Skip to content
counterscope

Privacy and Data Protection Policy

Version 1.0 · In effect from 20 August 2026

In short

We hold two very different kinds of personal data: data about you as a user of Counterscope, and data about people named in the public UAE records we index — most of whom are not our users. This policy explains both, states plainly where in the world that data is processed, and tells you how to see, correct, or object to it.

This summary is for orientation only. The numbered clauses below are what govern.

1. Who is responsible for your data

Counterscope Technologies FZ-LLC (in formation) is the controller of the personal data described in this policy. As explained in clause 1 of our Terms of Service, the company is in the process of being established in the United Arab Emirates; until its registration is complete the controller is the founding undertaking operating under the name "Counterscope", and on registration that role transfers to the company.

You can reach us about anything in this policy at privacy@counterscope.ae.

2. What this policy covers

This policy applies to the Counterscope website, the Counterscope platform, and our processing of the public records that make up the Counterscope database. It applies alongside our Terms of Service and our Cookie and Tracking Notice.

3. Data we hold about you, as a user

If you hold an account with us, we process:

  • Account data — your name, work email address, organisation, role and permissions within your workspace, preferred language, and the invitation that created your account. Passwords are handled by our authentication provider and stored only as salted hashes; we never see them.
  • Usage data — the searches you run (including the text of the query, the filters applied, and the number of results), the company profiles you open, the evidence you reveal, your watchlists and saved searches, your exports, and when you were last active.
  • Visitor data — when a page is viewed we record the page as a route pattern rather than a full address (for example /entity/:id, so the record never says which company was looked at), the language it was viewed in, a coarse country supplied by our content delivery network, a device class (mobile, tablet, or desktop), and the time. We do not store your IP address in any form, including hashed. If you are signed in, the page view is linked to your account.
  • Consent-gated visitor fields — if, and only if, you allow analytics, that same record also carries a first-party visitor identifier (a cookie named cs_vid), a session identifier, the host name of the site that referred you (the host only, never the full referring address), and any campaign tags in the link you followed. If you allow analytics and then create an account, we keep the visitor identifier from that signup on the account record so we can tell which visit led to it. If you do not allow analytics, every one of these fields is left empty and what remains cannot single you out.
  • Communications — emails we send you (such as alerts and digests), whether they were delivered, and your contact preferences, together with any message you send us.
  • Technical data — request logs and error diagnostics used to keep the Service running and secure. Your IP address is read transiently to apply rate limits and block abuse, held only in memory for the length of the rate-limit window, and then discarded — it is not written to our database.

4. Data we hold about people named in public records

Most of the data in Counterscope concerns companies. But records published by courts, regulators, and registries also name individuals, and we hold that information too. We want to be direct about this rather than describe it as something other than what it is.

Specifically, we hold:

  • Party records — the names of individuals and companies as they appear as parties in court cases, judgments, regulatory notices, inspections, and similar records, along with the role and side each party took, and the record the name came from. We currently hold in the order of 216,000 such party records.
  • Person records — where a source identifies an individual associated with a company, we may hold their name in Arabic and English, their stated nationality, and, where a source provided an Emirates ID number, a one-way cryptographic hash of it. We store the hash so that records about the same person can be matched; we do not store the identity number itself, and the hash cannot be reversed back into it.
  • Company records — names and aliases, licence numbers and status, jurisdiction and free zone, activities, addresses, and the legal events linked to each company.

5. Data relating to judicial matters

Some of what we hold relates to litigation, judgments, enforcement, insolvency, penalties, and regulatory action. Under the PDPL, data of this kind is treated as sensitive personal data and attracts additional protection. We process it only because it has already been lawfully published by the authority that produced it, only to the extent needed for the Service, and subject to the safeguards in this policy — including the correction and objection routes in clause 12 and the dedicated process in our Data Accuracy, Corrections and Right of Reply Policy.

We do not publish risk bands or scores about any named company on our public pages. Public pages carry registry facts that are already public; our assessment is shown only to authenticated users.

6. Why we process it

We process account and usage data to provide and secure the Service, to authenticate you, to operate your workspace and its quotas, to send you the alerts and messages you ask for, to understand and improve how the Service is used, and to comply with our legal obligations.

We process public-record data to deliver the core function of the Service: to make already-public information about UAE companies findable, linked to the right company, and understandable, so that businesses can assess counterparty risk before entering into dealings.

8. Automated processing, scoring, and AI

Two parts of the Service are automated and you should know about both.

First, facts are extracted from source documents by large language models operated by third-party providers, reached through an AI gateway. This means the text of source documents — which can contain personal data — is transmitted to those providers for processing. They act as processors on our instructions and are contractually restricted from using the content to train their models. This is a transfer outside the UAE; see clause 10.

