Sustained

    Privacy Policy

    Effective Date: April 27, 2026

    Beyin Digital Technology Limited

    FD - GF, Accelerator Building, Masdar City, Abu Dhabi, United Arab Emirates

    Contact: Support@beyin.me

    1. Introduction

    Beyin Digital Technology Limited ("Company", "we", "us", or "our") operates Sustained System (the "Service"), a multi-tenant SaaS platform providing customer relationship management, project management, helpdesk, invoicing, and workspace collaboration tools. This Privacy Policy explains how we collect, use, disclose, store, and protect personal information when you access or use the Service.

    This Policy applies to workspace owners, team members, customers, agents, and any visitors to our websites and applications. By using the Service you acknowledge that you have read and understood this Policy. If you do not agree, you must not use the Service.

    2. Scope and Definitions

    • "Personal Data" means any information relating to an identified or identifiable natural person.
    • "Workspace" means an isolated tenant environment within the Service controlled by a Workspace Owner.
    • "Workspace Owner" means the entity or individual responsible for a Workspace and its members.
    • "User" means any individual authorised to access a Workspace, including admins, team members, customers, and agents.
    • "Processing" has the meaning given under applicable data protection laws, including the UAE Federal Decree-Law No. 45 of 2021 (PDPL) and, where applicable, the EU General Data Protection Regulation (GDPR).

    3. Data Controller and Contact

    For Personal Data submitted into a Workspace, the Workspace Owner is the data controller and Beyin Digital Technology Limited acts as the data processor. For account-level data, marketing, billing, and platform telemetry, Beyin Digital Technology Limited acts as the data controller.

    For all privacy enquiries, requests, or complaints, contact: Support@beyin.me.

    4. Information We Collect

    4.1 Information You Provide

    • Account information: full name, email address, phone number, password (hashed), profile image, job title, and language preference.
    • Workspace data: workspace name, slug, branding, billing address, tax identifiers, currency settings, modules enabled, and member roles.
    • Customer Relationship Management (CRM) data: client and company records, contacts, notes, tags, deals, and lifecycle status.
    • Project and task data: projects, tasks, comments, attachments, time entries, and submission files.
    • Helpdesk and messaging data: chat conversations, WhatsApp message history (where integrated), support tickets, file attachments, and agent assignments.
    • Invoicing and financial data: invoices, line items, hour subscriptions, payments, payouts, exchange rates, and VAT details.
    • Communications: emails, in-app messages, feedback, and survey responses.

    4.2 Information Collected Automatically

    • Authentication metadata: login timestamps, IP address, session tokens (JWT), device and browser information, and OTP delivery logs.
    • Usage telemetry: pages visited, features used, performance metrics, error logs, and aggregated module usage counters.
    • Cookies and local storage: session identifiers, the active workspace identifier, theme preferences, and tutorial state.
    • Security logs: rate-limit events, suspicious activity flags, and audit trails for sensitive actions.

    4.3 Information from Third Parties

    • Identity providers and authentication services (Supabase Auth).
    • Payment processors (Stripe) for subscription billing and portal sessions.
    • Messaging providers (Meta WhatsApp Business API, Resend / Mailgun for email).
    • Integrations connected by Workspace Owners (e.g. GitHub, GitLab, OpenAI, n8n, analytics services).
    • Exchange rate providers and tax data services.

    5. How We Use Personal Data

    We process Personal Data for the following purposes:

    • Providing, maintaining, and improving the Service and its modules.
    • Authenticating users, managing sessions, and enforcing role-based access control across the five-layer permission hierarchy.
    • Operating multi-tenant workspace isolation and applying Row-Level Security policies.
    • Processing subscriptions, invoices, payments, and renewals through Stripe.
    • Sending transactional notifications by email and WhatsApp (account, billing, helpdesk, task, and workflow events).
    • Providing AI-assisted features through the Lovable AI Gateway and approved AI agents, subject to workspace configuration.
    • Generating analytics, reports, financial forecasts, and workspace intelligence documents.
    • Detecting, preventing, and responding to fraud, abuse, and security incidents.
    • Complying with legal, regulatory, tax, and accounting obligations.
    • Communicating service updates, security notices, and (with consent where required) marketing messages.

    6. Legal Bases for Processing

    Where the GDPR or comparable laws apply, we rely on the following legal bases:

    • Performance of a contract — to provide the Service to you and your Workspace.
    • Legitimate interests — to secure the platform, prevent abuse, and improve our products, balanced against your rights.
    • Legal obligation — to comply with tax, accounting, anti-fraud, and law-enforcement requirements.
    • Consent — for optional features such as marketing communications, certain cookies, and elective integrations. Consent may be withdrawn at any time.

    7. Sharing and Disclosure

    We do not sell Personal Data. We share Personal Data only as described below:

    • Within a Workspace: data is visible to authorised members of that Workspace according to their role and module permissions.
    • Service providers (sub-processors): cloud hosting (Supabase, Render), payment processing (Stripe), email delivery (Resend / Mailgun), messaging (Meta WhatsApp), AI inference (Lovable AI Gateway and approved providers), and analytics.
    • Workspace integrations enabled by the Workspace Owner (e.g. GitHub, GitLab, n8n, analytics dashboards).
    • Legal and regulatory disclosures where required by law, court order, or to protect rights, property, or safety.
    • Business transfers in the event of a merger, acquisition, financing, or sale of assets, subject to equivalent protections.

