Effective 24 September 2026
Who we are
The controller of your personal data is IB Digital Solutions LLC, licensed by Sharjah Media City (SHAMS), licence no. 2542792.01, Shams Business Center, Sharjah Media City Free Zone, Al Messaned, Sharjah, United Arab Emirates. We’re called “IB Digital” or “we” below.
For anything in this policy, write to hello@ib.digital. We haven’t appointed a data protection officer: the law doesn’t require one for the processing we do.
What this policy covers
This website (ib.digital and its subdomains), the AI Readiness Check, booking a call with us, email with us, the work we do for clients and how we invoice it, and the business outreach we do to companies that might need our services.
What we collect and why
Each row is one activity. “Legal basis” names the GDPR / UK GDPR basis first, then the UAE Personal Data Protection Law (PDPL) basis.
| Activity | Data | Why | Legal basis | Kept for |
|---|---|---|---|---|
| Analytics (only if you accept) | Pages you view, clicks, referrer and campaign tags, device and browser, approximate location from your IP, a random identifier. If you later book a call, that browsing is linked to your email. | See which pages help, where people drop off, and which channels lead to conversations. | Consent (GDPR 6(1)(a); PDPL consent). | Up to 12 months, then deleted. |
| Visitor statistics (only if you accept) | Page address (only campaign tags kept from the query string), referrer, device type, country. No cookies. | Count visits and top pages. | Consent. | Aggregated reports, for the retention window of our Vercel plan. |
| Running the site and blocking abuse | IP address, request details, browser. Rate limits use a keyed hash of your IP, never the address itself. | Deliver pages securely and stop the scanner from being used to hammer other sites. | Legitimate interests in a secure service (GDPR 6(1)(f)); providing the service you requested (PDPL). | Hosting logs per Vercel's short platform window; rate-limit counters 1 to 24 hours. |
| AI Readiness Check | The website address you scan and its result. Your email only if you ask for the report. | Run the check, keep your score link working, email the report after you confirm the address. | Your request (GDPR 6(1)(b); PDPL: steps at your request). | Scan results 90 days. Your email isn't stored, except a one-time “report sent” marker for 90 days. |
| Updates from us (only if you tick the box) | Email, the domain you scanned, when and with which wording you opted in. | Send the occasional AI-readiness update. | Consent. | Until you unsubscribe. |
| Booking a call | Name, email, company, your answers to the booking questions, meeting time. | Schedule and prepare the call, and keep track of the conversation in our CRM. | Steps at your request before a contract (GDPR 6(1)(b); PDPL). | For the relationship, then up to 3 years after our last contact. |
| Measuring which channels lead to work | A one-way hash of your email (no name, no address) with the fact that a booking or deal stage happened, and your company name if you gave it. | Know which pages and channels bring real conversations. | Legitimate interests (GDPR 6(1)(f)). You can object any time and we stop. | Up to 12 months. |
| Email and correspondence | What you send us and our replies. | Answer you and run the work. | Your request or our contract; legitimate interests in keeping business records. | For the relationship, then up to 3 years after our last contact. |
| Proposals | The proposal we write for you. How often the proposal link was opened and when (not tied to a person). | Send you a proposal and know whether it arrived. | Steps at your request before a contract. | For the relationship, then up to 3 years after our last contact. |
| Clients and payments | Billing name, company, address, email, invoices, payment status. Card details go to Stripe and never reach us. | Invoice, get paid, keep accounts. | Contract; legal obligation (GDPR 6(1)(c); PDPL: required by UAE law). | As long as UAE accounting and tax law requires (currently up to 7 years). |
| Business outreach | Name, role, company, public profile address, business contact details, notes from our conversations. Source: public professional profiles, mostly LinkedIn. | Offer our services to businesses that may need them. | Legitimate interests (GDPR 6(1)(f)); information you made public in your professional profile (PDPL). Object any time and we stop. | 12 months after our last contact if we don't start working together. |
Your email is required to receive the AI Readiness report, because that’s where we send it. Everything else is optional. You can use the whole site with analytics off.
Who processes it for us
These companies process personal data on our instructions, under data processing terms with each of them. We don’t sell your data or share it for advertising.
| Company | What for | Where |
|---|---|---|
| PostHog | Analytics (only with consent) | United States |
| Vercel | Hosting, visitor statistics | United States, global edge network |
| Resend | Sending the AI Readiness emails and updates | United States |
| Upstash | Storing AI Readiness scans and rate limits | United States |
| Cal.com (its privacy policy) | Booking calls | United States |
| Sanity | Our content system (blog, proposals) | European Union (Belgium); some account data in the United States |
| Google Workspace | United States, global | |
| Stripe (its privacy policy) | Card payments and invoices | United States; Ireland (Stripe Payments Europe); other countries where Stripe operates |
| Our bank | Bank transfers | United Arab Emirates |
International transfers
We’re based in the UAE, and most of the companies above process data in the United States. Each transfer is covered by that company’s data processing terms, which include the EU Standard Contractual Clauses and the UK Addendum where they apply, and the EU-U.S. Data Privacy Framework where the company is certified. Under the UAE PDPL the transfers rest on those contractual protections (Art. 23(1)(a)) and, for bookings, reports and invoices, on being necessary for what you asked us to do (Art. 23(1)(d)).
Your rights
You can ask us to:
- tell you what we hold about you and give you a copy;
- correct it;
- delete it;
- restrict how we use it;
- send it to you or another company in a portable format;
- stop using it for marketing (always honored) or on the basis of legitimate interests;
- withdraw a consent you gave. This doesn’t undo what we did before.
Write to hello@ib.digital. We reply within one month and may ask you to confirm who you are first. Unsubscribe links in our emails and “Cookie settings” in the footer work instantly without writing to us.
If you think we’ve handled your data wrongly, tell us first and we’ll fix it. You also have the right to raise it with a data protection authority: the UAE Data Office, or in the EU or UK the authority where you live.
Automated decisions
The AI Readiness Check scores websites, not people. We make no decisions about you by automated means that have legal or similarly significant effects.
Security and breaches
Everything travels over HTTPS. Access is limited to the people who need it for the work. We choose processors with published security programmes, and we store keyed hashes instead of raw identifiers where a raw value isn’t needed. If a breach puts your privacy at risk, we notify the relevant authority and you, as the law requires.
Children
This site and our services are for businesses. They aren’t meant for anyone under 18, and we don’t knowingly collect their data.
Changes to this policy
When something changes, we update this page and the date at the top. If the change affects what the analytics banner covers, the banner asks you again. Our service terms are on the terms page.