This Privacy Policy explains how Cobi collects, uses, shares and protects personal data when you visit our website, use our services, communicate with us, or otherwise interact with Cobi.
It also explains the choices and rights available to you.
01
How Cobi handles personal data
Cobi processes personal data in different ways depending on how you interact with us.
Information Cobi processes directly
Cobi may collect and process personal data relating to:
- visitors to our website;
- Cobi users and account administrators;
- prospective and existing customers;
- people who contact us;
- partners, suppliers and service providers; and
- people who interact with Cobi through events, research, sales or other business activities.
For this information, Cobi generally determines why and how the personal data is processed.
This means Cobi acts as the controller of that personal data.
Information customers process through Cobi
Customers may use Cobi to connect, analyse and act on customer, product and business data.
That data may contain personal data relating to their customers, users, employees or other individuals.
Where Cobi processes personal data solely on behalf of a customer and according to that customer's instructions, the customer determines the purposes of the processing and Cobi acts as a processor on its behalf.
That processing is governed by our agreement with the customer and, where applicable, a Data Processing Agreement.
If you believe your personal data is being processed through Cobi by one of our customers, that customer will generally be responsible for determining how your data is used and responding to your privacy requests.
Cobi will support customers with those requests where required.
02
Personal data we collect
The personal data we collect depends on how you interact with Cobi.
Information you provide
You may provide information to us when you:
- create or manage an account;
- request information or a demonstration;
- purchase or administer a subscription;
- contact our team;
- submit a support request;
- participate in research, events or surveys; or
- otherwise communicate with Cobi.
This information may include:
- your name;
- work email address;
- phone number;
- company;
- role or job title;
- account and profile information;
- information contained in communications with us;
- support requests;
- information submitted through website forms;
- subscription or billing information; and
- feedback or other information you choose to provide.
Information generated when you use Cobi
When you visit our website or use Cobi, we may collect technical and usage information about your interaction with the Services.
This may include:
- IP address;
- browser and device information;
- operating system;
- pages and features accessed;
- dates and timestamps;
- account activity;
- interactions with Cobi;
- session information;
- diagnostic and performance information; and
- security and audit logs.
We use this information to operate Cobi, maintain reliability, understand how the Services are used, protect our systems and improve the product.
Information received through customers
Customers may connect databases, applications, platforms or other systems to Cobi.
Those systems may provide Cobi with information that the customer has chosen to make available through the Services.
Where that information is Customer Data, Cobi processes it according to the customer's instructions and our agreement with them.
03
How we use personal data
Cobi uses personal data only where there is a legitimate reason to do so.
Providing Cobi
We use personal data to:
- create and administer accounts;
- authenticate users;
- provide the functionality of Cobi;
- enable integrations and connected services;
- administer subscriptions and billing;
- provide customer support;
- maintain the reliability of the Services; and
- communicate with you about your account or use of Cobi.
Improving Cobi
We may process information to understand how Cobi performs and how people use it.
This may include:
- analysing product usage;
- identifying technical issues;
- monitoring reliability and performance;
- improving existing features;
- developing new functionality;
- evaluating the effectiveness of product changes; and
- improving the user experience.
Where appropriate, Cobi may use aggregated or de-identified information for these purposes.
Security and prevention of misuse
We may process personal data to:
- secure accounts and systems;
- authenticate users;
- detect suspicious or unauthorised activity;
- investigate security events;
- prevent fraud or abuse;
- enforce our Terms of Service;
- protect Cobi and our infrastructure; and
- protect our customers, users and other people.
Managing customer and business relationships
We may process professional and business contact information to:
- respond to enquiries;
- communicate with prospective customers;
- manage customer relationships;
- manage partnerships and suppliers;
- provide requested information;
- negotiate and administer agreements;
- maintain business records; and
- operate Cobi's business.
Marketing and communications
Where permitted by law, Cobi may use professional contact information to send communications about:
- products and features;
- company developments;
- research and insights;
- events;
- educational content; and
- other information we believe may be relevant to you professionally.
You can opt out of marketing communications at any time using the unsubscribe option provided or by contacting us.
Opting out of marketing does not prevent Cobi from sending communications required to operate your account or relationship with us, including security, billing, transactional and service-related notices.
