This page is a working draft pending formal legal review, published here for transparency ahead of that sign-off.
Legal
Privacy Policy
Last updated: 2026-08-04
Please note: this Privacy Policy is a draft prepared ahead of formal legal review. It reflects Taleef Technologies’ intended data practices as accurately as possible, but has not yet been confirmed by legal counsel.
Who we are
This Privacy Policy explains how Taleef Technologies L.L.C-FZ (“Taleef,” “we,” “us,” or “our”) processes personal information through our website, our software products (Taleef CRM, TaleefChat, and TaleefAIBot), any mobile applications we offer, and the business communication and customer-support services delivered through them.
Taleef Technologies L.L.C-FZ is headquartered at Meydan Grand Stand, 6th Floor, Meydan Hotel, Nad Al Sheba, Meydan Road, Dubai, United Arab Emirates. You can reach us at [email protected] or +971 50 309 3218.
Taleef ChangeLink is a separate product with its own dedicated Privacy Policy at changelink.pages.dev. If you use Taleef ChangeLink, that product-specific policy governs your use of it; this policy covers taleeftech.com and our other products.
The two roles Taleef plays with personal information
Because Taleef CRM, TaleefChat, and TaleefAIBot are used by business clients to manage their own customers’ information, Taleef processes personal information in two different capacities, and it’s important to be clear about which applies in a given case.
Taleef as controller. We decide how information is used when it relates to our own business, including: website enquiries, sales leads, demo requests, billing contacts, our own marketing, job applications, and administration of Taleef accounts themselves. This Privacy Policy describes that processing in full.
Taleef as processor / service provider. When one of our business clients uses Taleef CRM, TaleefChat, or TaleefAIBot to manage their own customers’ data, contacts, conversations, or support tickets, we generally process that information on the client’s instructions, under the terms of our agreement with them. In that case, the client is responsible for obtaining any permissions needed from their own customers, providing their own customers with an appropriate privacy notice, and determining retention periods, and we process the data according to our agreement with that client. If you’re a customer of one of our business clients and have a question about how your data is used, the fastest route is usually to contact that business directly; we’re also glad to help route your enquiry appropriately, using the contact details above.
Information we collect
Account information: name, business email, phone number, company, role, and account identifiers, for anyone we or a business client provision an account for.
Authentication information: password hashes, login records, session tokens, and multi-factor authentication records, where applicable.
Contact and enquiry information: name, email address, phone number, company name, and any details shared through our contact form, quotation requests, demo bookings, consultation requests, or job applications.
CRM information: contacts, organisations, leads, opportunities, quotations, invoices, tasks, and notes entered into Taleef CRM by us or by a business client.
Communications: messages sent through our website chat, WhatsApp, email, or TaleefChat, including attachments, images, audio, and message metadata such as timestamps and delivery or read status.
Client-provided information: information uploaded, imported, connected, or entered by a business client using our products.
Device and technical information: IP address, device type, operating system, app version, and, where applicable, crash and security logs.
Usage information: features used, actions taken, login dates, support activity, and audit logs.
Support information: support tickets, troubleshooting details, and related communications.
AI information: prompts and content submitted to TaleefAIBot, and the responses generated.
Billing information: subscription, invoice, and payment-status information. We do not directly store full card numbers; payment processing is handled by our payment providers.
Mobile-device information and permissions: where we offer a mobile application, depending on the features you choose to use, it may request access to things like notifications, camera, microphone, photos, files, or contacts. We request access only where needed for a feature you initiate, such as uploading an attachment, recording an audio message, importing a business contact, or receiving a notification. You can manage these permissions through your device settings, and a given app only requests the specific permissions it actually needs for the features it offers.
We do not collect more information than we need to respond to you, provide the product or service you’ve asked about, or improve our website and products.
How we use your information, and our legal basis for doing so
We use the information we collect to:
- Respond to enquiries, quotation requests, demo bookings, and consultation requests.
- Provide, operate, and support Taleef CRM, TaleefChat, TaleefAIBot, and our related business services.
- Send information you’ve requested or opted in to receive.
- Improve our website and products.
- Review job applications, if you apply for an open role.
- Detect, investigate, and prevent fraud, abuse, and security incidents.
Where UK or EEA data protection law applies to our processing, we rely on one or more of the following legal bases: performance of a contract with you (or steps you’ve asked us to take before entering one), our legitimate interests in running and improving our business (balanced against your rights), compliance with a legal obligation, your consent (for optional marketing or non-essential analytics, which you can withdraw at any time), and, where necessary, establishing, exercising, or defending legal claims.
WhatsApp and TaleefChat
We use WhatsApp’s Business API (via Meta’s WhatsApp platform) as one of the channels available through TaleefChat, both for our own communications with you and, where a business client uses TaleefChat, for that client’s communications with their own customers.
Where TaleefChat is used by one of our business clients, Taleef generally processes WhatsApp communications on that client’s behalf. The client determines the recipients, purpose, and content of its communications and is responsible for obtaining any required consent or other legal authority for sending them.
Depending on how TaleefChat is configured, this can include processing:
- WhatsApp phone numbers and business profile information.
- Message content, attachments, audio, images, and documents.
- Message timestamps and delivery or read status.
- Conversation assignment and status within TaleefChat.
- Template-message information.
- Opt-in and opt-out records.
