Privacy Policy
AÏP Genius®
AI-powered IP advisory and prosecution at your fingertips.
Version: 3.0
Last Updated: July 9, 2026
AÏP Genius W.L.L. (“AÏP”, “we”, “our”, or “us”) is committed to protecting your privacy and safeguarding your Personal Data. This Privacy Policy explains how we collect, use, disclose, process, transfer, store, and protect your information when you access our Platform or use our services.
For the purposes of applicable data protection laws, including the Bahrain Personal Data Protection Law (PDPL), the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, and the European Union General Data Protection Regulation (GDPR), AÏP Genius acts as the Data Controller in relation to Personal Data processed through the Platform.
1. Information We Collect
We collect only the Personal Data reasonably necessary to provide our services related to Intellectual Property (IP) matters, operate the Platform, comply with legal obligations, and maintain the security and integrity of our systems. The categories of Personal Data we may collect include:
- Identity & Account Information: Full name, email address, telephone number, company name, professional title, account credentials, and billing contact information.
- Verification & Legal Documentation: Passports, national identity documents, powers of attorney (POAs), commercial registration documents, articles of incorporation, corporate authorizations, signature documents, priority documents, assignment documents, licences, recordal documents, and other documentation required to complete IP services.
- IP Rights Management Data: Information relating to trademarks, patents, designs, copyrights, domain names, ownership details, applicant information, inventor or creator information, priority claims, filing instructions, prosecution history, renewals, recordals, oppositions, cancellations, disputes, and related portfolio management data.
- AI Interaction Data: Queries, descriptions of inventions, trademarks, and other IP assets, together with documents and information submitted through our AI-powered modules, including “Ask AÏP” and “Search AÏP”, where such information constitutes Personal Data.
- Financial Data: Billing and transaction information. All payments are processed through secure PCI-DSS compliant third-party payment providers. AÏP does not store raw credit card information.
- Technical & Diagnostic Data: IP addresses, browser information, device information, login records, document access logs, filing activity, and other technical and diagnostic information generated through use of the Platform.
- Integrated CRM & Analytics Data (HubSpot): When you interact with our forms, subscribe to updates, or navigate our site, personal data (such as your name, email address, company name, and professional details) and technical metadata (such as your IP address, geographical location, browser type, and page views) are captured via integrated platform services provided by HubSpot Ireland Ltd. (HubSpot House, 1 Sir John Rogerson's Quay, Dublin 2, Ireland).
Users should only submit Personal Data and documentation that is necessary for the requested service and that they are legally authorized to provide. Users remain responsible for ensuring that any Personal Data or third-party information submitted to AÏP has been lawfully collected and shared.
2. AI Processing & Hosting Framework
- Data Residency: Our primary hosting infrastructure and Artificial Intelligence (AI) systems are deployed within secure Microsoft Azure cloud environments located in the United Arab Emirates (UAE). By using the Platform, you acknowledge that your data may be processed and stored within these secure cloud environments as described in this Privacy Policy.
- Proprietary AI Guardrails: User prompts, documents, and related information are processed within a private and encrypted environment. User data is logically isolated and is not used to train publicly accessible third-party AI models. Additionally, and unless expressly authorized by the user, confidential client information and personal data submitted through the Platform will not be used to train AÏP's proprietary AI models. AÏP may use anonymized, aggregated, and de-identified information for system monitoring, security, quality assurance, analytics, and platform improvement purposes.
- AI Output Disclaimer: AI-generated outputs are provided as informational and advisory support tools only and do not constitute legal advice, legal opinions, or professional representation. Users should independently review all AI-generated outputs and seek professional advice where appropriate.
- Automated Decision-Making & Human Oversight: While certain features of the Platform may use AI and Agentic AI capabilities to generate recommendations, draft outputs, searches, classifications, alerts, or workflow actions, AÏP does not rely on fully automated decision-making that produces legal or similarly significant effects on individuals without meaningful human oversight. Users remain responsible for reviewing, validating, and approving all outputs, filings, submissions, and actions before implementation or submission to any governmental authority or third party.
