Skip to content

Privacy Policy

Published August 24, 2026

Last updated August 24, 2026

This Privacy Policy describes how Aubrium Technologies L.L.C ("Aubrium", "we", "us" or "our") collects, uses, discloses, transfers, secures and retains personal data in connection with the website, platform and services which it operates (the "Services"), and sets out the rights available to individuals in respect of that data.

This Privacy Policy forms part of, and is to be read together with, the Terms of Use and the Cookie Policy. Capitalised terms which are not defined in this Privacy Policy have the meanings given to them in the Terms of Use.

1. Scope and application

1.1 This Privacy Policy applies to personal data processed by Aubrium in connection with: (a) the Aubrium website; (b) the Aubrium platform and the tools made available through it; (c) pages published by users of the Services and hosted by Aubrium; (d) correspondence between Aubrium and any individual; and (e) any other activity in which Aubrium determines the purposes and means of processing.

1.2 This Privacy Policy does not apply to: (a) any Social Platform or other third-party service, whether or not accessed through the Services; (b) any website or destination reached by following a link from a page hosted by Aubrium; (c) any processing carried out by a user of the Services acting as a controller in its own right; or (d) any processing carried out by a payment provider for its own regulatory or compliance purposes.

1.3 Aubrium is the controller of the personal data described in this Privacy Policy, save as provided in clause 1.4.

1.4 Where a user uses the Services to process personal data relating to its own clients, customers or contacts, that user is the controller of that personal data and Aubrium acts as a processor upon its documented instructions. In those circumstances the user is responsible for establishing a lawful basis for the processing, for providing any notice required to the individuals concerned, and for the accuracy and lawfulness of the data supplied to Aubrium. Where required by applicable data protection law, the parties will enter into a data processing agreement in a form provided by Aubrium.

1.5 Where Aubrium and another party each determine the purposes and means of a processing operation, they act as joint controllers only to the extent expressly agreed in writing between them.

2. Definitions

2.1 In this Privacy Policy:

"applicable data protection law" means all legislation relating to the protection of personal data applicable to the processing described in this Privacy Policy, including Federal Decree-Law No. 45 of 2021 of the United Arab Emirates, the General Data Protection Regulation (EU) 2016/679, the United Kingdom General Data Protection Regulation and the Data Protection Act 2018, and the privacy statutes of the individual states of the United States.

"controller" means the person which determines the purposes and means of the processing of personal data.

"personal data" means information relating to an identified or identifiable natural person.

"processing" means any operation performed on personal data, including collection, recording, organisation, storage, adaptation, retrieval, use, disclosure, restriction, erasure and destruction.

"processor" means a person which processes personal data on behalf of a controller.

"special category data" means personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, together with genetic data, biometric data processed for the purpose of uniquely identifying a natural person, data concerning health, and data concerning a natural person's sex life or sexual orientation.

"supervisory authority" means an authority competent under applicable data protection law to supervise the processing of personal data.

3. Categories of personal data

3.1 Identity and contact data. Name; email address; telephone number where provided for the purpose of account security; postal or billing address where provided; the name and registered details of an entity on whose behalf an individual acts; and any other identifying information voluntarily provided.

3.2 Account and authentication data. Account identifier; credentials held in hashed form; authentication factors and their configuration; records of sign-in and sign-out; records of active sessions and of the devices from which the Account has been accessed; account status, role and permission; and preferences and settings.

3.3 Social media profile data. The username of a social media profile provided by an individual for the purpose of configuring the Services, and publicly available information relating to that profile and to the content published on it, as further described in clause 4.

3.4 Transaction and financial data. Records of additions to the Balance and of deductions from it; orders placed; the amount, currency, date, status and reference of each payment; the type of payment instrument, its issuing country, its expiry and the last four digits of a payment card; a token representing a stored payment instrument; records of refunds, disputes and chargebacks; and invoices and receipts. Full card numbers and card security codes are not received or stored by Aubrium.

3.5 Content data. Material submitted to the Services, including text entered, files and images uploaded, configuration and settings, drafts, and pages created for publication.