Second, the risk band and score are produced automatically from the linked records. They are an opinion, not a decision about anyone. We do not use them to take decisions that produce legal effects concerning an individual, and our Terms of Service prohibit our users from doing so either. If an automated assessment concerns you, you may ask for it to be reviewed by a person, and you may object to it.

9. Who else processes the data

We use a small number of service providers who process data on our behalf, under contracts that limit them to our instructions. We do not sell personal data, and we do not share it for anyone else’s advertising.

They are, by function:

  • Database and authentication — Supabase, running on Amazon Web Services infrastructure in the Mumbai region (ap-south-1), India.
  • Application hosting, content delivery, document storage, and bot protection — Cloudflare, operating a global network.
  • Data-collection and processing servers — dedicated servers located in Germany, and a server located in the United Arab Emirates used only for sources that must be accessed from within the UAE.
  • Document fact-extraction — OpenAI and Anthropic language models, accessed through the Vercel AI Gateway, processed in the United States.
  • Product analytics — PostHog, processed in the United States, and only where you have consented.
  • Email delivery — Resend, and error monitoring — Sentry, both processed in the United States.
  • Payments — Stripe. No payment has ever been taken through the Service and this integration is currently dormant; if paid plans are introduced, Stripe will process payment data and we will update this policy first.

10. Where your data goes

As clause 9 makes clear, personal data processed through the Service is stored and processed outside the United Arab Emirates — principally in India, the United States, Germany, and across Cloudflare’s global network. We state this plainly because you are entitled to know it before you decide to use the Service.

Where the PDPL requires it, we make such transfers on the basis of appropriate contractual safeguards with each provider, obliging them to protect the data to a standard consistent with UAE law, to process it only on our instructions, and to assist us in meeting data-subject requests. Data is encrypted in transit.

If you are subject to a requirement that data about your organisation must not leave the UAE, the Service in its current form is not suitable for you, and you should not use it for that data.

11. How long we keep it

We keep account data for as long as your account is open, and for a reasonable period afterwards to meet legal, accounting, and audit obligations, after which we delete or anonymise it.

We retain visitor data — the page-view records described in clause 3 — for 24 months from the visit, then delete it. Twenty-four months is what lets us compare a period against the same period a year earlier; we have no reason to keep it longer. The consent-based visitor identifier itself expires within 400 days, and is deleted from your browser immediately if you withdraw consent.

Public-record data is kept while it remains relevant to counterparty risk. Where a record is corrected, withdrawn, overturned, or expunged at source, or where an objection succeeds, we correct, annotate, restrict, or remove our copy accordingly.

12. Your rights

Subject to the PDPL and its conditions, you have the right to be informed about how we process your data; to obtain a copy of it; to have inaccurate or incomplete data corrected; to have data erased in the circumstances the law allows; to restrict or object to processing, including processing based on legitimate interests; to receive data you gave us in a portable form; to withdraw consent where processing is based on consent; and to ask that an automated assessment concerning you be reviewed by a person.

To exercise any of these rights, write to privacy@counterscope.ae. We will acknowledge your request within five business days and respond substantively within 30 days. We may need to verify your identity first, and we will tell you if an exception in the law prevents us from doing what you have asked — and why.

Exercising these rights is free. If a request is manifestly excessive or repetitive we may decline it, and we will explain why.

13. If you are named in a record we hold

You do not need an account, and you do not need to be our customer, to ask us about data we hold about you. If a record on Counterscope names you or your company and you believe it is wrong, out of date, wrongly linked to you, or should not be there, our Data Accuracy, Corrections and Right of Reply Policy sets out exactly how to raise it, what we will check, how quickly we will respond, and what outcomes are available — including correcting the record, attaching your response to it, restricting it while we review, or removing it.

14. Security

We apply technical and organisational measures proportionate to the risk, including encryption in transit, row-level access controls that isolate each workspace, scoped and rotated credentials, least-privilege access for administrators, audit logging of sensitive operations, and monitoring. No system is perfectly secure, and we do not claim otherwise. If a breach occurs that is likely to put your rights at risk, we will notify you and the UAE Data Office as the PDPL requires.

15. Children

The Service is for business use by adults. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, tell us and we will delete it.

16. Changes and complaints

We may update this policy. Each version carries a version number and effective date, and we will give notice of material changes before they take effect.

If you are not satisfied with how we have handled your data or your request, write to us first at privacy@counterscope.ae so we have the chance to put it right. You also have the right to complain to the UAE Data Office.