1. Who we are and how to contact us
Qiko AI Labs FZCO ("Qiko", "we", "us" or "our") is located at IFZA Business Park, DDP, PO Box 342001, Dubai, United Arab Emirates. Contact us about privacy atsupport@qiko.ai.
The Service is business-to-business. This policy applies to customer administrators and users, prospective customers, business contacts, support contacts and people who interact with a customer's Qiko digital worker.
2. When Qiko is controller or processor
Qiko acts as a controller when it decides why and how to process account, commercial, security, website, support and business contact data. For these activities, Qiko is responsible for the processing described in this policy.
Qiko generally acts as a processor or service provider when a customer submits Customer Content, configures a digital worker or determines why personal data is handled through that worker. The customer is then the controller or equivalent business, and Qiko processes the data on its documented instructions and under applicable contractual terms. A rights request about that data may be routed to the relevant customer so it can respond as controller.
3. Personal data we process
- Account and business data: name, work email, organisation, role, tenant, account status and user preferences.
- Authentication and security data: password hashes, session and CSRF information, access permissions, authentication events, IP address and security logs.
- Device and technical data: browser and device type, operating system, request metadata, timestamps, diagnostics and service interactions. Qiko does not currently load browser analytics or marketing technologies.
- Customer Content: documents, prompts, messages, approved answers, knowledge sources, digital worker settings and generated responses, which may include personal data chosen by the customer or its users.
- Support and communications: enquiries, correspondence, feedback and troubleshooting information.
- Commercial and payment data: Orders, plan and transaction records. If enabled and initiated by a user, payment checkout is hosted by Stripe. Qiko does not need to receive full payment card details from that hosted checkout.
- Compliance data: records needed to manage legal requests, disputes, fraud, misuse and regulatory obligations.
4. Sources of personal data
We receive data directly from users and customer administrators, from Customer Content and interactions with digital workers, from devices and systems that connect to the Service, from customer-authorised integrations, from our service providers, and from business communications. Customers decide what Customer Content to submit and are responsible for providing required notices and having a lawful basis for it.
5. Why we process data
- create and administer accounts, tenants and permissions;
- provide, operate and support digital workers and other requested features;
- authenticate users, secure the Service, prevent abuse and investigate incidents;
- process Customer Content on the customer's instructions;
- respond to enquiries, provide support and send operational or legal notices;
- manage Orders, payments, tax and business records where applicable;
- diagnose faults and improve reliability, usability and features using appropriately limited data;
- establish, exercise or defend legal claims and comply with law; and
- seek and manage consent where consent is required.
6. Lawful bases
Where the EU GDPR or UK GDPR applies to Qiko as controller, we rely on performance of a contract or steps requested before a contract, compliance with legal obligations, and legitimate interests such as securing, operating and improving a B2B service, supporting customers and managing our business. We balance those interests against affected rights. We use consent where required, including for optional browser technologies. Consent can be withdrawn at any time without affecting earlier lawful processing.
Under UAE data protection law, we process personal data with consent where required and where another legal ground permits processing, including steps connected with a contract, compliance with law, protection of rights and other grounds available under applicable law. When Qiko is a processor, the customer determines the relevant lawful basis.
7. How AI and tenant retrieval work
Qiko can divide customer-provided knowledge into smaller passages, create numerical embeddings using Amazon Titan, and store and retrieve relevant passages within the customer's tenant context. When a user sends a prompt, relevant tenant content and instructions may be supplied through Amazon Bedrock to Anthropic Claude models for EU geographic inference. The resulting answer is returned to the digital worker experience.
A customer may review and approve an answer. Qiko may reuse that approved answer within the same tenant's retrieval flow to improve consistency. This is retrieval and approved-answer reuse, not foundation model fine-tuning. Customers control the knowledge and instructions they submit. Contract terms with AI and infrastructure providers govern their processing.
8. Automated decision support
AI outputs support customer workflows but can be inaccurate and require human review. Qiko does not intend the Service to make solely automated decisions on its own behalf that create legal or similarly significant effects for individuals. Customers must assess their own use, provide suitable human oversight and not use an output as the sole basis for a significant decision unless lawful safeguards are in place. Contact the relevant customer about a decision made through its digital worker.
