Back to Home
Legal

Privacy Policy

Last Updated: July 2026

1.Introduction

This Privacy Policy explains how Ione Tech Ltd ("IONE", "we", "us", or "our") collects, uses, discloses, and safeguards personal data. IONE is a private company registered with the DIFC Registrar of Companies under Commercial Licence No. CL12931, with its registered office at Unit IH-00-01-01-OF-01, Level 1, Innovation One, Dubai International Financial Centre, Dubai, United Arab Emirates.

This Policy applies to our website and to the IONE TECH platform, APIs, tools, and related software (together, the "Services"). It does not apply to third-party websites, products, or services that we do not control, including any site you reach by following a link from ours.

1.1 Our role. Where we determine why and how personal data is processed — for example, data relating to visitors to our website or to business contacts who make an enquiry — we act as a data controller. Where we process data on behalf of an institutional customer using the Services, that customer determines the purposes and means of processing and acts as the controller, while we act as a processor under our agreement with them. In that case, the customer's own privacy notice governs the processing, and requests from individuals should be directed to the customer.

1.2 Applicable law. We process personal data in accordance with the DIFC Data Protection Law No. 5 of 2020 and its regulations, UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, and, where it applies to a particular processing activity, the EU and UK General Data Protection Regulation.

2.Personal Data We Collect

2.1 Information you provide to us. If you contact us by email, through the contact form on our website, or by telephone, we receive whatever you choose to include — typically your name, email address, company or organisation, and the content of your message. The contact form on our website does not transmit your details to our servers: it opens a pre-filled message in your own email application, and we receive it only if and when you choose to send it.

2.2 Information collected automatically. When you visit our website, our hosting and content delivery providers automatically record standard technical information in server logs, including your IP address, browser type and version, device and operating system, the pages you request, referring URLs, and the date and time of each request. This information is generated by the operation of the internet itself and is used for security, diagnostics, and to keep the site available and performing correctly.

2.3 Information stored on your device. Our tools may store small amounts of information locally in your browser — for example, to remember that you dismissed a prompt to install our calculator as an application. This information remains on your device, is not transmitted to us, and can be cleared at any time through your browser settings.

2.4 Information from third parties. We may receive business contact details from public sources, industry events, referrals, or professional networks where an individual acts in a business capacity.

2.5 Data we do not seek. We do not knowingly collect special categories of personal data (such as data revealing health, biometric identifiers, racial or ethnic origin, political opinions, religious beliefs, or trade union membership) through our website, and we ask that you do not send such information to us unsolicited.

3.How We Use Personal Data

3.1 Purposes. We use personal data to respond to enquiries and correspondence; to provide, operate, maintain, and improve the Services; to administer accounts and contractual relationships with customers and suppliers; to communicate about service availability, security, and changes to terms; to monitor and protect the security and integrity of our systems; to detect, investigate, and prevent fraud, misuse, or unlawful activity; to compile aggregated and anonymised statistics that do not identify any individual; and to comply with legal, regulatory, and record-keeping obligations.

3.2 Marketing. We do not send unsolicited marketing communications through this website. Where we do send business communications to an existing contact, each message will identify us clearly and provide a means of asking us to stop.

3.3 Automated decision-making. We do not use personal data collected through this website to make decisions producing legal or similarly significant effects concerning an individual solely by automated means.

4.Legal Bases for Processing

Where a legal basis is required, we rely on one or more of the following: performance of a contract with you, or steps taken at your request before entering into a contract; our legitimate interests in operating, securing, and improving our business and the Services, where those interests are not overridden by your interests or fundamental rights; compliance with a legal or regulatory obligation to which we are subject; and, where applicable, your consent, which you may withdraw at any time without affecting the lawfulness of processing carried out before withdrawal.

5.Cookies and Similar Technologies

5.1 Our website does not use advertising cookies, analytics cookies, tracking pixels, or third-party profiling technologies, and it does not build behavioural profiles of visitors or share visitor data with advertising networks.

5.2 Certain features rely on strictly necessary technologies that operate on your device — for example, browser storage that remembers a dismissed prompt, and a service worker that caches pages so our calculator continues to work offline. These are essential to the functioning of the features you have chosen to use and do not track you across other websites.

