Privacy Policy
Vorne.ai is operated by Digitize LLC - FZ, Dubai, United Arab Emirates. This policy explains what we collect, why, who else touches it, and how to get it back or have it deleted. Questions go to info@digitizeuae.com.
Who the controller is
For the Vorne.ai service, Digitize LLC - FZ is the data controller for your account and billing information, and the data processor for the content and data you put into your workspace. You remain the controller of your own customers' data.
What we collect
- Account data: name, work email, password hash, organisation name, role, and the audit record of actions taken in your workspace.
- Workspace content: the sites, pages, claims, evidence, prompts and drafts you create or connect. This is yours; we process it to run the service.
- Connected accounts: when you connect a platform such as Shopify, we store the access grant and the data the integration needs. Credentials are encrypted at rest and never stored in plain application tables.
- Usage and diagnostics: request logs, error traces and aggregate feature usage, used to operate and debug the service.
- Website analytics: only if you choose to allow analytics on our public website, Google Analytics records the pages you visit, how you arrived, and general device and approximate location information, using the cookies described in our Cookie Policy. It is not used inside the signed-in product.
- Billing data: handled by our payment processor. We do not store card numbers.
We do not buy personal data, and we do not sell or rent yours.
Why we process it
To provide the service you asked for, to keep it secure, to meet legal obligations, and to improve reliability. Where the law requires consent, we ask for it and you can withdraw it.
AI providers
Running a visibility check or drafting content sends the relevant content to third-party AI providers. Those providers process it to return a result. We send the minimum needed for the task, and our subprocessor list names each provider we use.
Tenant isolation
Every record that belongs to an organisation carries that organisation's identity and is protected by PostgreSQL row-level security, enforced at the database rather than only in application code. The runtime database role is not the schema owner, so a bug in the application cannot quietly read across tenants.
Retention and deletion
You can export your data at any time. You can request deletion of a workspace from the product; deletion runs after a grace window during which you can cancel it, and it erases stored objects and clears embeddings rather than merely marking rows hidden. Records we must keep for legal or accounting reasons are retained for as long as the law requires and no longer.
Your rights
Depending on where you live, you may have the right to access, correct, export, restrict or delete your personal data, and to object to certain processing. Write to info@digitizeuae.com and we will respond within the period the applicable law allows. If you are in the UAE, Federal Decree-Law No. 45 of 2021 on Personal Data Protection may apply to you; if you are in the EEA or UK, the GDPR may apply.
International transfers
Our infrastructure and some subprocessors are located outside the UAE. Where personal data moves across borders we rely on the safeguards permitted by the applicable law.
Security
Encryption in transit and at rest, least-privilege database roles, append-only audit logging of side-effecting actions, and encrypted storage for integration credentials. No system is perfectly secure, and we will not claim otherwise.
Changes
We will update the date at the top of this page when this policy changes, and tell account holders about material changes.
Contact
Digitize LLC - FZ, Dubai, United Arab Emirates. Email info@digitizeuae.com. Phone +971 55 457 3286.