Privacy Policy

(Personal Data Processing Policy) of the Lansy Software

Controller and Applicable Law
1.1 COLLABO TECH LTD is the data controller for personal data collected from Site visitors.

We are registered in the DIFC and process personal data in accordance with the DIFC Data

Protection Law 2020 (DIFC DPL 2020) and, where applicable, the EU GDPR in respect of

personal data of individuals located in the EEA.

1.2 For GDPR purposes, we do not have a formal EU establishment. Where we offer services

to individuals in the EEA, we rely on adequacy frameworks or appropriate safeguards between

the DIFC and relevant jurisdictions. Individuals in the EEA may exercise their rights as set out

in Section 6.

  1. Personal Data We Collect from Site Visitors
    2.1 Data you provide voluntarily (via enquiry or contact form): first name, last name; company

    name and role; business email address; phone number; any other information you choose to

    include in free-text fields.

    2.2 Data collected automatically when you visit the Site: IP address and approximate

    geographic location (country/city level); device type, browser type and version, operating

    system; pages visited, time spent, click paths, referral source; cookies and similar tracking

    technologies (see Section 4).

    2.3 We do not collect special categories of personal data from Site visitors (e.g. health data,

    biometric data, racial or ethnic origin).

  2. Purposes and Legal Bases for Processing
    – Respond to enquiries and demo requests — legitimate interests / pre-contractual steps

    – Provide and improve the Site — legitimate interests

    – Analytics and performance measurement — legitimate interests (with cookie consent

    where required)

    – Send marketing communications — consent (where required by applicable law)

    – Comply with legal obligations — legal obligation

  3. Cookies
    4.1 We use cookies and similar technologies on the Site. A separate Cookie Policy is available

    at https://lansy.ai/legal/cookies and forms part of this Privacy Policy.

    4.2 We use: (a) strictly necessary cookies required for Site operation; (b) analytics cookies to

    understand how visitors use the Site; and (c) marketing cookies where consent is given. You

    may manage preferences via the cookie banner or your browser settings.

  4. Data Sharing and International Transfers
    5.1 We do not sell your personal data. We may share personal data with: service providers

    and sub-processors (hosting, email, analytics) under appropriate data processing

    agreements; professional advisers under confidentiality obligations; regulatory authorities or

    law enforcement where required by law.

    5.2 Where we transfer personal data internationally, we rely on adequacy decisions, standard

    contractual clauses, or other appropriate safeguards under the DIFC DPL 2020 and, where

    applicable, the GDPR.

  5. Your Rights
    Depending on the applicable law (DIFC DPL 2020 and/or GDPR), you may have the right to:

    access your personal data; rectify inaccurate or incomplete data; erasure (“right to be

    forgotten”); restriction of processing; data portability; object to processing based on legitimate

    interests; withdraw consent at any time; lodge a complaint with the DIFC Commissioner of

    Data Protection (difc.ae) or your local data protection authority (EEA).

    To exercise your rights, contact us at privacy@lansy.ai. We will respond within thirty (30) days.

  6. Retention
    7.1 We retain personal data collected from Site visitors for no longer than five (5) years from

    the date of collection, or such shorter period as required by applicable law. When data is no

    longer needed, it is securely deleted or anonymised.

    PART II — PLATFORM CLIENTS (DATA PROCESSING AGREEMENT)

    This Part II constitutes a data processing agreement (“DPA”) between Lansy (acting as Data

    Processor) and the legal entity or individual entrepreneur that has accepted the Terms of Use

    (acting as Data Controller). It applies from the moment the Client begins using the Platform.

    This DPA is designed to comply with the requirements of the DIFC Data Protection Law 2020.

    Where clients are subject to the EU GDPR or the laws of other jurisdictions, the parties agree

    to incorporate any additional requirements by mutual written agreement.

  7. Roles and Scope
    8.1 “Controller” means the Lansy client (legal entity or individual entrepreneur) that

    determines the purposes and means of processing personal data of its employees, customers,

    or other third parties whose data is contained in Audio Recordings uploaded to the Platform.

    8.2 “Processor” means COLLABO TECH LTD (“Lansy”), which processes personal data on

    behalf of and under the instructions of the Controller solely for the purpose of providing the

    Platform.

    8.3 “Data Subjects” means any natural persons whose personal data is contained in Audio

    Recordings or other materials uploaded to the Platform, including the Controller’s employees

    and its customers.

  8. Categories of Personal Data Processed
    – Voice recordings — which may constitute biometric personal data under applicable law

    (including DIFC DPL 2020 Art. 3) to the extent they are used to identify individuals.

    – Names, job titles, and other identifiers that may appear in Audio Recordings.

    – Customer interaction data and any other information contained in Audio Recordings

    uploaded by the Controller.

    The Processor does not actively collect special categories of personal data but acknowledges

    that Audio Recordings may incidentally contain health information, political opinions, or other

    special category data. The Controller is responsible for ensuring appropriate safeguards are in

    place.

  9. Purposes and Instructions
    10.1 The Processor processes personal data only on the documented instructions of the

    Controller and only for the following purposes: transcription of Audio Recordings;

    anonymisation of transcripts prior to AI analysis; AI-powered analysis and scoring of customer

    interactions; generation of analytical reports and dashboards; providing personalised coaching

    feedback to the Controller’s employees.

