Privacy Policy

Effective Date: January 01, 2025
Last Updated: 29 November, 2025
Version: 2.0

HelpForce AI Ltd. ("HelpForce", "we", "our", or "us") is committed to protecting your privacy. This Privacy Policy outlines how we collect, use, disclose, and safeguard your information when you visit our website www.helpforce.ai or engage with our AI-powered services.


CONTACT INFORMATION

HelpForce AI Ltd.
Commercial License Number: CL9930
Registered Address: Unit IH-00-VZ-01-FL-193, Level 1, Innovation Hub
Dubai International Financial Centre (DIFC), Dubai, UAE
DIFC Data Protection Registration: (Pending Approval)

General Inquiries: support@helpforce.ai
Data Protection Inquiries: privacy@helpforce.ai
Legal Matters: legal@helpforce.ai
Phone: +1 (646) 889-8373
Website: www.helpforce.ai

Data Protection Contact: Usman Ali Asghar (usman@helpforce.ai)
Authorized Signatory: Usman Ali Asghar

Note: We are developing our Data Protection Officer appointment framework in line with DIFC Data Protection Law 2020. As we do not currently engage in High Risk Processing activities, a formal DPO appointment is not mandatory at this stage.

1. INFORMATION WE COLLECT

1.1 Personal Information
We collect information that you voluntarily provide to us, including:
- Name, email address, phone number
- Job title, company name, and business address
- Information submitted through contact forms, inquiry forms, or service requests
- Account credentials for our services
- Billing and payment information

1.2 Usage Data
We automatically collect certain information when you visit our website:
- Browser type and version
- Pages visited and time spent on pages
- IP address and geographic location
- Device information (type, operating system, unique device identifiers)
- Referral source and clickstream data
- Cookies and similar tracking technologies (see Section 8)

1.3 Client Data
If you are an enterprise client using our AI services, we may collect and process:
- Data related to your use of our AI agents and automation tools
- Project communication records and collaboration data
- Integration data from your business systems
- Performance metrics and usage analytics

1.4 Categories of Personal Data We Process
We process the following categories of business-related personal data:

- Contact Information: Names, email addresses, phone numbers, job titles
- Professional Information: Company affiliations, employer details, business addresses
- Communication Records: Project communications, support tickets, inquiry forms
- Technical Data: IP addresses, browser type, device information, website usage data
- Employment Information: Limited employment details of client representatives, vendors, and our staff for operational purposes

We do NOT collect or process Special Categories of Personal Data (such as race, religion, health, biometric data, genetic data, or sensitive personal information) unless explicitly required and consented to for specific enterprise AI projects.

Data Subjects Include:- Enterprise clients and customers
- Business advisors, consultants, and professional experts
- Our staff, agents, and contractors
- Suppliers and vendors
- Enterprise users participating in AI solution testing (under explicit consent)

2. LEGAL BASIS FOR PROCESSING PERSONAL DATA

We process your personal data under the following legal bases as permitted by DIFC Data Protection Law 2020 and GDPR:

a) Consent
When you voluntarily submit information through our contact forms, subscribe to communications, or participate in AI solution testing under explicitly consented conditions.

b) Contract Performance
To deliver our AI automation services, provide technical support, and fulfill our contractual obligations with enterprise clients.

c) Legitimate Interests (Article 13, DIFC DP Law 2020)
- To improve and develop our AI models and automation systems
- For operational collaboration and project management with clients
- To prevent fraud and maintain security of our systems
- For research and development of AI technologies
- For accounting, auditing, and business administration purposes
- For marketing and promotional activities related to our services
- For consultancy, advisory services, and innovation research

We ensure that when relying on legitimate interests, your rights and freedoms are not overridden by our processing activities.

d) Legal Obligation
To comply with applicable laws, regulations, tax requirements, and regulatory obligations in the UAE, DIFC, and other jurisdictions where we operate.

3. HOW WE USE YOUR INFORMATION

We use the information we collect for the following purposes:

- To provide, operate, and improve our AI-driven services
- To communicate with you about updates, offers, support requests, and service notifications
- To process transactions and send billing statements
- To respond to your inquiries and provide customer support
- To develop new products, features, and AI capabilities
- To conduct research and analytics to improve our technology
- To personalize your experience and deliver relevant content
- To detect, prevent, and address fraud, security issues, and technical problems
- To comply with legal obligations, regulatory requirements, and enforce our Terms of Service
- For accounting, auditing, and business administration
- For marketing, advertising, and promotional activities (with your consent where required)

4. SHARING YOUR INFORMATION

We respect your privacy and do not sell your personal data to third parties.

