Privacy Policy

Personal Data Processing Policy

Last updated: 10 May 2026

This Privacy Policy (the "Policy") explains how PROFSOFT GLOBAL - FZCO ("Company", "we", "us", "our") collects, uses, stores, discloses and otherwise processes Personal Data in connection with the website and software service available at https://strophe.app/ (the "Service").

For the purposes of applicable UAE personal data protection laws, the Company generally acts as a Controller of Personal Data collected for account administration, payments, security, analytics, marketing and customer support. In relation to Personal Data contained in User Content submitted by business customers or their authorised users, the Company may act as a Processor or service provider, depending on the circumstances and applicable contractual terms.

If you have any questions about this Policy or about the processing of Personal Data, please contact us at hello@strophe.app.

This Policy is intended to be read together with the License Agreement, subscription terms, cookie consent and any other notices or terms made available through the Service. By registering for, accessing or using the Service, you acknowledge that you have read this Policy. Where applicable law requires consent for a specific processing activity, we will ask for your consent separately or through the relevant Service interface.

1. Applicable law and scope

1.1. This Policy is adapted for operation from the United Arab Emirates and is intended to reflect the requirements of UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "UAE PDPL") and other UAE laws applicable to electronic services, digital commerce, online communications, payments and consumer data protection, to the extent applicable to the Service.

1.2. This Policy applies to Personal Data processed through the Service, including Personal Data relating to visitors, registered users, subscribers, customers, authorised representatives of legal entities, prospects and persons who contact us through support or feedback channels.

1.3. This Policy does not apply to third-party websites, applications, AI models, payment systems or services that are not controlled by us, even if they are linked from or integrated with the Service. Such third parties process Personal Data under their own terms and privacy notices, unless they act as our Processor under a written agreement.

1.4. The Service is intended for users who have the legal capacity to enter into and perform the applicable terms of use. If you are using the Service on behalf of a company or other legal entity, you represent that you are authorised to do so and that you will ensure that the relevant persons are provided with appropriate privacy information.

2. Key terms

  • Personal Data means any data relating to an identified or identifiable natural person.

  • Sensitive Personal Data means Personal Data which, under applicable law, requires additional safeguards, including information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, biometric data, health data, criminal record data and similar categories.

  • Data Subject means the natural person to whom Personal Data relates.

  • Controller means the person or entity that determines the purposes and means of processing Personal Data.

  • Processor means the person or entity that processes Personal Data on behalf of the Controller.

  • Processing means any operation performed on Personal Data, including collection, recording, storage, organisation, use, transmission, disclosure, deletion, anonymisation or destruction.

  • Consent means a clear, specific, informed and unambiguous indication of the Data Subject’s agreement to the processing of Personal Data.

  • User Content means prompts, files, text, images, documents, metadata, project names, generated outputs and any other information submitted, uploaded, transmitted, processed or generated through the Service.

  • Cookies means small text files and similar technologies placed on or accessed from your device when you use the Service.

3. Your rights

Subject to applicable law and any permitted limitations, you may have the following rights in relation to your Personal Data:

  • the right to receive information about the categories of Personal Data processed, the purposes of processing, recipients, retention criteria, international transfers and safeguards;

  • the right to access your Personal Data;

  • the right to request correction or completion of inaccurate or incomplete Personal Data;

  • the right to request deletion of Personal Data where it is no longer necessary, where consent has been withdrawn and no other lawful basis applies, or where processing is unlawful;

  • the right to request restriction or cessation of processing in the cases provided by applicable law;

  • the right to object to processing for direct marketing and certain statistical or profiling purposes;

  • the right to receive Personal Data you provided to us in a structured, commonly used and machine-readable format, where technically feasible and where the legal conditions for portability are met;

  • the right to object to decisions based solely on automated processing, including profiling, where such decisions have legal or similarly significant effects, and to request human review where applicable;

  • the right to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal;

  • the right to submit a complaint to the UAE Data Office or another competent authority, where applicable.

4. How to exercise your rights

4.1. You may exercise your rights by contacting us at hello@strophe.app. We may ask you to provide information reasonably necessary to verify your identity, locate your account and understand your request.

