1. Scope
This Privacy Policy applies to the SousFounder websites, applications, support interactions and related services that link to it (the “Service”). It does not govern NeuraConnect products or services that display a different policy, or third-party services that a customer chooses to connect to SousFounder.
If a customer has entered into a master services agreement, order form or data processing addendum with us, that agreement may contain additional or more specific privacy terms. If those terms conflict with this Policy, the signed agreement controls to the extent of the conflict.
This Policy is intended to support applicable privacy requirements, including the UAE Personal Data Protection Law where it applies. References to privacy rights are subject to the law governing the particular processing and do not create rights that applicable law does not provide.
2. Our roles and your responsibilities
For website visitors, account administrators, prospects and business contacts, NeuraConnect generally acts as a controller of personal information. When we process data uploaded, imported or connected by a business customer (“Customer Data”), we generally act as that customer’s processor or service provider and process the data on its documented instructions.
Business customers are responsible for determining whether they have a lawful basis to collect and provide Customer Data, giving required notices, managing permissions and consent, responding to their end customers and configuring access appropriately. Requests concerning Customer Data should ordinarily be directed first to the relevant restaurant or business.
3. Information we collect
Information you provide directly
- Business contact and account information, such as name, work email, telephone number, company, role and authentication information.
- Communications, support requests, feedback, onboarding information and contractual records.
- Billing and transaction records where a paid service is agreed. Payment-card information may be handled directly by an authorized payment provider rather than stored by SousFounder.
Customer Data processed through the Service
- Restaurant operational information, including locations, menus, products, recipes, ingredients, procurement and inventory records.
- Order, transaction, settlement, payout, accounting and other financial information.
- Customer and guest information supplied by the customer or an authorized connected service, such as identifiers, contact details, order history and communication preferences.
- Marketing, analytics, review, campaign and connected-account information.
- OAuth grants, API credentials, resource identifiers and provider responses required for customer-directed integrations.
- Prompts, files, context and outputs associated with an AI-enabled feature that a customer elects to use.
Information collected automatically
We may collect IP address, browser and device details, timestamps, referring pages, diagnostics, security events, product usage, connector activity and audit information. The public website is not designed to use advertising trackers. See our Cookie Policy.
Customers should not provide highly sensitive personal information—such as health records, biometric identifiers, government identification numbers or cardholder data—unless an applicable written agreement expressly authorizes that processing.
4. Sources of information
We receive information directly from users and customers; from systems a customer chooses to connect; from authorized team members; from service providers supporting our operations; and from public or commercial sources where lawful. Before a customer enables a Connected Service, SousFounder presents a provider-specific data-use notice and external policy links. Authorized customers can review current disclosures in the in-app Trust Centre.
5. How we use information
- Provide, operate, secure, troubleshoot and improve the Service.
- Authenticate users, enforce permissions and maintain account and integration state.
- Process Customer Data according to customer instructions and provide requested analyses or workflows.
- Respond to inquiries, provide support and administer contracts and billing.
- Monitor reliability, prevent fraud, misuse and security incidents, and preserve auditability.
- Comply with law, enforce agreements and establish, exercise or defend legal claims.
- Send product or business communications where permitted. Recipients may opt out of non-essential marketing at any time.
Where applicable law requires a legal basis, we rely on performance of a contract, legitimate interests that are not overridden by individual rights, compliance with legal obligations, consent, and protection of legal rights. We do not use Customer Data for unrelated advertising.
6. Artificial intelligence and Zero Data Retention
Our production policy is that Customer Data may be submitted to an external AI model provider only when the provider is approved under an enterprise or API arrangement contractually and technically configured for Zero Data Retention (“ZDR”). An approved provider may process the data transiently to return the requested output but may not retain it after completion or use it to train, fine-tune or improve provider models.
ZDR describes retention by the external model provider. It does not mean that SousFounder retains no information. SousFounder may retain prompts, outputs, audit records or source information within the customer’s own Service environment where necessary to provide an enabled feature, maintain business records, investigate security, comply with law or follow the customer’s configuration. Such information remains subject to this Policy and the applicable customer agreement.
We will not activate a model provider for production Customer Data until its ZDR eligibility has been verified. If a requested capability cannot meet that requirement, it must remain disabled for production Customer Data. Customer Data is not used to train, fine-tune or improve third-party models.
AI output can be incomplete or inaccurate. The Service is not intended to make solely automated decisions that produce legal or similarly significant effects on an individual. Customers are responsible for appropriate human review and for decisions made using output.
7. Google API data
If a customer connects a Google service, SousFounder uses the authorized data only to provide and secure customer-requested functionality. Depending on the connection and resources selected, this may include discovering accessible Google Ads accounts, Google Analytics properties or Google Business Profile locations; reading relevant reports, metrics or reviews; and performing a customer-approved Business Profile reply where enabled.