We may share your information in the following circumstances:

a) Service Providers and Sub-Processors
We share data with trusted third-party service providers who assist us in operating our business, including:
- Cloud infrastructure providers (e.g., Google Cloud Platform, US-based servers)
- Payment processors and billing systems
- Analytics and performance monitoring tools (e.g., Google Analytics)
- Communication and collaboration tools
- Customer support platforms
- Development and technology services (UAE, Italy, Pakistan)

All service providers are bound by strict confidentiality agreements and Data Processing Agreements (DPAs) and may only use your data as instructed by us.

b) Business TransfersIf HelpForce is involved in a merger, acquisition, asset sale, or bankruptcy, your information may be transferred as part of that transaction. We will notify you before your data is transferred and becomes subject to a different privacy policy.

c) Legal Requirements
We may disclose your information if required to do so by law, court order, or regulatory authority, or if we believe disclosure is necessary to:
- Comply with legal obligations
- Protect and defend our rights or property
- Prevent fraud or illegal activity
- Protect the safety of our users or the public
- Respond to government requests or law enforcement

d) With Your Consent
We may share your information with third parties when you have given us explicit consent to do so.

5. YOUR DATA PROTECTION RIGHTS

Under the DIFC Data Protection Law 2020, GDPR, and applicable data protection laws, you have the following rights:

a) Right of Access (Article 29, DIFC DP Law)
Request a copy of your personal data we hold about you.

b) Right to Rectification (Article 30, DIFC DP Law)
Correct inaccurate, incomplete, or outdated personal data.

c) Right to Erasure (Article 31, DIFC DP Law)
Request deletion of your data ("right to be forgotten") when:
- Data is no longer necessary for its original purpose
- You withdraw consent (where processing is based on consent)
- You object to processing based on legitimate interests
- Data has been unlawfully processed
- Legal obligation requires erasure

d) Right to Restriction of Processing (Article 32, DIFC DP Law)
Limit how we process your data in certain circumstances, such as:
- Contesting the accuracy of the data
- Processing is unlawful but you prefer restriction over deletion
- We no longer need the data, but you need it for legal claims
- You have objected to processing pending verification of legitimate grounds

e) Right to Data Portability (Article 33, DIFC DP Law)
Receive your data in a structured, commonly used, machine-readable format (CSV, JSON, XML) and transmit it to another data controller.

f) Right to Object (Article 34, DIFC DP Law)
Opt-out of processing based on legitimate interests, including:
- Direct marketing (absolute right - we will stop immediately upon request)
- Automated decision-making and profiling
- Processing for research, innovation, or statistical purposes

g) Right to Withdraw Consent (Article 28, DIFC DP Law)
Withdraw your consent at any time without affecting the lawfulness of processing conducted before withdrawal.

h) Right to Lodge a Complaint
File a complaint with:
- DIFC Commissioner of Data Protection (dp@difc.ae)
- Your local data protection authority or supervisory authority

How to Exercise Your Rights:
- Email: privacy@helpforce.ai
- Website Form: www.helpforce.ai/contact
- Written Request: HelpForce AI Ltd., Unit IH-00-VZ-01-FL-193, Level 1, Innovation Hub, DIFC, Dubai, UAE
- Phone: +1 (646) 889-8373

Response Time:
We will respond to all requests within 30 days of receiving your request. For complex requests, we may extend this period by an additional 60 days and will inform you of the delay and reasons.

Verification:
To protect your privacy and security, we may request additional information to verify your identity before processing rights requests.

No Fee:
Exercising these rights is free of charge unless requests are manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable administrative fee or refuse the request.

6. INTERNATIONAL DATA TRANSFERS

Your personal data may be transferred to and processed in countries outside the Dubai International Financial Centre (DIFC), European Economic Area (EEA), and United Arab Emirates.

