Privacy Policy
Effective October 23, 2024
AutomaticWorX (AWX) — Ekkel AI
Effective Date: 21 July 2026 · Last Updated: 21 July 2026 · Version: 1.0
1. Who We Are
This Privacy Policy explains how Ekkel AI F.Z.E (“Ekkel AI”, “we”, “us” or “our”), a free zone establishment registered in the Ajman Free Zone, Emirate of Ajman, United Arab Emirates (trade licence 34436), with registered address at Office C1-1F-SF0940, C1 Building, Ajman Free Zone, Ajman, United Arab Emirates, collects, uses, shares and protects personal data in connection with the AutomaticWorX platform (“AWX” or the “Platform”), our websites (including ekkel.ai and automaticworx.com), and our sales, marketing and support activities (together, the “Services”).
AWX is an agentic customer experience automation platform used by business customers (“Customers”) to deploy AI agents that handle their customers’ conversations across email, WhatsApp and other messaging services, web chat and voice.
2. Our Role: Controller and Processor
We process personal data in two distinct capacities. Understanding which one applies to you determines how your rights work and who you should contact.
As a controller. We decide how and why this data is used. This covers visitors to our websites, prospective customers, event and demo registrants, and the account, billing and support contacts of our Customers.
As a processor. When individuals (“End Users”) interact with a business that uses AWX, we process their conversations and related data on that business’s behalf and under its instructions. That business is the controller of this data; we are its processor under a Data Processing Addendum (“DPA”). If you are an End User, please direct privacy questions and requests to the business you interacted with. If you contact us directly, we will refer your request to the relevant business and support it in responding.
3. Personal Data We Collect
3.1 Data you provide to us (as controller)
Account data: account credentials, role and permissions, and preferences of Authorized Users of the Platform.
Billing data: billing contacts, invoicing details and payment records (payment card data is handled by our payment providers and is not stored by us).
Support communications: messages, tickets and feedback you send to our support and success teams.
Contact and business details: name, job title, company, email address, phone number, and the content of enquiries, demo requests and sales conversations.
3.2 End User data processed on behalf of Customers (as processor)
Conversation content: the content of messages, emails and chats exchanged with a Customer through the Platform, including attachments.
Voice recordings and transcripts: call audio, transcripts and derived analysis (such as sentiment, topics and summaries) where a Customer enables voice channels.
Identifiers: names, phone numbers, email addresses, chat handles and similar identifiers used on the enabled channels.
Business system data: customer records, order and case data retrieved from the Customer’s systems (such as its CRM) where the Customer configures such integrations.
The categories of End User data processed depend on the Customer’s configuration and instructions. Customers may process special categories of data through the Platform only where they have a lawful basis to do so.
3.3 Data collected automatically
Device and log data: IP address, device and browser type, operating system, pages viewed, and referring pages.
Usage data: features used, actions taken and performance telemetry within the Platform.
Cookies and similar technologies: as described in Section 12 below.
4. How We Use Personal Data and Legal Bases
Where we act as controller, we use personal data for the purposes below, relying on the legal bases permitted under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, the “PDPL”) and, where applicable, the GDPR.
Purpose
Examples
Legal basis
Providing and administering the Services
Creating and managing accounts, authentication, support, invoicing
Performance of a contract
Sales and marketing
Responding to enquiries, demos, newsletters, event invitations
Consent; legitimate interests
Improving and securing the Services
Diagnostics, analytics, fraud and abuse prevention, service development
Legitimate interests
Legal compliance
Tax and accounting records, responding to lawful requests, enforcing agreements
Legal obligation; legitimate interests
Where we act as processor, we use End User data only to provide the Platform to the relevant Customer in accordance with its instructions and the DPA, and as required by law.
5. AI Processing and Automated Decision-Making
The Platform uses artificial intelligence, including large language models operated by us and by contracted third-party foundation model providers, to understand conversations, generate responses, route and escalate conversations, transcribe and analyse calls, and detect trends across a Customer’s support operation.
The Platform is designed with safeguards including confidence scoring, configurable guardrails and escalation to human agents. Customers control how their AI agents behave, when conversations are escalated to humans, and what disclosures End Users receive. The Platform is not designed to make fully automated decisions that produce legal or similarly significant effects on individuals; where a Customer’s use case approaches such decisions, the Customer is responsible for ensuring meaningful human involvement and compliance with applicable law.
6. Our Commitment on Model Training
We do not use Customer or End User personal data to train general-purpose AI models made available to other customers, unless the relevant Customer has given prior written consent. Customer Data may be used to configure, evaluate and improve that Customer’s own deployment. We may use aggregated, de-identified data that does not identify any individual or Customer to improve the Services.