- Information about the business operating the WhatsApp account.
We do not sell WhatsApp data, or disclose it for unrelated third-party advertising. Because WhatsApp messages necessarily pass through Meta’s infrastructure, and may pass through our hosting and infrastructure providers to be delivered, we can’t say WhatsApp data is never processed by anyone but Taleef; what we can say is that we don’t sell it or use it for advertising unrelated to the conversation it’s part of.
Your use of WhatsApp is also subject to WhatsApp’s own terms and privacy policy, which govern how Meta itself handles data on its platform; this policy covers what Taleef does with information once it reaches us.
TaleefAIBot and AI processing
TaleefAIBot is a live AI chat assistant. When you use it:
- What you type (your prompts) and TaleefAIBot’s responses may be stored, to maintain your conversation and to help us review and improve the product.
- A member of our team may review conversations, particularly where the system flags a conversation as a potential lead or a possible issue.
- Your prompt and the resulting response may be processed by third-party AI infrastructure in order to generate a reply.
- Taleef does not use TaleefAIBot conversations to train its own general-purpose AI models. Conversation content may be processed by third-party AI infrastructure to generate responses; before this policy leaves draft, we will confirm and disclose here whether that provider retains conversation content or uses it for their own model training or improvement, based on our provider agreement and account configuration.
- Please don’t submit sensitive personal information (such as financial account numbers, health information, or government ID numbers) to TaleefAIBot that isn’t necessary to answer your question.
- AI-generated responses can be inaccurate. Don’t rely on a TaleefAIBot response alone for a decision that matters; where it matters, confirm with our team directly.
- You can request deletion of your TaleefAIBot conversation history using the process described in “Your rights” below.
Hosting and international transfers
Depending on the product and the client’s requirements, Taleef-hosted infrastructure, a client’s own infrastructure, or an approved third-party cloud or hosting provider may be used to run our products and store the information described in this policy. Processing locations can differ between clients and products, and information may be transferred outside the country where you’re located as a result.
Where we transfer personal information internationally, we use legally required contractual and security safeguards appropriate to that transfer.
Who we share information with
Depending on the product and context, we may share personal information with:
- Taleef business clients, where you’re communicating with that client through one of our products.
- Hosting, infrastructure, and database providers.
- Storage and backup providers.
- Communications and messaging networks, including Meta/WhatsApp.
- Email-delivery providers.
- Security, monitoring, and fraud-prevention providers.
- Analytics providers.
- Customer-support providers.
- Payment and invoicing providers.
- Professional advisers, auditors, and insurers.
- Government, regulatory, and judicial authorities, where required by law.
- An acquirer or successor organisation, in connection with a merger, acquisition, or sale of assets.
- Providers selected by a Taleef business client, where that client has configured their own use of our products to include a third-party integration.
We require service providers that process personal information on our behalf to apply contractual, technical, organisational, and confidentiality protections appropriate to the information they handle. We do not sell your personal information.
Data retention
How long we retain information depends on the type of data, the product, our contract with the relevant client, and any applicable legal obligation. Our current retention periods are:
- Enquiries that don’t convert into a client relationship: 24 months, then deleted.
- Job applications: 12 months after a hiring decision is made.
- Client account records: for the duration of the client relationship, plus 6 years afterward.
- CRM data and client-controlled communications: for the period configured or contractually agreed with the relevant client.
- Security logs: 90 to 365 days.
- Support tickets: 3 years after closure.
- AI conversations (TaleefAIBot): 30 to 90 days, unless a conversation is converted into a support or sales record, in which case it’s retained under that category instead.
- Operational backups: a rolling 30 to 90 day cycle.
- Invoices and tax records: as required by applicable UAE tax and accounting law.
Deleting information from our live systems may not instantly remove it from encrypted backups; backup copies are retained only until they expire or are overwritten under our normal backup cycle, and are not used for any purpose other than restoring service.
Your rights
Depending on where you’re located and which processing applies, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Request deletion of your information.
- Restrict or object to certain processing.
- Request a portable copy of information you’ve provided.
- Withdraw consent, where processing is based on consent.
- Opt out of direct marketing.
- Complain to your relevant data protection regulator.
- Request human review of a decision made solely by automated means, where applicable.
To exercise any of these rights, contact us at [email protected]. We may need to verify your identity before fulfilling a request. Where we process information on behalf of a business client (see “The two roles Taleef plays” above), we may forward your request to that client or ask you to contact them directly, since they’re usually the party best placed to fulfil it.
For Taleef CRM, TaleefChat, and TaleefAIBot account and data deletion specifically, see our Account and Data Deletion page.
Children and business use
Taleef accounts and administrative access to our business products are intended for adults acting on behalf of a business or organisation. We do not knowingly allow children to create or administer Taleef accounts.
A business client may use our products to process information relating to other individuals, including minors where legally permitted, for example, as part of their own CRM records or customer communications. In those circumstances, the business client is responsible for obtaining any required parental consent or other lawful authority, and Taleef processes that information on the client’s instructions (see “The two roles Taleef plays with personal information” above).
Security
We take reasonable technical and organisational measures to protect personal information against unauthorised access, loss, or misuse.
Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page reflects the most recent revision.
Contact us
If you have questions about this Privacy Policy or how we handle your information, contact us at [email protected].
