Someli.ai Privacy Policy
Effective Date: January 16, 2026
Last Revised: January 16, 2026
1. Introduction and Scope
Someli Marketing & Technology Ltd. (“Someli,” “we,” “us,” or “our”), a company registered in the Dubai International Financial Centre (DIFC) with Company No. 4971, respects your privacy and is committed to protecting your personal data. We are committed to ensuring that your privacy is protected and that your information is used only in accordance with this privacy statement.
This policy governs how we collect, use, and process Personal Data in compliance with:
- DIFC Data Protection Law No. 5 of 2020 (DPL 2020)
- The EU General Data Protection Regulation (GDPR)
- The UK General Data Protection Regulation (UK GDPR)
This policy applies to all instances where we may collect and hold your personal data, including through the Site, related services, email, phone communications, and client service delivery.
Data Controller / Processor Status
Depending on the circumstances, we may be a data controller (e.g., for general website analytics) or a data processor (e.g., when generating content on behalf of a client/employer).
2. Data We Collect and Purpose of Processing
We collect Personal Data solely for the explicit purposes of providing and improving the AI-powered social media automation services, as well as for the effective and lawful operation of our business.
| Category of Data | Specific Data Points | Purpose of Processing | Lawful Basis (DPL 2020) |
|---|---|---|---|
| Client/User Data | Name, job title, company email, phone number, secure login credentials, IP address. | Account management, authentication, security logging, support communications, and to notify you of changes and updates to our services. | Contract Necessity, Legitimate Interest (security, business administration). |
| Content & Profile Data | Employee photos/profile pictures (if provided), social media account handles, Name, Address, Phone number and business information, content ideas, marketing preferences, language, time zone. | To generate AI-assisted content drafts that align with the user's brand and scheduling needs, and to properly deliver our contracted services to you. | Contract Necessity, Consent (for photos/non-essential data). |
| Usage Data | Login history, feature usage, API calls, technical configuration, error logs, details of your visit (location, traffic, pages visited). | Platform performance monitoring, bug fixing, internal record-keeping, and general analysis of website usage statistics. | Legitimate Interest (system maintenance, effective operation of business). |
| Financial Data | Payment information (Direct Debit instructions, Credit Card/Debit Card information details stored by the payment processor). | To process payments for our services and comply with contractual obligations. We do not store full credit card/debit card details in our database or records. Our payment processor is Paddle.com. | Contract Necessity, Legal Obligation (tax/regulatory). |
We may also collect data from third parties (e.g., marketing lists or publicly available data) to improve our services or conduct periodic market research, where it is in our Legitimate Business Interests and does not interfere with your rights.
3. AI Processing, Security, and Governance
As an AI technology company operating under DIFC DPL 2020, we adhere to the strict principles of Regulation 10 (Autonomous Systems):
3.1 AI Processing Safeguards
We ensure that the Personal Data provided by you is not used to train the underlying models of our third-party LLM Sub-Processors. We utilize these models in inference-only mode for content generation, meaning your data is used only to generate the output and then discarded or handled according to our standard retention policies.
3.2 Security Measures
We are committed to ensuring that your information is secure. In order to prevent unauthorized access or disclosure, we implement the following Technical and Organizational Measures (TOMs):
- Encryption: All data is encrypted at rest (AES-256) and in transit (TLS 1.2+).
- Access Control: Strict Role-Based Access Control (RBAC) and Identity & Access Management (IAM) policies.
- Monitoring & Audit: Continuous logging and monitoring of all processing activities, required for DIFC DPL compliance.
- Personnel Obligations: All our employees and any third parties we engage to process your personal information are obliged to respect the confidentiality of your information.
4. International Data Transfers and Sharing
4.1 Data Sharing
We do not share any of the personal data we hold with third parties, other than where necessary in the proper delivery of our services (Sub-Processors). We remain fully liable for any breach caused by our Sub-Processors. Data may also be shared as required by law or any regulatory authorities, and in the operation and administration of our business.
4.2 International Transfers
Someli is based in the DIFC, an independent jurisdiction. Given our use of global Sub-Processors (e.g., AWS, OpenAI) primarily located in the United States:
- DIFC Compliance: Transfers from the DIFC to non-DIFC jurisdictions are conducted using DIFC Article 27-compliant safeguards, including DIFC-approved contractual clauses (based on EU/UK Standard Contractual Clauses, or SCCs).
- GDPR/UK GDPR Compliance: We rely on the appropriate contractual safeguards (SCCs) to ensure the data retains the necessary level of protection as required by European law.
5. Data Subject Rights
As a Data Subject, you have the right to exercise the following rights:
| Right | Description |
|---|---|
| Right of Access | To obtain confirmation of whether data concerning you is being processed and to access that data. |
| Right to Rectification | To correct inaccurate or incomplete Personal Data. |
| Right to Erasure ('Right to be Forgotten') | To request the deletion of your Personal Data, subject to legal retention obligations. |
| Right to Restriction of Processing | To limit the way we use your Personal Data. |
| Right to Object / Withdrawing Consent | You are entitled to withdraw your consent to, or object to, our processing of your personal data for the purposes stated above. |
| Right to Data Portability | To receive your Personal Data in a structured, commonly used, and machine-readable format. |
| Right regarding Automated Decision-Making | To object to processing which is based solely on automated processing (including profiling) which produces legal or similarly significant effects concerning you. |
| Right to Lodge a Complaint | You have the right to lodge a complaint with the DIFC Commissioner of Data Protection or the relevant Supervisory Authority in your jurisdiction. |
To exercise any of these rights, please contact the Client (your employer/the Data Controller) in the first instance. You may also contact Someli by sending your request to our Data Rights Request Email at [email protected].
6. Data Retention
We retain your personal data for as long as you are a client or customer of our business or as long as necessary to fulfill the purposes for which it was collected.
- Service Termination: Upon termination of the service agreement, all Personal Data belonging to the Client will be deleted or returned within a maximum period of thirty (30) days, unless legal obligations require retention.
- Post-Termination Retention: Should you cease to trade with us, we may keep certain data for a period of up to seven (7) years for the purpose of complying with our Legal Obligations (e.g., tax, audit) or where it is necessary for our Legitimate Interests (e.g., defense of legal claims).
7. Miscellaneous Provisions
- Links to other websites: This website may contain links to other websites. We cannot be responsible for the protection and privacy of any information you provide whilst visiting such sites, and they are not governed by this privacy statement.
- Changes to Privacy Policy: We may change this policy from time to time by updating this page. You should check this page from time to time to ensure that you are happy with any changes.
- Where your personal data changes: Please advise us of changes to your personal data so that we can update our records accordingly.
8. Contact Information
If you have any questions about this Privacy Policy or our data practices, please contact:
Data Protection Officer (DPO) / Autonomous Systems Officer (ASO)
Someli Marketing & Technology Ltd.
DIFC Innovation Hub, Level 1, Gate Avenue South, Dubai International Financial Center, Dubai, United Arab Emirates.
[email protected]