We transfer data to the following jurisdictions:

a) Countries with Adequate Protection (Article 26, DIFC DP Law 2020)
- US: For cloud infrastructure, data storage, and processing services
- Other EU/EEA member states with equivalent data protection standards

b) Countries Requiring Additional Safeguards (Article 27, DIFC DP Law 2020)
- Pakistan: Operational support, software development, and technology services
- Italy: Technology development and AI model training services
- United States: Cloud services, analytics platforms, and business tools

For transfers to countries without an adequate level of data protection, we ensure security through:
- Explicit consent from data subjects after informing them of potential risks (Article 27(2)(a), DIFC DP Law)
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data Processing Agreements (DPAs) with all third-party service providers and sub-processors
- Appropriate technical and organizational security measures
- Binding corporate rules and certification mechanisms where applicable

Transfer Safeguards:
We implement the following protections for all international data transfers:
- End-to-end encryption during transit and at rest
- Access controls and authentication mechanisms
- Regular security audits and compliance assessments
- Contractual commitments from data recipients
- Ongoing monitoring of data protection laws in recipient countries

Consent and Choice:
By using our services, you acknowledge and consent to the international transfer of your personal data as described in this policy. If you do not consent to international data transfers, certain services may not be available to you.

For detailed information about our data transfer mechanisms and safeguards, contact privacy@helpforce.ai

7. DATA RETENTION

We retain personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy or as required by applicable law.

Retention Periods:

- Marketing Communications: Until you unsubscribe or after 24 months of inactivity, whichever comes first
- Client Project Data: Duration of active contract plus 7 years (for legal, accounting, and audit requirements)
- Website Analytics Data: 26 months (Google Analytics default retention period)
- Support Communications and Tickets: 3 years from the date of last interaction
- Employment and HR Records: Duration of employment plus 7 years (UAE labor law requirements)
- Accounting and Financial Records: 7 years from the end of the financial year (UAE commercial law and tax requirements)
- Legal Documents and Contracts: 10 years or duration specified by applicable law
- Website Visitor Data (Cookies): As specified in our Cookie Policy (typically 12-26 months)

Deletion and Anonymization:
After the retention period expires, we will:
- Securely delete personal data using industry-standard data destruction methods
- Anonymize data so it can no longer identify individuals
- Archive data in a secure, restricted environment if legally required to retain longer

Exceptions to Deletion:
We may retain personal data beyond the standard retention period when:
- Legal obligations, court orders, or regulatory requirements mandate longer retention
- There is an ongoing legal dispute, investigation, or audit
- Retention is necessary to establish, exercise, or defend legal claims
- You have specifically requested extended retention for legitimate purposes
- Data is required for scientific, historical research, or statistical purposes with appropriate safeguards

Your Right to Request Early Deletion:
You may request early deletion of your data at any time by contacting privacy@helpforce.ai. We will comply with your request within 30 days unless we are legally required or permitted to retain the data.

Secure Deletion Methods:
When deleting data, we use:
- Secure overwriting and degaussing for physical storage media
- Cryptographic erasure for encrypted data
- Permanent deletion from backup systems within 90 days
- Destruction certificates for physical documents containing personal data

8. COOKIES AND TRACKING TECHNOLOGIES

Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyze website traffic, and improve our services.

What Are Cookies?
Cookies are small text files stored on your device when you visit a website. They help websites remember your preferences and understand how you interact with the site.

Types of Cookies We Use:

a) Essential Cookies (Always Active - Cannot Be Disabled)
These cookies are necessary for the website to function properly and cannot be switched off.
- Session management and user authentication
- Security features and fraud prevention
- Load balancing and performance optimization
- Cookie consent preferences
Retention: Session-based or up to 12 months

b) Analytics Cookies (Optional - Requires Your Consent)
These cookies help us understand how visitors interact with our website.
- Google Analytics: Traffic analysis, user behavior patterns, page performance
- Heatmaps and user session recordings
- Conversion tracking and funnel analysis
Data Collected: Page views, time on site, bounce rate, traffic sources, device information
Retention: 26 months
Third Party: Google LLC (Privacy Policy: policies.google.com/privacy)

c) Functional Cookies (Optional - Requires Your Consent)
These cookies enable enhanced functionality and personalization.
- Remember your language and region preferences
- Save your settings and customizations
- Provide live chat support features
Retention: 12 months

d) Marketing and Advertising Cookies (Optional - Requires Your Consent)
These cookies track your browsing activity to deliver personalized advertisements.
- Track effectiveness of marketing campaigns
- Deliver targeted advertising based on interests
- Measure ad performance and ROI
- Retargeting and remarketing
Retention: 12-24 months
Third Parties: Google Ads, LinkedIn, Facebook (if applicable)

Managing Your Cookie Preferences:

Cookie Consent Banner:
When you first visit our website, you will see a cookie consent banner allowing you to:
- Accept all cookies
- Reject non-essential cookies
- Customize your cookie preferences

You can change your cookie settings at any time by:
- Clicking the "Cookie Preferences" link in our website footer
- Visiting www.helpforce.ai/cookie-preferences
- Contacting us at privacy@helpforce.ai

Browser Settings:
You can control and delete cookies through your browser settings:
- Chrome: Settings > Privacy and Security > Cookies
- Firefox: Settings > Privacy & Security > Cookies and Site Data
- Safari: Preferences > Privacy > Manage Website Data
- Edge: Settings > Privacy, Search, and Services > Cookies

For detailed instructions, visit: www.aboutcookies.org or www.allaboutcookies.org

Important Note:
Disabling certain cookies may limit website functionality and affect your user experience. Essential cookies cannot be disabled without preventing the website from functioning properly.