    10.2 The Processor shall not: (a) use personal data for its own purposes; (b) use personal

    data to train or improve its own AI models; (c) disclose personal data to third parties for

    commercial purposes.

  10. Audio Recording Processing Pipeline
    11.1 Step 1 — Receipt and secure storage: the Audio Recording is stored on encrypted

    servers for the time strictly necessary for transcription, not exceeding seven (7) calendar days.

    11.2 Step 2 — Transcription: the Processor transcribes the Audio Recording into text. No

    external sub-processors are used for transcription.

    11.3 Step 3 — Anonymisation: names, contact details, and other identifying information are

    removed from the transcript before any AI analysis.

    11.4 Step 4 — AI analysis: the anonymised transcript (not the Audio Recording) is submitted

    to the AI analysis engine.

    11.5 Step 5 — Deletion: the original Audio Recording is irreversibly deleted upon completion

    of transcription. No copies are retained.

  11. Obligations of the Processor
    – Process personal data only in accordance with the Controller’s instructions and this

    DPA.

    – Ensure that persons authorised to process personal data are bound by appropriate

    confidentiality obligations.

    – Implement appropriate technical and organisational security measures, including

    AES-256 encryption at rest and in transit; role-based access controls; access logging;

    regular security assessments.

    – Not engage any sub-processor without informing the Controller and obtaining prior

    written consent.

    – Notify the Controller without undue delay (and in any event within seventy-two (72)

    hours) of any personal data breach affecting the Controller’s data.

    – Provide the Controller with reasonable assistance in responding to Data Subject

    requests.

    – Delete or return all personal data upon termination of the engagement, and certify such

    deletion within thirty (30) days.

    – Make available all information reasonably necessary to demonstrate compliance with

    this DPA and support audits upon reasonable notice.

  12. Obligations of the Controller
    – Transmit to the Processor only personal data for which the Controller has a lawful basis

    for processing (including explicit consent for recording and analysis of voice data).

    – Inform Data Subjects about the transmission of their personal data to the Processor

    and the processing described in this DPA.

    – Comply with all applicable data protection laws in the Controller’s jurisdiction(s) as data

    controller.

    – Ensure that audio recording practices comply with local employment and privacy laws.

  13. Sub-processors
    14.1 The Processor shall not engage sub-processors to process personal data without the

    Controller’s prior written authorisation.

    14.2 Where sub-processors are authorised, the Processor shall: (a) conduct due diligence; (b)

    impose data protection obligations no less stringent than those in this DPA; (c) remain fully

    liable to the Controller for sub-processor performance.

  14. International Transfers of Personal Data
    15.1 Where the Processor transfers personal data outside the DIFC, it shall ensure that

    appropriate safeguards are in place in accordance with the DIFC DPL 2020 (Part 5) and,

    where applicable, the GDPR.

    15.2 Processing currently takes place on infrastructure located in UAE . The Processor will

    notify the Controller of any material change to processing locations.

  15. Data Subject Rights
    16.1 Data Subjects exercise their rights through the Controller as the primary responsible

    party.

    16.2 The Processor shall promptly forward any Data Subject request received directly to the

    Controller and assist the Controller in fulfilling those requests.

  16. Liability
    17.1 The Processor shall be liable to the Controller for losses caused by processing in breach

    of this DPA or applicable data protection law, to the extent attributable to the Processor’s fault.

    17.2 The Controller shall indemnify the Processor against claims, losses, and costs arising

    from the Controller’s breach of its obligations under this DPA or applicable law.

    17.3 The limitation of liability in Section 9 of the Terms of Use applies to this DPA, except to the

    extent prohibited by applicable law.

  17. Term
    18.1 This DPA takes effect upon the Client’s acceptance of the Terms of Use and remains in

    force for the duration of the Platform subscription or access period.

    18.2 Upon termination, the Processor shall delete all the Controller’s personal data within

    thirty (30) days, unless longer retention is required by applicable law.

    PART III — GENERAL PROVISIONS

  18. Security
    19.1 Lansy implements and maintains appropriate technical and organisational measures to

    protect personal data against unauthorised access, disclosure, alteration, or destruction,

    including AES-256 encryption, access controls, and regular security testing.

    19.2 Lansy isolates each client’s data. Client data is not accessible to other clients.

  19. Children’s Data
    20.1 The Platform is intended for use by business clients and is not directed at children. Lansy

    does not knowingly process personal data of individuals under the age of 18 through the

    Platform.

  20. Changes to this Policy
    21.1 Lansy may update this Policy from time to time. The updated Policy will be published at

    https://lansy.ai/privacy_policy with a revised effective date. Material changes will be

    communicated to clients by email. Continued use of the Site or Platform constitutes

    acceptance.

    Contact
    Email: privacy@lansy.ai

    Postal: Data Protection Officer, COLLABO TECH LTD, Unit IH-00-01-03-OF-05, Level 3

    IH-00-01CP-05, Dubai International Financial Centre, Dubai, United Arab Emirates

    We aim to respond to all privacy enquiries within thirty (30) days.

    COLLABO TECH LTD · License No. CL12226 · DIFC, Dubai, UAE · https://lansy.ai

    Version dated 08 June 2026