4.2. If you submit a request on behalf of another person, we may ask for evidence of your authority to act for that person.

4.3. We will respond to your request within the timeframe required by applicable law. If we need more time because the request is complex or because we receive a large number of requests, we will inform you where required.

4.4. We may refuse or limit a request where permitted by applicable law, for example where the request is manifestly unfounded or excessive, conflicts with legal proceedings or investigations, adversely affects security, affects the rights and freedoms of others, or where we must retain the data to comply with legal obligations or to establish, exercise or defend legal claims.

5. Personal Data we collect

Depending on how you interact with the Service, we may collect and process the following categories of Personal Data:

  • Account and profile data: email address, account identifier, nickname, profile photo, password/authentication data or other credentials, workspace/project information and settings.

  • Customer and business contact data: name, job title, company name, contact details, billing contact details, tax or registration details where required for contracting or invoicing.

  • Payment and subscription data: subscription plan, payment status, transaction identifiers, invoice details, billing history, last four digits of a payment card and payment token or stored credential references received from a payment processor.

  • Service usage and technical data: IP address, device identifiers, browser type and version, operating system, language, time zone, log data, session data, error reports, feature use, traffic source, pages viewed and activity timestamps.

  • Cookies and analytics data: cookie identifiers, consent preferences, analytics events, interaction data and advertising or marketing attribution data, where such tools are enabled.

  • User Content: prompts, messages, files, images, documents, project names, generated materials and other content submitted to or generated through the Service. User Content may include Personal Data if you choose to include it.

  • Support and communications data: messages, requests, complaints, feedback, attachments and any Personal Data contained in correspondence with us.

  • Marketing and survey data: email address, name, preferences, consents, survey responses, city/country, age range and other information voluntarily provided by you.

We do not intentionally request or require Sensitive Personal Data for ordinary use of the Service. You must not submit Sensitive Personal Data, government secrets, confidential third-party data, payment card full numbers, access credentials or other regulated information into prompts, files or other User Content unless you have a lawful basis and the processing is expressly permitted by the applicable terms and law.

6. How we collect Personal Data

  • directly from you when you register, use the Service, subscribe, purchase credits, contact support, complete forms, join a newsletter, participate in surveys or upload User Content;

  • automatically through cookies, logs, device identifiers, API calls and similar technologies when you access or use the Service;

  • from payment processors, authentication providers, analytics providers, anti-fraud tools, communication tools and other service providers involved in providing the Service;

  • from your organisation or account administrator, if your access is provided under an enterprise or team account.

7. Purposes and lawful bases of processing

We process Personal Data only for specified purposes and on a lawful basis under applicable law. Depending on the processing activity, the lawful basis may include performance of a contract with you, taking steps at your request before entering into a contract, compliance with legal obligations, your consent, protection of rights and legal claims, security and fraud prevention, or another basis permitted by applicable UAE law.

In particular, we process Personal Data for the following purposes:

  • to create, authenticate and manage your account, workspace and subscription;

  • to provide access to the Service and its features, including AI-powered tools, generation of materials, file processing, project management and API access;

  • to route prompts, files, metadata and other User Content to AI model/API providers and infrastructure providers where necessary to generate outputs and operate the Service;

  • to process payments, subscriptions, recurring payments, refunds, invoices, taxes and fraud checks;

  • to provide customer support, respond to requests and send service-related notices;

  • to maintain, troubleshoot, test, improve, personalise and secure the Service;

  • to detect, prevent and investigate misuse, abuse, unlawful activity, security incidents and violations of the applicable terms;

  • to send marketing communications where you have consented or where permitted by law, and to record your marketing preferences;

  • to conduct analytics, measure performance, understand how users interact with the Service and improve our products, subject to cookie and consent settings where required;

  • to comply with applicable laws, regulatory requests, sanctions, accounting, tax and recordkeeping obligations, and to establish, exercise or defend legal claims.