Third-Party Cookies:
Some cookies are placed by third-party services that appear on our pages. We do not control these cookies. Third-party providers have their own privacy policies:
- Google Analytics: policies.google.com/privacy
- Google Ads: policies.google.com/technologies/ads

Do Not Track (DNT):
Our website does not currently respond to "Do Not Track" browser signals. However, you can control tracking through your cookie preferences and browser settings.

For detailed information, see our full Cookie Policy at: www.helpforce.ai/cookie-policy

9. DATA SECURITY AND PROTECTION MEASURES

We take data security seriously and implement industry-standard technical and organizational measures to protect your personal data against unauthorized access, loss, destruction, alteration, or disclosure.

Technical Security Measures:

a) Encryption
- Data in Transit: TLS 1.2+ encryption (HTTPS) for all data transmitted over the internet
- Data at Rest: AES-256 encryption for stored data on servers and databases
- End-to-End Encryption: For sensitive communications and file transfers

b) Network Security
- Firewalls and intrusion detection/prevention systems (IDS/IPS)
- Virtual Private Networks (VPNs) for remote access
- Network segmentation and isolation of sensitive systems
- DDoS protection and traffic filtering
- Regular security patches and updates

c) Access Controls
- Multi-factor authentication (MFA) for all administrative access
- Role-based access control (RBAC) - principle of least privilege
- Unique user credentials and strong password policies
- Regular access reviews and deprovisioning of inactive accounts
- Audit logging of all access to personal data

d) Infrastructure Security
- Secure cloud hosting with ISO 27001 certified providers
- Regular vulnerability scans and penetration testing
- Automated security monitoring and threat detection
- Secure backup systems with encryption and geographic redundancy
- Disaster recovery and business continuity plans

e) Application Security
- Secure software development lifecycle (SDLC)
- Regular code reviews and security testing
- Input validation and sanitization to prevent injection attacks
- Protection against common web vulnerabilities (OWASP Top 10)
- API security with authentication tokens and rate limiting

Organizational Security Measures:

a) Policies and Procedures
- Information security policy and data protection policy
- Incident response and data breach notification procedures
- Business continuity and disaster recovery plans
- Vendor management and third-party risk assessment
- Regular policy reviews and updates

b) Employee Training and Awareness
- Mandatory data protection training for all staff
- Regular security awareness campaigns
- Confidentiality and non-disclosure agreements (NDAs) for all employees and contractors
- Background checks for personnel with access to sensitive data
- Clear desk and clean screen policies

c) Physical Security
- Restricted access to data centers and server rooms
- 24/7 video surveillance and security personnel
- Visitor logs and escort requirements
- Secure destruction of physical media containing personal data

d) Vendor Management
- Due diligence and security assessments of all third-party processors
- Data Processing Agreements (DPAs) with contractual security obligations
- Regular audits and compliance reviews of service providers
- Incident notification requirements in vendor contracts

Compliance and Certifications:

We are committed to achieving and maintaining:
- ISO 27001 Information Security Management System (in progress)
- DIFC Data Protection Law 2020 compliance
- GDPR (EU General Data Protection Regulation) compliance
- UAE Personal Data Protection Law (PDPL) compliance
- Industry best practices and security frameworks

Regular Audits and Assessments:
- Annual third-party security audits
- Quarterly internal security assessments
- Regular penetration testing and vulnerability assessments
- Continuous monitoring and threat intelligence
- Security metrics and KPI tracking

Data Breach Notification:

In the event of a personal data breach that poses a risk to your rights and freedoms, we will:

1. Internal Response (Immediate)
- Contain and investigate the breach
- Assess the scope and impact
- Document all details and response actions

2. Regulatory Notification (Within 72 Hours)
- Notify the DIFC Commissioner of Data Protection (Article 41, DIFC DP Law 2020)
- Provide details of the breach, affected data, potential consequences, and remedial measures

