TermsPrivacyMember access

HOW DATA MOVES THROUGH THE BOT

Engagement Bot Privacy Notice

This Notice explains what Akii Technologies, Ltd collects through Engagement Bot, why it uses the information, who receives it, how long it is retained, and the choices and rights available to customers, visitors, and people whose public posts may be processed.

Effective
19 July 2026
Version
2026-07-19.5
Operator
Akii Technologies, Ltd

IN THIS DOCUMENT

  1. Scope and controller
  2. Personal data we collect
  3. Sources of personal data
  4. Why we use personal data
  5. Legal bases
  6. Account access and legal acceptance
  7. Public social-media data
  8. AI and automated processing
  9. Who receives personal data
  10. No sale or behavioural advertising
  11. Email and notification choices
  12. Cookies, attribution, and analytics
  13. International transfers
  14. Retention
  15. Security
  16. Your rights
  17. Questions and complaints
  18. Children
  19. Changes to this Notice
  20. Controller contact

1. Scope and controller

Akii Technologies, Ltd is the controller of personal data described in this Notice. It is a private company registered in the Dubai International Financial Centre under commercial licence number CL12662, with its registered office at IH-00-01-03-OF-05, Level 3, Innovation One, Dubai International Financial Centre, Dubai, United Arab Emirates. Engagement Bot is a product brand operated by Akii Technologies, Ltd, not a separate legal entity.

This Notice covers website visitors, early-access leads, account users, workspace members, billing contacts, support contacts, affiliate-referred visitors, and other people who interact with the website, account, dashboard, monitoring, drafting, notification, billing, support, security, or product-improvement functions. It also covers identifiable people whose public social-media content is returned by an approved collection route.

A customer may act as a controller when it chooses monitored terms, sources, business purposes, exports, and how to use a suggested comment. Engagement Bot may act as a processor for customer-directed processing where applicable law and the circumstances establish that relationship. A signed data-processing agreement controls that processor relationship. Engagement Bot remains a controller for its own account, security, billing, legal, service-improvement, and independently determined operational purposes.

2. Personal data we collect

  • Identity and account data, such as verified email, internal account identifier, Google provider identifier stored as a one-way hash when Google sign-in is used, account status, role, workspace membership, session and access status, and legal acceptance evidence.
  • Early-access and attribution data, such as email, consent or request time, landing path, permitted campaign parameters, referrer, affiliate or creator attribution, source location, and delivery or suppression status.
  • Workspace and configuration data, such as organization or brand name, website, offer summary, audience, goals, selected platforms, monitored terms, exclusions, communities, language, timezone, cadence, notification settings, and member permissions.
  • Business-grounding and brand-voice data, such as customer-supplied facts, products, services, prices, policies, FAQs, examples, proof, use cases, links, source documents, writing preferences, comments, edits, and import evidence.
  • Public-source data, such as public post or comment text, title, source and canonical URLs, platform identifier, public author name or handle, public author and community URLs, community name, publication time, language, thread context, engagement metrics, deletion or restriction state, content fingerprints, and the terms or reasons that matched it.
  • Opportunity and drafting data, such as scores, classifications, summaries, risk reasons, confidence, model and rule provenance, generated and edited comments, copy or posting markers, dismissals, bookmarks, snoozes, feedback, outcomes, and export activity.
  • Usage and value data, such as monitoring runs, records processed, comments unlocked, plan allowances, feature activity, workflow events, time-saved estimates and accumulated totals, and aggregated product-performance measures.
  • Billing and entitlement data, such as plan, price mapping, billing period, subscription and access state, Stripe customer and transaction references, invoices, amounts, currency, discounts, tax, payment status, refunds, disputes, cancellation, upgrade or downgrade requests, and retained-configuration choices. We do not store a full payment-card number.
  • Communications and support data, such as requested notifications, authentication and service-email delivery, unsubscribe and suppression evidence, support requests, attachments, feedback, complaints, privacy requests, and administrator notes.
  • Technical and security data, such as request time, limited browser and device information, network and user-agent data or one-way hashes derived from them, session and access tokens stored as one-way hashes, rate-limit events, signed integration events, error and performance telemetry, security events, and audit logs.
  • Website and product analytics, such as a privacy-filtered page location, approved interaction event, permitted campaign parameters, filtered referrer, browser and device characteristics, language, approximate location, analytics identifier, and analytics preference.