3.6 Usage and technical data. Internet protocol address; device, operating system and browser characteristics; screen and viewport characteristics; language and locale; time zone; referring source; the pages, features and functions accessed and the date and time of access; the duration and sequence of activity; and diagnostic information relating to errors, latency and performance.

3.7 Security and fraud prevention data. Records of authentication attempts, including failed attempts; indicators of risk associated with an internet protocol address, a device, an email address or a payment instrument; signals used to distinguish a genuine user from automated traffic; the frequency and pattern of payment attempts; and records of investigation into suspected fraud, abuse or unauthorised access.

3.8 Artificial intelligence data. Material submitted to a feature employing artificial intelligence, material generated by such a feature, and associated records of use including the model applied and the volume of processing.

3.9 Support and correspondence data. The content of enquiries, support requests and correspondence, any attachment provided, and records of the communications sent by Aubrium and of their delivery.

3.10 Marketing data. Contact details, preferences and consents relating to marketing communications, and records of interaction with those communications.

3.11 Special category data. Aubrium does not seek to collect special category data, and the Services are not designed to receive or process it. Individuals must not submit special category data, financial account numbers, payment credentials, government identifiers or comparable sensitive information to the Services except where a feature is expressly designed to receive it.

4. Publicly available social media data

4.1 Where an individual provides the username of a social media profile, or requests the analysis of a publicly accessible profile or item of content, Aubrium processes information which is publicly available on the relevant Social Platform. That information may include profile details, audience and interaction counts, captions and descriptions, published media, and metrics relating to the performance of published content.

4.2 Aubrium does not request, require, receive or store the login credentials of any Social Platform, and does not access a private account, a private message, or any material which requires authentication to a Social Platform.

4.3 Publicly available social media data is obtained through data providers engaged by Aubrium. Those providers receive the username in respect of which information is requested. They do not receive account, contact or payment data relating to the individual making the request.

4.4 Where an individual uses the Services to analyse a publicly accessible profile belonging to another person, Aubrium processes that publicly available information on the instruction of the individual making the request and for the purpose of producing the analysis requested.

4.5 A person whose publicly available social media information has been processed by the Services may exercise the rights described in clause 14 in respect of that information.

5. Sources of personal data

5.1 From the individual directly, when an account is registered, information is entered or updated, a payment is made, content is submitted, a form is completed, or contact is made with Aubrium.

5.2 Automatically, when the Services are accessed, by means of server logs, cookies and comparable technologies, and analytics, performance and security tooling. The Cookie Policy describes those technologies.

5.3 From publicly available sources, as described in clause 4.

5.4 From service providers, including the outcome of a payment and the associated risk indicators from payment and fraud prevention providers, and delivery outcomes from the provider of transactional email.

5.5 From a user of the Services, where that user submits personal data relating to a third party in the circumstances described in clause 1.4.

6. Purposes of processing

6.1 Provision of the Services. To create, administer, secure and authenticate accounts; to make available the tools and features selected; to store and render content; to generate the analysis, reporting and output requested; to coordinate and fulfil orders; and to make available pages published by users.

6.2 Payment. To process additions to the Balance; to deduct Fees; to maintain a record of the Balance; to issue invoices and receipts; to process refunds; and to respond to disputes and chargebacks.

6.3 Support and communication. To respond to enquiries; to provide customer support; to send service, transactional, security and administrative communications; and to notify individuals of changes to the Services or to these policies.

6.4 Security, fraud prevention and enforcement. To protect the Services, accounts and payments; to detect, investigate, prevent and address fraud, payment abuse, account takeover, unauthorised access, and breach of the Terms of Use or the Acceptable Use Policy; to enforce those documents; and to maintain records relating to enforcement.

6.5 Maintenance and improvement. To monitor and maintain the availability, performance, reliability and usability of the Services; to identify and diagnose faults; to conduct testing; to understand how features are used; and to develop new and improved features.

6.6 Marketing. To send marketing communications where consent has been given or where applicable law otherwise permits, and to measure their effectiveness.