3. Individual Notification (Without Undue Delay)
- Notify affected individuals directly (Article 42, DIFC DP Law 2020)
- Explain the nature of the breach and potential impact
- Provide clear guidance on protective measures you can take
- Offer support and resources (e.g., credit monitoring if applicable)

4. Remediation and Prevention
- Implement measures to prevent future breaches
- Update security controls and procedures
- Provide regular updates on investigation progress

What You Can Do:
- Use strong, unique passwords for your accounts
- Enable multi-factor authentication where available
- Be cautious of phishing emails and suspicious links
- Keep your devices and software up to date
- Report any suspicious activity immediately

Report Security Concerns:
If you discover a security vulnerability or have concerns about data security:
- Email: privacy@helpforce.ai or support@helpforce.ai
- Phone: +1 (646) 889-8373
- We will investigate and respond within 48 hours

Limitations:
While we implement robust security measures, no system is 100% secure. We cannot guarantee absolute security of data transmitted over the internet or stored electronically. You transmit data at your own risk.

10. AUTOMATED DECISION-MAKING AND AI PROCESSING

As an AI technology company, we develop and deploy automated processing systems and machine learning algorithms to deliver our services to enterprise clients.

Our AI Processing Activities:

We use AI and automation for:
- Business process automation and workflow optimization
- Data analysis, pattern recognition, and predictive analytics
- Natural language processing and intelligent document processing
- Computer vision and image recognition (where applicable)
- Robotic process automation (RPA) for repetitive tasks
- Decision support systems for operational efficiency

Important Safeguards:

a) No Solely Automated Decisions with Legal/Significant Effects
We do NOT use automated decision-making that produces legal effects or similarly significantly affects individuals without meaningful human oversight and intervention.

b) Human Review and Oversight
- All AI outputs are subject to human review before final decisions
- Qualified personnel can override or modify AI recommendations
- Regular audits of AI system performance and accuracy
- Continuous monitoring for bias, errors, and unintended outcomes

c) Transparency and Explainability
- We provide explanations of how AI systems process data and generate outputs
- Enterprise clients receive documentation of AI logic and decision criteria
- Users can request information about automated processing affecting them

d) Consent for AI Testing
Enterprise users participating in AI solution testing do so under:
- Explicit, informed consent with clear opt-in mechanisms
- Full disclosure of data collection and processing purposes
- Right to withdraw consent at any time without penalty
- Assurance that participation is voluntary and optional

e) Fairness and Non-Discrimination
We are committed to developing AI systems that:
- Do not discriminate based on protected characteristics
- Are regularly tested for bias and fairness
- Use diverse and representative training data
- Include fairness metrics in performance evaluation

Your Rights Regarding Automated Processing:

Under GDPR Article 22 and DIFC DP Law principles, you have the right to:
- Not be subject to decisions based solely on automated processing that significantly affect you
- Request human intervention in automated decisions
- Express your point of view and contest automated decisions
- Obtain an explanation of decisions reached through automated means
- Request review and reconsideration of automated decisions

AI Ethics Principles:

We adhere to responsible AI principles:
- Transparency: Clear communication about AI use
- Accountability: Human responsibility for AI outcomes
- Fairness: Equitable treatment and bias mitigation
- Privacy: Data minimization and protection by design
- Safety: Testing and validation before deployment
- Reliability: Continuous monitoring and improvement

Third-Party AI Services:

We may use third-party AI and machine learning services, including:
- Google Cloud AI Platform
- OpenAI API (if applicable)
- Other enterprise AI tools

These services are governed by their respective privacy policies and our Data Processing Agreements.

Questions or Concerns:

If you have concerns about automated processing or AI systems affecting you:
- Email: privacy@helpforce.ai or support@helpforce.ai
- Phone: +1 (646) 889-8373
- We will review your case and provide a detailed response

11. CHILDREN'S PRIVACY

Our services are designed exclusively for businesses, enterprise clients, and professional users. We do not knowingly collect personal data from individuals under the age of 18 without parental or guardian consent.

