Legal

Privacy Notice

This notice explains what personal data SYBERIS processes, why, on what lawful basis, and the rights available to you under UAE Federal Decree-Law No. 45 of 2021 (PDPL).

Last updated: 12 August 2026

01 Who we are

SYBERIS operates a technology-assisted cyber exposure and UAE compliance assessment platform. For personal data processed through the platform, SYBERIS acts as controller for account and usage data, and as processor for the scan data you submit about systems you own or are authorised to assess.

02 What we collect

  • Account data: email address and authentication identifiers.
  • Scan input: the domain or hostname you submit, plus your written authorisation confirmation.
  • Scan output: publicly observable technical data (DNS records, TLS and HTTP response headers, reachable paths, IP reputation).
  • Evidence you upload: images or PDFs you attach to a finding. On guest scans these stay in your browser and are never transmitted to us.
  • Advisor conversations: questions you send to the Security Advisor, together with the scan context in the current session.

03 Lawful basis (PDPL Article 4)

We rely on performance of a contract for delivering the assessment you request, consent for optional communications, and legitimate interests for platform security and abuse prevention. You may withdraw consent for optional communications at any time.

04 Guest scans

Guest scans are read-only and are not persisted to our database. Results, evidence uploads and finding status live only in your browser's local storage and are cleared when you clear site data.

05 Third parties we transmit data to

  • Threat intelligence and vulnerability sources: VirusTotal, AbuseIPDB, AlienVault OTX and the NIST National Vulnerability Database. We send only the domain, hostname or IP being assessed.
  • Our AI gateway provider, for generating summaries and Security Advisor responses. Prompts contain scan findings, not your account credentials.
  • Our managed database and authentication provider, for account and saved-scan data.

06 Cross-border transfers

Some processors operate outside the UAE. Transfers are made under contractual protections consistent with PDPL Articles 22–23. UAE-hosted data residency is on our roadmap for Q4 2026 and is not available today — we do not claim otherwise.

07 Retention

Account data is retained while your account is active and for up to 12 months afterwards. Saved scans are retained until you delete them or close your account. Guest scan data is not retained by us at all.

08 Your rights (PDPL Articles 13–19)

You may request access, correction, erasure, restriction of processing, portability of your data, and you may object to processing. Contact privacy@syberis.ae. We respond within 30 days. You may also complain to the UAE Data Office.

09 Security

We apply encryption in transit, least-privilege access, row-level authorisation on stored records, and secret management for third-party API keys. See our Security page for details.

10 Free zone entities

If your entity is registered in ADGM or the DIFC, those free zones operate their own data protection regimes rather than the federal PDPL. Our processing commitments in this notice apply equally.

This document describes SYBERIS' own practices and commitments. It is not legal advice and does not constitute a regulatory attestation. For formal certification or legal interpretation, engage an accredited auditor or licensed UAE legal counsel.