1Who we are
Array Dynamics Future ("we", "us") is the data controller for the personal data described in this policy. We provide energy trading consulting, energy management systems, AI integration and custom software development to clients in Europe, the Middle East and Asia.
For any privacy matter — including access, correction or deletion requests — contact us at info@arraydynamicsfuture.com.
2Which laws apply
We operate from the United Arab Emirates and serve clients across the European Union. Because we offer services to organisations and individuals in the EU, the EU General Data Protection Regulation (GDPR) applies to that processing, in addition to UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL).
Where the two frameworks differ, we apply whichever standard gives you stronger protection.
3What we collect
We collect only what we need to answer your enquiry and deliver our services:
- Contact details you submit — your name, email address, and the project interest you select in our contact form.
- Message content — anything you choose to write to us through the form or by email.
- Client and project data — material you share with us during an engagement, which may include business documents, operational data, source code or datasets used for AI modelling.
- Technical data — IP address, browser type, device and pages visited, collected automatically in server logs for security and reliability.
We do not collect special category data (such as health, biometric or political data), and we ask that you do not send it to us through the contact form.
4Why we process it, and on what basis
The GDPR requires a lawful basis for every processing purpose. Ours are:
- Responding to enquiries
- Legitimate interest — we cannot answer a business enquiry without processing the contact details you send us.
- Delivering client projects
- Performance of a contract — processing is necessary to carry out the services set out in the signed agreement.
- Security and abuse prevention
- Legitimate interest — server logs and rate limiting protect the site from automated abuse.
- Legal and accounting records
- Legal obligation — we retain contracts and invoices for the periods required by applicable tax and company law.
5How long we keep it
- Contact form enquiries
- 24 months from last contact, then deleted.
- Client project data
- The duration of the engagement plus 12 months, unless the contract specifies otherwise.
- Contracts and invoices
- As long as required by applicable tax and company law.
- Server logs
- Up to 12 months.
You can ask us to delete your data sooner — see “Your rights” below.
6Who we share it with
We do not sell personal data, and we do not share it for advertising. We use a small number of service providers who process data on our behalf under contract:
- Hosting and content delivery — to serve this website and store its data.
- Email delivery — to transmit messages sent through the contact form.
- Where a specific client project requires additional processors, we identify them in the project agreement before any data is shared.
We may also disclose data where a competent authority legally requires us to.
7International transfers
We operate from the UAE, many of our clients are in the EU, and our infrastructure providers may process data in other countries. Personal data may therefore be transferred outside the country where you are located.
Where data leaves the European Economic Area, we rely on the European Commission's Standard Contractual Clauses, or another transfer mechanism permitted under Chapter V of the GDPR, and we assess whether additional safeguards are needed.
8Client data and AI models
When we deliver AI or machine learning work, any proprietary data you provide is treated as confidential and used only to build and operate the systems agreed in your contract.
We do not use client data to train generalised or shared models, and we do not use it for any other client, unless you agree to it in writing in a separate Data Processing Agreement.
Where a project involves us acting as a processor on your behalf, we sign a Data Processing Agreement setting out our obligations under Article 28 GDPR before processing begins.
10Your rights
Under the GDPR and the UAE PDPL you can ask us to:
- Access — receive a copy of the personal data we hold about you.
- Rectify — correct data that is inaccurate or incomplete.
- Erase — delete your data where we have no overriding legal reason to keep it.
- Restrict or object — limit how we process your data, including processing based on legitimate interest.
- Port — receive your data in a structured, machine-readable format.
- Withdraw consent — at any time, where processing is based on consent.
Email info@arraydynamicsfuture.com to exercise any of these. We respond within 30 days and do not charge for a first request.
If you are in the EU or EEA and believe we have handled your data improperly, you have the right to lodge a complaint with your national data protection supervisory authority. We would appreciate the chance to resolve it with you first.
11How we protect it
We apply access controls, encryption in transit (HTTPS across the entire site), and rate limiting on our contact endpoint. Access to client project data is restricted to team members working on that engagement.
No system is perfectly secure. If a breach occurs that is likely to affect your rights, we will notify the relevant supervisory authority within 72 hours and inform you where the law requires it.
12Changes to this policy
We update this policy when our practices or the law change. The date at the top always reflects the current version.
If a change materially affects how we handle your data, we will make that clear on this page rather than relying on the date alone.