Age Restrictions:
- You must be at least 18 years old to use our services
- If you are under 18, you may only use our services with the involvement and consent of a parent or legal guardian

Parental Rights:
If you are a parent or guardian and believe we have inadvertently collected information from a minor without appropriate consent:
- Contact us immediately at privacy@helpforce.ai
- We will investigate and delete the information promptly (within 30 days)
- We will take steps to prevent future collection

Schools and Educational Institutions:
If we provide services to educational institutions involving minors:
- We will obtain appropriate consent from the institution acting in loco parentis
- We will comply with applicable child protection laws (e.g., COPPA in the US, GDPR protections for children)
- We will implement additional safeguards for processing children's data

Our Commitment:
We are committed to protecting children's privacy and will:
- Not knowingly market to or target children
- Not knowingly collect sensitive data from minors
- Implement age verification where appropriate
- Cooperate with parents, guardians, and authorities to protect children

12. THIRD-PARTY LINKS AND SERVICES

Our website and services may contain links to third-party websites, applications, or services that are not operated or controlled by HelpForce AI.

Disclaimer:
- We are not responsible for the privacy practices, content, or security of third-party sites
- This Privacy Policy does not apply to third-party websites or services
- We do not endorse or make representations about third-party sites

Your Responsibility:
When you click on third-party links or use third-party services:
- You leave our website and are subject to the third party's terms and privacy policy
- We encourage you to review the privacy policy of every website you visit
- Exercise caution when providing personal information to third parties

Third-Party Services We Use:
We integrate with and use various third-party services, including:
- Google Cloud Platform (cloud infrastructure)
- Google Analytics (website analytics)
- Payment processors - if applicable
- CRM systems - if applicable
- Communication and collaboration tools

These third parties have their own privacy policies and data processing practices. We require all third-party processors to comply with our data protection standards through Data Processing Agreements.

Social Media:
If we maintain social media profiles (LinkedIn, Twitter, Facebook, etc.):
- These platforms have their own privacy policies
- Interactions on social media are governed by the platform's terms
- We may collect publicly available information you share on social media

Your Privacy Choices:
- Review and adjust privacy settings on third-party platforms
- Limit information sharing with third-party apps and services
- Use browser extensions to block third-party trackers
- Contact third parties directly for their data practices

13. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, technology, or business operations.

When We Update:
- We will post the updated policy on this page with a new "Effective Date" and "Last Updated" date
- The version number will be incremented (e.g., from v2.0 to v3.0)
- For material changes that significantly affect your rights or how we process your data, we will provide prominent notice through:
 - Email notification (if you have provided an email address)
 - Pop-up notice or banner on our website
 - In-app notification (for users of our services)
 - At least 30 days' advance notice before changes take effect

What Constitutes a Material Change:
- Changes to the purposes for which we collect or process data
- Expansion of data sharing with third parties
- Changes to data retention periods
- New types of data collection
- Changes to your rights or how to exercise them
- Transfers to new countries or jurisdictions
- Changes to security measures that may affect data protection

Your Acceptance:
- Continued use of our services after the effective date of changes constitutes acceptance of the updated Privacy Policy
- If you do not agree with changes, you should discontinue use of our services and may request deletion of your data
- For material changes requiring consent, we will obtain your explicit consent before applying changes to your data

Version History:
We maintain a record of previous versions of this Privacy Policy. To request access to previous versions:
- Email: privacy@helpforce.ai
- We will provide the requested version within 10 business days

Current Version: 2.0
Last Updated: 29 November, 2025
Previous Version: 1.0 (Effective Date: January 01, 2025)

Review Frequency:
We review and update this Privacy Policy at least annually or whenever:
- There are significant changes to our data processing activities
- New laws or regulations come into effect
- We receive guidance from regulatory authorities
- We identify improvements to better protect your privacy

Notification Preferences:
To ensure you receive notifications about policy changes:
- Keep your email address up to date in your account settings
- Check our website periodically for updates
- Subscribe to our newsletter or announcements (if available)

14. COMPLAINTS AND REGULATORY INFORMATION

We are committed to resolving any concerns you have about how we handle your personal data. If you believe we have not processed your data in accordance with this Privacy Policy or applicable data protection laws, please contact us first so we can address your concerns.

Step 1: Contact Us Directly

We encourage you to contact us first with any privacy concerns:

Email: privacy@helpforce.ai (preferred method for data protection inquiries)
Phone: +1 (646) 889-8373
Website Form: www.helpforce.ai/contact
Mail: HelpForce AI Ltd., Unit IH-00-VZ-01-FL-193, Level 1, Innovation Hub, DIFC, Dubai, UAE

What to Include in Your Complaint:
- Your name and contact information
- Description of your concern or complaint
- Details of the alleged privacy violation
- Any relevant dates, communications, or documentation
- What resolution you are seeking