6.7 Legal and regulatory compliance. To comply with obligations arising under tax, accounting, corporate, anti-money-laundering, sanctions and consumer protection law; to comply with the rules of payment schemes; to respond to lawful requests from competent authorities; and to maintain the records required by applicable law.

6.8 Legal claims and corporate transactions. To establish, exercise and defend legal claims; to obtain legal, accounting and insurance advice; and to carry out a merger, acquisition, financing, reorganisation or sale of assets.

6.9 Aubrium does not process personal data for any purpose incompatible with those described in this clause 6. Where Aubrium proposes to process personal data for a new and incompatible purpose, it will provide notice and, where required, obtain consent.

6.10 Aubrium may create anonymised and aggregated data from personal data. Such data does not identify any individual, is not personal data, and may be used for any lawful purpose including analysis, reporting, benchmarking and the improvement and promotion of the Services.

7. Legal bases for processing

7.1 Where applicable data protection law requires a legal basis for processing, Aubrium relies upon the bases set out in this clause 7.

7.2 Performance of a contract. Processing necessary for the performance of the contract between Aubrium and the individual, or in order to take steps at the individual's request before entering into that contract. This basis applies to the purposes described in clauses 6.1, 6.2 and 6.3.

7.3 Legitimate interests. Processing necessary for the purposes of the legitimate interests pursued by Aubrium or by a third party, being the interests in maintaining the security and integrity of the Services and of user accounts, in preventing fraud and financial loss, in enforcing the Terms of Use, in maintaining and improving the Services, in developing the business, in communicating with users about the Services, and in establishing and defending legal claims. This basis applies to the purposes described in clauses 6.4, 6.5, 6.6 where permitted, and 6.8.

7.4 In relying upon legitimate interests, Aubrium has in each case assessed whether those interests are overridden by the interests, rights and freedoms of the individuals concerned, having regard to the nature of the data, the reasonable expectations of those individuals, and the safeguards applied. Further information concerning that assessment is available on request.

7.5 Compliance with a legal obligation. Processing necessary for compliance with a legal obligation to which Aubrium is subject. This basis applies to the purposes described in clauses 6.7 and, in part, 6.4.

7.6 Consent. Processing carried out with the individual's consent, where consent is required by applicable law, including in respect of certain marketing communications and of cookies which are not strictly necessary. Consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

7.7 Where more than one basis applies to a processing operation, Aubrium may rely upon each of them.

8. Payment data

8.1 Card details are captured within a field operated by a specialist payment provider and are transmitted from that provider to the payment processor. Payment providers engaged by Aubrium for that purpose are certified to PCI DSS Level 1.

8.2 Aubrium does not receive, store or log a full card number or a card security code. Those details do not reach Aubrium's systems, logs or backups.

8.3 Where an individual elects to retain a payment instrument for future use, Aubrium stores a token issued by the payment provider. That token permits a further charge to the instrument and does not permit the card number to be derived.

8.4 Payment providers process personal data both as processors on Aubrium's instructions and, in respect of their own regulatory, fraud prevention and compliance obligations, as independent controllers. Their own privacy notices apply to the latter processing.

9. Artificial intelligence

9.1 Certain features of the Services employ artificial intelligence supplied by third-party model providers.

9.2 Where such a feature is used, the material submitted to it, together with any publicly available content processed by that feature on the user's instruction, is transmitted to the relevant model provider for the sole purpose of generating a result in response to the request. Each provider processes that material in accordance with its own terms.

9.3 Aubrium does not use material submitted to those features to train its own models, and does not license, sell or otherwise make it available to any person for that purpose.

9.4 Individuals must not submit to those features any confidential information, any personal data relating to another individual which they are not entitled to disclose, or any information falling within clause 3.11.

9.5 Aubrium retains records of the use of those features for the purposes of providing the feature, enabling material generated to be retrieved, calculating Fees, providing support, and detecting and investigating abuse.

9.6 The AI Policy contains further provisions concerning the use of those features.

10. Disclosure of personal data

10.1 Aubrium does not sell personal data and does not disclose personal data to data brokers. Where cookies and comparable technologies are used for advertising and conversion measurement, that use is described in the Cookie Policy and in clause 11.

