Incorpify

Privacy Policy

1. Introduction

This Privacy Policy explains how Incorpify AI Holdings Ltd, a company incorporated in the Abu Dhabi Global Market (ADGM), with its registered office at DD-15-134-004 -007, Level 15, WeWork Hub71, Al Khatem Tower, Abu Dhabi Global Market Square, 46617, Abu Dhabi, Al Maryah Island, United Arab Emirates (“Incorpify”, “we”, “us”, or “our”), collects, uses, discloses, and retains personal data.

Incorpify is the data controller of the personal data collected via:

  • The platform available at www.incorpify.ai,
  • Our web and mobile applications,
  • Integrated chat systems and AI agents,
  • Third-party integrations initiated by the user.

This Privacy Policy applies to:

  • All users who access or register an account on the Platform;
  • All customers who use our business services;
  • Any individual whose personal data is processed in the course of providing such services.

We are committed to protecting your data in compliance with the ADGM Data Protection Regulations 2021, GDPR (where applicable), and other relevant data protection laws including UAE and KSA obligations.


For privacy-related inquiries, you may contact us at:


Privacy Contact Email: privacy@incorpify.ai
Main Contact Email: support@incorpify.ai

2. What Does This Privacy Policy Cover?

This Privacy Policy governs how Incorpify collects, processes, stores, and shares personal data when you:
  • Create an account or access the Incorpify platform;
  • Interact with our AI chat agents or submit queries;
  • Use any service including company formation, tax filing, licensing, trademark registration, payroll setup, or visa applications;
  • Upload documents or complete compliance tasks;
  • Receive communications, notifications, or partner offers;
  • Access the website, mobile application, or embedded tools;
  • Interact with us via support, referrals, or marketing programs.

It also applies to:

  • AI-generated recommendations and data analysis derived from your inputs;
  • Partner-integrated services (e.g., banks, insurance, accountants) used through the Platform;
  • Analytical tools (e.g., Google Analytics, Hotjar) used to enhance performance and security.

This Privacy Policy does not cover the practices of third-party platforms you may be redirected to (e.g., government portals, banking websites), which are governed by their own privacy policies.

3. Categories of Personal Data Collected

Incorpify collects the following categories of personal data, either directly from you or through automated tools, in the course of using the Platform:

3.1 Identity and Contact Information

  • Full name, nationality, date of birth
  • Email address, phone number, business address
  • Identification documents (e.g., passport, Emirates ID, KSA ID)

3.2 Company and Regulatory Data

  • Business trade name, license number, legal form
  • Company registration documents and ownership data
  • Tax registration details and filing status
  • KYC/AML documents and UBO declarations

3.3 Usage and Interaction Data

  • Platform activity logs and feature usage
  • Chatbot interactions and prompt history
  • Selected service packages and workflows triggered
  • Device ID, IP address, location (approximate)

3.4 Uploaded and Generated Documents

  • Files uploaded by the user (PDF, ID scans, etc.)
  • Documents generated through the platform (MOAs, invoices, tax filings)
  • Internally created reports and checklists linked to your account

3.5 Payment and Transaction Data

  • Payment method (masked card info, IBAN)
  • Transaction history, invoice records, and timestamps
  • No credit card details are stored by Incorpify directly (handled via secure third-party processors)

3.6 Analytics and Tracking Data

Collected via tools such as Google Analytics and Hotjar, including:

  • Session behavior, clickstreams, bounce rates
  • Device type, browser version, operating system
  • Cookie identifiers (subject to our Cookie Policy)

4. Purpose of Processing

Incorpify processes your personal data for the following purposes:

4.1 Contractual Purposes

To deliver the services you request and manage your account, including:

  • Registering and maintaining your user profile;
  • Verifying your identity and performing KYC/AML checks;
  • Preparing, submitting, and renewing company licenses, tax registrations, trademarks, visas, and other filings;
  • Generating invoices, reports, and business documentation;
  • Providing customer support, document reviews, and compliance assistance.

