ProsperityLab

Privacy policy

Effective 4 April 2026. This policy explains how ProsperityLab Technology Ltd collects, uses, stores, and protects personal data when you visit prosperitylab.io or interact with us. It is issued in compliance with the DIFC Data Protection Law No. 5 of 2020 (“DP Law”) and the DIFC Data Protection Regulations, as amended.

1. Data controller

The controller of your personal data is ProsperityLab Technology Ltd (Registered Number 12992, Licence CL12992), a private company incorporated in the Dubai International Financial Centre (DIFC) under the Companies Law, DIFC Law No. 5 of 2018, and operating under the DIFC Innovation Hub programme. We hold a non-financial innovation licence and are not regulated by the Dubai Financial Services Authority (DFSA).

Registered address: Unit IH-00-01-01-OF-01, Level 1, Innovation One, Dubai International Financial Centre, Dubai, United Arab Emirates.

Data protection enquiries: hello@thinkingwealth.ai

2. Personal data we collect

We collect only the minimum personal data necessary to deliver or respond to the services you request. This includes:

Information you provide directly. When you submit a demo request or contact form, we collect your name, work email address, company name, job title, product interest, and any additional information you choose to include in the message field.

Information collected automatically. When you visit our website, we collect limited technical data through Vercel Analytics, which measures page performance metrics (such as page load times and web vitals). Vercel Analytics does not use cookies, does not track individual users, and does not collect personal identifiers. No advertising trackers, third-party analytics cookies, or social media pixels are present on this website.

3. Purposes of processing

We process your personal data for the following purposes:

Responding to enquiries and scheduling demos. When you submit a form, we use the data to respond to your enquiry, arrange a demonstration if requested, and follow up in a business context. The legal basis is your consent (by submitting the form) and our legitimate interest in managing business relationships.

Website operation and improvement. We use aggregated, non-personal performance data to maintain and improve the website. The legal basis is our legitimate interest in operating a functional, performant website.

Legal and regulatory compliance. We may process personal data where required to comply with applicable law, regulation, or legal process. The legal basis is compliance with a legal obligation.

We do not sell, rent, or trade your personal data to third parties. We do not use your personal data for automated decision-making or profiling.

4. Data sharing and transfers

We share personal data only where necessary and with appropriate safeguards:

Service providers. We use SendGrid (Twilio Inc.) to deliver form submission notifications internally. SendGrid processes your name and email address solely for the purpose of transmitting the email on our behalf and is bound by a data processing agreement.

Hosting. This website is hosted by Vercel Inc. Vercel processes technical request data (such as IP addresses in server logs) in accordance with its privacy policy and data processing addendum.

Where personal data is transferred outside the DIFC, we ensure that adequate safeguards are in place as required by the DP Law, including standard contractual clauses, adequacy assessments, or the recipient’s binding compliance with an adequate data protection framework.

5. Cookies and tracking

This website uses only a single functional cookie (“sidebar_state”) to remember your user interface preferences. This cookie is strictly necessary for the operation of the website and does not track your activity or collect personal data.

We do not use advertising cookies, cross-site tracking pixels, or third-party analytics cookies. If this changes in the future, we will update this policy and implement a cookie consent mechanism before deploying any non-essential cookies.

6. Data retention

We retain enquiry data for as long as reasonably necessary to manage the business relationship arising from your enquiry, and thereafter only as required by applicable law. When personal data is no longer needed, we securely delete or anonymise it. Performance analytics data is aggregated and contains no personal identifiers.

7. Security measures

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These include encryption of data in transit (TLS), access controls on internal systems, and regular review of security practices. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Your rights under the DP Law

Under the DIFC Data Protection Law No. 5 of 2020, you have the following rights in relation to your personal data:

Right of access. You may request confirmation of whether we process your personal data and, if so, request a copy of that data.

Right to rectification. You may request that we correct inaccurate or incomplete personal data.

Right to erasure. You may request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, or where you withdraw consent.

Right to restrict processing. You may request that we restrict processing of your personal data in certain circumstances.

Right to data portability. Where technically feasible, you may request that your personal data be provided to you or transferred to another controller in a structured, commonly used, machine-readable format.

Right to object. You may object to processing based on our legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds.

Right to withdraw consent. Where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at hello@thinkingwealth.ai. We will respond within 30 days. There is no charge for exercising your rights.

9. Complaints

If you are not satisfied with our response to a data protection request, you have the right to lodge a complaint with the DIFC Commissioner of Data Protection. Details are available at difc.ae.

10. Children’s data

This website is not directed at individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us and we will delete it promptly.

11. Artificial intelligence

This website does not use artificial intelligence, machine learning, or autonomous/semi-autonomous systems to process your personal data. Our products may incorporate AI capabilities; where they do, separate and specific privacy disclosures will be provided in accordance with DIFC Data Protection Regulation 10.

12. Changes to this policy

We may update this policy to reflect changes in our practices or applicable law. The effective date at the top of this page will be updated accordingly. We encourage you to review this policy periodically. Material changes will be communicated via a notice on our website.

Back to home