Legal
Data Protection and GDPR Policy
- Effective
- Last updated
Introduction and Scope
This Data Protection and GDPR Policy (the “Policy”) describes how Nine Square Technology (“we,” “us,” or “our”), the operator of the Rannah AI agent platform, processes personal data in compliance with the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”) and, where applicable, the UK GDPR and Data Protection Act 2018. It applies to the processing of personal data of individuals in the European Economic Area (“EEA”) and the United Kingdom in connection with the Rannah platform, voice and chat AI agents, websites, and related services (the “Service”). This Policy supplements our Privacy Policy.
Definitions
The terms “personal data,” “processing,” “controller,” “processor,” “data subject,” “special categories of personal data,” and “supervisory authority” have the meanings given to them in the GDPR. “Customer” means an organization or individual that subscribes to the Service and deploys AI Agents. “End User” means an individual who interacts with a Customer’s AI Agent.
Controller and Processor Roles
Our role under the GDPR depends on the processing activity. We act as a controller in respect of personal data we process for our own purposes, such as account administration, billing, website analytics, and direct communications with Customers. We act as a processor in respect of personal data contained in Customer configurations and in End User conversations processed through AI Agents; in that case, the Customer is the controller and determines the purposes and means of the processing, and we process such data only on the Customer’s documented instructions under a data processing agreement. Customers are responsible for ensuring they have a valid legal basis and have provided all required notices to their End Users.
Principles of Processing
We process personal data in accordance with the GDPR principles. Personal data is processed lawfully, fairly, and transparently; collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes; adequate, relevant, and limited to what is necessary; accurate and, where necessary, kept up to date; kept in a form that permits identification for no longer than necessary; and processed in a manner that ensures appropriate security, integrity, and confidentiality. We are able to demonstrate compliance with these principles (accountability).
Lawful Bases for Processing
Where we act as a controller, we rely on one or more of the following lawful bases under Article 6 of the GDPR:
- Contract:
- processing necessary to perform our contract with you or to take steps at your request before entering into a contract.
- Legitimate interests:
- processing necessary for our legitimate interests in operating, securing, and improving the Service, where those interests are not overridden by your interests or fundamental rights.
- Consent:
- where you have given consent, for example for certain cookies or marketing communications, which you may withdraw at any time.
- Legal obligation:
- processing necessary to comply with a legal obligation to which we are subject.
We do not intentionally process special categories of personal data unless a specific condition under Article 9 of the GDPR applies. Customers must not configure AI Agents to collect special category data from End Users without ensuring an appropriate condition and lawful basis apply.
Data Subject Rights
Subject to the conditions and exemptions in the GDPR, data subjects have the following rights:
- Right to be informed:
- to receive clear information about how their personal data is processed.
- Right of access:
- to obtain confirmation of whether we process their personal data and a copy of that data.
- Right to rectification:
- to have inaccurate personal data corrected and incomplete data completed.
- Right to erasure:
- to have their personal data deleted in certain circumstances (the “right to be forgotten”).
- Right to restriction of processing:
- to request that we limit the processing of their personal data in certain circumstances.
- Right to data portability:
- to receive their personal data in a structured, commonly used, machine-readable format and to have it transmitted to another controller where technically feasible.
- Right to object:
- to object to processing based on legitimate interests or to direct marketing.
- Rights related to automated decision-making:
- not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, except as permitted by law.
How to Exercise Your Rights
Data subjects may exercise their rights by contacting us using the details in the “Contact Us” section below. Where the personal data relates to a Customer’s AI Agent and we act as processor, we will refer the request to, or assist, the relevant Customer as controller, and the data subject should direct the request to that Customer in the first instance. We will respond to verified requests without undue delay and within one month, which may be extended by up to two further months for complex or numerous requests, in which case we will inform you. We do not charge a fee unless a request is manifestly unfounded or excessive.
Consent and Withdrawal
Where we rely on consent, we obtain it through a clear affirmative action, keep a record of it, and make it as easy to withdraw consent as to give it. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
International Data Transfers
Personal data processed through the Service may be transferred to, and stored in, countries outside the EEA and the United Kingdom, including the Kingdom of Bahrain. Where we transfer personal data to a country that has not received an adequacy decision, we implement an appropriate transfer mechanism under the GDPR, such as the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where relevant), together with any supplementary technical and organizational measures necessary to ensure an essentially equivalent level of protection. You may request further information about these safeguards using the contact details below.
Sub-Processors
We engage carefully selected third-party sub-processors to help provide the Service, including cloud hosting, infrastructure, AI model processing, communications, and analytics providers. We impose data-protection obligations on each sub-processor by written contract that are no less protective than those in our own agreements, and we remain responsible for their performance of data-protection obligations. Where we act as processor, we will inform Customers of intended changes to sub-processors and give them the opportunity to object, in accordance with the applicable data processing agreement.
Security of Processing
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. These measures include encryption of personal data in transit, access controls and authentication, network and application security, logging and monitoring, regular review of our measures, and staff confidentiality obligations. We also maintain processes to restore availability and access to personal data in a timely manner in the event of an incident.
Personal Data Breaches
We maintain procedures to detect, investigate, and respond to personal data breaches. Where we act as controller and a breach is likely to result in a risk to the rights and freedoms of data subjects, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, and we will notify affected data subjects where the breach is likely to result in a high risk to them. Where we act as processor, we will notify the affected Customer without undue delay after becoming aware of a personal data breach so that the Customer can meet its own notification obligations.
Data Retention and Deletion
We retain personal data only for as long as necessary for the purposes for which it was collected, to provide the Service, and to comply with legal, regulatory, accounting, and reporting obligations. Where we act as processor, retention and deletion of Customer and End User data follow the Customer’s instructions and configured settings and the applicable data processing agreement. On expiry of the applicable retention period, we securely delete or anonymize personal data.
Data Protection by Design and by Default; Impact Assessments
We take data protection into account when designing and operating the Service, and we apply measures designed to process only the personal data necessary for each specific purpose (data protection by design and by default). Where a type of processing is likely to result in a high risk to the rights and freedoms of individuals, we carry out a Data Protection Impact Assessment and, where required, consult the relevant supervisory authority.
Records of Processing and Accountability
We maintain records of our processing activities as required by Article 30 of the GDPR, review our data-protection practices periodically, and provide training to relevant personnel to support ongoing compliance and accountability.
Complaints and Supervisory Authority
If you have a concern about how we handle your personal data, please contact us first using the details below, and we will do our best to resolve it. You also have the right to lodge a complaint with a supervisory authority, in particular in the EEA or UK member state of your habitual residence, place of work, or the place of the alleged infringement.
Contact Us
For any questions, requests, or concerns relating to this Policy or our processing of personal data, please contact us:
Nine Square Technology (Rannah)Commercial Registration No. 184120-1, Kingdom of BahrainDiyar Al Muharraq, Kingdom of BahrainEmail: info@rannah.ioTelephone: +973 1755 0717