Legal and compliance purposes
We may process information where necessary to:
- comply with applicable laws and regulations;
- respond to lawful requests or legal process;
- establish, exercise or defend legal claims;
- protect Cobi's rights and property;
- maintain appropriate records; and
- meet legal, regulatory, tax or accounting obligations.
04
Legal bases for processing
Where applicable law requires Cobi to identify a legal basis for processing personal data, we rely on one or more of the following grounds.
Contract
We may process personal data where it is necessary to enter into or perform an agreement with you or the organisation you represent.
For example, we may use account information to provide access to Cobi or billing information to administer a subscription.
Legitimate interests
We may process personal data where necessary for Cobi's legitimate business interests or those of another party, provided those interests are not overridden by your rights and interests.
These legitimate interests may include:
- operating and improving Cobi;
- protecting our systems and users;
- preventing fraud and misuse;
- communicating with customers and prospective customers;
- conducting business analytics;
- maintaining commercial relationships; and
- protecting our legal rights.
Where we rely on legitimate interests, we consider the nature of the information, the purpose of the processing and the impact on the individuals concerned.
Consent
In some circumstances, we may ask for your consent before processing personal data.
Where processing is based on consent, you can withdraw that consent at any time.
Withdrawing consent does not affect processing that occurred before the withdrawal.
Legal obligations
We may process personal data where necessary to comply with laws, regulations, court orders or other binding legal obligations.
Other permitted grounds
Where appropriate, Cobi may rely on another lawful basis recognised under applicable data protection law.
05
Customer Data
Customers control the data they choose to make available to Cobi.
Cobi does not acquire ownership of Customer Data.
Customer Data may include information contained in customer databases, data warehouses, CRM platforms, product systems, payment systems, marketing platforms and other services connected to Cobi.
Where Customer Data contains personal data, Cobi processes that information only as necessary to provide the Services and in accordance with:
- the customer's instructions;
- our agreement with the customer;
- any applicable Data Processing Agreement; and
- applicable law.
Cobi does not sell Customer Data.
Cobi does not use Customer Data for unrelated advertising purposes.
Customers are responsible for determining what Customer Data they provide to Cobi and for ensuring that they have an appropriate legal basis to do so.
06
Artificial intelligence
Cobi uses artificial intelligence and machine learning to help customers understand information, identify patterns and opportunities, generate insights and recommendations, and support actions.
These capabilities may process information contained in Customer Data.
Where that information includes personal data, Cobi processes it on behalf of the relevant customer unless otherwise stated.
Model training
Cobi does not use Customer Data to train third-party general-purpose or foundation AI models.
Where third-party AI technology supports Cobi functionality, Cobi seeks to use appropriate commercial arrangements and controls governing how Customer Data is handled.
Cobi may use aggregated, statistical or de-identified information to operate, secure, analyse and improve the Services, provided that the information does not reasonably identify an individual or customer.
AI-assisted processing
AI systems may analyse, classify, summarise or generate information based on data supplied through the Services.
Customers determine the business purposes for which they use Cobi's AI functionality and remain responsible for ensuring that their use of that functionality complies with applicable law.
Cobi may provide controls designed to support appropriate oversight of AI-assisted and automated functionality.
08
International data transfers
Cobi operates internationally, and our customers, users and service providers may be located in different jurisdictions.
Personal data may therefore be transferred to, stored in or processed in countries other than the country in which it was originally collected.
Different jurisdictions may have different data protection laws.
Where applicable law requires additional safeguards for an international transfer of personal data, Cobi uses an appropriate transfer mechanism.
Depending on the circumstances, this may include:
- transferring personal data to a jurisdiction recognised as providing an adequate level of protection;
- using approved contractual safeguards;
- using standard contractual clauses or equivalent mechanisms;
- imposing appropriate contractual obligations on recipients; or
- relying on another transfer mechanism permitted by applicable law.
Where personal data subject to DIFC Data Protection Law is transferred outside the DIFC, Cobi applies the safeguards required under the applicable DIFC data protection framework.
DIFC's current framework expressly regulates transfers of personal data outside DIFC and provides for mechanisms including adequacy and contractual safeguards.
09
Data retention
Cobi retains personal data only for as long as reasonably necessary for the purposes for which it was collected.