Our third-party foundation model providers are engaged under contracts that prohibit them from using data submitted through the Platform to train their models.
7. How We Share Personal Data
We do not sell personal data. We share personal data only as follows:
Subprocessors and service providers: service providers that support the Platform, including cloud hosting and infrastructure providers, foundation model providers, telephony and messaging providers (including WhatsApp Business solution infrastructure), email delivery, analytics and payment processors. Subprocessors handling End User data are listed in the DPA (and available on request) and are bound by data protection obligations consistent with this Policy and the DPA.
Affiliates and advisers: our affiliates and professional advisers (legal, accounting, insurance) under confidentiality obligations.
Corporate transactions: in connection with a merger, acquisition, financing or sale of assets, subject to confidentiality protections and notice where required.
Legal requirements: where required by applicable law, regulation or a binding request from a competent authority, or to establish, exercise or defend legal claims.
8. Data Residency and International Transfers
For enterprise deployments, we offer hosting of Customer Data in data centres located in the United Arab Emirates, as specified in the applicable Order Form.
Where personal data is transferred outside the UAE (or outside the jurisdiction where it was collected), we do so only in accordance with applicable law, including Articles 22 and 23 of the PDPL: to jurisdictions recognised as providing adequate protection, or subject to appropriate safeguards such as contractual data protection clauses, or on another lawful basis such as the data subject’s consent or contractual necessity.
9. Data Retention
Controller data (accounts, billing, marketing): retained for the duration of our relationship and thereafter as needed for legal, accounting and dispute-resolution purposes, typically no longer than seven (7) years.
End User data (processor): retained in accordance with the relevant Customer’s configuration and instructions. On termination of a Customer’s subscription, End User data is made available for export and then deleted in accordance with the DPA, typically within ninety (90) days, unless retention is required by law.
Logs and telemetry: retained only as long as needed for the purposes described in this Policy or until de-identified.
10. Security
We implement technical and organisational measures appropriate to the risk of processing, including encryption of data in transit and at rest, role-based access controls and authentication, network and application security controls, logging and monitoring, personnel confidentiality obligations and training, and documented incident response procedures. No system is completely secure; we cannot guarantee absolute security, but we review and improve our measures on an ongoing basis.
11. Your Rights
Subject to applicable law, you have the right to: request access to your personal data and a copy of it; request correction of inaccurate or incomplete data; request erasure; request restriction of processing; receive your data in a portable format; object to processing, including for direct marketing; withdraw consent at any time (without affecting prior processing); and object to decisions based solely on automated processing that produce legal or similarly significant effects.
To exercise your rights, contact us at privacy@ekkel.ai. We will respond within the timeframes required by applicable law (generally within thirty (30) days). We may need to verify your identity before acting on a request.
If you are an End User of a business that uses AWX, that business is the controller of your data: please direct your request to it. We will notify the relevant business of requests we receive directly and assist it in responding.
12. Cookies and Similar Technologies
Our websites and web chat use cookies and similar technologies for the following purposes: strictly necessary cookies (authentication, security, session continuity of chat conversations); functional cookies (preferences); and analytics cookies (understanding how our websites are used). Where required by law, we request your consent before setting non-essential cookies via our cookie banner, and you may withdraw consent at any time through the cookie settings on our website or your browser settings. Disabling certain cookies may affect the operation of web chat.
13. Children
Our websites and Services are directed at businesses and are not intended for children under eighteen (18). We do not knowingly collect personal data from children as a controller. Where a Customer’s End Users may include minors, the Customer is responsible for ensuring its use of the Platform complies with applicable laws on children’s data.
14. Personal Data Breaches
In the event of a personal data breach, we will act in accordance with applicable law and our incident response procedures, including notifying the UAE Data Office and affected individuals where required by the PDPL, and notifying affected Customers without undue delay so they can meet their own obligations as controllers.
15. Third-Party Websites and Services
Our websites and the Platform may link to or interoperate with third-party websites and services (such as messaging platforms and CRMs). Their privacy practices are governed by their own policies, which we encourage you to review.
16. Changes to This Policy
We may update this Policy from time to time. We will post the updated version with a revised “Last Updated” date and, for material changes, provide notice through the Services or by email. Continued use of the Services after the effective date constitutes acknowledgement of the updated Policy.
17. Contact Us
Privacy questions, requests and complaints may be directed to:
Ekkel AI F.Z.E — Attn: Privacy, Office C1-1F-SF0940, C1 Building, Ajman Free Zone, Ajman, United Arab Emirates. Email: privacy@ekkel.ai.
If you are not satisfied with our response, you may lodge a complaint with the UAE Data Office or, where applicable, with the supervisory authority in your jurisdiction.