Google OAuth grants are protected as integration credentials, access is scoped to the applicable tenant and selected resources, and customers may disconnect a Google integration. We do not sell Google user data, use it for targeted advertising, or permit humans to read it except where necessary for security, legal compliance, or support requested and authorized by the customer.
SousFounder’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Customers should also review Google’s Privacy Policy, Google Safety and Security, and the Google Analytics privacy safeguards. Instructions for disconnecting access and requesting deletion are available on our Data Deletion page.
8. When we disclose information
We do not sell personal information or Customer Data. We do not share it for cross-context behavioural advertising. We may disclose information only as reasonably necessary:
- To personnel and contractors subject to confidentiality and access restrictions.
- To vetted subprocessors that provide cloud infrastructure, security, communications, support or approved ZDR AI processing. Current details are provided to authorized customers in the Trust Centre and applicable data processing agreements.
- To third-party services at the customer’s direction, including when the customer authorizes an integration or external action. The information exchanged is presented before connection and remains available in the customer’s Trust Centre.
- To professional advisers, auditors, insurers and financing parties under appropriate duties of confidentiality.
- To authorities or other parties when required by law, valid legal process, or reasonably necessary to protect rights, safety and security.
- In connection with a merger, financing, restructuring or transfer of all or part of our business, subject to appropriate confidentiality and notice obligations.
We will review government demands for validity and scope and, where legally permitted, seek to notify the affected customer before disclosure.
9. Security
We use technical and organizational measures intended to protect information according to its sensitivity and risk. These include tenant-scoped authorization, role-based access, encryption of integration credentials before storage, HTTPS for production traffic, authenticated integration flows, logging, backups, deployment controls and incident-response procedures.
No method of storage or transmission is completely secure, and we cannot guarantee absolute security. See Security & Trust for our security approach. Authorized customers can review current provider security information in the in-app Trust Centre.
10. Data minimization and retention
We seek to collect and retain only information reasonably necessary for the stated purposes. Retention depends on the nature of the data, customer instructions, account status, security needs and legal obligations.
- Customer Data is retained for the service term and deleted or returned according to the applicable agreement and documented customer instructions, subject to limited backup cycles and legal holds.
- Account, contractual, billing and transaction records may be retained as required for tax, accounting, dispute and compliance purposes.
- Security, diagnostic and audit records are retained for a period proportionate to investigation, reliability and accountability needs.
- Prospect and support communications are retained while relevant to the relationship and applicable limitation periods.
Deletion from active systems may not immediately remove information from encrypted backups. Backup copies remain protected, are not restored except for continuity or recovery, and are removed through the ordinary backup lifecycle unless a legal hold applies.
11. International processing
NeuraConnect is based in the United Arab Emirates and may use providers or personnel in other countries. Where required, we use contractual, organizational and technical safeguards designed to support lawful transfers, such as data-processing agreements and recognized transfer clauses. Data location and transfer requirements may also be addressed in a customer agreement.
12. Privacy rights
Depending on location and applicable law, individuals may have rights to access, correct, delete, restrict or object to processing; withdraw consent; receive a portable copy; or complain to a regulator. These rights may be subject to exceptions and identity verification.
To exercise a right concerning a SousFounder account or our direct business relationship, email info@neuraconnect.ai. For information controlled by a restaurant or other customer, contact that business first. We will assist customers with verified requests as required by contract and law.
We will not discriminate against an individual for exercising an applicable privacy right.
13. Children
The Service is intended for businesses and authorized adult users. It is not directed to children, and we do not knowingly collect personal information directly from children. If you believe a child has provided information directly to us, please contact us.
14. Third-party services and links
Customer-directed integrations and external websites are controlled by third parties. Their independent processing, platform operation and security are governed by their own terms and policies. NeuraConnect does not control or assume responsibility for those independent practices. Customers should review the provider’s terms and requested permissions before authorizing a connection and disconnect access when it is no longer needed.
NeuraConnect remains responsible for how information received through a connection is handled within SousFounder and for subprocessors appointed by NeuraConnect as required by applicable law and contract. Provider-specific notices and links are shown to authorized customers before connection and remain available in the in-app Trust Centre.
15. Changes to this Policy
We may update this Policy as the Service, law and practices develop. The “Last updated” date identifies the latest version. We will provide additional notice of material changes where required by law or contract. Changes do not retroactively reduce contractual protections for Customer Data.
16. Contact
Privacy questions and requests may be sent to:
NeuraConnect Technologies F.Z.E
United Arab Emirates
info@neuraconnect.ai
www.neuraconnect.ai