Our Response Process:
- Acknowledgment: We will acknowledge receipt of your complaint within 5 business days
- Investigation: We will thoroughly investigate your concern, which may include reviewing records, interviewing staff, and consulting legal counsel
- Response: We will provide a substantive response within 30 days (or 60 days for complex matters, with notification of the extension)
- Resolution: We will explain our findings, any corrective actions taken, and your options if you remain unsatisfied

Step 2: Regulatory Complaints

If you are not satisfied with our response, or if you prefer to contact a regulatory authority directly, you have the right to lodge a complaint with:

DIFC Commissioner of Data Protection
Level 14, The Gate Building
PO Box 74777
Dubai, United Arab Emirates
Website: www.difc.ae/laws-regulations/data-protection
Email: dp@difc.ae
Phone: +971 4 362 2222

DIFC Commissioner Authority:
The DIFC Commissioner of Data Protection oversees compliance with the DIFC Data Protection Law 2020 and has authority to:
- Investigate complaints and data breaches
- Conduct audits and inspections
- Issue warnings, reprimands, and corrective orders
- Impose administrative fines for violations
- Order suspension of data processing activities

For EU/EEA Residents:

If you are located in the European Union or European Economic Area, you may also lodge a complaint with your local Data Protection Authority (DPA):

Find Your DPA: https://edpb.europa.eu/about-edpb/board/members_en

Examples:
- Ireland: Data Protection Commission (dataprotection.ie)
- Germany: Federal Commissioner for Data Protection and Freedom of Information (bfdi.bund.de)
- France: CNIL (cnil.fr)
- UK: Information Commissioner's Office (ico.org.uk)

For Other Jurisdictions:

UAE Residents (outside DIFC):
UAE Telecommunications and Digital Government Regulatory Authority (TDRA)
Website: tdra.gov.ae

Pakistan Residents:
National Commission for Personal Data Protection (NCPDP)

No Retaliation:
You have the right to lodge a complaint with regulatory authorities at any time, and we will not:
- Retaliate against you for filing a complaint
- Terminate services solely because you filed a complaint
- Charge fees or impose penalties for exercising your complaint rights

However, we strongly encourage you to contact us first so we have the opportunity to address your concerns directly and promptly.

Dispute Resolution:
For contractual disputes related to our services (as opposed to privacy complaints), please refer to the dispute resolution procedures in our Terms of Service.

15. LEGAL FRAMEWORK AND COMPLIANCE

This Privacy Policy is designed to comply with multiple data protection frameworks applicable to our operations:

Applicable Laws and Regulations:

a) DIFC Data Protection Law 2020 (DIFC Law No. 5 of 2020)As a DIFC-registered entity, we comply with all provisions of the DIFC Data Protection Law, including:

  • Article 14: Compliance program and accountability requirements
  • Article 15: Record of processing activities (ROPA)
  • Articles 16-18: Data Protection Officer appointment (when required)
  • Articles 23-25: Processor and joint controller obligations
  • Articles 26-27: International data transfer requirements
  • Articles 28-34: Data subject rights
  • Article 40: Data subject contact methods
  • Articles 41-42: Personal data breach notification
  • Schedule 1: High Risk Processing assessment

b) EU General Data Protection Regulation (GDPR)For EU/EEA residents and data subjects, we comply with GDPR requirements, including:

  • Lawful basis for processing (Article 6)
  • Special categories of data (Article 9)
  • Data subject rights (Articles 15-22)
  • Data protection by design and default (Article 25)
  • Data protection impact assessments (Article 35)
  • International data transfers (Articles 44-50)
  • Breach notification (Articles 33-34)

c) UAE Federal Data Protection Law (Expected Implementation)
We monitor developments in UAE federal data protection legislation and will ensure compliance when enacted.

d) Other Applicable Laws

  • UAE Cybercrime Laws
  • UAE Commercial Companies Law
  • Industry-specific regulations applicable to our clients (e.g., healthcare, financial services)
  • Data protection laws in jurisdictions where we operate or have clients

Compliance Measures:

We maintain ongoing compliance through:

  • Legal and regulatory monitoring
  • Regular compliance audits and assessments
  • Staff training and awareness programs
  • Documentation and record-keeping (ROPA, DPIAs, etc.)
  • Vendor due diligence and management
  • Incident response and breach notification procedures
  • Continuous improvement of policies and practices

Accountability:We embrace the principle of accountability under DIFC DP Law Article 14, which means:

  • We can demonstrate compliance with data protection obligations
  • We maintain comprehensive documentation of processing activities
  • We implement appropriate technical and organizational measures
  • We regularly review and update our compliance program
  • We take responsibility for our processors and sub-processors

Legal Basis Documentation:We maintain records documenting the legal basis for each processing activity, including:

  • Consent records and audit trails
  • Contract performance necessities
  • Legitimate interest assessments (LIA)
  • Legal obligation requirements
  • Vital interest documentation (if applicable)

Data Protection Impact Assessments (DPIA):When required by law or when processing poses high risks to individuals' rights, we conduct DPIAs to:

  • Assess necessity and proportionality of processing
  • Identify and mitigate privacy risks
  • Document compliance measures
  • Consult with the DIFC Commissioner when necessary

We use the DPIA template provided by the DIFC Commissioner and follow best practice guidelines.