10.2 Service providers. Aubrium discloses personal data to third parties engaged to perform functions on its behalf, comprising: providers of hosting, storage, content delivery and infrastructure; providers of card security and payment processing; providers of transactional email; providers of analytics and product measurement, including Google and PostHog; providers of fraud prevention, risk scoring, identity verification and bot detection; providers of artificial intelligence models; providers of data relating to publicly accessible social media profiles; and providers of internal support and operational tooling.

10.3 Each service provider is engaged under a written agreement which: permits it to process personal data only upon Aubrium's documented instructions and for the purpose of providing its service; imposes obligations of confidentiality upon its personnel; requires appropriate technical and organisational security measures; restricts onward transfer and the engagement of further sub-processors; and requires the deletion or return of personal data on termination.

10.4 Information about certain key service providers used by Aubrium is available in our Trust Center.

10.5 Fulfilment of orders. Where a user places an order requiring coordination with a network of participating creators, the reference to the publicly accessible content concerned and the parameters of the order are disclosed to the partner coordinating that network. Account details, contact details and payment data are not disclosed for that purpose.

10.6 Payment providers and card schemes. Aubrium discloses personal data to the extent required to process a payment, refund or dispute, and to respond to a chargeback in accordance with scheme rules.

10.7 Professional advisers and insurers. Aubrium discloses personal data to lawyers, accountants, auditors, insurers and comparable advisers, in each case where necessary and subject to duties of confidentiality.

10.8 Legal and regulatory disclosure. Aubrium discloses personal data where disclosure is required by applicable law, by a competent authority, by a court order or other valid legal process, or by the rules of a payment scheme; or where Aubrium considers, acting reasonably, that disclosure is necessary in order to prevent or investigate fraud or unlawful activity, to enforce the Terms of Use, or to protect the rights, property or safety of Aubrium, of its users or of the public.

10.9 Where Aubrium receives a request for disclosure from an authority, it reviews the request for validity, discloses only such personal data as is within its scope, and maintains a record of the disclosure. Where Aubrium is lawfully permitted to notify the affected individual, it will do so.

10.10 Corporate transactions. Aubrium may disclose personal data to a prospective or actual purchaser, investor, lender or successor in connection with a merger, acquisition, financing, reorganisation or sale of assets, subject to appropriate confidentiality undertakings and to the continued application of this Privacy Policy or of an equivalent notice.

10.11 With consent. Aubrium may disclose personal data to any other person with the individual's consent.

10.12 At the user's direction. Where a user publishes content through the Services, that content is made available to the persons to whom the user has made it accessible. A user which publishes personal data through the Services does so as controller of that data.

11. Cookies and comparable technologies

11.1 Aubrium uses cookies, local storage and comparable technologies for purposes which are strictly necessary to the operation and security of the Services, for the recording of preferences, for analytics and performance measurement, for advertising and conversion measurement, and for the prevention of fraud.

11.2 The Cookie Policy describes the categories used and the means by which preferences may be managed.

11.3 Cookies which are not strictly necessary may be blocked or deleted by means of the browser controls described in the Cookie Policy, and an objection may be raised by contacting Aubrium using the details in clause 25.

11.4 Aubrium does not sell data collected by means of cookies.

12. Automated decision-making

12.1 Aubrium operates automated controls which may, without individual human review at the time the decision is taken: decline or delay a payment; restrict the ability to add funds or to place orders; require the completion of a verification step before access is granted; refuse or filter a request submitted to a feature employing artificial intelligence; or restrict access to content published through the Services pending review.

12.2 Those controls operate by reference to indicators including the response of a payment provider, risk scores relating to an internet protocol address, a device or a payment instrument, the frequency and pattern of attempts, records of previous enforcement, and automated assessment of content.

12.3 Those controls are necessary for the entry into and the performance of the contract between Aubrium and the user, and for compliance with Aubrium's obligations to payment providers and under applicable law.

12.4 An individual in respect of whom such a decision is taken may obtain human intervention, may express their point of view, may obtain an explanation of the decision, and may contest it, by contacting Aubrium in accordance with clause 15. A review is conducted by a person who was not involved in the automated decision.