3. Sources of personal data

We collect information directly from you and authorized workspace users, from your browser or device, from Akii-owned products and Marquorum where you use shared identity or affiliate attribution, and from providers used for authentication, email, billing, analytics, observability, hosting, and support.

We receive public social-media content and related public metadata through approved routes operated by providers such as Bright Data, Apify, and an official platform API where enabled. The customer’s monitored terms and platform choices determine the requested search. We may also revisit a public source to verify freshness, deletion, or context where the route supports it.

We receive AI response content and request metadata from approved AI routing and model inference providers. We may receive subscription, payment, refund, dispute, invoice, and fraud status from Stripe, and attribution or commercial-event status from Marquorum.

4. Why we use personal data

  • Provide accounts, workspaces, public-conversation monitoring, opportunity ranking, AI-assisted comments, manual-posting links, notifications, exports, billing controls, support, and requested product functions.
  • Configure and improve relevance, safety, source quality, grounding, brand voice, drafts, user experience, reliability, capacity, and plan fit.
  • Calculate and display usage, plan allowances, upgrade evidence, workflow progress, and estimated or accumulated time saved.
  • Authenticate users, secure sessions and integrations, prevent abuse and fraud, enforce terms, investigate incidents, recover failed work, and maintain audit evidence.
  • Process subscriptions, payments, invoices, refunds, disputes, taxes, affiliate attribution, and application-owned entitlements.
  • Deliver required service messages and customer-selected opportunity notifications, and send optional product communications where permitted by the recorded preference and applicable law.
  • Measure website and product performance through privacy-filtered first-party events and Google Analytics, subject to the available opt-out control.
  • Comply with law, court orders, regulatory duties, accounting and tax duties, establish or defend claims, and respond to valid rights requests.
  • Create aggregated or de-identified statistics, including product-performance and time-saved reporting, that do not reasonably identify a person or customer.

5. Legal bases

Contract and requested steps. We process account, workspace, configuration, monitoring, drafting, subscription, billing, support, and required communication data to enter into and perform the customer agreement or take requested pre-contract steps.

Legitimate interests. We operate and improve the service, identify relevant public business conversations, protect accounts, prevent abuse, measure performance and value, administer relevant product communications, enforce agreements, establish or defend claims, and maintain business continuity. We assess necessity, proportionality, public context, source expectations, sensitivity, customer purpose, and individual rights before relying on this basis.

Legal obligation. We process information to meet applicable data-protection, tax, accounting, sanctions, court, regulatory, security, and record-keeping duties.

Consent. We rely on consent where applicable law requires it, including certain optional marketing and analytics where required. You may withdraw consent without affecting earlier lawful processing.

Other lawful grounds. We may process information to protect vital interests, perform a public-interest task, establish legal claims, or rely on another ground expressly available under applicable law.

6. Account access and legal acceptance

When you request a passwordless link, we use the email, limited request evidence, a single-use token, delivery status, and return path to send and secure it. Merely opening the link does not create a session. Confirmation consumes the link and may verify the email, activate an authorized account, record the applicable legal acceptance, and create a revocable session.

When you choose Google sign-in, Google authenticates you and returns a stable account identifier, verified email, basic identity claims, and a signed identity token. We store the provider identifier only as a one-way hash, do not receive your Google password, request only identity scopes, do not request Gmail or Drive access, and do not retain a Google access or refresh token.

We retain the legal document set, version, hashes, effective date, displayed acceptance text, acceptance action, verified identity, timestamp, source context, and bounded one-way security evidence. This evidence protects both parties and supports electronic contracting and legal-record requirements.

7. Public social-media data

Engagement Bot is designed to process public posts and related public profile or community metadata for keyword-based business monitoring, relevance analysis, and customer-directed engagement review. It is not designed to collect private messages, closed-group content, private account content, social-account credentials, or a customer’s private contacts.

