Last updated 5 September 2026. This policy is provided for information. Where you hold a signed licence agreement, order form or data processing addendum with BizfyLabs FZC LLC, that executed document governs and prevails over this page. Nothing here is legal advice; please take your own advice on how these terms apply to you.
1.Who we are and what this policy covers
DocxIntel is an on-premise document intelligence platform and a product of BizfyLabs FZC LLC, a company registered in the United Arab Emirates and operating from Dubai. Where this policy says "we", "us" or "our", it means BizfyLabs FZC LLC. For the personal data described in this policy, BizfyLabs FZC LLC is the controller.
This policy explains what personal data we collect when you visit this website, contact us, evaluate the product or raise a support request under a licence agreement. It also explains the lawful bases we rely on, how long we keep the data and the rights you can exercise.
This policy does not describe the contents of the documents you process inside your own deployment. That distinction is the single most important thing to understand about how DocxIntel handles data, and it is set out in the next clause.
- In scope: enquiries and contact form submissions, sales and pre-sales correspondence, Proof of Value engagement records, support tickets, marketing preferences and website technical logs.
- In scope: the limited personal data we are given where a customer purchases managed single-tenant hosting or a support service that requires access to their environment.
- Out of scope: the document content, extracted fields and end-user records held inside a self-hosted DocxIntel deployment, which remain under the customer's sole control.
- Out of scope: the privacy practices of third-party websites, marketplaces or partner sites that link to this one.
2.The architectural point: we never receive your document content
DocxIntel is licensed software that is installed and runs inside the customer's own infrastructure. The models needed to analyse, identify, classify, map, modify and answer questions about documents ship inside the deployment bundle and load from local storage. There is no call to an external inference API, no phone-home telemetry channel and no cloud fallback path.
The practical consequence is legal, not just technical. In a self-hosted deployment the customer is the controller of the personal data contained in its documents, and BizfyLabs FZC LLC is normally not a processor of that data at all — because we never receive it. We cannot read, copy, retain, transmit or be compelled to produce document content that has never left the customer's network.
- Documents are read from storage the customer already controls and results are written back to storage the customer already controls.
- Model weights, encryption keys and audit logs sit inside the customer's environment and are administered by the customer's own staff.
- An air-gapped installation performs the same processing as a connected one, so there is no degraded mode that depends on reaching us.
- We hold no copy of processed documents, no shadow index and no derived dataset built from customer content.
There are narrow, deliberate exceptions where a processor relationship does arise: where a customer buys managed single-tenant hosting and asks us to operate the environment on its behalf; where a customer chooses to send us a sample document, diagnostic bundle or log extract to investigate a support issue; and where we handle contact and correspondence data for the website and sales relationship. Those cases are described in the data processing addendum and, where the customer requires it, in a signed addendum.
3.Personal data we collect
We collect a deliberately small amount of personal data, and almost all of it is data you give us directly when you get in touch.
- Enquiry and contact data
- Name, business email address, employer, job title, country and the content of the message you send us through the contact page or in reply to us.
- Sales and engagement correspondence
- Emails, meeting notes, questionnaire and security-review responses, and the commercial records created while scoping a deployment or a Proof of Value engagement.
- Support and service data
- Ticket contents, environment and version details, and any log excerpt, configuration file or sample document a customer chooses to attach to a support request. We ask customers to redact or synthesise personal data before sending samples.
- Contract and billing data
- Signatory and authorised-contact details, order form and purchase order references, invoicing contacts and payment records held for accounting purposes.
- Website technical data
- IP address, approximate location derived from it, browser and device type, referring page, pages viewed and timestamps, collected in server and security logs and in aggregate analytics.
- Marketing preferences
- Whether you have asked to receive product or release updates, and the record of that consent or of its withdrawal.
We do not ask for and do not want special categories of personal data, government identity documents or payment card numbers through this website. Please do not include them in an enquiry.
4.Lawful bases for processing
Where the UAE Personal Data Protection Law applies we process personal data on the bases permitted by that law. Where the EU or UK General Data Protection Regulation applies — for example because you contact us from the European Economic Area or the United Kingdom — we rely on the bases in Article 6 GDPR. In practice the bases are the same handful.
