, payment, refund, dispute, invoice, and fraud status from Stripe, and attribution or commercial-event status from Marquorum.
4. Why we use personal data
- Provide accounts, workspaces, public-conversation monitoring, opportunity ranking, AI-assisted comments, manual-posting links, notifications, exports, billing controls, support, and requested product functions.
- Configure and improve relevance, safety, source quality, grounding, brand voice, drafts, user experience, reliability, capacity, and plan fit.
- Calculate and display usage, plan allowances, upgrade evidence, workflow progress, and estimated or accumulated time saved.
- Authenticate users, secure sessions and integrations, prevent abuse and fraud, enforce terms, investigate incidents, recover failed work, and maintain audit evidence.
- Process subscriptions, payments, invoices, refunds, disputes, taxes, affiliate attribution, and application-owned entitlements.
- Deliver required service messages and customer-selected opportunity notifications, and send optional product communications where permitted by the recorded preference and applicable law.
- Measure website and product performance through privacy-filtered first-party events and Google Analytics, subject to the available opt-out control.
- Comply with law, court orders, regulatory duties, accounting and tax duties, establish or defend claims, and respond to valid rights requests.
- Create aggregated or de-identified statistics, including product-performance and time-saved reporting, that do not reasonably identify a person or customer.
5. Legal bases
Contract and requested steps. We process account, workspace, configuration, monitoring, drafting, subscription, billing, support, and required communication data to enter into and perform the customer agreement or take requested pre-contract steps.
Legitimate interests. We operate and improve the service, identify relevant public business conversations, protect accounts, prevent abuse, measure performance and value, administer relevant product communications, enforce agreements, establish or defend claims, and maintain business continuity. We assess necessity, proportionality, public context, source expectations, sensitivity, customer purpose, and individual rights before relying on this basis.
Legal obligation. We process information to meet applicable data-protection, tax, accounting, sanctions, court, regulatory, security, and record-keeping duties.
Consent. We rely on consent where applicable law requires it, including certain optional marketing and analytics where required. You may withdraw consent without affecting earlier lawful processing.
Other lawful grounds. We may process information to protect vital interests, perform a public-interest task, establish legal claims, or rely on another ground expressly available under applicable law.
6. Account access and legal acceptance
When you request a passwordless link, we use the email, limited request evidence, a single-use token, delivery status, and return path to send and secure it. Merely opening the link does not create a session. Confirmation consumes the link and may verify the email, activate an authorized account, record the applicable legal acceptance, and create a revocable session.
When you choose Google sign-in, Google authenticates you and returns a stable account identifier, verified email, basic identity claims, and a signed identity token. We store the provider identifier only as a one-way hash, do not receive your Google password, request only identity scopes, do not request Gmail or Drive access, and do not retain a Google access or refresh token.
We retain the legal document set, version, hashes, effective date, displayed acceptance text, acceptance action, verified identity, timestamp, source context, and bounded one-way security evidence. This evidence protects both parties and supports electronic contracting and legal-record requirements.
8. AI and automated processing
Engagement Bot sends bounded business-grounding data, campaign configuration, public conversation context, platform or community constraints, and draft context to approved AI routing and model inference providers when model-assisted scoring, recommendations, or drafting is enabled. We exclude social-account credentials and do not intentionally send payment-card data, authentication tokens, or unnecessary sensitive data.
AI requests may pass through one or more approved routing and model inference providers. The provider or model may change for resilience or a product change. Provider retention and training rules can vary, so we do not promise that every provider applies the same policy. We configure available privacy controls and minimize submitted content, but customers must not place confidential or sensitive personal data in ordinary product fields.
Automated rules and models help rank conversations, classify intent and risk, generate summaries and comments, and recommend configuration. They do not post to a social platform or make a final decision about a person with legal or similarly serious effect. A customer reviews the original source and decides whether to use a draft. You may provide feedback, dismiss an opportunity, edit a comment, or choose not to post.
9. Who receives personal data
- Akii Technologies, Ltd personnel and authorized contractors who need the information for their role and are subject to confidentiality and access controls.
- Supabase for managed database and authentication infrastructure, and Railway for the web application and isolated worker hosting.