12.5 Aubrium does not carry out profiling for the purpose of evaluating personal aspects relating to an individual otherwise than as described in this clause 12.

13. International transfers

13.1 Aubrium is established in the United Arab Emirates. Aubrium and the service providers which it engages process personal data in the United Arab Emirates, the European Economic Area, the United Kingdom, the United States and other jurisdictions in which those providers operate.

13.2 Where personal data is transferred from a jurisdiction which restricts international transfer to a jurisdiction which is not the subject of a finding of adequacy, Aubrium relies upon one or more of the following: standard contractual clauses approved by the competent authority, supplemented where necessary by additional technical, organisational and contractual measures; the safeguards permitted under the data protection law of the United Arab Emirates; binding corporate rules where applicable; or a derogation permitted by applicable data protection law.

13.3 Aubrium assesses, in respect of each transfer, whether the law and practice of the destination jurisdiction is liable to impinge upon the effectiveness of the safeguard relied upon, and applies supplementary measures where appropriate.

13.4 A description of the safeguards applicable to a specific transfer, and a copy of the relevant clauses, may be obtained on request.

14. Retention

14.1 Personal data is retained only for so long as is necessary for the purposes for which it was collected, including for the purpose of satisfying a legal, accounting, tax or reporting requirement, or for the establishment, exercise or defence of legal claims.

14.2 In determining an appropriate retention period Aubrium has regard to the nature, scope and sensitivity of the personal data; the potential risk of harm arising from unauthorised use or disclosure; the purposes for which it is processed and whether those purposes can be achieved by other means; the reasonable expectations of the individuals concerned; and the requirements of applicable law.

14.3 Account records are retained for the duration of the account. Records of transactions, invoices and tax documentation are retained for the period prescribed by the applicable tax, accounting and corporate legislation. Records relating to fraud, disputes, enforcement and blocked access are retained for so long as is necessary to prevent recurrence and to defend claims. Technical, diagnostic and security logs are retained for a limited period appropriate to their purpose. Content and material generated through the Services is retained for the duration of the account unless deleted earlier by the user.

14.4 Where personal data is no longer required for any purpose described in this Privacy Policy, it is deleted or irreversibly anonymised.

14.5 Backups are retained on a rolling basis and are overwritten in the ordinary course. Personal data deleted from the live environment may persist in a backup until that backup is overwritten, during which period it is not used for any purpose other than restoration.

14.6 Upon closure of an account, Aubrium removes or anonymises the personal data by which the account holder is identified. Certain transaction, fraud prevention, compliance and legal records may continue to contain personal data, where their retention is necessary for the establishment, exercise or defence of legal claims, for the prevention of fraud and of abuse of the Services, or where retention is required by applicable law. Closure of an account cannot be reversed.

15. Security

15.1 Aubrium implements technical and organisational measures appropriate to the risk presented by the processing, having regard to the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing.

15.2 Those measures include: the encryption of personal data in transit and at rest; controls restricting access to those personnel who require it for the performance of their duties; the logging of administrative activity; the segregation of production from non-production environments; the management of credentials within controlled systems; and documented processes for the detection, assessment, containment and reporting of security incidents.

15.3 Personnel with access to personal data are subject to obligations of confidentiality and receive instruction appropriate to their role. Access is withdrawn upon a change of role or on departure.

15.4 Card details are handled by payment providers certified to PCI DSS Level 1 and are not received by Aubrium.

15.5 No system of information security can be guaranteed to be impenetrable. Individuals are responsible for maintaining the confidentiality of their credentials, for enabling the security features made available, and for the security of the devices from which they access the Services.

15.6 Where a personal data breach occurs which is likely to result in a risk to the rights and freedoms of individuals, Aubrium notifies the competent supervisory authority within the period prescribed by applicable data protection law, and, where the breach is likely to result in a high risk, notifies the affected individuals without undue delay.

16. Rights of individuals

16.1 Subject to applicable data protection law and to the conditions, limitations and exemptions for which that law provides, an individual has the following rights in respect of their personal data.