Cooperation with Authorities:We commit to:

  • Respond promptly to regulatory inquiries and requests
  • Cooperate with investigations and audits
  • Provide required documentation and information
  • Implement corrective measures as directed by authorities
  • Report data breaches and incidents as required by law

Penalties for Non-Compliance:We acknowledge that violations of data protection laws can result in:

  • Administrative fines and penalties
  • Corrective orders and compliance directives
  • Suspension or restriction of processing activities
  • Reputational damage and loss of trust
  • Civil liability and compensation claims

We are committed to full compliance to protect both your rights and our business operations.

16. DEFINITIONS

To help you understand this Privacy Policy, here are definitions of key terms:

Controller: The entity that determines the purposes and means of processing personal data. HelpForce AI acts as a Controller for account, billing, and marketing data.

Data Subject: An identified or identifiable natural person whose personal data is being processed.

DIFC: Dubai International Financial Centre, a financial free zone in Dubai, UAE with its own legal and regulatory framework.

DIFC DP Law: DIFC Data Protection Law 2020 (DIFC Law No. 5 of 2020), the primary data protection legislation governing our operations.

GDPR: General Data Protection Regulation (EU) 2016/679, the European Union's comprehensive data protection law.

Personal Data: Any information relating to an identified or identifiable natural person, including name, email, IP address, location data, online identifiers, etc.

Processing: Any operation performed on personal data, including collection, recording, organization, storage, use, disclosure, erasure, or destruction.

Processor: An entity that processes personal data on behalf of a Controller. HelpForce AI acts as a Processor for client data processed through our AI services.

Special Categories of Personal Data: Sensitive data requiring additional protection, including data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation.

Third Country: A country outside the DIFC, EEA, or UAE that may not have adequate data protection laws.

17. CONTACT US

For any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:

HelpForce AI Ltd.
Commercial License Number: CL9930
Unit IH-00-VZ-01-FL-193, Level 1, Innovation Hub
Dubai International Financial Centre (DIFC)
Dubai, United Arab Emirates

General Inquiries and Support:
Email: support@helpforce.ai
Response Time: Within 48 business hours

Data Protection and Privacy Inquiries:
Email: privacy@helpforce.ai
Response Time: Within 30 days (48 hours for urgent matters)

Legal and Contractual Matters:
Email
: legal@helpforce.ai
Response Time: Within 5 business days

Phone (All Inquiries):+1 (646) 889-8373
Available: Monday - Friday, 9:00 AM - 5:00 PM GST (Gulf Standard Time)

Website: www.helpforce.ai
Contact Form: www.helpforce.ai/contact

Data Protection Contact:
Usman Ali Asghar
Email: usman@helpforce.ai

Authorized Signatory: Usman Ali Asghar

Business Hours: Monday - Friday: 9:00 AM - 5:00 PM GST
Closed: Saturday - Sunday

Mailing Address for Legal Notices:
HelpForce AI Ltd.
Unit IH-00-VZ-01-FL-193
Level 1, Innovation Hub
Dubai International Financial Centre (DIFC)
PO Box 507359
Dubai, United Arab Emirates

DIFC Registration Information:
Commercial License: CL9930
DIFC Data Protection Registration: (Pending Approval)
Company Activities: Innovation & AI Consultancy, Technology Research & Development, IT Consultancy, Web Design, Software Development

We aim to respond to all inquiries as quickly as possible. For urgent privacy matters, please mark your email "URGENT - Privacy Request" in the subject line.

Thank you for trusting HelpForce AI Ltd. with your information. Your privacy is important to us.

END OF PRIVACY POLICY

© 2025 HelpForce AI Ltd. All rights reserved.

Backed by
Nvidia Inception Program BadgeAWS Activate Logo and Helpforce is Member nowMicrosoft for Startups member badge
© 2025 Helpforce AI Ltd. All rights reserved.