3. International Data Transfers & Public Records
To provide IP related services across multiple jurisdictions, Personal Data may need to be transferred internationally.
- Local IP Agents (PLAs): Where necessary to perform requested services, AÏP may share relevant information with authorized local IP agents, attorneys, representatives, and service providers in the applicable filing jurisdiction. These parties may act as independent data controllers or sub-processors depending on local legal requirements. AÏP implements appropriate contractual, confidentiality, and data protection safeguards designed to ensure that Personal Data is processed securely and in accordance with applicable law.
- Transfer Safeguards: AÏP implements appropriate cross-border transfer mechanisms as recognized or permitted under applicable local laws.
- Transfers Required to Perform Services: By instructing AÏP to perform any services related to IP matters in a particular jurisdiction, you acknowledge and direct that Personal Data may need to be transferred to that jurisdiction as required and needed to perform such services.
- Public Record Disclosure: Certain IP rights filings require disclosure of information to governmental IP offices. Once a trademark, patent, design, or other IP application is formally filed and published by a competent authority, certain information may become part of the public record pursuant to applicable law. Once such information becomes publicly available through a governmental registry, it may no longer be subject to deletion, erasure, or removal rights available under applicable data protection laws.
4. Legal Basis for Processing
Depending on the applicable jurisdiction, AÏP may process Personal Data on one or more of the following legal bases:
- Performance of Services & Contractual Necessity: Where recognized by applicable law, we process Personal Data to manage user accounts, provide requested services, perform intellectual property workflows, and facilitate interactions with authorized local representatives and service providers.
- Legal Obligation & Regulatory Compliance: We process Personal Data where necessary to comply with applicable laws, regulations, court orders, tax obligations, anti-money laundering requirements, Know Your Customer (KYC) obligations, and disclosure requirements imposed by governmental authorities or intellectual property offices.
- Consent: We rely on consent where required by law, including for marketing communications, non-essential cookies, and certain optional Platform features. Where processing is based on consent, users may withdraw consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
- Legitimate Interests: Where recognized by applicable law, we may process technical, diagnostic, and usage information to maintain platform security, prevent fraud, improve performance, protect our systems, and support the ongoing operation and improvement of our services, provided that such interests do not override the fundamental rights and freedoms of affected individuals.
5. Data Retention & Deletion
- Operational Retention: Personal Data is generally retained for as long as a user account remains active and for as long as is reasonably necessary to provide the requested services, operate the Platform, maintain security, resolve disputes, enforce our agreements, and fulfil the purposes described in this Privacy Policy.
- Statutory Retention: Following account closure or the completion of requested services, certain Personal Data may be retained where necessary to comply with applicable legal, regulatory, tax, accounting, intellectual property, anti-money laundering, corporate recordkeeping, or other statutory obligations. As a general guideline, intellectual property filing records may be retained for up to five (5) years and financial records for up to seven (7) years, unless a longer retention period is required or permitted by applicable law.
Where Personal Data is processed through our customer relationship management (CRM) platform, including HubSpot, retention periods vary depending on the purpose of processing. Marketing subscription information is retained until you unsubscribe from marketing communications or withdraw your consent, where consent is the legal basis for processing. Following unsubscription, your contact details may be retained on a suppression list solely to ensure that you do not receive further marketing communications. Information submitted through general enquiries or “Contact Us” forms is generally retained for one (1) year following the resolution of the enquiry, unless an ongoing business, contractual, or legal relationship is established. Where communications result in a client relationship or contractual engagement, the relevant Personal Data may be retained for the duration of that relationship and for an additional five (5) to seven (7) years, or for such longer period as required by applicable law, to satisfy legal, regulatory, financial, tax, accounting, intellectual property, and corporate recordkeeping obligations. Technical analytics information collected through CRM and website analytics tools is retained only for as long as necessary for the relevant analytical purpose and, where required by applicable law, is processed subject to your consent. As a general guideline, such analytics data is retained for up to fourteen (14) months unless a different retention period is required or permitted by law.
