Privacy Policy
Last updated: 21 July 2026
This Privacy Policy explains how CUZN Information Technology Innovation Consultants – FZCO (“CUZN,” “we,” “us”), a company registered in the IFZA / Dubai Silicon Oasis free zone in the United Arab Emirates, and operator of cuzn.studio and app.cuzn.studio (the “Services”), collects, uses, shares, and protects personal data, and the rights you have over your information.
1. Who is responsible for your data
For our own marketing site and account data, CUZN is the data controller. When we process data on behalf of a business customer inside their workspace (for example, their contacts, content, or connected social/analytics accounts), CUZN acts as a processor and that customer is the controller; our processing is governed by our agreement with them.
2. Data we collect
- You provide it: name, email, company, and message when you contact us or create an account; billing details processed by our payment provider.
- You connect it: when you link a third-party account (e.g. Instagram, Facebook, TikTok, YouTube, LinkedIn, Google/Microsoft Drive), we receive the tokens and the data those platforms’ official APIs return for the actions you authorize — such as your profile, the posts/analytics of accounts you own, and content you upload.
- Content you upload: media, documents, and text you add to your workspace, and derived artifacts (transcripts, extracted frames, generated drafts).
- Automatically: device/log data, IP address, and basic usage analytics needed to operate and secure the Services.
3. How we use it
To provide, secure, and improve the Services; to authenticate you and enforce access controls; to publish, schedule, and analyze content on accounts you connect at your direction; to generate AI content you request; to bill you; to respond to you; and to comply with law. We do not sell your personal data. Sensitive customer content is not sent to any AI provider that would train on it — no-training commitments flow down our provider chain.
4. Legal bases (EU/UK GDPR)
Where GDPR applies, we rely on: performance of a contract (to deliver the Services); legitimate interests (to secure and improve the Services); consent (for optional integrations, marketing, and any use of a person’s likeness — see below); and legal obligation. You may withdraw consent at any time.
5. Sharing & subprocessors
We share data only with vendors that help us run the Services, under contract and only as needed. These currently include, by category: cloud & database (Supabase, Fly.io, Cloudflare), AI (Anthropic), payments (Stripe), email (Resend), and — where you enable them — social publishing/analytics aggregators (e.g. Ayrshare, Phyllo) and the official platform APIs you connect. A current subprocessor list is available on request. We also disclose data where required by law.
6. International transfers & data residency
We operate across the U.S., Canada, U.K., E.U., Australia, New Zealand, the GCC (incl. the UAE), and Lebanon, and some vendors are based outside your country. Where required, we use appropriate safeguards (such as Standard Contractual Clauses) and, for regulated work, route data to keep it within the boundaries its rules require.
7. Retention
We keep personal data only as long as needed for the purposes above or as required by law, then delete or anonymize it. Business customers control the retention of data inside their workspace.
8. Your rights
Depending on where you live (GDPR, UK GDPR, UAE PDPL, PIPEDA, CCPA/CPRA, Australia’s Privacy Act, New Zealand’s Privacy Act, and others), you may have the right to access, correct, delete, port, or object to the processing of your data, and to lodge a complaint with your regulator. We do not discriminate against you for exercising these rights.
To delete your data, use our Data Deletion page. For any other request, contact us (below) and we will respond within the time your law requires.
9. Cookies
Our marketing site uses only the cookies necessary to operate it and to understand aggregate usage. We do not use advertising cookies.
10. Security
We protect data with two-factor authentication, least-privilege and row-level access controls, full audit logging, encrypted secrets, and a security review of new capabilities before they run. No system is perfectly secure, but security is our baseline, not a tier.
11. Children
The Services are for businesses and are not directed to children under 16.
12. Changes
We may update this policy; we will change the “last updated” date above and, for material changes, notify account holders.
13. Contact
CUZN Information Technology Innovation Consultants – FZCO, IFZA / Dubai Silicon Oasis, Dubai, UAE. Email: [email protected].