16.2 Right of access. To obtain confirmation as to whether personal data concerning them is processed and, where it is, to obtain a copy of that personal data together with information as to the purposes of the processing, the categories of data concerned, the recipients, the retention period, the source of the data, and the existence of the other rights described in this clause.

16.3 Right to rectification. To obtain without undue delay the correction of inaccurate personal data and the completion of incomplete personal data.

16.4 Right to erasure. To obtain the deletion of personal data where it is no longer necessary for the purposes for which it was collected, where consent is withdrawn and no other basis applies, where the individual objects and no overriding legitimate ground exists, where the data has been unlawfully processed, or where erasure is required for compliance with a legal obligation. This right does not extend to personal data which Aubrium is required to retain by law, which is necessary for the establishment, exercise or defence of legal claims, or which is necessary for the prevention of fraud and of abuse of the Services.

16.5 Right to restriction of processing. To obtain the restriction of processing where the accuracy of the personal data is contested, where the processing is unlawful and the individual opposes erasure, where Aubrium no longer requires the data but the individual requires it for a legal claim, or pending verification of an objection.

16.6 Right to object. To object at any time, on grounds relating to their particular situation, to processing carried out on the basis of legitimate interests, in which case Aubrium will cease that processing unless it demonstrates compelling legitimate grounds which override the interests, rights and freedoms of the individual, or the processing is necessary for a legal claim. An individual may object at any time, and without giving reasons, to processing for the purposes of direct marketing, in which case Aubrium will cease that processing.

16.7 Right to data portability. To receive personal data which the individual has provided to Aubrium, in a structured, commonly used and machine-readable format, and to transmit that data to another controller, where the processing is based upon consent or upon a contract and is carried out by automated means.

16.8 Right to withdraw consent. To withdraw consent at any time where processing is based upon consent, without affecting the lawfulness of processing carried out before withdrawal.

16.9 Rights in relation to automated decisions. As described in clause 12.4.

16.10 Right to lodge a complaint. To lodge a complaint with a competent supervisory authority. In the United Arab Emirates, that authority is the UAE Data Office. In the European Economic Area or the United Kingdom, it is the supervisory authority of the individual's habitual residence, place of work, or the place of the alleged infringement. Aubrium requests the opportunity to address any concern before a complaint is made.

17. Exercising rights

17.1 The Services provide facilities within account settings by which an account holder may obtain a copy of the personal data held in respect of their account, and by which an account may be closed and the personal data within it anonymised.

17.2 Any other request may be submitted to legal [at] aubrium.com, and should be sent from the email address recorded on the account where the individual holds one.

17.3 Aubrium may request such information as is reasonably necessary to verify the identity of the person making a request and, where the request is made by an agent, evidence of that agent's authority. Aubrium may decline to act upon a request where identity or authority cannot be verified.

17.4 Aubrium responds to a request within thirty (30) days of receipt, or within such longer period as applicable law permits where the request is complex or where a number of requests have been received, in which case Aubrium will notify the individual of the extension and of the reasons for it within the initial period.

17.5 No fee is charged in respect of a request, unless the request is manifestly unfounded or excessive, in particular by reason of its repetitive character, in which case Aubrium may charge a reasonable fee reflecting its administrative costs or may decline to act.

17.6 Where Aubrium declines to act upon a request, it will inform the individual of the reasons and of the right to lodge a complaint with a supervisory authority and to seek a judicial remedy.

17.7 No individual will be subjected to discriminatory treatment by reason of having exercised a right described in this Privacy Policy or conferred by applicable data protection law.

18. Marketing communications

18.1 Aubrium sends service, transactional, security and administrative communications which are necessary to the operation of an account. Those communications form part of the Services and cannot be declined while the account remains open.

18.2 Marketing communications are sent only where consent has been given, or where applicable law otherwise permits their transmission to an existing customer in respect of similar services.

18.3 Marketing communications may be declined at any time by means of the facility contained within each such communication, by amendment of account settings, or by contacting Aubrium. A request to cease marketing communications is actioned without undue delay.