9. Providers, subprocessors and disclosures
We disclose data only as needed for the purposes above, including to:
- Amazon Web Services: core EU Central infrastructure, storage, Amazon Bedrock Claude inference with EU geographic routing, and Amazon Titan embeddings;
- Cloudflare: conditional network delivery, availability and security services, which may set necessary security cookies;
- Stripe: conditional user-initiated hosted payment checkout and payment processing if that feature is enabled;
- contracted communications, email, support, monitoring and professional service providers where used to operate Qiko;
- customer-authorised integrations and recipients selected by the customer;
- advisers, auditors, insurers and a buyer, investor or successor involved in a genuine corporate transaction, subject to appropriate confidentiality; and
- courts, regulators, law enforcement or other parties where required by law or necessary to protect rights, safety and security.
These providers process data under contractual restrictions appropriate to their role. Qiko does not sell personal data. Contact support@qiko.ai for current subprocessor information relevant to a customer's Service.
10. International data locations and transfers
Core processing currently uses AWS EU Central infrastructure. Amazon Bedrock Claude requests use EU geographic inference routing. Qiko is established in the UAE, and authorised Qiko personnel may access data from the UAE for administration, security and support. Providers may also process data in locations permitted by their contracts. Qiko does not promise UAE-only, EU-only or single-region processing.
Where personal data is transferred from the EEA, UK or another jurisdiction that restricts international transfers, Qiko uses safeguards required for the transfer and appropriate to the parties' roles, such as adequacy mechanisms or approved contractual clauses, supplemented by technical and organisational measures where appropriate. Transfer arrangements are subject to the applicable customer and provider contracts.
11. Retention
We retain personal data for as long as reasonably needed for the relevant account, Order, customer instruction or purpose. We also consider legal and tax obligations, security and fraud prevention, backup cycles, dispute and limitation periods, the sensitivity and volume of data, technical feasibility and whether data can be de-identified. Different records therefore have different retention periods.
When retention is no longer justified, we delete, de-identify or securely isolate data as appropriate. Backup and legal-hold copies may remain until their applicable cycle or hold ends. Available deletion and export functions vary by feature and contract. This policy does not promise comprehensive self-service deletion, a fixed export format or a fixed deletion period.
12. Security
Qiko uses technical and organisational measures designed to protect personal data, including access controls, tenant separation, credential hashing, encryption in transit, logging and provider security controls where appropriate. No internet service or security measure can guarantee absolute security. Customers remain responsible for their account access, endpoint security, user permissions and the content they choose to submit.
13. Your rights
Depending on the applicable UAE, EEA, UK or other data protection law and relevant exemptions, you may have rights to receive information about processing, access personal data, correct it, request deletion, restrict or object to processing, receive portable data, withdraw consent, and object to certain direct marketing. You may also have rights concerning qualifying solely automated decisions.
Send requests to support@qiko.ai. We may verify identity and authority, ask for details needed to locate data, or decline or limit a request where law permits. If Qiko processes the data for a customer, we may direct the request to that customer and assist it under our contract.
You may complain to the UAE Data Office where it has jurisdiction, an EEA supervisory authority in your country, or the UK Information Commissioner's Office. We encourage you to contact us first so we can try to address the concern.
14. Cookies, local storage and privacy signals
Necessary cookies and storage operate authentication, security, consent and password reset continuity. Qiko does not currently load analytics or marketing technologies in the browser. Optional categories default to off and can be managed through Cookie settings. We honour Global Privacy Control conservatively by keeping marketing off. Do Not Track defaults optional choices to off but can be changed. See our Cookie Policy.
15. Marketing and service communications
We may send B2B communications where permitted by law and will respect applicable opt-out rights. Operational, account, security and legal messages are not marketing and may still be sent while an account or business relationship is active. Qiko does not currently use browser marketing or advertising technologies.
16. Children
The Service is for organisations and their authorised business users. It is not directed to children, and Qiko does not knowingly offer accounts to children. Customers must not configure a digital worker to collect children's personal data unless they have confirmed a lawful basis and appropriate safeguards with Qiko.
17. Changes to this policy
We may update this policy as our Service, providers or legal obligations change. We will post the updated policy with a revised effective date and provide additional notice where required.
18. Contact
Email privacy questions and requests to support@qiko.ai, or write to Qiko AI Labs FZCO, IFZA Business Park, DDP, PO Box 342001, Dubai, United Arab Emirates.