8. User Content and AI processing

8.1. The Service enables users to submit prompts, files and other User Content to generate outputs using AI tools and third-party AI model/API providers. To provide these features, User Content may be transmitted to, processed by and returned from such providers and related infrastructure.

8.2. You are responsible for ensuring that you have all necessary rights, permissions, notices and lawful bases to submit User Content, including any Personal Data of third parties. If you use the Service on behalf of an organisation, that organisation is responsible for providing any required notices to its employees, contractors, customers or other Data Subjects whose Personal Data is included in User Content.

8.3. We recommend that you avoid including unnecessary Personal Data in prompts or files and that you remove or anonymise Personal Data whenever possible before submitting User Content to the Service.

8.4. The Service does not generally make decisions that produce legal or similarly significant effects on users based solely on automated processing. AI-generated outputs are provided for user review and use at the user’s discretion. Where applicable law grants a right to human review of automated decisions, you may contact us using the details in this Policy.

9. Cookies and similar technologies

9.1. We use cookies and similar technologies to operate the Service, remember preferences, understand usage, improve performance, prevent fraud and, where enabled, support analytics and marketing.

9.2. The Service may use the following types of cookies:

  • Strictly necessary cookies: required for the website and Service to function, authenticate users, maintain sessions, remember security settings and provide requested features.

  • Functional cookies: used to remember preferences such as language, interface settings or consent choices.

  • Analytics and performance cookies: used to understand how users interact with the Service, count visits, analyse errors and improve performance.

  • Advertising or tracking cookies: used to measure campaigns, identify traffic sources and provide or measure personalised or interest-based advertising, if enabled.

    9.3. Where required by applicable law, non-essential cookies will be used only after you give consent through the cookie banner or other consent mechanism. You may withdraw or change cookie consent through the available settings or by adjusting your browser settings. If you disable some cookies, parts of the Service may not function properly.

10. Disclosure of Personal Data

We do not sell Personal Data. We may disclose Personal Data only where necessary for the purposes described in this Policy and under appropriate confidentiality, data protection and security commitments, including to:

  • hosting, cloud, database, storage, security and infrastructure providers;

  • AI model, API, inference, compute and file-processing providers used to operate Service features;

  • payment processors, acquiring banks, anti-fraud tools and subscription management providers;

  • analytics, cookie management, marketing, email delivery and customer communication providers;

  • professional advisers, auditors, accountants, legal counsel and insurers;

  • affiliates, contractors and personnel who need access to operate, support or improve the Service;

  • government authorities, courts, regulators, law enforcement agencies or other third parties where disclosure is required by law, necessary to protect rights or safety, or necessary to enforce our terms;

  • another entity in connection with a merger, acquisition, restructuring, sale of assets or similar corporate transaction, subject to appropriate confidentiality and data protection safeguards.

The categories of processors and recipients may change as the Service evolves. Where required, we maintain records of processing activities and use written contracts or other legally recognised safeguards with processors and other recipients.

11. International transfers

11.1. Personal Data may be stored, accessed or processed in the UAE and in other jurisdictions where we, our affiliates, processors, AI providers, payment providers, cloud providers or other service providers operate.

11.2. Where Personal Data is transferred outside the UAE, we rely on one or more safeguards or lawful grounds permitted by applicable law, such as transfer to jurisdictions with an adequate level of protection, contractual commitments requiring appropriate protection measures, your explicit consent where required, transfer necessary to perform a contract with you or to serve your interests, transfer necessary for legal claims, or another permitted basis.

11.3. Because AI and cloud infrastructure may operate across multiple regions, you should not submit Personal Data or confidential information to the Service unless you are satisfied that such transfer and processing is lawful and appropriate for your intended use.

12. Security and breach management

12.1. We implement appropriate technical and organisational measures designed to protect Personal Data against unauthorised access, loss, alteration, disclosure or destruction. These measures may include access controls, encryption or pseudonymisation where appropriate, logging, backups, vulnerability management, staff access limitations and contractual confidentiality commitments.

12.2. No online service, internet transmission or storage system can be guaranteed to be completely secure. You are responsible for maintaining the confidentiality of your credentials, using strong passwords and promptly notifying us of suspected unauthorised access to your account.