19. Children

19.1 The Services are intended for and directed exclusively to persons who are at least eighteen (18) years of age.

19.2 Aubrium does not knowingly collect personal data relating to a person below that age. Where Aubrium becomes aware that it holds such data, it will delete it without undue delay and will close any associated account.

19.3 A parent or guardian who believes that a child has provided personal data to Aubrium should contact legal [at] aubrium.com.

20. Visitors to pages hosted by Aubrium

20.1 Where a user of the Services publishes a page which is hosted by Aubrium, Aubrium records the fact that the page was viewed and that a link was followed, together with limited technical information comprising an approximate location derived from internet protocol address, the referring source, and a general indication of device type.

20.2 That data is processed on the basis of Aubrium's legitimate interest in measuring and securing the pages which it hosts, and in providing aggregate statistics to the user who published the page.

20.3 The user who published the page receives aggregate counts and trends only. That user does not receive from Aubrium the internet protocol address of any visitor, nor any other means by which an individual visitor may be identified.

20.4 Aubrium does not track visitors across unrelated websites and does not use data collected from hosted pages for advertising purposes.

20.5 A destination reached by following a link from a hosted page is operated by a third party, whose own privacy practices apply to any processing which it carries out.

21. Third-party services and links

21.1 The Services may contain links to, or integrate with, websites and services operated by third parties. Aubrium does not control those websites and services and is not responsible for their content or for their processing of personal data.

21.2 Where an individual elects to connect a third-party service to the Services, the processing carried out by that third party is governed by its own privacy notice.

22. Accuracy and the individual's obligations

22.1 Individuals are responsible for ensuring that the personal data which they provide to Aubrium is accurate and current, and for updating it when it changes.

22.2 Where an individual submits personal data relating to another person, that individual represents that it is entitled to do so and that the necessary notice has been given and, where required, consent obtained.

23. Additional regional disclosures

23.1 United Arab Emirates. Aubrium processes personal data in accordance with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and its implementing legislation. The rights described in clause 16 include the rights conferred by that legislation, and a complaint may be made to the UAE Data Office.

23.2 European Economic Area and United Kingdom. Where the General Data Protection Regulation or the United Kingdom General Data Protection Regulation applies to the processing, the legal bases described in clause 7 are those provided by Article 6 of the relevant Regulation, the rights described in clause 16 are those provided by Chapter III, and the transfer safeguards described in clause 13 apply. Aubrium does not carry out processing which requires the designation of a data protection officer under Article 37.

23.3 United States. Where a state privacy statute applies to the processing: Aubrium does not sell personal information as that term is defined in the applicable statute; where personal information is shared for cross-context behavioural advertising within the meaning of that statute, a resident may exercise the right to opt out by contacting Aubrium using the details in clause 25; Aubrium does not process sensitive personal information for a purpose which would give rise to a right to limit; residents of those states may exercise the rights of access, correction, deletion, portability and non-discrimination described in clause 16 by the means described in clause 17; an authorised agent may submit a request upon production of evidence of authority; and an individual may appeal a decision declining a request by writing to legal [at] aubrium.com, in which case Aubrium will respond within the period prescribed by the applicable statute.

23.4 Where the requirements of a regional supplement conflict with the general provisions of this Privacy Policy, the regional supplement prevails in respect of individuals to whom it applies.

24. Amendment

24.1 Aubrium may amend this Privacy Policy from time to time in order to reflect a change in the Services, in its practices, or in applicable law.

24.2 An amendment takes effect upon publication of the amended Privacy Policy, save that where an amendment is material Aubrium will give notice by email or by notice within the Services before it takes effect.

24.3 The date upon which this Privacy Policy was last amended is shown at the head of this page. Aubrium retains previous versions and will provide a copy on request.

25. Contact

25.1 Enquiries, requests and complaints concerning this Privacy Policy or the processing of personal data may be addressed to:

AUBRIUM TECHNOLOGIES L.L.C

Iris Bay Tower

Business Bay, Dubai

United Arab Emirates, 35866

Data protection: legal [at] aubrium.com

General enquiries: support [at] aubrium.com

Legal notices: legal [at] aubrium.com