5.3 If we introduce analytics or other non-essential technologies in future, this Policy will be updated and, where the law requires it, your consent will be obtained before they are used.

6.Disclosure of Personal Data

6.1 Service providers. We share personal data with third parties that provide services to us, including cloud hosting and content delivery, email and communications, market data feeds, and professional advisers. These providers act on our instructions under contractual terms requiring them to protect personal data and to use it only for the purposes we specify.

6.2 Legal and regulatory disclosure. We may disclose personal data where we are required to do so by law, regulation, court order, or a lawful request from a competent authority, or where disclosure is necessary to establish, exercise, or defend legal claims, to enforce our terms, or to protect the rights, property, or safety of IONE, our customers, or others.

6.3 Corporate transactions. If we are involved in a merger, acquisition, restructuring, financing, or sale of assets, personal data may be transferred as part of that transaction, subject to the recipient continuing to protect it in a manner consistent with this Policy.

6.4 We do not sell personal data, and we do not rent or trade it to third parties for their own marketing purposes.

7.International Transfers

Our service providers, including our hosting and content delivery providers, operate infrastructure in multiple countries, and personal data may therefore be processed outside the DIFC and the United Arab Emirates. Where personal data is transferred to a jurisdiction that is not recognised as providing an adequate level of protection, we put in place an appropriate transfer mechanism — such as standard contractual clauses or another safeguard recognised under applicable law — so that the data continues to be protected. Further information about the safeguards applied is available on request.

8.Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, regulatory, or reporting requirements, and to establish, exercise, or defend legal claims. Correspondence and enquiry records are retained for as long as needed to deal with the matter and for a reasonable period afterwards. Server logs are retained for a limited period for security and diagnostic purposes. When personal data is no longer required, it is deleted or irreversibly anonymised.

9.Security

We implement appropriate technical and organisational measures designed to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, or damage. These include encryption of data in transit, strict transport security, access controls and least-privilege principles, network and platform hardening, and regular review of our systems and providers.

No method of transmission over the internet or method of electronic storage is completely secure. While we work to protect personal data, we cannot guarantee absolute security, and any transmission is at your own risk. If a personal data breach occurs that is likely to result in a risk to individuals, we will notify the relevant supervisory authority and affected individuals where required by applicable law.

10.Your Rights

10.1 Subject to applicable law and to any exemptions that apply, you have the right to request access to the personal data we hold about you; to request correction of data that is inaccurate or incomplete; to request erasure of data where there is no continuing lawful basis for us to hold it; to request restriction of processing in certain circumstances; to object to processing carried out on the basis of our legitimate interests; to receive certain data in a structured, commonly used, machine-readable format and to have it transmitted to another controller; and to withdraw consent where processing is based on consent.

10.2 To exercise any of these rights, contact us using the details in section 14. We may ask for information to verify your identity before acting on a request. We will respond within the period required by applicable law. There is normally no charge, although we may charge a reasonable fee or decline to act where a request is manifestly unfounded or excessive.

10.3 If you are dissatisfied with how we have handled your personal data or your request, you may lodge a complaint with the DIFC Commissioner of Data Protection or with the supervisory authority in your country of residence.

11.Children's Privacy

The Services are intended for institutional and business users and are not directed at children. We do not knowingly collect personal data from anyone under the age of 18. If you believe a child has provided us with personal data, contact us and we will take steps to delete it.

12.Third-Party Links and Services

Our website may link to third-party websites, documentation, or tools that we do not operate. We are not responsible for the privacy practices or content of those third parties, and this Policy does not apply to them. We encourage you to read the privacy notice of any third-party site you visit.

13.Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, the Services, or applicable law. The date below indicates when it was last revised. Where a change is material, we will take reasonable steps to bring it to your attention. Continued use of the Services after a revision takes effect constitutes acknowledgement of the updated Policy.

14.Contact Us

For questions about this Policy, to exercise any of the rights described above, or to raise a concern about how we handle personal data, contact us at:

Ione Tech Ltd Commercial Licence No. CL12931 (DIFC Registrar of Companies) Unit IH-00-01-01-OF-01, Level 1, Innovation One Dubai International Financial Centre Dubai, United Arab Emirates Telephone: +971 4 580 9923 Email: info@ionetech.io Website: ionetech.io