- Approved AI routing and model inference providers for bounded AI processing. Their processing may include request metadata and the prompt and response content needed for the request.
- Bright Data, Apify, and an approved official platform API for customer-directed public-source collection, route operation, usage, provenance, and provider support.
- Stripe for checkout, customer billing, payment methods, invoices, refunds, disputes, fraud controls, tax support, and subscription events.
- Resend for authentication, required service email, customer-selected notifications, optional product email, delivery evidence, and suppression.
- Google for optional account authentication and bounded Google Analytics across website and product pages.
- Sentry for bounded error, performance, release, and incident telemetry. Product code is designed to exclude secrets and unnecessary source or customer content from telemetry.
- Marquorum and other Akii-owned product systems for shared identity where used, affiliate attribution, subscription and refund event handoff, creator-code continuity, and portfolio operations allocated to those systems.
- Professional advisers, auditors, insurers, banks, investors, acquirers, and transaction counterparties under appropriate confidentiality and due-diligence controls.
- Courts, regulators, law enforcement, tax authorities, sanctions authorities, platforms, and other competent recipients where disclosure is required or lawfully necessary to protect rights, safety, or service integrity.
10. No sale or behavioural advertising
We do not sell personal data for money. We do not share customer account, workspace, public-source, or draft data for cross-context behavioural advertising. We do not use Google Analytics advertising features. If a future practice is treated as a sale, targeted-advertising disclosure, or regulated sharing under applicable law, we will provide the notice and choice required before starting it.
11. Email and notification choices
Authentication, security, billing, subscription, incident, legal, and support messages are sent as needed to operate the account or meet a duty. A customer may separately choose campaign notifications after each completed scan, daily, weekly, or off, subject to plan and cadence. Notification email contains bounded opportunity summaries and directs the user back to the manual-review workflow.
Early-access and other product updates use the recorded consent or another lawful basis permitted in the recipient’s location. Every promotional email contains a working no-login unsubscribe. A promotional unsubscribe does not disable authentication, security, billing, legal, or requested campaign messages. A campaign-level unsubscribe does not change another campaign or user preference.
13. International transfers
Engagement Bot is operated from the DIFC and serves an international professional customer base. Providers, model infrastructure, social platforms, public sources, support personnel, and users may be located outside the DIFC and the United Arab Emirates. Personal data may therefore be processed in other countries.
We use a transfer mechanism available under applicable law, such as a recognized adequate jurisdiction, contractual safeguards, approved standard clauses, a necessary contract transfer, a legal obligation, or another permitted derogation. We assess the recipient, purpose, data, country, security, onward transfers, and enforceable rights where required. You may ask for information about safeguards relevant to your data.
14. Retention
We retain personal data only for the purpose collected and for legitimate service, legal, accounting, security, audit, dispute, and enforcement needs. We consider the relationship, record type, source availability, customer actions, sensitivity, risk, applicable limitation periods, provider rules, and mandatory duties.
- Unconsumed passwordless links expire after 15 minutes. Limited registration, delivery, and abuse-prevention evidence may be retained for up to 90 days, or longer when linked to an incident or active account record.
- Raw provider observations are scheduled for deletion after 30 days under the current public-source route policy. Normalized public-source records receive a retention review after 12 months and may be deleted, de-identified, refreshed, or retained where still linked to an active customer workflow, user action, objection, security need, or legal hold.
- Active account, workspace, configuration, grounding, opportunity, draft, usage, time-saved, acceptance, support, and notification records are retained during the relationship. After closure they are normally deleted, de-identified, or placed beyond ordinary use within 90 days, except for records retained under the categories below and backups that cycle out under provider schedules.
- Billing, payment, refund, dispute, tax, accounting, fraud, sanctions, agreement, and legal-claim records may be retained for up to ten years where applicable law, an authority, risk, or a claim reasonably requires it.
- Routine technical, model-request metadata, audit, and security records are normally retained for up to 24 months. Incident evidence may be retained until investigation, remediation, and applicable claim periods end.
- Google Analytics user-level and event-level data is retained for 14 months. Aggregated or irreversibly de-identified analytics and time-saved statistics may be retained without an account-level period.