4.2 Legal and Regulatory Compliance

To comply with applicable laws and regulations in the UAE, KSA, ADGM, and other jurisdictions, including:

  • Tax law, company law, and commercial licensing obligations;
  • Anti-money laundering (AML) and counter-terrorist financing (CTF) frameworks;
  • Data retention obligations (e.g., 10-year document storage).

4.3 Legitimate Interest Purposes

To protect our operations and improve your experience:

  • Service improvement and feature development;
  • Internal analytics and AI training (with safeguards);
  • Fraud detection, abuse prevention, and security monitoring;
  • Handling claims, disputes, or legal proceedings.

All such processing is performed with due consideration for your rights and does not override your fundamental freedoms.

4.4 Marketing and Partner Communications

  • Sending platform updates, service announcements, and referral offers;
  • Sending newsletters or product updates (only if opted-in);
  • Sharing your data (limited to name, company, email) with verified business partners (e.g., insurers, banks, legal firms) only if you use or opt into those services.

You may opt out of marketing at any time using dashboard preferences or unsubscribe link in emails.

6. How We Process and Protect Personal Data

6.1 Processing Methods

Personal data is processed using:

  • Automated systems (AI agents, workflow triggers, API calls);
  • Manual operations by Incorpify staff for regulatory tasks, compliance checks, and document verification.

All access and actions are logged and role-restricted.

6.2 Infrastructure and Hosting

All data processing is hosted on Microsoft Azure, ensuring:

  • Compliance with ISO/IEC 27001, SOC 2, and GDPR standards;
  • Redundant storage and disaster recovery within secure, audited data centers;
  • Geo-specific routing when mandated by UAE/KSA law.

6.3 Data Security Measures

Incorpify applies strong encryption and access control protocols:

  • AES-256 encryption for data at rest;
  • TLS 1.2+ encryption for all data in transit;
  • Two-factor authentication (2FA) for all internal accounts;
  • Device and IP-based access control;
  • Continuous security audits and intrusion detection monitoring.

Files uploaded to the platform (e.g., IDs, licenses) are scanned in isolated environments to prevent malware and unauthorized code execution.

6.4 AI Usage and Safeguards

AI systems analyze user inputs to generate insights, complete workflows, and automate compliance checks. To protect user data:

  • AI prompt logs are anonymized and stored securely;
  • No personal data is shared with public AI models or third-party LLMs;
  • All AI usage is monitored, and potentially abusive prompts are flagged or blocked;
  • High-risk queries are either escalated to human review or restricted.

7. Data Sharing and Transfers

7.1 Who May Access Your Data

Incorpify shares your personal data only when strictly necessary to fulfill service delivery or comply with legal obligations. This includes:

  • Internal staff involved in incorporation, compliance, and customer support;
  • Verified service partners such as:
    • Government portals (e.g., DED, MoE, GAZT, FTA)
    • Banks and financial institutions
    • Insurance providers, accountants, and legal advisors
  • Infrastructure and technology providers, such as Microsoft Azure (AI and hosting), cloud storage, and analytics platforms.

All partners and processors are contractually bound to maintain confidentiality, comply with applicable data protection laws, and only process data on Incorpify’s instructions.

7.2 Cross-Border Transfers

Some personal data may be transferred outside the UAE or KSA to countries offering an adequate level of protection, including:

  • The European Economic Area (EEA)
  • The United Kingdom
  • Other jurisdictions where Microsoft Azure or service partners operate

If transfers occur to countries without an adequacy decision, Incorpify ensures that:

  • Standard Contractual Clauses (SCCs) or similar safeguards are in place;
  • Transfer is necessary for performance of a contract or legal compliance;
  • Additional technical measures (e.g., encryption, pseudonymization) are applied.

7.3 No Sale or Commercial Disclosure

Incorpify does not sell, rent, or commercially disclose your personal data to third parties for marketing purposes.