- Performance of a contract, or steps before entering one
- Responding to an enquiry, quoting, scoping and running a Proof of Value, delivering a deployment bundle, providing support and invoicing under a licence agreement.
- Legitimate interests
- Operating and securing this website, keeping records of business correspondence, understanding in aggregate which pages are useful, and sending relevant business-to-business product information where that is permitted. We balance those interests against your rights and stop where the balance does not hold.
- Consent
- Non-essential cookies and analytics where consent is required, and marketing email to individual subscribers. Consent can be withdrawn at any time without affecting processing that has already taken place.
- Compliance with a legal obligation
- Retaining accounting and tax records, responding to lawful requests from a competent authority, and meeting export control and sanctions screening requirements.
5.How we use personal data
- To answer your enquiry and to have the follow-up conversation you asked for.
- To scope a deployment: to size infrastructure, agree an accuracy threshold and prepare a Proof of Value statement of work.
- To deliver licensed software, release notes, model updates and the notice and licence manifests that ship with a release.
- To provide support and to reproduce, diagnose and fix defects reported by a customer.
- To administer the commercial relationship, including order forms, renewals, invoicing and collection.
- To keep this website available and secure, to detect abuse and to investigate suspected security incidents.
- To measure in aggregate how the website is used so that we can improve it.
- To send product and release information to people who have asked for it, with an unsubscribe link in every message.
- To meet legal, regulatory, export control and sanctions obligations, and to establish, exercise or defend legal claims.
We do not sell personal data. We do not use enquiry, support or correspondence data to train or fine-tune models, and we do not build advertising profiles from website activity.
6.Cookies and analytics
This website uses a small number of cookies and similar technologies: those strictly necessary to serve the site, those that remember a preference you have set, and those that provide aggregate analytics about page usage. Non-essential categories are used only where you have agreed to them, and you can change that decision at any time in your browser.
A DocxIntel deployment running inside a customer's environment is a different matter entirely. It does not set marketing or advertising cookies on the customer's end users, and it does not report usage back to us. Any cookie set by a deployed instance exists to hold a session for an authenticated internal user, under the customer's own configuration.
The categories, purposes, approximate lifetimes and browser controls are described in the DocxIntel cookie policy at docxintel.com/cookies, which forms part of this privacy policy.
7.Sharing and sub-processors
We keep the number of third parties that touch personal data as small as the business allows. We share personal data only with the categories of recipient below, only for the purposes described, and only under a written contract that requires confidentiality and appropriate security.
- Infrastructure and content delivery providers that host this website and its logs.
- Business email, calendar and document collaboration providers used to correspond with you.
- A customer relationship management and marketing platform used to record enquiries and manage subscription preferences.
- Aggregate website analytics used to understand page performance.
- Ticketing and code-issue tracking used to record and resolve support requests.
- Accounting, banking, audit, insurance and legal advisers, where necessary for the commercial relationship or for advice.
- A competent authority, court or regulator where disclosure is legally required, and an acquirer or successor in the event of a corporate transaction.
Because customer document content never reaches BizfyLabs FZC LLC in a self-hosted deployment, none of these providers has access to it. The current list of sub-processors used for the limited managed and support services we do offer is available to customers on request through the contact page at https://bizfylabs.com/contact-us.
8.International transfers
We are based in the United Arab Emirates and some of the service providers above process data in other countries. Where personal data is transferred out of the UAE we apply the cross-border transfer conditions of the UAE Personal Data Protection Law and its implementing decisions, which permit transfer to jurisdictions with an adequate level of protection or subject to appropriate contractual safeguards.
Where the GDPR applies to a transfer out of the European Economic Area or the United Kingdom, we rely on an adequacy decision where one exists and otherwise on standard contractual clauses together with a transfer risk assessment, plus supplementary technical and organisational measures where the assessment calls for them.
For customers whose regulator requires data to remain inside a specific jurisdiction, the relevant point is that a self-hosted or air-gapped deployment involves no transfer of document content at all: the data stays on infrastructure the customer chooses, in the country the customer chooses.