    All sub-processors are bound by written agreements requiring confidentiality, security, and lawful processing.

    8. International Data Transfers

    The Service is operated from the United Arab Emirates and uses cloud infrastructure that may process data in other jurisdictions. Where Personal Data is transferred outside the UAE or the European Economic Area, we rely on appropriate safeguards such as Standard Contractual Clauses, adequacy decisions, or equivalent mechanisms recognised under the UAE PDPL.

    9. Data Retention

    • Account and workspace data: retained for the duration of the subscription and for a reasonable period after termination to allow recovery, dispute resolution, and legal compliance.
    • Invoices, financial records, and tax documentation: retained for the period required by applicable tax and accounting law (typically up to seven years).
    • Helpdesk, chat, and submission data: retained while the Workspace remains active and according to the Workspace Owner's configured retention preferences.
    • Authentication logs and security audit trails: retained for up to twenty-four months for security and compliance purposes.
    • Backups: retained on a rolling schedule and overwritten in the ordinary course of operations.

    Upon Workspace deletion, Personal Data is removed or irreversibly anonymised within ninety (90) days, except where retention is required by law.

    10. Security

    We implement technical and organisational measures designed to protect Personal Data against unauthorised access, alteration, disclosure, or destruction. Measures include:

    • Encryption in transit (TLS) and at rest for stored data and backups.
    • Multi-tenant isolation enforced through Row-Level Security and SECURITY DEFINER functions in the database.
    • Role-based access control with module- and action-level permissions.
    • Hashed and salted password storage; secure OTP-based onboarding flows.
    • Rate limiting, CORS hardening, Helmet security headers, and DOM sanitisation utilities.
    • Edge function authentication, JWT validation, and signed webhook verification.
    • Private storage buckets with workspace-scoped access policies for sensitive attachments.
    • Continuous logging, monitoring, and security scanning.

    No security measure is perfect. Users are responsible for maintaining the confidentiality of their credentials and for promptly reporting any suspected compromise.

    11. Your Rights

    Subject to applicable law, you may have the following rights with respect to your Personal Data:

    • Right of access — to obtain confirmation and a copy of your Personal Data.
    • Right to rectification — to correct inaccurate or incomplete data.
    • Right to erasure — to request deletion of Personal Data, subject to legal exceptions.
    • Right to restriction or objection — to limit or object to certain processing activities.
    • Right to data portability — to receive your data in a structured, commonly used, machine-readable format.
    • Right to withdraw consent — at any time, without affecting prior lawful processing.
    • Right to lodge a complaint — with the UAE Data Office or your local supervisory authority.

    To exercise these rights, contact Support@beyin.me. For data held within a Workspace, requests should generally be directed to the Workspace Owner who acts as the controller of that data; we will assist them as their processor.

    12. Cookies and Similar Technologies

    The Service uses cookies, local storage, and similar technologies to:

    • Maintain authenticated sessions and remember the active workspace selection.
    • Persist user interface preferences such as theme and language.
    • Measure performance and diagnose errors.
    • Support optional analytics and integration features when enabled.

    You can control cookies through your browser settings. Disabling essential cookies may prevent the Service from functioning correctly.

    13. AI Features and Automated Processing

    The Service offers AI-assisted features, including AI agents, automated chat replies, workflow execution, financial forecasting, and workspace intelligence document generation. Where AI features are enabled:

    • Inputs may be transmitted to approved model providers via the Lovable AI Gateway for processing.
    • Workspace Owners control whether AI features are enabled and can disable them at any time.
    • AI outputs are generated programmatically and should be reviewed by a human before being relied upon for material decisions.
    • We do not use Workspace content to train third-party foundation models without an explicit opt-in.

    14. Children's Privacy

    The Service is not directed to children under the age of 18. We do not knowingly collect Personal Data from children. If we become aware that a child has provided Personal Data, we will take reasonable steps to delete it.

    15. Third-Party Services and Links

    The Service integrates with and may link to third-party services. Their privacy practices are governed by their own policies. We are not responsible for the content or privacy practices of third-party services.

    16. Data Breach Notification

    In the event of a Personal Data breach likely to result in a risk to the rights and freedoms of individuals, we will notify affected Workspace Owners and, where required, the relevant supervisory authority without undue delay and in accordance with applicable law.

    17. Changes to this Policy

    We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Material changes will be communicated by email, in-app notice, or by updating the Effective Date above. Continued use of the Service after changes take effect constitutes acceptance of the updated Policy.

    18. Governing Law

    This Privacy Policy is governed by the laws of the United Arab Emirates, including the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, without regard to conflict-of-laws principles. Disputes shall be subject to the exclusive jurisdiction of the competent courts of Abu Dhabi, UAE.

    19. Contact Us

    If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact:

    Beyin Digital Technology Limited
    FD - GF, Accelerator Building, Masdar City, Abu Dhabi, United Arab Emirates
    Email: Support@beyin.me
    Website: https://sustained.ae

    © 2026 Beyin Digital Technology Limited. All rights reserved.