12.3. If we become aware of a Personal Data breach that is likely to prejudice privacy, confidentiality or security of Personal Data, we will assess the incident and notify the competent authority and affected Data Subjects where required by applicable law.

13. Data retention and deletion

13.1. We retain Personal Data only for as long as reasonably necessary for the purposes for which it was collected, including to provide the Service, maintain accounts, comply with legal obligations, resolve disputes, enforce agreements, prevent fraud and maintain security.

13.2. Retention periods vary depending on the type of data and the context of processing. More detailed retention information is set out in Appendix 1. Where retention is no longer necessary, we will delete, anonymise or otherwise irreversibly de-identify Personal Data, unless a longer retention period is required or permitted by law.

13.3. If you delete your account or request deletion of Personal Data, we will delete or anonymise Personal Data subject to technical limitations, backup cycles, legal retention duties, payment and accounting records, security logs, dispute records and any information necessary to establish, exercise or defend legal claims.

14. Marketing communications

We may send you marketing communications only where you have consented or where otherwise permitted by applicable law. You may unsubscribe or withdraw consent at any time by using the unsubscribe link in the communication or by contacting us. We may continue to send transactional and service-related communications that are necessary for account administration, security, billing or performance of the Service.

15. Third-party links and services

The Service may contain links to third-party websites, platforms, payment pages, AI services, documentation or integrations. We are not responsible for the privacy practices, content or security of such third parties unless they process Personal Data on our behalf under a contract. You should review the privacy notices of any third-party service before using it.

16. Children and minors

The Service is not directed to children. We do not knowingly collect Personal Data from children below the age at which they can lawfully use the Service or provide consent under applicable law without parental or guardian involvement. If you believe that a child has provided Personal Data to us without appropriate consent, please contact us so that we can take appropriate steps.

17. Changes to this Policy

We may update this Policy from time to time. The updated version will be posted through the Service and will indicate the date of the latest update. Where changes are material or where required by law, we will take reasonable steps to notify you through the Service, by email or by other appropriate means. Your continued use of the Service after an updated Policy becomes effective means that you acknowledge the updated Policy, while any processing that requires consent will remain subject to the applicable consent rules.

18. Governing law and disputes

This Policy and any non-contractual obligations arising out of or in connection with it are governed by the laws of the United Arab Emirates, to the extent applicable. Unless mandatory consumer or data protection rules require otherwise, disputes arising in connection with this Policy may be submitted to the competent courts of Dubai, UAE.