- Marketing objections, unsubscribe evidence, source-content objections, and minimum suppression fingerprints may be retained for as long as reasonably necessary to honor the choice and prevent accidental re-enrollment or re-collection.
- Data subject to a dispute, chargeback, investigation, legal hold, security incident, rights request, or authority request is retained until the hold and required follow-up end.
15. Security
We use technical and organizational measures designed for the nature and risk of the processing. These include passwordless single-use access, optional Google identity verification, scanner-safe confirmation, hashed tokens and request evidence, HTTP-only session controls, role-based access, least privilege, row-level database security, service isolation, signed integrations, bounded provider credentials, rate limits, immutable legal and financial evidence, monitoring, secret scanning, backups, recovery procedures, and raw-provider retention controls.
No system is completely secure. You must protect your email account, Google account, device, session, workspace permissions, exports, and connected services and notify us promptly of suspected compromise. If a personal-data breach creates a legal reporting duty, we will notify the DIFC Commissioner and affected people as applicable.
16. Your rights
Depending on applicable law and the circumstances, you may have the right to be informed, access personal data, receive a copy, correct inaccurate data, erase data, restrict processing, object to processing, withdraw consent, receive portable data, and request human review of certain automated decisions. You may object to direct marketing at any time and without charge.
A right may be limited by another person’s rights, legal privilege, confidentiality, security, fraud prevention, a legal duty, an ongoing claim, source integrity, or an applicable exemption. We will explain a refusal where law permits. We do not charge for an ordinary request, but applicable law may allow a reasonable fee or refusal for a manifestly unfounded, excessive, or repetitive request.
To exercise a right, email hello@marquorum.com or write to the registered office. You do not need an Engagement Bot account. We may verify identity, email control, authority, source URL, country, and request scope before disclosing or changing data. We aim to respond within one month where the DIFC Data Protection Law applies, subject to lawful extensions for complexity or volume.
17. Questions and complaints
Contact us first at hello@marquorum.com so we can investigate and respond. You may also lodge a complaint with the DIFC Commissioner of Data Protection or another competent supervisory authority that applies to you. Exercising a right or making a complaint will not result in retaliation.
The DIFC Data Protection Law may also provide a private right of action through the DIFC Courts in circumstances defined by that law.
18. Children
Engagement Bot is a professional service for adults. It is not directed to children, and account users must be at least 18 and of legal majority where they live. Customers must not use it to identify or target children. Public-source filters may not identify every child correctly. If you believe we processed a child’s personal data, contact us so we can investigate and take appropriate action.
19. Changes to this Notice
We may update this Notice to reflect changes in law, service, providers, models, platforms, products, or processing. The version and effective date identify the current Notice. We will provide reasonable advance notice of a material change through email, dashboard notice, or a new acknowledgement where appropriate, unless an immediate update is required by law, security, or urgent risk.
A new Notice does not convert an earlier unlawful purpose into a lawful one. If a change requires consent or another specific action, we will obtain it before that processing begins. A material change to the customer legal set may require fresh acceptance.
20. Controller contact
Akii Technologies, Ltd, IH-00-01-03-OF-05, Level 3, Innovation One, Dubai International Financial Centre, Dubai, United Arab Emirates. Email: hello@marquorum.com. This contact method is available without creating an account.
REFERENCED SERVICES AND AUTHORITIES
Current external terms and authorities
External terms can change independently. The current version published by the provider or authority applies to its own service or function.
- DIFC Commissioner of Data Protection
The supervisory authority for the DIFC Data Protection Law and an official source for rights, complaints, transfers, and guidance.
- DIFC Data Protection Law No. 5 of 2020
The current DIFC legal framework for personal data, rights, transfers, security, and direct marketing.
- Bright Data Privacy Policy
Bright Data’s current privacy terms for its own services and public-web data products.
- Apify Privacy Policy
Apify’s current privacy terms and its controller and processor role explanations.
- Stripe Privacy Center
Stripe’s explanation of payment-service data and privacy rights.
- Google Privacy Policy
Google’s privacy terms for optional identity authentication and bounded Analytics.
- Google Analytics privacy and safeguards
Google’s explanation of how Analytics data is protected and processed.
