Privacy Policy

Effective date: [DATE]

Last updated: [DATE]

1. Who we are

SCORA (“SCORA”, “we”, “us”, “our”) is a cybersecurity assessment platform operated by [LEGAL ENTITY NAME], a company [established / licensed] in [JURISDICTION — e.g. Abu Dhabi, UAE / ADGM / DIFC], with its registered address at [ADDRESS]. We are the data controller responsible for the personal data described in this policy.

For any privacy-related question or to exercise your rights, contact us at [PRIVACY CONTACT EMAIL].

2. Scope

This policy explains what personal data we collect when you use the SCORA platform at scora.ae and related services, why we process it, who we share it with, how we protect it, and the rights available to you. It applies to account holders, members of organisations (tenants) using SCORA, and visitors who contact us.

3. Personal data we collect

  • Account data: your full name, email address, and a securely hashed password. We do not store your password in readable form.
  • Organisation (tenant) data: the organisation you belong to, your role within it, and team-invitation details (the email address of people you invite).
  • Assessment data: the answers you provide to assessment questions, the resulting maturity and risk scores, any AI-generated analysis of your responses, and the reports generated from them. These responses may describe your organisation’s security posture.
  • Technical and usage data: IP address, browser/device information, and security and audit logs (for example, login events), used for security, abuse prevention, and troubleshooting.
  • Communications: messages you send us (for example, support or contact-form submissions).

We do not intentionally collect special categories of personal data, and we ask that you not submit such data in free-text assessment fields.

4. How and why we use your data, and our legal basis

PurposeLegal basis (PDPL)
Create and manage your account; authenticate youPerformance of a contract
Provide the assessment service, generate scores, analysis, and reportsPerformance of a contract
Send service emails (verification, password reset, notifications)Performance of a contract
Secure the platform, prevent abuse, rate-limit, maintain audit logsOur legitimate interests in protecting the service and its users
Respond to your enquiries and provide supportPerformance of a contract / our legitimate interests
Comply with legal obligationsCompliance with a legal obligation
Optional product communications, if anyYour consent (which you may withdraw at any time)

5. AI-assisted analysis

If AI analysis is enabled for an assessment, your assessment responses (and derived data) are processed by an automated analysis system, including a third-party AI service provider ([AI PROVIDER — confirm]), to generate written analysis and recommendations. This analysis is advisory and may contain errors or omissions; it does not replace professional judgement. We do not use your assessment data to train third-party AI models. [Confirm the AI provider’s data-use terms with counsel.]

6. Cookies and similar technologies

We use a small number of strictly necessary cookies to keep you signed in and to secure your session (delivered as secure, HTTP-only cookies). We use Cloudflare Turnstile to protect forms from automated abuse, which processes limited technical data to distinguish humans from bots. We do not use advertising cookies. [If any analytics are added before launch, disclose them here.]

7. How we share your data

We share personal data only as needed to run the service:

  • Service providers (sub-processors) acting on our instructions, including [HOSTING PROVIDER] (infrastructure), [EMAIL/SMTP PROVIDER] (transactional email), Cloudflare (security/anti-abuse), and [AI PROVIDER] (assessment analysis, where enabled).
  • Within your organisation: assessment data may be visible to authorised members of your organisation (tenant) according to their role.
  • Share links: if you create a shareable results link, anyone with that link can view the shared results until the link expires or is revoked. Treat these links as confidential.
  • Legal and safety: where required by law, regulation, or valid legal process, or to protect rights, safety, and the integrity of the service.

We do not sell your personal data.

8. International data transfers

Some of our service providers may process data outside the UAE ([CONFIRM HOSTING/SUB-PROCESSOR LOCATIONS]). Where personal data is transferred outside the UAE, we will ensure an appropriate legal basis and safeguards consistent with the applicable UAE data-protection law before transfer. [Counsel to confirm transfer mechanism and any required consents.]

9. Data retention

We retain personal data only as long as necessary for the purposes above:

  • Account and organisation data: for the life of your account and [RETENTION PERIOD] after closure.
  • Assessment responses, scores, analysis, and reports: [RETENTION PERIOD].
  • Security and audit logs: [RETENTION PERIOD].

After the applicable period, data is deleted or irreversibly anonymised. [Confirm concrete periods with counsel and operations.]

10. How we protect your data

We apply technical and organisational measures appropriate to the risk, including:

  • Encryption at rest of sensitive data — including account identifiers, assessment responses, scores, AI analysis output, and generated report content — using authenticated AES-256 encryption.
  • Encryption in transit via TLS.
  • Passwords stored only as salted bcrypt hashes; access and share tokens stored only as hashes.
  • Role-based access controls and tenant isolation so organisations can access only their own data.
  • Rate limiting, audit logging, and other safeguards against unauthorised access and abuse.

No system is perfectly secure, but we work to protect your data and to address vulnerabilities responsibly.

11. Your rights

Subject to the applicable UAE data-protection law, you have the right to: access your personal data; request correction of inaccurate data; request erasure; restrict or object to certain processing; request portability of data you provided; and withdraw consent where processing is based on consent. Exercising these rights will not affect the lawfulness of processing carried out beforehand.

To exercise any right, contact [PRIVACY CONTACT EMAIL]. At launch, account deletion requests are handled by contacting us; [self-service deletion is planned for a future release]. We will respond within the period required by applicable law.

If you believe we have not handled your data properly, you may lodge a complaint with the competent UAE authority ([the UAE Data Office / the relevant free-zone regulator — confirm based on jurisdiction]).

12. Children

SCORA is a business tool not directed at children and is not intended for anyone under 18. We do not knowingly collect personal data from children.

13. Data breaches

If a personal-data breach occurs that is likely to affect your rights, we will notify the competent authority and, where required, affected individuals, in accordance with applicable law.

14. Changes to this policy

We may update this policy from time to time. We will post the updated version with a revised “Last updated” date and, where appropriate, notify you of material changes.

15. Contact

[LEGAL ENTITY NAME][PRIVACY CONTACT EMAIL][ADDRESS]