19. Company details and contacts

Company: PROFSOFT GLOBAL - FZCO

Address: 6008, UAE, Dubai, Dubai Silicon Oasis, IFZA Properties, A2

License No.: 21028

Email: hello@strophe.app

Appendix 1 to the Privacy Policy

Personal Data Processing Details

No.Processing purposeCategories of Personal DataLawful basis / conditionRetention periodProcessing type and deletion method
1Preparation, conclusion and performance of the License Agreement, subscription terms and related customer relationship.Email address; name and surname where provided; account identifier; nickname; profile photo where provided; company name and role where applicable; billing contact details; tax or registration details where required.Performance of a contract; steps taken at the request of the Data Subject; compliance with applicable legal obligations; consent for optional profile data where applicable.For the account term and for as long as required to perform the contract. Certain records may be retained after termination where required for accounting, tax, legal claims, security or dispute resolution.Automated and mixed processing; deletion, anonymisation or irreversible de-identification from active systems when retention is no longer required; backup deletion according to backup cycles.
2Creation, use and management of user account, workspace, projects and Service settings.Email address; authentication data; account and workspace identifiers; nickname; project names; settings; role/permissions; activity status.Performance of a contract; security and account administration; consent where optional data is provided.Until account deletion or termination, subject to legal retention, backup cycles and dispute/security records.Automated processing; irreversible deletion or anonymisation from information systems where feasible.
3Provision of Service functions, including AI tools, prompt processing, file upload, generation of outputs and API use.User Content, prompts, uploaded files, generated outputs, project metadata, API identifiers, account identifiers, technical metadata, IP address and usage logs.Performance of a contract; processing necessary to provide requested Service functions; consent where required for optional or non-essential processing; legal claims and security where applicable.For the period necessary to provide the Service and maintain user projects, subject to user deletion controls, backups, security logs and legal retention requirements.Automated processing; deletion or anonymisation from active systems; deletion from backups according to backup retention cycles.
4Technical operation, security, fraud prevention, abuse detection and protection of the Service, users and third parties.IP address; device and browser identifiers; session and log data; operating system; language; timestamps; error reports; API events; security events; cookie identifiers necessary for security.Processing necessary for operation and security of the Service; compliance with legal obligations; establishment, exercise or defence of legal claims.For the period necessary for security, fraud prevention, troubleshooting and compliance. Security logs may be retained for a reasonable period after account termination.Automated and mixed processing; deletion, aggregation or anonymisation after expiry of retention period.
5Analytics of Service use, user preferences and product improvement.Usage events; pages viewed; feature interactions; traffic source; IP address; device/browser data; language; cookie identifiers; account identifiers where analytics are tied to registered use; preferences and interests.Consent for non-essential analytics and cookies where required; performance of a contract for strictly necessary technical diagnostics; de-identified or aggregated analytics where possible.Usually until consent withdrawal or expiry of cookie/analytics retention period. Aggregated or anonymised statistics may be retained longer.Automated processing; deletion, aggregation, anonymisation or depersonalisation.
6Newsletter subscription and marketing communications.Email address; name where provided; marketing preferences; consent records; unsubscribe status; campaign interaction data.Consent or another lawful basis permitted by applicable law; withdrawal of consent available at any time.Until unsubscribe or withdrawal of consent. Suppression records may be retained to ensure that marketing is not sent again against your preference.Automated processing; deletion from marketing systems or restriction through suppression list.
7Surveys, research, feedback and product interviews.Name; email address; phone number where provided; age range or city/country where provided; survey answers; interview notes; preferences and feedback.Consent; performance of a contract where feedback is part of support; anonymised or aggregated research where possible.For the period disclosed at collection or until consent withdrawal, unless anonymised or required for legal claims.Automated and mixed processing; deletion, anonymisation or aggregation.
8Customer support and processing of requests, complaints and communications submitted through the Service or contact channels.Name; email address; phone number; account ID; message content; attachments; support history; technical information necessary to investigate the request.Performance of a contract; consent where you voluntarily provide optional data; compliance with legal obligations; establishment, exercise or defence of legal claims.For the period necessary to resolve the request and then for a reasonable period for quality control, dispute resolution and legal claims.Mixed processing; deletion from active support systems and physical destruction of any paper records if any.
9Payments, subscriptions, recurring billing, credits, invoicing, refunds and chargebacks.Billing name and contact details; transaction identifiers; subscription plan; payment status; invoice data; last four digits of card; token or stored credential reference; chargeback/refund details. We do not intentionally store full card numbers or CVV codes.Performance of a contract; consent for stored credentials and recurring transactions where required; compliance with accounting, tax and payment laws; fraud prevention and legal claims.For the account term and for the period required by applicable tax, accounting, payment, anti-fraud and legal obligations. Stored credential references are retained until cancellation, expiry or withdrawal where applicable.Automated and mixed processing; deletion or restriction when no longer required, subject to financial record retention and payment processor rules.
10Compliance with laws, regulator requests, sanctions, enforcement of terms and protection of rights.Account data; identity or authority documents where lawfully requested; communications; transaction records; logs; User Content and technical data relevant to investigation or claims.Compliance with applicable legal obligations; protection of rights; judicial, regulatory or security procedures; establishment, exercise or defence of legal claims.For as long as required by applicable law, regulator request, dispute, investigation, limitation period or legal hold.Mixed processing; deletion, restriction or secure archival after the legal basis for retention ends.

Note: The retention periods above are indicative and may be shortened or extended where required by applicable law, user settings, technical backup cycles, fraud prevention, security incidents, disputes, investigations, tax or accounting obligations, or legal holds.