Public content can contain personal data. Public availability does not remove a person’s data-protection, privacy, intellectual-property, or other rights. We limit fields and route purposes, retain source links and provenance, restrict direct database access, and apply deletion, lock, stale-content, risk, and retention controls.

If your public content appears in Engagement Bot and you want us to review, correct, restrict, or remove the copy we control, contact hello@marquorum.com with the source URL and enough information to verify the request. Removal from Engagement Bot does not remove content from the original platform, and deletion at the original source may not be immediate in provider results. We may retain minimum evidence needed to honor an objection, prevent re-collection, protect security, or comply with law.

A customer that exports or uses public-source data remains responsible for its own purpose, legal basis, notices, rights handling, retention, and compliance. A customer must not repurpose the data for unrelated profiling, sensitive targeting, surveillance, or high-impact decisions.

8. AI and automated processing

Engagement Bot sends bounded business-grounding data, campaign configuration, public conversation context, platform or community constraints, and draft context to approved AI routing and model inference providers when model-assisted scoring, recommendations, or drafting is enabled. We exclude social-account credentials and do not intentionally send payment-card data, authentication tokens, or unnecessary sensitive data.

AI requests may pass through one or more approved routing and model inference providers. The provider or model may change for resilience or a product change. Provider retention and training rules can vary, so we do not promise that every provider applies the same policy. We configure available privacy controls and minimize submitted content, but customers must not place confidential or sensitive personal data in ordinary product fields.

Automated rules and models help rank conversations, classify intent and risk, generate summaries and comments, and recommend configuration. They do not post to a social platform or make a final decision about a person with legal or similarly serious effect. A customer reviews the original source and decides whether to use a draft. You may provide feedback, dismiss an opportunity, edit a comment, or choose not to post.

9. Who receives personal data

  • Akii Technologies, Ltd personnel and authorized contractors who need the information for their role and are subject to confidentiality and access controls.
  • Supabase for managed database and authentication infrastructure, and Railway for the web application and isolated worker hosting.
  • Approved AI routing and model inference providers for bounded AI processing. Their processing may include request metadata and the prompt and response content needed for the request.
  • Bright Data, Apify, and an approved official platform API for customer-directed public-source collection, route operation, usage, provenance, and provider support.
  • Stripe for checkout, customer billing, payment methods, invoices, refunds, disputes, fraud controls, tax support, and subscription events.
  • Resend for authentication, required service email, customer-selected notifications, optional product email, delivery evidence, and suppression.
  • Google for optional account authentication and bounded Google Analytics across website and product pages.
  • Sentry for bounded error, performance, release, and incident telemetry. Product code is designed to exclude secrets and unnecessary source or customer content from telemetry.
  • Marquorum and other Akii-owned product systems for shared identity where used, affiliate attribution, subscription and refund event handoff, creator-code continuity, and portfolio operations allocated to those systems.
  • Professional advisers, auditors, insurers, banks, investors, acquirers, and transaction counterparties under appropriate confidentiality and due-diligence controls.
  • Courts, regulators, law enforcement, tax authorities, sanctions authorities, platforms, and other competent recipients where disclosure is required or lawfully necessary to protect rights, safety, or service integrity.

10. No sale or behavioural advertising

We do not sell personal data for money. We do not share customer account, workspace, public-source, or draft data for cross-context behavioural advertising. We do not use Google Analytics advertising features. If a future practice is treated as a sale, targeted-advertising disclosure, or regulated sharing under applicable law, we will provide the notice and choice required before starting it.

11. Email and notification choices

Authentication, security, billing, subscription, incident, legal, and support messages are sent as needed to operate the account or meet a duty. A customer may separately choose campaign notifications after each completed scan, daily, weekly, or off, subject to plan and cadence. Notification email contains bounded opportunity summaries and directs the user back to the manual-review workflow.

Early-access and other product updates use the recorded consent or another lawful basis permitted in the recipient’s location. Every promotional email contains a working no-login unsubscribe. A promotional unsubscribe does not disable authentication, security, billing, legal, or requested campaign messages. A campaign-level unsubscribe does not change another campaign or user preference.