Data shared with service partners (e.g., an insurance broker or payroll provider) is limited to what’s required to deliver the selected service and is subject to your consent or active usage.

8. Data Retention

Incorpify retains personal data only as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

8.1 Regulatory and Contractual Retention

We retain the following categories of data for 10 years, in line with UAE and KSA legal obligations:

  • Company incorporation records and trade licenses;
  • Tax filings and compliance documents;
  • Visa, payroll, and regulatory filings;
  • Invoices and financial transaction records.

This applies even after account closure, service termination, or user deletion requests, unless overridden by a competent authority.

8.2 Operational and Technical Data

We retain non-regulatory data for shorter durations:

  • Chatbot logs and prompt history: 12 months (anonymized if used for AI training)
  • Session and analytics data (e.g., Google, Hotjar): 12–24 months, per tool policy
  • Support interactions and email logs: 24 months
  • Deleted account metadata (timestamp, action): 12 months

8.3 Data Deletion and Restriction

Upon user request and subject to legal constraints, we may:

  • Delete or anonymize personal data not required by law;
  • Restrict processing of inactive accounts or disputed records;
  • Archive data for litigation hold if under regulatory investigation.

Requests can be submitted via your dashboard or by emailing privacy@incorpify.ai.

9. User Rights

As a data subject, you have the following rights under applicable data protection laws, including the ADGM Data Protection Regulations, and where applicable, GDPR or local UAE/KSA laws:

9.1 Right to Access

You have the right to request a copy of the personal data we hold about you, along with information on how and why it is processed.

9.2 Right to Rectification

You may request the correction of inaccurate or incomplete personal data at any time.

9.3 Right to Erasure (Right to Be Forgotten)

You may request deletion of your personal data if:

  • It is no longer necessary for the purpose it was collected;
  • You withdraw consent (where applicable);
  • Processing was unlawful.

Note: We may retain data required under law (e.g., licensing, tax, compliance) even after such requests.

9.4 Right to Restriction of Processing

You may request the restriction of processing where:

  • You contest the accuracy of data;
  • Processing is unlawful but deletion is not desired;
  • You need the data to establish, exercise, or defend legal claims.

9.5 Right to Object

You can object to:

  • Processing based on legitimate interest;
  • Receiving marketing or promotional content (unsubscribe available in all communications).

9.6 Right to Data Portability

If processing is based on consent or contract and carried out by automated means, you may request to receive your data in a structured, machine-readable format and transmit it to another controller.

9.7 Right to Withdraw Consent

Where processing is based on your consent (e.g., marketing, third-party sharing), you may withdraw it at any time without affecting the lawfulness of prior processing.

9.8 Right to Lodge a Complaint

You may lodge a complaint with the competent authority:

  • ADGM Commissioner of Data Protection

Requests must be submitted via your Incorpify account dashboard or by emailing privacy@incorpify.ai.

10. Children’s Data

The Incorpify Platform is intended exclusively for users who are 18 years of age or older.


We do not knowingly collect, process, or store personal data relating to individuals under the age of 18. If we become aware that data has been submitted by a minor without verified parental or legal guardian consent, we will:

  • Immediately delete the data from all systems;
  • Disable any associated account;
  • Notify any relevant supervisory authority if required by law.

If you believe that a child under 18 has provided us with personal data, please contact privacy@incorpify.ai immediately.

11. Updates and Notifications

Incorpify reserves the right to update this Privacy Policy at any time in response to:

  • Changes in legal or regulatory requirements;
  • Modifications to our platform, services, or AI architecture;
  • Security or data handling improvements.

11.1 Notification of Changes

Material changes to this Policy will be:

  • Announced via email to registered users;
  • Communicated through dashboard notifications;
  • Published on the Incorpify website with a revised “Last Updated” date.

We encourage users to review this Policy periodically. Continued use of the Platform after a Policy update constitutes acceptance of the revised terms.