Privacy Policy

Spry Insights FZ-LLC — covering Spry Insights research services and the AIRA platform

Version 1.0  |  Effective date: 8 July 2026

Approved by: Vaibhav Sharma, Chief Executive Officer


1. Introduction

Spry Insights FZ-LLC ("Spry Insights", "we", "us" or "our"), a free zone limited liability company registered in Dubai, United Arab Emirates (License No. 107824), with its registered office at In5 Tech - HD16C, Dubai Internet City, Dubai, U.A.E., operates market research and data analytics services, the websites spryinsights.com and spryaira.com, and the AIRA intelligence platform (collectively, the "Services").

This Privacy Policy describes how we collect, use, disclose and protect personal data in the course of providing the Services. We process personal data in accordance with applicable data protection laws, including the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) and, where applicable to our clients and research activities, the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) and other regional privacy laws such as the Malaysian Personal Data Protection Act 2010 (PDPA) when conducting studies involving data subjects in those jurisdictions.

2. Personal Data We Collect

2.1 Clients and platform users

  • Account and contact data: name, business email address, phone number, company, job title and account credentials.
  • Commercial data: billing details, contract and engagement records.
  • Project data: research briefs, survey designs, study configurations, project notes and correspondence.
  • Usage data: platform activity logs, device and browser information, IP address.

2.2 Research respondents and panel participants

  • Survey responses, opinions and open-ended feedback provided with the respondent's consent.
  • Demographic and screening data (e.g., age band, gender, location, occupation) used for sampling and quota control.
  • Behavioural research data collected in the course of a study, where disclosed and consented at the point of collection.
  • Audio/video recordings from qualitative research (interviews, focus groups), only with explicit prior consent.

2.3 Website visitors

  • Cookies and similar technologies, analytics identifiers and pages visited. Non-essential cookies are used only with consent where required by law.

3. How We Use Personal Data

  • To deliver the Services: design, field and analyse market research studies and produce reports and insights.
  • To operate, secure and improve the AIRA platform, including quality control and fraud detection in fieldwork.
  • To manage client relationships, billing and support.
  • To comply with legal and regulatory obligations.

Research outputs are aggregated. Deliverables provided to clients contain aggregated and/or anonymised findings. We do not provide clients with identifiable respondent data unless the respondent has given explicit consent for that purpose.

4. Legal Bases for Processing

Where the GDPR or similar laws apply, we rely on: (a) consent — for research participation, recordings and non-essential cookies; (b) performance of a contract — for client account and engagement data; (c) legitimate interests — for service improvement, security and fraud prevention, balanced against data subjects' rights; and (d) legal obligation — where processing is required by applicable law.

5. Sharing and Sub-Processors

We do not sell personal data. We share personal data only with:

  • Amazon Web Services (AWS) — cloud infrastructure and in-environment AI services (ISO 27001, ISO 27017, SOC 1/2/3, CSA STAR certified). Data is encrypted in transit and at rest.
  • NeoSapients Inc. — AI governance and data-minimisation layer that ensures data remains within the designated secure AWS environment and that only the data required for a given task is accessed (ISO 27001 certified).
  • Vetted respondent panel providers — for sample sourcing, under contractual data protection obligations.
  • Professional advisers, and public authorities where disclosure is required by law.

All sub-processors are bound by written agreements imposing data protection obligations consistent with this Policy.

6. International Transfers

Personal data is hosted in designated AWS regions selected per engagement. Where personal data is transferred across borders, we apply safeguards required by applicable law, including transfer mechanisms recognised under the UAE PDPL and, where relevant, EU Standard Contractual Clauses or equivalent protections.

7. Security

We apply industry-standard technical and organisational measures, including:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256 via AWS KMS)
  • Least-privilege role-based access control with multi-factor authentication
  • Continuous security monitoring and logging (AWS CloudTrail, GuardDuty, WAF)
  • Documented incident response procedures with notification of affected parties without undue delay (target within 72 hours of confirmation)
  • Automated encrypted backups with periodic restore testing

8. Retention

We retain personal data only as long as necessary for the purposes described above or as required by law. Respondent-level study data is retained for the duration of the study and a limited verification period, after which it is deleted or irreversibly anonymised in accordance with our documented retention schedule. Client account data is retained for the duration of the relationship and applicable statutory periods.

9. Your Rights

Subject to applicable law, you may have the right to: access your personal data; request correction or deletion; object to or restrict processing; withdraw consent at any time (including withdrawing from a study); receive a copy of your data in a portable format; and lodge a complaint with a supervisory authority (including the UAE Data Office or, for GDPR matters, your local supervisory authority).

To exercise any right, contact us using the details in Section 12. We respond within the timelines required by applicable law.

10. Children

Our Services are not directed at children. We do not knowingly collect personal data from minors without verifiable parental or guardian consent, and research involving minors is conducted only where permitted by, and in accordance with, applicable law and research ethics standards.

11. Changes to This Policy

We may update this Policy from time to time. Material changes will be notified via our websites or by email. The "Effective date" above indicates the latest revision.

12. Contact

Data Protection Contact: Vaibhav Sharma, CEO

  • Email: vaibhav.sharma@spryinsights.com
  • Phone: +971 50 103 8470
  • Address: Spry Insights FZ-LLC, In5 Tech - HD16C, Dubai Internet City, Dubai, United Arab Emirates (License No. 107824)