12. Cookies, attribution, and analytics

Engagement Bot uses strictly necessary cookies for session security, passwordless-link confirmation, Google sign-in state and code-verifier protection, workspace selection, affiliate attribution, and account access. These cookies are needed for the requested service or security and are not advertising cookies.

A necessary first-party preference cookie records the cookie-banner acknowledgement and whether Analytics is granted or denied for up to 12 months. This preserves the browser choice even when local storage is unavailable. It contains no account, campaign, source-post, draft, or Analytics event data.

Our first-party public analytics endpoint accepts only narrowly defined page-view and approved interaction events. It creates a one-way anonymous cohort value and is designed not to retain a raw network address, raw user agent, URL query, account identity, form content, or browser credential.

Google Analytics is enabled by default across all website and product pages unless you opt out. On the public site, the first-visit cookie banner explains the available categories and opens full settings. After the banner is closed, the Cookie settings link in the public-site footer reopens those settings. Turning Analytics off stops future Google Analytics collection from that browser and removes accessible Analytics cookies for the current site. You can use the same settings to turn Analytics back on. The preference does not affect account access, a subscription, or product use.

Google Analytics may process a privacy-filtered page location, permitted campaign parameters, a filtered referrer, approved website and product interactions, a completed account-entry event, browser and device characteristics, language, approximate location, and first-party identifiers such as _ga. We configure it without Google Signals, advertising personalization, advertising storage, advertising user data, cross-site behavioural advertising, or form-field capture.

Email addresses, account identifiers, magic-link tokens, Google sign-in codes, creator codes, business-grounding data, monitored conversations, prepared comments, and unapproved URL parameters are excluded from Analytics event content. User-level and event-level Analytics data is retained for 14 months unless deleted sooner. Aggregated reports may remain after source-level retention expires.

13. International transfers

Engagement Bot is operated from the DIFC and serves an international professional customer base. Providers, model infrastructure, social platforms, public sources, support personnel, and users may be located outside the DIFC and the United Arab Emirates. Personal data may therefore be processed in other countries.

We use a transfer mechanism available under applicable law, such as a recognized adequate jurisdiction, contractual safeguards, approved standard clauses, a necessary contract transfer, a legal obligation, or another permitted derogation. We assess the recipient, purpose, data, country, security, onward transfers, and enforceable rights where required. You may ask for information about safeguards relevant to your data.

14. Retention

We retain personal data only for the purpose collected and for legitimate service, legal, accounting, security, audit, dispute, and enforcement needs. We consider the relationship, record type, source availability, customer actions, sensitivity, risk, applicable limitation periods, provider rules, and mandatory duties.

  • Unconsumed passwordless links expire after 15 minutes. Limited registration, delivery, and abuse-prevention evidence may be retained for up to 90 days, or longer when linked to an incident or active account record.
  • Raw provider observations are scheduled for deletion after 30 days under the current public-source route policy. Normalized public-source records receive a retention review after 12 months and may be deleted, de-identified, refreshed, or retained where still linked to an active customer workflow, user action, objection, security need, or legal hold.
  • Active account, workspace, configuration, grounding, opportunity, draft, usage, time-saved, acceptance, support, and notification records are retained during the relationship. After closure they are normally deleted, de-identified, or placed beyond ordinary use within 90 days, except for records retained under the categories below and backups that cycle out under provider schedules.
  • Billing, payment, refund, dispute, tax, accounting, fraud, sanctions, agreement, and legal-claim records may be retained for up to ten years where applicable law, an authority, risk, or a claim reasonably requires it.
  • Routine technical, model-request metadata, audit, and security records are normally retained for up to 24 months. Incident evidence may be retained until investigation, remediation, and applicable claim periods end.
  • Google Analytics user-level and event-level data is retained for 14 months. Aggregated or irreversibly de-identified analytics and time-saved statistics may be retained without an account-level period.
  • Marketing objections, unsubscribe evidence, source-content objections, and minimum suppression fingerprints may be retained for as long as reasonably necessary to honor the choice and prevent accidental re-enrollment or re-collection.
  • Data subject to a dispute, chargeback, investigation, legal hold, security incident, rights request, or authority request is retained until the hold and required follow-up end.