9.How long we keep personal data
We keep personal data only for as long as we need it for the purpose it was collected for, and then delete it or reduce it to aggregate form.
- Enquiries that do not lead to a commercial relationship are kept for the duration of the conversation and a reasonable period afterwards, so we can pick up a follow-up question, and then deleted.
- Sales and engagement records are kept for the life of the relationship and for the limitation period that applies to claims under the agreement.
- Support tickets are kept for the licence term and a reasonable period afterwards so that recurring defects can be traced across releases.
- Any sample document or diagnostic bundle sent to us for support is deleted once the ticket is closed, and sooner on request.
- Contract, invoicing and accounting records are kept for the period required by applicable UAE tax and company law.
- Marketing preferences, including the record of an unsubscribe, are kept for as long as needed to honour the preference.
- Website server, security and analytics logs are kept for a short operational window and then deleted or aggregated.
10.Security
We apply technical and organisational measures appropriate to the limited personal data we hold: encryption in transit, encryption at rest for stored records, access control on a need-to-know basis with multi-factor authentication, logging of administrative access, hardened endpoints, background-checked personnel bound by confidentiality obligations, and a documented process for handling suspected incidents.
We do not claim to hold a SOC 2 attestation or an ISO/IEC 27001 certificate, and we will not imply one in a sales conversation. What we do provide is an architecture designed so that the controls a regulated customer already operates — network segregation, key management, identity, logging, retention — apply to DocxIntel without exception, because the software runs inside that customer's own control environment.
No system is perfectly secure. If we become aware of a personal data breach affecting data we control, we will assess it, notify the competent authority and affected individuals where the applicable law requires it, and tell affected customers without undue delay.
11.Your rights and how to exercise them
Depending on the law that applies to you, you have some or all of the following rights in relation to personal data we hold about you. Under the UAE Personal Data Protection Law and under the GDPR these rights overlap substantially.
- Access: to be told whether we hold personal data about you and to receive a copy of it.
- Rectification: to have inaccurate or incomplete data corrected.
- Erasure: to have data deleted where we no longer have a valid reason to keep it.
- Restriction: to ask us to pause processing while a dispute about accuracy or lawfulness is resolved.
- Objection: to object to processing based on legitimate interests, including direct marketing, which we will stop on request.
- Portability: to receive data you gave us in a structured, commonly used, machine-readable format, or to have it transmitted to another controller.
- Withdrawal of consent: to withdraw consent at any time where consent is the basis we rely on.
- Automated decisions: not to be subject to a decision based solely on automated processing that has a legal effect on you. We do not make such decisions about you.
- Complaint: to complain to the UAE Data Office or, where the GDPR applies, to your national supervisory authority.
To exercise a right, contact us through the contact page at https://bizfylabs.com/contact-us and tell us which right you are exercising. We may need to verify your identity before we act, and we will respond within the period set by the applicable law — one month under the GDPR, extendable where a request is complex. Exercising these rights is free unless a request is manifestly unfounded or excessive.
One important routing note: if your personal data appears inside documents processed by an organisation that has licensed DocxIntel, that organisation is the controller of that data and we are not. We have no access to it and cannot search it. Please direct your request to that organisation, which will handle it under its own privacy notice.
12.Children's data
DocxIntel is enterprise software sold to organisations. This website is not directed at children, we do not knowingly collect personal data from anyone under 18 through it, and we have no features intended for children.
If you believe a child has provided us with personal data, contact us at https://bizfylabs.com/contact-us and we will delete it.
13.Changes to this policy
We update this policy when our practices, our service providers or the applicable law change. The date at the top of the page always reflects the current version, and material changes will be flagged on this page.
Where a change materially affects how we process personal data under an existing agreement, we will tell affected customers through the notice mechanism in that agreement rather than relying on a silent website update.
14.How to contact us
BizfyLabs FZC LLC is the controller for the personal data described in this policy. All privacy enquiries, data subject requests and complaints should be submitted through the contact page at https://bizfylabs.com/contact-us, which routes to the team responsible for privacy matters.
Please use that route rather than an individual employee's address, so that your request is logged and answered inside the response period the law allows. If you are an existing customer, you may also raise the request through your named commercial contact or your support channel.