Privacy Policy
Last updated: 13 April 2026
This Privacy Policy explains how Spectral Automata (FZE), a company registered in SRTI Park, Sharjah, United Arab Emirates (Trade License No. 20141), collects and uses information through spectralautomata.com (the "Website"). By using this Website, you agree to the practices described below.
1. Our commitment to data protection
Spectral Automata is committed to protecting the privacy and personal data of all individuals who interact with this Website. We operate in full compliance with UAE Federal Decree-Law No. 45 of 2021 Regarding the Protection of Personal Data (the "PDPL") and its Executive Regulations, as well as all other applicable data protection laws and regulations of the United Arab Emirates.
As the data controller for information collected through this Website, Spectral Automata is responsible for ensuring that your personal data is processed lawfully, fairly, and transparently, and only for the purposes described in this policy.
2. What we collect
This Website is a marketing and informational site. We do not require you to create an account, log in, or provide any personal information to browse the site. We collect data only in the following circumstances:
Contact form submissions
When you submit the contact form, you voluntarily provide the following information:
- Your name
- Your professional role
- Your institution name
- Your email address
- Which product you are exploring (Kompliant, RMS, or both)
- An optional message
Lawful basis for processing (PDPL Article 5): We process this data based on your explicit consent, which you provide by voluntarily completing and submitting the contact form. You may withdraw your consent at any time by contacting us (see Section 10).
This information is sent directly to our internal email inbox (contact@spectralautomata.com) via Resend, a transactional email service. We do not store form submissions in a database. We do not add you to any mailing list, marketing sequence, or CRM system. Your submission goes to a human inbox and is read by the Spectral Automata team.
Anti-bot verification
The contact form uses Cloudflare Turnstile to distinguish genuine visitors from automated bots. Turnstile processes a verification token during form submission. We do not receive or store any personal data from this process beyond a pass/fail result.
Rate limiting
To prevent abuse, we temporarily store a counter associated with your IP address in Cloudflare KV (a key-value store). This counter tracks the number of form submissions from your IP address within a one-hour window and automatically expires after that period. We do not log, retain, or associate your IP address with any other data.
3. Analytics
We use Cloudflare Web Analytics, a privacy-first analytics service that does not use cookies, does not track individual visitors, and does not collect personal data. It provides us with aggregate metrics only (page views, referrers, browser types). No advertising network or third-party tracker is present on this Website.
4. Cookies
This Website does not set any cookies. Cloudflare Web Analytics is cookieless by design. No session cookies, tracking cookies, or advertising cookies are used.
5. No data sharing — including with AI companies
Spectral Automata does not sell, rent, trade, license, or share your personal data with any third party. This includes, without limitation:
- Advertising networks or data brokers
- Artificial intelligence (AI) companies, large language model providers, or machine learning training pipelines
- Social media platforms
- Marketing automation providers
- Any other entity not directly involved in the technical delivery of this Website
Your personal data is never used to train, fine-tune, or improve any AI model, whether internal or external. We maintain a strict policy of data isolation: your information is used solely for the purpose of responding to your inquiry.
6. Infrastructure providers
The following infrastructure providers process limited technical data (such as your IP address or browser type) solely as part of delivering their service to us. They act as data processors under our instruction and do not use your data for their own purposes:
- Cloudflare (Pages hosting, DNS, Turnstile anti-bot, KV rate limiting, Web Analytics) — Privacy Policy
- Resend (transactional email delivery for form submissions only) — Privacy Policy
- Google Fonts (font file delivery: Inter, Fraunces, JetBrains Mono) — Privacy Policy. Google Fonts may process your IP address when your browser requests font files. No cookies are set. We are evaluating self-hosting fonts in a future update to eliminate this external dependency.
These are the only third parties with any access to technical data generated through your use of this Website. No other third party receives any data from us.
7. Cross-border data processing
Cloudflare and Resend operate globally, which means limited technical data (such as IP addresses and email content) may be processed on servers outside the United Arab Emirates as part of service delivery. In accordance with PDPL Article 22 and its Executive Regulations, we ensure that any cross-border processing is conducted by providers who maintain appropriate data protection standards and that such transfers are necessary for the performance of the service.
Spectral Automata's own commercial products (Kompliant and RMS) are hosted entirely within Microsoft Azure's UAE North region in Dubai. This Website, however, is a static marketing site served globally by Cloudflare's content delivery network.
8. Data retention
Contact form submissions are retained in our email inbox for the purpose of responding to your inquiry and for a reasonable period thereafter for business records. Upon request, we will delete your submission within 30 days (see Section 9). Rate-limiting counters expire automatically after one hour. Cloudflare Web Analytics does not retain identifiable visitor data.
9. Your rights under the PDPL
Under UAE Federal Decree-Law No. 45 of 2021, you have the following rights regarding your personal data:
- Right of access — You may request confirmation of whether we process your personal data and obtain a copy of that data.
- Right to rectification — You may request correction of inaccurate or incomplete personal data.
- Right to erasure — You may request deletion of your personal data, subject to any legal obligation requiring its retention.
- Right to restriction — You may request that we restrict the processing of your personal data in certain circumstances.
- Right to data portability — You may request that we provide your personal data in a structured, commonly used format.
- Right to object — You may object to the processing of your personal data, including objecting to automated decision-making.
- Right to withdraw consent — Where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before the withdrawal.
To exercise any of these rights, email contact@spectralautomata.com with the subject line "Data Privacy Request." We will acknowledge your request within 7 days and respond substantively within 30 days.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the UAE Data Office.
10. Data security
In accordance with PDPL Article 28 and its Executive Regulations, we implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption of all data in transit via HTTPS (TLS)
- HTTP Strict Transport Security (HSTS) with preload
- Strict Content Security Policy (CSP) on all responses
- X-Frame-Options, X-Content-Type-Options, and Referrer-Policy headers
- Cloudflare Turnstile to prevent automated abuse
- Per-IP rate limiting on form submissions
11. Children
This Website is intended for professionals working in higher education and research institutions. We do not knowingly collect information from children under the age of 18. In accordance with PDPL provisions on the protection of minors' data, if we become aware that we have inadvertently collected personal data from a child, we will delete it promptly.
12. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or in applicable law. Changes will be posted on this page with an updated "Last updated" date. If we make material changes, we will make reasonable efforts to notify affected individuals. We encourage you to review this page periodically.
13. Data controller and contact
The data controller for information collected through this Website is:
Spectral Automata (FZE)
Block C-C01-057, SRTI Park
Sharjah, United Arab Emirates
Trade License No. 20141
contact@spectralautomata.com
For data protection inquiries, use the subject line "Data Privacy Request" when emailing the address above.