The appropriate retention period depends on factors including:
- the type and sensitivity of the information;
- the purpose for which it was collected;
- how long we have an active relationship with you;
- the requirements of our agreements;
- security and fraud-prevention needs;
- legal, regulatory, accounting or tax requirements; and
- whether information may be required to establish or defend legal claims.
For example, some account information may need to be retained while an account remains active, while certain transaction, contractual or security records may need to be retained for longer periods.
When personal data is no longer required, Cobi will delete, anonymise or otherwise dispose of it in accordance with our retention practices.
Customer Data
Retention and deletion of Customer Data are governed primarily by the applicable customer agreement and any applicable Data Processing Agreement.
When a customer relationship ends, Customer Data will be handled according to those terms and Cobi's applicable data-handling processes, except where retention is required by law.
10
Security
Cobi uses administrative, technical and organisational safeguards designed to protect personal data against:
- unauthorised access;
- unauthorised disclosure;
- alteration;
- accidental or unlawful loss;
- misuse; and
- destruction.
Our security practices are designed to take into account the nature of the information being processed and the risks associated with that processing.
Security is a shared responsibility.
Users are responsible for:
- protecting account credentials;
- maintaining appropriate access permissions;
- managing authorised users; and
- appropriately configuring systems and integrations under their control.
No online service, network or storage system can guarantee absolute security.
More information about Cobi's approach to security may be available through our security and trust resources.
12
Your privacy rights
Depending on your location and the law that applies to your personal data, you may have rights concerning how Cobi processes your information.
These may include the right to:
Access
Request confirmation of whether Cobi processes your personal data and obtain access to certain information about that processing.
Correction
Request correction of personal data that is inaccurate or incomplete.
Deletion
Request deletion of personal data in circumstances where applicable law gives you that right.
Restriction
Request that Cobi restrict certain processing of your personal data.
Objection
Object to processing based on certain legal grounds, including in some circumstances processing based on legitimate interests or for direct marketing.
Portability
Request a copy of certain personal data in a structured, commonly used and machine-readable format where applicable.
Withdraw consent
Where Cobi relies on consent to process personal data, withdraw that consent at any time.
Automated processing
Where applicable law provides such rights, you may have rights relating to decisions based solely on automated processing that produce legal or similarly significant effects.
Complaints
You may have the right to raise a concern with a competent data protection authority.
These rights are not absolute and may be subject to conditions, limitations and exemptions under applicable law.
Exercising your rights
To exercise a privacy right relating to personal data for which Cobi is responsible, contact us using the details below.
We may request information necessary to verify your identity and protect personal data against unauthorised disclosure.
We will respond to valid requests within the timeframe required under applicable law.
Information processed for Cobi customers
Where Cobi processes your personal data solely on behalf of a customer, that customer generally controls the information and is responsible for responding to privacy requests.
You should normally direct your request to that organisation.
Cobi will assist its customers with valid privacy requests where required under applicable law or our agreement with them.
DIFC's Data Protection Law provides individuals with rights and remedies concerning processing of their personal data, with the Commissioner responsible for supervision and enforcement.
13
Children
Cobi is designed for business and professional use.
The Services are not directed to children, and Cobi does not knowingly collect personal data directly from children through our website or account-registration process.
If you believe that a child has provided personal data directly to Cobi without appropriate authorisation, please contact us so that we can review the situation and take appropriate action.
This does not prevent organisations from using Cobi to process information where they are lawfully authorised to do so under their own responsibilities and applicable law.
14
Changes to this Privacy Policy
Cobi may update this Privacy Policy from time to time.
Changes may be made to reflect:
- changes to Cobi or the Services;
- changes in how we process personal data;
- new features or technologies;
- changes in applicable law or regulatory guidance; or
- changes to our business practices.
When we make material changes, we will provide notice where appropriate or required by law.
The effective date at the top of this Privacy Policy identifies the current version.
15
Contact us
Cobi AI Limited is established in the Dubai International Financial Centre, Dubai, United Arab Emirates.
If you have questions about this Privacy Policy, want to exercise a privacy right, or have concerns about how Cobi handles personal data, contact us:
Email: legal@hellocobi.comWebsite: hellocobi.comWhere applicable, you may also have the right to raise a complaint with the DIFC Commissioner of Data Protection or another competent data protection authority.