15. Security

We use technical and organizational measures designed for the nature and risk of the processing. These include passwordless single-use access, optional Google identity verification, scanner-safe confirmation, hashed tokens and request evidence, HTTP-only session controls, role-based access, least privilege, row-level database security, service isolation, signed integrations, bounded provider credentials, rate limits, immutable legal and financial evidence, monitoring, secret scanning, backups, recovery procedures, and raw-provider retention controls.

No system is completely secure. You must protect your email account, Google account, device, session, workspace permissions, exports, and connected services and notify us promptly of suspected compromise. If a personal-data breach creates a legal reporting duty, we will notify the DIFC Commissioner and affected people as applicable.

16. Your rights

Depending on applicable law and the circumstances, you may have the right to be informed, access personal data, receive a copy, correct inaccurate data, erase data, restrict processing, object to processing, withdraw consent, receive portable data, and request human review of certain automated decisions. You may object to direct marketing at any time and without charge.

A right may be limited by another person’s rights, legal privilege, confidentiality, security, fraud prevention, a legal duty, an ongoing claim, source integrity, or an applicable exemption. We will explain a refusal where law permits. We do not charge for an ordinary request, but applicable law may allow a reasonable fee or refusal for a manifestly unfounded, excessive, or repetitive request.

To exercise a right, email hello@marquorum.com or write to the registered office. You do not need an Engagement Bot account. We may verify identity, email control, authority, source URL, country, and request scope before disclosing or changing data. We aim to respond within one month where the DIFC Data Protection Law applies, subject to lawful extensions for complexity or volume.

17. Questions and complaints

Contact us first at hello@marquorum.com so we can investigate and respond. You may also lodge a complaint with the DIFC Commissioner of Data Protection or another competent supervisory authority that applies to you. Exercising a right or making a complaint will not result in retaliation.

The DIFC Data Protection Law may also provide a private right of action through the DIFC Courts in circumstances defined by that law.

18. Children

Engagement Bot is a professional service for adults. It is not directed to children, and account users must be at least 18 and of legal majority where they live. Customers must not use it to identify or target children. Public-source filters may not identify every child correctly. If you believe we processed a child’s personal data, contact us so we can investigate and take appropriate action.

19. Changes to this Notice

We may update this Notice to reflect changes in law, service, providers, models, platforms, products, or processing. The version and effective date identify the current Notice. We will provide reasonable advance notice of a material change through email, dashboard notice, or a new acknowledgement where appropriate, unless an immediate update is required by law, security, or urgent risk.

A new Notice does not convert an earlier unlawful purpose into a lawful one. If a change requires consent or another specific action, we will obtain it before that processing begins. A material change to the customer legal set may require fresh acceptance.

20. Controller contact

Akii Technologies, Ltd, IH-00-01-03-OF-05, Level 3, Innovation One, Dubai International Financial Centre, Dubai, United Arab Emirates. Email: hello@marquorum.com. This contact method is available without creating an account.

REFERENCED SERVICES AND AUTHORITIES

Current external terms and authorities

External terms can change independently. The current version published by the provider or authority applies to its own service or function.

  • DIFC Commissioner of Data Protection↗

    The supervisory authority for the DIFC Data Protection Law and an official source for rights, complaints, transfers, and guidance.

  • DIFC Data Protection Law No. 5 of 2020↗

    The current DIFC legal framework for personal data, rights, transfers, security, and direct marketing.

  • Bright Data Privacy Policy↗

    Bright Data’s current privacy terms for its own services and public-web data products.

  • Apify Privacy Policy↗

    Apify’s current privacy terms and its controller and processor role explanations.

  • Stripe Privacy Center↗

    Stripe’s explanation of payment-service data and privacy rights.

  • Google Privacy Policy↗

    Google’s privacy terms for optional identity authentication and bounded Analytics.

  • Google Analytics privacy and safeguards↗

    Google’s explanation of how Analytics data is protected and processed.

Find the right conversations, prepare useful comments, and post them yourself.

TermsPrivacyhello@marquorum.com