Version 2026-07-25-v1 · Forms part of the Terms & Conditions (§6.3) · Between HIBR e trade (trading as Hibr AI), Sharjah, United Arab Emirates (“HIBR”) and the customer accepting the Terms (“Customer”).
For personal data that Customer submits or directs into the Services, Customer is the controller and HIBR is the processor. Customer decides why and how that data is processed; HIBR processes it only on Customer's documented instructions, which are given by Customer's configuration and use of the Services and by this DPA.
For HIBR's own business data — Customer's account, billing and support records — HIBR is the controller, and its Privacy Policy applies.
| Subject matter | Provision of the Services described in the Terms and any order. |
|---|---|
| Duration | For as long as Customer's subscription or engagement is active, plus the retention period in Section 8. |
| Nature & purpose | Receiving, storing, analysing and scoring content and records that Customer sends into the Services; generating outputs; and delivering those outputs to destinations Customer configures. |
| Categories of data subjects | Customer's own leads, prospects, customers, contacts, and staff — i.e. individuals whose data Customer chooses to submit. |
| Categories of personal data | Typically identifiers and business-contact data (name, email, company, role, phone) and free-text a person supplies (their enquiry or message), plus metadata such as source and timestamp. |
| Special-category data | Not permitted. Customer must not submit special-category or sensitive personal data (health, biometric, religious, political, criminal, financial-account, or children's data). The Services are not designed for it and HIBR does not apply the additional controls such data requires. |
Before content is sent to an AI provider for scoring, HIBR automatically strips fields that look like sensitive identifiers — phone, address, national ID, passport, bank and card numbers, salary and location coordinates — and caps the number and length of fields passed. This runs on every request; it is not an option a customer has to enable.
HIBR does not currently hold ISO 27001 or SOC 2 certification and does not claim to.
Customer gives general authorisation for HIBR to engage sub-processors. The current list, with what each one does and where it is located, is published at hibr.ai/subprocessors. HIBR imposes data-protection obligations on each sub-processor no less protective than this DPA and remains responsible for their performance.
HIBR will give at least 30 days' notice before adding or replacing a sub-processor. If Customer has a reasonable data-protection objection, the parties will work in good faith to resolve it; if they cannot, Customer may terminate the affected Service and receive a pro-rata refund of prepaid fees.
Customer Data is processed outside the UAE. Production systems are hosted in the United Kingdom (Hostinger) and AI processing is performed in the United States (Anthropic). HIBR relies on the transfer mechanisms permitted under UAE Federal Decree-Law No. 45 of 2021 (PDPL), including contractual safeguards with each recipient and, where required, Customer's consent. Where a Customer or its data subjects are covered by the EU/UK GDPR, HIBR will enter into Standard Contractual Clauses on request.
If Customer requires data residency inside the UAE, HIBR cannot meet that on its standard Services.
If an individual contacts HIBR directly about data HIBR holds on Customer's behalf, HIBR will not respond substantively — it will refer them to Customer and notify Customer without undue delay. HIBR will assist Customer in responding, including by providing, correcting or deleting the relevant records.
Some Services score or rank individuals (for example lead scoring). HIBR's scoring is designed so that a human can inspect and override any score, and every score carries the reasoning behind it. Customer is responsible for ensuring that how it uses those scores complies with applicable law, and for not using them to make a decision with legal or similarly significant effects on a person without human review.
HIBR will notify Customer without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Data, with the information available at the time — what happened, the categories and approximate volume affected, likely consequences, and the steps taken. HIBR will cooperate with Customer's own regulatory notifications.
On reasonable written notice, no more than once a year (or after a breach), HIBR will provide the information reasonably necessary to demonstrate compliance with this DPA. Given HIBR's size, this takes the form of written responses and evidence rather than an on-site inspection.
This DPA is governed by the laws of the United Arab Emirates as applied in the Emirate of Sharjah, and disputes are subject to the exclusive jurisdiction of the Sharjah Courts, matching Section 16 of the Terms.
Questions, a signed counterpart, SCCs, or a data request: info@hibr.ai.
← Back to Terms & Conditions