- Deletion Requests: Subject to applicable law, users may request the deletion of their Personal Data at any time. AÏP will review and respond to such requests in accordance with applicable legal requirements and will delete or anonymize Personal Data where legally permitted. Certain information may be retained where necessary to comply with legal obligations, establish, exercise or defend legal claims, fulfil contractual obligations, protect legitimate business interests, or maintain records required under applicable intellectual property or regulatory laws.
6. Data Security & Access Control
AÏP recognizes that information submitted through the Platform may include confidential, proprietary, commercially sensitive, or unpublished IP information, including trademark strategies, patent disclosures, inventions, business plans, licensing information, trade secrets, and related legal or technical documentation. AÏP treats such information as confidential and implements reasonable administrative, technical, and organizational measures designed to protect it from unauthorized access, disclosure, alteration, or destruction. To safeguard Personal Data and confidential information, AÏP maintains industry-standard security measures, including:
- Encryption: Data is encrypted at rest (AES-256) and in transit (TLS 1.2+).
- Role-Based Access Control (RBAC): Access to Personal Data is restricted to authorized personnel based on business need and the principle of “Least Privilege”.
- Auditability: Access to sensitive information is logged and monitored through secure audit mechanisms designed to support accountability and security oversight.
- Data Breach Notification: In the event of a personal data breach or security incident that poses a risk to Personal Data, AÏP will take reasonable steps to investigate the incident, mitigate its impact, secure affected systems, and implement appropriate remedial measures. Where required by applicable law, AÏP will notify competent authorities and affected individuals within the applicable legal timeframes.
Where Personal Data is processed by authorized third-party service providers, including customer relationship management (CRM), hosting, analytics, and communication service providers, AÏP ensures that such providers are subject to appropriate contractual obligations and maintain security measures designed to protect Personal Data, including encryption, access controls, and internationally recognized security practices.
While AÏP continuously reviews and enhances its security measures to address evolving threats and industry standards, no method of electronic transmission, storage, or processing can be guaranteed to be completely secure. AÏP periodically reviews its security controls against internationally recognized standards and may obtain independent certifications or attestations from time to time.
7. Cookies and Tracking Technologies
AÏP uses cookies and similar technologies to support platform functionality, improve user experience, and analyze performance.
- Essential Cookies: Certain cookies are necessary for the operation, security, and functionality of the Platform and are deployed automatically.
- Non-Essential Cookies: Analytics, performance, and marketing cookies will only be used where permitted by applicable law and, where required, with your consent.
- Cookie Management: Users may manage cookie preferences through browser settings or any cookie management tools made available through the Platform.
8. Children's Privacy
The Platform is intended for business, professional, and commercial users and is not directed to individuals under the age of 18. AÏP does not knowingly collect Personal Data from children. If we become aware that Personal Data relating to a child has been collected without appropriate authorization or legal basis, we will take reasonable steps to delete such information in accordance with applicable law.
9. Data Subject Rights
Subject to applicable law, users may have the right to:
- Access their Personal Data;
- Correct inaccurate Personal Data;
- Request deletion of Personal Data;
- Object to or restrict certain processing activities;
- Request data portability;
- Withdraw consent where processing is based on consent.
To exercise any applicable rights, please contact AÏP using the contact details provided below. We will review and respond to requests in accordance with applicable legal requirements.
10. Changes to This Privacy Policy
AÏP may update or amend this Privacy Policy from time to time to reflect changes in services, platform functionality, legal requirements, operational practices, security measures, or data processing activities. Updated versions will be published on the Platform. Where required by applicable law, we will provide appropriate notice and obtain any necessary consent before material changes take effect. Users are encouraged to review this Privacy Policy periodically.
11. Contact Us
If you have any questions regarding this Privacy Policy or wish to exercise your rights under applicable data protection laws, you can contact us by Email at: [email protected]
